CurNext · Legal
Data Processing Agreement
CurNext provides a Data Processing Agreement for customers who need processor terms when CurNext processes personal data for the Client's use of the platform - including customers in Finland (EU), Canada, and Cameroon.
CurNext acts as processor for Client Data instructed through the Services. Core application and database hosting for the platform is in Germany / Frankfurt. Commercial markets today: Finland, Canada, and Cameroon. Enterprise programs execute the DPA within 30 days of schedule signature.
This page is a procurement-oriented summary aligned with GDPR Art. 28 practice (roles, scope, TOMs, public subprocessors, transfer and notice language). A signed DPA is a legal instrument - final clause language should be reviewed by counsel. Do not treat this page as the executed agreement body.
Who this is for
B2B customers, procurement, and legal / security reviewers who need processor terms for CurNext SaaS and site monitoring.
- - EU customers needing GDPR Art. 28 terms (Finland and other EEA Clients)
- - Canadian customers needing transparency for PIPEDA / Quebec Law 25 vendor reviews
- - Cameroon customers needing a clear controller / processor split and subprocessor map
- - IT and security reviewers mapping subprocessors, AI vendors, and hosting regions
Markets we sell into vs where data is hosted
CurNext sells into Finland, Canada, and Cameroon. Platform Client Data for those markets is processed on the same EU-anchored production stack unless a written enterprise residency addendum says otherwise. Selling into a country is not the same as hosting a local production region there.
| Market | Commercial | Hosting | Frameworks |
|---|---|---|---|
| Finland (EU) | Operating market | Core app + database in Germany / Frankfurt; GDPR applies as EU processing | GDPR; Finnish supervisory authority as applicable |
| Canada | Operating market | Same EU production stack - Client Data is hosted in the EU and accessed by Canadian users/admins as instructed | PIPEDA and provincial rules (including Quebec Law 25 where applicable) - Client remains controller for Client Data; transfers documented below |
| Cameroon | Operating market | Same EU production stack - Client Data is hosted in the EU and accessed by Cameroon users/admins as instructed | Local data-protection obligations as applicable - Client remains controller for Client Data; transfers documented below |
CurNext does not currently advertise separate production regions in Canada or Cameroon. Edge CDN, email delivery, payments, AI APIs, and observability may process limited data outside Germany - see subprocessors.
Pricing by marketParties and roles
Where CurNext processes personal data on behalf of Client, CurNext is processor and Client remains controller for that Client Data.
| Role | Party | Notes |
|---|---|---|
| Provider / Processor | CurNext, Helsinki, Finland | Processes personal data on Client instructions to deliver the Services |
| Client / Controller | Customer organization (Finland, Canada, Cameroon, or other contracted Client) | Determines purposes and means for personal data it instructs CurNext to process |
| Data subjects | Typically Client's employees, contractors, invitees, and site contacts | Invite-only B2B platform users - not a B2C consumer app audience |
- - CurNext may also be controller for its own account, billing, HR, security logs of its systems, and marketing leads - see the Privacy Policy.
- - Do not read this page as "CurNext is always only a processor."
What we process
Nature and purpose: construction and facilities site monitoring and readiness - device telemetry, BIM/site configuration, dashboards, alerts, compliance evidence, team access, APIs/webhooks, AI-assisted features where enabled, and support.
| Category | Examples |
|---|---|
| Account / identity | Name, work email, role, org membership, invite status |
| Authentication context | Session and MFA status (not passwords - managed auth) |
| Project / site metadata | Project names, building addresses Client enters, floor and room labels |
| Operational content | Alert recipients, tickets, uploaded plans/BIM files, notes |
| Device / telemetry | Sensor readings, device IDs, readiness scores (generally not installer PII unless Client adds it) |
| AI feature context | Prompts and context Client or the Services send to AI features (for example readiness assistance) - minimized and not used to train CurNext models outside product needs |
| Audit / security | Access logs, permission denials, GDPR audit events (IDs preferred; emails masked in logs) |
CurNext is not designed to process special-category data (for example health or biometrics for identification) as a core feature. If Client uploads such data, explicit written instructions are required.
Processing continues for the term of the Services / subscription, then return or deletion follows the DPA and termination clauses.
- - Device telemetry should exclude installer PII unless required
- - Logs must not contain passwords, JWTs, API keys, or full email bodies
- - AI features should receive the minimum context needed for the task
- - Provider will not process Client Data for unrelated purposes (for example selling personal data)
Instructions and Client responsibilities
- - Client instructs processing via the platform UI, APIs, contracts, and written support requests
- - Client is responsible for lawful basis, notices to data subjects, and responding to DSRs for data Client controls in their market (EU, Canada, Cameroon, or other)
- - Client manages user invites and RBAC within their tenant
- - Platform supports personal data export for the signed-in user (profile, memberships, preferences). A full self-serve erasure portal is not claimed here until shipped - erasure follows support and contractual process
Where processing happens
Core application compute runs on Hetzner in Germany. Managed PostgreSQL and Auth run on Supabase in Frankfurt, Germany. Customers in Canada and Cameroon use that same EU production stack for Client Data unless an enterprise addendum provides otherwise.
DatacentersSubprocessors
Public list of third parties that may process Client personal data to deliver the Services. Industry practice is a table with purpose, data categories, and location. Enterprise terms: material new subprocessors receive at least thirty (30) days notice; Client may object on reasonable data-protection grounds. Subscribe to changes via [email protected].
