Data Processing Agreement
Version: 2026-09-03
Vicenarius · KVK 87135213
This DPA applies when the customer processes personal data in Vicenarius. The customer is the controller and Vicenarius is the processor to the extent Vicenarius processes data solely on the customer's behalf.
Subject and duration
Processing covers hosting, storage, security, support, communications and product functions used by the customer, for the subscription term and agreed deletion period.
Instructions and confidentiality
Vicenarius processes data only on documented customer instructions unless legally required otherwise. People with access are bound by confidentiality and receive only the access needed for their duties.
Security and incidents
We apply appropriate technical and organisational measures, including access controls, tenant isolation, encrypted transport, logging and recovery measures. We notify the customer of a personal-data breach without undue delay and provide available information for the customer's reporting duties.
Subprocessors
Current subprocessor categories are listed in the privacy policy: Supabase, Netlify, Resend, Mollie, Stripe, Expo, map providers, technical error diagnostics and—after consent—browser analytics and session replay. Vicenarius remains responsible for their obligations where required by GDPR.
Deletion and assistance
After termination, Vicenarius deletes or returns personal data under the agreed retention periods except where legal retention applies. We provide reasonable assistance with data-subject requests, DPIAs and supervisory enquiries. Contact support@vicenarius.eu.