energie27for householdsYour electricity costs from 2027, when net metering endsCalculator
Quick calculations

Data processing agreement

For advisers with a licence. On the dashboard you store your clients' addresses with your licence. In doing so we process personal data for you: you are the controller, we are the processor (Article 28 GDPR). You agree to this agreement by ticking a box when you first log in. Version of 5 October 2026. This is a translation; the Dutch text is binding.

1. Parties

Processor: SynerZhi Consultancy B.V., trading as MagicT, maker of energie27, Liselott Linsenhoffstraat 27, Almere, Chamber of Commerce no. 83929452, info@magict.nl (hereinafter: energie27).

Controller: the company that holds the licence for the dashboard, as stated with the licence (hereinafter: the licence holder).

Terms such as personal data, processing, data subject and data breach have the meaning given in the General Data Protection Regulation (GDPR). This agreement belongs to the licence. If it conflicts with other arrangements about personal data, this agreement prevails.

2. What energie27 processes and why

energie27 stores what the licence holder enters in the dashboard, only to show it again on every device he logs in on, to calculate with it and to make a report of it. Annex 1 describes which data this is.

energie27 uses this data for nothing else: not to test the calculation model, not for statistics or advertising, and not to contact the clients. energie27 shares it with no one except the sub-processor in article 4.

The licence holder ensures he has a legal basis to enter his clients' data and informs his clients about it. He does not enter special categories of personal data, criminal data, citizen service numbers (BSN) or bank details.

3. Obligations of energie27

  1. energie27 processes the data only in accordance with this agreement and the instructions of the licence holder. What the licence holder does in the dashboard (saving, making a report, deleting) counts as an instruction.
  2. If energie27 considers an instruction to infringe the GDPR, it reports this immediately.
  3. Everyone at energie27 with access to the data has a duty of confidentiality. At present that is only the maker of energie27, and only when needed for maintenance, a fault or a request from the licence holder.
  4. energie27 takes appropriate technical and organisational measures (Annex 2) and keeps them up to date.
  5. energie27 assists the licence holder where reasonable with a data protection impact assessment (DPIA) or a question from the Dutch Data Protection Authority.

4. Sub-processor and transfer

The licence holder consents to Cloudflare, Inc. as sub-processor: hosting, the server, the database and making a report as a PDF. Cloudflare is an American company; data may be processed outside the EEA. That transfer is based on the EU-US Data Privacy Framework, under which Cloudflare is certified, and on the standard contractual clauses in Cloudflare's data processing agreement. Through that agreement energie27 imposes the same obligations on Cloudflare as here.

energie27 announces a new or different sub-processor by e-mail at least 30 days in advance. The licence holder may then object and, if that cannot be resolved, end the licence.

5. Data breaches, rights of data subjects and audits

Data breach. energie27 reports a data breach affecting the licence holder's data without undue delay and at the latest within 36 hours of discovery, with what is known: what happened, which data and how many clients, the consequences and the measures taken. The licence holder decides on notifying the Dutch Data Protection Authority and his clients.

Rights of data subjects. The licence holder can view, change, delete and save everything as a file himself in the dashboard. If a client asks energie27 for access, correction or deletion, energie27 forwards the request and does not answer it itself.

Audits. On request, energie27 gives the licence holder the information needed to see whether it complies with this agreement. An audit is possible once a year, at the licence holder's expense, with at least 30 days' notice, by an independent expert bound by confidentiality.

6. Termination, liability and law

Termination. This agreement runs as long as the licence runs, and after that until the data has been deleted. An address the licence holder deletes is removed from the database immediately. When the licence ends, the licence holder can save his data as a file under Settings until the end, and request it from energie27 for 30 days after that. energie27 deletes the addresses, input, settings and logo within 30 days after the end, and confirms this on request. Cloudflare's restore points of the database then expire by themselves, within 30 days.

Liability. Each party is liable for damage caused by its own breach of the GDPR or this agreement, as set out in Article 82 GDPR. The liability of energie27 is limited to direct damage, up to at most € 1,000, except in case of intent or wilful recklessness.

Changes. energie27 announces a material change at least 30 days in advance; the dashboard then asks for agreement again. Anyone who does not agree can end the licence.

Law. Dutch law applies. Disputes are submitted to the District Court of Midden-Nederland.

Annex 1. Data and data subjects

  • Data subjects: clients and prospective clients of the licence holder (occupants of the addresses).
  • Data per address: name or label, address or postcode, note, the codes for sharing, the chosen options and the bill now and with that choice.
  • Per comparison (up to six per address): what was entered in the calculator, such as consumption, generation, appliances, contract, purchase prices, postcode and town, and the annual statement; with a code from a client, also that client's input.
  • Shared situations (Share with client, or a code from the client): the same input, encrypted in the browser with the code, so that energie27 cannot read it; deleted after 12 months.
  • Report as PDF: the text of the report briefly passes through the server and Cloudflare's browser; not stored and not logged.
  • Where: Cloudflare D1 (the database), with the licence. A copy is also kept in the licence holder's browser; that falls outside this agreement.

Data about the licence holder himself (company name, adviser's name, logo, price list, offers, logging in) is processed by energie27 as controller; for that, see the privacy statement.

Annex 2. Security measures

  • All traffic over https; the database is at Cloudflare and stored there encrypted.
  • Access only with a licence code. The database stores only a hash of the code and of the session. The cookie is HttpOnly, Secure and SameSite=Strict and expires after 30 days. At most three devices per licence at a time; revoking or a new code ends all sessions immediately.
  • Too many failed login attempts per IP address block for an hour; for this only a hash of the IP address is stored in the database.
  • Each licence sees only its own addresses; the server checks this on every request.
  • Addresses and input are not separately encrypted in the database, so that they work on every device, also after a new licence code.
  • For the PDF, JavaScript is off and Cloudflare's browser loads only files from energie27.nl itself.
  • Test versions of the site have no access to the real database. Expired sessions, login attempts and shared situations are deleted every night.
  • Only the maker of energie27 can access the database, through the Cloudflare account with two-factor authentication.

Find it useful? Spread the word.

The more people do the sums, the fewer surprises when net metering ends.

WhatsAppEmailLinkedInFacebookX

Report a problem

Is something not working, such as a button or the layout? Let us know.

What is sent along?

Not what you entered.