Data Processing Agreement (Member Sites)

Venturee, operated by Binderr B.V.

Effective Date: August 31, 2026 · Version: 1.3

This Data Processing Agreement ("DPA") is between you, the Venturee member who publishes a site (the "Controller"), and Binderr B.V., Geertestraat 27 BS, 3511 XD Utrecht, The Netherlands, KvK 91797047 ("Binderr", the "Processor").

It forms part of the Terms of Service. It applies automatically from the moment you first publish a site through Venturee, and for as long as Binderr hosts it. It implements Article 28(3) of the GDPR for the processing described below.

Contents

  1. Roles and scope
  2. Processing details
  3. Binderr's obligations as processor
  4. Sub-processors
  5. International transfers
  6. Your obligations as controller
  7. Deletion
  8. Contact
  9. General

Version history


1. Roles and scope

1.1 When you publish a site, you are the controller for the personal data of your site's visitors, customers, and users: you decide what your site collects and why, and you are responsible for its privacy notice, any cookie consent, and the handling of data-subject requests, as the Terms state.

1.2 Binderr is your processor for that data, strictly in its role as the host and operator of the infrastructure your site runs on.

1.3 This DPA covers only your site's data. For your own Venturee account — registration data, your profile, prompts, messages, and content you create on the platform — Binderr is the controller, and the Privacy Statement applies instead of this DPA.


2. Processing details (Article 28(3) GDPR)

Article 28(3) itemWhat it is for your site
Subject matterHosting, serving, storing, and securing your published site and the data it collects.
DurationWhile your site is published and hosted by Binderr — including the 60-day wind-down after your Venturee subscription ends, during which the site is paused but still hosted and this DPA remains in force (section 7.2) — plus the deletion periods in section 7.
Nature and purposeProviding the hosting and platform features you configure — serving pages, storing site content and records your site creates (for example form submissions, accounts, orders, bookings, messages), backups, and security and reliability logging. Pictures uploaded through your site's admin pages are resized before they are stored, as section 5.10 of the Terms describes; where such a picture contains personal data, that resizing is part of the processing you instruct by using the feature. Files your site sells for download are stored unchanged.
Categories of personal dataTechnical data of visitors (such as IP addresses and request logs); account data of your site's users; the contact and order details of guest buyers who purchase without an account; and whatever other personal data your site is configured to collect from its visitors.
Categories of data subjectsVisitors, customers, and registered users of your site.
Special categoriesYour site is not intended for special categories of data (Article 9 GDPR), and you agree not to design it to collect them.

Payments. If your site takes live payments, payment-card data is collected and processed by Stripe under your own agreement with Stripe, acting for you — not as Binderr's sub-processor. Binderr does not receive, hold, or transmit your customers' funds or full card data; only transaction metadata needed to run your site's features passes through the infrastructure.


3. Binderr's obligations as processor

Binderr will:

3.1 process your site's personal data only to host and operate the site as you have configured it, and on the documented instructions this DPA and your use of the platform's controls constitute — not for its own purposes. Section 3.5 of the Privacy Statement ("What we do not collect: visitors to your published sites") states this commitment publicly;

3.2 immediately inform you if, in Binderr's opinion, an instruction you give infringes the GDPR or other EU or Member State data protection law (Article 28(3)(h));

3.3 ensure persons authorised to process the data are bound by confidentiality;

3.4 implement the technical and organisational measures set out in section 10 of the Privacy Statement (Article 32 GDPR), including encryption in transit and at rest and least-privilege access controls;

3.5 assist you, insofar as reasonably possible and taking the nature of the processing into account, in responding to data-subject requests concerning your site and in meeting your obligations under Articles 32–36 GDPR. If Binderr receives a request directly from one of your site's data subjects, it will not respond on the merits and will forward it to you without undue delay;

3.6 notify you without undue delay after becoming aware of a personal data breach affecting your site's data, with the information Article 33(3) requires as it becomes available;

3.7 where Binderr receives a legally binding request from a public authority for your site's personal data, notify you before disclosing unless legally prohibited from doing so. Where prohibited, Binderr will use reasonable efforts to obtain a waiver, will challenge requests that are unlawful or overbroad, and will disclose only the minimum required;

3.8 at your choice, delete or return your site's personal data when hosting ends, and delete remaining copies, unless law requires retention (section 7);

3.9 make available the information reasonably necessary to demonstrate compliance with this DPA — Binderr's current providers, transfer mechanisms, and security measures are documented in the Privacy Statement — and allow for and contribute to audits, which for proportionality are ordinarily satisfied by that documentation and written answers to reasonable questions.


