Concept — juridische controle vereist

This is a working draft prepared for legal review. It is not yet final and does not constitute legal advice. The final text is fixed by the operator’s legal counsel before launch.

Privacy Statement

How ZoraMatch handles personal data under the EU General Data Protection Regulation (GDPR).

Last updated 14 July 2026

1. Controller

The controller for the personal data processed on the ZoraMatch platform is GoChainWise (handelsnaam, B.V. i.o.)(“the Operator”, “we”). For any privacy question, data-subject request, or to reach our data protection contact, email contact@mapemedia.com (placeholder DPO / privacy contact until the Operator appoints a dedicated one).

2. What data we process

Depending on how you use the Platform, we process:

  • Account & identity data — name, business email, password (hashed), role, organisation membership, and preferences.
  • Organisation & profile data — company name, country, KvK / VAT numbers, DUNS, sector, certifications, product portfolio, and free-text descriptions.
  • Intake & conversation data — the messages you exchange with our AI during supplier/buyer intake and lead screening, and the structured data extracted from them.
  • Transaction data — discovery orders, match results, screening reports, workspace messages, and versioned order drafts.
  • Waitlist / prospect data — name, email, company, and what you are looking for, if you sign up before launch.
  • Technical & usage data — log data, IP address (for security and rate limiting), device/browser information, and cookieless product analytics.

3. Why we process it, and our legal basis

PurposeLegal basis (GDPR Art. 6)
Provide your account, matching, screening, and workspace featuresPerformance of a contract — Art. 6(1)(b)
Run AI intake, screening, and order-draft generation you requestPerformance of a contract — Art. 6(1)(b)
Fraud prevention, security, rate limiting, and abuse detectionLegitimate interest — Art. 6(1)(f)
Company-register (KvK / VAT) checksLegitimate interest / legal obligation — Art. 6(1)(f) / (c)
Product analytics and service improvement (cookieless)Legitimate interest — Art. 6(1)(f)
Waitlist sign-up and pre-launch updatesConsent — Art. 6(1)(a)
Keeping records shared with a still-active counterpartyLegitimate interest — Art. 6(1)(f)

4. AI processing

Your intake and screening conversations are processed by third-party AI models to extract structured data and to generate reports, matches, and order drafts. We never feed raw user text directly into a scoring prompt as instructions; conversations pass through a sanitisation step first. Every AI-generated artifact stores the model, version, and settings used so results stay reproducible.

5. Processors we use

We share personal data only with vetted processors who act on our instructions. Our current processors are:

ProcessorRoleLocation / transfer
VercelApplication hostingEU region
SupabaseDatabase, authentication, file storageEU (Frankfurt)
UpstashRate limiting (Redis)EU region
ResendTransactional email deliveryEU / US — under Standard Contractual Clauses
Anthropic, Google, OpenAIAI intake, screening, report and order-draft generationUS — under Standard Contractual Clauses / adequacy safeguards
Plausible AnalyticsCookieless, aggregate product analyticsEU-hosted
SentryError monitoring (PII-scrubbed)EU / US — under Standard Contractual Clauses

We do not sell your personal data. We give at least 14 days’ notice before adding a new processor.

6. International transfers

Data stays in the EEA except where our AI, email, or monitoring providers process it in the United States. Those transfers rely on Standard Contractual Clauses or an applicable adequacy decision. You can ask us for details of the safeguards in place.

7. How long we keep data

CategoryRetention
Waitlist / prospect contact dataMaximum 90 days after last contact, then deleted
Platform data (accounts, profiles, orders, workspaces)Contract duration + 1 year, or until you delete it
Financial records7 years (Dutch legal obligation), held by the Operator’s finance stack

When you delete your organisation, records shared with a still-active counterparty are anonymised rather than deleted, so the other party keeps their own business history. Your identity is stripped from those records.

8. Your rights

Under the GDPR you have the right to:

  • Access and portability — download a machine-readable copy of your data. Signed-in users can export from Settings → Profile → Data & privacy.
  • Erasure — delete your account, or (as an organisation owner) delete the whole organisation, from the same Settings → Data & privacy panel.
  • Rectification — correct inaccurate data directly in your profile or by contacting us.
  • Restriction and objection — object to processing based on legitimate interest.
  • Withdraw consent — where processing relies on consent, withdraw it at any time (this does not affect prior processing).

To exercise a right, use the in-app tools above or email contact@mapemedia.com. You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).

9. Security

We protect data with encryption in transit (HTTPS/TLS), row-level security scoped to each organisation, strict access controls, secrets kept out of source code, isolated development and production environments, and error monitoring. In the event of a personal-data breach we follow a defined 72-hour response process.

10. Cookies

We use only strictly necessary and functional cookies and cookieless analytics — see our Cookie Statement. No advertising or cross-site tracking cookies are set.

11. Changes

We may update this statement. Material changes are notified by email or in-product. The “last updated” date above always reflects the current version.