What it says
What this says
Current to 11 Oct 26BB-Demo's final answers to Veldmaat Payments' security questions during evaluation of the Growth tier, written by Hannah Lowe on 25 Oct 2025. It is not a contract. Four items remain open, and SSO, SCIM and Sandbox are excluded from Growth.
What it is: a security and data-handling questionnaire prepared by Hannah Lowe, Solutions Engineer, for Veldmaat Payments in Amsterdam. It states that it describes the Growth tier and "do not replace the contract".
Commits: the brain runs inside Veldmaat's own Snowflake account and nightly refresh is "complete by 07:00 customer local time on business days, on every tier". On Growth, credits relate to availability only.
Unusual: the P1 response is not given as a figure, only as the Growth commitment "written into the order form and agreement". SSO and SCIM are Enterprise only, which is a possible tier conversation.
Not settled: encryption detail, independent assurance reports, the sub-processor list and incident notification wording are all open. The document is dated 25 Oct 2025, and the evidence does not show whether those answers were ever sent.
As found in this document
Current to 9 Oct 26- Data refreshThe refresh is complete by 07:00 customer local time on business days, on every tier.The refresh is complete by 07:00 customer local time on business days, on every tier. · Source: object_read:doc_003_001
- Service credits on GrowthOn Growth, credits relate to availability only.On Growth, credits relate to availability only. · Source: object_read:doc_003_001
- P1 first responseFirst response is within the Growth business-hours commitment, which is written into the order form and agreement.First response is within the Growth business-hours commitment, which is written into the order form and agreement. · Source: object_read:doc_003_001
- HostingInside Veldmaat Payments' own Snowflake account.Inside Veldmaat Payments' own Snowflake account. · Source: object_read:doc_003_001
The document
Body
Veldmaat Payments - Security Questionnaire
Prepared for: Veldmaat Payments, Amsterdam Prepared by: Hannah Lowe, Solutions Engineer, BB-Demo Date: 25 Oct 2025 Status: Final Tier under discussion: Growth
Purpose
This questionnaire records BB-Demo's answers to the security and data-handling questions raised by Veldmaat Payments during evaluation. Where I could not give a complete answer without checking, I have said so rather than guess, and the item is listed under open points at the end. To be precise, the answers below describe the Growth tier and the way BB-Demo is deployed; they do not replace the contract.
Hosting and data location
Read the whole document (3,570 characters)
| Question | Answer |
|---|---|
| Where does the brain run? | Inside Veldmaat Payments' own Snowflake account. BB-Demo builds and operates it there. |
| Does your data leave your Snowflake account? | The short answer is no, the brain is built and run inside your account. The longer answer is a data-flow diagram, which I will put in writing with the final pack. |
| Can data residency be fixed to the EU? | Yes. Dedicated EU data residency is available as an add-on. |
| Who owns the data in the brain? | Veldmaat Payments. It sits in your account under your control. |
Connected systems
| Question | Answer |
|---|---|
| Which systems will be connected? | HubSpot, Zendesk and your accounting system, so account managers and merchant risk see one view of each merchant. |
| How are connectors authorised? | Each connector uses credentials that your own administrators issue and can revoke at any time. |
| Can we limit which objects or fields are read? | Yes. Scope is agreed per connector during implementation and written into the design document. |
Access control
| Question | Answer |
|---|---|
| Is single sign-on available? | SSO and SCIM are part of the Enterprise tier. They are not included in Growth. If they matter to your security team, that is a conversation about tier. |
| Is access role-based? | Users are managed by your administrators, and what each person can see follows the access you grant. |
| Is there a separate test environment? | The Sandbox is an Enterprise feature from the second price book. It is not part of Growth. |
Data freshness and service levels
| Question | Answer |
|---|---|
| How often is data refreshed? | Nightly. The refresh is complete by 07:00 customer local time on business days, on every tier. |
| What response do we get on a priority-one incident? | The Growth service level applies. First response is within the Growth business-hours commitment, which is written into the order form and agreement. |
| Are service credits available? | On Growth, credits relate to availability only. Data freshness is credited on Enterprise only. |
Support and people
| Question | Answer |
|---|---|
| Who is your point of contact for security? | Hannah Lowe, Solutions Engineer. Elena Novak will be your customer success manager once you are live. |
| Is a named engineer available? | Premium support, with a named engineer, is an add-on. |
Open points
These are the items I will answer in writing after checking internally. I would rather confirm than overstate a control.
- Encryption detail at each layer, beyond what Snowflake provides in your account.
- Independent assurance reports and the scope each one covers.
- Sub-processor list and the process for notifying you of changes.
- Incident notification wording to be used in the agreement.
I'll put each of these in writing with the architecture diagram.
Thanks, Hannah
Unusual terms
Current to 9 Oct 26- SSO and SCIM excluded from Growth
- Sandbox excluded from Growth
- Four open security points