Bespoke AI.GDPR Article 28 — template effective for all Bespoke AI customers. By subscribing to the Service, the Customer accepts this DPA; a counter-signed copy is available on request.
Version 2.0 · Issued by Haiku Labs (Paris, France) · Supersedes version 1.0.
"Controller", "Processor", "Personal Data", "Processing", "Personal Data Breach", "Data Subject" and "Supervisory Authority" have the meanings given in Regulation (EU) 2016/679 ("GDPR"). "UK GDPR" means the GDPR as incorporated into UK law by the Data Protection Act 2018. "SCCs" means the Standard Contractual Clauses annexed to Commission Implementing Decision (EU) 2021/914. "Service Agreement" means the Bespoke AI Terms and Conditions or the signed enterprise order form between the parties. In the event of conflict, this DPA prevails over the Service Agreement in respect of the processing of Personal Data; the SCCs prevail over this DPA in respect of restricted international transfers.
The Customer is the Controller (or, where the Customer itself acts on behalf of a third party, the Processor) of Customer Personal Data. Bespoke AI, operated by Haiku Labs (Paris, France), acts as Processor (or sub-processor accordingly). Each party independently determines the purposes and means of its own processing of account administration and billing data, for which each acts as an independent Controller.
Subject matter: provision of the Bespoke AI design and CAD generation platform. Duration: for the term of the Customer subscription plus the deletion window in clause 13. Nature and purpose: hosting, storage, transmission, computation and AI-assisted transformation of Customer content strictly to deliver the Service, perform billing, meet legal obligations and maintain security. Bespoke AI does not process Customer Personal Data for its own marketing, profiling or model-training purposes.
The Processor processes Customer Personal Data only on the Controller's documented instructions, including with regard to international transfers, unless required to do so by Union or Member State law; in that case the Processor informs the Controller of that legal requirement before processing, unless the law prohibits such notification on important grounds of public interest. This DPA, the Service Agreement and the Customer's use of the Service constitute the complete documented instructions. The Processor immediately informs the Controller if, in its opinion, an instruction infringes the GDPR or other applicable data protection law.
The Processor ensures that persons authorised to process Personal Data are bound by written confidentiality undertakings surviving termination of employment, are subject to role-based least-privilege access, receive annual security and privacy training, and are onboarded/offboarded under a documented access review procedure (quarterly reviews).
The Processor implements and maintains the technical and organisational measures set out in Annex II, taking into account the state of the art, costs of implementation, and the nature, scope, context and purposes of processing, as well as the risk to the rights and freedoms of natural persons. Measures are reviewed at least annually and updated where necessary; the Processor will not materially degrade the overall level of protection during the term.
The sub-processors engaged to deliver the Service are listed at /sub-processors. Each sub-processor processes Personal Data under its own published data protection terms; those terms — not this DPA — govern the sub-processor's handling of data, and the Processor does not claim to impose this DPA's obligations on them by separate written contract. The Processor reviews each provider's terms before authorising it and links them in the sub-processor table; however, the Processor is not liable for the acts, omissions, security incidents or data-governance practices of sub-processors or third-party model providers operating under their own published terms, and the Provider's own policy — not this DPA — governs its retention, logging and use of data. Where a sub-processor's behaviour is unsatisfactory, the Processor's obligation is limited to ending its engagement where reasonably practicable. The Processor gives at least 30 days' prior notice (by email to the Customer's administrative contact and by updating the sub-processor page) of any intended addition or replacement. The Customer may object on reasonable, documented data-protection grounds within that period; the parties will work in good faith to find an alternative, and failing that the Customer may terminate the affected part of the Service without penalty and receive a pro-rata refund of prepaid fees. Where a sub-processor's terms cannot meet the Customer's requirements, the Processor can restrict the tenant to an agreed subset of providers or exclude specific providers entirely, on request.
The Processor does not use Customer content — designs, CAD files, images, prompts or outputs — to train, fine-tune or evaluate its own or any third-party model. Where the Service relies on third-party model providers listed in Annex III, those providers govern their own handling of data under their own published terms, which are linked in the sub-processor table. The Processor reviews these terms before authorising a provider; however, each provider's own retention, logging and data-governance practices are governed by that provider's policy, not by this DPA. Where a provider's terms cannot meet the Customer's requirements, the Processor can restrict the tenant to an agreed subset of providers or models, or exclude specific providers entirely, on request (see section 7).
