Data Processing Terms

Version date: 03.08.2026

DATA PROCESSING TERMS
Annex 1 to the Terms of Service (https://b4me.lv/tenant-agreement)

Version effective from: 03.08.2026

These terms constitute a written agreement within the meaning of Article 28(3) of the General Data Protection Regulation (EU) 2016/679 (the "GDPR"; https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32016R0679) between the customer (the Controller) and B4ME, reg. No. 40203755902 (the Processor). They remain in force for as long as the Terms of Service are in force and are accepted together with them.

1. SUBJECT MATTER AND NATURE OF PROCESSING

1.1. The Processor stores and processes, on the Controller's behalf, the personal data entered into the B4ME platform by the Controller or its users, solely for the purpose of providing the services.

1.2. Categories of data subjects: the Controller's employees and users, customers, business partners and their contact persons. Categories of data: identification and contact data, company details, transaction and financial data, and other data entered by the Controller. Special categories of data are not intended to be processed on the platform.

1.3. Duration of processing: the term of the services plus the period defined in Section 12.3 of the Terms of Service.

2. OBLIGATIONS OF THE PROCESSOR

2.1. Process personal data only on the Controller's documented instructions — use of the platform's functionality and the Controller's settings are deemed such instructions. If the Processor is required by law to process otherwise, it informs the Controller unless the law prohibits it.

2.2. Ensure that persons processing the data are bound by an obligation of confidentiality.

2.3. Implement appropriate technical and organisational measures (Article 32 GDPR): access control and permission management, separation of customer environments (data schemas), encrypted data transmission, regular backups, activity auditing.

2.4. Notify the Controller without undue delay of any personal data breach, stating the known circumstances, consequences and measures taken.

2.5. Taking into account the nature of processing, assist the Controller in fulfilling its obligations regarding data subject requests, security of processing and impact assessments.

2.6. Upon termination of the services, at the Controller's choice, return (export) or delete the personal data, unless retention is required by law.

2.7. Make available to the Controller the information necessary to demonstrate compliance with these obligations and, to a reasonable extent, allow audits at a time and scope agreed in advance.

2.8. Not use the Controller's personal data to train its own artificial intelligence or other models.

3. SUB-PROCESSORS

3.1. The Controller grants a general authorisation to engage sub-processors for infrastructure and support services (hosting, data storage, e-mail delivery, payment processing, as well as optional features activated by the Controller at its own choice). The Processor imposes the same data protection obligations on sub-processors and remains liable for their performance.

3.2. The current list of sub-processors — stating the service provided by each, its location and whether it relates to a feature the Controller activates separately — is publicly available at: https://b4me.lv/subprocessors

3.3. Before engaging a new sub-processor or replacing an existing one, the Processor updates the list referred to in Section 3.2 and notifies the Controller's administrator e-mail at least 30 days in advance. Within that period the Controller may raise reasonable objections; if an objection cannot be resolved, the Controller may terminate the use of the services and the unused prepaid period is refunded proportionally.

4. TRANSFERS OUTSIDE THE EU/EEA

4.1. Platform data (database, documents and backups) is stored in the European Union/EEA.

4.2. Certain optional features activated by the Controller at its own choice (for example, the AI assistant or notifications via messaging applications) may involve transfers of data to sub-processors outside the EU/EEA. Such features are not mandatory and the Controller may leave them inactive or switch them off.

4.3. Transfers outside the EU/EEA take place only with the safeguards provided in Chapter V of the GDPR (a European Commission adequacy decision or standard contractual clauses). The safeguard applied to each sub-processor is stated in the list referred to in Section 3.2.

5. FINAL PROVISIONS

5.1. In case of conflict between these terms and the Terms of Service on data protection matters, these terms prevail.

5.2. Amendments and permanent storage of versions follow Section 11 of the Terms of Service. Updating the list of sub-processors is not an amendment of these terms and follows Section 3.3.

Data protection contact: info@b4me.lv