News

New data processing agreement as of 1 September 2026

2026-09-01

New data processing agreement as of 1 September 2026

As of 1 September 2026, a new version of our data processing agreement applies. Version 2.0 replaces version 1.1 of 20 November 2023. The reason: our range of services has changed considerably in recent years, we now use AI in several products and our information security policy has moved to the ISO/IEC 27001:2022 standard. The data processing agreement is fully aligned with that again.

The structure stays the same: part 1 is our Data Pro Statement, part 2 contains the Standard Clauses for Data Processing by NLdigital (November 2023 version). Nothing has changed in part 2. All changes are in the Data Pro Statement.

Current products and services

The list of products and services covered by the agreement has been completely rewritten. Services we no longer deliver (Universal private cloud, hosted SharePoint and SQL, Remote Desktop Services, managed virtual servers and Skykick) have been removed. Newly included are:

  • Microsoft cloud services via CSP: Microsoft 365, including Microsoft Defender and Copilot, Azure and Dynamics 365
  • Managed services: Security as a Service (SecaaS) with uDefend, Backup and Recovery for Microsoft 365 and Azure, managed Azure workplaces, uWelcome and uProvision
  • Universal Communications Suite: uWebChat (live chat and AI agents for websites, Teams and WhatsApp), uWebChat Voice (contact centre and telephony for Teams, with recordings, transcription, AI summaries and uWallboard), uAnswer and uContactManager
  • uCompose: website hosting and content management through an AI chat, on European infrastructure
  • uDeliver: a dedicated development environment in which AI agents build software and the client approves every phase

For each product, the agreement now also describes which types of data we process, from chat conversations and call recordings to source code and security alerts.

Privacy by design and AI

The privacy-by-design section has grown from a single paragraph into concrete commitments:

  • All products and managed services run on Microsoft Azure and Microsoft 365 in European regions (West Europe, Sweden Central and the Microsoft EU Data Boundary). Client data stays within the EU/EEA.
  • Every client has its own tenant or isolated environment. This separation is enforced at application and database level and is part of the internal audit.
  • AI functions only process client data for the function the client has switched on. Universal does not use client data to train AI models. Models run on Azure OpenAI in the EU wherever possible.
  • If you connect your own Azure OpenAI, Azure Speech, Azure AI Foundry or ElevenLabs resources to uWebChat or uWebChat Voice, those fall under your own agreement with that provider.
  • Access to client environments is limited to authorised engineers, with MFA, Conditional Access and least privilege. Changes to production are approved and logged, including changes made with AI tooling.
  • Data is encrypted in transit (TLS) and at rest.

Updated list of sub-processors

The list of sub-processors has been updated and is now a table showing the purpose, products involved, location and safeguards for each party. MessageBird has been removed. The current sub-processors are:

Sub-processorPurposeLocation and safeguards
Microsoft Ireland Operations Ltd.Azure, Microsoft 365, Dynamics 365, Azure OpenAIEU, Microsoft DPA and SCCs
TD SYNNEX (StreamOne)CSP distributor: licensing and billingEU, administrative data only
Cloudflare, Inc.DNS, CDN, firewall and access controlEU edge, SCCs and EU-US Data Privacy Framework
BT Netherlands N.V.Telephony and SIP trunkingEU/UK, adequacy decision and SCCs
Anthropic, PBCAI models (Claude) for uDeliverUS, SCCs, only for the AI function
ConnectWise, LLCCloud Backup for Microsoft 365 and AzureConnectWise processing terms and SCCs
Meta Platforms Ireland Ltd.uWebChat WhatsApp channel, only when you activate itEU, Meta terms and SCCs

Transfers outside the EU/EEA are also described more precisely. They only happen when a sub-processor on this list requires it, and always under the Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework. Changes to the list are announced in the Universal Customer Portal.

ISO/IEC 27001:2022 and information security

Where version 1.1 still referred to ISO 27001:2015, version 2.0 is aligned with ISO/IEC 27001:2022. We now also name our certificate explicitly: issued by Kiwa Nederland B.V. (K-0221887), valid until 16 December 2027. The certificate and the Statement of Applicability are published on our website.

New in the security policy:

  • Annual cycle: annual internal audits, an annual external audit by the certification body and a management review. The Data Pro Statement itself is reviewed at least once a year.
  • New topic-specific policies, including secure development and change management (covering AI-assisted development tools), responsible use of AI, supplier and sub-processor management, and logging, monitoring and incident management.
  • Suppliers and sub-processors are assessed at least once a year.
  • Rules of conduct now explicitly cover the use of AI tools.
  • Development always includes code review, vulnerability and dependency scanning and approval before production.
  • Universal does not operate its own data centres. All hosting runs on Microsoft Azure and Microsoft 365.

Data subject rights, deletion and data breaches

  • Data subject requests: in most products you can view, export, correct and delete data yourself. Where that is not possible, we assist within ten working days.
  • End of agreement: within three months we delete the client environment per product, including chat histories, recordings, transcripts, content and source code. Backups are removed at the end of the retention period. Your own Microsoft 365 and Azure tenant remains yours; we only revoke our administrative access. On request, you receive your data in a machine-readable format before deletion.
  • Data breaches: detection now runs through Microsoft Defender, audit logging and monitoring of our own platform, with alerts handled through uDefend. In the event of a (suspected) data breach we notify you without undue delay and where possible within 48 hours, by e-mail and phone. Every incident, its cause and the measures taken are recorded in the ISMS.

What does this mean for you?

As a client, you do not need to do anything. The new version applies to all existing agreements from 1 September 2026 and can always be downloaded from the footer of our website. If you cannot reasonably agree to the changes, Article 2.2 of the standard clauses allows you to terminate the data processing agreement in writing, stating your reasons, within thirty days of this notice.

Download the data processing agreement v2.0 (PDF)

Questions about the new data processing agreement or data protection in general? Contact our Security Officer at so@universal.cloud.

Want to learn more?

Contact Universal Cloud to discuss how we can help your organization.

Get in touch

Related Articles

Cloud security for business: a complete guide and free check (2026)
Security2026-06-19

Cloud security for business: a complete guide and free check (2026)

What is cloud security and how do you protect your cloud applications and company data? A practical guide covering the biggest risks, 6 concrete measures and a 10-question cloud security check.

Read More
Uh-oh, this is getting serious
AI2026-06-13

Uh-oh, this is getting serious

A week with Claude Fable — the most powerful AI model yet — and what it meant when the US government switched it off overnight. On digital sovereignty and the European alternative.

Read More
ConnectWise Cloud Backup now includes Entra ID protection
Security2025-12-30

ConnectWise Cloud Backup now includes Entra ID protection

Protect your Microsoft 365 identity layer with comprehensive Entra ID backup - users, groups, roles, and policies now included.

Read More