Concept — juridische controle vereist
This is a working draft prepared for legal review. It is not yet final and does not constitute legal advice. The final text is fixed by the operator’s legal counsel before launch.
Privacy Statement
How ZoraMatch handles personal data under the EU General Data Protection Regulation (GDPR).
Last updated 14 July 2026
1. Controller
The controller for the personal data processed on the ZoraMatch platform is GoChainWise (handelsnaam, B.V. i.o.)(“the Operator”, “we”). For any privacy question, data-subject request, or to reach our data protection contact, email contact@mapemedia.com (placeholder DPO / privacy contact until the Operator appoints a dedicated one).
2. What data we process
Depending on how you use the Platform, we process:
- Account & identity data — name, business email, password (hashed), role, organisation membership, and preferences.
- Organisation & profile data — company name, country, KvK / VAT numbers, DUNS, sector, certifications, product portfolio, and free-text descriptions.
- Intake & conversation data — the messages you exchange with our AI during supplier/buyer intake and lead screening, and the structured data extracted from them.
- Transaction data — discovery orders, match results, screening reports, workspace messages, and versioned order drafts.
- Waitlist / prospect data — name, email, company, and what you are looking for, if you sign up before launch.
- Technical & usage data — log data, IP address (for security and rate limiting), device/browser information, and cookieless product analytics.
3. Why we process it, and our legal basis
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Provide your account, matching, screening, and workspace features | Performance of a contract — Art. 6(1)(b) |
| Run AI intake, screening, and order-draft generation you request | Performance of a contract — Art. 6(1)(b) |
| Fraud prevention, security, rate limiting, and abuse detection | Legitimate interest — Art. 6(1)(f) |
| Company-register (KvK / VAT) checks | Legitimate interest / legal obligation — Art. 6(1)(f) / (c) |
| Product analytics and service improvement (cookieless) | Legitimate interest — Art. 6(1)(f) |
| Waitlist sign-up and pre-launch updates | Consent — Art. 6(1)(a) |
| Keeping records shared with a still-active counterparty | Legitimate interest — Art. 6(1)(f) |
4. AI processing
Your intake and screening conversations are processed by third-party AI models to extract structured data and to generate reports, matches, and order drafts. We never feed raw user text directly into a scoring prompt as instructions; conversations pass through a sanitisation step first. Every AI-generated artifact stores the model, version, and settings used so results stay reproducible.
5. Processors we use
We share personal data only with vetted processors who act on our instructions. Our current processors are:
| Processor | Role | Location / transfer |
|---|---|---|
| Vercel | Application hosting | EU region |
| Supabase | Database, authentication, file storage | EU (Frankfurt) |
| Upstash | Rate limiting (Redis) | EU region |
| Resend | Transactional email delivery | EU / US — under Standard Contractual Clauses |
| Anthropic, Google, OpenAI | AI intake, screening, report and order-draft generation | US — under Standard Contractual Clauses / adequacy safeguards |
| Plausible Analytics | Cookieless, aggregate product analytics | EU-hosted |
| Sentry | Error monitoring (PII-scrubbed) | EU / US — under Standard Contractual Clauses |
We do not sell your personal data. We give at least 14 days’ notice before adding a new processor.
6. International transfers
Data stays in the EEA except where our AI, email, or monitoring providers process it in the United States. Those transfers rely on Standard Contractual Clauses or an applicable adequacy decision. You can ask us for details of the safeguards in place.
7. How long we keep data
| Category | Retention |
|---|---|
| Waitlist / prospect contact data | Maximum 90 days after last contact, then deleted |
| Platform data (accounts, profiles, orders, workspaces) | Contract duration + 1 year, or until you delete it |
| Financial records | 7 years (Dutch legal obligation), held by the Operator’s finance stack |
When you delete your organisation, records shared with a still-active counterparty are anonymised rather than deleted, so the other party keeps their own business history. Your identity is stripped from those records.
8. Your rights
Under the GDPR you have the right to:
- Access and portability — download a machine-readable copy of your data. Signed-in users can export from Settings → Profile → Data & privacy.
- Erasure — delete your account, or (as an organisation owner) delete the whole organisation, from the same Settings → Data & privacy panel.
- Rectification — correct inaccurate data directly in your profile or by contacting us.
- Restriction and objection — object to processing based on legitimate interest.
- Withdraw consent — where processing relies on consent, withdraw it at any time (this does not affect prior processing).
To exercise a right, use the in-app tools above or email contact@mapemedia.com. You also have the right to lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
9. Security
We protect data with encryption in transit (HTTPS/TLS), row-level security scoped to each organisation, strict access controls, secrets kept out of source code, isolated development and production environments, and error monitoring. In the event of a personal-data breach we follow a defined 72-hour response process.
10. Cookies
We use only strictly necessary and functional cookies and cookieless analytics — see our Cookie Statement. No advertising or cross-site tracking cookies are set.
11. Changes
We may update this statement. Material changes are notified by email or in-product. The “last updated” date above always reflects the current version.