CurNext

CurNext · Legal

Data Processing Agreement

CurNext provides a Data Processing Agreement for customers who need processor terms when CurNext processes personal data for the Client's use of the platform - including customers in Finland (EU), Canada, and Cameroon.

CurNext acts as processor for Client Data instructed through the Services. Core application and database hosting for the platform is in Germany / Frankfurt. Commercial markets today: Finland, Canada, and Cameroon. Enterprise programs execute the DPA within 30 days of schedule signature.

This page is a procurement-oriented summary aligned with GDPR Art. 28 practice (roles, scope, TOMs, public subprocessors, transfer and notice language). A signed DPA is a legal instrument - final clause language should be reviewed by counsel. Do not treat this page as the executed agreement body.

Who this is for

B2B customers, procurement, and legal / security reviewers who need processor terms for CurNext SaaS and site monitoring.

  • - EU customers needing GDPR Art. 28 terms (Finland and other EEA Clients)
  • - Canadian customers needing transparency for PIPEDA / Quebec Law 25 vendor reviews
  • - Cameroon customers needing a clear controller / processor split and subprocessor map
  • - IT and security reviewers mapping subprocessors, AI vendors, and hosting regions

Markets we sell into vs where data is hosted

CurNext sells into Finland, Canada, and Cameroon. Platform Client Data for those markets is processed on the same EU-anchored production stack unless a written enterprise residency addendum says otherwise. Selling into a country is not the same as hosting a local production region there.

CurNext commercial markets versus hosting residency
MarketCommercialHostingFrameworks
Finland (EU)Operating marketCore app + database in Germany / Frankfurt; GDPR applies as EU processingGDPR; Finnish supervisory authority as applicable
CanadaOperating marketSame EU production stack - Client Data is hosted in the EU and accessed by Canadian users/admins as instructedPIPEDA and provincial rules (including Quebec Law 25 where applicable) - Client remains controller for Client Data; transfers documented below
CameroonOperating marketSame EU production stack - Client Data is hosted in the EU and accessed by Cameroon users/admins as instructedLocal data-protection obligations as applicable - Client remains controller for Client Data; transfers documented below

CurNext does not currently advertise separate production regions in Canada or Cameroon. Edge CDN, email delivery, payments, AI APIs, and observability may process limited data outside Germany - see subprocessors.

Pricing by market

Parties and roles

Where CurNext processes personal data on behalf of Client, CurNext is processor and Client remains controller for that Client Data.

DPA parties and roles
RolePartyNotes
Provider / ProcessorCurNext, Helsinki, FinlandProcesses personal data on Client instructions to deliver the Services
Client / ControllerCustomer organization (Finland, Canada, Cameroon, or other contracted Client)Determines purposes and means for personal data it instructs CurNext to process
Data subjectsTypically Client's employees, contractors, invitees, and site contactsInvite-only B2B platform users - not a B2C consumer app audience
  • - CurNext may also be controller for its own account, billing, HR, security logs of its systems, and marketing leads - see the Privacy Policy.
  • - Do not read this page as "CurNext is always only a processor."

What we process

Nature and purpose: construction and facilities site monitoring and readiness - device telemetry, BIM/site configuration, dashboards, alerts, compliance evidence, team access, APIs/webhooks, AI-assisted features where enabled, and support.

Typical categories of Client Data
CategoryExamples
Account / identityName, work email, role, org membership, invite status
Authentication contextSession and MFA status (not passwords - managed auth)
Project / site metadataProject names, building addresses Client enters, floor and room labels
Operational contentAlert recipients, tickets, uploaded plans/BIM files, notes
Device / telemetrySensor readings, device IDs, readiness scores (generally not installer PII unless Client adds it)
AI feature contextPrompts and context Client or the Services send to AI features (for example readiness assistance) - minimized and not used to train CurNext models outside product needs
Audit / securityAccess logs, permission denials, GDPR audit events (IDs preferred; emails masked in logs)

CurNext is not designed to process special-category data (for example health or biometrics for identification) as a core feature. If Client uploads such data, explicit written instructions are required.

Processing continues for the term of the Services / subscription, then return or deletion follows the DPA and termination clauses.

  • - Device telemetry should exclude installer PII unless required
  • - Logs must not contain passwords, JWTs, API keys, or full email bodies
  • - AI features should receive the minimum context needed for the task
  • - Provider will not process Client Data for unrelated purposes (for example selling personal data)

Instructions and Client responsibilities

  • - Client instructs processing via the platform UI, APIs, contracts, and written support requests
  • - Client is responsible for lawful basis, notices to data subjects, and responding to DSRs for data Client controls in their market (EU, Canada, Cameroon, or other)
  • - Client manages user invites and RBAC within their tenant
  • - Platform supports personal data export for the signed-in user (profile, memberships, preferences). A full self-serve erasure portal is not claimed here until shipped - erasure follows support and contractual process

Where processing happens

Core application compute runs on Hetzner in Germany. Managed PostgreSQL and Auth run on Supabase in Frankfurt, Germany. Customers in Canada and Cameroon use that same EU production stack for Client Data unless an enterprise addendum provides otherwise.

Datacenters

Subprocessors

Public list of third parties that may process Client personal data to deliver the Services. Industry practice is a table with purpose, data categories, and location. Enterprise terms: material new subprocessors receive at least thirty (30) days notice; Client may object on reasonable data-protection grounds. Subscribe to changes via [email protected].

