Data Processing Agreement for providers
Version 2026-10-08-v1 · Effective 8 October 2026
This agreement is part of the Provider Terms and applies once you accept them. It covers how GoAhead processes personal data you are responsible for as a provider, mainly your employees' data in GoAhead Teams.
1. Roles
You (the provider) are the controller and GoAhead (Nova Viae) is the processor for: employee data in GoAhead Teams (profiles, roles, schedules, tasks, training, preboarding, chats and files) and documents with personal data that you upload.
For customer data in orders and bookings, GoAhead and you are each an independent controller of your own processing. This agreement does not cover that.
2. Subject and duration
GoAhead processes the data only to provide GoAhead Teams and Provider Admin, for as long as the Provider Terms apply.
Data subjects: your employees, applicants and contractors. Data: name, contact details, role, working hours, tasks, training results, messages and files you or your team upload. Do not upload special category data (such as health data) or the Dutch citizen service number (BSN) unless the law allows it and it is strictly necessary.
3. GoAhead's obligations
GoAhead processes the data only on your documented instructions, as set out in this agreement and through the settings in the app. This includes transfers outside the EU. If the law requires GoAhead to process the data otherwise, GoAhead tells you in advance, unless the law forbids that.
If GoAhead believes an instruction infringes data protection law, GoAhead tells you immediately.
Everyone at GoAhead with access is bound by confidentiality.
GoAhead applies appropriate security: encryption, role-based access enforced in the database, mandatory two-step verification for administrators and a tamper-proof audit log.
GoAhead helps you with data subject requests (access, correction, deletion), with security and data breaches, and with a data protection impact assessment and prior consultation of the supervisory authority where needed.
4. Sub-processors
You give general authorisation for the sub-processors listed in the Privacy Policy (including Supabase, Vercel, Resend, OpenAI and Anthropic). GoAhead announces a new sub-processor at least 30 days ahead; you may object and, if needed, end the service.
GoAhead binds sub-processors in writing to the same obligations and remains fully liable to you for their work. Transfers outside the EU rely only on the EU-US Data Privacy Framework or standard contractual clauses.
5. Data breaches
GoAhead reports a personal data breach without undue delay and at the latest within 48 hours of discovery, with the information you need to notify the authority and the people affected.
6. End of processing
When the relationship ends you can export the data through the closure process. GoAhead then deletes it within 90 days, unless the law requires retention.
7. Audits
GoAhead gives you the information needed to demonstrate compliance. An audit or inspection by you or an independent expert is possible by arrangement, at most once a year and at your cost. The once-a-year limit does not apply after a data breach or at the request of a supervisory authority.