Data Processing Agreement

Last updated: 29 June 2026

This Data Processing Agreement (“DPA”) forms part of the agreement between the merchant using the Boekhoudbrug app (the “Controller”) and Bright Fern Labs, a sole proprietorship of Mike den Boer trading as Boekhoudbrug, KVK 42099020, VAT NL224101183B01, Galgendijk 105, 4484 NH Kortgene, the Netherlands (the “Processor”). It governs the processing of personal data under the EU General Data Protection Regulation (GDPR) and is accepted by the Controller upon installation and use of the app.

1. Roles & subject matter

The Controller determines the purposes and means of processing the personal data of its customers. The Processor processes that data solely to provide the app’s service: automatically booking the Controller’s paid Shopify orders into the Controller’s accounting platform and, where enabled, issuing PEPPOL e-invoices. The processing lasts for the duration of the app installation.

2. Categories of data subjects & personal data

Data subjects: the Controller’s customers (order buyers).
Personal data: customer name, email and billing/contact address. Where the Controller enables e-invoicing, additionally the buyer’s VAT number and the buyer party as stated on the UBL invoice. No special categories of data are processed.

3. Processor obligations

4. Data-subject requests

The app implements Shopify’s mandatory privacy webhooks (data access request, customer redaction, shop redaction) to help the Controller fulfil GDPR requests. Because the app retains almost no raw customer personal data locally (it is forwarded to the Controller’s own accounting platform), the Controller fulfils access requests from that administration; deletion requests remove the app’s local records as described in our Privacy Policy.

5. International transfers

Application data is stored in the EU. Where a sub-processor processes data outside the EEA, the transfer is covered by appropriate safeguards such as the EU Standard Contractual Clauses.

6. Liability & governing law

This DPA is governed by the laws of the Netherlands. Liability is subject to the limitations agreed in the main agreement between the parties.

Annex I — Processing details

Nature & purpose: reading paid Shopify orders and creating corresponding sales invoices/credit notes in the Controller’s accounting platform; optionally generating and transmitting PEPPOL e-invoices.
Duration: for the term of the app installation.
Frequency: continuous (event-driven per order, plus a daily catch-up).

Annex II — Security measures

Annex III — Approved sub-processors

Sub-processorPurposeLocation
SupabaseManaged PostgreSQL databaseEU (Frankfurt)
VercelApplication hostingUSA (SCCs)
ResendTransactional email & PDF e-invoice fallbackUSA (SCCs)
RecommandPEPPOL access point (e-invoicing only)EU
EC / OpenPeppol validatorsUBL conformance checking (e-invoicing only)EU

Questions about this DPA: joandenboe@gmail.com