ZienKlaar
Language
Back

Data Processing Agreement

Version 1.2 · 2026 · GDPR compliant

This Data Processing Agreement (hereinafter: “DPA”) applies to the processing activities carried out by Media Koerier (KVK 94186367, Generaal Spoorlaan 133, 2283 GE Rijswijk, hereinafter: “Processor”) on behalf of the User (hereinafter: “Controller”) in the context of using ZienKlaar.

Article 1 — Definitions

Personal data: any information relating to an identified or identifiable natural person, as defined under the GDPR.

Processing: any operation or set of operations performed on personal data, as set out in Article 4(2) GDPR.

Sub-processor: a third party engaged by the Processor to process personal data.

Article 2 — Subject matter and duration

The Processor processes personal data solely for the purpose of providing the ZienKlaar platform. The DPA is valid for the duration of the user agreement and terminates automatically upon account cancellation.

Article 3 — Nature of processing

Categories of personal data: email addresses, names and usage data (room type, style, timestamp) of the Controller's staff. Uploaded property photos may contain personal data if individuals are visible; these are retained for 30 days in secure cloud storage and automatically deleted thereafter.

Support chat and support tickets: messages typed by a visitor or user in the chat on the website are processed in order to answer the question; for that purpose they are sent to Google's Vertex AI in the EU region europe-west4 (the Netherlands) and are not stored by us. If the conversation is turned into a support ticket, the conversation and the contact email address provided are stored and automatically deleted after 90 days.

Purposes: delivery of AI-styled images, authentication, invoicing and customer support (including handling support requests).

Data subjects: staff and clients of the Controller.

Article 4 — Obligations of the Processor

The Processor undertakes to:

  • Process data solely on the basis of documented instructions from the Controller;
  • Ensure confidentiality by all involved staff;
  • Implement technical and organisational security measures in accordance with Article 32 GDPR;
  • Assist in facilitating the rights of data subjects;
  • Report data breaches within 72 hours of discovery;
  • Delete or return data upon termination of the agreement, except for data the Processor is required to retain by law (invoice and payment data, 7 years — art. 52(4) AWR);
  • Provide all information necessary to demonstrate GDPR compliance.

Article 5 — Sub-processors

The Processor uses the following sub-processors. By accepting this DPA, the Controller consents to the engagement of these parties:

  • OpenAI, Inc. (US) — AI image processing. Uploaded photos are not stored by OpenAI after processing. Transfer based on Standard Contractual Clauses (SCC, EU Decision 2021/914).
  • Google LLC (US) — creative AI image generation via Google Gemini, generating the answers in the support chat, and email via Google Workspace. Chat messages are processed via Vertex AI in the EU region europe-west4 (the Netherlands); image generation may take place outside the EU. Support-ticket emails — containing the contact email address and the chat conversation — are sent via Google Workspace and stored in the Processor's mailbox. Processing in accordance with Google's Cloud Data Processing Addendum. Transfer based on SCC.
  • Modal Labs, Inc. (US) — Photos are exclusively processed and not stored. Transfer based on SCC.
  • Vercel, Inc. (US) — web application hosting and secure storage of photos, generated images and videos (maximum 30 days, then automatically deleted). Transfer based on SCC.
  • Neon, Inc. (EU) — PostgreSQL database hosting for account data and usage statistics, hosted in the EU (Frankfurt, eu-central-1).
  • Clerk, Inc. (US) — authentication services and identity management. Transfer based on SCC.
  • Mollie B.V. (NL) — payment processing. Based in the EU, subject to EU regulations.
  • Moneybird B.V. (NL) — invoicing and bookkeeping. For every purchase, name, email address, the invoice line, the amount and the VAT are recorded; for a business buyer, also company name, address, Chamber of Commerce and VAT numbers. Based in the Netherlands, data hosted within the EU — no transfer outside the EEA, so Article 6 does not apply to it.

The Processor will notify the Controller in advance of any changes to the list of sub-processors. The Controller may object within 14 days.

Article 6 — International transfers

Personal data and property photos may be transferred to the United States when processed by OpenAI, Google, Modal Labs, Vercel and Clerk. All transfers take place on the basis of Standard Contractual Clauses pursuant to Decision (EU) 2021/914, supplemented by technical measures (encryption in transit and at rest).

Support chat messages are sent by us to Google's Vertex AI endpoint in the EU region europe-west4 (the Netherlands), and therefore not to an endpoint outside the EU.

Article 7 — Security

The Processor applies the following security measures: TLS encryption for all data transmission, encryption of databases and file storage at rest, least-privilege access control, and regular security reviews.

Article 8 — Audits

The Controller has the right to verify compliance with this DPA, either through written questions or by means of an audit (with reasonable advance notice and at the Controller's own cost).

Article 9 — Governing law

This DPA is governed by Dutch law. Disputes are submitted to the competent court in The Hague.

Article 10 — Contact

For questions regarding this DPA: info@zienklaar.nl