Legal · Processing
Data Processing Agreement
This agreement governs personal data FutureContent processes on a business customer's documented instructions.
Last updated 14 August 2026
1. Parties and scope
This Data Processing Agreement forms part of the Terms of Service between the customer and Future CX, trading as FutureContent and registered with the Dutch Chamber of Commerce under number 86444042. It applies when the customer is a controller and FutureContent processes personal data on its behalf to provide the service.
2. Processing details
FutureContent processes submitted public-page content, URLs, Workspace configuration, account identity data, and related service data only to provide, secure, support, and maintain the service. Data subjects may include the customer's Users and people mentioned on a submitted public page. Processing lasts for the customer's use of the service and the applicable documented retention period.
3. Customer instructions and responsibilities
The Terms, product controls, and lawful requests from the customer are documented instructions. The customer is responsible for the lawfulness of those instructions, the submitted data, and notices to data subjects. FutureContent will notify the customer if an instruction appears to infringe applicable data-protection law, unless the law prevents that notice.
4. Confidentiality and security
People authorized to process customer personal data are bound by confidentiality. FutureContent uses proportionate technical and organizational measures, including encrypted transport, access control, tenant isolation, least-privilege service boundaries, and operational monitoring. No online service can eliminate every risk.
5. Subprocessors and transfers
The customer gives general authorization for the providers on our Subprocessors page. FutureContent remains responsible for requiring appropriate data-protection terms from subprocessors. We will publish material additions or replacements before they take effect where reasonably practicable. The customer may object on reasonable data-protection grounds by contacting us.
Where a restricted international transfer requires a safeguard, FutureContent or the relevant provider uses an applicable adequacy decision, Standard Contractual Clauses, or another lawful mechanism.
6. Assistance and incidents
Taking account of the processing and information available to us, we will reasonably assist with data-subject requests, security obligations, impact assessments, regulatory consultations, and information needed to demonstrate compliance. We will notify the customer without undue delay after becoming aware of a personal-data breach affecting customer data and provide available information needed for the customer's response.
7. Return, deletion, and recovery copies
Customer controls and documented retention rules govern deletion and export. On termination, FutureContent deletes or returns customer personal data unless law requires retention. As verified on 11 August 2026, FutureContent's Supabase projects use the Free plan and expose no scheduled-backup or point-in-time recovery restore points. Historic database recovery is available only when an explicitly maintained operator-owned logical dump exists. Any future provider physical backup or point-in-time recovery copy restores the database as a whole and cannot be selectively edited through the provider's supported restore controls. If an older copy is restored, normal service remains unavailable while current retention and deletion controls run again.
8. Audit information and contact
On reasonable written request, FutureContent will provide information necessary to demonstrate compliance and permit a proportionate audit where that information is insufficient. Audits must protect other customers, security, and confidential information and avoid unnecessary disruption.
Questions and requests can be sent to m.van.deel@futurecx.nl. Also see our Privacy Policy and Terms of Service.