General Terms and Conditions for Mortgage Documents of Smart Backoffice Solutions B.V.

Version dated 14 September 2026

The parties to these General Terms and Conditions are:

A. Smart Backoffice Solutions B.V., established and having its office at Saal van Zwanenbergweg 11, 5026 RM Tilburg, the Netherlands, registered with the Chamber of Commerce under number 90141482, hereinafter referred to as ‘Provider’; and

B. The business or organisation that has concluded an agreement for Mortgage Documents with Provider, or that uses Mortgage Documents without a written agreement, for example during a Trial, hereinafter referred to as ‘Customer’.

Provider and Customer are hereinafter jointly referred to as the Parties and each individually as a Party.

Whereas:

Have agreed as follows:

1. Definitions:

1.1. Agreement: the agreement concluded between the Parties with regard to the Software that Customer purchases from Provider. If the Parties have not concluded a written agreement, as during a Trial, the use of the Software constitutes the Agreement.

1.2. User: A natural person authorised by Customer to use the Software on behalf of Customer.

1.3. Trial: use of the Software, whether or not free of charge, without a written agreement or pending one, for example to test the Software with one’s own documents. During a Trial these General Terms and Conditions and the Data Processing Agreement apply in full. Clause 4 and clauses 5.1 to 5.4 apply during a Trial only insofar as the Parties have agreed rates or a contract term.

1.4. End of the Agreement: the moment at which the Agreement ends. For a Trial this is the earliest of the following: Provider revokes Customer’s API key; Customer informs Provider by email that it is stopping; or six months have passed since Customer last submitted a document.

2. Access to and use of the Software:

2.1. Provider grants Customer a non-exclusive and non-transferable right to access and use the Software.

2.2. Customer may designate and authorise users to access and use the Software on behalf of Customer. Customer is responsible for the actions and compliance of these users.

2.3. Customer is responsible for the careful handling of and access to the Software, and for the careful handling of the login credentials and API keys for the Software by its users. Customer indemnifies Provider against claims by third parties for damage caused by careless conduct by its users with regard to access and access credentials to the Software.

2.4. Customer is itself responsible for ensuring that the personal data provided to Provider for processing comply with the applicable data protection laws and regulations, including the General Data Protection Regulation (‘GDPR’).

2.5. Customer agrees not to:

3. Functionality:

3.1. The functionality offered by Provider comprises

3.2. Provider aims for an availability of 98%. This availability is defined as the percentage of the total number of hours during which the Software is available for use by Customer. This total number of hours is calculated as the sum of the hours between Monday and Friday, 9:00 to 17:00, excluding:

3.3. Provider is not liable for damage caused by force majeure or by unforeseen circumstances over which it has no influence. Force majeure includes, among other things, an internet outage, epidemic, war, natural disaster or strike.

3.4. Provider offers support in the event of a Defect in what has been supplied, provided the Defect is demonstrable and/or reproducible. Defect means the failure to comply, or to comply fully, with the functionality as described in these General Terms and Conditions.

3.5. Customer shall inform Provider within a period of two weeks of a Defect in a supply, or of a shortcoming in the performance of the Agreement. If a Defect or shortcoming has not been raised within two weeks, Provider’s liability in this respect lapses.

3.6. The Software processes one document per call. Extraction results can be retrieved through the API for one hour after processing has finished; after that the API no longer returns them. Customer retrieves results in time and stores them itself.

4. Rates and invoicing

4.1. Provider may increase rates once per calendar year by a maximum of 5%. Customer will be informed of this in good time. An annual rate increase does not give the right to terminate the Agreement early.

4.2. Periodic payments are due in advance of the period concerned. ‘Overuse’ rates are invoiced periodically (monthly or quarterly) in arrears.

5. Term and termination of the Agreement:

5.1. On expiry of the contract term stated in the Agreement, the Agreement is automatically renewed for the same term.

5.2. Customer may terminate the agreement with Provider subject to a notice period of three calendar months before the end of the contract term.

5.3. If Customer has not used the Software for one continuous period of six months, Provider has the right to terminate the Agreement unilaterally. Provider will draw Customer’s attention to this, after which, following a ‘grace period’ of a further two months without use, the Agreement may be terminated by Provider.

5.4. Delivery and payment obligations continue to apply until the end of the contract term of a (terminated) Agreement.

5.5. After termination, the right to access and use the Software lapses. What happens after the End of the Agreement to documents and data uploaded to the Software by Customer, and to the extraction results, is governed by clause 5.3 of the Data Processing Agreement.

5.6. In the event of an application for a suspension of payments, a declaration of bankruptcy or the discontinuation of the business, the Agreement may be terminated without observing a notice period. If Provider terminates the Agreement in these cases, there is no right to a refund of monies already received or to (damages) compensation.

