EverStamp
Home › Terms

Terms of use

The terms for the app, the verification page, share links, the dashboard and the API. Part A applies to everyone, part B to users of the app, part C to organisations; annex 1 refers to the data processing agreement. As at 30 September 2026.

Part AFor everyone

Article 1. Who we are

1.1

EverStamp is a service of Digital Sandbox B.V., Waalstraat 2, 8052 AE Hattem, the Netherlands, registered with the Netherlands Chamber of Commerce (Kamer van Koophandel) under number 42124304, VAT number NL869836109B01 (“we”, “EverStamp”).

1.2

Contact: info@everstamp.app. Telephone: +31 6 21 52 00 00, on working days. For privacy: privacy@everstamp.app. To report a vulnerability or misuse: security@everstamp.app; see also everstamp.app/security. By post: Waalstraat 2, 8052 AE Hattem.

1.3

Authorities and users can reach us for notices under the Digital Services Act at the same addresses, in Dutch or English.

Article 2. Definitions

  • App: the EverStamp app for iOS and Android.
  • File: a series of photos that the app records as a whole, with the data that belongs to them.
  • Stamp bar: the bar that the app places in every photo, showing among other things the date and time of the device and the location.
  • Timestamp: a qualified electronic timestamp within the meaning of the eIDAS Regulation (EU) 910/2014, issued by a qualified time-stamping service that we choose, currently SK ID Solutions AS in Estonia.
  • Registry: our service that enrols devices, signs photos and records that a file exists.
  • Registry receipt: the entry in a file showing that the registry has included the file, with the path to the timestamped period; the verification page checks it and asks the registry whether it knows the entry.
  • Public log: the part of the registry that anyone can inspect and mirror, without the photos.
  • Verification page: the page at https://everstamp.app/verify where anyone can check a file.
  • Share link: a link to an encrypted copy of a file held by us, for a limited time.
  • Organisation: a company or institution with a Business or Enterprise subscription.
  • Member: someone who belongs to an organisation: whoever created it in the dashboard, or whoever personally accepted an invitation from the organisation; with a role: owner, administrator, field worker or reader.
  • Owner: a member who may do everything in the organisation, including arranging the subscription and billing.
  • Administrator: a member who manages people, phones, templates and orders.
  • Reader: a member who only looks on: sees the organisation’s list of files and changes nothing, gets no linking code and records nothing. When a member becomes a reader, that member’s phones are unlinked and the open linking codes are revoked.
  • Audit log: the log of an organisation in the dashboard, with every change, and every opening of a delivery or stored file: who, what and when. Only owners and administrators see it. It is something else than the public log.
  • Guest: someone who supplies photos at the request of an organisation.
  • Request: an organisation’s invitation to a guest to supply photos, with a link that the guest opens on their phone.
  • Delivery: the encrypted file that a guest’s app sends to us in response to a request, and that we store for the organisation.
  • Plan: Basis, Plus, Business or Enterprise; Business in the size that the organisation chooses (Business S, M, L or XL; the dashboard calls that size a bundle), with the number of files and users that the dashboard states at checkout.
  • Pricing page: everstamp.app/pricing, in Dutch everstamp.app/nl/prijzen.
  • Extra files: five files that a user with Plus buys in the app, called “Five extra files” in the app and the stores (article 18.3).

Article 3. Applicability and order of precedence

3.1

These terms apply to every use of EverStamp: the app, the verification page, share links, the dashboard and the API.

3.2

Anyone who gets the app from the App Store or Google Play, or buys Plus there, is also subject to the terms of Apple or Google (article 16). For an organisation, a quotation, where there is one (article 26.1), and the data processing agreement (annex 1, article 34) also apply.

3.3

In the event of conflict, precedence is as follows: (a) mandatory law, (b) the data processing agreement (annex 1), insofar as personal data are concerned, (c) a quotation accepted by both parties, (d) these terms. The terms of Apple and Google take precedence insofar as they themselves so provide.

3.4

We expressly reject an organisation’s general terms and conditions, including purchasing terms. They apply only if we accept them in writing.

3.5

The terms are available at everstamp.app/nl/voorwaarden and everstamp.app/terms, also as a PDF to save. We send them free of charge on request.

