Data Processing Agreement
Last updated: September 30, 2026.
This Data Processing Agreement (“DPA”) is between Bienvue Ltd. (“Bienvue”), and the organization that has accepted our Terms of Service (the “Customer”). It forms part of the Terms and takes effect when the Customer accepts them; it needs no signature. It applies whenever Bienvue processes Customer Personal Data on the Customer’s behalf. If the Customer needs a copy with its details filled in, write to [email protected].
If this DPA conflicts with the Terms, this DPA governs. If it conflicts with the Standard Contractual Clauses, the UK Addendum or the Swiss terms in section 12, those govern.
1. Definitions
- Data Protection Laws means every law on the processing of personal data that applies to the processing under this DPA, including the EU General Data Protection Regulation 2016/679 (“GDPR”), the GDPR as it forms part of UK law (“UK GDPR”) and the UK Data Protection Act 2018, the Swiss Federal Act on Data Protection (“FADP”), and the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA”).
- Customer Personal Data means personal data in content the Customer and its members put into the Service that Bienvue processes on the Customer’s behalf. It does not include data for which Bienvue is the controller, such as account, billing, security and website data, which our Privacy Policy covers.
- Subprocessor means another processor Bienvue engages to process Customer Personal Data.
- Standard Contractual Clauses or SCCs means the clauses annexed to European Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
- Controller, processor, data subject, personal data, personal data breach, processing and supervisory authority have the meanings the GDPR gives them, and the equivalent terms in other Data Protection Laws (such as business and service provider under the CCPA) are read accordingly.
2. The processing
The subject matter, duration, nature and purpose of the processing, and the types of personal data and categories of data subjects, are set out in Annex I. The Customer is the controller, or a processor acting for its own clients, and Bienvue is its processor or subprocessor.
3. Instructions
Bienvue processes Customer Personal Data only on the Customer’s documented instructions, including with regard to transfers to a third country, unless EU or member state law (or other law Bienvue is subject to) requires otherwise; in that case Bienvue tells the Customer of that requirement before processing, unless the law forbids it on important grounds of public interest. The Terms, this DPA and the Customer’s use and configuration of the Service are the Customer’s complete instructions; further instructions must be consistent with them and given in writing. Bienvue tells the Customer immediately if, in its opinion, an instruction infringes Data Protection Laws.
The Customer is responsible for the lawfulness of the processing it instructs, for its legal basis, and for informing the data subjects concerned.
4. Confidentiality
Bienvue ensures that everyone it authorizes to process Customer Personal Data has committed to confidentiality or is under an appropriate statutory obligation of confidentiality, and has access only as far as their work needs it.
5. Security
Bienvue implements the technical and organizational measures in Annex II to protect Customer Personal Data as Article 32 of the GDPR requires. Bienvue may change those measures as technology and risks change, provided the overall level of protection is not reduced.
6. Subprocessors
The Customer gives Bienvue general written authorization to engage Subprocessors. The Subprocessors in use are listed in Annex III. Bienvue will tell the Customer of any intended addition or replacement at least 30 days in advance, by updating Annex III and emailing the Customer’s owners, so the Customer can object. The Customer may object on reasonable data protection grounds by writing to [email protected] within that period. The parties will then discuss the objection in good faith; if they can’t resolve it, the Customer may end the affected part of the Service before the change and Bienvue will refund prepaid fees for the unused part of the billing period.
Bienvue imposes on each Subprocessor, by written contract, data protection obligations that give the same level of protection as this DPA, in particular sufficient guarantees of appropriate technical and organizational measures. Bienvue remains fully liable to the Customer for each Subprocessor’s performance of those obligations.
7. Data subject requests
Taking into account the nature of the processing, Bienvue assists the Customer by appropriate technical and organizational measures in responding to requests from data subjects to exercise their rights. The dashboard lets the Customer find, correct, delete and export Customer Personal Data itself. Where it can’t, Bienvue gives reasonable further help. If Bienvue receives a request about Customer Personal Data, it passes it to the Customer without undue delay and does not answer it other than to tell the requester to contact the Customer, unless the Customer authorizes it or the law requires otherwise.
8. Other assistance
Taking into account the nature of the processing and the information available to it, Bienvue assists the Customer in meeting its obligations under Articles 32 to 36 of the GDPR: security of processing, notifying personal data breaches, data protection impact assessments and prior consultation with a supervisory authority. This DPA, Annex II and the Privacy Policy provide the information Bienvue has for those purposes; further help can be requested at [email protected].
9. Personal data breaches
Bienvue notifies the Customer of a personal data breach affecting Customer Personal Data without undue delay, and in any event within 72 hours of becoming aware of it, by email to the Customer’s owners. The notice describes, as far as then known, the nature of the breach, the categories and approximate numbers of data subjects and records concerned, its likely consequences, the measures taken or proposed to address it, and a contact for more information. Where not all of this is known at once, Bienvue provides it in phases without further undue delay. Bienvue takes reasonable steps to contain the breach and limit its effects. Notifying a breach is not an admission of fault.
