Version 4 September 2026
In short
Your employees’ data remains 100% the property of your organization (the Data Controller). Hoeray is solely the Processor: we use the data only to send the gifts you set up and never sell or share it for our own purposes. After the end of the agreement we delete all personal data: at your request within 30 days, and otherwise automatically no later than 90 days after the end of the customer relationship — only the financial records are kept for 7 years because the Dutch Tax Administration requires this (see Article 12).
1.1 On the basis of the General Terms and Conditions, this Data Processing Agreement (hereinafter: “Agreement”) forms an integral part of the main agreement between the following parties:
Data Controller — the Client: the organization using Hoeray’s services, hereinafter: “Client”.
Data Processor — Hoeray (trade name of The Circle of 10 B.V.), with its registered office at Danzigerbocht 45S, 1013 AM Amsterdam, the Netherlands, registered in the Dutch Commercial Register under Chamber of Commerce (KvK) number 92475809, VAT ID NL866064485B01, hereinafter: “Hoeray” or “Processor”.
Data subjects — the Client’s employees whose personal data is processed by Hoeray.
1.2 Capitalized terms used in this Agreement that are not defined herein have the meaning given to them in the General Data Protection Regulation (GDPR) or in Hoeray’s General Terms and Conditions.
2.1 This Agreement relates to the processing of personal data of the Client’s employees by Hoeray in the context of the main agreement.
2.2 The duration of this Agreement equals the term of the main agreement between the parties.
2.3 Obligations under this Agreement which by their nature are intended to survive termination — including in any event the obligations concerning confidentiality (Article 5(b)), return and deletion (Article 12) and demonstrating compliance with respect to the period during which processing took place (Article 11) — remain in force after termination of the main agreement until they have been fully performed.
3.1 Hoeray processes personal data of the Client’s employees for the purpose of sending gifts (including cards and flowers) based on HR data at milestones, including birthdays, work anniversaries, promotions, joining the company and leaving the company — in each case after approval by the Client through the monthly approval round.
3.2 The processing comprises collecting (through the HR integration activated by the Client or manual entry), storing, structuring, consulting, using and disclosing to the sub-processors listed in Article 6, insofar as necessary to perform the services, as well as erasure in accordance with Article 12.
3.3 Hoeray processes personal data solely on the basis of documented instructions from the Client, unless a legal obligation to which Hoeray is subject requires otherwise; in that case, Hoeray informs the Client thereof before the processing, unless that legislation prohibits such notification.
3.4 The following in any event qualify as documented instructions from the Client: the main agreement and this Agreement, the configuration the Client records in the dashboard (including the activated occasions and gift types), the activation of an HR integration by the Client, the Client’s monthly approvals and rejections, and additional written instructions (including instructions given by email).
3.5 If Hoeray is of the opinion that an instruction from the Client infringes the GDPR or other Union or Member State data protection provisions, Hoeray shall immediately inform the Client thereof and is entitled to suspend the execution of that instruction until the parties have reached agreement.
4.1 The following categories of personal data are processed:
4.2 In addition, Hoeray stores on the Client’s behalf the access credentials for the HR integration activated by the Client. These are stored in encrypted form (see Annex 1) and are used solely to perform the synchronization activated by the Client.
4.3 The data subjects are employees of the Client. This includes current employees and, insofar as relevant to the services, employees who have recently left employment.
Hoeray commits to the following obligations:
a) Instructions
Hoeray processes personal data solely in accordance with Article 3.
b) Confidentiality
Hoeray ensures that all persons who have access to personal data under its authority have committed themselves to confidentiality or are bound by an appropriate statutory obligation of confidentiality.
c) Security (Art. 32 GDPR)
Hoeray implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk. The current measures are described in Annex 1 (Security measures, set out in Article 9), which forms part of this Agreement.
d) Sub-processors
Hoeray engages sub-processors solely in accordance with the regime of Article 6.
e) Assistance with data subject requests (Art. 28(3)(e) GDPR)
Taking into account the nature of the processing, Hoeray assists the Client by appropriate technical and organizational measures in fulfilling the Client’s obligation to respond to requests from data subjects (access, rectification, erasure, restriction, portability and objection). If Hoeray receives such a request directly from a data subject, Hoeray forwards it to the Client without undue delay and does not handle it independently.
f) Assistance with security, data breaches, DPIAs and prior consultation (Art. 28(3)(f) GDPR)
Taking into account the nature of the processing and the information available to Hoeray, Hoeray assists the Client in complying with the Client’s obligations under Articles 32 to 36 GDPR: security of processing, notification of breaches to the supervisory authority and to data subjects, data protection impact assessments (DPIA) as well as prior consultation of the supervisory authority (Art. 36 GDPR).
g) Notification of data breaches
In accordance with Article 8.
h) Information and audits (Art. 28(3)(h) GDPR)
Hoeray makes available to the Client all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR, and allows for audits in accordance with Article 11.
6.1 The Client hereby grants Hoeray a general written authorization to engage sub-processors for the performance of the services.