3.6

An agreement with us is formed by electronic means. (a) With a user of the app it is formed by using the app, and a purchase by confirming it in the store; with an organisation as article 26.1 says. (b) The terms are on the site, also as a PDF to save (article 3.5). For an organisation we record which text it accepted, with the state of the data processing agreement, who did so and when. (c) Until confirming, whoever creates an organisation can read over and change the data entered; after that an owner can change them in the dashboard. The user confirms a purchase in the app on the screen of the store, where they can also abandon it. (d) The agreement can be concluded in Dutch and in English (article 14.5). (e) We have not subscribed to a code of conduct. (f) Whoever creates an organisation receives a confirmation by email, with the moment, the state of the terms they accepted and a link to that text.

Article 4. What EverStamp records, and what it does not

4.1

EverStamp is a tool for recording what someone photographed and when, in a way that another person can check for themselves. What a file is worth in a dispute is decided by the recipient, an insurer or a court. Not by us.

4.2

In the European Union, a qualified timestamp enjoys the presumption of the accuracy of the date and time it indicates, and of the integrity of the data to which that date and time are bound (Article 41(2) of the eIDAS Regulation). The presumption goes no further than those two things. In the Netherlands, the court assesses the evidence freely (Article 152 of the Dutch Code of Civil Procedure (Rv)).

4.3

What a file records:

  • that the photos existed in this form before the moment of the timestamp;
  • that any change after that shows up, including in the order of the photos;
  • for a file that our registry confirms during the check: that the photos were signed with the key of the device named, and that Apple or Google has declared that this key was made by our app on a real device. That is a declaration by Apple or Google, not a finding of ours.
4.4

What a file does not record:

  • what can be seen in a photo, or whether that is accurate; a photo of a screen is still a photo;
  • the time on the stamp bar: that is the clock of the device, a declared value; the time that counts is that of the timestamp;
  • the location on the stamp bar: that is what the device reports;
  • who used the device;
  • without that confirmation by the registry: whether the file was made with our app.
4.5

The timestamp is issued by the time-stamping service, not by us. For the timestamp itself, that service is liable on the basis of Article 13 of the eIDAS Regulation.

4.6

Even without a network, the device signs every capture immediately with its own key in the secure hardware. What needs a connection, namely the C2PA signature of our service and the timestamp, follows as soon as there is a connection or the time-stamping service is available again. The time of the timestamp is then later than the capture; the file shows the window between capture and stamp, and a photo signed later is marked as such.

Article 5. The registry and the verification page

5.1

For each file, the public log contains only: the fingerprint (hash) of the file, the serial number and the time of the timestamp, an identifier of the device and the identifier of the file. Never the photos or the position. The identifier of the device differs per file, so that entries of the same device cannot be linked to each other; entries from before 29 September 2026 carry the fixed identifier of the device.

5.2

In addition, the registry keeps what is needed to provide the service, as the privacy statement describes: among other things the key and the attestation of a device, for each photo the fingerprint that is signed, for Plus a fingerprint of the subscription and the usage, and for a file of an organisation the name, the checklist and the completed fields, only for that organisation.

5.3

Entries in the public log remain in existence indefinitely and cannot be removed; that is how a file remains checkable later on. We erase the names and file data of an organisation when the organisation is dissolved, except the organisation’s name in a revoked link of a phone, which stays for another fourteen days (data processing agreement, article 11). The privacy statement explains what this means for the rights of the people concerned.

5.4

The verification page is free to use, without an account. We may restrict automated use that hinders the service for others.

Article 6. Share links and storage with us

6.1

Photos stay on the user’s device, except in three cases: (a) a share link that the user creates, or that a guest’s app makes by itself right after the delivery as a receipt (with the key only in the link), (b) photos that are supplied at the request of an organisation, (c) files that an organisation has us store. In those cases we keep an encrypted copy.

6.2

A share link remains available until it expires or is withdrawn. How long a link is valid depends on the plan and is shown in the app and on the pricing page. After expiry or withdrawal we delete the copy; backups disappear no later than 17 days after that.

