Data processing agreement

Our data processing agreement.

How we process personal data on your behalf. Ask for a signed copy at hello@pendira.com.

Last updated 2 October 2026

In short

  • We process personal data only on your instructions.
  • Your data is hosted in the EU, and every sub-processor is listed.
  • We tell you about a breach without undue delay.
  • You can audit, export and delete.

What this page is

Every Pendira customer gets a data processing agreement (DPA). It sets out how AGByte Labs processes personal data for you, as Article 28 of the GDPR requires. This page summarizes it in plain words. The signed agreement is the binding text.

Request the signed DPA

Email hello@pendira.com with your company's name and the name of the person who signs for it. We send you the DPA to sign, and it becomes part of your agreement with us.

Roles

You are the controller of the personal data in your company in Pendira. AGByte Labs is the processor that runs Pendira for you.

Subject and duration

The subject is providing Pendira to you. Processing lasts as long as your agreement runs, plus the time needed to return and delete your data at the end.

Nature and purpose

We store, organize, show, send and delete personal data so you can run your jobs in Pendira: log work, staff engineers, send them text messages and links, record proof from site, close work and prepare invoices and payouts. We process it for no other purpose.

Who the data is about

  • your team members who use Pendira
  • engineers you work with, employed or freelance
  • contacts at your clients
  • people on site, such as the store manager who signs off a visit

What data

  • names, email addresses and phone numbers
  • job and site addresses
  • check-in and check-out times, with location
  • photos, signatures, checklist answers and receipts
  • engineer skills, regions, documents, rates, ratings and notes
  • comments on jobs
  • sign-in and security records

Pendira is not built for special categories of personal data, such as health data. Please do not store them in Pendira.

Our duties

  • We process personal data only on your documented instructions. If we think an instruction breaks the law, we tell you.
  • Everyone at AGByte Labs who can reach your data is bound to keep it confidential.
  • We keep technical and organizational security measures in place. Our security page describes them.
  • We help you answer people who use their rights under the GDPR.
  • We help you with data protection impact assessments and with consulting the supervisory authority, where you need it.

Sub-processors

You allow us to use the sub-processors on our list. Each one is bound by a data processing agreement with the same duties we have. We tell you before we add or replace one, so you can object. If we cannot resolve your objection, you can end the agreement.

International transfers

Your data is hosted in the EU. Where a sub-processor could reach personal data from outside the EU, the transfer is protected by the EU Standard Contractual Clauses.

Personal data breaches

If a breach affects your personal data, we tell you without undue delay after we learn of it. We say what happened, which data and people are involved, the likely consequences and what we are doing about it. We help you meet your own duty to report it.

End of service

When your agreement ends, we return your personal data on request, in a common format, and then delete it, unless the law requires us to keep it.

Audits

We give you the information you need to show that we meet these duties, and we answer your security questionnaires. You, or an auditor you appoint who is bound to confidentiality, may audit our compliance with reasonable notice.

Contact

AGByte Labs, the Netherlands. Email hello@pendira.com.

Every job, from request to paid.

See Pendira with your own jobs in a 30 minute demo. Bring a messy week, and we will show you that week in one record.

EU based. GDPR compliant. We never sell your data.

A smiling engineer crouches with his laptop beside a server rack

Cookies, honestly

Necessary

Always on

The consent cookie itself. Nothing else.