General Terms and Conditions for Mortgage Documents of Smart Backoffice Solutions B.V.
Version dated 14 September 2026
The parties to these General Terms and Conditions are:
A. Smart Backoffice Solutions B.V., established and having its office at Saal van Zwanenbergweg 11, 5026 RM Tilburg, the Netherlands, registered with the Chamber of Commerce under number 90141482, hereinafter referred to as ‘Provider’; and
B. The business or organisation that has concluded an agreement for Mortgage Documents with Provider, or that uses Mortgage Documents without a written agreement, for example during a Trial, hereinafter referred to as ‘Customer’.
Provider and Customer are hereinafter jointly referred to as the Parties and each individually as a Party.
Whereas:
- Provider offers, under the name Mortgage Documents, Software as a Service that automatically reads and processes mortgage documents, hereinafter referred to as the ‘Software’;
- These General Terms and Conditions apply exclusively to the Software and to Provider’s supplies related to it, and not to other services and products of Provider, unless expressly agreed otherwise in writing between the Parties; and
- Arrangements on the processing of Personal Data are laid down in a Data Processing Agreement linked to these General Terms and Conditions (see annex); and
- These General Terms and Conditions take effect as soon as Customer concludes an agreement for the Software with Provider or (if this occurs earlier) Customer makes use of the Software, for example by submitting a document; this also applies during a Trial; and
- The Software is intended exclusively for use in the course of a profession or business; and
- These General Terms and Conditions are valid from 14 September 2026.
Have agreed as follows:
1. Definitions:
1.1. Agreement: the agreement concluded between the Parties with regard to the Software that Customer purchases from Provider. If the Parties have not concluded a written agreement, as during a Trial, the use of the Software constitutes the Agreement.
1.2. User: A natural person authorised by Customer to use the Software on behalf of Customer.
1.3. Trial: use of the Software, whether or not free of charge, without a written agreement or pending one, for example to test the Software with one’s own documents. During a Trial these General Terms and Conditions and the Data Processing Agreement apply in full. Clause 4 and clauses 5.1 to 5.4 apply during a Trial only insofar as the Parties have agreed rates or a contract term.
1.4. End of the Agreement: the moment at which the Agreement ends. For a Trial this is the earliest of the following: Provider revokes Customer’s API key; Customer informs Provider by email that it is stopping; or six months have passed since Customer last submitted a document.
2. Access to and use of the Software:
2.1. Provider grants Customer a non-exclusive and non-transferable right to access and use the Software.
2.2. Customer may designate and authorise users to access and use the Software on behalf of Customer. Customer is responsible for the actions and compliance of these users.
2.3. Customer is responsible for the careful handling of and access to the Software, and for the careful handling of the login credentials and API keys for the Software by its users. Customer indemnifies Provider against claims by third parties for damage caused by careless conduct by its users with regard to access and access credentials to the Software.
2.4. Customer is itself responsible for ensuring that the personal data provided to Provider for processing comply with the applicable data protection laws and regulations, including the General Data Protection Regulation (‘GDPR’).
2.5. Customer agrees not to:
- modify, decompile or disassemble the Software; and
- sublicense, lease, lend or rent the Software to third parties without the prior written consent of Provider; and
- use the Software for illegal or unauthorised purposes; and
- transmit viruses or malicious code; and
- disrupt the Software.
3. Functionality:
3.1. The functionality offered by Provider comprises
- forwarding documents; and
- automatically reading documents; and
- (where applicable) performing checks and cross-checks within a document; and
- reporting results back to Customer.
3.2. Provider aims for an availability of 98%. This availability is defined as the percentage of the total number of hours during which the Software is available for use by Customer. This total number of hours is calculated as the sum of the hours between Monday and Friday, 9:00 to 17:00, excluding:
- public holidays;
- time for maintenance and for putting new releases of the Software into production.
3.3. Provider is not liable for damage caused by force majeure or by unforeseen circumstances over which it has no influence. Force majeure includes, among other things, an internet outage, epidemic, war, natural disaster or strike.
3.4. Provider offers support in the event of a Defect in what has been supplied, provided the Defect is demonstrable and/or reproducible. Defect means the failure to comply, or to comply fully, with the functionality as described in these General Terms and Conditions.
