Data Processing Agreement

Effective Date: August 8, 2026
Last Updated: August 8, 2026

1. Purpose and Scope

This Data Processing Agreement ("DPA") governs the processing of Personal Data by Van Lierde & Co in connection with the Customer's use of Asset Navigator where Van Lierde & Co processes Personal Data on behalf of the Customer.

Asset Navigator is a Software-as-a-Service platform that helps developers, project managers, business analysts, and other users understand relationships and dependencies between business and technical assets.

These assets may include:

  • Applications
  • Reports and dashboards
  • Datasets
  • Data lakes
  • Databases
  • APIs
  • Data flows
  • Integrations
  • Components
  • Business processes
  • Technical systems
  • Other related assets and metadata

This DPA applies where the Customer uses Asset Navigator to process Personal Data for which the Customer determines the purposes and means of processing and Van Lierde & Co acts as a data processor.

2. Acceptance and Applicability

This DPA is incorporated into and forms part of the Asset Navigator Terms of Use.

Where a Customer uses Asset Navigator on behalf of an organization and accepts the Terms of Use on behalf of that organization, the person accepting the Terms represents that they have the authority to bind that organization.

This DPA becomes effective when the Customer accepts the Asset Navigator Terms of Use and uses Asset Navigator in circumstances where Van Lierde & Co processes Personal Data on the Customer's behalf.

A separate physical signature is not required for this DPA unless the Customer and Van Lierde & Co expressly agree otherwise in writing.

Enterprise customers may request a separately executed copy of this DPA where required by their procurement, legal, regulatory, or internal compliance requirements.

3. Definitions

For the purposes of this DPA, the following terms apply:

"Applicable Data Protection Law" means all applicable laws and regulations relating to the protection of Personal Data, including, where applicable, the Swiss Federal Act on Data Protection ("FADP"), the EU General Data Protection Regulation 2016/679 ("GDPR"), and applicable national data-protection legislation.

"Customer Data" means information submitted, uploaded, transmitted, stored, or otherwise made available by or on behalf of the Customer through Asset Navigator.

"Data Subject" means an identified or identifiable natural person to whom Personal Data relates.

"Personal Data" means personal data or personal information as defined by Applicable Data Protection Law.

"Process", "Processing", "Processes" and "Processed" have the meanings given to those terms under Applicable Data Protection Law.

"Controller" means the Customer where the Customer determines the purposes and means of Processing Personal Data.

"Processor" means Van Lierde & Co when processing Personal Data on behalf of the Customer.

"Subprocessor" means a third party appointed by Van Lierde & Co to process Personal Data on behalf of the Customer.

"Security Incident" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to Customer Personal Data.

4. Roles of the Parties

The Customer is the Controller of Customer Personal Data processed through Asset Navigator, except where the Customer itself acts as a processor on behalf of another organization.

Van Lierde & Co acts as Processor when processing Customer Personal Data on behalf of the Customer.

Where the Customer acts as a processor for another organization, the Customer represents that it has the necessary authority to instruct Van Lierde & Co to process the relevant Personal Data.

Nothing in this DPA prevents Van Lierde & Co from processing Personal Data as an independent Controller for its own legitimate business purposes, such as account administration, billing, security, analytics, legal compliance, and other purposes described in the Asset Navigator Privacy Policy.

5. Customer Instructions

The Customer instructs Van Lierde & Co to process Customer Personal Data as reasonably necessary to provide Asset Navigator and related services.

These instructions include:

  • Providing access to Asset Navigator
  • Storing Customer Data
  • Creating and managing assets
  • Creating and managing relationships between assets
  • Providing visualization and analysis functionality
  • Processing information submitted through the Asset Navigator API
  • Providing search and retrieval functionality
  • Providing technical and customer support
  • Maintaining backups
  • Maintaining service availability
  • Protecting the security of the Service
  • Troubleshooting and maintaining the Service
  • Performing other processing reasonably necessary to provide the contracted services

Van Lierde & Co may process Personal Data where necessary to comply with Applicable Data Protection Law.

If Van Lierde & Co reasonably believes that an instruction from the Customer violates Applicable Data Protection Law, Van Lierde & Co may inform the Customer and, where legally required, suspend the relevant processing until the issue is resolved.

6. Customer Responsibilities

The Customer is responsible for ensuring that its use of Asset Navigator complies with Applicable Data Protection Law.

