This data processing agreement ("DPA") governs the processing of personal data that Bryntra B.V. carries out as a processor on behalf of its customers, and contains the arrangements required by Article 28(3) GDPR. It forms an integral and binding part of the terms of service and therefore applies automatically to every customer from the moment Bryntra processes personal data on that customer's behalf. Separate signature is not required; on request via support@bryntra.com Bryntra will provide a copy signed by it for the Customer's records. This document is an English translation of the Dutch verwerkersovereenkomst; in the event of any discrepancy, the Dutch version prevails.
Processor: Bryntra B.V., Visbystraat 9, 7418 BE Deventer, the Netherlands · Chamber of Commerce (KvK) 42133268 · VAT idNL869871456B01
Controller: the Customer, as defined in the terms of service
Version 2.0 — adopted and published on 21 August 2026. Capitalised terms have the meaning given in the terms of service; terms such as "personal data", "processing", "data subject" and "personal data breach" have the meaning given in the GDPR.
Article 1 — Parties, status and precedence
- 1.1For the processing of personal data forming part of Customer Data, the Customer is the controller and Bryntra is the processor within the meaning of Article 4 GDPR.
- 1.2This DPA applies to all processing of personal data that Bryntra carries out on behalf of the Customer in the context of the Agreement, including during the Trial Period.
- 1.3In the event of conflict between this DPA and the other parts of the Agreement, this DPA prevails insofar as the processing of personal data is concerned.
- 1.4Processing for which Bryntra itself is the controller (such as account and billing data) falls outside this DPA; it is governed by the privacy policy.
Article 2 — Subject-matter and duration of the processing
- 2.1Bryntra processes personal data exclusively for the provision of the Service to the Customer. The subject-matter, nature and purpose of the processing, the types of personal data and the categories of data subjects are specified in Annex 1.
- 2.2The processing lasts for as long as the Agreement continues, plus the period for return and deletion referred to in Article 11.
- 2.3The Service is not designed for the processing of special categories of personal data (Art. 9 GDPR), data relating to criminal convictions (Art. 10 GDPR) or national identification numbers (such as the Dutch BSN). The Customer ensures that such data is not stored in the Service; if the Customer nevertheless processes such data, it does so at its own expense and risk.
Article 3 — Processing on documented instructions
- 3.1Bryntra processes personal data only on documented instructions from the Customer, unless Union or Member State law to which Bryntra is subject requires processing. In that case, Bryntra informs the Customer of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.
- 3.2Documented instructions include in any event: this DPA, the other parts of the Agreement, and the configuration of and actions within the Service by the Customer and its Users (including sending documents, managing data and using the export and deletion functions).
- 3.3Bryntra immediately informs the Customer if, in its opinion, an instruction infringes the GDPR or other applicable data protection provisions. Bryntra may suspend the execution of such an instruction until it has been confirmed or amended.
- 3.4Bryntra does not process the personal data for its own purposes, does not sell it and does not use it to train AI models.
Article 4 — Confidentiality of personnel
- 4.1Bryntra ensures that the persons authorised to process personal data have committed themselves to confidentiality by contract or are under an appropriate statutory obligation of confidentiality.
- 4.2Access to personal data is limited to persons for whom that access is necessary for the performance of their role (need-to-know) and is revoked as soon as that necessity lapses.
Article 5 — Security (Article 32 GDPR)
- 5.1Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing, Bryntra implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk. The current measures are described in Annex 2.
- 5.2Bryntra may update and improve the measures, provided the level of security is not materially reduced.
- 5.3The Customer is itself responsible for security on the customer side, including the management of Accounts and roles, password hygiene, whether or not two-factor authentication is enforced within the Workspace, and the devices with which Users access the Service.
Article 6 — Sub-processors
- 6.1The Customer hereby grants Bryntra general written authorisation within the meaning of Article 28(2) GDPR to engage sub-processors. The sub-processors engaged as at the effective date of this version are listed in Annex 3.
- 6.2Bryntra imposes on each sub-processor, by contract, the same data protection obligations as set out in this DPA, including the provision of sufficient guarantees regarding appropriate technical and organisational measures. Bryntra remains fully liable to the Customer for the performance of the sub-processor's obligations.