10. Deletion and return
At any time before its data is deleted, the Customer can export each property’s guide and photos from Settings. When the Customer deletes a property, an organization or its account, or the Terms end, Bienvue deletes Customer Personal Data on the schedule in the Privacy Policy: a deleted organization is permanently removed 30 days after deletion, and an archived property two months after it was archived. Copies in Bienvue’s point-in-time database recovery expire within 30 days after that. Bienvue keeps no copy after that unless the law requires it, in which case it keeps the data confidential and processes it only for that purpose.
11. Audits
Bienvue makes available to the Customer the information necessary to demonstrate compliance with Article 28 of the GDPR and this DPA, and allows for and contributes to audits, including inspections, by the Customer or an auditor it mandates. Audits start with documentation: this DPA, Annex II, the security documentation of Bienvue’s hosting provider (including its SOC 2 Type II report and ISO/IEC 27001 certificate), and Bienvue’s written answers to a reasonable security questionnaire, once a year. If that documentation is not enough to demonstrate compliance, or a supervisory authority requires it, the Customer may carry out an audit on at least 30 days’ written notice, no more than once in any 12 months (unless following a personal data breach or a supervisory authority’s request), during business hours, under a confidentiality agreement, without access to other customers’ data, and at the Customer’s cost. Audits under the SCCs are carried out in the same way.
12. International transfers
Bienvue is established in the United States and processes Customer Personal Data there and wherever its Subprocessors operate, as listed in Annex III.
EU Standard Contractual Clauses. To the extent a transfer of Customer Personal Data from the Customer to Bienvue is a transfer to a third country subject to the GDPR, the SCCs are incorporated into this DPA by reference and apply as follows, with the Customer as data exporter and Bienvue as data importer:
- Module Two (controller to processor) applies where the Customer is a controller, and Module Three (processor to processor) where the Customer is a processor.
- Clause 7 (docking clause) applies.
- Clause 9(a): Option 2, general written authorization, with the notice period in section 6 of this DPA (30 days).
- Clause 11(a): the optional independent dispute resolution language does not apply.
- Clause 13(a): the competent supervisory authority is the one set out in Annex I.C.
- Clause 17: Option 1; the SCCs are governed by the law of Ireland.
- Clause 18(b): disputes are resolved by the courts of Ireland.
- Annexes I, II and III of the SCCs are Annexes I, II and III of this DPA.
Where the SCCs require the Customer, under Module Three, to forward information to its own controller, Bienvue provides that information to the Customer.
United Kingdom. To the extent a transfer is subject to the UK GDPR, the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner under section 119A(1) of the Data Protection Act 2018 (version B1.0, in force 21 March 2022, the “UK Addendum”) is incorporated by reference. Its Table 1 is completed with the parties and details in Annex I.A; Table 2 with the modules and clause selections above; Table 3 with Annexes I to III; and in Table 4 both the importer and the exporter may end the UK Addendum as its Section 19 provides. Its Part 2 Mandatory Clauses apply.
Switzerland. To the extent a transfer is subject to the FADP, the SCCs apply as above with these changes: references to the GDPR are read as references to the FADP where the transfer is subject to it; the competent supervisory authority under Clause 13 is the Swiss Federal Data Protection and Information Commissioner; the term “member state” in Clause 18(c) does not prevent data subjects habitually resident in Switzerland from suing in Switzerland; and Clause 17 and Clause 18(b) remain as above.
If an authority or court finds a transfer mechanism in this section invalid, the parties will cooperate in good faith to put a valid one in place.
13. California service-provider terms
To the extent the CCPA applies to the Customer and Bienvue processes personal information on its behalf as a service provider:
- Bienvue processes personal information only for the business purposes of hosting and delivering the Customer’s guides, providing support, and securing the Service, as described in Annex I.
- Bienvue will not sell or share the personal information the Customer provides.
- Bienvue will not retain, use, or disclose that personal information for any purpose other than those business purposes, or outside the direct business relationship between the Customer and Bienvue, and will not combine it with personal information Bienvue receives from or on behalf of another source, except as the CCPA permits.
- Bienvue will comply with the CCPA and provide the same level of privacy protection the CCPA requires of businesses.
- Bienvue will notify the Customer if it determines it can no longer meet its obligations under the CCPA.
- The Customer may take reasonable and appropriate steps to ensure Bienvue uses the personal information consistently with the Customer’s CCPA obligations, and, on notice, to stop and remediate any unauthorized use.
- Bienvue passes these same terms down to any subprocessor that processes personal information on its behalf.
- Bienvue certifies that it understands and will comply with these restrictions.
14. Liability and term
Each party’s liability arising out of this DPA is subject to the limitation of liability in the Terms, except where the SCCs or Data Protection Laws do not allow it to be limited, including each party’s liability to data subjects under Clause 12 of the SCCs. This DPA lasts as long as Bienvue processes Customer Personal Data. We may update it as the Terms provide for changes; a change that reduces the protection it gives Customer Personal Data needs the Customer’s agreement unless the law requires it.
