Data processing agreement
Last updated 2026-10-02
Personuppgiftsbiträdesavtal (Art. 28 GDPR) between you, the venue (controller), and Codexier (Jamshaid Amjad, enskild firma), the Bordly provider (processor). It's part of the terms of service and applies automatically when you use Bordly.
1. Subject and duration
The processor processes personal data of the controller's guests to provide Bordly, for as long as the controller has an account.
2. Categories
Data subjects: guests of the venue. Data: loyalty card code and stamp history, optional email and marketing consent, feedback text, rating, photo and optional contact details, wallet device push tokens. No special categories (Art. 9) are intended; the controller must not ask guests for them.
3. Processor obligations
- Process only on documented instructions (the product configuration you choose counts as instructions).
- Ensure everyone with access is bound by confidentiality.
- Implement appropriate security (Art. 32): encryption in transit, hashed secrets, access control, row-level security, backups, rate limiting.
- Help the controller answer data subject requests and with DPIAs where relevant.
- Notify the controller without undue delay, and within 48 hours, after becoming aware of a personal data breach.
- Delete or return all personal data when the account ends (deletion of the venue deletes the data; backups roll over within 30 days).
- Make available the information needed to demonstrate compliance and allow reasonable audits, with 30 days' notice.
4. Sub-processors
The controller gives general authorisation for the sub-processors below. We give 30 days' notice by email before adding or replacing one, and the controller may object by cancelling.
| Provider | Purpose | Safeguard |
|---|---|---|
| Vercel Inc. | Hosting and serverless functions (EU region, Frankfurt) | EU + SCCs / EU–US DPF |
| Supabase Inc. or Neon Inc. | Postgres database (EU region) | EU + SCCs |
| Resend Inc. | Sending emails (alerts, reports, campaigns) | SCCs / EU–US DPF |
| Stripe Payments Europe Ltd. | Subscription billing (venue owners only) | EU |
| Google LLC | Google Wallet passes; reading public rating via Places API | SCCs / EU–US DPF |
| Apple Inc. | Apple Wallet pass updates (push notifications) | SCCs / EU–US DPF |
| Anthropic PBC | AI menu import (menu text and photos only, no guest data) | SCCs / EU–US DPF |
5. Transfers
Primary storage is in the EU (Frankfurt, Germany). Any transfer to a third country relies on an adequacy decision, the EU–US Data Privacy Framework or Standard Contractual Clauses.
6. Contact
Data protection questions: hej@codexier.com. Need a signed copy for your records? Email us and we'll send one for e-signing.
Codexier (Jamshaid Amjad, enskild firma) · org.nr 950311-3954 · Godkänd för F-skatt · Momsreg.nr SE950311395401 · Sverige · hej@codexier.com