3.5. Customer shall inform Provider within a period of two weeks of a Defect in a supply, or of a shortcoming in the performance of the Agreement. If a Defect or shortcoming has not been raised within two weeks, Provider’s liability in this respect lapses.
3.6. The Software processes one document per call. Extraction results can be retrieved through the API for one hour after processing has finished; after that the API no longer returns them. Customer retrieves results in time and stores them itself.
4. Rates and invoicing
4.1. Provider may increase rates once per calendar year by a maximum of 5%. Customer will be informed of this in good time. An annual rate increase does not give the right to terminate the Agreement early.
4.2. Periodic payments are due in advance of the period concerned. ‘Overuse’ rates are invoiced periodically (monthly or quarterly) in arrears.
5. Term and termination of the Agreement:
5.1. On expiry of the contract term stated in the Agreement, the Agreement is automatically renewed for the same term.
5.2. Customer may terminate the agreement with Provider subject to a notice period of three calendar months before the end of the contract term.
5.3. If Customer has not used the Software for one continuous period of six months, Provider has the right to terminate the Agreement unilaterally. Provider will draw Customer’s attention to this, after which, following a ‘grace period’ of a further two months without use, the Agreement may be terminated by Provider.
5.4. Delivery and payment obligations continue to apply until the end of the contract term of a (terminated) Agreement.
5.5. After termination, the right to access and use the Software lapses. What happens after the End of the Agreement to documents and data uploaded to the Software by Customer, and to the extraction results, is governed by clause 5.3 of the Data Processing Agreement.
5.6. In the event of an application for a suspension of payments, a declaration of bankruptcy or the discontinuation of the business, the Agreement may be terminated without observing a notice period. If Provider terminates the Agreement in these cases, there is no right to a refund of monies already received or to (damages) compensation.
5.7. Unless stipulated otherwise, upon termination of the Agreement the arrangements in these General Terms and Conditions which by their nature are intended to continue after termination of the Agreement remain in full force.
6. Intellectual property rights
6.1. Provider and any licensor(s) of Provider own all intellectual property rights in Provider’s supplies (including all software, databases, manuals, quotations and websites). All intellectual property therein remains with Provider and any licensor(s) of Provider.
6.2. Content (data, documents) uploaded by Customer to Provider’s applications and Software is and remains the property of Customer. Customer grants Provider the right to use the content to perform these General Terms and Conditions and, under the conditions of clause 2.8 of the Data Processing Agreement, to test and improve the Software.
6.3. Provider indemnifies Customer against any claims by third parties for an infringement of intellectual property rights through the use of Provider’s Software. This is on condition that these claims are not (partly) the result of Customer’s own wrongful conduct. Customer shall also (at its own expense) cooperate fully with Provider in order to be able to refute any claims.
7. Confidentiality and data security
7.1. Both parties agree to confidentiality and secrecy with regard to proprietary or confidential information which they receive from the other Party during the formation and the term of the Agreement. Neither party will share or transfer data or information concerning each other’s business operations, software, services, etc. to other parties, not even after the termination of an Agreement.
7.2. The duty of confidentiality also applies to all natural persons and legal entities with which the Parties are affiliated. If it is necessary to engage an external party for the proper performance of these General Terms and Conditions, it is permitted to share data and knowledge with the external Party provided that it undertakes confidentiality in writing in advance.
8. Liability
8.1. Provider is never responsible for any damage suffered as a result of an incorrectly read or analysed document. Customer is and remains itself responsible for a correct analysis of the documents and files uploaded to the Software. Customer acknowledges that the Software is merely a tool for the analysis and assessment of documents, and that the responsibility for a correct assessment of documents remains with Customer.
8.2. Without prejudice to mandatory statutory provisions, Provider’s liability for direct or indirect damage is limited to the amount paid out under Provider’s general liability insurance and/or professional liability insurance, and, if the general liability insurance and/or professional liability insurance does not apply or does not pay out, to one time the invoice value of Customer’s most recent 12 calendar months.
9. Non-solicitation of employees clause: During an Agreement and for a period of one year following a terminated Agreement, it is not permitted to have employees of Provider, directly or indirectly, perform work for Customer without the prior written consent of Provider. In the event of a breach of this clause, an immediately payable penalty of €50,000 per breach applies.
10. Other arrangements
10.1. These arrangements, and all non-contractual rights and obligations arising from them, are governed in all respects by Dutch law. All disputes between the Parties which may arise in connection with these arrangements, or with arrangements resulting from them, shall in the first instance be settled by the court in whose district Provider has its place of business.