Last updated: 9 August 2026

CurNext subprocessors with purpose, data categories, and location
SubprocessorPurposeData categoriesLocationPrivacy
Hetzner Online GmbHInfrastructureApplication hosting (Docker origins behind load balancers)Application data, account identifiers in app workloadsGermanyPolicy
Supabase, Inc.InfrastructureManaged PostgreSQL database and authenticationAccount, project, telemetry metadata, auth contextFrankfurt, Germany (eu-central)Policy
Cloudflare, Inc.InfrastructureDNS, TLS, WAF, CDN, Turnstile; optional R2 object storageConnection metadata, form protection signals; objects/uploads when R2 is usedGlobal edge; R2 EU jurisdiction option for objects / audit archivePolicy
SMTP2GOEmailTransactional email (invites, password flows, notifications)Email address, name, message content required to deliver mailEU data center (Amsterdam) when the CurNext account is EU-hosted; recipient delivery may reach MTAs worldwidePolicy
Stripe, Inc.PaymentsPayments and billing when usedBilling contact and payment metadata per Stripe termsPer Stripe's terms (often US/EEA processing)Policy
Google LLC (Gemini / Google AI)AIAI features in the product when Gemini is enabledPrompts and context required for the AI featurePer Google Cloud / Gemini data processing termsPolicy
Groq, Inc.AIInference for the public Knowledge Base assistant on curnext.app (after user consent), and other product AI features when Groq is enabledPrompts, chat questions, and short conversation context required for the featurePer provider data processing / privacy termsPolicy
Signicat ASIdentityElectronic identity / eID flows when used for strong authenticationIdentity attributes required for the eID transactionEEA (Norway / EU processing per Signicat)Policy
Datadog, Inc.ObservabilityApplication and infrastructure observabilityOperational logs and metrics (secrets excluded by design)Per Datadog site / region configured for CurNextPolicy
Grafana LabsObservabilityMetrics / dashboard observability when usedOperational metrics and related metadataPer Grafana Cloud region configured for CurNextPolicy
OpenWeather Ltd.DataWeather context for site / surface readiness features when usedLocation or site coordinates Client configures; weather responsesPer OpenWeather termsPolicy

Core app + database for platform Client Data: Germany / Frankfurt. AI, email delivery, payments, edge CDN, and observability may process limited personal data outside Germany. Hardware / manufacturing partners (for example Semtech, Sensirion, JLCPCB) are not listed as personal-data subprocessors unless they receive Client personal data.

International transfers

  • - Primary storage and application processing for Client Data is designed around EU hosting (Germany / Frankfurt), including for Clients in Canada and Cameroon
  • - Access by Client users in Canada or Cameroon is an international transfer / remote access pattern - Client remains controller for how it invites users in those markets
  • - Where a subprocessor transfers or accesses data outside the EEA/UK (for example Gemini, Groq, Stripe, or Cloudflare edge), Provider will use an appropriate transfer mechanism (for example EU SCCs or an adequacy decision) as required by law
  • - Canadian Clients: Provider supports PIPEDA / Law 25 vendor diligence with this list, TOMs, and counsel-approved DPA exhibits - local hosting in Canada is not claimed here
  • - Cameroon Clients: Provider supports local diligence with this list and DPA - local hosting in Cameroon is not claimed here
  • - SCC exhibits and transfer assessments are attached in counsel-approved DPA packages

Technical and organizational measures

High-level summary only. See Security Policy and the Security page for architecture detail. CurNext does not claim ISO 27001 or SOC 2 certification for itself on this page.

Technical and organizational measures summary
ControlSummary
Access controlInvite-only access; RBAC; MFA for privileged / OWNER roles
TransportHTTPS / TLS; field uplink WireGuard + MQTT mTLS (broker not public)
At restManaged DB encryption; object storage encryption when used
Tenant isolationOrganization / project scoping; RLS where applicable
Logging / auditStructured GDPR-oriented audit events; secrets not logged
BackupsEncrypted backups with restore testing in the security program
Edge protectionCloudflare WAF / TLS in front of origins
AI controlsIn-house curing prediction (TensorFlow.js) runs in the product; Gemini and Groq used only for enabled assisted features; minimize prompt context; no sale of Client Data
Incident pathGDPR Art. 33-oriented notification; enterprise 24 h target to Client security contact
Vulnerability / CRA themesSigned OTA, SBOM cadence, disclosure via [email protected]

Breach notification and assistance

Breach notification targets by agreement type
ContextTarget
Standard agreementWithout undue delay after confirmed personal data breach affecting Client Data
EnterpriseWithin 24 hours to Client's designated security contact after confirming a personal data breach or enterprise-impacting security incident affecting Client Data
RegulatoryGDPR Art. 33 path (72 h to authority where applicable) - Client/Controller obligations may differ by market (EU, Canada, Cameroon)

DSR assistance

  • - Access / export (platform export tools + support channel)
  • - Rectification (account / admin tools)
  • - Erasure / restriction (support + contractual process; audit logs may be append-only or pseudonymized per design)
  • - Portability (machine-readable export where available)

Client remains the front door for most DSRs about Client-controlled data in every operating market.

[email protected]

How to execute the DPA

Standard service terms: parties execute a DPA upon request where Provider processes personal data on behalf of Client. Enterprise schedule: execute Provider's DPA within thirty (30) days of Schedule signature (unless an existing DPA already governs).

  • - Request the executable DPA from [email protected] or via Contact (Finland, Canada, and Cameroon Clients welcome)
  • - Security overview and current subprocessor list available upon request; material changes: 30-day enterprise notice
  • - Governing law for commercial agreements: laws of Finland; courts in Helsinki, Finland (subject to mandatory protections) - align final DPA governing-law clause with counsel

Translations are provided for convenience. Where a signed agreement exists, the English instrument controls.