Version July 2026. English translation for convenience; the Dutch version prevails.

General Terms and Conditions stipt B.V.

English translation for convenience. In the event of any conflicting meaning, the Dutch version prevails.

1. Definitions

1.1 In these Terms and Conditions:

  • Customer: the legal entity or business that has entered into an Agreement with stipt for the Services;
  • Services: the Core Service and any Additional Services;
  • Core Service: making the Software available via the cloud as configured for the Customer;
  • Additional Services: implementation, training, consultancy, custom work or other activities described in the offer;
  • Agreement: the entirety of the offer, these Terms and Conditions, the Data Processing Agreement and any written supplements;
  • Software: the SaaS platform offered by stipt under the name "stipt", including the mobile and web applications and the AI functionality ("dot");
  • AI functionality: components of the Software that generate, classify, summarize or answer content with the aid of artificial intelligence;
  • Data Processing Agreement: the annex to these Terms and Conditions concerning the processing of personal data (Annex 1);
  • stipt: stipt B.V., with its registered office at Gedempte Oude Gracht 101 C, 2011GN Haarlem, Chamber of Commerce (KvK) 42115688, VAT [BTW];
  • Terms and Conditions: the most recent version of these general terms and conditions.

2. Applicability

2.1 These Terms and Conditions apply to all offers made by stipt and to all agreements between stipt and the Customer.

2.2 If these Terms and Conditions have been provided to the Customer in a language other than Dutch, the Dutch version prevails in the event of any difference in meaning.

2.3 In the event of a conflict between these Terms and Conditions and the offer or any other part of the Agreement, the offer or that other part prevails. The Data Processing Agreement prevails where the processing of personal data is concerned.

2.4 General terms and conditions of the Customer, including industry terms and conditions, do not apply and are expressly rejected.

3. Offer and formation

3.1 All offers made by stipt are without obligation and valid for 30 days, unless stated otherwise. The Agreement is formed upon written acceptance of the offer by the Customer (signature, including digital signature, or confirmation by email), or when stipt commences performance.

3.2 Offers are based on the information provided by the Customer. The Customer warrants that this information is accurate and complete.

4. The Services

4.1 For the duration of the Agreement, stipt grants the Customer a non-exclusive, non-transferable right to use the Software for the number of users and the modules set out in the offer.

4.2 The Customer may use the Services solely for its own business operations. Access is provided via personal accounts; accounts may not be shared. The Customer is responsible for keeping login credentials confidential and for all use that takes place via its accounts.

4.3 The Customer is responsible for the equipment and internet access required to use the Software.

4.4 stipt uses reasonable efforts to keep the Software available and functioning properly, but does not guarantee uninterrupted availability. Where reasonably possible, stipt carries out scheduled maintenance outside office hours.

4.5 stipt provides updates and improvements to the Software when it deems this necessary. Updates are free of charge. stipt may change functionality, provided that the core functionality of the modules purchased is preserved.

4.6 stipt provides support during office hours for the use of the Software.

4.7 stipt is not responsible for the operation of integrations with third-party software or services used by the Customer, to the extent that the malfunction lies outside stipt's sphere of influence.

5. AI functionality

5.1 The Software includes AI functionality that can, among other things, classify and summarize messages, draft responses and, if enabled by the Customer, respond automatically to the Customer's end customers.

5.2 AI-generated output is a tool, not advice. Output may contain inaccuracies. The Customer decides which AI functionality is enabled and with which settings, and remains responsible for the communication with its end customers conducted with the aid of the Software.

5.3 Where the Software communicates with the Customer's end customers on an automated basis, stipt makes clear in the communication that automated (AI) handling is involved, in accordance with the EU AI Act.

5.4 stipt does not use the content of customer data to train generic AI models. Processing by AI sub-processors is governed by the Data Processing Agreement.

6. Prices and payment

6.1 The fee for the Services is stated in the offer. Amounts are exclusive of VAT.

6.2 stipt invoices the license fee monthly or annually in advance, as specified in the offer. stipt invoices Additional Services upon formation of the Agreement or upon completion.

6.3 The payment term is 14 days from the invoice date. In the event of late payment, the Customer owes the statutory commercial interest without notice of default being required. In the event of non-payment, stipt may suspend the Services after the Customer has been given a reminder and a reasonable period to perform.