Annex I: Description of the processing and transfer
A. List of parties
- Data exporter: the Customer, as named in its Bienvue account. Contact: the owners of its organization, at the email addresses on the account. Activities relevant to the transfer: using Bienvue to write guides for its properties and deliver them to televisions, guide links and public guide pages. Role: controller (Module Two), or processor for its own clients (Module Three). Signature and date: given by accepting the Terms.
- Data importer: Bienvue Ltd., 1500 N Grant St Ste N, Denver, CO 80203, United States. Contact: [email protected]. Activities relevant to the transfer: providing the Service under the Terms. Role: processor. Signature and date: given by making the Terms available and providing the Service.
B. Description of the transfer
- Categories of data subjects: the Customer’s staff, co-hosts, contractors and local contacts named in its guides; people who appear in photos the Customer uploads; and guests or other people only if the Customer chooses to include them in a guide. Bienvue does not collect personal data from guests who view a guide.
- Categories of personal data: whatever the Customer puts in its guides, typically names, phone numbers, email addresses, property addresses and photos that may show people.
- Sensitive data: none intended. The Customer agrees not to put special categories of personal data, or data about criminal convictions and offenses, in its guides. The restrictions and safeguards in Annex II apply to all Customer Personal Data.
- Frequency of the transfer: continuous, for as long as the Customer uses the Service.
- Nature of the processing: collection through the dashboard, storage, hosting, resizing and re-encoding of images, formatting into guides, transmission to televisions, guide links and public guide pages, backup, export and deletion.
- Purpose of the processing: providing the Service to the Customer under the Terms, including support and security.
- Retention: for as long as the Customer keeps the content in the Service, then as set out in section 10.
- Transfers to Subprocessors: as listed in Annex III, for the purposes stated there and for the duration of the processing.
C. Competent supervisory authority
The supervisory authority of the EU member state in which the Customer is established. Where the Customer is not established in the EU but the GDPR applies to it under Article 3(2) and it has appointed a representative, the supervisory authority of the member state where that representative is established. Where it has not appointed one, the supervisory authority of the member state in which the data subjects whose personal data is transferred are located. For transfers under the UK Addendum, the UK Information Commissioner; under the FADP, the Swiss Federal Data Protection and Information Commissioner.
Annex II: Technical and organizational measures
- Encryption: all traffic to and from the Service uses TLS. Databases and file storage are encrypted at rest by our hosting provider.
- Hosting and physical security: the Service runs on Cloudflare, whose data centers, network and physical security are covered by its SOC 2 Type II report and ISO/IEC 27001 certification.
- Separation of customers: every request for a customer’s data is resolved to the organization from the signed-in session, never from the request, and this is covered by automated tests.
- Authentication: passwords are stored only as salted hashes; sessions end when a password is reset or changed; sign-in attempts are rate-limited; hosts can turn on two-factor authentication, and an organization’s owners can require it for every member; deleting data, exporting it and changing the team require the user to confirm their password (and code) again.
- Roles: owners, admins and members have different permissions; only owners and admins manage the team, export or delete properties.
- Televisions: each screen authenticates with its own token, stored by us only as a hash and bound to that device; hosts can release a screen at any time.
- Photos: uploaded photos are served only through signed, expiring links, and only re-encoded copies are ever served.
- Abuse protection: public forms are protected by Cloudflare Turnstile and rate limits.
- Logging and monitoring: credentials and message contents are kept out of logs; error reports are stripped of cookies, request bodies and tokens before they are sent; team changes and support actions are recorded in audit logs.
- Secrets: production secrets are held in the hosting provider’s secret store, never in source code or configuration.
- Change management: every change passes an automated gate of type checks, linting and tests before it is deployed, and is deployed to a separate staging environment, with its own database and storage, before production.
- Backups and recovery: the database can be restored to any point in the last 30 days.
- Data minimization and retention: guest surfaces set no cookies and record no guest identity; logs and device records are kept on the schedule in the Privacy Policy; deleted data is purged by a daily job, with a record of each purge.
- Data subject rights: hosts can correct, delete and export their data from the dashboard.
- Subprocessors: engaged only under written data protection terms, as in section 6.
Annex III: Subprocessors
Bienvue uses these Subprocessors, for the purposes shown. Each may process data in the United States and in the other countries where it operates. Not every one receives Customer Personal Data; each receives only what its purpose needs.
- Cloudflare (edge hosting, compute, and encrypted storage)
- Mailjet (account confirmations, security notices, and the newsletter for people who confirm they want it)
- Google (Analytics on our marketing and sign-up pages, only with your consent; Places and Gemini, which receive your property’s address and location and the name, category, and address of nearby places to build your Nearby suggestions — never guest data)
- Geoapify (KEPTAGO LTD, Cyprus; EU hosting), which receives the names and locations of nearby places, and your property’s address when it finds places for you, to look up their details in OpenStreetMap — never guest data
- Apple (Maps, which shows hosts a place’s details beside its card in the dashboard; receives the place’s name and location and the host’s browser address — never guest data)
- Stripe (billing and payment processing)
- Sentry (error reports from our API, dashboard, and admin tool; session cookies, request bodies and tokens in URLs are excluded before a report is sent)