10.2. All changes to these General Terms and Conditions will be communicated to Customer by email.
10.3. Provider is entitled to amend these General Terms and Conditions unilaterally. In that case, Provider will inform Customer of the changes in good time. There will be at least one month between this notification and the entry into force of the amended terms. If the change results in Customer being provided with a performance that differs materially from the original performance and Provider cannot offer a suitable solution for this, Customer has the power to dissolve the Agreement as of the date on which the amended terms enter into force.
10.4. If one or more provisions of these General Terms and Conditions prove not to be legally valid in this agreement or the accompanying annexes, these General Terms and Conditions and the annexes will otherwise remain in force. The Parties will consult on the provisions that are not legally valid in order to agree a replacement arrangement that is legally valid and corresponds as closely as possible to the purport of the provision to be replaced.
The following annexes form part of these General Terms and Conditions:
Data Processing Agreement with annexes
Annex: Data Processing Agreement
The parties to this data processing agreement are:
A. Smart Backoffice Solutions B.V., established and having its office at Saal van Zwanenbergweg 11, 5026 RM Tilburg, the Netherlands, registered with the Chamber of Commerce under number 90141482, hereinafter referred to as ‘Processor’; and
B. The business or organisation that has concluded an agreement for Mortgage Documents with Processor, or that uses Mortgage Documents without a written agreement, for example during a Trial, hereinafter referred to as ‘Controller’.
Processor and Controller are hereinafter jointly referred to as the Parties and each individually as a Party.
Whereas:
- Controller wishes to use the Software (Mortgage Documents) offered by Processor;
- The General Data Protection Regulation (‘GDPR’) applies to the processing of personal data;
- The Parties attach great importance to the protection of Personal Data and wish to lay down arrangements on this in this agreement;
- The Parties agree that this Data Processing Agreement forms an inseparable part of the ‘General Terms and Conditions for Mortgage Documents of Smart Backoffice Solutions B.V.’ for the use of the Software, and that capitalised terms not defined here, such as Agreement, Trial and End of the Agreement, have the meaning given to them in those General Terms and Conditions;
- The Parties agree that this data processing agreement applies from the first use of the Software, including during a Trial, and remains in force for as long as Processor holds personal data of Controller, including after the End of the Agreement.
Have agreed as follows:
1. Definitions:
1.1. Controller: The entity (a natural or legal person, a service, public authority or other organisation) that determines the purposes and means of the processing of personal data.
1.2. Processor: The entity (a natural or legal person, a service, public authority or other organisation) that processes personal data on behalf of Controller.
1.3. Data Subject: The person whose personal data are processed, usually a client of Controller.
1.4. Personal Data: Any information relating to an identified or identifiable natural person.
1.5. Processing: Any operation or set of operations performed on personal data. This includes but is not limited to the collection, recording, storage, alteration, retrieval, consultation, use, disclosure and erasure of data.
1.6. Sub-processor: Any external service provider or subcontractor engaged by Processor to assist with data processing, under the terms of this data processing agreement.
1.7. Data breach: A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.
2. Purpose and scope of the processing:
2.1. Processor processes personal data only on documented instructions from Controller. This data processing agreement, the General Terms and Conditions and the submission of documents to the Software constitute those instructions. Processor processes the data only for the purposes described in annex A, and not for other purposes (its own purposes, or those of others). Testing and improving the Software (purpose (b) in annex A) takes place only under the conditions of clause 2.8.
2.2. Processor will only process categories of Personal Data described in annex A.
2.3. Processor will not share data with parties other than the sub-processors listed in annex B, unless Processor is required to do so by law. In that case Processor informs Controller in advance, unless the law prohibits this.
2.4. Processor will not edit or add data without the prior consent of Controller, other than the reading, checking and formatting of data that the Software performs as its service.
2.5. Processor retains submitted documents and the extraction results for the term of the Agreement, so that Processor can provide support, reprocess documents and, under the conditions of clause 2.8, test and improve the Software. Results can be retrieved through the API for one hour after processing has finished; after that the API no longer returns them. Controller may at any time request in writing (an email suffices) that some or all documents and results be deleted; Processor carries out such a request within one month. Processor may also delete documents and results earlier.
