Data processingLast updated 26 September 2026

Data processing
agreement.

Draft, pending legal review

When we work in your analytics, forms or ad accounts, we handle personal data on your behalf. This agreement sets out how we do that, as required by the GDPR.

01Parties and roles

This data processing agreement (DPA) is between the client (the controller) and Rozenblad Global B.V., trading as Tjenno AI, registered at Argonweg 23, 1362 AA Almere, the Netherlands, Chamber of Commerce (KvK) 76316114, VAT NL860585712B01 (the processor). It is part of every agreement under our terms in which we process personal data on the client's behalf, and follows article 28 of the General Data Protection Regulation (GDPR).

02What we process and why

We process personal data only to deliver the agreed services, such as:

  • setting up and managing analytics, tag management and conversion tracking;
  • building, hosting and maintaining websites, webshops and forms;
  • managing ad accounts and audiences on platforms such as Google and Meta;
  • sending or setting up email and marketing automation;
  • reporting on results.

03Whose data, and which data

Depending on the service: visitors of your website, leads, customers and your own staff. The data may include names, contact details, company details, online identifiers such as IP addresses and cookie IDs, usage and conversion data, and messages sent through forms. We do not process special categories of personal data unless agreed in writing.

04Your instructions

We process personal data only on your documented instructions, which are the agreement, your offer and your written requests. If we believe an instruction breaks the GDPR, we tell you straight away. If the law requires us to process data in another way, we tell you first unless that is not allowed.

05Confidentiality

Everyone who works with the data, including the specialists in our team, is bound to confidentiality and only gets access where needed for the work.

06Security

We take appropriate technical and organisational measures, including:

  • personal accounts with multi-factor authentication where available, and access on a need-to-know basis;
  • encrypted connections (HTTPS/TLS) for websites, dashboards and data transfers;
  • regular updates, backups and monitoring of the systems we manage;
  • working on the client's own accounts where possible, so data stays under your control;
  • removing our access when the work ends.

07Sub-processors

You give general permission to use sub-processors. These are the specialists in our team who work on your project, and suppliers such as hosting providers, email and analytics tools. We bind them to the same obligations as this DPA. A current list is available on request, and we inform you in advance of new sub-processors so you can object on reasonable grounds.

08Transfers outside the EU

We process data within the European Economic Area where possible. If a tool processes data outside it, we only use it with a valid transfer basis, such as an adequacy decision (including the EU-US Data Privacy Framework) or the EU standard contractual clauses.

09Helping you meet your obligations

We help you, within reason, to respond to requests from data subjects (access, correction, deletion and so on), with data protection impact assessments and with questions from the supervisory authority. Work that goes beyond normal support may be charged at our hourly rate after your okay.

10Data breaches

If we discover a personal data breach that affects your data, we inform you without undue delay and in any case within 48 hours, with the information you need to decide whether to notify the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) and the people involved.

11Audits

On request we give you the information you need to check that we comply with this DPA. You may have an audit done once a year by an independent expert bound to confidentiality, at your cost, after at least 30 days' notice.

12Term and deletion

This DPA runs as long as we process personal data for you. When the agreement ends, we return the data or delete it within 30 days, as you choose, unless the law requires us to keep it. Data in your own accounts stays yours; we simply remove our access.

13Liability and law

The liability rules of our terms apply to this DPA. Dutch law applies, and disputes go to the court named in our terms.

Questions about this page? Mail hello@tjenno.ai.

Let's see where
you stand.

Twenty minutes, no deck. You tell us what you sell and to whom; we tell you what Google and the AI assistants currently say about you.

  • Where you stand in Google and in AI answers
  • What your competitors do better
  • The first three things to fix
EtienneTjenno AI · your point of contact20 min · no deck

Questions we answer in a 20-minute intro:

  1. Why does my competitor show up in ChatGPT and we don't? Usually it comes down to the sources AI trusts. In 20 minutes we show you which ones mention them, and how to get you in.
  2. How do we get more leads without a bigger ad budget? By putting ads and SEO on one keyword plan, so they stop competing for the same clicks. We'll show you where that pays off first.
  3. Our new website looks great. So why doesn't it rank? Often it's structure, speed or content Google can't read. We check it live and give you the first three fixes.
  4. What does AI say about our company right now? Let's ask it together. In the intro we check Google's AI overview, ChatGPT, Perplexity and Gemini for your name.
  5. Which of our marketing actually brings in customers? We tie every channel to calls, forms and sales, so you know what each euro brings in. Want to see where you stand?