- 6.3Bryntra informs the Customer at least thirty (30) days before the intended addition or replacement of a sub-processor, by e-mail or through the Service. The Customer may object within that period, in writing and on reasonable grounds relating to data protection.
- 6.4In the event of a timely objection, the parties will consult on a reasonable solution. If the consultation does not lead to a solution within thirty (30) days, the Customer may terminate the Agreement with effect from the date on which the change takes effect; prepaid fees for the period after termination will be refunded.
Article 7 — Transfers outside the EEA
- 7.1Customer Data is stored within the European Union.
- 7.2Transfers of personal data to a country outside the European Economic Area take place only in accordance with Chapter V GDPR, on the basis of an adequacy decision of the European Commission (including the EU-US Data Privacy Framework for recipients certified under it) and/or the European Commission's Standard Contractual Clauses, supplemented where necessary by additional measures. The mechanism used per sub-processor is stated in Annex 3.
Article 8 — Assistance to the Customer
- 8.1Data subject rights. Taking into account the nature of the processing, Bryntra assists the Customer with appropriate technical and organisational measures in fulfilling the Customer's obligation to respond to data subject requests (Articles 15 to 22 GDPR). To that end the Service contains built-in access, export, correction and deletion functions. If Bryntra receives a request from a data subject directly that relates to Customer Data, Bryntra forwards it to the Customer without delay and does not respond substantively, except where legally required.
- 8.2DPIA and prior consultation. Bryntra provides the Customer with reasonable assistance in carrying out a data protection impact assessment (Art. 35 GDPR) and any prior consultation of the supervisory authority (Art. 36 GDPR), insofar as these relate to the processing under this DPA.
- 8.3Assistance under this article that goes beyond the use of the functions built into the Service and requires more than negligible effort may be charged by Bryntra at reasonable, previously communicated rates, unless the need for assistance is attributable to Bryntra.
Article 9 — Personal data breaches
- 9.1Bryntra informs the Customer without undue delay — aiming for no later than 48 hours — after becoming aware of a personal data breach affecting Customer Data.
- 9.2The notification contains, insofar as known at that time, at least: the nature of the breach, the (categories of) data subjects and personal data records concerned and an estimate of the numbers, the likely consequences, the measures taken and proposed, and contact details for further information. Information not yet available is provided in phases as it becomes available.
- 9.3Assessing whether the breach must be notified to the supervisory authority (Art. 33 GDPR) or to data subjects (Art. 34 GDPR), and making those notifications, are and remain the Customer's responsibility. Bryntra does not itself notify the supervisory authority or data subjects on the Customer's behalf, unless the parties agree so in writing or Bryntra is legally required to do so.
- 9.4Bryntra documents breaches and the measures taken, and provides the Customer with the cooperation it reasonably needs for its own notification obligations and record-keeping.
Article 10 — Accountability and audits
- 10.1On written request, Bryntra makes available to the Customer all information reasonably necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR, including a description of the measures taken and relevant (summaries of) reports and certifications of sub-processors.
- 10.2If the information provided is demonstrably insufficient, the Customer may have an audit carried out at most once every twelve (12) months, by itself or by an independent expert appointed by the Customer who is not a competitor of Bryntra and who commits to confidentiality towards Bryntra.
- 10.3An audit is announced in writing at least thirty (30) days in advance, takes place during office hours, disrupts business operations and the Service as little as possible, and does not extend to data of or about other customers of Bryntra. The costs of the audit are borne by the Customer, unless the audit reveals material shortcomings on Bryntra's part.
- 10.4Audit findings are confidential. The parties discuss the findings; substantiated findings are addressed by Bryntra within a reasonable period.
Article 11 — End of the agreement: return and deletion
- 11.1Throughout the term and until thirty (30) days after the end of the Agreement, the Customer can independently export all Customer Data in a common, machine-readable format using the Service's export function. Return of personal data is thus effected by means of this export.
- 11.2After the period referred to in Article 11.1, Bryntra permanently deletes all personal data in the Workspace from the production systems, after which it also rotates out of the backups within the regular backup cycle. At the Customer's written request, deletion takes place earlier.
- 11.3On request, Bryntra confirms the deletion in writing.
- 11.4Bryntra may retain personal data for longer insofar as Union or Member State law requires it to do so; in that case the safeguards of this DPA continue to apply to that data.
