Data processing agreement
Personal data of your visitors and customers can come in through your website. You are responsible for that data and we process it on your behalf. The law (article 28 GDPR) requires us to lay down agreements about that. We do so here. This agreement is part of our terms of service and applies automatically as soon as you are a customer; you do not need to sign anything.
1. Parties and roles
You are the controller. Zwovo is the processor. We process the data only to provide your website, in line with this agreement and your instructions through the dashboard or by email.
2. Which data
| Whose | Visitors to your website and people who contact you through your website |
|---|---|
| Which data | Technical data of a visit (IP address and browser, only briefly and to count visits); data someone enters themselves where your website offers that, such as name, email address, phone number and a message or requested appointment |
| What for | Showing your website, keeping visit figures for you, passing messages and requests on to you, and confirming appointments and reminding your customers of them |
| How long | Messages and appointments: up to 12 months, or shorter if you delete them in your dashboard yourself. Other data: for as long as your subscription runs; after that in line with article 9 |
You do not use your website to collect special categories of personal data, such as health data, unless we have made separate arrangements for that.
3. Only on your instructions
We process the data only for the purposes above. If we believe an instruction breaches the law, we tell you. If we are legally required to disclose data, we tell you beforehand unless the law forbids it.
4. Confidentiality
Everyone at Zwovo who has access to the data is bound by confidentiality.
5. Security
We take appropriate measures to protect the data, including encrypted connections, storage with certified hosting providers, access only for those who need it, passwordless sign-in with a one-time link, and regular backups.
6. Companies we use
You authorise us to use the following sub-processors. With each of them we have agreements that offer at least the same protection as this agreement.
| Sub-processor | What for | Where |
|---|---|---|
| Vercel | Hosting your website | EU and US |
| Supabase | Database and storage | EU and US |
| Resend | Sending email: messages and overviews to you, and confirmations and reminders to your customers | EU and US |
| Anthropic | Writing texts and processing changes you ask for | US |
If we want to add or replace a sub-processor, we tell you at least 30 days in advance. If you have a well-founded objection, you can cancel your subscription. For transfers outside the EU we rely on the EU-US Data Privacy Framework or the European Commission's standard contractual clauses.
7. Requests from data subjects
If someone asks us to access, correct or delete data that belongs to your website, we forward that request to you. We help you, as far as is reasonable, to comply with it.
8. Data breaches
If we discover a security breach involving data from your website, we tell you without undue delay and within 48 hours at the latest. We tell you what happened, which data is involved and what we have done. You decide whether you need to inform the supervisory authority or the people concerned; we help you with that.
9. After your subscription ends
After your subscription ends we delete the data that belongs to your website, at the latest 12 months after your website went offline. If you ask for it sooner, we delete it within 30 days. Data we must keep by law, we keep for as long as required.
10. Audit
We give you the information you reasonably need to show that we comply with this agreement. If you want to have that verified, we agree on a way that fits the scale of the service. The cost of an audit is yours, unless it shows that we did not comply with this agreement.
11. Liability and law
The limitation of liability and the choice of law in our terms of service apply to this agreement.