6.2 The current list of sub-processors is set out in Article 6.6 and is kept up to date at hoeray.com/dpa.
6.3 Hoeray informs the Client at least thirty (30) days before the intended engagement of a new sub-processor or the replacement of an existing sub-processor, by email to the Client’s account owners.
6.4 Within this period of thirty (30) days, the Client may object to the intended change in writing, stating its reasons. In that case, the parties will consult on a reasonable solution. If no solution is reached and Hoeray proceeds with the change, the Client has the right to terminate the main agreement with effect from the date on which the new sub-processor is engaged, without being bound by the regular notice period; subscription fees already paid in advance for the period after termination will in that case be refunded pro rata.
6.5 Hoeray imposes on every sub-processor, by contract, the same data protection obligations as set out in this Agreement, in particular the obligation to provide sufficient guarantees to implement appropriate technical and organizational measures. Where the sub-processor fails to fulfil its obligations, Hoeray remains fully liable to the Client for the performance of that sub-processor’s obligations.
6.6 At the time of entering into this Agreement, the following sub-processors are engaged:
| Sub-processor | Service | Location/region | Transfer mechanism |
|---|---|---|---|
| Stripe | Payment processing (customer and payment data only) | Ireland/US | DPF-certified (EU-US, including UK and Swiss extensions; certification active) |
| Print.one B.V. | Card printing and delivery | Netherlands | n/a (EEA) |
| Fleurop Interflora Nederland B.V. | Flower delivery | Netherlands | n/a (EEA) |
| Neon Inc. | Database hosting | US company, EU data region | No DPF — SCCs with supplementary measures based on a Transfer Impact Assessment, via Neon’s DPA; EU data region |
| Resend Inc. | Email delivery (including the order email with recipient details to Fleurop) | US | DPF-certified (EU-US, including UK extension) |
| Vercel Inc. | Application hosting | US company, EU edge network | DPF-certified, with SCCs as contractual fallback |
The transfer mechanisms in this table were verified on 27 August 2026.
7.1 Hoeray transfers personal data to countries outside the European Economic Area (EEA) only where an adequate level of protection is ensured on the basis of:
7.2 The transfer mechanism applied per sub-processor is stated in the table in Article 6.6. The Client may request a copy of the safeguards applied via hello@hoeray.com.
8.1 Hoeray notifies the Client of a personal data breach affecting the data processed under this Agreement without undue delay, and no later than 72 hours after establishing the breach, by email to the account owners.
8.2 The notification contains, insofar as known at that time: the nature of the breach, where possible the categories and approximate number of data subjects and personal data records concerned, the likely consequences, the measures taken and proposed, and a contact point for further information. Information not yet available is provided by Hoeray in phases as soon as it becomes available.
8.3 Hoeray documents all breaches, supports the Client in any notification to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) and to data subjects, and does not independently report a breach to the supervisory authority or to data subjects on the Client’s behalf, unless the Client so requests or a legal obligation of Hoeray requires it.
The following technical and organizational measures have been implemented. This annex describes only measures that have actually been implemented and is updated in the event of material changes.
Encryption
Access management
Monitoring and continuity
Organizational
10.1 On first request, Hoeray makes available to the Client all information reasonably necessary to demonstrate compliance with the obligations under Article 28 GDPR and this Agreement.
10.2 Initial reasonable assistance with the obligations referred to in this Agreement is included in the services; Hoeray does not charge any costs for it. For assistance exceeding this (such as extensive DPIA projects or repeated extensive information requests), Hoeray may charge the actual reasonable costs, provided these are announced in advance.
11.1 The Client has the right to conduct audits, or to have them conducted by an independent expert bound by confidentiality, to verify compliance with this Agreement, subject to the following conditions:
11.2 Hoeray cooperates with audits and provides the auditor with the information reasonably necessary for the audit.
12.1 At the Client’s written request, made upon or after termination of the main agreement, Hoeray shall within thirty (30) days, at the Client’s choice:
12.2 If the Client makes no request, Hoeray automatically deletes or anonymizes all personal data of data subjects — including the delivery details (recipient name and delivery address) in the delivery history — no later than ninety (90) days after the end of the customer relationship.
12.3 Hoeray confirms the deletion to the Client in writing.
12.4 By way of exception to the foregoing, Hoeray retains only the data subject to the statutory (tax) retention obligation of seven (7) years: invoices, the payment and credit records and the accounting data necessary for them. After the deletion pursuant to Article 12.1 or 12.2, these financial records no longer contain recipient names or delivery addresses of data subjects.
12.5 If the Client itself deletes the data of an individual data subject during the term of the agreement (for example after the employee leaves employment), Hoeray no longer processes that data, subject to the tax exception of Article 12.4.
13.1 The liability of the parties under this Agreement is subject to the limitations and conditions set out in the main agreement (Hoeray’s General Terms and Conditions), it being understood that nothing in this Agreement limits the rights of data subjects under the GDPR and that the statutory allocation of liability under Article 82 GDPR remains unaffected. In the event of a conflict between this Agreement and the General Terms and Conditions, this Agreement prevails insofar as damage in connection with the processing of personal data is concerned (Article 2.5 of the General Terms and Conditions).
