Legal · Template

Data Processing Agreement

The GDPR Article 28 terms under which Ninefold processes the personal data in a client’s books when it provides Vezna. Fields in [square brackets] are completed for each client.

Version effective 5 October 2026Last updated 5 October 2026

On this page
  1. Parties
  2. 1. Scope
  3. 2. Definitions
  4. 3. Roles
  5. 4. Instructions
  6. 5. Confidentiality
  7. 6. Security
  8. 7. Sub-processors
  9. 8. Services the client connects
  10. 9. International transfers
  11. 10. Assistance
  12. 11. Personal data breaches
  13. 12. Return and deletion
  14. 13. Information and audits
  15. 14. Liability
  16. 15. Term
  17. 16. Governing law
  18. Signatures
  19. Annex 1 — Processing
  20. Annex 2 — Security measures
  21. Annex 3 — Sub-processors

Parties

  1. [Client legal name], a company registered in [country], registration number (ЕИК) [number], VAT number [VAT number], registered address [address], represented by [name, position] (the “Client”); and
  2. Ninefold Ltd (Найнфолд ЕООД), a company registered in Bulgaria, VAT number BG204012589, registered address 6-ti Septemvri St. 4 (ул. „6-ти Септември“ 4), 1000 Sofia, Bulgaria, represented by Ivan Iliev, Manager (Управител) (“Ninefold”), which provides the Vezna service.

1. Scope

1.1 This Data Processing Agreement (“DPA”) applies to the personal data that Ninefold processes on the Client’s behalf when providing Vezna and the accounting services agreed with the Client (“Client Personal Data”).

1.2 This DPA forms part of the agreement between the parties, which consists of the engagement agreed with the Client (the “engagement”) and the Vezna Terms of Service. On the processing of personal data, this DPA prevails over the engagement and the Terms of Service, unless the engagement expressly changes a clause of this DPA.

2. Definitions

2.1 “Personal data”, “processing”, “controller”, “processor”, “data subject”, “personal data breach” and “supervisory authority” have the meanings given in Regulation (EU) 2016/679 (the “GDPR”).

2.2 “Data Protection Law” means the GDPR and the Bulgarian Personal Data Protection Act (Закон за защита на личните данни). “Sub-processor” means another processor that Ninefold engages to process Client Personal Data.

3. Roles

3.1 The Client is the controller, and Ninefold the processor, of Client Personal Data. Annex 1 describes the processing.

3.2 The Client is responsible for the lawfulness of the processing it instructs, including having a legal basis for sharing the personal data in its documents and informing the people concerned.

4. Instructions

4.1 Ninefold processes Client Personal Data only on the Client’s documented instructions, including with regard to transfers to third countries, unless EU or Bulgarian law requires otherwise; in that case Ninefold informs the Client before the processing, unless that law prohibits it.

4.2 The Client’s instructions are this DPA; the engagement; the Client’s use and configuration of Vezna, including the data sources it connects, the users it invites and the AI assistants its users connect; and any further written instructions the parties agree.

4.3 Ninefold informs the Client immediately if, in its opinion, an instruction infringes Data Protection Law.

4.4 Ninefold does not process Client Personal Data for its own purposes. In particular, it does not use it to train AI models, for advertising, or to sell it.

5. Confidentiality

Ninefold ensures that everyone it authorises to process Client Personal Data — its staff, contractors and sub-processors — has committed to confidentiality or is under an appropriate statutory obligation of confidentiality.

6. Security

Ninefold implements the technical and organisational measures described in Annex 2, as required by Article 32 GDPR. It may update them as technology and risks evolve, provided the overall level of protection does not decrease.

7. Sub-processors

7.1 The Client gives Ninefold general authorisation to engage the sub-processors listed at vezna.ai/subprocessors (Annex 3).

7.2 Ninefold informs the Client’s owners by email at least 30 days before adding or replacing a sub-processor. The Client may object on reasonable data protection grounds within that period. The parties will then discuss the objection in good faith; if they cannot resolve it, the Client may terminate the affected part of the service.

7.3 Ninefold imposes on each sub-processor, by contract, data protection obligations that give the same level of protection as this DPA, and remains liable to the Client for each sub-processor’s performance of them.