6.3

With an ordinary share link, the key travels only in the link itself; we cannot read the content. With a delivery to an organisation or storage with us, we hold the key. Through the dashboard or the API we open such a file only at the request of that organisation: a signed-in owner or administrator, or an API key of that organisation; not for a field worker or reader. Every opening through the dashboard or the API is recorded in that organisation’s audit log. Because we manage the key, we can technically also open such a file outside the dashboard, and then without a line in that audit log; we do so only at the written request of that organisation, or if a competent court or authority obliges us to by an order or demand based on the law. We review such an order or demand, we provide no more than is demanded, and we tell the organisation in advance or as soon as that is allowed, unless the law forbids that notice.

6.4

Anyone who shares a share link decides who receives it. Anyone who has the link can open the file.

Article 7. Rules of use

7.1

It is not permitted to use EverStamp:

  • for content or acts that are contrary to the law, including illegal content within the meaning of Article 3(h) of the Digital Services Act;
  • to photograph people or distribute their image without the law permitting it; anyone who works for a company or organisation is responsible for having a legal basis under the GDPR (AVG) and respects the right to one’s own image (portretrecht);
  • to falsify a file, to make it appear to be something it does not record, or to mislead another person about what a file records (article 4);
  • to disrupt or overload the app, the registry, the verification page or the API, to use them to view other people’s data, or to probe them without permission; only the last of these has an exception, within the rules of everstamp.app/security for anyone who reports a vulnerability in good faith;
  • to circumvent the device check (App Attest on the iPhone, Android Key Attestation on Android).
7.2

Researchers who investigate and report a vulnerability in good faith in accordance with everstamp.app/security will not face legal action from us for doing so. Good faith means at least: without disrupting or overloading the service and without viewing other people’s data. The commitment on /security applies in the same way.

Article 8. Notices, measures and complaints

8.1

Anyone who believes that a share link or a stored file contains illegal content, or that EverStamp is being misused, reports this via security@everstamp.app, and states: the reason, the link or the reference, their name and email address (except in the case of certain criminal offences), and a statement of good faith. A notice from someone who can be recognised in a photo and objects to it counts as a notice too. We confirm receipt and let the person reporting know what we decided. A notice that arrives at info@everstamp.app is handled in the same way.

8.2

A notice is not a reason for us to open encrypted content: we cannot read an ordinary share link, and we open a delivery or a stored file only as article 6.3 describes. After a notice, we may block or remove a share link. In the event of repeated misuse, we may also restrict access to share links or the dashboard. We do so carefully, objectively and proportionately, and we give reasons for a measure if we can reach the person concerned.

8.3

If a notice gives rise to a suspicion of a criminal offence that threatens the life or safety of people, we report it to the competent authorities.

8.4

Complaints about EverStamp: info@everstamp.app. We reply within 3 working days, and within 24 hours in urgent matters. Consumers can also go to the competent court. For purchases through the stores, they can also turn to Apple or Google.

Article 9. Intellectual property

9.1

The app, the verification page, the dashboard, the software and the trade marks belong to us or our licensors.

9.2

The photos and files belong to the user, or to the organisation for which they work. We receive only the right that is needed to provide the service: to store and display a share link, to hand over a delivery to the organisation, to store a file.

Article 10. Privacy

10.1

How we handle personal data is set out in the privacy statement at everstamp.app/privacy. The privacy statement is information and not part of these terms. For share links, the registry (except what it keeps for an organisation, articles 5.2 and 10.2), the public log, Plus, the sign-in account for the dashboard (email address, sign-in method, sessions, last sign-in and second step) and the payments, we are the controller, and also for what is needed for the security of the service and preventing abuse, with the access logs and the system journal that belong to it: we do that as the provider on our own responsibility, not on an organisation’s instruction.

10.2

For what we process on behalf of an organisation (deliveries, stored files, data of guests, the membership and the role of members, the organisation’s audit log, and the name, the checklist and the fields of its files in the registry) we are the processor, and the data processing agreement (annex 1, article 34) applies.

Article 11. Availability, maintenance and updates

11.1

We do our best to keep EverStamp available, but we do not promise uninterrupted operation. Where possible, we announce maintenance in advance.

11.2

EverStamp also depends on services of others: the time-stamping service, Apple and Google (device check and purchases), and the user’s networks. If these do not work, a timestamp may come later (article 4.6).

11.3

We provide updates to the app, including security updates, for as long as may reasonably be expected. Anyone who does not install an update bears the consequences of that if we have informed them about it.

Article 12. Liability (general)

12.1

We are not liable for what a recipient, insurer or court does with a file or concludes about it, nor for the content of photos.

