Security & Trust Center
The procurement questions
answered in one link.
EU data residency, a subprocessor list with jurisdictions, a signable Article 28 DPA, encryption scope, RBAC, audit logging, and responsible disclosure. Send this page to your client's legal and DPO contacts instead of the back-and-forth.
Confirmed claims, not logos on trust
Each entry below is a fact about how Nimbu is built and operated. We would rather hand you a document you can verify than a certification logo you have to take on trust.
Jurisdiction
EU jurisdiction, Belgian company
Nimbu is built and operated by Zenjoy, a Belgian company. The supervisory authority is the Belgian APD. EU law governs how your client's data is handled.
Data hosting
EU-hosted customer data
Customer data is hosted in the EU. Any US-incorporated platform is reachable by US authorities under the CLOUD Act regardless of server location. That structural fact does not apply here.
Consent management
GDPR consent built into the platform
Consent and cookie management ship as part of Nimbu via the consent_manager Liquid tag and a CDN-served consent script. No third-party CMP to bolt on and audit separately.
Data agreement
Article 28 DPA, version-stamped and signable
A version-stamped Article 28 DPA your client's legal team can review and sign. It sets out roles, instructions, security measures, subprocessor terms, and breach obligations. The signed DPA governs.
Precise scope, not blanket claims
We are specific because procurement teams check it. Each item below is a verifiable fact about the platform's design.
-
Sensitive fields encrypted at rest, EU-held keys
Field-level encryption for fields marked sensitive in the Custom Field model. Not full-database encryption; we do not claim it is. Keys held in the EU.
-
TLS for all traffic in transit
Traffic to and from the platform is served over TLS. No plain-text paths.
-
OAuth2 and OIDC, granular read/write scopes
API access is scoped so an integration or agent receives exactly the permissions it is granted and no more. The CLI supports read-only mode and command allowlists for constrained automation.
-
Role-based access control, least privilege
Platform access is role-based and scoped to what a role needs. No standing broad access.
-
Audit trail for content and commerce changes
Changes are recorded with an audit trail that traces each action to an actor and a time.
-
Regular backups with defined recovery procedures
Customer data is backed up on a regular schedule. Recovery procedures are defined and tested.
Encryption in practice
Fields classified as sensitive are protected at rest by design
Encryption is part of the Custom Field model. A site marks a field as encrypted and the value is protected at rest with EU-held keys, not a setting applied after the fact. Rendered only where authorised.
- Field-level, not full-database We do not claim full-DB encryption. If that is a hard requirement, tell us and we answer specifically.
- Keys held in the EU Not a US-incorporated parent under the CLOUD Act.
- Protection by design The field type carries the protection. No post-deployment configuration step to forget.
The list your DPO reconciles, the document that governs
Third parties that process customer data on Nimbu's behalf are listed with their jurisdiction and the legal basis for any transfer. The subprocessor list is updated before a new subprocessor begins processing. Subscribed contacts are notified in advance.
Subprocessor list
Each subprocessor entry carries: name, role, country of incorporation, data-center location, and legal transfer basis. We state the basis honestly per row. We do not collapse the list into a blanket claim we cannot stand behind.
Article 28 DPA
A version-stamped DPA your client's legal team can review and sign as part of the engagement. It covers roles and instructions, security measures, subprocessor terms, and breach obligations. Available as a PDF and inline at /legal/dpa.
The signed DPA is the binding instrument. This page summarises; the document governs.
What happens when something goes wrong, and how data leaves
Breach notification, responsible disclosure, data portability. Each works the same way regardless of which client site is involved.
Breach notification
In the event of a personal-data breach, we notify affected controllers without undue delay and in line with the GDPR and the signed DPA. The notification window is set out in the DPA so the page and the document agree.
Responsible disclosure
If you have found a vulnerability, report it privately and give us a reasonable window to remediate before public disclosure. We acknowledge reports and keep you updated through remediation. Contact: security@nimbu.io
Data portability on demand
Content, products, and orders are reachable over the REST API and the CLI throughout the engagement. A client can export their data at any time rather than have it held hostage by the platform.
Retention and deletion
Customer data is retained for the life of the engagement and the period set out in the DPA. On termination, data is deleted or returned per the DPA terms. The DPA is authoritative where this summary and the document differ.
From the field
Their trust center answered the client's DPO questionnaire in one link. What used to be a two-week email loop became a single page we forwarded before the kick-off call.
Send this page, download the DPA, book a demo
Forward this page to your client's procurement and DPO contacts. Download the DPA for their legal team. Book a 30-minute intro call and see Nimbu on your own client work.
Request received.
We read every request personally and will get back to you to schedule the call.
Book a demo
We reply personally to plan a 30-minute call.
Something went wrong while sending. Please try again in a moment.