Aneo B.V.

Data Processing Agreement

This Data Processing Agreement forms part of the agreement between Aneo B.V. and the customer for the use of aneo products and services. It is incorporated into the Terms of Service and applies when Aneo B.V. processes Customer Personal Data as processor. This DPA has been effective since 19 November 2025 and was last updated on 24 June 2026.

Last updated: 24 June 2026

1. Parties, roles, and scope

This DPA applies to aneo.io and all subdomains and aliases operated by Aneo B.V., including examples such as app.aneo.io, api.aneo.io, docs.aneo.io, status.aneo.io, and any future subdomains under *.aneo.io.

The customer is the controller of Customer Personal Data, or the business where US state privacy laws use that term. Aneo B.V. is the processor, service provider, or processor under applicable law for Customer Personal Data.

Aneo B.V. is an independent controller for account administration data, billing data, product security telemetry, fraud prevention, website analytics where applicable, and service operations data as described in the Privacy Policy.

2. Definitions

Offerings means aneo software products and services, including cloud apps, APIs, downloadable plugins if provided, and related support. Customer Personal Data means personal data that the customer submits to or generates in the Offerings.

Applicable Data Protection Law means laws that apply to the processing of Customer Personal Data, including GDPR, UK GDPR, Swiss FADP, CCPA/CPRA and similar US state privacy laws, LGPD, PDPA, DPDP, and other applicable laws.

Sub-processor means a third party engaged by Aneo B.V. to process Customer Personal Data. SCCs means the EU Standard Contractual Clauses, Commission Implementing Decision (EU) 2021/914. UK Addendum means the UK International Data Transfer Addendum to the EU SCCs.

Zero-retention means an optional mode where certain AI prompts and outputs are not retained beyond transient processing, subject to supported provider and plan configuration.

3. Scope, nature, and purpose

Aneo B.V. processes Customer Personal Data only on the customer's documented instructions and as necessary to provide, secure, support, maintain, and improve the contracted Offerings. Documented instructions include the agreement, this DPA, product configuration, user actions, support requests, and lawful customer administration of the Offerings.

Processing includes account setup, authentication, framework and control selection, policy and document generation, incident response workflows, AI-assisted guidance, storage, backup, retrieval, transmission, logging, monitoring, support, billing, security operations, deletion, and other operations needed to provide the Offerings.

Framework-Pro processing may include questionnaire responses, framework selection, ISO 27001 and NIST CSF control mapping, policy drafts, scope documents, supporting resources, generated outputs, and payment-related metadata. IncidentAI processing may include incident tickets, classifications, categories, timelines, owners, response actions, MITRE ATT&CK mapping context, summaries, evidence notes, and closure records.

4. Categories of data and data subjects

Data subjects may include customer employees, contractors, administrators, end users, security analysts, incident owners, stakeholders, and counterparties named in uploaded documents, tickets, evidence notes, or product records.

Categories of Customer Personal Data may include identification data, business contact data, authentication data and tokens, roles and permissions, usage logs, device data, uploaded documents, incident tickets, policy drafts, questionnaire answers, prompts, AI outputs, support information, and evidence notes.

Customers should avoid special category data, criminal-offence data, payment card data, secrets, credentials, and other highly sensitive data unless there is a lawful basis, appropriate safeguards, and a written agreement with Aneo B.V. that permits that processing.

5. Customer instructions

Aneo B.V. will process Customer Personal Data only on documented customer instructions unless required by applicable law. If Aneo B.V. is required by law to process Customer Personal Data outside the customer's instructions, Aneo B.V. will inform the customer before processing unless the law prohibits notice.

If Aneo B.V. believes an instruction violates Applicable Data Protection Law, it may notify the customer and suspend the affected processing where appropriate.

6. Data regions and international transfers

Core product processing is intended to be configured in EU regions where practical. Aneo B.V. may deploy on Google Cloud Platform EU regions and may use Supabase EU for the application database where used by the relevant product or configuration.

