Bespoke AI home

    Data Processing Agreement

    GDPR Article 28 — Template effective for all Bespoke AI customers.

    Version 1.0 · Issued by Haiku Labs (Paris, France).

    1. Subject Matter & Duration

    This Data Processing Agreement ("DPA") governs Bespoke AI ("Processor") processing of Personal Data on behalf of the Customer ("Controller") in connection with the Bespoke AI service. The DPA is effective for the duration of the Customer's subscription and any post-termination retention period.

    2. Nature & Purpose of Processing

    The Processor processes Personal Data solely to (a) provide the Service, (b) perform billing, (c) meet legal obligations, and (d) maintain security and detect abuse. No processing for the Processor's own marketing purposes.

    3. Categories of Data Subjects

    Customer's authorised users, end-users invited to Customer projects, and contacts whose information is uploaded by the Customer.

    4. Categories of Personal Data

    Authentication identifiers (email, hashed password), account metadata, billing details, project files and AI prompts, IP addresses, browser fingerprint, and security event logs.

    5. Sub-processors

    Customer authorises the sub-processors listed at /sub-processors. The Processor will give 30 days notice of new sub-processors and allow the Customer to object on reasonable data-protection grounds.

    6. Security Measures (Annex II)

    Encryption in transit (TLS 1.2+) and at rest (AES-256). Row-Level Security on all multi-tenant tables. JWT-based authentication. Role-based access controls. Rate limiting. Audit logging. Quarterly access reviews. Annual penetration test. Vendor security reviews. Incident response runbook.

    7. Data Subject Rights

    The Processor assists the Controller in fulfilling requests for access, rectification, erasure, restriction, portability, and objection — typically within 30 days. Self-service account deletion is available in account settings.

    8. Personal Data Breach Notification

    The Processor notifies the Controller without undue delay and in any event within 72 hours of becoming aware of a Personal Data breach affecting the Controller's data.

    9. International Transfers

    Transfers outside the EEA rely on the EU Standard Contractual Clauses (2021/914), supplemented where required. The Processor maintains a transfer-impact assessment.

    10. Return & Deletion

    On termination, Personal Data is deleted within 30 days unless retention is required by law. Backups are purged within 90 days.

    11. Audits

    The Customer may, no more than once per year, request a copy of the latest SOC 2 / ISO 27001 report or equivalent. On-site audits available on reasonable notice under NDA.

    12. Liability & Governing Law

    Governed by the law of the Republic of France. Liability follows the main Service Agreement.

    Need a signed copy?

    Email dpa@bespokeai.build with your legal entity name and we'll counter-sign within 5 business days.