6.4 Extrajudicial collection costs amount to 15% of the outstanding claim, with a minimum of EUR 250.

6.5 stipt may adjust prices once per calendar year in line with the CBS Consumer Price Index, plus a surcharge of no more than 5%. Price changes take effect as of the next renewal date and are announced at least two months in advance.

7. Term and termination

7.1 The Agreement has the term set out in the offer. In the absence of any agreement to the contrary, the term is 12 months from technical delivery.

7.2 Either party may terminate the Agreement in writing effective at the end of the current contract period, subject to a notice period of 1 month. Without notice of termination, the Agreement is tacitly renewed each time for 12 months, or for the period specified in the offer.

7.3 Either party may terminate the Agreement in writing with immediate effect if: a) the other party attributably fails to perform a material obligation and that failure has not been remedied within 14 days after written notice of default; b) the other party has been declared bankrupt, has applied for or been granted a suspension of payments, is dissolved or ceases its activities; c) a situation of force majeure persists for more than 30 days.

7.4 Upon termination, on any ground, all claims of stipt against the Customer become immediately due and payable. Fees already paid are not refunded, except for license fees paid in advance for the period after a termination by the Customer pursuant to article 7.3.

7.5 After the end of the Agreement, stipt enables the Customer for a period of 30 days to export its own data in a common, machine-readable format. Thereafter, stipt deletes the Customer's data in accordance with the Data Processing Agreement.

8. Customer data

8.1 All data entered into the Software by the Customer or its end customers remains the property of the Customer. stipt only acquires the right to process this data to the extent necessary for the performance of the Agreement.

8.2 stipt ensures periodic backups of the Customer's data and appropriate technical and organizational security measures, as further described in the Data Processing Agreement.

8.3 stipt may collect and use aggregated and anonymized usage data about the use of the Software for the improvement and optimization of the Software. This data cannot be traced back to the Customer or to natural persons.

9. Confidentiality

9.1 The parties treat all information and materials that they receive from each other or to which they gain access in the context of the Agreement as confidential, and do not make these available to third parties without the prior written consent of the other party. This obligation does not apply to information that was already public or that becomes public through no fault of the receiving party. This provision remains in force after the end of the Agreement.

10. Personal data

10.1 To the extent that stipt processes personal data on behalf of the Customer in the performance of the Agreement, stipt is the processor and the Customer is the controller within the meaning of the GDPR. The Data Processing Agreement (Annex 1) applies to that processing and forms an integral part of the Agreement.

11. Liability

11.1 stipt's liability for damage suffered by the Customer in connection with the Agreement is limited, per event (a series of related events being deemed one event), to direct damage and to the amount received by stipt from the Customer under the Agreement in the 6 months preceding the event causing the damage, with a maximum of EUR 25,000 per calendar year.

11.2 stipt is not liable for indirect damage, including consequential damage, loss of profit, missed savings, damage due to business interruption or loss of data to the extent that the Customer could reasonably have exported or backed up that data itself.

11.3 The limitations in this article do not apply to the extent that the damage results from intent or deliberate recklessness on the part of stipt or its executives, and do not apply to the extent that liability cannot be limited under mandatory law.

11.4 stipt indemnifies the Customer against third-party claims alleging that the Software infringes their intellectual property rights, up to a maximum of EUR 20,000 per claim, provided that the Customer informs stipt without delay and leaves the handling of the claim to stipt.

11.5 Any claim of the Customer against stipt lapses 12 months after the Customer became aware, or could have become aware, of its existence, unless legal proceedings have been initiated within that period.

12. Force majeure

12.1 Neither party is obliged to perform an obligation if it is prevented from doing so by force majeure within the meaning of article 6:75 of the Dutch Civil Code. Force majeure includes in any event: war, civil unrest, government measures, strikes, power or internet outages outside the sphere of influence of the party concerned, and non-attributable failures at suppliers.

12.2 A security incident or cyberattack only qualifies as force majeure to the extent that stipt had taken the appropriate security measures required under the Data Processing Agreement and the GDPR and the incident nevertheless could not have been prevented.

12.3 The party affected by force majeure notifies the other party in writing as soon as possible. Obligations are suspended for the duration of the force majeure. If the force majeure lasts longer than 30 days, either party may terminate the Agreement in writing with immediate effect, without any obligation to pay damages.

