Data Processing Agreement
Document ID VADA-DPA · Version 1.0 · Effective 16 August 2026 · In force
This agreement governs Bernage BV’s processing of personal data on behalf of an organisation that licenses vada. It forms part of the contract described in clause 3.1 of the Organisation Licence Terms and gives effect to Article 28 of the EU General Data Protection Regulation (GDPR).
1. Scope, and who is responsible for what
1.1 This agreement applies to personal data of third parties that a Named Engineer enters into the Tool — for example the names, professional certification numbers and contact or address details of approvers and of the Organisation’s clients (“Customer Personal Data”). For that data the Organisation is the controller and Bernage is the processor.
1.2 This agreement does not apply to Account Data — the names, professional certification details and contact details of Named Engineers, and the Organisation’s billing details. Bernage is the controller of Account Data and processes it under the vada Privacy Policy.
1.3 This agreement does not apply to Derived Data — aggregated, anonymised or otherwise non-identifying records, including geometry, quantity, capacity and validation records — which Bernage processes as an independent controller under clause 9.3 of the Organisation Licence Terms. Bernage shall not use Customer Personal Data to create Derived Data except by rendering it non-identifying.
1.4 The terms controller, processor, personal data, processing, personal data breach, sub-processor, data subject and supervisory authority have the meanings given in the GDPR.
2. Details of the processing
2.1 The subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects are set out in Schedule 1, as required by Article 28(3) GDPR.
2.2 The Organisation warrants that it has a lawful basis under the GDPR to provide Customer Personal Data to Bernage and to instruct the processing described in Schedule 1, and that it has given any notice required to the data subjects.
2.3 The Organisation shall not enter special categories of personal data (Article 9 GDPR) or data relating to criminal convictions and offences (Article 10 GDPR) into the Tool.
3. Processing on documented instructions
3.1 Bernage shall process Customer Personal Data only on the Organisation’s documented instructions, including as regards transfers to a third country. The Organisation Licence Terms, this agreement, the Order and the Organisation’s use of the Tool constitute those documented instructions.
3.2 Bernage shall inform the Organisation if, in its opinion, an instruction infringes the GDPR or other Union or Member State data protection law, and may suspend the affected processing until the instruction is confirmed, withdrawn or amended.
3.3 Where Union or Member State law requires Bernage to process Customer Personal Data otherwise than on those instructions, Bernage shall inform the Organisation of that legal requirement before processing, unless the law prohibits it on important grounds of public interest.
4. Confidentiality of personnel
4.1 Bernage shall ensure that persons authorised to process Customer Personal Data are bound by an appropriate obligation of confidentiality that survives the end of their engagement, are informed of the confidential nature of the data, and receive access only to the extent required for the purposes in Schedule 1.
5. Security of processing
5.1 Bernage shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking account of the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing. The measures in place are described in Schedule 2.
5.2 Bernage may update those measures provided the level of protection is not reduced.
6. Sub-processors
6.1 The Organisation gives Bernage general authorisation to engage the sub-processors listed in Schedule 3.
6.2 Bernage shall give the Organisation at least thirty (30) days’ notice of an intended addition or replacement. The Organisation may object on reasonable data-protection grounds within that period. If the objection cannot be resolved, the Organisation may terminate the affected part of the contract without penalty, and the pilot or licence fees for the unused remainder of the term shall be refunded pro rata.
6.3 Bernage shall impose on each sub-processor, by written contract, data-protection obligations equivalent to those in this agreement, and remains fully liable to the Organisation for the performance of that sub-processor’s obligations.
7. Assisting with data-subject rights
7.1 Taking into account the nature of the processing, Bernage shall assist the Organisation by appropriate technical and organisational measures, insofar as possible, to fulfil the Organisation’s obligation to respond to requests to exercise data-subject rights under Chapter III GDPR.
7.2 If a data subject contacts Bernage directly about Customer Personal Data, Bernage shall forward the request to the Organisation without undue delay and shall not respond substantively, save to confirm that it acts as a processor and to identify the Organisation where lawful.
8. Personal data breaches, and assistance with Articles 32–36
8.1 Bernage shall notify the Organisation without undue delay and in any event within forty-eight (48) hours of becoming aware of a personal data breach affecting Customer Personal Data, providing the information then reasonably available — the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences and the measures taken or proposed — and shall supply further information as it becomes available.
8.2 Bernage shall not notify a supervisory authority or a data subject of such a breach on the Organisation’s behalf unless the Organisation instructs it in writing to do so.
8.3 Taking into account the nature of the processing and the information available to it, Bernage shall assist the Organisation in complying with its obligations under Articles 32 to 36 GDPR, including security of processing, breach notification, data protection impact assessments and prior consultation.
9. Return and deletion
9.1 On expiry or termination of the Organisation Licence Terms, Bernage shall, at the Organisation’s election, delete or return Customer Personal Data within sixty (60) days and delete existing copies, unless Union or Member State law requires it to be stored.
