Data Processing Agreement
Last updated: 16 September 2026
Your team writes things into Penholder that count as personal data: names, email addresses, who suggested what, who is doing it. Under the GDPR that makes your company the controller and us the processor, and it means the two of us need an agreement about how we handle it. This is that agreement, written to be read rather than filed.
1. Who this is between, and when it applies
This agreement is between the company or person whose account it is, called you here, and ZOOMERS NETWORK LGTM S.R.L. (CUI 51548084), called we or us. It is part of our Terms of Service and applies from the moment you start using Penholder, for as long as you have an account. You do not need to sign anything. If your company needs a signed copy for its records, write to privacy@penholder.app with the name and address to put on it and we will send one back signed.
Two roles, kept apart on purpose. For what your team puts into Penholder, you decide and we only carry out: you are the controller, we are the processor, and this agreement covers it. For the account relationship itself, the address we send invoices and password resets to, the records we keep to stop abuse, we decide, so there we are the controller and our Privacy Policy covers it.
2. What we do with your team's data
- Why: to run Penholder for you, and nothing else. No advertising, no profiling, no selling, no training anything on your content.
- What we do with it: store it, show it to the people on your team, email them about it, back it up, and delete it when you say so.
- For how long: for as long as your account exists, and then as section 10 says.
- Whose data: the people on your teams, and the people you invite to them.
- What kind: names, email addresses, an optional photo, the password as a scrypt hash, and everything your team writes: teams, projects, topics, items, the reasons behind them, fields, flags, images, who is assigned to what, and the history of who changed what. Your card details are not in that list: they go straight to Stripe and we never see them.
- What we never ask for: special categories of data, the sensitive kinds the GDPR singles out. Penholder is not built for them, so please keep them out of it.
3. We act on your instructions
We process your team's data only on your documented instructions, which are these terms, this agreement, and whatever you and your team do in the app or through the API. We do not use it for anything of our own. If the law ever forces us to do something else, we will tell you first unless that same law forbids it. If we think an instruction of yours breaks data protection law, we will say so.
4. Who can see it
Everyone who works on Penholder is bound to confidentiality, and only the people who genuinely need production access have it, which today is a very short list. Your team's content is reached only to keep the service running or to fix something you have asked us to fix.
5. How we keep it safe
What we actually do, not a wish list:
- Everything travels over HTTPS, and the site is served behind Cloudflare.
- Passwords are stored as scrypt hashes, never as you typed them. API tokens are stored as a SHA-256 hash and shown once.
- Sessions use signed, HttpOnly, Secure cookies that expire after 30 days. Emailed links, invitations, password resets and confirmations, expire within a week.
- Sign-in, sign-up, password reset and invitations are rate limited, and a human check stands in front of them.
- The database and the file storage are managed services that encrypt what they hold at rest.
- Uploaded images are re-encoded, which removes hidden details such as where a photo was taken.
- The API only answers requests that come through our own front door, checked with a shared secret.
- A backup is written every day and deleted after 30 days.
- Only an owner can see a team's billing, and only members of a team can see anything in it.
We keep this up to date as Penholder changes. If a measure here stops being true, the page changes with it.
6. Who helps us
You agree that we can use the companies below, the sub-processors in the GDPR's word for them, and that we stay responsible for what they do with your data. Each of them is under a data processing agreement with us. The sub-processors page is the same list with what each one receives and where, kept current.
- Cloudflare, United States and worldwide edge: serves the site, stores uploaded images and backups, and runs the human check on sign-in.
- FastAPI Cloud, United States: runs the application server.
- Supabase, United States: hosts the database.
- Brevo, European Union: sends our emails.
- Stripe, United States and Ireland: takes payments for teams that pay.
- Google, United States: confirms who you are, but only for people who choose to sign in with Google.
If we add one or swap one out, we will say so on this page and email the owner of every paying team at least 30 days before it starts. If you object on reasonable data protection grounds within those 30 days, tell us at privacy@penholder.app. If we cannot find a way through it together, you can stop using Penholder and we will refund the time you paid for and did not get.
7. Where the data is
We are in Romania, so your data starts in the European Union. Some of the companies in section 6 are in the United States, and when data reaches them it is covered by the EU-US Data Privacy Framework where that company is certified under it, and otherwise by the European Commission's Standard Contractual Clauses, which we have in place with each of them. Where those clauses apply, they are part of this agreement, with you as data exporter and us acting on your behalf.
8. When someone asks about their data
If a person on your team writes to us directly, we will not answer for you: we will point them at you and tell you it happened. If you need help answering, tell us what you need and we will help, at no charge for anything reasonable. A lot of it you can do yourself inside the app, without asking us: see and edit a profile, export a topic's items and history as CSV, remove someone from a team, or delete a team outright. We will also help with a data protection impact assessment or a conversation with a supervisory authority, as far as what we know is any use to you.
9. If something goes wrong
If personal data of yours is breached, we will tell you without undue delay and in any case within 48 hours of us becoming aware, with what we know: what happened, who is affected, what the likely consequences are, and what we are doing about it. If we do not know everything yet we will send what we have and follow up rather than wait.
10. Getting it back, and deleting it
Any time you like, you can export a topic's items and its history as CSV, and the API gives you everything else in JSON. When you delete a team, its projects, topics, items, images and history go with it. When you delete your account, your profile and photo go, along with any team where you were the only member. Backups are deleted after 30 days, so a copy can survive in a backup for that long and no longer. Team history older than 12 months is deleted every day whether you ask or not. If you close your account and want written confirmation that everything is gone, ask and we will send it.
11. Checking on us
Ask and we will tell you what you need to satisfy yourself that we are doing what this page says. Once a year, or after a breach that affected you, you can audit us: give us 30 days' notice, keep it to what is relevant, and expect it to be remote unless there is a reason it cannot be. You cover the cost unless the audit finds we broke this agreement.
12. How this fits with the Terms
This agreement is part of the Terms of Service. If the two ever disagree about how we handle personal data, this page wins. Everything else in the Terms, including the limits on what we owe each other, applies here too. Romanian law applies, as it does to the Terms.
13. Talk to us
Anything about this agreement, a signed copy, a question from your own data protection officer: privacy@penholder.app. Our full company details are on the company details page.