4. Sub-processors

4.1 You give Binderr general written authorisation to engage sub-processors for the processing described in section 2. Three providers process your site's data today:

Sub-processorWhat it does for your site
SupabaseThe database and authentication service your site's records and user accounts live in
RenderHosting — serves your site's pages and holds its request logs
StripeOnly where your site takes payments, and only for the transaction metadata your site's features need. Your customers' card data is Stripe's own processing for you under your Stripe agreement, not Binderr's sub-processing — see the Payments note in section 2

Each provider's region and transfer safeguard is in section 8 of the Privacy Statement, which also lists providers Binderr uses for the platform itself — AI generation from your prompts, platform email, images. Those are not sub-processors of your site's data and receive none of it; only the three above are engaged for the processing this DPA covers.

4.2 Notice of changes. Before adding or replacing a sub-processor, Binderr will update that list and notify you by email at least 30 days in advance, except where a shorter period is unavoidable for security or continuity reasons, in which case Binderr will give as much notice as it reasonably can.

4.3 Objection. If you object on reasonable data-protection grounds within that period, Binderr will work with you to find a resolution. If none is found, you may end the processing by deleting the venture under section 7 — export or request the return of anything you need first. Ending the processing does not by itself end your Venturee subscription. If you also choose to cancel that, section 9.3 of the Terms applies — your plan runs to the end of the billing period you have already paid for and you are not charged again — and any unused Top-up Credits are refunded under section 10.7. Where the sub-processor change is also a modification of the Service that affects you in more than a minor way, section 11.2 of the Terms gives you the statutory right to keep the Service unmodified or to terminate and be reimbursed for the period you have paid for in advance and will not now receive.

4.4 Binderr imposes data-protection obligations on each sub-processor equivalent to this DPA and remains responsible to you for their performance.


5. International transfers

Where processing involves transfers outside the EEA, the safeguards set out in section 12 of the Privacy Statement apply: the EU–US Data Privacy Framework for certified providers, and the European Commission's Standard Contractual Clauses (2021) otherwise, with supplementary measures where needed.


6. Your obligations as controller

6.1 You are responsible for the lawfulness of your site's processing: an adequate privacy notice for your site, any required consent (including cookies and marketing), honouring visitor rights requests, and compliance with the consumer, e-commerce, and sector rules that apply to what your site does.

6.2 You will not instruct processing that violates applicable law, and you will not configure your site to collect special-category data.


7. Deletion

7.1 What ends the processing. Deleting the venture, closing your Venturee account, the end of the 60-day wind-down after your Venturee subscription ends (7.2), or this DPA otherwise ending.

7.2 When deletion happens. There are two triggers, and both delete immediately when they fire — there is no copy held back in case you change your mind:

Residual copies in routine infrastructure backups age out and are purged within 35 days of deletion. The only exception is the limited records Binderr must keep by law, described in section 9 of the Privacy Statement.

⚠️ Export anything you need BEFORE deletion — yours or the scheduled one. Deletion cannot be undone, and nothing is retained for you afterwards.

7.3 What you can export yourself. You can download your venture's code and documents from Venturee at any time while the venture exists. Your site's collected records — the accounts (with their contact addresses), orders, bookings, form submissions and other records your site gathered from its visitors — are available as a self-service export: Export site data in the venture's Users Monitor tab produces one file containing every record your site holds, in structured, commonly used, machine-readable formats. It works at any time the venture exists, including while the site is paused during the 60-day wind-down — that window exists precisely so you can take your data out first.

7.4 Return instead of deletion (Article 28(3)(g)). If you cannot use the export, or need something it does not cover, return is available as a manual procedure: email privacy@venturee.work from your account's email address, naming the venture, before it is deleted — by you or by the 7.2 schedule. Binderr will provide your site's hosted personal data in a structured, commonly used, machine-readable format within 30 days of verifying the request, and will delete it afterwards on your instruction. A verified request made before a scheduled 7.2 deletion suspends that deletion until the request is fulfilled — the schedule never defeats the return. A request that arrives after the venture is deleted cannot be met — the data is gone by then.


8. Contact

For any matter under this DPA — instructions, data-subject requests, breach notifications, sub-processor objections, or audit questions — contact privacy@venturee.work.


9. General

9.1 This DPA is governed by the same law and forum as the Terms of Service.

9.2 If this DPA conflicts with those Terms on the processing of your site's personal data, this DPA controls.

9.3 Nothing in this DPA limits data subjects' rights or either party's obligations under the GDPR.


Version history

Version 1.3 — current

Version 1.2

Version 1.1

Version 1.0 — Initial version.

Previous versions are available on request.