2.6. Processor will not store or process data outside the European Economic Area (‘EEA’).
2.7. Controller is itself responsible for ensuring that the personal data provided to Processor for processing comply with the applicable data protection laws and regulations. This applies in particular to data concerning health and to the citizen service number (BSN), which appear on some documents (see annex A), and to informing data subjects about the processing, including the processing under clause 2.8.
2.8. Controller instructs and permits Processor to use submitted documents and extraction results also to test and improve the Software for all customers of the Software, for example by recording correct outcomes against which accuracy is measured, and by improving instructions and models. The following conditions apply: (i) only employees of Processor designated for this purpose have access; (ii) the data remain within the EEA and are processed only with the sub-processors listed in annex B; (iii) the data are not sold, not disclosed to third parties and not used to assess or contact data subjects. Controller may refuse or end this use at any time in writing (an email suffices). Processor then uses Controller’s data only for purpose (a) in annex A and removes them within one month from the datasets used to test and improve the Software. Improvements already made, such as revised instructions, remain. After the End of the Agreement, Processor no longer uses the data for this purpose.
3. Principles for data processing:
3.1. Processor will process personal data in accordance with all applicable data protection laws and regulations, including the GDPR.
3.2. All employees of Processor are bound to secrecy with regard to data made available by Controller of which they take note.
3.3. Processor immediately informs Controller if, in Processor’s opinion, an instruction infringes the GDPR or other data protection rules.
4. Sub-processing:
4.1. Processor has one or more sub-processors; these are listed in annex B. By using the Software, Controller agrees to the use of the services of these sub-processor(s) by Processor.
4.2. Controller gives Processor general written authorisation to engage sub-processors. Processor informs Controller by email at least one month in advance of any addition or replacement of a sub-processor. Controller may object on reasonable grounds within that period. If the Parties cannot find a solution, Controller may terminate the Agreement with effect from the date on which the change takes effect.
4.3. Processor imposes on sub-processors at least the same obligations as those set out in this data processing agreement, and verifies that these sub-processor(s) comply with them.
4.4. Processor remains fully liable to Controller for the performance of the obligations of the sub-processor.
5. Data security and storage
5.1. Processor implements appropriate technical and organisational measures to ensure the security and confidentiality of the personal data. See annex C for a list of some of these measures.
5.2. Processor notifies Controller of a Data breach without undue delay, and where possible within 48 hours after Processor becomes aware of it. Processor provides the information Controller needs to notify the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) and, where necessary, data subjects, and keeps Controller informed of the measures taken.
5.3. After the End of the Agreement, Processor retains Controller’s documents, extraction results and other personal data until Controller requests in writing (an email suffices) that they be deleted or returned. Return takes the form of an export of the extraction results in a common file format. Processor carries out such a request within one month and at the same time deletes all existing copies, unless applicable law requires storage. Without such a request, Processor deletes the data no later than twelve months after the End of the Agreement. Until then, Processor uses the data only to store them and to return them on request. Copies in back-ups expire with the normal back-up cycle.
5.4. Processor assists Controller in fulfilling its obligations under Articles 32 to 36 GDPR (security, notification of Data breaches, data protection impact assessment and prior consultation), taking into account the nature of the processing and the information available to Processor.
6. Audits and inspections
6.1. Processor makes available to Controller all information necessary to demonstrate compliance with the obligations laid down in this data processing agreement, and allows audits and inspections by Controller or an auditor authorised by Controller and reasonably cooperates with them.
6.2. Processor assists Controller in fulfilling its obligations to respond to requests from data subjects exercising their rights under the applicable data protection legislation.
7. Other provisions
7.1. Each Party is liable for its own breach of this data processing agreement and indemnifies the other Party against all damage arising from such a breach.
7.2. This agreement, and all non-contractual rights and obligations arising from it, are governed in all respects by Dutch law. All disputes between the Parties which may arise in connection with this agreement, or with agreements resulting from it, shall in the first instance be settled by the court in whose district Processor has its place of business.
7.3. All changes to this data processing agreement are communicated by Processor to Controller by email.
7.4. Processor is entitled to amend this data processing agreement unilaterally. In that case, Processor will inform Controller of the changes in good time. There will be at least one month between this notification and the entry into force of the amended terms. If the change results in Controller being provided with a performance that differs materially from the original performance and Processor cannot offer a suitable solution for this, Controller has the power to dissolve the Agreement as of the date on which the amended terms enter into force.