5.7. Unless stipulated otherwise, upon termination of the Agreement the arrangements in these General Terms and Conditions which by their nature are intended to continue after termination of the Agreement remain in full force.

6. Intellectual property rights

6.1. Provider and any licensor(s) of Provider own all intellectual property rights in Provider’s supplies (including all software, databases, manuals, quotations and websites). All intellectual property therein remains with Provider and any licensor(s) of Provider.

6.2. Content (data, documents) uploaded by Customer to Provider’s applications and Software is and remains the property of Customer. Customer grants Provider the right to use the content to perform these General Terms and Conditions and, under the conditions of clause 2.8 of the Data Processing Agreement, to test and improve the Software.

6.3. Provider indemnifies Customer against any claims by third parties for an infringement of intellectual property rights through the use of Provider’s Software. This is on condition that these claims are not (partly) the result of Customer’s own wrongful conduct. Customer shall also (at its own expense) cooperate fully with Provider in order to be able to refute any claims.

7. Confidentiality and data security

7.1. Both parties agree to confidentiality and secrecy with regard to proprietary or confidential information which they receive from the other Party during the formation and the term of the Agreement. Neither party will share or transfer data or information concerning each other’s business operations, software, services, etc. to other parties, not even after the termination of an Agreement.

7.2. The duty of confidentiality also applies to all natural persons and legal entities with which the Parties are affiliated. If it is necessary to engage an external party for the proper performance of these General Terms and Conditions, it is permitted to share data and knowledge with the external Party provided that it undertakes confidentiality in writing in advance.

8. Liability

8.1. Provider is never responsible for any damage suffered as a result of an incorrectly read or analysed document. Customer is and remains itself responsible for a correct analysis of the documents and files uploaded to the Software. Customer acknowledges that the Software is merely a tool for the analysis and assessment of documents, and that the responsibility for a correct assessment of documents remains with Customer.

8.2. Without prejudice to mandatory statutory provisions, Provider’s liability for direct or indirect damage is limited to the amount paid out under Provider’s general liability insurance and/or professional liability insurance, and, if the general liability insurance and/or professional liability insurance does not apply or does not pay out, to one time the invoice value of Customer’s most recent 12 calendar months.

9. Non-solicitation of employees clause: During an Agreement and for a period of one year following a terminated Agreement, it is not permitted to have employees of Provider, directly or indirectly, perform work for Customer without the prior written consent of Provider. In the event of a breach of this clause, an immediately payable penalty of €50,000 per breach applies.

10. Other arrangements

10.1. These arrangements, and all non-contractual rights and obligations arising from them, are governed in all respects by Dutch law. All disputes between the Parties which may arise in connection with these arrangements, or with arrangements resulting from them, shall in the first instance be settled by the court in whose district Provider has its place of business.

10.2. All changes to these General Terms and Conditions will be communicated to Customer by email.

10.3. Provider is entitled to amend these General Terms and Conditions unilaterally. In that case, Provider will inform Customer of the changes in good time. There will be at least one month between this notification and the entry into force of the amended terms. If the change results in Customer being provided with a performance that differs materially from the original performance and Provider cannot offer a suitable solution for this, Customer has the power to dissolve the Agreement as of the date on which the amended terms enter into force.

10.4. If one or more provisions of these General Terms and Conditions prove not to be legally valid in this agreement or the accompanying annexes, these General Terms and Conditions and the annexes will otherwise remain in force. The Parties will consult on the provisions that are not legally valid in order to agree a replacement arrangement that is legally valid and corresponds as closely as possible to the purport of the provision to be replaced.

The following annexes form part of these General Terms and Conditions:

Data Processing Agreement with annexes

Annex: Data Processing Agreement

The parties to this data processing agreement are:

A. Smart Backoffice Solutions B.V., established and having its office at Saal van Zwanenbergweg 11, 5026 RM Tilburg, the Netherlands, registered with the Chamber of Commerce under number 90141482, hereinafter referred to as ‘Processor’; and

B. The business or organisation that has concluded an agreement for Mortgage Documents with Processor, or that uses Mortgage Documents without a written agreement, for example during a Trial, hereinafter referred to as ‘Controller’.

Processor and Controller are hereinafter jointly referred to as the Parties and each individually as a Party.

Whereas:

Have agreed as follows:

1. Definitions:

1.1. Controller: The entity (a natural or legal person, a service, public authority or other organisation) that determines the purposes and means of the processing of personal data.

1.2. Processor: The entity (a natural or legal person, a service, public authority or other organisation) that processes personal data on behalf of Controller.

