Last updated: September 2026

Data Processing Agreement

What we do with personal data that passes through our hands on your instructions, and which arrangements apply.

1. Parties and relationship

This data processing agreement applies between you as client ("Controller") and Circularmonster B.V., registered with the Dutch Chamber of Commerce under number 89759192 and trading as XITAD ("Processor").

It forms part of the agreement between the parties and of XITAD’s terms and conditions. Where it differs from those on the processing of personal data, this agreement prevails.

2. Subject matter, nature and duration

XITAD processes personal data solely to perform the assignment: assessing, valuing, collecting, erasing, processing and trading IT equipment, and the administration that goes with it.

The processing lasts as long as the assignment, subject to the retention periods in article 10.

3. Which data, and whose

It concerns limited data, usually not the purpose of the processing but a by-product of what is supplied:

  • Contact details: name, business email address, telephone number and role of your staff involved in the assignment.
  • Data in inventory lists: exports from an asset management system often contain user names, departments, locations or asset assignments. We ask you to remove these; whatever still reaches us is processed under this agreement.
  • Data in files and photos: hidden data such as location and author name is removed automatically on receipt.
  • Data subjects: your staff, and the individuals to whom the equipment was assigned in your records.

4. Instructions

XITAD processes the data solely on your documented instructions, including the instructions implicit in the assignment and in the use of the platform. XITAD does not use the data for its own purposes and does not sell it.

If XITAD considers an instruction to be contrary to the law, it says so before carrying it out, unless the law prohibits this.

5. Confidentiality

Everyone at XITAD with access to the data is bound to confidentiality. Access is role-based and limited to those who need the data for their work. Processing and logistics partners additionally sign a confidentiality undertaking beforehand; without that signature they see neither name nor address.

6. Security

XITAD takes appropriate technical and organisational measures, including at least:

  • Encrypted transport to and from the platform, and encrypted storage.
  • Role-based access, with two-factor authentication available for every account.
  • Automatic removal of hidden data from uploaded files and photos.
  • Shielding of your identity from bidding parties: they see the town, not the name or address, until a bid has been accepted.

7. Sub-processors

You give general authorisation for engaging sub-processors. Which ones and for what purpose is set out in the privacy policy; that overview is the current list.

One sub-processor is located outside the European Economic Area: the contents of a supplied hardware list are sent to OpenAI in the United States to extract brand, model and quantities. That transfer relies on the European Commission’s standard contractual clauses.

If XITAD adds or replaces a sub-processor, it notifies you in advance and you may object, with reasons, within fourteen days. If the parties cannot reach agreement, you may terminate the assignment for the part to which the objection relates.

8. Assistance

XITAD assists you within a reasonable period in responding to requests from data subjects for access, rectification, erasure or restriction, and with a data protection impact assessment or prior consultation. If a data subject approaches XITAD directly, XITAD refers them to you and does not handle the request itself.

9. Personal data breaches

If XITAD discovers a personal data breach, it notifies you without undue delay and in any event within forty-eight hours of discovery, with what is known at that time: the nature of the breach, the data and data subjects concerned as far as known, the likely consequences and the measures taken. Notification to the supervisory authority and to data subjects is made by you; XITAD supplies what you need for it.

10. Retention, return and deletion

XITAD does not keep data longer than necessary. A residual value scan that does not lead to a project expires together with the supplied file after thirty days. Invoices, certificates of destruction and the related records are kept for seven years under tax retention rules.

On completion of the assignment XITAD deletes the personal data or returns it at your request, except for what it must retain under a legal obligation. That remainder stays subject to this agreement for as long as it is retained.

11. Audit

You may verify compliance with these arrangements once a year, and in addition after a personal data breach. This may be done by an independent expert appointed by you and bound to confidentiality. You announce an audit at least thirty days in advance and bear the costs, unless the audit shows that XITAD falls short.

12. Governing law

Dutch law applies to this data processing agreement. Disputes are submitted to the competent court in the district of Amsterdam.

Would you like to receive this agreement signed, or do you have your own model you wish to use? Contact us at privacy@xitad.com.