Parties
- [Client legal name], a company registered in [country], registration number (ЕИК) [number], VAT number [VAT number], registered address [address], represented by [name, position] (the “Client”); and
- Ninefold Ltd (Найнфолд ЕООД), a company registered in Bulgaria, VAT number BG204012589, registered address 6-ti Septemvri St. 4 (ул. „6-ти Септември“ 4), 1000 Sofia, Bulgaria, represented by Ivan Iliev, Manager (Управител) (“Ninefold”), which provides the Vezna service.
1. Scope
1.1 This Data Processing Agreement (“DPA”) applies to the personal data that Ninefold processes on the Client’s behalf when providing Vezna and the accounting services agreed with the Client (“Client Personal Data”).
1.2 This DPA forms part of the agreement between the parties, which consists of the engagement agreed with the Client (the “engagement”) and the Vezna Terms of Service. On the processing of personal data, this DPA prevails over the engagement and the Terms of Service, unless the engagement expressly changes a clause of this DPA.
2. Definitions
2.1 “Personal data”, “processing”, “controller”, “processor”, “data subject”, “personal data breach” and “supervisory authority” have the meanings given in Regulation (EU) 2016/679 (the “GDPR”).
2.2 “Data Protection Law” means the GDPR and the Bulgarian Personal Data Protection Act (Закон за защита на личните данни). “Sub-processor” means another processor that Ninefold engages to process Client Personal Data.
3. Roles
3.1 The Client is the controller, and Ninefold the processor, of Client Personal Data. Annex 1 describes the processing.
3.2 The Client is responsible for the lawfulness of the processing it instructs, including having a legal basis for sharing the personal data in its documents and informing the people concerned.
4. Instructions
4.1 Ninefold processes Client Personal Data only on the Client’s documented instructions, including with regard to transfers to third countries, unless EU or Bulgarian law requires otherwise; in that case Ninefold informs the Client before the processing, unless that law prohibits it.
4.2 The Client’s instructions are this DPA; the engagement; the Client’s use and configuration of Vezna, including the data sources it connects, the users it invites and the AI assistants its users connect; and any further written instructions the parties agree.
4.3 Ninefold informs the Client immediately if, in its opinion, an instruction infringes Data Protection Law.
4.4 Ninefold does not process Client Personal Data for its own purposes. In particular, it does not use it to train AI models, for advertising, or to sell it.
5. Confidentiality
Ninefold ensures that everyone it authorises to process Client Personal Data — its staff, contractors and sub-processors — has committed to confidentiality or is under an appropriate statutory obligation of confidentiality.
6. Security
Ninefold implements the technical and organisational measures described in Annex 2, as required by Article 32 GDPR. It may update them as technology and risks evolve, provided the overall level of protection does not decrease.
7. Sub-processors
7.1 The Client gives Ninefold general authorisation to engage the sub-processors listed at vezna.ai/subprocessors (Annex 3).
7.2 Ninefold informs the Client’s owners by email at least 30 days before adding or replacing a sub-processor. The Client may object on reasonable data protection grounds within that period. The parties will then discuss the objection in good faith; if they cannot resolve it, the Client may terminate the affected part of the service.
7.3 Ninefold imposes on each sub-processor, by contract, data protection obligations that give the same level of protection as this DPA, and remains liable to the Client for each sub-processor’s performance of them.
8. Services the client connects
Banks and payment providers, the Client’s Google accounts, and AI assistants such as ChatGPT or Claude that the Client’s users connect to Vezna are not Ninefold’s sub-processors. Data flows to and from them on the Client’s instructions and under the Client’s, or its users’, own agreements with those providers, and Ninefold is not responsible for their processing. Ninefold applies the controls described in Annex 2 to the Vezna connector that assistants use.
9. International transfers
Ninefold transfers Client Personal Data outside the European Economic Area only in compliance with Chapter V GDPR — for example under an adequacy decision, including the EU–US Data Privacy Framework, or the European Commission’s Standard Contractual Clauses. Where Standard Contractual Clauses are needed between Ninefold and a sub-processor, Ninefold concludes them (Module 3, processor to processor).
10. Assistance
10.1 Taking into account the nature of the processing, Ninefold assists the Client, by appropriate technical and organisational measures, in responding to requests from data subjects exercising their rights. If Ninefold receives such a request directly, it forwards it to the Client without undue delay and does not respond to it unless the Client authorises it.
10.2 Taking into account the nature of the processing and the information available to it, Ninefold assists the Client with its obligations under Articles 32 to 36 GDPR: security, notification of personal data breaches, data protection impact assessments and prior consultation.
11. Personal data breaches
Ninefold notifies the Client without undue delay after becoming aware of a personal data breach affecting Client Personal Data and in any case within 48 hours. The notice includes the information listed in Article 33(3) GDPR as it becomes available. Ninefold takes reasonable steps to contain the breach and limit its consequences.
12. Return and deletion
12.1 While the service runs, the Client can export its books from Vezna.
12.2 When the service ends, Ninefold keeps Client Personal Data for 90 days so that the Client can export it or ask Ninefold for an export, and then deletes it, including copies, unless EU or Bulgarian law requires its storage. Deleted data leaves Ninefold’s encrypted backups within about two months, as the backups rotate.
12.3 On request, Ninefold confirms the deletion in writing.
12.4 The Client remains responsible for keeping its own records for the periods required by law, for example under Article 12 of the Accountancy Act (Закон за счетоводството).