12.2

We are not liable for damage caused by services of others not being available, or being available only later (article 11.2), insofar as we have no influence over this.

12.3

The limitations in these terms do not apply in the case of intent or wilful recklessness (opzet of bewuste roekeloosheid) on the part of us or our senior management, nor insofar as mandatory law prohibits them. For consumers, article 23 also applies; for organisations, article 36.

Article 13. Force majeure

We are not required to perform an obligation for as long as force majeure prevents this. Force majeure also includes a failure of a service of others over which we cannot reasonably exert influence (article 11.2). If the force majeure lasts longer than 60 days, either party may terminate the agreement, without compensation.

Article 14. Final provisions

14.1

These terms and every agreement with us are governed by Dutch law. A consumer retains the protection of the mandatory rules of the country where they live.

14.2

Disputes with an organisation are settled by the Rechtbank Gelderland (the District Court of Gelderland). A consumer can always go to the court of their own place of residence; we bring proceedings against a consumer only there.

14.3

If a provision is void or is annulled, the other provisions remain in force and we replace it with a provision that comes as close as possible to its purpose and is valid.

14.4

We may amend these terms. Every version is on the site, with the date on which it takes effect; the app links to the terms. We distinguish two kinds of amendment:

  • A minor amendment: a clarification, the correction of a mistake, an amendment that only benefits the user or the organisation, or an adjustment the law requires that is not to the disadvantage of the user or the organisation. It takes effect on the day it is on the site, and the dashboard shows a notice.
  • A material amendment: every other amendment, and in any case a change to a price (except an indexation under article 31.4), to what the service does, to what the user or the organisation has to do, or to a retention period that these terms state. We announce it at least 30 days in advance: on the site, in the dashboard, and by email to the owners of every organisation, with a link to the new text as a PDF at its fixed address. That email is a service message and is sent even to someone who does not receive product news. Anyone who does not want the amendment may terminate the agreement free of charge before the day it takes effect; a consumer has that right for every material amendment (see also article 21).
14.5

These terms exist in Dutch and English. Where the two differ, the Dutch text prevails, except towards a consumer for whom the English text is more favourable.

Part BFor users of the app (Basis and Plus)

Article 15. The licence

15.1

We grant the user a personal, non-exclusive and non-transferable right to use the app on devices that they own or control, in accordance with these terms and the rules of the store.

15.2

iPhone. Apple’s standard licence agreement (Licensed Application End User License Agreement, https://www.apple.com/legal/internet-services/itunes/dev/stdeula/) also applies to the app from the App Store. These terms supplement it. The agreement is between the user and us, not with Apple; Apple is not responsible for the app, its maintenance or its support; claims about the app are to be addressed to us; Apple and its subsidiaries are third-party beneficiaries of these terms and may enforce them against the user.

15.3

Android. For the app from Google Play, this licence applies; the Google Play terms take precedence insofar as they so provide.

15.4

The app is for anyone aged 16 or over. For a guest, article 25 applies.

Article 16. Purchases through Apple and Google

16.1

You buy Plus and the extra files in the app through the App Store or Google Play. The store handles the payment, the VAT, the renewal, the cancellation and any refund, under its own terms. Anyone in the European Union who buys through the App Store buys from Apple Distribution International Ltd.; through Google Play, from Google Commerce Limited. What Plus gives, how long it runs and how it renews is ours and is in article 18.

16.2

The price is the price that the store shows at the time of purchase.

Article 17. Basis

Basis is free and gives one file per calendar month, with the same sealing as in Plus. No account is needed.

Article 18. Plus and the extra files

18.1

Plus is a monthly or yearly subscription. It gives five files per month, the customer’s signature on the screen in a checklist that asks for it, backup to a cloud folder of your own, your own logo on the report and share links with a password, with the periods that the app and the pricing page show.

18.2

The subscription renews automatically for the same period until the user cancels it in the subscription settings of the store. Cancellation takes effect from the end of the current period.

18.3

You buy the extra files (“Five extra files”) five at a time, on top of the five per month; they are available only to those who have Plus. Each month the five from the subscription are used first, then the purchased credit.

18.4

Purchased credit does not expire, not even when the subscription ends. After Plus ends, it remains usable for new files. Additional credit can only be bought with Plus.

