Bienzoli
Legal centreData protectionUse Bienzoli free

DATA PROCESSING TERMS

Clear roles for customer data.

These processor terms apply automatically when a business uses Bienzoli to process personal data for which it is the controller.

Effective and last updated: 17 July 2026
ON THIS PAGE
Scope & rolesInstructionsSecuritySubprocessorsAssistanceIncidentsReturn & deletionProcessing details
VINCEDOTCODE LTDBRN C25220943ERN 04390814vince@vincedotcode.com
01

Scope and roles

These terms supplement the Terms & Conditions. The business using Bienzoli is the controller for personal data it enters about customers, suppliers, staff or other people (“Business Data”). VINCEDOTCODE LTD is the processor for that Business Data.

Each party will comply with the Mauritius Data Protection Act 2017 and other data-protection law applicable to its role.

02

Documented instructions

We process Business Data only to provide, secure, maintain and support Bienzoli, as described in these terms, or on other documented lawful instructions from the business. We will inform the business if an instruction appears to infringe applicable data-protection law.

We ensure that people authorised to process Business Data are subject to confidentiality duties and access it only where necessary.

03

Security measures

We maintain measures appropriate to the service and risk, including encrypted transport, managed authentication, restricted production credentials, tenant-scoped application queries, database controls, security headers, dependency review and incident procedures.

The business is responsible for secure devices, user access, strong passwords, lawful collection and avoiding sensitive information that Bienzoli is not designed to hold.

04

Approved subprocessors

The business gives general authorisation for the providers listed in our provider register. Current core providers are Supabase for authentication and database services, Vercel for hosting and delivery, and Resend for transactional email.

OpenRouter is engaged as a sub-processor for optional AI features, and only for content the business submits to those features: product photographs, and figures and product names for the weekly summary. Bienzoli routes such requests only to model providers that do not retain or train on submitted content, and does not transmit customer personal data (names, telephone numbers or email addresses) to any AI provider. A business that does not use the AI features has no data processed by this sub-processor.

We require appropriate data-protection commitments from subprocessors and remain responsible for our processor obligations. We will publish material changes to the provider register and, where appropriate, give advance notice.

05

Rights, compliance and audits

Taking account of the service and information available, we will reasonably assist the business with data-subject requests, security obligations, impact assessments and enquiries from the Mauritius Data Protection Office.

We will provide information reasonably necessary to demonstrate compliance. Any audit must protect other users, confidentiality and system security, use existing reports first and occur on reasonable written notice.

06

Personal-data incidents

We will notify the business without undue delay after becoming aware of a confirmed breach affecting its Business Data and provide available information needed for the business to meet its obligations. The business remains responsible for deciding whether and how to notify affected people or authorities as controller.

07

Return and deletion

During use, the business can view and reproduce records through Bienzoli. On closure or a verified request, we will delete Business Data from active systems within 30 days unless law requires retention. Residual backups may take up to a further 30 days to expire and remain protected while retained.

08

Processing details

Subject
Hosting and operation of the Bienzoli business-management service.
Duration
For the account term and the deletion period described above.
Operations
Collection, organisation, storage, retrieval, display, transmission, support, restriction and deletion.
People
Business users, customers, suppliers and other contacts recorded by the business.
Data
Names, contact details, notes, invoice and transaction references, product and service details, and account identifiers.
Special data
Not intended or authorised.
Bienzoli
PrivacyTermsAcceptable useData processing
Governed by the laws of Mauritius.