Nimbu Platform Privacy Statement
Version 2.3 — 27 July 2026 • Nimbu, a platform by Zenjoy BV
This document is a courtesy translation. Only the Dutch version is legally binding; in case of any discrepancy, the Dutch text prevails.
This statement concerns personal data that Zenjoy BV processes for its own purposes in the delivery, security and administration of Nimbu. For personal data that a Customer processes via its own website, web application, forms, databases, shop or app, that Customer is in principle the controller and Zenjoy is the processor under the Nimbu Data Processing Agreement (DPA).
Where Zenjoy consults or processes customer data, logs or records solely to perform a service requested by the Customer — for example during support investigations in the Customer's environment, backup, restoration or security of customer environments — Zenjoy acts as a processor on behalf of that Customer under the DPA and this statement does not apply. The role is determined per individual purpose according to the actual processing.
1. Controller and contact
Zenjoy BV, Blijde Inkomststraat 22, 3000 Leuven, KBO BE 0838.367.436, is the controller for the processing operations described in this statement.
Questions and requests concerning personal data may be addressed to help@zenjoy.be. Reports of potentially illegal hosted content belong at abuse@zenjoy.be.
2. Which data do we process, why and on which basis?
Account, access and authentication
We process name, business or private contact details, profile, account, role, authentication and access data in order to grant and secure access. Legal basis: performance of the agreement for the Account Owner and our legitimate interest in correct and secure access for other Users (Article 6(1)(b) and (f) GDPR).
Customer management, invoicing and contract administration
We process identification, contact, company, invoicing, payment-status, contract and correspondence data of Customers and contact persons. Legal basis: performance of the agreement, statutory tax and accounting obligations and legitimate customer management (Article 6(1)(b), (c) and (f) GDPR).
Electronic acceptance and proof of authority
We record the identity and stated function of the accepting person, the identified Customer and the account, date and time, document version or hash, language and, insofar as available and necessary, the IP address. This serves to demonstrate the conclusion of the contract, the applicable version and representation. Legal basis: performance of the agreement and our legitimate interest in legal certainty and dispute prevention (Article 6(1)(b) and (f) GDPR).
Platform security, logging and fraud prevention
We process technical logs, IP addresses, device, connection, event and security data in order to detect, investigate and prevent malfunctions, misuse, unauthorised access, fraud and security incidents. Legal basis: our legitimate interest and our statutory security obligations (Article 6(1)(c) and (f) GDPR).
Support and service communication
We process data from support requests, error reports and service communication in order to provide assistance, follow up on incidents and inform Customers. Legal basis: performance of the agreement and legitimate customer management (Article 6(1)(b) and (f) GDPR).
Reports of illegal content
In the case of a DSA report, we process the name and e-mail address of the reporter, the reported URL, evidence and explanation, our assessment, communication and decision. Legal basis: compliance with Regulation (EU) 2022/2065 and our legitimate interest in safe and lawful hosting (Article 6(1)(c) and (f) GDPR). For reports concerning the sexual offences against children referred to in the DSA, the reporter may be legally exempted from identification.
Which data are mandatory?
Identification, contact, invoicing, contract and necessary account data are, depending on the situation, contractually necessary to create a Nimbu account, grant access, conclude and perform an agreement or comply with statutory accounting and tax obligations. You are not legally obliged to provide this data, but without this data we may not be able to open an account, grant access, invoice or conclude or perform the agreement. Data that is not necessary is indicated as optional where appropriate.
3. From whom do we receive data?
We receive data from the Account Owner, Users, contact persons of the Customer, our technical systems and security tools, suppliers that support the Services and persons or authorities that submit a report or request.
4. Retention periods
- Active account and profile data: for the duration of the service provision. After termination, the transition and retrieval period of in principle thirty days applies, followed by deletion in accordance with the Hosting and License Agreement and DPA.
- Backups: after the transition and retrieval period, the data concerned is deleted from the active systems. Residual copies in already existing secured backups are not used operationally and disappear upon expiry of the documented backup cycle, at the latest twelve months after the end of the retrieval period. Upon restoration, earlier deletions are reapplied before the environment is used operationally.
- Invoices and accounting documents: for the statutory period, in principle ten years from 1 January of the year following issuance.
- Contracts and proof of acceptance: for the duration of the agreement and a maximum of ten years thereafter, or longer as long as a specific dispute or statutory retention requires this.
- Application and system logs: thirty days hot and searchable and thereafter a maximum of one year cold/archived, unless a relevant incident requires longer separate retention.
- Metrics: fourteen days at full resolution and downsampled for a maximum of two years.
- Support communication: a maximum of five years after closure of the request, unless longer retention is needed for an ongoing contract, incident or dispute.
- DSA reports and decisions: a maximum of five years after closure, unless proceedings or a statutory obligation require longer retention.
We delete or anonymise earlier when data is no longer needed and no statutory or legitimate reason for retention exists.
5. Recipients and sub-processors
Only authorised employees and suppliers that need the processing are granted access. For platform hosting and processing on instruction we use the current sub-processors at https://www.nimbu.io/sub-processors. Important categories are OVHcloud for hosting, storage, primary backup and logs, Hetzner for encrypted offsite backups, Scaleway for transactional e-mail, Bunny.net for DNS and CDN and Mistral AI for AI-based spam detection on form submissions (processing within the EEA, with zero data retention).
We provide data to authorities where the law requires this and limit the provision to what is required. We do not sell personal data.
6. International transfers
Primary hosting, databases, primary and offsite backups and transactional e-mail processing take place within the EEA. Bunny.net may process publicly retrievable website content, technical request data and IP addresses via worldwide edge locations. For transfers outside the EEA we use an adequacy decision where applicable and otherwise the relevant standard contractual clauses of the European Commission and supplementary measures where required.
GlitchTip and the in-house spam and abuse filters run self-hosted within the Nimbu infrastructure; their software suppliers therefore receive no production data. For additional spam detection on form submissions we engage Mistral AI as a sub-processor; that processing takes place within the EEA with zero data retention and under a data processing agreement.
Information about the applicable transfer safeguards and, insofar as permitted, a copy of the relevant standard contractual clauses may be requested via help@zenjoy.be. Confidential business information and security-sensitive data may be appropriately redacted in doing so.
7. Security
We take risk-based technical and organisational measures, including encryption, TLS, strong authentication and MFA for infrastructure management, central access management, tenant isolation, monitoring, vulnerability follow-up, offsite backups and periodic restore tests. A more detailed description is set out in Annex B to the DPA.
8. Your rights
You may, depending on the statutory conditions, request access, rectification, erasure, restriction and portability, and object to processing based on legitimate interest. Where processing is based on consent, you may withdraw it without affecting earlier lawful processing.
Send your request to help@zenjoy.be. We may ask for reasonable additional information where this is necessary to verify your identity and authority. We respond within the statutory period.
If your request concerns personal data in the website, database, shop or application of a Nimbu Customer, please address it first to that Customer as controller. We assist the Customer in accordance with the DPA.
9. Complaint
You may lodge a complaint with the Data Protection Authority, Drukpersstraat 35, 1000 Brussel, contact@apd-gba.be, https://www.gegevensbeschermingsautoriteit.be.
10. Automated decision-making
For its own processing operations described here, Zenjoy does not take decisions based solely on automated processing that produce legal effects or similarly significantly affect you. Automatic security and spam filters may, however, block technical traffic or messages; legal decisions about specific customer content are not taken solely by automated means.
11. Changes
The version and date at the top show the latest change. In the event of a material change, we inform affected Users or Customers via the admin environment, e-mail or another appropriate channel.