The Customer is responsible for:

  • Determining the lawful basis for processing Personal Data
  • Providing appropriate privacy notices to Data Subjects
  • Ensuring that Personal Data submitted to Asset Navigator may lawfully be processed
  • Ensuring that its instructions to Van Lierde & Co are lawful
  • Configuring user access and permissions appropriately
  • Protecting account credentials
  • Using the Asset Navigator API appropriately
  • Complying with applicable data-retention requirements
  • Responding to Data Subject requests where the Customer is the Controller

Customers should avoid submitting unnecessary sensitive or special category Personal Data to Asset Navigator.

7. Categories of Data Subjects

Depending on how the Customer uses Asset Navigator, Customer Personal Data may relate to:

  • Employees
  • Contractors
  • Consultants
  • Customer representatives
  • Project managers
  • Developers
  • Business analysts
  • Application owners
  • Data owners
  • System owners
  • Business users
  • Suppliers and service providers
  • Customers of the Customer
  • Other individuals whose information is included in Customer Data

8. Categories of Personal Data

Depending on the Customer's use of Asset Navigator, Customer Personal Data may include:

  • Names
  • Business email addresses
  • Business contact information
  • Job titles and roles
  • Company or organization information
  • User identifiers
  • Application ownership information
  • Project ownership information
  • Asset ownership information
  • Comments and descriptions
  • Technical identifiers
  • Metadata
  • Audit and activity information
  • API-related information
  • Access and authorization information
  • Other Personal Data submitted by the Customer

9. Special Categories of Personal Data

Asset Navigator is not designed to require the processing of special categories of Personal Data.

Customers should not intentionally submit special categories of Personal Data unless such processing is necessary, lawful, and appropriately protected.

If a Customer requires Asset Navigator to process special categories of Personal Data on a systematic or substantial basis, the Customer should contact Van Lierde & Co before doing so so that appropriate technical, contractual, and organizational safeguards can be considered.

10. Processing Operations

Depending on the functionality used, Van Lierde & Co may perform the following processing operations:

  • Collection
  • Recording
  • Organization
  • Structuring
  • Storage
  • Retrieval
  • Consultation
  • Use
  • Transmission
  • Visualization
  • Modification
  • Analysis necessary to provide the Service
  • Deletion
  • Other processing necessary to provide Asset Navigator

Van Lierde & Co does not sell Customer Personal Data.

11. Duration of Processing

Van Lierde & Co will process Customer Personal Data for the duration of the Customer's use of Asset Navigator and for any limited period reasonably required after termination for deletion, backup expiration, legal retention, or other purposes permitted under this DPA.

Following termination of the Customer's use of Asset Navigator, Van Lierde & Co aims to delete or anonymize Customer Personal Data within three months.

This period may be extended where:

  • Applicable law requires continued retention
  • Retention is necessary to establish, exercise, or defend legal claims
  • Data remains temporarily in backups
  • Technical limitations make immediate deletion impracticable

Backup copies containing Customer Personal Data are subject to access restrictions and are deleted or overwritten according to the applicable backup lifecycle.

12. Confidentiality

Van Lierde & Co will ensure that persons authorized to process Customer Personal Data:

  • Are subject to appropriate confidentiality obligations
  • Receive appropriate instructions concerning data protection
  • Only access Customer Personal Data to the extent necessary for their role

Van Lierde & Co will not disclose Customer Personal Data to third parties except where necessary to provide the Service, where authorized under this DPA, where required by law, or where otherwise permitted under the applicable agreement.

13. Security Measures

Van Lierde & Co implements reasonable technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or unauthorized access.

Depending on the nature of the processing, these measures may include:

  • Access controls
  • Authentication controls
  • Role-based access
  • Least-privilege principles
  • Restricted administrative access
  • Encryption in transit
  • Encryption at rest where applicable
  • Production access restrictions
  • Logging and monitoring
  • Security updates
  • Vulnerability management
  • Backup procedures
  • Disaster recovery procedures
  • Incident-response procedures
  • Physical security controls at hosting facilities
  • Confidentiality obligations
  • Periodic review of security measures

No internet-based service can guarantee absolute security. Van Lierde & Co will nevertheless maintain security measures appropriate to the risks associated with the processing.