13. Intellectual property

13.1 All intellectual property rights in the Software, the Services and everything that stipt makes available under the Agreement are vested in stipt or its licensors. The Customer only acquires the right of use set out in article 4.1.

13.2 No transfer applies to the Customer's data: article 8.1 applies.

14. Other provisions

14.1 stipt may amend these Terms and Conditions. stipt announces material amendments at least one month in advance. If an amendment demonstrably and more than insignificantly worsens the Customer's position, the Customer may terminate the Agreement effective as of the date on which the amendment takes effect.

14.2 The Customer may not transfer the Agreement to a third party without the prior written consent of stipt. stipt may transfer the Agreement to a group company or in the context of a transfer of its business; stipt informs the Customer thereof.

14.3 If any provision of these Terms and Conditions proves to be void or voidable, the remaining provisions remain in force. The parties replace the provision in question, in consultation, with a valid provision that approximates the purpose and intent as closely as possible.

14.4 "In writing" includes email.

15. Applicable law and disputes

15.1 These Terms and Conditions and the Agreement are governed by Dutch law.

15.2 Disputes are submitted exclusively to the competent court of the District Court of Noord-Holland (Rechtbank Noord-Holland).

Annex 1: Data Processing Agreement.


Annex 1: Data Processing Agreement

English translation for convenience. In the event of any conflicting meaning, the Dutch version prevails.

Parties

  1. stipt B.V., with its registered office at Gedempte Oude Gracht 101 C, 2011GN Haarlem, Chamber of Commerce (KvK) 42115688, hereinafter: Processor or stipt; and
  2. the Customer as defined in the General Terms and Conditions, hereinafter: Controller.

This Data Processing Agreement forms an integral part of the Agreement and applies to every processing of personal data carried out by stipt on behalf of the Controller.

1. Definitions

Terms such as personal data, processing, data subject, personal data breach, controller and processor have the meaning given to them by the GDPR (Regulation (EU) 2016/679, including the Dutch GDPR Implementation Act (Uitvoeringswet AVG)). Sub-processor: a third party engaged by stipt that processes personal data on behalf of the Controller. EEA: all EU member states plus Liechtenstein, Norway and Iceland.

2. Order of precedence

In the event of a conflict between the Agreement and this Data Processing Agreement, this Data Processing Agreement prevails to the extent that the processing of personal data is concerned.

3. Subject matter and instructions

3.1 stipt processes personal data solely on behalf of and on the basis of written instructions from the Controller, and not for its own purposes. The Agreement, this Data Processing Agreement and the settings the Controller selects in the Software (including enabling or disabling AI functionality and automations) constitute those instructions.

3.2 By way of derogation from 3.1, stipt may process personal data if a provision of Union law or Dutch law requires it to do so. In that case, stipt informs the Controller prior to the processing, unless that legislation prohibits this.

3.3 The processing concerns solely the personal data, categories of data subjects and purposes described in Schedule 1. stipt informs the Controller without delay if, in its opinion, an instruction infringes the GDPR.

4. Duration

4.1 This Data Processing Agreement remains in force for as long as stipt processes personal data on behalf of the Controller, including where this continues after the end of the Agreement. Provisions that by their nature are intended to survive (including confidentiality and article 10) remain in force thereafter.

5. Security

5.1 stipt takes appropriate technical and organizational measures as referred to in article 32 GDPR to protect personal data against destruction, loss, alteration, unauthorized access and unlawful processing. The current measures are described in Schedule 3.

5.2 stipt may update the measures, provided that the level of security does not deteriorate.

6. Confidentiality

6.1 stipt treats the personal data as confidential. Persons processing personal data under the authority of stipt are bound by a duty of confidentiality.

7. Sub-processors

7.1 The Controller hereby grants stipt general written authorization to engage sub-processors. The current sub-processors are listed in Schedule 2 and on stipt's website.

7.2 stipt informs the Controller at least 30 days in advance of an intended addition or replacement of a sub-processor. The Controller may object within that period in writing, stating its reasons. If the parties cannot reach agreement, the Controller may terminate the Agreement effective as of the date on which the change takes effect, without either party being liable for damages.

7.3 stipt imposes on every sub-processor obligations that are at least equivalent to stipt's obligations under this Data Processing Agreement. stipt remains fully liable towards the Controller for performance by sub-processors.