If Customer Personal Data is transferred outside the EEA, United Kingdom, or Switzerland, Aneo B.V. will use a valid transfer mechanism. The SCCs, and where applicable the UK Addendum and Swiss addendum, apply as set out in Annex I.

7. Confidentiality

Aneo B.V. ensures persons authorized to process Customer Personal Data are under appropriate confidentiality obligations and receive security and privacy training appropriate to their role.

Access to Customer Personal Data is limited to personnel and Sub-processors who need access to provide, support, secure, or maintain the Offerings.

8. Security

Aneo B.V. implements appropriate technical and organizational measures designed to protect Customer Personal Data, including encryption in transit and at rest where appropriate, access controls, MFA for administrative access where available, least privilege, logging and monitoring, vulnerability management, secure development, incident response, backups, and regular testing.

Security measures may evolve over time, provided the overall level of protection is not materially reduced. A summary of security measures is included in Annex II and additional information is available in the Security Overview.

9. AI-specific safeguards

AI outputs are informational and require human review. They are not legal advice, security guarantees, compliance certifications, or substitutes for accountable customer decision-making.

Aneo B.V. may use vetted model providers to perform inference. Customer Personal Data is not used to train foundation models unless the customer opts in or agrees in writing.

On supported plans or configurations, customers may enable zero-retention for certain AI prompts and outputs. Logs, security telemetry, billing records, abuse prevention records, and operational data may still be retained where needed for security, billing, legal, or service operation purposes.

10. Sub-processors

The customer authorizes Aneo B.V. to engage Sub-processors to support the Offerings. Current Sub-processors and processing purposes are listed at https://www.aneo.io/subprocessors/.

Aneo B.V. will provide at least 15 days' advance notice of material Sub-processor changes by updating the Sub-processors page and, where practical or required, notifying customer administrators by email.

The customer may object within the notice period on reasonable data protection grounds. The parties will discuss the objection in good faith. If the objection cannot be resolved, the customer may suspend the affected features or terminate the affected order for convenience with a prorated refund for unused prepaid fees for the affected part of the Offerings, unless a signed agreement states otherwise.

Aneo B.V. contracts with Sub-processors under data protection terms no less protective than this DPA in all material respects.

11. Assistance and data subject requests

Aneo B.V. provides reasonable assistance to help the customer respond to data subject requests, regulator inquiries, privacy impact assessments, data protection impact assessments, prior consultations, and other obligations related to the Offerings.

If Aneo B.V. receives a request relating to Customer Personal Data directly, it will promptly notify the customer where appropriate and will not respond except on the customer's documented instructions, unless required by law.

12. Personal data breach notification

Aneo B.V. maintains incident response procedures for suspected personal data breaches. If Aneo B.V. becomes aware of a personal data breach affecting Customer Personal Data, it will notify the affected customer without undue delay and, in any case, within 72 hours of becoming aware where required by applicable law or agreement.

The notification will describe known details, likely consequences, remediation steps, and a contact point where available. Customers remain responsible for determining whether notification to supervisory authorities, individuals, customers, insurers, or other third parties is required.

13. Audit and verification

Aneo B.V. makes available information reasonably necessary to demonstrate compliance with processor obligations, including security and privacy documentation, summaries, questionnaire responses, and third-party audit reports where available.

On written request, and no more than once per 12 months unless required by law or after a confirmed material incident, the customer or its independent auditor may conduct a reasonable audit subject to confidentiality, at least 30 days' prior notice, reasonable scope, and no disruption to Aneo B.V. operations.

Remote audits, documentation reviews, and report reviews will be used before any on-site visit.

14. Return and deletion

Upon termination or expiry of the agreement, the customer can export Customer Personal Data using available tools where supported by the relevant product.

After termination, Aneo B.V. will delete or de-identify Customer Personal Data within 30 days from active systems and within 90 days from backups, unless retention is required by law, dispute, security investigation, accounting obligation, or legal claim.

