Last updated: 11 August 2026
Data Processing Agreement
This Data Processing Agreement ("DPA") is entered into between Bkody Software ("Zinevu", "Processor"), registered with the Dutch Chamber of Commerce under KVK number 71881832, and the customer who has accepted the Terms of Service ("Controller"). This DPA forms part of and is incorporated into the Terms of Service.
This DPA applies where the Controller uses Zinevu to process personal data of the Controller's own customers, leads, or employees within the meaning of the General Data Protection Regulation (EU) 2016/679 ("GDPR").
1. Definitions
Terms not otherwise defined here have the meanings given in the GDPR. In particular:
- "Personal Data" means any data as defined in GDPR Article 4(1) that the Controller uploads or stores within the Zinevu platform ("Platform").
- "Processing" has the meaning given in GDPR Article 4(2).
- "Sub-processor" means any third party engaged by the Processor to process Personal Data on behalf of the Controller.
- "Services" means the cloud-based SaaS platform described in the Terms of Service.
2. Subject matter and duration
The Processor will process Personal Data on behalf of the Controller solely to provide the Services as described in the Terms of Service. Processing will begin when the Controller first uploads or stores Personal Data in the Platform and will continue for the duration of the subscription. Upon termination, the Processor will handle Personal Data as set out in clause 9.
3. Nature and purpose of processing
The Processor processes Personal Data for the following purposes and no others:
- Storing and displaying customer contact records within the CRM module;
- Generating and storing sales quotations and proposals;
- Managing project records and scheduling;
- Processing and storing invoices;
- Providing the 3D product configurator and associated customer-facing workflows;
- Enabling the Controller to manage planning and field service assignments;
- Providing technical support and troubleshooting at the Controller's request.
4. Types of personal data
The Personal Data processed under this DPA may include:
- Name, email address, phone number and postal address of end customers;
- Company name and VAT number;
- Purchase history, quotations and invoice data;
- Communication records between the Controller and their customers;
- Any other data the Controller chooses to store in the Platform's free-text fields.
The Controller is responsible for ensuring that no special categories of personal data (GDPR Article 9) are uploaded to the Platform unless separately agreed in writing.
5. Categories of data subjects
Data subjects whose Personal Data may be processed include: the Controller's end customers (individuals and business contacts), leads and prospects, and the Controller's own employees where their data is entered into the Platform.
6. Obligations of the Processor
The Processor agrees to:
- Process Personal Data only on documented instructions from the Controller (including as set out in this DPA and the Terms of Service), unless required to do so by EU or member state law;
- Ensure that authorised personnel are bound by appropriate confidentiality obligations;
- Implement technical and organisational measures appropriate to the risk, as described in clause 7;
- Comply with the conditions for engaging Sub-processors set out in clause 8;
- Assist the Controller in responding to requests from data subjects exercising their GDPR rights, to the extent technically feasible and at the Controller's cost;
- Assist the Controller in complying with its obligations under GDPR Articles 32–36 (security, breach notification, data protection impact assessments and prior consultation) to the extent reasonably possible given the nature of the processing;
- Notify the Controller without undue delay (and in any case within 48 hours) upon becoming aware of a personal data breach affecting Personal Data;
- Make available to the Controller all information necessary to demonstrate compliance with GDPR Article 28 and allow for and contribute to audits as provided in clause 10;
- Promptly inform the Controller if, in the Processor's opinion, an instruction infringes the GDPR or other applicable data protection law.
7. Security measures
The Processor has implemented the following technical and organisational measures to protect Personal Data:
- Encryption of data in transit using TLS 1.2 or higher;
- Encryption of data at rest on all storage systems;
- Role-based access controls limiting access to Personal Data to authorised personnel;
- Regular automated backups with point-in-time recovery;
- Infrastructure hosted on Vercel and Railway, which maintain SOC 2 Type II certification and ISO 27001 aligned controls;
- Vulnerability scanning and dependency monitoring;
- Internal access logs and anomaly detection.
8. Sub-processors
8.1 Authorisation
The Controller grants the Processor general authorisation to engage Sub-processors, subject to the conditions in this clause.
8.2 Current Sub-processors
The Processor currently uses the following Sub-processors for processing Personal Data:
| Sub-processor | Role | Location |
|---|---|---|
| Vercel Inc. | Application hosting and edge delivery | USA (EU region available) |
| Railway Corp. | Background worker and database hosting | USA |
| Stripe Inc. | Payment processing (billing data only) | USA |
8.3 Changes to Sub-processors
The Processor will inform the Controller of any intended changes to Sub-processors by updating this DPA and providing at least 14 days' prior written notice by email. If the Controller reasonably objects to a new Sub-processor on data protection grounds, the parties will work in good faith to resolve the objection; if no resolution is reached, the Controller may terminate the subscription without penalty.
8.4 Obligations on Sub-processors
The Processor will impose data protection obligations on each Sub-processor equivalent to those in this DPA (by contract or equivalent binding instrument) and remains liable to the Controller for Sub-processor performance.
9. International data transfers
Where Sub-processors are located outside the European Economic Area, the Processor will ensure that transfers comply with GDPR Chapter V by relying on:
- An adequacy decision by the European Commission; or
- Standard Contractual Clauses (SCCs) as approved by the European Commission; or
- The EU–US Data Privacy Framework where the Sub-processor is certified thereunder.
10. Audits
The Controller may, at its own expense and upon at least 30 days' prior written notice, audit the Processor's compliance with this DPA up to once per calendar year. The Controller may appoint a third-party auditor bound by confidentiality obligations. The Processor may satisfy audit requests by providing a current SOC 2 Type II report or equivalent third-party audit report in lieu of granting direct access.
11. Return and deletion of data
Within 30 days of termination of the subscription, the Processor will, at the Controller's choice, either:
- Make available for export all Personal Data stored in the Platform in a standard machine-readable format; or
- Securely delete or anonymise all Personal Data.
The Processor will retain Personal Data beyond 30 days only to the extent required by applicable law, and only for the minimum period required.
12. Liability
Each party's liability under this DPA is subject to the limitations and exclusions set out in the Terms of Service. Nothing in this DPA limits either party's liability to data subjects or supervisory authorities under the GDPR.
13. Priority
In the event of a conflict between this DPA and the Terms of Service, this DPA prevails to the extent the conflict relates to the processing of Personal Data.
14. Governing law
This DPA is governed by the laws of the Netherlands. The parties submit to the exclusive jurisdiction of the competent courts in Amsterdam, the Netherlands.
15. Contact
Bkody Software (trading as Zinevu)
KVK: 71881832
Email: [email protected]