Data Processing Agreement

Last updated: September 30, 2026.

This Data Processing Agreement (“DPA”) is between Bienvue Ltd. (“Bienvue”), and the organization that has accepted our Terms of Service (the “Customer”). It forms part of the Terms and takes effect when the Customer accepts them; it needs no signature. It applies whenever Bienvue processes Customer Personal Data on the Customer’s behalf. If the Customer needs a copy with its details filled in, write to [email protected].

If this DPA conflicts with the Terms, this DPA governs. If it conflicts with the Standard Contractual Clauses, the UK Addendum or the Swiss terms in section 12, those govern.

1. Definitions

2. The processing

The subject matter, duration, nature and purpose of the processing, and the types of personal data and categories of data subjects, are set out in Annex I. The Customer is the controller, or a processor acting for its own clients, and Bienvue is its processor or subprocessor.

3. Instructions

Bienvue processes Customer Personal Data only on the Customer’s documented instructions, including with regard to transfers to a third country, unless EU or member state law (or other law Bienvue is subject to) requires otherwise; in that case Bienvue tells the Customer of that requirement before processing, unless the law forbids it on important grounds of public interest. The Terms, this DPA and the Customer’s use and configuration of the Service are the Customer’s complete instructions; further instructions must be consistent with them and given in writing. Bienvue tells the Customer immediately if, in its opinion, an instruction infringes Data Protection Laws.

The Customer is responsible for the lawfulness of the processing it instructs, for its legal basis, and for informing the data subjects concerned.

4. Confidentiality

Bienvue ensures that everyone it authorizes to process Customer Personal Data has committed to confidentiality or is under an appropriate statutory obligation of confidentiality, and has access only as far as their work needs it.

5. Security

Bienvue implements the technical and organizational measures in Annex II to protect Customer Personal Data as Article 32 of the GDPR requires. Bienvue may change those measures as technology and risks change, provided the overall level of protection is not reduced.

6. Subprocessors

The Customer gives Bienvue general written authorization to engage Subprocessors. The Subprocessors in use are listed in Annex III. Bienvue will tell the Customer of any intended addition or replacement at least 30 days in advance, by updating Annex III and emailing the Customer’s owners, so the Customer can object. The Customer may object on reasonable data protection grounds by writing to [email protected] within that period. The parties will then discuss the objection in good faith; if they can’t resolve it, the Customer may end the affected part of the Service before the change and Bienvue will refund prepaid fees for the unused part of the billing period.

Bienvue imposes on each Subprocessor, by written contract, data protection obligations that give the same level of protection as this DPA, in particular sufficient guarantees of appropriate technical and organizational measures. Bienvue remains fully liable to the Customer for each Subprocessor’s performance of those obligations.

7. Data subject requests

Taking into account the nature of the processing, Bienvue assists the Customer by appropriate technical and organizational measures in responding to requests from data subjects to exercise their rights. The dashboard lets the Customer find, correct, delete and export Customer Personal Data itself. Where it can’t, Bienvue gives reasonable further help. If Bienvue receives a request about Customer Personal Data, it passes it to the Customer without undue delay and does not answer it other than to tell the requester to contact the Customer, unless the Customer authorizes it or the law requires otherwise.

8. Other assistance

Taking into account the nature of the processing and the information available to it, Bienvue assists the Customer in meeting its obligations under Articles 32 to 36 of the GDPR: security of processing, notifying personal data breaches, data protection impact assessments and prior consultation with a supervisory authority. This DPA, Annex II and the Privacy Policy provide the information Bienvue has for those purposes; further help can be requested at [email protected].

9. Personal data breaches

Bienvue notifies the Customer of a personal data breach affecting Customer Personal Data without undue delay, and in any event within 72 hours of becoming aware of it, by email to the Customer’s owners. The notice describes, as far as then known, the nature of the breach, the categories and approximate numbers of data subjects and records concerned, its likely consequences, the measures taken or proposed to address it, and a contact for more information. Where not all of this is known at once, Bienvue provides it in phases without further undue delay. Bienvue takes reasonable steps to contain the breach and limit its effects. Notifying a breach is not an admission of fault.