8. Transfers outside the EEA

8.1 stipt processes, and has processing carried out, within the EEA, unless a transfer to a third country is permitted under Chapter V GDPR (adequacy decision, EU-US Data Privacy Framework or standard contractual clauses, where necessary with supplementary measures). The current transfer situation per sub-processor is set out in Schedule 2.

9. Personal data breaches

9.1 stipt informs the Controller without undue delay, and no later than 24 hours after discovery, of a personal data breach that (possibly) relates to personal data of the Controller. To the extent known, stipt provides: a) the nature of the personal data breach and the (suspected) cause; b) the categories of personal data and data subjects and the (estimated) numbers; c) the likely consequences; d) the measures taken and proposed, including measures to mitigate adverse consequences; e) a contact point for further information.

9.2 Notification to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) and to data subjects is the responsibility of the Controller. stipt does not independently notify the supervisory authority or data subjects, unless the Controller requests this in writing or the law requires stipt to do so.

9.3 stipt documents all personal data breaches, including the facts, consequences and corrective measures, and maintains a register thereof. stipt has a written procedure for handling personal data breaches.

10. Assistance to the Controller

10.1 stipt provides reasonable assistance in fulfilling the Controller's obligation to respond to requests from data subjects (access, rectification, erasure, restriction, portability, objection). If stipt receives such a request directly, it forwards it without delay and does not handle it substantively itself.

10.2 stipt provides reasonable assistance with data protection impact assessments (DPIAs) and prior consultation as referred to in articles 35 and 36 GDPR, to the extent that these relate to the processing under this Data Processing Agreement.

10.3 For assistance that materially exceeds normal service provision, stipt may charge reasonable costs, subject to prior notification.

11. Requests from authorities

11.1 If stipt receives a request or order from a Dutch or foreign authority for the provision of, or access to, personal data, stipt informs the Controller without delay, unless this is legally prohibited. Where possible, stipt follows the reasonable instructions of the Controller and provides no more than strictly necessary.

12. Audits

12.1 Upon request, stipt makes available all information reasonably necessary to demonstrate compliance with article 28 GDPR, including summaries of security documentation and, where available, reports of independent security assessments (such as penetration test reports).

12.2 The Controller may, no more than once per year and upon reasonable notice of at least 14 days, conduct or have conducted an audit by an independent expert bound by confidentiality. The audit disrupts stipt's business operations as little as possible and does not provide access to data of other customers of stipt. Each party bears its own costs; if the audit reveals a material shortcoming on the part of stipt, stipt bears the reasonable costs and remedies the shortcoming as soon as possible.

13. Deletion and return

13.1 After the end of the Agreement, stipt enables the Controller for a period of 30 days to export the personal data in a common, machine-readable format. Thereafter, stipt deletes all personal data, unless a statutory retention obligation prevents this.

13.2 Deletion also includes the Controller's encryption keys, as a result of which encrypted data becomes permanently inaccessible. Personal data in backups is overwritten by the regular backup rotation no later than 35 days after deletion.

14. Liability

14.1 Liability under this Data Processing Agreement is governed by the provisions of article 11 of the General Terms and Conditions, on the understanding that the limitations contained therein do not apply to the extent that this would conflict with mandatory law, including article 82 GDPR.

14.2 The Controller warrants that the processing it instructs is lawful, that it has a valid legal basis for it and that it adequately informs data subjects. The Controller indemnifies stipt against claims from data subjects or third parties arising from non-compliance with those obligations.

15. Applicable law

15.1 This Data Processing Agreement is governed by Dutch law. The dispute resolution provisions of the General Terms and Conditions apply.


Schedule 1: The processing

Nature and purpose of the processing. stipt provides a SaaS platform for customer communication and work organization for installation and construction companies. The processing comprises: storage and hosting; receiving, displaying and sending customer communication (email, WhatsApp, phone notes, customer portal); CRM and file management; quotes and invoicing; planning; and, to the extent enabled by the Controller, AI-supported processing, namely: classification and summarization of messages, generating draft responses, automated responses via the WhatsApp assistant, and making documents and communication searchable via a knowledge base (retrieval augmented generation). AI processing takes place per request; the content is not used by the AI sub-processors to train generic models.