8. Services the client connects

Banks and payment providers, the Client’s Google accounts, and AI assistants such as ChatGPT or Claude that the Client’s users connect to Vezna are not Ninefold’s sub-processors. Data flows to and from them on the Client’s instructions and under the Client’s, or its users’, own agreements with those providers, and Ninefold is not responsible for their processing. Ninefold applies the controls described in Annex 2 to the Vezna connector that assistants use.

9. International transfers

Ninefold transfers Client Personal Data outside the European Economic Area only in compliance with Chapter V GDPR — for example under an adequacy decision, including the EU–US Data Privacy Framework, or the European Commission’s Standard Contractual Clauses. Where Standard Contractual Clauses are needed between Ninefold and a sub-processor, Ninefold concludes them (Module 3, processor to processor).

10. Assistance

10.1 Taking into account the nature of the processing, Ninefold assists the Client, by appropriate technical and organisational measures, in responding to requests from data subjects exercising their rights. If Ninefold receives such a request directly, it forwards it to the Client without undue delay and does not respond to it unless the Client authorises it.

10.2 Taking into account the nature of the processing and the information available to it, Ninefold assists the Client with its obligations under Articles 32 to 36 GDPR: security, notification of personal data breaches, data protection impact assessments and prior consultation.

11. Personal data breaches

Ninefold notifies the Client without undue delay after becoming aware of a personal data breach affecting Client Personal Data and in any case within 48 hours. The notice includes the information listed in Article 33(3) GDPR as it becomes available. Ninefold takes reasonable steps to contain the breach and limit its consequences.

12. Return and deletion

12.1 While the service runs, the Client can export its books from Vezna.

12.2 When the service ends, Ninefold keeps Client Personal Data for 90 days so that the Client can export it or ask Ninefold for an export, and then deletes it, including copies, unless EU or Bulgarian law requires its storage. Deleted data leaves Ninefold’s encrypted backups within about two months, as the backups rotate.

12.3 On request, Ninefold confirms the deletion in writing.

12.4 The Client remains responsible for keeping its own records for the periods required by law, for example under Article 12 of the Accountancy Act (Закон за счетоводството).

13. Information and audits

13.1 Ninefold makes available to the Client all information necessary to demonstrate compliance with Article 28 GDPR.

13.2 Ninefold allows for and contributes to audits, including inspections, by the Client or an auditor it mandates who is bound by confidentiality, on these conditions: at least 30 days’ written notice; no more than once in any 12 months, unless a supervisory authority requires it or after a personal data breach; during business hours, without access to other clients’ data or disruption to their service; and at the Client’s cost. Ninefold may first offer written information that answers the audit’s scope.

14. Liability

Each party’s liability under this DPA is subject to the limitations in the engagement and the Terms of Service, without prejudice to Article 82 GDPR or to liability that cannot be limited by law.

15. Term

This DPA applies for as long as Ninefold processes Client Personal Data, and its obligations on confidentiality, return and deletion survive the end of the service.

16. Governing law

This DPA is governed by the laws of Bulgaria. Disputes go to the competent courts in Sofia, Bulgaria.

Signatures

For the Client

[Client legal name]
Name: [name]
Position: [position]
Date: [date]
Signature: ______________________

For Ninefold Ltd

Ninefold Ltd (Найнфолд ЕООД)
Name: Ivan Iliev
Position: Manager (Управител)
Date: [date]
Signature: ______________________