15. US state privacy laws

Where CPRA or similar US state privacy laws apply, Aneo B.V. acts as a service provider or processor for Customer Personal Data. Aneo B.V. will not sell or share Customer Personal Data, will not combine Customer Personal Data except as permitted for service provider or processor purposes, and will provide assistance required by applicable law.

16. Government and third-party requests

Aneo B.V. will notify the customer of any binding request for disclosure of Customer Personal Data by a government, law enforcement authority, regulator, or third party unless legally prohibited.

Aneo B.V. will challenge unlawful or overbroad requests to the extent reasonable and legally permitted.

17. Liability and precedence

The limitations and exclusions of liability in the applicable agreement apply to this DPA unless a signed agreement states otherwise.

If there is a conflict between this DPA and the agreement, this DPA controls for processing of Customer Personal Data. If there is a conflict between this DPA and the SCCs, the SCCs control for transfers governed by the SCCs.

18. Changes

Aneo B.V. may update this DPA to reflect changes in law, products, providers, security measures, or processing activities. Material changes will be notified to customers where required by agreement or law. Continued use after the effective date of an updated DPA constitutes acceptance where permitted by law.

19. Annex I: International transfers

The EU Standard Contractual Clauses, Module 2 controller to processor, are incorporated by reference where required. Execution of the agreement is deemed execution of the SCCs. The UK Addendum is incorporated for transfers subject to UK GDPR. References to GDPR in the SCCs are read as references to the Swiss FADP where appropriate.

Exporter: the customer as controller, with address and contact as stated in the order, account profile, or customer records. Importer: Aneo B.V., Thomas Morelaan 104, 2135 WC Hoofddorp, Netherlands. Contact: legal@aneo.io.

Description of transfer: categories of data subjects and data, frequency, nature, purpose, and retention are described in this DPA. Sub-processors are listed at https://www.aneo.io/subprocessors/. Technical and organizational measures are summarized in Annex II.

20. Annex II: Security measures summary

Aneo B.V. uses a layered security program appropriate to the nature of the Offerings, Customer Personal Data, and processing risk.

  • Organization and governance: security policies, defined roles, confidentiality obligations, and regular training.
  • Access control: unique IDs, strong authentication, MFA for administrative access where available, least privilege, and timely provisioning and deprovisioning.
  • Data protection: encryption in transit and at rest where appropriate, key management, logical isolation, and access restrictions.
  • Application security: secure development practices, code review, dependency scanning, secret management, vulnerability remediation, change control, and periodic testing.
  • Logging and monitoring: centralized security-event logging, alerting for anomalies, time synchronization, and restricted log access.
  • Availability and resilience: managed infrastructure, EU regions for core data where practical, backups, restore testing, capacity monitoring, and disaster recovery planning.
  • Incident response: documented response plan, breach assessment and notification, remediation tracking, and post-incident review.
  • Vendor management: security review before onboarding, contractual protections, and periodic review.
  • Privacy by design: data minimization, pseudonymization where practical, configurable retention and region options, and customer controls for access, export, and deletion.

21. Annex III: Stack and Sub-processors

Current providers are listed at https://www.aneo.io/subprocessors/. Informative provider categories may include Google Cloud Platform EU for hosting, Supabase EU for database services, Firebase Authentication for authentication, OAuth via Google, Microsoft, and LinkedIn as identity providers where enabled, OpenAI for model inference, Hostinger for website hosting and DNS, HubSpot for CRM and customer communication, Google Workspace for email and collaboration, and Google Analytics 4 for analytics subject to consent where enabled.

Provider use may vary by product, plan, region, and customer configuration.

22. Contact

For privacy and data protection matters, contact legal@aneo.io or privacy@aneo.io.

General enquiries can be sent to hello@aneo.io.

Postal address: Aneo B.V., Thomas Morelaan 104, 2135 WC Hoofddorp, Netherlands.