Last Updated: August 3, 2026
This Data Processing Agreement (“DPA”) forms part of the agreement between Bondi Labs, Inc. (“Bondi”) and the customer using the Services (“Customer”) when Bondi processes Personal Data on Customer’s behalf. Capitalized terms not defined here have the meaning in the Terms of Service or applicable order form.
If a signed Enterprise agreement contains different data-processing terms, the signed terms control.
1. Roles and scope
Customer is the Controller or Business and Bondi is the Processor or Service Provider for Personal Data contained in Customer Data. Each party will comply with the data-protection laws applicable to its role.
Customer determines the lawful basis, purpose, categories of data, data subjects, retention instructions, and people permitted to use the Services. Customer instructs Bondi to process Personal Data only as needed to provide, secure, support, and improve the reliability of the Services, to follow Customer’s documented product configuration and requests, and to comply with law.
Bondi will notify Customer if it believes an instruction violates applicable data-protection law, unless law prohibits the notice. Bondi will not sell Customer Personal Data or use it for targeted advertising.
2. Processing details
The processing lasts for the term of the Services plus the retention and deletion period in the agreement.
- Subject matter: hosting and operating Customer’s business systems, databases, files, screens, forms, Portals, workflows, integrations, APIs, audit, AI, support, backup, and export features.
- Nature: collection, transmission, organization, storage, retrieval, consultation, modification, analysis, generation, disclosure at Customer’s direction, restriction, export, and deletion.
- Purpose: providing and securing the Services and the customer-configured business processes that run on them.
- Data subjects: Customer personnel, users, applicants, suppliers, clients, Portal users, business contacts, and other people whose data Customer submits.
- Data categories: identity and contact data, account and permission data, business records, communications, files, operational events, device and usage data, and any other fields Customer chooses to process.
- Sensitive data: Customer must not process regulated or special-category data unless it has a lawful basis, has assessed the risk, and has configured appropriate controls. Enterprise requirements must be agreed in writing.
3. Confidentiality and personnel
Bondi limits access to Customer Personal Data to people and systems that need it to provide or secure the Services. Authorized personnel are subject to confidentiality obligations and receive access appropriate to their responsibilities. Bondi remains responsible for its personnel’s compliance with this DPA.
4. Security measures
Bondi maintains technical and organizational measures appropriate to the risk, including:
- dedicated PostgreSQL databases for customer data and workspace-aware access controls;
- distinct human, Portal, Partner, Agent, Automation, API Key, and Service Account identities;
- role-, screen-, action-, record-, and field-level authorization according to plan and configuration;
- HTTPS/TLS for network transport and managed-provider encryption for stored data;
- secrets kept outside source code through managed secret stores and protected runtime bindings;
- audit records for sensitive access, security, billing, and system changes;
- environment separation, controlled publication, version history, and rollback where included in the plan;
- monitoring, structured logs, backup and restore workflows, and incident investigation; and
- data export and an account deletion workflow after the contractual retention period.
Further detail is available at Security at Bondi. Security certifications, reports, penetration-test materials, data regions, dedicated infrastructure, IP allowlists, SSO/SCIM, and contractual SLA terms apply only when currently available or included in a signed Enterprise agreement.
5. Subprocessors
Customer gives Bondi general authorization to use subprocessors to provide the Services. Bondi will require a subprocessor that processes Customer Personal Data to protect it under obligations materially consistent with this DPA, and Bondi remains responsible for the subprocessor’s processing to the extent required by law.
Core subprocessors currently include:
| Subprocessor | Purpose | Typical processing location |
|---|---|---|
| Google Cloud | Runtime, secrets, monitoring, archives, and selected AI/document processing | European Union and other configured Google regions |
| Cloudflare | DNS, edge delivery, Workers, realtime services, abuse protection, and object storage | Global network |
| Neon | Managed PostgreSQL databases | Configured database region, currently including AWS EU Central for production |
| Stripe | Subscription billing, payments, invoicing, fraud controls, and tax calculation | United States and Stripe’s global infrastructure |
| Resend | Transactional and customer-configured email delivery | United States and provider infrastructure |
| Anthropic | AI processing when Claude or an Anthropic fallback is invoked | Provider processing locations |
| OpenAI | AI processing when an OpenAI capability is invoked | Provider processing locations |
Customer-configured integrations are recipients selected and instructed by Customer. Google Analytics and Contentful support Bondi’s public website and do not ordinarily process Customer Data under this DPA.
Bondi may update this list as the Service changes. Where required by the Customer’s agreement or applicable law, Bondi will provide reasonable advance notice of a new subprocessor that will process Customer Personal Data. Customer may object on reasonable data-protection grounds; the parties will work in good faith on a commercially reasonable solution.
6. International transfers
Customer authorizes Bondi and its subprocessors to process Personal Data in the locations needed to provide the Services. A specific data region applies only when included in a signed Enterprise agreement.
For a restricted transfer that requires a safeguard, the parties incorporate the applicable European Commission Standard Contractual Clauses, UK addendum, adequacy decision, or other lawful mechanism. For the SCCs, Customer is the data exporter and Bondi is the data importer in the module appropriate to their roles; this DPA and the agreement supply the annex information. The optional docking clause applies, supervisory authority and governing-law selections follow the data exporter’s establishment where required, and no optional general third-party beneficiary rights are added beyond the SCCs.
7. Data-subject requests
Taking into account the nature of processing, Bondi will provide reasonable assistance through product controls or support so Customer can respond to requests for access, correction, deletion, restriction, objection, or portability. If Bondi receives a request relating to Customer Data, Bondi may direct the requester to Customer and will not independently respond on Customer’s behalf unless required by law.
8. Security incidents
Bondi will notify Customer without undue delay after confirming a Personal Data Breach affecting Customer Personal Data, provide information reasonably available to support Customer’s obligations, and take reasonable steps to contain and remediate the incident. Notification is not an admission of fault. Customer is responsible for notices to data subjects and authorities unless law assigns that duty to Bondi.
9. Compliance assistance
Taking into account the nature of processing and information available to Bondi, Bondi will provide reasonable assistance with security, breach response, data-protection impact assessments, and regulator consultations required by applicable law. Additional work, bespoke questionnaires, audits, or on-site support may be subject to Enterprise terms and reasonable fees.
10. Information and audits
Bondi will make information reasonably necessary to demonstrate compliance with this DPA available to Customer. Customer should first use current documentation, questionnaires, and independent materials Bondi makes available. If those are insufficient and law requires further verification, Customer may request one audit per year on reasonable notice, subject to confidentiality, security, scope, timing, and cost controls. An audit must not expose another customer’s data or compromise the Service.
11. Return and deletion
During active access and the stated read-only period, Customer can use available export tools. After a Trial expires or a cancellation becomes effective, Bondi generally provides 30 days of read-only and export access before queuing Customer Data for deletion. An unpaid account remains view-only until the subscription is canceled, recovered, or terminated.
Bondi may retain billing, tax, fraud, security, referral, and legal records where required or reasonably necessary. Provider-level backup and recovery copies expire under their lifecycle policies and remain protected and unavailable for ordinary product use after deletion.
12. Liability, duration, and conflicts
The liability limits and governing law in the agreement apply to this DPA except where prohibited by data-protection law or the SCCs. This DPA remains effective while Bondi processes Customer Personal Data. If this DPA conflicts with the SCCs, the SCCs control for the restricted transfer; otherwise this DPA controls over inconsistent general privacy language in the Terms.
13. Contact
Bondi Labs, Inc.
2803 Philadelphia Pike, Suite B #356
Claymont, DE 19703, United States