Bespoke AI.GDPR Article 28 — Template effective for all Bespoke AI customers.
Version 1.0 · Issued by Haiku Labs (Paris, France).
This Data Processing Agreement ("DPA") governs Bespoke AI ("Processor") processing of Personal Data on behalf of the Customer ("Controller") in connection with the Bespoke AI service. The DPA is effective for the duration of the Customer's subscription and any post-termination retention period.
The Processor processes Personal Data solely to (a) provide the Service, (b) perform billing, (c) meet legal obligations, and (d) maintain security and detect abuse. No processing for the Processor's own marketing purposes.
Customer's authorised users, end-users invited to Customer projects, and contacts whose information is uploaded by the Customer.
Authentication identifiers (email, hashed password), account metadata, billing details, project files and AI prompts, IP addresses, browser fingerprint, and security event logs.
Customer authorises the sub-processors listed at /sub-processors. The Processor will give 30 days notice of new sub-processors and allow the Customer to object on reasonable data-protection grounds.
Encryption in transit (TLS 1.2+) and at rest (AES-256). Row-Level Security on all multi-tenant tables. JWT-based authentication. Role-based access controls. Rate limiting. Audit logging. Quarterly access reviews. Annual penetration test. Vendor security reviews. Incident response runbook.
The Processor assists the Controller in fulfilling requests for access, rectification, erasure, restriction, portability, and objection — typically within 30 days. Self-service account deletion is available in account settings.
The Processor notifies the Controller without undue delay and in any event within 72 hours of becoming aware of a Personal Data breach affecting the Controller's data.
Transfers outside the EEA rely on the EU Standard Contractual Clauses (2021/914), supplemented where required. The Processor maintains a transfer-impact assessment.
On termination, Personal Data is deleted within 30 days unless retention is required by law. Backups are purged within 90 days.
The Customer may, no more than once per year, request a copy of the latest SOC 2 / ISO 27001 report or equivalent. On-site audits available on reasonable notice under NDA.
Governed by the law of the Republic of France. Liability follows the main Service Agreement.
Email dpa@bespokeai.build with your legal entity name and we'll counter-sign within 5 business days.