Taking into account the nature of the processing, the Processor assists the Controller by appropriate technical and organisational measures, insofar as possible, in fulfilling requests to exercise rights of access, rectification, erasure, restriction, portability and objection. Self-service export and account deletion are available in account settings. Where a request is received directly by the Processor, it will not respond on the merits but will forward it to the Controller without undue delay and in any event within 5 business days. The Processor responds to Controller assistance requests within 10 business days and supports the Controller in meeting the one-month statutory deadline.
The Processor assists the Controller in ensuring compliance with the obligations on security of processing, breach notification to the supervisory authority and to data subjects, data protection impact assessments, and prior consultation with the supervisory authority, taking into account the nature of processing and the information available to the Processor. The security documentation package (encryption, logging and monitoring, incident response, retention, vendor risk, change management) is provided on request to support a DPIA.
The Processor notifies the Controller without undue delay and in any event within 72 hours of becoming aware of a Personal Data Breach affecting Customer Personal Data. The notification describes, to the extent known: the nature of the breach and categories and approximate number of data subjects and records concerned; the likely consequences; the measures taken or proposed to address it and mitigate adverse effects; and a contact point for further information. Information is supplied in phases where it is not all available at once. The Processor maintains an incident response runbook and a post-incident review procedure.
Customer Personal Data is hosted in the European Union (primary region France, auxiliary region Frankfurt). Where a transfer of Personal Data outside the EEA is necessary, it is governed by the SCCs (Decision (EU) 2021/914), which are incorporated into this DPA by reference and completed by Annexes I–III below: Module Two (controller-to-processor) applies where the Customer is a Controller, and Module Three (processor-to-processor) applies where the Customer is itself a Processor. For UK transfers, the UK International Data Transfer Addendum (version B1.0) applies; for Switzerland, the SCCs apply with the amendments issued by the FDPIC. Clause 17 governing law: France; Clause 18 forum: the courts of Paris, France. The Processor maintains a documented Transfer Impact Assessment, available on request.
At the Customer's choice, made within 30 days of the end of the provision of services, the Processor deletes or returns all Customer Personal Data and deletes existing copies, unless Union or Member State law requires further storage. Absent a Customer choice, data is deleted. Production data is deleted within 30 days of termination or of a verified deletion request; encrypted backups are purged on a rolling cycle completed within 90 days. Certification of deletion is provided on written request.
The Processor maintains a record of processing activities carried out on behalf of the Controller and makes available all information necessary to demonstrate compliance with Art. 28. The Customer may, no more than once per twelve-month period (and additionally following a Personal Data Breach affecting its data or a documented regulator request), request the most recent third-party audit report, penetration test summary and security questionnaire responses. Where these are insufficient to demonstrate compliance, the Customer or an independent auditor mandated by the Customer (not a competitor of the Processor) may conduct an on-site or remote audit on 30 days' written notice, during business hours, under NDA, limited in scope to systems processing Customer Personal Data, and without unreasonable disruption. Each party bears its own costs, except that the Customer bears reasonable Processor costs for audits exceeding one per year.
Liability under this DPA is subject to the limitations and exclusions of the Service Agreement, except where such limitation is not permitted by applicable data protection law, including Art. 82 GDPR. Nothing in this DPA limits any data subject's rights. Haiku Labs is not responsible or liable for the acts, omissions, security incidents, data breaches, retention or data-governance practices, or any other behaviour of sub-processors or third-party model providers, each of which processes data under its own published terms; the Customer's remedy in respect of any such provider lies against that provider directly under its own terms. This DPA is governed by the law of the Republic of France, with exclusive jurisdiction of the courts of Paris, without prejudice to Clause 17/18 of the SCCs.
