Legal
Data Processing Agreement
How Thynex processes personal data on behalf of the stores that use it, as required by the GDPR. Part of our Terms of Service. Last updated 1 October 2026.
1. Parties and scope
This Data Processing Agreement (“DPA”) is between the business that uses Thynex (the “Customer”, controller) and Thynex, a sole proprietorship (eenmanszaak) registered with the Dutch Chamber of Commerce (KvK) under number 91791987, with its office at Irisstraat 14, 7151 VT Eibergen, the Netherlands (“Thynex”, processor).
It forms part of our Terms of Service and applies whenever Thynex processes personal data on the Customer’s behalf to provide the Service (“Customer Personal Data”). It meets the requirements of Article 28 of the General Data Protection Regulation (“GDPR”). If this DPA and the Terms conflict on data protection, this DPA prevails.
2. Definitions
Terms such as “personal data”, “processing”, “controller”, “processor”, “data subject” and “personal data breach” have the meaning given in the GDPR. Other capitalised terms have the meaning given in the Terms of Service.
3. What we process
The subject, nature, purpose, types of personal data and categories of data subjects are described in Annex 1. We process Customer Personal Data for as long as we provide the Service, and afterwards only as described in section 12.
4. Instructions
- We process Customer Personal Data only on the Customer’s documented instructions, unless EU or Dutch law requires otherwise. If it does, we tell the Customer first, unless the law forbids that.
- The Terms, this DPA and the Customer’s use and configuration of the Service, such as connected stores and channels, Venus settings, Guardrails, approvals and scenarios, are the Customer’s instructions.
- We tell the Customer straight away if we believe an instruction breaks the GDPR or other data protection law.
- The Customer is responsible for having a lawful basis for the processing and for informing its end customers, including that they may be talking to an AI system.
5. Confidentiality
Everyone at Thynex who can access Customer Personal Data is bound to confidentiality. We look at conversations only when needed to provide, support or secure the Service, or when the Customer asks us to. Such staff access requires two-factor authentication and every view of a conversation is logged.
6. Security
We take appropriate technical and organisational measures to protect Customer Personal Data, taking into account the state of the art, the costs, and the nature, scope, context, purposes and risks of the processing. The current measures are listed in Annex 2. We may change them, as long as the overall level of protection does not go down.
7. Sub-processors
- The Customer authorises Thynex to use sub-processors. The current sub-processors are listed in Annex 3.
- We tell the Customer by email at least 30 days before we add or replace a sub-processor. The Customer may object on reasonable data protection grounds within that period. If we can’t resolve the objection, the Customer may end the affected part of the Service without penalty, and we refund any fees paid in advance for the period after it ends.
- We bind every sub-processor to data protection obligations at least as protective as this DPA, and we remain responsible for their work.
- Services the Customer connects itself, such as its store platform, messaging channels, shipping and returns providers, Slack and other integrations, are not our sub-processors. The Customer has its own agreement with them, and we exchange data with them on the Customer’s instructions.
8. Transfers outside the EU
We host and process Customer Personal Data in the European Union. If a sub-processor processes it outside the European Economic Area, we make sure the transfer is covered by an adequacy decision or by the European Commission’s Standard Contractual Clauses, with additional measures where needed.
9. Helping the Customer
- The Service lets the Customer find, export, correct and delete the data of its end customers. Where the Customer can’t do this itself, we help it answer requests from data subjects.
- If a data subject contacts us directly, we pass the request on to the Customer and don’t answer it ourselves, unless the Customer asks us to.
- We help the Customer, with the information we have, with data protection impact assessments and prior consultations with a supervisory authority.
10. Personal data breaches
We notify the Customer without undue delay, and at the latest within 48 hours, after we become aware of a personal data breach affecting Customer Personal Data. We share what we know about the nature of the breach, the data and data subjects involved, the likely consequences and the measures taken or proposed, and we add information as it becomes available. We take reasonable steps to contain the breach and limit its effects.
11. Venus and AI models
- Venus uses Customer Personal Data only to provide the Service to that Customer: to draft and send replies, search its knowledge and catalogue, and carry out actions within its settings.
- Payment card numbers and passwords are redacted before any text is sent to the AI model provider. The provider may not use Customer Personal Data to train its own models.
- We use Customer Personal Data to improve the models behind Venus only if the Customer switches on “Let Thynex learn from your conversations” (off by default). We then keep its AI interactions with email addresses, phone numbers and postcodes masked, and may use them to improve the models we use for all customers. Switching the setting off deletes what was kept, and erasing an end customer deletes their data from it.
12. End of the Service
When the Service ends, the Customer has 30 days to export its data. After that we delete Customer Personal Data, including copies, unless EU or Dutch law requires us to keep it. Data in backups is overwritten in the normal backup cycle.
13. Information and audits
We make available the information needed to show that we meet this DPA. The Customer may have our compliance audited once a year, with at least 30 days’ notice, during business hours, by an independent auditor bound to confidentiality, at the Customer’s own cost. An audit may not give access to other customers’ data.
14. Liability
The limitations of liability in the Terms of Service apply to this DPA, except where the GDPR does not allow them.
15. Duration, law and contact
This DPA applies for as long as we process Customer Personal Data. It is governed by Dutch law, and disputes are handled as set out in the Terms of Service. Questions: hello@thynex.ai.
Annex 1. Description of the processing
- Data subjects: the Customer’s end customers and prospects who contact it through the Service, and the Customer’s own users, such as agents.
- Types of personal data: contact details (name, email address, phone number, social media handles); conversation content and attachments; order and shipment details (order numbers, products, delivery addresses, tracking information); identifiers in connected stores and channels; technical data from the chat widget (such as IP address and browser); satisfaction ratings; and user account data of the Customer’s agents.
- Special categories of data: not intended. End customers may still include them in their messages; the Customer should not ask for them.
- Nature and purpose: receiving, storing, organising, searching and displaying customer conversations; generating draft and automatic replies with AI; looking up and, within the Customer’s settings and approvals, changing orders in connected stores; verifying customers’ identity by email codes; sending messages and emails on the Customer’s behalf; and reporting on support performance.
- Duration: the term of the Customer’s subscription, plus the 30-day export period.
Annex 2. Security measures
- Hosting in data centres in the European Union (Amsterdam, the Netherlands); encrypted connections (TLS) for all traffic to the app.
- Strict separation between customer accounts: every lookup is scoped to the account it belongs to.
- Access tokens and credentials for connected services are stored encrypted.
- Role-based access for the Customer’s own users; two-factor authentication available for every user and required for Thynex staff with admin access; every staff view of a conversation is logged.
- Payment card numbers and passwords are redacted before text is sent to the AI model provider.
- Before Venus changes an order, the end customer proves they own it with a code sent to the order’s email address; risky actions wait for human approval under the Customer’s settings.
- Technical logs of AI requests are kept for 30 days and usage records of Venus replies for 180 days. Neither contains message text.
- A database backup is made before every software update.
- Code changes are reviewed, including for security, before release, and software dependencies are kept up to date.
Annex 3. Sub-processors
- DigitalOcean, LLC — hosting of the Thynex app and database. Location: Amsterdam, the Netherlands (EU). Transfer safeguard: Standard Contractual Clauses, as DigitalOcean belongs to a US group.
- Mistral AI SAS — AI language models and search embeddings for Venus. Location: France (EU).
- Titan (email service provided through Hostinger) — delivery of service emails, such as notifications and order verification codes. Location: may be outside the EU; transfer safeguard: Standard Contractual Clauses.