Data Processing Agreement
Last updated: 30 June 2026
This Data Processing Agreement ("DPA") applies when you ("Controller") use Beecause.AI to process personal data on your behalf. It supplements our Terms of Service. By using Beecause.AI, the Controller accepts this DPA. Where there is a conflict between the DPA and the Terms of Service on data-protection matters, the DPA prevails.
1. Definitions
- "Controller" — the customer organisation that determines the purposes and means of processing personal data.
- "Processor" / "Beecause.AI" — Wisely, Lda., a company incorporated in Portugal (registered office: Rua de S. Pedro n.º 12A, 4720-092 Amares, Portugal), operator of the Beecause.AI service, processing personal data on the Controller's behalf.
- "Personal Data", "Processing", "Data Subject", "Supervisory Authority" — as defined in the GDPR (Regulation (EU) 2016/679) and applicable national data-protection law.
- "Sub-processor" — any third party engaged by Beecause.AI to process Personal Data on behalf of the Controller.
2. Subject matter, nature, and purpose of processing
- Subject matter: Personal data submitted to, or accessible by, Beecause.AI in the course of providing the incident root-cause-analysis service.
- Nature: collection, storage, retrieval, analysis, transmission to AI sub-processors, and deletion of personal data.
- Purpose: solely to provide the Beecause.AI service as described in the Terms of Service and on the Controller's documented instructions.
- Duration: for the term of the Controller's subscription plus the retention period set out in Section 9 below.
3. Categories of data subjects and personal data
Depending on what the Controller connects to Beecause.AI, processing may involve:
| Data subjects | Categories of personal data |
|---|---|
| Controller's employees and contractors | Names, usernames, email addresses appearing in logs, traces, Slack messages, commit history, incident comments, or other telemetry connected to the service. |
| End users of the Controller's products | User identifiers, error messages, request IDs, or other personal data incidentally present in logs, traces, or metrics shared with Beecause.AI. |
The Controller is responsible for ensuring it has a lawful basis to transfer personal data to Beecause.AI for processing.
4. Controller instructions
Beecause.AI will process Personal Data only on documented instructions from the Controller (as set out in the Terms of Service and this DPA, or as otherwise communicated in writing). If Beecause.AI is required by applicable law to process Personal Data beyond those instructions, it will notify the Controller before doing so (unless prohibited by law).
5. Confidentiality of processing
Beecause.AI will ensure that persons authorised to process Personal Data are bound by appropriate confidentiality obligations (whether contractual or statutory). Access to Personal Data is restricted to personnel who require it to deliver the service.
6. Security measures
Taking into account the state of the art, costs, and the nature and risks of the processing, Beecause.AI implements and maintains appropriate technical and organisational measures, including:
- Encryption of Personal Data at rest and in transit (TLS 1.2+).
- Logical tenant isolation — each Controller's data is kept separate.
- Encrypted storage of tool credentials provided by the Controller for integration purposes.
- Access controls with the principle of least privilege.
- Regular patching of infrastructure and dependencies.
- Hosting in the EU (Google Cloud, europe-west1) with Cloudflare edge protection.
7. Sub-processing
The Controller authorises Beecause.AI to engage the sub-processors listed at beecause.ai/subprocessors. Beecause.AI will:
- Impose data-protection obligations on sub-processors equivalent to those in this DPA.
- Notify the Controller of any intended addition or replacement of a sub-processor at least 14 days in advance by updating the sub-processor list (and, where the Controller has subscribed, by email). The Controller may object on reasonable grounds within 14 days; if no agreement can be reached, the Controller may terminate the service with a pro-rata refund for any prepaid period.
- Remain fully liable to the Controller for the acts and omissions of its sub-processors.
8. Data subject request assistance
Beecause.AI will, taking into account the nature of the processing, assist the Controller by appropriate technical and organisational measures in fulfilling its obligation to respond to Data Subject requests (e.g. access, erasure, portability). Requests received directly by Beecause.AI will be forwarded to the Controller without undue delay.
9. Personal data breach notification
Beecause.AI will notify the Controller without undue delay (and in any event within 72 hours of becoming aware) of any personal data breach affecting the Controller's data. Notification will include, to the extent then known: a description of the nature of the breach; the categories and approximate number of data subjects and records affected; the likely consequences; and the measures taken or proposed to address the breach.
10. Deletion and return on termination
Upon termination or expiry of the service, Beecause.AI will, at the Controller's choice, delete or return all Personal Data (and delete existing copies) within 30 days, except to the extent that applicable law requires longer retention. Backup data may persist for up to 30 days after deletion from live systems.
11. Audit rights
Beecause.AI will make available to the Controller all information necessary to demonstrate compliance with this DPA, and will allow for and contribute to audits and inspections conducted by the Controller or an auditor mandated by the Controller. Audits must be: (a) requested with at least 30 days' written notice; (b) conducted during business hours without disrupting operations; and (c) subject to appropriate confidentiality obligations.
12. International data transfers
Beecause.AI's primary processing occurs within the EU (Google Cloud, europe-west1). Where Personal Data is transferred to sub-processors outside the EU/EEA, the transfer is covered by Standard Contractual Clauses or the EU-US Data Privacy Framework, as set out in the sub-processor list.
Where required by applicable law, the SCCs (Module 3: Processor to Sub-Processor) are incorporated into the relevant sub-processing agreements.
13. Contact
For questions about this DPA, or to submit a Data Subject request, contact: privacy@beecause.ai. For data-protection enquiries: dpo@beecause.ai.
Wisely, Lda.
Rua de S. Pedro n.º 12A, 4720-092 Amares, Portugal