Data Processing Agreement

Last updated: 31 August 2026

1. Parties and scope

This Data Processing Agreement is entered into between Stevin.AI B.V., trading as Stevin.AI (the Processor), and the Customer using the Stevin platform (the Controller). It forms an integral part of the Terms of Service and governs the processing of personal data under Article 28 of the GDPR.

2. Subject matter

Stevin processes personal data on behalf of the Customer that originates from connected marketing and advertising platforms (Google Ads, Meta, GA4, Search Console, etc.), CRM systems, and email and call integrations. The sole purpose is to deliver the Stevin platform and its reports, signals and advisories.

3. Nature and duration

Processing lasts for the duration of the agreement between Customer and Stevin. Nature: automated retrieval, analysis, storage and presentation via dashboards and notifications. Categories of data subjects: Customer users, end-customers of Customer, prospects and CRM leads. Categories of personal data: name and address, contact details (email, phone, LinkedIn), job title, company data, online behaviour (campaign interactions, page views, search queries) and communications (emails, call transcripts insofar as Customer shares these).

4. Processor obligations

  • Stevin processes personal data only on documented instructions from Customer, unless required by law.
  • Personnel with access are bound by confidentiality.
  • Stevin implements appropriate technical and organisational measures (section 7).
  • Stevin assists Customer with data-subject rights requests, breach notifications, DPIAs and consultations with the supervisory authority.
  • Stevin deletes or returns personal data within 60 days after termination, at Customer's choice.
  • Stevin provides Customer with the information needed to demonstrate compliance with Article 28, and allows audits (section 9).

5. Sub-processors

Customer grants Stevin general authorisation to engage sub-processors. Current material sub-processors:

  • Supabase (database hosting, EU region)
  • AWS (compute and object storage, EU-Frankfurt)
  • Vercel (frontend hosting, EU region where possible)
  • Anthropic, OpenAI, Mistral, Google (AI inference, under data-processing addenda; no training on Customer data)
  • Resend (transactional email)
  • Slack (notification channel)

Changes are announced at least 30 days in advance by email. Customer may object in writing within that period.

6. International transfers

Where a sub-processor processes personal data outside the EEA, Standard Contractual Clauses (EU 2021/914) and additional safeguards apply. Stevin prefers EU-only hosting where technically feasible.

7. Security

  • Encryption at rest (AES-256) and in transit (TLS 1.2+)
  • Row-level security in the database, service-role isolation
  • Tenant-scoped data: agency A never sees agency B data
  • OAuth tokens stored encrypted, rotated periodically
  • Access logging to tenant data, 12-month audit trail
  • Periodic penetration tests and automated dependency scanning (Aikido)
  • Backups: daily incremental, 7 to 30 days retention
  • 2FA mandatory for all staff with production access

8. Data breaches

Stevin notifies Customer of any suspected or confirmed personal data breach without undue delay after becoming aware of it, via the designated contact address, with the information Customer needs for any onward notification to the Dutch Data Protection Authority or to data subjects.

9. Audit

Customer may conduct (or have conducted) one audit per calendar year, at Customer's cost, with at least 30 days written notice and subject to confidentiality. Stevin may instead provide a recent independent audit report (such as SOC 2 or ISO 27001) where available.

10. Liability

Liability under this DPA is limited as set out in the Terms of Service, without prejudice to the statutory liability towards data subjects under Article 82 GDPR.

11. Governing law

This agreement is governed by Dutch law. Disputes are submitted to the competent court in Breda, the Netherlands.

Stevin.AI is the trade name of Stevin.AI B.V., registered with the Dutch Chamber of Commerce (KvK) under number 42138941, with its registered seat in Breda, the Netherlands, VAT number NL869893610B01.

Contact: info@stevin.ai