All topics
On this page
For the readings of your gateways and the data of your customers, ModbusCloud is the processor and you are the controller. If you act as a processor for your customer, ModbusCloud is a sub-processor. For the data of your own account, ModbusCloud is the controller itself. The privacy statement applies to that data.
Agreement when you create your organisation
Under article 10.3 of the terms and conditions, the data processing agreement belongs to your licence and forms part of the agreement with ModbusCloud.
When you create your organisation, you select the checkbox to agree to the terms and conditions, the privacy statement and the data processing agreement. Without that checkbox, Create organization does not work. If you create your account with an email address and password, the same checkbox is already on Create account.
With the checkbox you also confirm that you may agree on behalf of your organisation. When the organisation is created, the portal records who agreed, when, which version and from which IP address.
The full data processing agreement is on the website in Dutch, English and German. The version number and the date of the last change are at the top of the agreement. To learn how to create an organisation, read Sign in and create your organisation.
What the agreement sets out
The data processing agreement follows article 28 of the GDPR and has five annexes. The table shows the main arrangements, with the article or annex where each one appears.
| Subject | What the agreement sets out | Article or annex |
|---|---|---|
| Instructions | ModbusCloud processes only what you instruct. What you set in the portal, such as roles and API keys, also counts as an instruction | 4 |
| Security | Encryption of traffic and stored data, data separated per organisation in the database and role-based access | Annex 2 |
| Backups | Daily backups and restore to an earlier point in time. After a serious failure, the target is at most 24 hours of data loss and full recovery within 72 hours | Annex 2.3 |
| Data breach | ModbusCloud notifies you of a data breach within 48 hours of discovering it. You report to the Dutch Data Protection Authority and to data subjects, with help from ModbusCloud | 10 |
| Requests from data subjects | If someone asks ModbusCloud for access to or deletion of their data, ModbusCloud forwards the request to you | 8 |
| What you do not enter | No special categories or criminal-law personal data, such as health data, not even in names of Modbus devices, notes or reports | Annex 1.7 |
| Audit | Once per calendar year, announced at least 30 days in advance. You bear the costs, unless ModbusCloud fails materially | 11 |
| End of the licence | Within 30 days of the end, you choose whether ModbusCloud returns or deletes the personal data. If you do not choose, deletion follows after a reminder | 13 |
For how long ModbusCloud keeps readings and alerts, and how to take your data with you, read Retention periods and exporting your data.
Sub-processors
ModbusCloud has part of the processing done by sub-processors. The table shows which sub-processors are listed in annex 3 and what ModbusCloud uses them for.
| Sub-processor | Purpose |
|---|---|
| Vercel | Hosting of the portal and the website |
| Supabase | Database, sign-in and file storage |
| Railway | Backend, such as processing readings and checking alert rules |
| EMQX Cloud | MQTT broker through which the gateway sends its readings |
| Stripe | Payments in the webshop |
| Signing in with a Google account and website statistics | |
| Microsoft | Signing in with a Microsoft account |
| Resend | Sending email, such as alert emails |
| Moneybird | Bookkeeping and invoices |
The safeguard under which data leaves the EEA, such as the EU-US Data Privacy Framework or the standard contractual clauses, is listed per sub-processor in annex 3. To learn where your data is stored, read Where your data is stored and who can access it.
ModbusCloud imposes the same obligations on every sub-processor and remains responsible to you. ModbusCloud announces a new or replacement sub-processor at least 30 days in advance. If you also want that announcement by email, tell the ModbusCloud privacy contact in annex 5.
If you believe a new sub-processor does not comply with the GDPR, object with reasons within 30 days of the announcement. If you and ModbusCloud cannot agree, you may terminate the agreement and the data processing agreement for the part affected by that sub-processor.
Make a signed copy
If you need a signed copy, you complete and sign the agreement yourself. What you fill in is listed at the end of the agreement under Before signing.
Print the agreement
Print the data processing agreement, or paste the text into your own document.
Fill in the parties
Under Parties, enter the name, Chamber of Commerce (KvK) number, address, contact person, email address and phone number of your organisation.
Fill in the contact persons
In annex 5.1, enter your contact person for general questions, for privacy and for data breaches. The same person may fill all three roles.
Name the data protection officer
In annex 5.3, enter your data protection officer. If your organisation has none, note that none has been appointed.
Sign the agreement
Complete the signature block in article 19 with your name, position, place, date and signature.
Send the signed copy
Send the signed copy to the ModbusCloud privacy contact in annex 5.
Updated on 7 October 2026
Still stuck?
Email or call us. Include the serial number of the gateway, so we can take a look straight away.
Go to support






