Data Processing Agreement
Last updated: 29 June 2026
This Data Processing Agreement (“DPA”) forms part of the agreement between the merchant using the Boekhoudbrug app (the “Controller”) and Bright Fern Labs, a sole proprietorship of Mike den Boer trading as Boekhoudbrug, KVK 42099020, VAT NL224101183B01, Galgendijk 105, 4484 NH Kortgene, the Netherlands (the “Processor”). It governs the processing of personal data under the EU General Data Protection Regulation (GDPR) and is accepted by the Controller upon installation and use of the app.
1. Roles & subject matter
The Controller determines the purposes and means of processing the personal data of its customers. The Processor processes that data solely to provide the app’s service: automatically booking the Controller’s paid Shopify orders into the Controller’s accounting platform and, where enabled, issuing PEPPOL e-invoices. The processing lasts for the duration of the app installation.
2. Categories of data subjects & personal data
Data subjects: the Controller’s customers (order buyers).
Personal data: customer name, email and billing/contact address. Where the Controller enables e-invoicing, additionally the buyer’s VAT number and the buyer party as stated on the UBL invoice. No special categories of data are processed.
3. Processor obligations
- Process personal data only on the Controller’s documented instructions (including this DPA and use of the app), unless required otherwise by EU or member-state law.
- Ensure persons authorised to process the data are bound by confidentiality.
- Implement appropriate technical and organisational security measures as set out in Annex II (Article 32 GDPR).
- Engage sub-processors only as listed in Annex III, under equivalent data-protection obligations, and inform the Controller of intended changes so they can object.
- Assist the Controller, taking into account the nature of processing, in responding to data-subject requests and in meeting its obligations under Articles 32–36 GDPR.
- Notify the Controller without undue delay after becoming aware of a personal-data breach.
- At the Controller’s choice, delete or return the personal data after the end of the service, except where storage is required by law (e.g. fiscal retention of issued e-invoices).
- Make available the information necessary to demonstrate compliance and allow for and contribute to audits.
4. Data-subject requests
The app implements Shopify’s mandatory privacy webhooks (data access request, customer redaction, shop redaction) to help the Controller fulfil GDPR requests. Because the app retains almost no raw customer personal data locally (it is forwarded to the Controller’s own accounting platform), the Controller fulfils access requests from that administration; deletion requests remove the app’s local records as described in our Privacy Policy.
5. International transfers
Application data is stored in the EU. Where a sub-processor processes data outside the EEA, the transfer is covered by appropriate safeguards such as the EU Standard Contractual Clauses.
6. Liability & governing law
This DPA is governed by the laws of the Netherlands. Liability is subject to the limitations agreed in the main agreement between the parties.
Annex I — Processing details
Nature & purpose: reading paid Shopify orders and creating corresponding sales invoices/credit notes in the Controller’s accounting platform; optionally generating and transmitting PEPPOL e-invoices.
Duration: for the term of the app installation.
Frequency: continuous (event-driven per order, plus a daily catch-up).
Annex II — Security measures
- Encryption in transit (TLS) and at rest (database + backups).
- Access control: Row Level Security and application-only database credentials; no anonymous/public access.
- Secrets stored in environment variables, never in source control.
- Data minimisation: only the order fields required to book the order are requested.
- Access logging of every read of customer personal data by the sync pipeline.
- Separation of test/development and production data.
Annex III — Approved sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase | Managed PostgreSQL database | EU (Frankfurt) |
| Vercel | Application hosting | USA (SCCs) |
| Resend | Transactional email & PDF e-invoice fallback | USA (SCCs) |
| Recommand | PEPPOL access point (e-invoicing only) | EU |
| EC / OpenPeppol validators | UBL conformance checking (e-invoicing only) | EU |
Questions about this DPA: joandenboe@gmail.com