Categories of data subjects.

  • (end) customers and prospects of the Controller and their contact persons;
  • employees and users of the Controller;
  • other persons appearing in the Controller's communication or documents (such as partners, advisors, suppliers).

Categories of personal data.

  • name, address, place of residence, email address, phone number;
  • content of communication: emails, WhatsApp messages, chat messages, notes, call reports;
  • photos and attachments, including photos of and around the home (site survey, execution, delivery);
  • quote, order and invoice data, including price and product data;
  • signatures (for quotes and deliveries);
  • data about the home and installation, including energy consumption and preferences regarding PV systems or other installations;
  • IBAN, to the extent provided by the Controller or the data subject;
  • planning and appointment data;
  • account data of users (name, email, role, activity in the platform).

stipt does not aim to process special categories of personal data (art. 9 GDPR). The Controller ensures that these are not unnecessarily included in communication or documents.

Retention period. For the duration of the Agreement, plus the export and deletion periods set out in article 13.

Schedule 2: Sub-processors

The current list is available at stipt.ai/privacy. Upon entering into this Data Processing Agreement, these are:

Always engaged:

Sub-processorPurposeProcessing locationTransfer mechanism
Hetzner Online GmbHHosting of the applicationEU (Germany)n/a (EEA)
Supabase, Inc.Database, storage and authenticationEU (Frankfurt); parent company USSCCs
Anthropic, PBCAI processing (classification, summarization, draft responses, assistant)USSCCs
Cohere, Inc.Making knowledge base and documents searchable (embeddings, reranking of search results)USSCCs
Meta Platforms Ireland LtdWhatsApp Business Platform (message traffic)EU (Ireland); transfer to US possibleSCCs
Resend, Inc.Transactional emailUSEU-US DPF / SCCs
Functional Software, Inc. (Sentry)Error monitoring (personal data minimized)EU (Germany, EU data location)n/a (EEA)

Only if the Controller selects the relevant AI provider:

Sub-processorPurposeProcessing locationTransfer mechanism
OpenAI, LLCAI processing (selectable by customer)USEU-US DPF / SCCs
Google LLC (Gemini)AI processing (selectable by customer)EU/USEU-US DPF / SCCs
Mistral AI SASAI processing (selectable by customer)EU (France)n/a (EEA)

Not sub-processors of stipt. Services with which the Controller itself has a direct relationship and which it itself connects to the Software do not process as a sub-processor of stipt but on behalf of the Controller itself. This includes in any event: the Controller's own email provider (such as Microsoft 365, Google Workspace or its own IMAP/SMTP server) and integrations and automation steps configured by the Controller that send data to external services chosen by the Controller (such as a CRM integration or HTTP steps in workflows). Public (government) data services that are queried solely with address or location data to retrieve public building and yield data (PDOK, 3D BAG, PVGIS) likewise do not qualify as sub-processors.

Geocoding (independent controllers). For geocoding addresses for planning, travel times and map display, the Software shares only address and location data with Google LLC (Maps Platform) and the OpenStreetMap Foundation (Nominatim). Under their own terms, these parties act as independent controllers, not as sub-processors of stipt. No names, contact details or communication content are shared with them.

Schedule 3: Technical and organizational measures

  • Encryption: layered encryption; login credentials and integration tokens encrypted at application level with a separate key per integration, email addresses and phone numbers in the contact file additionally encrypted at application level with the customer environment's key, all other data (including message content, which must remain searchable) encrypted at rest; TLS for all connections.
  • Per-customer key management: each customer environment has its own encryption key; deletion of the key makes the data permanently inaccessible (crypto shredding).
  • Access separation: strict separation between customer environments at database level (row level security on every table), tenant isolation at subdomain level and strict cookie isolation.
  • Access management: personal accounts, role-based authorization, magic link authentication; administrative access limited to authorized personnel with multi-factor authentication.
  • Logging and monitoring: activity logging in the platform, error monitoring, operational health monitoring with alerting.
  • Minimization in logs: no names, email addresses or phone numbers in application logs.
  • Backups: periodic automated backups with limited retention, stored within the EEA.
  • Data location: hosting and storage within the EEA (Germany).
  • Development process: separated development and production environments, code review, dependency management.
  • Personnel: duty of confidentiality for everyone with access to personal data.