18.5

The credit is tied to the subscription: the registry keeps track of it with a fingerprint of the subscription, as the privacy statement describes. While Plus runs, you use it on every device with that subscription; after Plus ends, on the devices that were already linked.

Article 19. Right of withdrawal

19.1

A consumer can withdraw from a purchase made through the store within 14 days, through the store and according to its rules. We do not work against this.

19.2

If a consumer withdraws within the cooling-off period, we ask no payment for the use up to that moment.

19.3

After a withdrawal, we return to the user their own files on request, insofar as they are held by us. Files on the device stay there.

Article 20. No account

20.1

The app works without an account. Files are stored on the user’s device. We cannot retrieve or erase them.

20.2

If a device is lost or the app is deleted without a backup, the files on that device are gone. Plus offers a backup to a cloud folder of your own. You restore a purchase with “Restore purchases” in the app.

20.3

These features (files on the device, no recovery by us, share links with a limited validity) are deliberate characteristics of the service.

Article 21. Changes to the service

21.1

We may change the app and the service during a subscription if there is a good reason for this, such as security, legislation, a change at Apple, Google or the time-stamping service, or improvement of the service. A change costs the user nothing extra.

21.2

If a change has more than minor negative consequences for the user, we notify them of this in advance, and they may cancel free of charge within 30 days of our notification or, if later, of the change. The store then refunds the unused part according to its rules.

Article 22. Restriction and termination

22.1

We may block share links or withdraw a device’s access to the registry in the case of: misuse as referred to in article 7, a valid notice as referred to in article 8, a device whose key does not pass attestation (App Attest on the iPhone, Android Key Attestation on Android), or a purchase that the store has reversed.

22.2

We do so proportionately and state the reason if we can reach the user. Files on the device remain the user’s.

Article 23. Liability towards consumers

23.1

Towards consumers, we are liable in accordance with the law. We do not limit the rights of a consumer if the service does not conform to the agreement.

23.2

Articles 12.1 and 12.2 describe what lies outside our service; that is not a limitation of statutory rights.

Article 24. Complaints and disputes

You report a complaint to info@everstamp.app (article 8.4). For a purchase, a consumer can also turn to Apple or Google. A consumer can submit a dispute to the court of their place of residence.

Article 25. Guests

Anyone who supplies photos at the request of an organisation confirms in the app that they take the photos themselves, on site and at that moment, and that they are 18 years or older or act on behalf of the insured person or the tenant. Their name appears on the photos and in the organisation’s file. The photos go to that organisation; for that organisation we are the processor. Articles 4, 6, 7, 8, 9, 10, 12, 14 and 15 of these terms apply to the guest. These terms are at everstamp.app/terms.

Part CFor organisations (Business and Enterprise)

Article 26. Formation of the agreement

26.1

An agreement with an organisation is formed by creating an organisation in the dashboard with acceptance of these terms, or by a quotation accepted by both parties. If the agreement is concluded by email or on paper, we send the terms with it as a PDF.

26.2

Anyone acting on behalf of an organisation declares that they are authorised to do so.

Article 27. Administration, members and linking codes

27.1

The organisation appoints owners and administrators. They invite members, manage linking codes, templates and settings, and are responsible for what happens under the organisation. An invitation counts as a membership only once the invited person accepts it.

27.2

A linking code is personal and secret. An owner or administrator can revoke a code, unlink or block a linked phone, and withdraw an invitation while it is unanswered.

Article 28. Requests to guests

28.1

An organisation can ask guests for photos by means of a request. The organisation is itself responsible for having a legal basis under the GDPR and for informing the guest, and we show the guest the notice in article 25.

28.2

Sending requests is free; an answered request counts as a file.

Article 29. Deliveries and storage at EverStamp

29.1

Photos that are delivered in response to a request are stored by us for the organisation. In addition, an organisation can have all its files stored with us; that comes with Business and Enterprise, and an owner or administrator switches that storage on. In both cases the files stay for as long as the agreement runs, unless the organisation sets a shorter retention term itself in the dashboard; by default there is no term, and there is no term per plan.

29.2

We store encrypted, with the key held by us, and open only as article 6.3 describes. When the agreement ends, the organisation has the 30 days of article 35.1 to collect its files, and after that we delete them. If an owner or administrator withdraws a file earlier, or the organisation is dissolved, we delete it at that moment. Backups disappear no later than 17 days after that.