10. Deletion and return

At any time before its data is deleted, the Customer can export each property’s guide and photos from Settings. When the Customer deletes a property, an organization or its account, or the Terms end, Bienvue deletes Customer Personal Data on the schedule in the Privacy Policy: a deleted organization is permanently removed 30 days after deletion, and an archived property two months after it was archived. Copies in Bienvue’s point-in-time database recovery expire within 30 days after that. Bienvue keeps no copy after that unless the law requires it, in which case it keeps the data confidential and processes it only for that purpose.

11. Audits

Bienvue makes available to the Customer the information necessary to demonstrate compliance with Article 28 of the GDPR and this DPA, and allows for and contributes to audits, including inspections, by the Customer or an auditor it mandates. Audits start with documentation: this DPA, Annex II, the security documentation of Bienvue’s hosting provider (including its SOC 2 Type II report and ISO/IEC 27001 certificate), and Bienvue’s written answers to a reasonable security questionnaire, once a year. If that documentation is not enough to demonstrate compliance, or a supervisory authority requires it, the Customer may carry out an audit on at least 30 days’ written notice, no more than once in any 12 months (unless following a personal data breach or a supervisory authority’s request), during business hours, under a confidentiality agreement, without access to other customers’ data, and at the Customer’s cost. Audits under the SCCs are carried out in the same way.

12. International transfers

Bienvue is established in the United States and processes Customer Personal Data there and wherever its Subprocessors operate, as listed in Annex III.

EU Standard Contractual Clauses. To the extent a transfer of Customer Personal Data from the Customer to Bienvue is a transfer to a third country subject to the GDPR, the SCCs are incorporated into this DPA by reference and apply as follows, with the Customer as data exporter and Bienvue as data importer:

Where the SCCs require the Customer, under Module Three, to forward information to its own controller, Bienvue provides that information to the Customer.

United Kingdom. To the extent a transfer is subject to the UK GDPR, the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner under section 119A(1) of the Data Protection Act 2018 (version B1.0, in force 21 March 2022, the “UK Addendum”) is incorporated by reference. Its Table 1 is completed with the parties and details in Annex I.A; Table 2 with the modules and clause selections above; Table 3 with Annexes I to III; and in Table 4 both the importer and the exporter may end the UK Addendum as its Section 19 provides. Its Part 2 Mandatory Clauses apply.

Switzerland. To the extent a transfer is subject to the FADP, the SCCs apply as above with these changes: references to the GDPR are read as references to the FADP where the transfer is subject to it; the competent supervisory authority under Clause 13 is the Swiss Federal Data Protection and Information Commissioner; the term “member state” in Clause 18(c) does not prevent data subjects habitually resident in Switzerland from suing in Switzerland; and Clause 17 and Clause 18(b) remain as above.

If an authority or court finds a transfer mechanism in this section invalid, the parties will cooperate in good faith to put a valid one in place.

13. California service-provider terms

To the extent the CCPA applies to the Customer and Bienvue processes personal information on its behalf as a service provider:

14. Liability and term

Each party’s liability arising out of this DPA is subject to the limitation of liability in the Terms, except where the SCCs or Data Protection Laws do not allow it to be limited, including each party’s liability to data subjects under Clause 12 of the SCCs. This DPA lasts as long as Bienvue processes Customer Personal Data. We may update it as the Terms provide for changes; a change that reduces the protection it gives Customer Personal Data needs the Customer’s agreement unless the law requires it.

Annex I: Description of the processing and transfer

A. List of parties

B. Description of the transfer

C. Competent supervisory authority

The supervisory authority of the EU member state in which the Customer is established. Where the Customer is not established in the EU but the GDPR applies to it under Article 3(2) and it has appointed a representative, the supervisory authority of the member state where that representative is established. Where it has not appointed one, the supervisory authority of the member state in which the data subjects whose personal data is transferred are located. For transfers under the UK Addendum, the UK Information Commissioner; under the FADP, the Swiss Federal Data Protection and Information Commissioner.

Annex II: Technical and organizational measures

Annex III: Subprocessors

Bienvue uses these Subprocessors, for the purposes shown. Each may process data in the United States and in the other countries where it operates. Not every one receives Customer Personal Data; each receives only what its purpose needs.