Legal documents
One place for Nimbu's
legal documents.
Privacy Policy, Terms of Service, Data Processing Agreement, and Cookie Policy. Each document has a clear scope and effective date. This page provides outline-level briefs. Final binding text is subject to legal review.
Document overview
Every document, one clear scope
Nimbu is operated by Zenjoy, a Belgian company under EU jurisdiction. The supervisory authority is the Belgian Data Protection Authority (APD). Customer data is hosted in the EU.
Privacy Policy
Nimbu as controller for its own site
Covers how Nimbu handles the data of visitors to nimbu.io and people who contact the team. Not about client data on the platform. That is covered by the DPA.
Terms of Service
The agreement for account holders and agencies
Sets out service scope, acceptable use, IP ownership, liability, and governing law. Includes the pathway for agencies that need a negotiated contract.
Terms of Use
The rules for users of the Nimbu platform
The usage terms that apply to everyone working in a Nimbu site: account holders, editors, and collaborators.
Data Processing Agreement
Nimbu as processor under GDPR Article 28
The document client legal and procurement teams ask for. Covers roles, processing scope, subprocessor reference, international transfers, and security measures. Available as a version-stamped PDF.
Sub-processors
Every sub-processor Nimbu relies on
The full register of sub-processors used to run the platform, with role, location, and safeguards per vendor.
Data portability
Export your data, switch without lock-in
How to export sites, content, and customer data from Nimbu, and the switching register that documents it.
Hosting & licence
The hosting and licence agreement
The full agreement covering hosting of Nimbu sites and the licence under which the platform is provided.
Illegal content
Report possibly illegal content
The DSA notice point for reporting possibly illegal content hosted on a Nimbu-powered site.
Cookie Policy
Cookies on Nimbu's own site
Covers cookies set on nimbu.io: categories, providers, and durations. Separate from the consent mechanism client sites use via the consent_manager tag.
Privacy Policy
Nimbu as data controller for its own site
This document covers the personal data Nimbu collects when you visit nimbu.io or contact the team. It does not cover data your agency processes for clients on the platform. The DPA covers that relationship.
What is collected and why
Site analytics, contact-form and demo-request data, account-administration data, and marketing-communication preferences. Each category has a stated GDPR Article 6 basis: consent, contract, legitimate interest, or legal obligation.
Retention, rights, and supervisory authority
How long each category is kept and what triggers deletion. Data-subject rights: access, rectification, erasure, restriction, portability, and objection. The supervisory authority is the APD (gegevensbeschermingsautoriteit.be).
Subprocessors and DPO contact
Nimbu's operational subprocessors for its site and marketing, with their role and jurisdiction. The contact point for privacy questions is noted in the document.
Read the full document at /legal/privacy
Terms of Service
Service scope, acceptable use, and governing law
The agreement between Nimbu and the people and agencies who use the platform. It sets out what the service is, how it may be used, who owns what, and the legal framework around the relationship.
Service scope and acceptable use
What the platform provides and the boundaries of that service. What users may and may not do, including prohibited content and conduct, and consequences of breach.
IP ownership and liability
Nimbu retains the platform. The customer retains their themes, content, and the output of their API calls. Liability allocation and any caps are stated in the document.
Governing law and enterprise pathway
Belgian law, with the competent courts named. Includes the pathway for agencies that need a negotiated contract rather than the standard terms. Changes are communicated with notice.
Read the full document at /legal/terms
Data Processing Agreement
The document your client's legal team asks for
When your agency runs client sites on Nimbu, you or your client are the controller and Nimbu is the processor. This is the GDPR Article 28 agreement that governs that relationship. Available as a version-stamped PDF.
Roles and processing scope
Who is controller and who is processor, including where an agency acts on behalf of its own client. The subject matter, duration, nature and purpose of processing, data subject categories, and types of personal data are all defined.
Subprocessors and international transfers
The subprocessor list with jurisdictions and how changes are notified. See /security for the current list. The transfer basis for any processing outside the EEA, including the transfer mechanism and supplementary measures where relevant. Customer data is hosted in the EU.
Security measures and controller assistance
Technical and organisational measures under Article 32. Customer data is hosted in the EU; sensitive customer fields are encrypted at rest with EU-held keys at the field level. Breach notification, data-subject-request support, and audit cooperation are addressed.
Download the DPA at /legal/dpa
Cookie Policy
Cookies on Nimbu's own site
This policy covers cookies set on nimbu.io. It is separate from how consent works on the client sites your agency builds. Client sites manage their own consent through the consent_manager tag.
Cookie categories and durations
Cookies are grouped into three categories: Strictly Necessary (core site function, no consent required), Analytics (measuring site usage, consent required), and Marketing (campaign and remarketing, consent required). Each category lists the provider and duration.
Consent behaviour and preferences
Non-essential categories are off by default. No pre-ticked boxes for Analytics or Marketing. Nothing in those categories is set before the visitor opts in. The policy explains how a visitor reopens their preferences after the initial decision.
Read the full document at /legal/cookies
Important note
These are outlines, not final legal text
The briefs on this page describe the scope and structure of Nimbu's legal documents. They are not the binding agreements and are not a substitute for them. Each document must be reviewed and approved by counsel before publication, and reviewed again per language before translation. Where a brief and a published document disagree, the published document governs.
Questions on any of the above: hallo@zenjoy.be.
Related pages
More on privacy, security, and EU compliance
Security and procurement
Subprocessor list with jurisdictions, the data-flow overview, APD registration reference, and the DPA download.
EU privacy as a platform feature
The narrative behind these documents: EU jurisdiction, EU-hosted data, built-in consent, and what that means for your clients and proposals.
Questions about the DPA or legal documents
Download the DPA as a version-stamped PDF, or contact us directly. We reply personally.