| Data exporter | The Customer (as identified in the Service Agreement or order form), acting as Controller or Processor of the Personal Data described below. Contact: the Customer's administrative account owner. |
|---|---|
| Data importer | Haiku Labs, operating Bespoke AI, Paris, France — Processor providing an AI-assisted design and CAD generation platform. Contact: sa@bespokeai.build. |
| Categories of data subjects | The Customer's authorised users and administrators; end-users invited to Customer projects; individuals whose personal data is contained in content uploaded by the Customer. |
| Categories of personal data | Authentication identifiers (email address, hashed password, MFA factors); account and organisation metadata; billing contact and payment tokens; project files, images, prompts and generated outputs; IP address, user agent and device metadata; security and audit event logs. |
| Special categories of data | None requested or required. The Customer must not upload special-category data (Art. 9) or criminal-conviction data (Art. 10) to the Service. |
| Frequency of transfer | Continuous, for the duration of the subscription. |
| Nature and purpose of processing | Hosting, storage, transmission, computation and AI-assisted transformation of Customer content to deliver the Service; authentication; billing; abuse prevention and security monitoring. |
| Retention period | For the duration of the subscription; deletion of production data within 30 days of termination or verified deletion request; backups purged within 90 days. Security and audit logs retained for 12 months. |
| Sub-processor transfers | As listed in Annex III, for the purpose and duration stated there. |
| Competent supervisory authority | Commission Nationale de l'Informatique et des Libertés (CNIL), France — the Processor is established in France. |
| Measure | Implementation |
|---|---|
| Pseudonymisation and encryption | TLS 1.2+ for all data in transit; AES-256 encryption at rest for databases, object storage and backups; passwords stored using salted one-way hashing; signed, short-lived URLs for asset access; EXIF/GPS metadata stripped from uploads. |
| Confidentiality | Row-Level Security on all multi-tenant tables; per-account data isolation; JWT-based authentication with MFA support and SSO for enterprise tenants; role-based access control and least privilege; quarterly access reviews; confidentiality undertakings for all personnel. |
| Integrity | Signed and hash-verified uploads (SHA-256 and byte-length verification); immutable finalised objects for processing jobs; code review and change-management approval for all production changes; infrastructure-as-code with versioned deployments. |
| Availability and resilience | Managed, redundant EU cloud infrastructure; automated daily backups with point-in-time recovery; documented backup restore testing; rate limiting and abuse controls; status page for service availability. |
| Restoration of availability | Documented backup and restore runbook; recovery objectives RPO 24h / RTO 24h for production data; restoration tests performed at least annually. |
| Testing and evaluation of measures | Annual third-party penetration test; automated dependency and vulnerability scanning with tracked remediation SLAs; continuous control monitoring through a compliance automation platform (Drata); annual review of this Annex. |
| User identification and authorisation | Unique named accounts, no shared credentials; enforced MFA for administrative access; API keys scoped per account with revocation and rate limiting; session expiry and revocation. |
| Logging and monitoring | Centralised audit logging of authentication, administrative and data-access events; alerting on anomalous activity; logs retained 12 months and access-controlled. |
| Data minimisation and retention | Only the minimum data required to operate the Service is collected; documented retention schedule; ephemeral storage for intermediate processing artefacts; automated cleanup of expired uploads. |
| Incident management | Documented incident response plan with severity classification, 72-hour controller notification, post-incident review and corrective actions. |
| Sub-processor governance | Review of each provider's published data protection terms before engagement; annual vendor reassessment; 30-day change notification to customers. Each provider's own terms govern its handling of data (see clause 7). |
| Physical security | Processing takes place in certified cloud data centres (ISO 27001 / SOC 2 accredited providers) with 24/7 physical access control; no Customer Personal Data is stored on employee endpoints. |
The current list of authorised sub-processors, including purpose, categories of data and hosting region, is maintained at bespokeai.build/sub-processors and forms part of this DPA. Changes are notified at least 30 days in advance under clause 7.
Processor: Haiku Labs — Bespoke AI, Paris, France.
Privacy and data protection contact: sa@bespokeai.build. No statutory Data Protection Officer is designated under Art. 37; the privacy contact above handles all data protection matters and supervisory authority correspondence.
Competent supervisory authority: CNIL (France).
Email sa@bespokeai.build with your legal entity name, registered address and signatory details, and we'll counter-sign within 5 business days. Enterprise customers can also request the Transfer Impact Assessment, the security documentation package and the SOC 2 readiness report.