Annex 1 — Description of the processing

Subject matter and durationProviding Vezna and the accounting services in the engagement, for the term of the engagement and the return and deletion period in clause 12.
Nature of the processingCollecting data from the sources the Client connects (bank and payment APIs, statement uploads, documents from Google Drive, a connected Gmail mailbox, uploads and email); storing it; reading and extracting documents, including with AI models; categorising transactions; matching documents to payments; proposing journal entries; reporting and preparing VAT and SAF-T drafts; communicating with the Client (questions, reminders and digests); the in-app assistant; making data available to AI assistants the Client’s users connect; backup; deletion.
PurposeKeeping the Client’s accounts and supporting its statutory accounting and tax obligations, as set out in the engagement.
Data subjects
  • the Client’s employees and contractors;
  • the Client’s owners, directors and representatives;
  • the Client’s customers and suppliers who are individuals, including sole traders, and contact persons of organisations;
  • other individuals who appear in the Client’s bank transactions or documents, such as payers and payees;
  • the Client’s users of Vezna.
Categories of personal data
  • identification and contact data printed on documents: names, addresses, email addresses, phone numbers, company and VAT numbers of sole traders;
  • financial data: bank transaction details, account identifiers such as IBANs, amounts, invoice data;
  • employment-related payments as they appear in the books: salaries and fees paid, social-security and tax payments, expense reimbursements;
  • personal identification numbers (ЕГН/ЛНЧ), where a source document contains them;
  • communications: questions and answers about the books, chat messages, and the metadata and attachments of emails in a connected mailbox;
  • records of who did what in Vezna, and when.
Special categoriesNone intended. The Client should not upload special categories of data unless they are necessary for its accounting and agreed with Ninefold.
FrequencyContinuous, for the term of the engagement.

Annex 2 — Technical and organisational measures

Hosting, encryption and backup

  • The app and the books are hosted in the EU (DigitalOcean, Frankfurt, Germany).
  • All traffic is encrypted in transit (TLS) and passes through Cloudflare’s network protection; the application server accepts no direct connections from the internet.
  • Daily backups are encrypted before they leave the server and are stored separately; they rotate through 14 daily and 8 weekly copies.

Isolation and access control

  • Each company’s books live in a separate workspace with its own process and data directory. The front door passes each request to the company’s process with a signed identity, and the company’s process refuses unsigned requests.
  • Named accounts with roles: owners and team members use the company workspace; accountants use the accounting workspace. Owners and team members can connect AI assistants; accountants can’t.
  • Ninefold staff access client data only as needed to run and support the service.

Authentication

  • Passwords are stored only as scrypt hashes; Google sign-in uses OpenID Connect.
  • Sessions use an HttpOnly, Secure cookie, expire after 30 days, or 7 days without activity, and can be ended at sign-out.
  • Sign-in attempts are rate-limited. Invitation links expire after 7 days and password-reset links after 1 hour.
  • Session, invitation, password-reset and connector tokens are stored only as cryptographic hashes.

The Vezna connector for AI assistants

  • OAuth 2.1 with PKCE; the owner approves each connection on a consent screen that lists what the assistant will be able to do.
  • Access tokens are valid for one hour; refresh tokens rotate on every use; a connection unused for 30 days lapses; owners can revoke a connection at any time.
  • The connector offers no tools to make payments, file returns, approve ledger entries, change users or settings, or delete data.
  • Tool results never include personal identification numbers (ЕГН/ЛНЧ) or full payment-card numbers. Email search returns only date, sender, recipients, subject and attachment names.
  • Every tool call is logged with the user, the assistant, the tool and the time.

Logging and minimisation

  • Account and administration events, automatic bookings, learned rules and ledger events (proposals, approvals, edits) are logged.
  • Bank and payment connections are used to read activity; Vezna does not initiate payments.
  • The AI provider does not use data sent through its API to train its models.
  • Credentials for the Client’s connections are kept out of the code, in the server environment.

Organisation

  • Confidentiality commitments for everyone with access (clause 5).
  • Sub-processors are bound by contract to equivalent protection (clause 7).
  • Personal data breaches are handled and notified as clause 11 describes.

Annex 3 — Sub-processors

As at the effective date of this version. The current list, with the data each provider processes and the safeguards, is at vezna.ai/subprocessors.

ProviderPurposeLocation
DigitalOcean, LLCServers and storageFrankfurt, Germany (EU)
Cloudflare, Inc.DNS, TLS and network protectionGlobal network
AnthropicAI models (Claude)United States
GoogleGoogle Drive and Gmail, only if the Client connects them; Google sign-in, if a user chooses itGoogle’s infrastructure
ResendInvitation and password-reset emailsUnited States
Cloudflare (R2 object storage)Encrypted off-site backupsEuropean Union (R2 EU jurisdiction)