13. Information and audits
13.1 Ninefold makes available to the Client all information necessary to demonstrate compliance with Article 28 GDPR.
13.2 Ninefold allows for and contributes to audits, including inspections, by the Client or an auditor it mandates who is bound by confidentiality, on these conditions: at least 30 days’ written notice; no more than once in any 12 months, unless a supervisory authority requires it or after a personal data breach; during business hours, without access to other clients’ data or disruption to their service; and at the Client’s cost. Ninefold may first offer written information that answers the audit’s scope.
14. Liability
Each party’s liability under this DPA is subject to the limitations in the engagement and the Terms of Service, without prejudice to Article 82 GDPR or to liability that cannot be limited by law.
15. Term
This DPA applies for as long as Ninefold processes Client Personal Data, and its obligations on confidentiality, return and deletion survive the end of the service.
16. Governing law
This DPA is governed by the laws of Bulgaria. Disputes go to the competent courts in Sofia, Bulgaria.
Signatures
For the Client
[Client legal name]
Name: [name]
Position: [position]
Date: [date]
Signature: ______________________
For Ninefold Ltd
Ninefold Ltd (Найнфолд ЕООД)
Name: Ivan Iliev
Position: Manager (Управител)
Date: [date]
Signature: ______________________
Annex 1 — Description of the processing
| Subject matter and duration | Providing Vezna and the accounting services in the engagement, for the term of the engagement and the return and deletion period in clause 12. |
| Nature of the processing | Collecting data from the sources the Client connects (bank and payment APIs, statement uploads, documents from Google Drive, a connected Gmail mailbox, uploads and email); storing it; reading and extracting documents, including with AI models; categorising transactions; matching documents to payments; proposing journal entries; reporting and preparing VAT and SAF-T drafts; communicating with the Client (questions, reminders and digests); the in-app assistant; making data available to AI assistants the Client’s users connect; backup; deletion. |
| Purpose | Keeping the Client’s accounts and supporting its statutory accounting and tax obligations, as set out in the engagement. |
| Data subjects |
|
| Categories of personal data |
|
| Special categories | None intended. The Client should not upload special categories of data unless they are necessary for its accounting and agreed with Ninefold. |
| Frequency | Continuous, for the term of the engagement. |
Annex 2 — Technical and organisational measures
Hosting, encryption and backup
- The app and the books are hosted in the EU (DigitalOcean, Frankfurt, Germany).
- All traffic is encrypted in transit (TLS) and passes through Cloudflare’s network protection; the application server accepts no direct connections from the internet.
- Daily backups are encrypted before they leave the server and are stored separately; they rotate through 14 daily and 8 weekly copies.
Isolation and access control
- Each company’s books live in a separate workspace with its own process and data directory. The front door passes each request to the company’s process with a signed identity, and the company’s process refuses unsigned requests.
- Named accounts with roles: owners and team members use the company workspace; accountants use the accounting workspace. Owners and team members can connect AI assistants; accountants can’t.
- Ninefold staff access client data only as needed to run and support the service.
Authentication
- Passwords are stored only as scrypt hashes; Google sign-in uses OpenID Connect.
- Sessions use an HttpOnly, Secure cookie, expire after 30 days, or 7 days without activity, and can be ended at sign-out.
- Sign-in attempts are rate-limited. Invitation links expire after 7 days and password-reset links after 1 hour.
- Session, invitation, password-reset and connector tokens are stored only as cryptographic hashes.
The Vezna connector for AI assistants
- OAuth 2.1 with PKCE; the owner approves each connection on a consent screen that lists what the assistant will be able to do.
- Access tokens are valid for one hour; refresh tokens rotate on every use; a connection unused for 30 days lapses; owners can revoke a connection at any time.
- The connector offers no tools to make payments, file returns, approve ledger entries, change users or settings, or delete data.
- Tool results never include personal identification numbers (ЕГН/ЛНЧ) or full payment-card numbers. Email search returns only date, sender, recipients, subject and attachment names.
- Every tool call is logged with the user, the assistant, the tool and the time.
Logging and minimisation
- Account and administration events, automatic bookings, learned rules and ledger events (proposals, approvals, edits) are logged.
- Bank and payment connections are used to read activity; Vezna does not initiate payments.
- The AI provider does not use data sent through its API to train its models.
- Credentials for the Client’s connections are kept out of the code, in the server environment.
Organisation
- Confidentiality commitments for everyone with access (clause 5).
- Sub-processors are bound by contract to equivalent protection (clause 7).
- Personal data breaches are handled and notified as clause 11 describes.
Annex 3 — Sub-processors
As at the effective date of this version. The current list, with the data each provider processes and the safeguards, is at vezna.ai/subprocessors.
| Provider | Purpose | Location |
|---|---|---|
| DigitalOcean, LLC | Servers and storage | Frankfurt, Germany (EU) |
| Cloudflare, Inc. | DNS, TLS and network protection | Global network |
| Anthropic | AI models (Claude) | United States |
| Google Drive and Gmail, only if the Client connects them; Google sign-in, if a user chooses it | Google’s infrastructure | |
| Resend | Invitation and password-reset emails | United States |
| Cloudflare (R2 object storage) | Encrypted off-site backups | European Union (R2 EU jurisdiction) |