14. Hosting and Infrastructure

Asset Navigator production systems are hosted on dedicated infrastructure located at a server facility in Belgium, European Economic Area .

The hosting provider and relevant infrastructure provider are identified in the Asset Navigator Subprocessor List.

The hosting provider may provide infrastructure and data-centre services including physical security, power, cooling, network connectivity, and hardware-related services.

Van Lierde & Co remains responsible for its obligations under this DPA notwithstanding the use of third-party infrastructure.

15. Subprocessors

The Customer authorizes Van Lierde & Co to engage Subprocessors as reasonably necessary to provide Asset Navigator.

The current list of Subprocessors is available at:

Asset Navigator Subprocessor List

Van Lierde & Co may add, remove, or replace Subprocessors from time to time where reasonably necessary to operate, maintain, secure, or improve the Service.

Where required by Applicable Data Protection Law, Van Lierde & Co will provide reasonable advance notice of material changes to its Subprocessors.

Van Lierde & Co will impose appropriate data-protection obligations on Subprocessors that process Customer Personal Data on its behalf.

Van Lierde & Co remains responsible for its Subprocessors to the extent required by Applicable Data Protection Law.

16. Current Subprocessor Categories

The Asset Navigator Subprocessor List may include providers supporting the following services:

  • Hosting and server infrastructure
  • Payment processing
  • Analytics
  • Email delivery
  • Security and monitoring
  • Other infrastructure or service providers required to operate Asset Navigator

The definitive list of current Subprocessors, including their names, purposes, and relevant processing locations, is maintained separately in the Asset Navigator Subprocessor List.

Providers used solely by Van Lierde & Co for its own administrative, accounting, tax, legal, or other business purposes are not necessarily Subprocessors under this DPA where they do not process Customer Personal Data on behalf of the Customer.

17. Assistance with Data Subject Rights

Taking into account the nature of the processing, Van Lierde & Co will provide reasonable assistance to the Customer in responding to requests from Data Subjects exercising their rights under Applicable Data Protection Law.

Where technically available, this may include assistance with:

  • Access to Customer Personal Data
  • Correction of Customer Personal Data
  • Deletion of Customer Personal Data
  • Restriction of processing
  • Export of Customer Personal Data
  • Other reasonable technical requests

The Customer remains responsible for responding to Data Subject requests and determining whether a request should be fulfilled.

If Van Lierde & Co receives a Data Subject request relating to Customer Personal Data, Van Lierde & Co may refer the Data Subject to the Customer where appropriate.

18. Assistance with Security and Compliance

Taking into account the nature of the processing and the information available to Van Lierde & Co, Van Lierde & Co will provide reasonable assistance to the Customer in relation to:

  • Security obligations
  • Personal Data breach notifications
  • Data protection impact assessments where reasonably necessary
  • Consultations with supervisory authorities where required

Requests requiring substantial additional resources may be subject to reasonable charges where permitted under the applicable agreement.

19. Personal Data Breaches

Van Lierde & Co will notify the Customer without undue delay after becoming aware of a confirmed Personal Data breach affecting Customer Personal Data.

Where reasonably available, the notification may include:

  • The nature of the breach
  • The categories of Personal Data affected
  • The approximate number of affected Data Subjects, where known
  • The likely consequences
  • The measures taken or proposed to address the incident
  • Contact information for the person or team handling the incident

Van Lierde & Co will take reasonable steps to contain, investigate, and remediate the incident.

The Customer remains responsible for determining whether notification to a supervisory authority or Data Subjects is required.

20. International Data Transfers

Van Lierde & Co is established in Switzerland.

Asset Navigator's primary production hosting is located in Belgium.

Some Subprocessors may process Personal Data outside Switzerland or the European Economic Area.

Where an international transfer requires a legal transfer mechanism, Van Lierde & Co will use an appropriate mechanism under Applicable Data Protection Law.

This may include:

  • An applicable adequacy decision
  • EU Standard Contractual Clauses
  • Swiss-recognized contractual safeguards
  • Appropriate supplementary measures
  • Another legally recognized transfer mechanism

Where the GDPR applies, the Parties intend that the applicable requirements of Chapter V of the GDPR will be satisfied.

Where the Swiss FADP applies, the Parties intend that applicable Swiss requirements relating to international data transfers will be satisfied.