Last updated: 9 August 2026
| Subprocessor | Purpose | Data categories | Location | Privacy |
|---|---|---|---|---|
| Hetzner Online GmbHInfrastructure | Application hosting (Docker origins behind load balancers) | Application data, account identifiers in app workloads | Germany | Policy |
| Supabase, Inc.Infrastructure | Managed PostgreSQL database and authentication | Account, project, telemetry metadata, auth context | Frankfurt, Germany (eu-central) | Policy |
| Cloudflare, Inc.Infrastructure | DNS, TLS, WAF, CDN, Turnstile; optional R2 object storage | Connection metadata, form protection signals; objects/uploads when R2 is used | Global edge; R2 EU jurisdiction option for objects / audit archive | Policy |
| SMTP2GOEmail | Transactional email (invites, password flows, notifications) | Email address, name, message content required to deliver mail | EU data center (Amsterdam) when the CurNext account is EU-hosted; recipient delivery may reach MTAs worldwide | Policy |
| Stripe, Inc.Payments | Payments and billing when used | Billing contact and payment metadata per Stripe terms | Per Stripe's terms (often US/EEA processing) | Policy |
| Google LLC (Gemini / Google AI)AI | AI features in the product when Gemini is enabled | Prompts and context required for the AI feature | Per Google Cloud / Gemini data processing terms | Policy |
| Groq, Inc.AI | Inference for the public Knowledge Base assistant on curnext.app (after user consent), and other product AI features when Groq is enabled | Prompts, chat questions, and short conversation context required for the feature | Per provider data processing / privacy terms | Policy |
| Signicat ASIdentity | Electronic identity / eID flows when used for strong authentication | Identity attributes required for the eID transaction | EEA (Norway / EU processing per Signicat) | Policy |
| Datadog, Inc.Observability | Application and infrastructure observability | Operational logs and metrics (secrets excluded by design) | Per Datadog site / region configured for CurNext | Policy |
| Grafana LabsObservability | Metrics / dashboard observability when used | Operational metrics and related metadata | Per Grafana Cloud region configured for CurNext | Policy |
| OpenWeather Ltd.Data | Weather context for site / surface readiness features when used | Location or site coordinates Client configures; weather responses | Per OpenWeather terms | Policy |
Core app + database for platform Client Data: Germany / Frankfurt. AI, email delivery, payments, edge CDN, and observability may process limited personal data outside Germany. Hardware / manufacturing partners (for example Semtech, Sensirion, JLCPCB) are not listed as personal-data subprocessors unless they receive Client personal data.
International transfers
- - Primary storage and application processing for Client Data is designed around EU hosting (Germany / Frankfurt), including for Clients in Canada and Cameroon
- - Access by Client users in Canada or Cameroon is an international transfer / remote access pattern - Client remains controller for how it invites users in those markets
- - Where a subprocessor transfers or accesses data outside the EEA/UK (for example Gemini, Groq, Stripe, or Cloudflare edge), Provider will use an appropriate transfer mechanism (for example EU SCCs or an adequacy decision) as required by law
- - Canadian Clients: Provider supports PIPEDA / Law 25 vendor diligence with this list, TOMs, and counsel-approved DPA exhibits - local hosting in Canada is not claimed here
- - Cameroon Clients: Provider supports local diligence with this list and DPA - local hosting in Cameroon is not claimed here
- - SCC exhibits and transfer assessments are attached in counsel-approved DPA packages
Technical and organizational measures
High-level summary only. See Security Policy and the Security page for architecture detail. CurNext does not claim ISO 27001 or SOC 2 certification for itself on this page.
| Control | Summary |
|---|---|
| Access control | Invite-only access; RBAC; MFA for privileged / OWNER roles |
| Transport | HTTPS / TLS; field uplink WireGuard + MQTT mTLS (broker not public) |
| At rest | Managed DB encryption; object storage encryption when used |
| Tenant isolation | Organization / project scoping; RLS where applicable |
| Logging / audit | Structured GDPR-oriented audit events; secrets not logged |
| Backups | Encrypted backups with restore testing in the security program |
| Edge protection | Cloudflare WAF / TLS in front of origins |
| AI controls | In-house curing prediction (TensorFlow.js) runs in the product; Gemini and Groq used only for enabled assisted features; minimize prompt context; no sale of Client Data |
| Incident path | GDPR Art. 33-oriented notification; enterprise 24 h target to Client security contact |
| Vulnerability / CRA themes | Signed OTA, SBOM cadence, disclosure via [email protected] |
Breach notification and assistance
| Context | Target |
|---|---|
| Standard agreement | Without undue delay after confirmed personal data breach affecting Client Data |
| Enterprise | Within 24 hours to Client's designated security contact after confirming a personal data breach or enterprise-impacting security incident affecting Client Data |
| Regulatory | GDPR Art. 33 path (72 h to authority where applicable) - Client/Controller obligations may differ by market (EU, Canada, Cameroon) |
DSR assistance
- - Access / export (platform export tools + support channel)
- - Rectification (account / admin tools)
- - Erasure / restriction (support + contractual process; audit logs may be append-only or pseudonymized per design)
- - Portability (machine-readable export where available)
Client remains the front door for most DSRs about Client-controlled data in every operating market.
How to execute the DPA
Standard service terms: parties execute a DPA upon request where Provider processes personal data on behalf of Client. Enterprise schedule: execute Provider's DPA within thirty (30) days of Schedule signature (unless an existing DPA already governs).
- - Request the executable DPA from [email protected] or via Contact (Finland, Canada, and Cameroon Clients welcome)
- - Security overview and current subprocessor list available upon request; material changes: 30-day enterprise notice
- - Governing law for commercial agreements: laws of Finland; courts in Helsinki, Finland (subject to mandatory protections) - align final DPA governing-law clause with counsel
Translations are provided for convenience. Where a signed agreement exists, the English instrument controls.