Data processing agreement
For customers whose own compliance needs it on paper. It applies to every customer as it stands, so there is nothing to negotiate and nothing to wait for — and if you need it signed, mail us and you get it signed.
Novogara BV, version 1.0, 11 October 2026. Kingsfordweg 151, 1043GR Amsterdam, The Netherlands · Chamber of Commerce 67854060 · VAT NL857199857B01.
Data processing agreement38 KB
1. What this covers
This agreement supplements our terms and conditions and applies to every service we deliver: dedicated servers, colocation and connectivity. Where this agreement and the terms say different things about personal data, this agreement prevails.
2. Who is what
Our services are unmanaged. We deliver a machine, a rack and a network connection; we have no account on your server and no access to what you store on it.
For the personal data you process on your own machine you are the controller. We do not read it, do not copy it and do not process it on your instructions, so for that data we are not acting as your processor in any ordinary sense. To the extent that European data protection law nevertheless treats us as a processor because the data sits on infrastructure we operate, the clauses below apply in full.
For the data you give us as a customer — contact details, company details, invoices, tickets — we are the controller ourselves. What we do with that is described in our privacy statement, not here.
3. Subject matter, nature and duration
Subject matter: the provision of unmanaged infrastructure and connectivity. Nature and purpose: providing the machine and the rack your own systems run on, and carrying your traffic. Nothing beyond that — we are an internet service provider, not a hosting company, and we do not operate anything on your behalf. Duration: as long as the agreement between us runs.
Types of personal data and categories of data subjects are determined entirely by you, because you decide what runs on the machine. We have no knowledge of either.
4. Instructions
We process personal data on your infrastructure only to the extent required to deliver the service, and otherwise only on your documented instructions. An instruction that we consider to be in breach of data protection law will be refused, and we will tell you why.
Where a legal obligation requires us to act — a lawful demand from Dutch authorities, for example — we comply, and we inform you unless the law forbids it.
5. Confidentiality
Everyone at Novogara who could come near customer systems is bound to confidentiality, during and after their engagement. The number of people who can is deliberately small.
6. Security measures
The measures below are the ones we actually take, not a wish list:
- Your machine is yours. We have no credentials on it and we do not install agents on it.
- Our racks stand in carrier-grade Amsterdam facilities with access control, surveillance and fire suppression. Inside them, only our own engineers handle the hardware.
- Administrative access to our own network and management systems is restricted to named engineers, over encrypted connections, from known locations.
- Infrastructure is monitored around the clock, and network equipment is kept current — in a redundant design, so patching does not require taking you offline.
- Abuse and incident reports are handled under a written notice and takedown procedure, by people in the same time zone as the network.
- On termination, storage media that pass back through our hands are wiped before reuse.
You remain responsible for everything above the operating system: patching, encryption at rest, access control, backups and the configuration of your own software. We cannot do any of that for you, because we are not in your machine.
7. Sub-processors
We do not hand your data to anyone for processing. The only third parties with any proximity to it are the operators of the datacenters where our racks stand, who control physical access to the building and never have logical access to your systems.
If that ever changes, you hear about it in advance and you may terminate if you do not accept it.
8. Where the data is
In the Netherlands. We do not transfer personal data outside the European Economic Area, and we do not use infrastructure outside it to deliver these services.
9. Helping you with your obligations
If a data subject contacts us about data on your server, we refer them to you — we cannot answer for data we cannot see. Where you need assistance with a request, an impact assessment or a consultation with a supervisory authority, we provide the information we hold about our own infrastructure.
10. Personal data breaches
If we become aware of a breach affecting the infrastructure under your service, we notify you without undue delay, with what we know, what we are doing about it and who to reach for more. We will not sit on it, and we will not dress it up.
Breaches inside your own operating system or application are yours to detect and to report; we have no visibility there.
11. Deletion and return
When the agreement ends, your data goes with your machine. For dedicated servers, storage is wiped before the hardware is reused. For colocation, you take your own hardware and whatever is on it. We keep no copies, because we never had any.
12. Audits
On request we provide the information needed to demonstrate that we meet these obligations. If that is not enough for your auditor, an inspection can be arranged by appointment, during office hours, at your cost, and without access to other customers' equipment.
13. Liability and changes
The liability provisions of our terms and conditions apply to this agreement as well. We may update it when the law or our setup changes; the current version is always on this page with its number and date, and material changes are announced in advance.
14. Signing it
This agreement applies to every customer as published, without anyone having to sign anything. If your procurement or your auditor needs a signed copy, or a PDF for the file, mail support@novogara.com and you get one.
Related documents
Terms and conditions · Acceptable use policy · Privacy statement · Uptime commitment