1.3. Data Subject: The person whose personal data are processed, usually a client of Controller.

1.4. Personal Data: Any information relating to an identified or identifiable natural person.

1.5. Processing: Any operation or set of operations performed on personal data. This includes but is not limited to the collection, recording, storage, alteration, retrieval, consultation, use, disclosure and erasure of data.

1.6. Sub-processor: Any external service provider or subcontractor engaged by Processor to assist with data processing, under the terms of this data processing agreement.

1.7. Data breach: A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.

2. Purpose and scope of the processing:

2.1. Processor processes personal data only on documented instructions from Controller. This data processing agreement, the General Terms and Conditions and the submission of documents to the Software constitute those instructions. Processor processes the data only for the purposes described in annex A, and not for other purposes (its own purposes, or those of others). Testing and improving the Software (purpose (b) in annex A) takes place only under the conditions of clause 2.8.

2.2. Processor will only process categories of Personal Data described in annex A.

2.3. Processor will not share data with parties other than the sub-processors listed in annex B, unless Processor is required to do so by law. In that case Processor informs Controller in advance, unless the law prohibits this.

2.4. Processor will not edit or add data without the prior consent of Controller, other than the reading, checking and formatting of data that the Software performs as its service.

2.5. Processor retains submitted documents and the extraction results for the term of the Agreement, so that Processor can provide support, reprocess documents and, under the conditions of clause 2.8, test and improve the Software. Results can be retrieved through the API for one hour after processing has finished; after that the API no longer returns them. Controller may at any time request in writing (an email suffices) that some or all documents and results be deleted; Processor carries out such a request within one month. Processor may also delete documents and results earlier.

2.6. Processor will not store or process data outside the European Economic Area (‘EEA’).

2.7. Controller is itself responsible for ensuring that the personal data provided to Processor for processing comply with the applicable data protection laws and regulations. This applies in particular to data concerning health and to the citizen service number (BSN), which appear on some documents (see annex A), and to informing data subjects about the processing, including the processing under clause 2.8.

2.8. Controller instructs and permits Processor to use submitted documents and extraction results also to test and improve the Software for all customers of the Software, for example by recording correct outcomes against which accuracy is measured, and by improving instructions and models. The following conditions apply: (i) only employees of Processor designated for this purpose have access; (ii) the data remain within the EEA and are processed only with the sub-processors listed in annex B; (iii) the data are not sold, not disclosed to third parties and not used to assess or contact data subjects. Controller may refuse or end this use at any time in writing (an email suffices). Processor then uses Controller’s data only for purpose (a) in annex A and removes them within one month from the datasets used to test and improve the Software. Improvements already made, such as revised instructions, remain. After the End of the Agreement, Processor no longer uses the data for this purpose.

3. Principles for data processing:

3.1. Processor will process personal data in accordance with all applicable data protection laws and regulations, including the GDPR.

3.2. All employees of Processor are bound to secrecy with regard to data made available by Controller of which they take note.

3.3. Processor immediately informs Controller if, in Processor’s opinion, an instruction infringes the GDPR or other data protection rules.

4. Sub-processing:

4.1. Processor has one or more sub-processors; these are listed in annex B. By using the Software, Controller agrees to the use of the services of these sub-processor(s) by Processor.

4.2. Controller gives Processor general written authorisation to engage sub-processors. Processor informs Controller by email at least one month in advance of any addition or replacement of a sub-processor. Controller may object on reasonable grounds within that period. If the Parties cannot find a solution, Controller may terminate the Agreement with effect from the date on which the change takes effect.

4.3. Processor imposes on sub-processors at least the same obligations as those set out in this data processing agreement, and verifies that these sub-processor(s) comply with them.

4.4. Processor remains fully liable to Controller for the performance of the obligations of the sub-processor.

5. Data security and storage

5.1. Processor implements appropriate technical and organisational measures to ensure the security and confidentiality of the personal data. See annex C for a list of some of these measures.

5.2. Processor notifies Controller of a Data breach without undue delay, and where possible within 48 hours after Processor becomes aware of it. Processor provides the information Controller needs to notify the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) and, where necessary, data subjects, and keeps Controller informed of the measures taken.

5.3. After the End of the Agreement, Processor retains Controller’s documents, extraction results and other personal data until Controller requests in writing (an email suffices) that they be deleted or returned. Return takes the form of an export of the extraction results in a common file format. Processor carries out such a request within one month and at the same time deletes all existing copies, unless applicable law requires storage. Without such a request, Processor deletes the data no later than twelve months after the End of the Agreement. Until then, Processor uses the data only to store them and to return them on request. Copies in back-ups expire with the normal back-up cycle.

5.4. Processor assists Controller in fulfilling its obligations under Articles 32 to 36 GDPR (security, notification of Data breaches, data protection impact assessment and prior consultation), taking into account the nature of the processing and the information available to Processor.

