Seratify

Data processing agreement

Last updated October 7, 2026

When you collect answers with Seratify, Serat Media processes them on your behalf. Article 28 of the GDPR requires an agreement about that. This is it. You accept it together with the terms of service, for yourself or for the organisation you act for.

Parties and roles

The controller is the account holder, or the organisation on whose behalf the account holder uses Seratify. The processor is Serat Media, Titaniumweg 498, 2401 ML Alphen aan den Rijn, Chamber of Commerce number 97857327.

What is processed

  • Purpose: hosting forms, collecting and storing responses, showing them to the controller, exporting them, and sending the email the controller turns on.
  • People concerned: respondents to the controller's forms, and members of the controller's workspace.
  • Data: whatever the controller's forms ask for, such as names, contact details, and answers. The controller decides this and is responsible for it, including any sensitive data.
  • Duration: as long as the controller uses Seratify, and until the data is deleted as described below.

Processing only on instructions

We process the data only to provide Seratify as the controller configures it, and never for our own purposes. If we are legally required to process it otherwise, we tell the controller first, unless the law forbids that.

Confidentiality

Everyone at Serat Media with access to the data is bound to confidentiality, and access is limited to what their work needs.

Security measures

  • Encrypted connections (HTTPS) for all traffic.
  • Hosting in the European Union, behind a firewall, with automatic security updates and key-only maintenance access.
  • Strict separation between workspaces: every query is limited to the workspace that owns the data.
  • Hashed passwords, and one-way hashes for the identifiers used in response limits.
  • Daily backups kept for 30 days.
  • Rate limits against automated abuse.

Subprocessors

The controller agrees that we use these subprocessors, each bound by obligations at least as strict as this agreement:

  • Hetzner Online GmbH (Gunzenhausen, Germany): hosting, storage, and backups, in the European Union.
  • Mailjet SAS (Paris, France): email delivery.

We announce new subprocessors at least 30 days in advance on this page and by email. The controller may object for a reasonable cause; if we cannot resolve it, the controller may end the agreement by deleting the account.

Helping the controller

Seratify lets the controller view, export, and delete responses, so it can answer requests from respondents itself. If a respondent contacts us directly, we forward the request to the controller. We also help with data protection impact assessments and with questions from supervisory authorities, as far as can reasonably be expected.

Data breaches

If we discover a breach involving the controller's data, we tell the controller without undue delay and at the latest within 48 hours, with what we know about its nature, its likely consequences, and the measures taken. The controller decides whether to notify the authority and the people concerned.

Deletion at the end

When the controller deletes responses, forms, or the account, we delete the data immediately from the live system and within 30 days from backups. We keep no copies, unless the law requires us to.

Information and audits

We give the controller the information needed to show that we meet this agreement. The controller may have an independent auditor check this, at its own cost, after reasonable notice, at most once a year unless there is a concrete reason.

Liability and law

The limits of liability in the terms of service apply. Dutch law applies to this agreement. If this agreement and the terms conflict about personal data, this agreement prevails.