9.2 This does not apply to Design Documents already issued. A Design Document carries the name and certification number of the approver and the designer on its face, as a record of who approved it; Bernage retains issued Design Documents and their revision history as an integrity record of what was issued and to whom, and the Organisation retains them under the perpetual licence in clause 5 of the Organisation Licence Terms.
10. Information and audit
10.1 Bernage shall make available to the Organisation the information necessary to demonstrate compliance with Article 28 GDPR.
10.2 Bernage shall allow for and contribute to audits, including inspections, conducted by the Organisation or an auditor it mandates: on thirty (30) days’ written notice, no more than once in any twelve-month period — save where required by a supervisory authority or following a personal data breach — during business hours, subject to confidentiality obligations, and in a manner that does not unreasonably disrupt Bernage’s operations.
10.3 Bernage may satisfy an audit request by providing a relevant third-party audit report, certification or the report of its sub-processors, where these reasonably address the scope of the request.
11. International transfers
11.1 Customer Personal Data is stored in the European Union. Bernage shall not transfer it outside the EEA except to a country benefiting from a European Commission adequacy decision, or under appropriate safeguards such as the EU Standard Contractual Clauses, and shall inform the Organisation before doing so.
12. Liability, term and law
12.1 Liability under this agreement is subject to the limitations and exclusions in clause 12 of the Organisation Licence Terms, save to the extent those limitations may not lawfully be applied to obligations under the GDPR.
12.2 This agreement takes effect with the Order and continues for as long as Bernage processes Customer Personal Data. Clauses 4, 9, 10 and 12 survive its termination.
12.3 This agreement is governed by Belgian law. The courts of Brussels have exclusive jurisdiction.
Schedule 1 — Details of the processing
- Subject matter: provision of the vada bridge-design tool to the Organisation under the Organisation Licence Terms.
- Duration: the term of the Organisation Licence Terms, plus the retention described in clause 9.
- Nature and purpose: storage, retrieval, display and reproduction of third-party details entered by Named Engineers, so that those details appear on Design Documents and in the associated project and revision records.
- Types of personal data: name; professional certification or registration number; role or job title; organisation name; postal address (client); country or jurisdiction.
- Categories of data subjects: approvers designated by the Organisation; contacts at the Organisation’s clients or employers named by a Named Engineer.
- Special categories: none. See clause 2.3.
- Frequency of processing: continuous, on input by a Named Engineer.
- Retention: for as long as the associated project record is retained, then in accordance with clause 9.
Schedule 2 — Technical and organisational measures
| Measure | What is in place |
| Hosting and location | All Customer Personal Data is stored in the European Union (Frankfurt, Germany) on the Nhost platform. No Customer Personal Data is stored outside the EEA. |
| Encryption in transit | All traffic to vada.bernage.be and the backend API is served over HTTPS/TLS, and plain-HTTP requests are redirected to HTTPS. |
| Encryption at rest | Data is encrypted at rest with AES-256 by the hosting platform, covering the database, file storage and service volumes. |
| Access control | Individually authenticated accounts for the licensed-engineer area. Access is conditioned on verified professional licence status and expiry, not on sign-in alone. Credentials are personal and may not be shared. Administrative access is separated from engineer accounts and limited to those who require it. |
| Logging and monitoring | Operational events — design attempts, issuance of drawing packs, errors and abuse signals — are logged and reference the engineer profile and minimal technical facts about the event. Bernage’s stated retention period for these logs is twelve (12) months. |
| Backup and resilience | The hosting platform plan currently in use provides NO automated backups: database backups are manual only and point-in-time recovery is not enabled. Platform backups would in any event cover stored-file metadata and permissions rather than the contents of stored files. No restore has been tested. |
| Personnel | Access is limited to personnel who need it for the purposes in Schedule 1, who are bound by confidentiality obligations that survive the end of their engagement. |
| Secure development | A security review of the codebase was carried out in August 2026, including verification that no visitor identifier, device storage or IP value is present in the analytics path. |
| Sub-processor control | Sub-processors are limited to those in Schedule 3, each engaged under a written data-processing agreement imposing equivalent obligations. |
| Deletion | On instruction, Customer Personal Data is deleted or returned in accordance with clause 9, subject to the exception for issued Design Documents. |
Schedule 3 — Authorised sub-processors
Sub-processors that receive Customer Personal Data as defined in clause 1.1.
| Sub-processor | Purpose | Location |
| Nhost | Backend platform: authentication, database, file storage and serverless functions in which project records, Design Documents and operational logs are held. | EU — Frankfurt, Germany |
Bernage’s full company-level processor list — covering payments, the contact form and website hosting — is published in the vada Privacy Policy. Those processors do not receive Customer Personal Data as defined in clause 1.1.