21. Government and Legal Requests

If Van Lierde & Co is legally required to disclose Customer Personal Data to a public authority, Van Lierde & Co will, where legally permitted:

  • Notify the Customer before disclosure
  • Provide information concerning the request
  • Limit disclosure to the information legally required
  • Reasonably cooperate with the Customer's efforts to limit or challenge the disclosure

Van Lierde & Co will not notify the Customer where prohibited from doing so by law.

22. Audits and Compliance Information

Van Lierde & Co will make available information reasonably necessary to demonstrate compliance with its obligations under this DPA.

Where required by Applicable Data Protection Law, the Customer may request an audit of Van Lierde & Co's relevant processing activities.

Before conducting an audit, the Customer must provide reasonable written notice.

Audits must:

  • Be conducted during normal business hours
  • Minimize disruption to Van Lierde & Co's operations
  • Respect confidentiality obligations
  • Not compromise the security of other customers
  • Not provide access to another customer's data
  • Be limited to matters relevant to Customer Personal Data

Where Van Lierde & Co provides relevant audit reports, certifications, security documentation, or questionnaires, the Customer will consider such information before requesting an additional audit.

23. AI-Assisted Functionality

Asset Navigator may introduce AI-assisted functionality in the future.

Potential functionality may include:

  • Identifying potential relationships between assets
  • Suggesting missing information
  • Identifying inconsistencies
  • Recommending classifications
  • Improving asset descriptions
  • Assisting users in understanding asset relationships

Where AI-assisted functionality processes Customer Data, such processing will be limited to providing the relevant Asset Navigator functionality and will remain subject to this DPA and the applicable Customer instructions.

Van Lierde & Co does not currently use Customer Personal Data to train a general-purpose AI model across customers.

If Van Lierde & Co introduces functionality involving the use of Customer Personal Data for model training or another materially different purpose, Van Lierde & Co will obtain the necessary authorization or consent where required and provide appropriate information about the processing.

24. Return and Deletion of Customer Data

Following termination of the Customer's use of Asset Navigator, the Customer may request deletion of Customer Data subject to the applicable Terms of Use and this DPA.

Van Lierde & Co will delete or anonymize Customer Personal Data within a target period of three months following termination, subject to:

  • Legal retention obligations
  • Retention necessary to establish, exercise, or defend legal claims
  • Backup retention procedures
  • Technical limitations applicable to secure deletion

Where technically available, Van Lierde & Co may provide Customer Data in a commonly used electronic format.

25. Data Protection by Design

Van Lierde & Co will take reasonable measures to incorporate data protection and security principles into the design and operation of Asset Navigator.

These measures may include:

  • Access controls
  • Data minimization
  • Role-based permissions
  • Secure development practices
  • Logging
  • Encryption
  • Controlled production access
  • Secure deletion procedures

26. Confidentiality of Customer Data

Customer Data is confidential information of the Customer.

Van Lierde & Co will protect Customer Data using at least reasonable care and will not use or disclose Customer Data except as permitted by the applicable agreement, this DPA, the Customer's documented instructions, or Applicable Data Protection Law.

27. Liability

The liability of each Party in connection with this DPA is subject to the liability limitations and exclusions contained in the applicable Asset Navigator Terms of Use or other applicable agreement, except to the extent that Applicable Data Protection Law does not permit such limitation or exclusion.

Nothing in this DPA limits or excludes liability that cannot legally be limited or excluded.

28. Priority and Conflicts

This DPA forms part of the agreement governing the Customer's use of Asset Navigator.

If there is a conflict between this DPA and another agreement between the Parties concerning the processing of Customer Personal Data, this DPA will prevail to the extent of the conflict.

If Applicable Data Protection Law imposes a higher standard than this DPA, the Parties will comply with the applicable legal requirement.

29. Changes to this DPA

Van Lierde & Co may update this DPA from time to time where reasonably necessary to:

  • Reflect changes in Applicable Data Protection Law
  • Reflect changes to Asset Navigator
  • Introduce new security measures
  • Reflect changes to Subprocessors
  • Reflect changes to processing activities

Where a change materially affects the Customer's rights or obligations, Van Lierde & Co will provide reasonable notice where required.

The updated DPA will be published on the Asset Navigator website with an updated "Last Updated" date.

30. Term

This DPA becomes effective when accepted by the Customer or when the Customer begins using Asset Navigator in circumstances where this DPA applies.