Article 30. Term, renewal and cancellation

30.1

A subscription can always be cancelled as of the end of a calendar month.

30.2

You pay for a yearly subscription in advance. If you cancel it during the year, it ends at the end of the current calendar month, and we credit the part of the amount paid that corresponds pro rata to the remaining full months. If more files were used than the plan gives pro rata for the elapsed months, we settle the difference at the price per extra file (article 31.2).

30.3

An owner cancels in the dashboard or by email to info@everstamp.app. Where that is in the dashboard is in the user guide in the dashboard. An owner can withdraw the cancellation of a monthly subscription until the subscription has ended; it then simply continues. With a year that is not possible, because the part for the remaining months has then already been settled.

30.4

Enterprise: term and cancellation as in the quotation.

30.5

A Business subscription renews automatically for the same period, a month or a year, until the organisation cancels it as articles 30.1 to 30.3 describe.

Article 31. Prices and payment

31.1

The prices are in the dashboard, when the organisation is created and at checkout, or in the quotation, excluding VAT. You pay for Business in advance, monthly, or yearly with the discount stated in the dashboard at checkout, through the payment provider in the dashboard. Every payment comes with an invoice, already marked as paid. Business can be tried free for the first 14 days, with the number of files stated on the pricing page and without payment details; what the trial includes and what still works afterwards without payment is on the pricing page. The trial ends after 14 days or after the number of files the pricing page states, whichever comes first. A bundle can be taken by a business established in the European Union; outside the Netherlands that requires a valid VAT number, which we check with VIES. The trial is open in every country the dashboard offers at creation. If the trial ends without the organisation taking a bundle, the agreement ends at that moment: from then on the organisation has the 30 days of article 35.1 to collect its data, and then we delete them, as on cancellation. If the organisation takes a bundle within those 30 days after all, the agreement continues and everything stays. We email the owners at the end of the trial and a week before we delete. Enterprise pays as in the quotation.

31.2

The number of files per plan is a soft cap: we refuse nothing because a counter is full, and we charge for the excess afterwards at the price per extra file that the dashboard states at checkout for the chosen bundle. With a yearly subscription, the files count over the whole year. We notify the owner when the bundle is 80% and 100% used, before we charge for any excess, so that an additional charge does not come as a surprise. Extra users are a paid monthly add-on, at the price the dashboard states at checkout.

31.3

If a payment through the payment provider fails, we report this and the payment provider tries again. If a payment is more than 14 days late, we may suspend the service as article 32 describes. Statutory commercial interest is due on a late payment (Article 6:119a BW).

31.4

We may change prices as of a new period. A price change is a material amendment (article 14.4): we announce it at least 30 days in advance by email to the owners, and an organisation that does not want it may cancel free of charge before the day the new price takes effect. The only exception is an indexation. At most once per twelve months we may raise the prices by no more than inflation: the year-on-year change of the consumer price index (CPI), all expenditure, of Statistics Netherlands (CBS), over the last month for which the figure has been published on the day we announce the indexation. If CBS replaces the series, the series that takes its place applies. An indexation does not count as a material amendment and gives no right to cancel free of charge; we announce it at least 30 days in advance, stating the figure and the month. A consumer may nevertheless always cancel free of charge before the day the new price takes effect, as with every material amendment (article 14.4).

Article 32. Suspension and termination

32.1

We may suspend the service for an organisation after a written demand for payment if payment is more than 14 days overdue, or immediately in the case of serious misuse as referred to in article 7.

32.2

Either party may terminate the agreement if the other fails to perform a material obligation and does not remedy this within 30 days of a written notice of default, or in the event of bankruptcy or a suspension of payments (surseance).

32.3

During a suspension, files remain on the users’ devices, and the registry and the verification page continue to work.

Article 33. Availability and support

33.1

For Business, article 11 applies: a best-efforts obligation. Support through the dashboard and via info@everstamp.app, on working days.

33.2

For Enterprise, the quotation may include a service level, with availability, maintenance windows, response times and any service credits.

