Last updated: 22 September 2026
Data Processing Agreement
This Data Processing Agreement ("DPA") is entered into between Bkody Software ("Zinevu", "Processor"), registered with the Dutch Chamber of Commerce under KVK number 71881832, and the customer who has accepted the Terms of Service ("Controller"). This DPA forms part of and is incorporated into the Terms of Service.
This DPA applies where the Controller uses Zinevu to process personal data of the Controller's own customers, leads, or employees within the meaning of the General Data Protection Regulation (EU) 2016/679 ("GDPR").
1. Definitions
Terms not otherwise defined here have the meanings given in the GDPR. In particular:
- "Personal Data" means any data as defined in GDPR Article 4(1) that the Controller uploads or stores within the Zinevu platform ("Platform").
- "Processing" has the meaning given in GDPR Article 4(2).
- "Sub-processor" means any third party engaged by the Processor to process Personal Data on behalf of the Controller.
- "Services" means the cloud-based SaaS platform described in the Terms of Service.
2. Subject matter and duration
The Processor will process Personal Data on behalf of the Controller solely to provide the Services as described in the Terms of Service. Processing will begin when the Controller first uploads or stores Personal Data in the Platform and will continue for the duration of the subscription. Upon termination, the Processor will handle Personal Data as set out in clause 9.
3. Nature and purpose of processing
The Processor processes Personal Data for the following purposes and no others:
- Storing and displaying customer contact records within the CRM module;
- Generating and storing sales quotations and proposals;
- Managing project records and scheduling;
- Processing and storing invoices;
- Providing the 3D product configurator and associated customer-facing workflows;
- Enabling the Controller to manage planning and field service assignments;
- Providing technical support and troubleshooting at the Controller's request.
4. Types of personal data
The Personal Data processed under this DPA may include:
- Name, email address, phone number and postal address of end customers;
- Company name and VAT number;
- Purchase history, quotations and invoice data;
- Communication records between the Controller and their customers;
- Any other data the Controller chooses to store in the Platform's free-text fields.
The Controller is responsible for ensuring that no special categories of personal data (GDPR Article 9) are uploaded to the Platform unless separately agreed in writing.
5. Categories of data subjects
Data subjects whose Personal Data may be processed include: the Controller's end customers (individuals and business contacts), leads and prospects, and the Controller's own employees where their data is entered into the Platform.
6. Obligations of the Processor
The Processor agrees to:
- Process Personal Data only on documented instructions from the Controller (including as set out in this DPA and the Terms of Service), unless required to do so by EU or member state law;
- Ensure that authorised personnel are bound by appropriate confidentiality obligations;
- Implement technical and organisational measures appropriate to the risk, as described in clause 7;
- Comply with the conditions for engaging Sub-processors set out in clause 8;
- Assist the Controller in responding to requests from data subjects exercising their GDPR rights, to the extent technically feasible and at the Controller's cost;
- Assist the Controller in complying with its obligations under GDPR Articles 32–36 (security, breach notification, data protection impact assessments and prior consultation) to the extent reasonably possible given the nature of the processing;
- Notify the Controller without undue delay (and in any case within 48 hours) upon becoming aware of a personal data breach affecting Personal Data;
- Make available to the Controller all information necessary to demonstrate compliance with GDPR Article 28 and allow for and contribute to audits as provided in clause 10;
- Promptly inform the Controller if, in the Processor's opinion, an instruction infringes the GDPR or other applicable data protection law.
7. Security measures
The Processor has implemented the following technical and organisational measures to protect Personal Data:
- Encryption of data in transit using TLS 1.2 or higher;
- Encrypted storage of passwords and access tokens for connected services (such as calendars, accounting integrations, webhooks and WhatsApp);
- Role-based access controls limiting access to Personal Data to authorised personnel;
- Daily automated backups of the database and files;
- Infrastructure hosted by Hetzner Online GmbH in European Union data centres covered by its ISO/IEC 27001-certified information security management system;
- Vulnerability scanning and dependency monitoring;
- Internal access logs and anomaly detection.
8. Sub-processors
8.1 Authorisation
The Controller grants the Processor general authorisation to engage Sub-processors, subject to the conditions in this clause.
8.2 Current Sub-processors
The Processor currently uses the following Sub-processors for processing Personal Data:
| Sub-processor | Role | Location |
|---|---|---|
| Hetzner Online GmbH | Hosting of servers, databases and backups | EU |
| Cloudflare, Inc. | Content delivery (CDN), DNS and protection against attacks | Global network (US company, EU–US Data Privacy Framework) |
| Resend (Plus Five Five, Inc.) | Transactional email delivery, including offers and notifications for dealers without their own mail server | EU (Ireland) for sending; USA (EU–US Data Privacy Framework, standard contractual clauses) |
| OpenAI, Inc. / OpenAI Ireland Limited | Language model behind the AI assistant, only for dealers who switch that feature on. Processes, per turn, the messages in that one conversation, the company information the dealer supplied for it, and the questions of that dealer form. The data is not used to train models and is retained by OpenAI for at most 30 days for abuse monitoring. | USA (standard contractual clauses) |
| Stripe Inc. | Payment processing (billing data only) | USA |
8.3 Changes to Sub-processors
The Processor will inform the Controller of any intended changes to Sub-processors by updating this DPA and providing at least 14 days' prior written notice by email. If the Controller reasonably objects to a new Sub-processor on data protection grounds, the parties will work in good faith to resolve the objection; if no resolution is reached, the Controller may terminate the subscription without penalty.
8.4 Obligations on Sub-processors
The Processor will impose data protection obligations on each Sub-processor equivalent to those in this DPA (by contract or equivalent binding instrument) and remains liable to the Controller for Sub-processor performance.
9. International data transfers
Where Sub-processors are located outside the European Economic Area, the Processor will ensure that transfers comply with GDPR Chapter V by relying on:
- An adequacy decision by the European Commission; or
- Standard Contractual Clauses (SCCs) as approved by the European Commission; or
- The EU–US Data Privacy Framework where the Sub-processor is certified thereunder.
10. Audits
The Controller may, at its own expense and upon at least 30 days' prior written notice, audit the Processor's compliance with this DPA up to once per calendar year. The Controller may appoint a third-party auditor bound by confidentiality obligations. Before an audit takes place, the Processor will first make available the information necessary to demonstrate compliance, such as written answers to reasonable security questionnaires and relevant documentation. Where that information does not reasonably demonstrate compliance, the audit described above may proceed.
11. Return and deletion of data
Within 30 days of termination of the subscription, the Processor will, at the Controller's choice, either:
- Make available for export all Personal Data stored in the Platform in a standard machine-readable format; or
- Securely delete or anonymise all Personal Data.
The Processor will retain Personal Data beyond 30 days only to the extent required by applicable law, and only for the minimum period required.
12. Liability
Each party's liability under this DPA is subject to the limitations and exclusions set out in the Terms of Service. Nothing in this DPA limits either party's liability to data subjects or supervisory authorities under the GDPR.
13. Priority
In the event of a conflict between this DPA and the Terms of Service, this DPA prevails to the extent the conflict relates to the processing of Personal Data.
14. Governing law
This DPA is governed by the laws of the Netherlands. The parties submit to the exclusive jurisdiction of the competent courts in Amsterdam, the Netherlands.
15. Contact
Bkody Software (trading as Zinevu)
KVK: 71881832
Email: [email protected]