14.1 Hoeray may amend this Agreement, for example in the event of changed legislation or changed services. Amendments are communicated to the Client by email at least thirty (30) days in advance, in accordance with the amendment clause in the General Terms and Conditions. Updates to the list of sub-processors follow the regime of Article 6.
14.2 Hoeray keeps a dated copy of every version; earlier versions can be requested via hello@hoeray.com.
15.1 This Data Processing Agreement is governed by Dutch law. Disputes arising from or in connection with this Agreement shall be submitted to the competent court in Amsterdam.
Annex to the General Terms and Conditions (Article 9.4). With this ready-to-use text, an employer (the Client, data controller) informs its employees that their name, date of birth and home address are shared with Hoeray (processor) and its delivery partners for the purpose of sending gifts. This model text is made available to clients through the Platform.
Attenties bij bijzondere momenten — wat betekent dit voor jouw gegevens?
[Organisatienaam] laat bijzondere momenten van medewerkers niet ongemerkt voorbijgaan. Bij gelegenheden zoals verjaardagen, werkjubilea, indiensttreding en uitdiensttreding versturen wij een attentie — bijvoorbeeld een kaart of bloemen — naar je huisadres. Voor het versturen daarvan gebruiken wij Hoeray, een dienst van The Circle of 10 B.V. (hoeray.com).
Welke gegevens delen wij? Wij delen jouw naam, geboortedatum en privéadres met Hoeray. Hoeray verwerkt deze gegevens uitsluitend in onze opdracht (als verwerker onder een verwerkersovereenkomst) en deelt jouw naam en adres alleen met haar bezorgpartners — de kaartendrukkerij en de bloemist — voor zover dat nodig is om de attentie bij je te bezorgen. Hoeray gebruikt je gegevens nooit voor eigen doeleinden en verkoopt ze niet.
Op welke grondslag? Wij doen dit op grond van ons gerechtvaardigd belang als werkgever (art. 6 lid 1 sub f AVG): het tonen van waardering en persoonlijke aandacht voor onze medewerkers bij bijzondere momenten.
Hoe lang worden de gegevens bewaard? Hoeray bewaart je gegevens zolang wij van de dienst gebruikmaken. Verwijderen wij jouw gegevens uit het platform, dan verwerkt Hoeray ze niet langer. Uiterlijk 90 dagen na het einde van onze klantrelatie met Hoeray worden alle medewerkergegevens — inclusief de bezorghistorie — verwijderd of geanonimiseerd.
Jouw rechten. Wil je inzage in je gegevens, wil je ze laten corrigeren of verwijderen, of wil je liever géén attenties ontvangen? Neem dan contact op met [contactpunt HR, bijvoorbeeld hr@organisatie.nl]. Wij regelen je verzoek direct in het platform; je hoeft hiervoor niet zelf contact op te nemen met Hoeray. Ontvangt Hoeray toch rechtstreeks een verzoek van jou, dan stuurt Hoeray dat naar ons door en ondersteunt het de afhandeling.
Bezwaar. Je kunt te allen tijde bezwaar maken tegen het delen van jouw gegevens voor dit doel. Maak je bezwaar, dan zetten wij je op “geen attenties”: je gegevens worden dan niet langer voor dit doel met Hoeray en de bezorgpartners gedeeld.
Meer weten over hoe Hoeray met persoonsgegevens omgaat? Zie de privacyverklaring op hoeray.com/privacy en de verwerkersovereenkomst op hoeray.com/dpa.
Gifts on special occasions — what this means for your personal data
[Organisation name] does not let its employees’ special moments pass unnoticed. On occasions such as birthdays, work anniversaries, joining the company and leaving the company, we send a small gift — for example a card or flowers — to your home address. To send these, we use Hoeray, a service provided by The Circle of 10 B.V. (hoeray.com).
Which data do we share? We share your name, date of birth and home address with Hoeray. Hoeray processes this data solely on our instructions (as a processor under a data processing agreement) and shares your name and address only with its delivery partners — the card printer and the florist — to the extent necessary to deliver the gift to you. Hoeray never uses your data for its own purposes and never sells it.
On what legal basis? We do this on the basis of our legitimate interest as an employer (Art. 6(1)(f) GDPR): showing appreciation and personal attention to our employees on special occasions.
How long is the data kept? Hoeray keeps your data for as long as we use the service. If we delete your data from the platform, Hoeray no longer processes it. No later than 90 days after the end of our customer relationship with Hoeray, all employee data — including the delivery history — is deleted or anonymised.
Your rights. Would you like to access, correct or delete your data, or would you prefer not to receive any gifts? Please contact [HR contact point, e.g. hr@organisation.com]. We will handle your request directly in the platform; you do not need to contact Hoeray yourself. If Hoeray nevertheless receives a request directly from you, Hoeray will forward it to us and support the handling of it.
Objection. You may object at any time to the sharing of your data for this purpose. If you object, we will set you to “no gifts”: your data will then no longer be shared with Hoeray and its delivery partners for this purpose.
Want to know more about how Hoeray handles personal data? See the privacy statement at hoeray.com/privacy and the data processing agreement at hoeray.com/dpa.
Version 4 September 2026 — replaces version 1.0 (March 2026)