Article 34. Data processing agreement

34.1

For personal data that we process on behalf of an organisation, the data processing agreement (annex 1) applies; it follows Article 28(3) GDPR. For Business it is accepted electronically with these terms (Article 28(9) GDPR). For Enterprise the same text is signed, with its annex B filled in, and DPIA material and a fixed contact person are added.

34.2

The subprocessors are listed on everstamp.app/security. We announce a new subprocessor, or a material change in what a subprocessor does, at least 30 days in advance; an organisation can object to it. If the objection is not resolved, the organisation can cancel free of charge.

34.3

An amendment of the data processing agreement follows article 14.4. An amendment that reduces the protection of personal data is always a material amendment. The text that an organisation with Enterprise has signed changes only with the consent of both parties.

Article 35. End of the agreement and return

35.1

When the agreement ends, an organisation has at least 30 days to retrieve its data. An owner or administrator exports the data in the dashboard in one go, as JSON and CSV; the photos are not included. They retrieve the archives of stored files there, with the photos, in one go; those of deliveries per request, in the dashboard or through the API. How that works is in the user guide in the dashboard. After that we delete everything, with the exception of the entries in the public log (article 5.3) and what the law requires us to keep (article 35.2).

35.2

If an organisation dissolves itself in the dashboard, we immediately erase what we keep for it, or strip it of names and contact details, except the entries in the public log, the name in a revoked link of a phone that stays for another fourteen days (both article 5.3), and what the law requires us to keep, such as payments and invoices, for seven years; backups disappear no later than 17 days after that, as the privacy statement and /security describe. So export first.

35.3

If an organisation wants to switch to another service or to systems of its own, we cooperate with this, in line with the Data Act (Regulation (EU) 2023/2854, Article 25):

  • (a) On cancelling, the organisation tells us what it chooses: switching to another service, and which; switching to systems of its own; or having its data erased.
  • (b) What can be transferred is everything the organisation can export: the data of the organisation and its members, the audit log, the links of phones, orders, requests, files with their name, checklist and fields, projects, labels, checklists of its own, webhooks, share links and deliveries, the subscription and the usage, as JSON and CSV; and of every stored file and every delivery the archive as the app made it, with the file, the photos and the report.
  • (c) What cannot be transferred is what belongs to the working of our service: keys and secrets (the keys in the vault of the registry, API keys and the secrets of webhooks), the access logs and the system journal, and the backups. The entries in the public log are public and stay (article 5.3).
  • (d) The notice period for switching is never longer than two months. A Business subscription ends at the end of the current calendar month (article 30.1); for Enterprise the quotation states the period.
  • (e) The agreement ends when switching is complete, or at the end of the notice period if the organisation does not switch but wants its data erased; we let the organisation know that it has ended.
  • (f) After the end the organisation has the 30 days of article 35.1 to retrieve its data. After that we erase them completely, as articles 35.1 and 35.2 say.
  • (g) Switching costs nothing: we charge no switching charges.
35.4

The 30 days of article 35.1 also apply after a trial.

Article 36. Liability towards organisations

36.1

Our total liability towards an organisation is limited to the amount that the organisation paid us in the twelve months before the event. This limitation also applies to our liability for a personal data breach, subject to the exception in article 36.3; an organisation with an Enterprise agreement may agree a separate arrangement for this.

36.2

We are not liable for indirect damage, including consequential damage, lost profit, lost savings, reputational damage, and damage because a recipient or court assesses a file differently from what the organisation expected. We do not exclude loss of stored files or deliveries through a failure of ours; it falls under the cap of article 36.1.

36.3

These limitations do not apply in the case of intent or wilful recklessness on the part of us or our senior management.

36.4

A claim lapses if the organisation does not report it to us in writing within twelve months of discovering the damage.

Article 37. Confidentiality

Both parties keep confidential information of the other secret and use it only for the agreement. This also applies after the end of the agreement.

Article 38. Governing law and jurisdiction

The agreement with an organisation is governed by Dutch law. Disputes are submitted to the Rechtbank Gelderland, insofar as the law allows that choice.

Annex 1Data processing agreement

For the personal data we process on behalf of an organisation, the data processing agreement applies. In the event of conflict about personal data it takes precedence, as article 3.3 provides.

It is in the dashboard at dashboard.everstamp.app/documenten, as a page and as a PDF to save, for anyone who is signed in. These terms refer to the data processing agreement as of 30 September 2026.