7.5. If one or more provisions of this agreement prove not to be legally valid, the agreement will otherwise remain in force. The Parties will consult on the provisions that are not legally valid in order to agree a replacement arrangement that is legally valid and corresponds as closely as possible to the purport of the arrangement to be replaced.
The following annexes form part of this data processing agreement:
- Data Processing Agreement Annex A: Personal data processed and processing purposes
- Data Processing Agreement Annex B: Sub-processors
- Data Processing Agreement Annex C: Technical and organisational security measures
Data Processing Agreement Annex A: Personal data processed and processing purposes
1. Personal data processed
Processor’s Software reads documents using OCR/AI techniques. Necessarily, this means that all legible data in these documents are processed, including data not listed in the table below, such as a passport photo or a signature on the document. The Software does not use a passport photo to recognise people.
If Controller wishes certain data on documents to be supplied not to be processed (such as the citizen service number, BSN), these data must be masked on the documents supplied.
The personal data processed differ per document. The table below indicates for each document category (i) which documents the Software processes and (ii) which personal data the Software extracts from them.
The total of personal data processed for a Controller is determined by the documents that Controller forwards to Processor’s Software for processing.
| Document category | Documents | Personal data extracted |
|---|---|---|
Identification documents |
Passport, identity card |
|
Income documents |
Payslip, employer’s statement |
|
Company data |
Chamber of Commerce (KvK) extract |
|
Financial products |
DUO student debt overview |
|
Property data |
Purchase agreement, valuation report |
|
2. Data subjects
- The client(s) for whom the mortgage application is in progress at Controller;
- The (former) partners, (former) spouses and/or (step)children of the client(s) for whom the mortgage application is submitted by Controller;
- Persons named on the documents, such as signatories on behalf of employers, notaries, valuers, sellers, and owners, partners, shareholders and directors of companies;
- Other persons or legal entities involved in a mortgage application concerned, such as the chosen lender.
3. Processing purposes
(a) Automatically reading documents for further analysis and processing by Controller, including support and reprocessing of documents;
(b) Testing and improving the Software used in (a) above, under the conditions of clause 2.8 of this data processing agreement.
Explanatory note: Controller may refuse use for purpose (b) at any time by email; the data are then used for purpose (a) only.
4. Retention periods
- Through the API: up to one hour after processing has finished;
- At Processor: for the term of the Agreement, unless Controller requests deletion earlier (clause 2.5);
- After the End of the Agreement: until Controller requests deletion or return, and for no more than twelve months (clause 5.3).
Data Processing Agreement Annex B: Sub-processors
Smart Backoffice Solutions B.V. uses the following sub-processors:
| Sub-processor | Service | Location of the data |
|---|---|---|
Microsoft Ireland Operations Limited (Microsoft Azure) |
Hosting of the Software, storage of documents and results, database, Azure AI Document Intelligence and Azure OpenAI |
Data centres in the Netherlands (West Europe), Ireland (North Europe, for back-ups) and Sweden (Sweden Central). Azure OpenAI processes data exclusively within Microsoft’s EU Data Zone. |
Data Processing Agreement Annex C: Technical and organisational security measures
1. Our technical security measures include, among others:
- Encryption of transmitted data (TLS 1.2 or higher) and of stored data;
- Access controls including Multi-Factor Authentication for administrators; the Software accesses other Azure services with a managed identity, without stored passwords;
- A separate API key for each customer, stored by Processor only as a hash; each customer has access only to its own documents;
- Extraction results can be retrieved through the API for only one hour after processing, so a leaked API key is worth little;
- For each document type the API returns only the fields needed for the purpose; for an identity document, for example, only whether the citizen service number is visible, not the number itself;
- Regular back-ups of the database to be able to restore data in the event of data loss or a breach;
- A platform managed and kept up to date by Microsoft, and software libraries pinned to fixed versions that are updated deliberately;
- Monitoring of the Software with automatic alerts on abnormal failure rates.
2. Our organisational security measures include, among others:
- Clear policy on access to data for employees;
- All employees are bound to confidentiality;
- Only purchasing services from sub-processors with excellent credentials in the field of GDPR and data security, such as Microsoft Azure;
- Regular evaluations of security protocols;
- Privacy by design: integrating principles of organisational data protection into the design and development of products and services from the outset.