This DPA remains in effect for as long as Van Lierde & Co processes Customer Personal Data on behalf of the Customer.

Obligations relating to confidentiality, security, deletion, liability, and other provisions intended by their nature to survive termination will survive termination of this DPA.

31. Governing Law

This DPA is governed by the governing-law provisions contained in the Asset Navigator Terms of Use, unless the Parties have separately agreed otherwise in writing.

Nothing in this section prevents either Party from exercising rights that cannot lawfully be waived under Applicable Data Protection Law.

32. Contact

For questions concerning this DPA or data processing by Asset Navigator, please contact:

Van Lierde & Co
Asset Navigator
Geneva
Switzerland

Email: legal@assetnavigator.io

Annex 1 – Processing Details

1. Subject Matter

The subject matter of processing is the provision of Asset Navigator as a SaaS platform, including the storage, management, visualization, linking, and processing of Customer Data.

2. Duration

Processing continues for the duration of the Customer's use of Asset Navigator and for any limited period necessary for deletion, backup expiration, legal retention, or other permitted purposes.

The target period for deletion or anonymization following termination is three months, subject to the exceptions described in this DPA.

3. Nature and Purpose

Processing may include:

  • Account and user administration
  • Storage of Customer Data
  • Creation and management of assets
  • Creation and management of relationships between assets
  • Visualization of asset relationships
  • API processing
  • Search and retrieval
  • Technical support
  • Security monitoring
  • Backup and recovery
  • Service maintenance
  • Troubleshooting
  • Other processing necessary to provide Asset Navigator

4. Categories of Data Subjects

The Customer may submit Personal Data relating to:

  • Employees
  • Contractors
  • Consultants
  • Business contacts
  • Project managers
  • Developers
  • Business analysts
  • Application owners
  • Data owners
  • System owners
  • Customers
  • Suppliers
  • Other individuals represented in Customer Data

5. Categories of Personal Data

The Customer may submit:

  • Names
  • Business contact information
  • Email addresses
  • Job titles
  • Roles and responsibilities
  • Organizational information
  • Asset ownership information
  • Project information
  • Technical identifiers
  • Comments and descriptions
  • Metadata
  • API-related information
  • Access-related information
  • Other Personal Data included in Customer Data

6. Special Categories of Personal Data

Asset Navigator is not intended to process special categories of Personal Data.

Annex 2 – Technical and Organizational Security Measures

1. Access Control

Van Lierde & Co maintains controls designed to ensure that access to Customer Personal Data is limited to authorized personnel.

Measures may include:

  • Unique user accounts
  • Authentication controls
  • Role-based access
  • Least-privilege access
  • Restricted administrative access
  • Periodic review of access rights

2. Data Transmission

Customer Personal Data transmitted between users and Asset Navigator is protected using appropriate transport security measures.

3. Data Storage

Customer Data is stored on dedicated production infrastructure hosted at a server facility in Belgium.

Reasonable technical controls are used to protect stored Customer Data against unauthorized access.

4. Production Access

Production infrastructure access is restricted to authorized personnel who require access for operational, maintenance, security, or support purposes.

5. Logging and Monitoring

Appropriate logging and monitoring may be used to:

  • Detect unauthorized access
  • Investigate security incidents
  • Maintain system reliability
  • Troubleshoot technical problems
  • Support security investigations

6. Backup and Recovery

Reasonable backup procedures are maintained to support service continuity and recovery.

Backups may contain Customer Personal Data and are subject to access restrictions and retention procedures.

7. Security Incidents

Van Lierde & Co maintains procedures for identifying, investigating, containing, and responding to security incidents.

8. Personnel Confidentiality

Personnel with authorized access to Customer Personal Data are subject to confidentiality obligations.

9. Secure Deletion

Customer Personal Data is deleted or anonymized following termination according to the applicable deletion and backup procedures.

10. Physical Security

Asset Navigator production infrastructure is hosted in a professional server facility in Belgium.

Physical security measures are maintained by the relevant hosting provider and may include controlled physical access, monitoring, environmental controls, power protection, and other data-centre security measures.

Annex 3 – Subprocessor List

The current list of Asset Navigator Subprocessors is maintained separately and is available at:

Asset Navigator Subprocessor List

The Subprocessor List identifies the relevant provider, purpose of processing, and applicable processing location where available.