6. Audits and inspections

6.1. Processor makes available to Controller all information necessary to demonstrate compliance with the obligations laid down in this data processing agreement, and allows audits and inspections by Controller or an auditor authorised by Controller and reasonably cooperates with them.

6.2. Processor assists Controller in fulfilling its obligations to respond to requests from data subjects exercising their rights under the applicable data protection legislation.

7. Other provisions

7.1. Each Party is liable for its own breach of this data processing agreement and indemnifies the other Party against all damage arising from such a breach.

7.2. This agreement, and all non-contractual rights and obligations arising from it, are governed in all respects by Dutch law. All disputes between the Parties which may arise in connection with this agreement, or with agreements resulting from it, shall in the first instance be settled by the court in whose district Processor has its place of business.

7.3. All changes to this data processing agreement are communicated by Processor to Controller by email.

7.4. Processor is entitled to amend this data processing agreement unilaterally. In that case, Processor will inform Controller of the changes in good time. There will be at least one month between this notification and the entry into force of the amended terms. If the change results in Controller being provided with a performance that differs materially from the original performance and Processor cannot offer a suitable solution for this, Controller has the power to dissolve the Agreement as of the date on which the amended terms enter into force.

7.5. If one or more provisions of this agreement prove not to be legally valid, the agreement will otherwise remain in force. The Parties will consult on the provisions that are not legally valid in order to agree a replacement arrangement that is legally valid and corresponds as closely as possible to the purport of the arrangement to be replaced.

The following annexes form part of this data processing agreement:

Data Processing Agreement Annex A: Personal data processed and processing purposes

1. Personal data processed

Processor’s Software reads documents using OCR/AI techniques. Necessarily, this means that all legible data in these documents are processed, including data not listed in the table below, such as a passport photo or a signature on the document. The Software does not use a passport photo to recognise people.

If Controller wishes certain data on documents to be supplied not to be processed (such as the citizen service number, BSN), these data must be masked on the documents supplied.

The personal data processed differ per document. The table below indicates for each document category (i) which documents the Software processes and (ii) which personal data the Software extracts from them.

The total of personal data processed for a Controller is determined by the documents that Controller forwards to Processor’s Software for processing.

Document category Documents Personal data extracted

Identification documents

Passport, identity card

  • Surname, given names, date and place of birth, sex, nationality;
  • Type of document, document number, date of issue, expiry date and issuing authority;
  • The machine-readable zone, which on some documents contains the citizen service number. For the citizen service number the API returns only whether it is visible, not the number itself.

Income documents

Payslip, employer’s statement

  • Employee’s name, given names, date of birth and address; employer’s name, address and Chamber of Commerce number; name and telephone number of the signatory;
  • IBAN, job title, employment details, hours, salary and other income components, pension contribution and net pay;
  • Private loans through the employer and wage garnishment;
  • Data concerning health and leave, where the payslip shows sick pay, sick leave or parental leave;
  • Whether the citizen service number is visible.

Company data

Chamber of Commerce (KvK) extract

  • Trade name, legal form, KvK and RSIN numbers, SBI codes, start date;
  • Name, given names and role (such as owner, partner, shareholder or director) of the persons on the extract.

Financial products

DUO student debt overview

  • Borrower’s name, given names and address;
  • For each student loan the balance, interest, term, monthly payment and repayment rules;
  • Whether the citizen service number is visible.

Property data

Purchase agreement, valuation report

  • Buyers’ name, given names, date and place of birth, address, email address, telephone number and marital status; name and address of the clients who commissioned the valuation;
  • Data about the purchase such as purchase price, movable goods, transfer date, notary, bank guarantee and financing condition;
  • Data about the property such as address, market value, leasehold, homeowners’ association, energy label, sustainability and foundation.

2. Data subjects

3. Processing purposes

(a) Automatically reading documents for further analysis and processing by Controller, including support and reprocessing of documents;

(b) Testing and improving the Software used in (a) above, under the conditions of clause 2.8 of this data processing agreement.

Explanatory note: Controller may refuse use for purpose (b) at any time by email; the data are then used for purpose (a) only.

4. Retention periods

Data Processing Agreement Annex B: Sub-processors

Smart Backoffice Solutions B.V. uses the following sub-processors:

Sub-processor Service Location of the data

Microsoft Ireland Operations Limited (Microsoft Azure)

Hosting of the Software, storage of documents and results, database, Azure AI Document Intelligence and Azure OpenAI

Data centres in the Netherlands (West Europe), Ireland (North Europe, for back-ups) and Sweden (Sweden Central). Azure OpenAI processes data exclusively within Microsoft’s EU Data Zone.

Data Processing Agreement Annex C: Technical and organisational security measures

1. Our technical security measures include, among others:

2. Our organisational security measures include, among others: