Wattify

Data Processing Agreement (DPA) of Wattify BV
BE0777.610.990 – Kriephoekstraat 25, 9230 Wetteren, Belgium

This Data Processing Agreement forms an integral part of every agreement between Wattify BV (the “processor”) and the customer using the Wattify platform, such as a charging point owner, CPO, owners’ association, employer or installer (the “data controller”). It governs the processing of personal data by Wattify on behalf of the customer, in accordance with Article 28 of the General Data Protection Regulation (GDPR, Regulation (EU) 2016/679).

Article 1: Definitions

Terms such as “personal data”, “processing”, “data controller”, “data processor”, “data subject”, “sub-processor” and “personal data breach” have the meanings assigned to them by the GDPR. “Main Agreement” means the agreement or quotation on the basis of which Wattify provides its services to the customer, including Wattify’s general terms and conditions.

Article 2: Subject matter and duration

1. Wattify processes personal data solely to the extent necessary to provide the services under the main agreement: the management and control of charging points, the recording and billing of charging sessions, the management of charging cards and users, invoicing and payments, roaming and the associated customer support.
2. This data processing agreement shall remain in force for as long as Wattify processes personal data on behalf of the customer.

Article 3: Nature of the processing, data and data subjects

1. Data subjects: users of the client’s charging points (EV drivers), charging card holders, employees, residents or tenants of the client, and the client’s contact persons.
2. Personal data: identification and contact details (name, email address, telephone number, address), charging card and token identifiers, data relating to charging sessions (time, duration, consumption, location of the charging point), vehicle registration numbers where provided, billing and payment details (such as account number) and user accounts on the platform.
3. Wattify does not process special categories of personal data within the meaning of Article 9 of the GDPR, unless the customer enters such data into the platform themselves.

Article 4: Instructions from the data controller

1. Wattify shall process personal data exclusively on the basis of written instructions from the customer. The main agreement, this data processing agreement and the customer’s use of the platform’s functions shall be deemed to constitute such instructions.
2. Wattify shall immediately inform the customer if, in its opinion, an instruction contravenes the GDPR or other data protection legislation.
3. If Wattify is obliged to process data under EU law or Belgian law, it shall notify the customer in advance, unless such legislation prohibits this.

Article 5: Confidentiality

Wattify shall ensure that persons authorised to process personal data have undertaken to maintain confidentiality or are bound by an appropriate legal obligation of confidentiality, and that they are granted access only to the extent necessary for the performance of their duties.

Article 6: Security

Wattify shall take appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as referred to in Article 32 of the GDPR. These include, amongst other things: encrypted connections, role-based access control, segregation of data by customer, logging, regular backups and the timely installation of security updates. Wattify may amend these measures, provided that the level of security is not reduced.

Article 7: Sub-processors

1. The customer grants Wattify general authorisation to engage sub-processors, such as hosting providers, payment service providers, roaming platforms and suppliers of email and communication services.
2. Upon request, Wattify shall inform the customer of the sub-processors it engages and shall notify the customer in advance of any proposed changes, so that the customer may raise a reasoned objection to them.
3. Wattify shall impose on each sub-processor, in writing, at least the same data protection obligations as those set out in this data processing agreement, and shall remain liable to the customer for compliance with them.

Article 8: Transfers outside the EEA

In principle, Wattify processes personal data within the European Economic Area. Transfers to a country outside the EEA shall only take place if appropriate safeguards exist within the meaning of Chapter V of the GDPR, such as an adequacy decision or the European Commission’s standard contractual clauses.

Article 9: Rights of data subjects

Wattify shall, taking into account the nature of the processing, provide the customer with reasonable assistance in responding to requests from data subjects exercising their rights (access, rectification, erasure, restriction, portability and objection). If Wattify receives such a request directly, it shall forward it to the customer without delay.

Article 10: Personal data breaches

1. Wattify shall notify the customer of any personal data breach without undue delay, and where possible within 48 hours of becoming aware of it.
2. The notification shall include, to the extent known, the nature of the breach, the categories of data and the estimated number of data subjects affected, the likely consequences and the measures taken or proposed.
3. Wattify shall provide the customer with reasonable assistance in fulfilling their obligation to notify the Data Protection Authority and the data subjects.

Article 11: Assistance and audits

1. Wattify shall provide the customer with reasonable assistance in carrying out a data protection impact assessment and in prior consultation with the supervisory authority, insofar as these relate to the processing carried out by Wattify.
2. Wattify shall make available to the customer all information necessary to demonstrate compliance with this data processing agreement. The Customer may, subject to reasonable prior written notice and no more than once a year, have an audit carried out by an independent expert who is bound by a duty of confidentiality. The costs of the audit shall be borne by the Customer.

Article 12: Termination of processing

Upon termination of the main agreement, Wattify shall, at the customer’s discretion, either delete the personal data or return it in a commonly used format, and shall delete any existing copies, unless retention is required by EU law or Belgian law (such as the accounting and tax retention periods for invoices and charging sessions underlying invoices).

Article 13: Liability

The liability of the parties under this data processing agreement is governed by the main agreement and Wattify’s general terms and conditions, without prejudice to Article 82 of the GDPR.

Article 14: Order of precedence, applicable law and disputes

1. In the event of any conflict between this Data Processing Agreement and the main agreement, this Data Processing Agreement shall prevail in respect of the processing of personal data.
2. This data processing agreement is governed by Belgian law. Disputes shall be submitted to the court with territorial jurisdiction over Wattify’s registered office.

Contact

Any questions regarding this Data Processing Agreement or the processing of personal data may be addressed to our Data Protection Officer: dpo@wattify.be.

Version 1.0 – 6 October 2026