Article 12 — Liability
- 12.1Liability under this DPA is governed mutatis mutandis by the liability arrangement of the terms of service (Article 18), insofar as mandatory law — including Article 82 GDPR — does not preclude this.
- 12.2Each party is liable towards data subjects in accordance with the allocation of Article 82 GDPR. Fines imposed on a party for an infringement attributable to that party remain for that party's account.
Article 13 — Final provisions
- 13.1Amendment of this DPA follows the procedure for amending the terms of service (announcement of material changes at least thirty (30) days in advance). Bryntra ensures that amendments do not lead to a lower level of protection for data subjects.
- 13.2This DPA is governed by Dutch law; disputes are submitted to the court designated in the terms of service.
- 13.3This DPA remains in force for as long as Bryntra processes personal data on behalf of the Customer, even if the Agreement has otherwise ended.
Annex 1 — Specification of the processing
- A1.1Subject-matter and nature of the processing:hosting, storing, structuring, displaying, transmitting (including sending quotes, invoices and notifications by e-mail to the Customer's relations), backing up, securing and otherwise processing Customer Data, as well as processing Customer Data on a per-request basis in AI features initiated by the Customer.
- A1.2Purpose of the processing: exclusively the provision of the Service as described in the Agreement and configured by the Customer.
- A1.3Duration: the term of the Agreement, plus the period of Article 11.
- A1.4Categories of data subjects: (i) customers, leads and prospects of the Customer and their contact persons; (ii) employees, Users and auxiliary persons of the Customer; (iii) other persons whose data is entered into the Service by or on behalf of the Customer.
- A1.5Types of personal data: name, address and contact details (name, address, e-mail address, phone number); company and role data; commercial and financial data in quotes, orders, invoices and payment statuses (including chamber-of-commerce and VAT numbers of relations); planning and work-order data (appointments, locations, notes, photos of project locations); signature data from e-signing (signature image, timestamp, technical metadata); account data of Users (name, e-mail address, role); the content of communications sent through the Service.
Annex 2 — Technical and organisational measures
- Encryption: all transport via TLS; data and backups stored encrypted (encryption at rest); passwords exclusively as cryptographic hashes.
- Logical separation: every Workspace is separated at the database level through row-level security, enforced by the database itself.
- Access control: role-based access following the least-privilege principle; two-factor authentication available for all Accounts and enforceable per Workspace; mandatory two-factor authentication and personal accounts for Bryntra's platform administration; access by Bryntra personnel to production data limited to what is necessary and logged.
- Logging and monitoring: audit logging of sensitive actions (who, what, when); technical monitoring and error reporting; security logs.
- Continuity: daily encrypted backups within the EU; recovery procedures; redundant infrastructure with European hosting providers.
- Development process: separation of development, test and production environments; review of changes; the "money path" (amounts, VAT, numbering) exclusively through deterministic, tested software.
- Data minimisation in AI features: processing on a per-request basis only; no use of Customer Data for model training.
- Vulnerability management: responsible-disclosure process via support@bryntra.com; timely security updates.
- Built-in GDPR functions: export and deletion functions for workspace owners (Settings → Data & privacy).
- Personnel: contractual confidentiality; access on a need-to-know basis; termination of access upon departure.
Annex 3 — Sub-processors
The following sub-processors are engaged as at the date of this version. Changes are announced in accordance with Article 6.3.
| Sub-processor | Processing | Processing location | Transfer mechanism |
|---|---|---|---|
| Supabase | database, authentication, file storage | EU (Ireland); US parent company | EU-US DPF and/or SCCs |
| Vercel | application hosting | EU region (Dublin); US parent company | EU-US DPF and/or SCCs |
| Stripe | payment processing and subscription management | EU and US | EU-US DPF and/or SCCs |
| Resend | sending transactional e-mail on behalf of the Customer and Bryntra | US | EU-US DPF and/or SCCs |
| Cloudflare | bot protection on public forms (Turnstile) | EU and US | EU-US DPF and/or SCCs |
| Mapbox | address autocomplete (only the address typed) | US | SCCs |
| OpenRouter | routing of Customer-initiated AI requests to AI models | US | SCCs |
| Sentry | error reporting (technical logs) | EU and US | EU-US DPF and/or SCCs |
Contact
Questions about this DPA or about data processing can be addressed to support@bryntra.com.