Enterprise Data Processing Addendum
Effective Date: August 22, 2026 · Last Updated: August 22, 2026 · Version 2026-08-22-personal-memory-v1
Effective Date: August 22, 2026
This Data Processing Addendum ("DPA") forms part of the agreement between BEE RAD TECH LLC ("Processor," "Service Provider," "Ruzzler," or "BEE RAD TECH") and the applicable enterprise Customer ("Customer") where Ruzzler processes Personal Data on Customer's behalf.
1. Definitions
"Applicable Data Protection Law" means privacy or data-protection law applicable to the Processing covered by this DPA.
"Customer Personal Data" means Personal Data contained in Customer Content and processed by BEE RAD TECH on Customer's behalf. It excludes an individual's Personal Memory and private Vault unless and only to the extent the individual affirmatively copies a specifically reviewed item into a named Customer workspace.
"Personal Data," "Processing," "Controller," "Processor," "Business," "Service Provider," and similar terms have the meanings given by applicable law.
2. Roles
For Customer Personal Data: Customer acts as Controller, Business, or comparable determining party; and BEE RAD TECH acts as Processor, Service Provider, Contractor, or comparable processing party, except where applicable law assigns a different role to a particular activity.
BEE RAD TECH may act independently for its own account administration, security, billing, compliance, and similar legitimate business activities.
3. Customer Instructions
BEE RAD TECH will process Customer Personal Data only: on documented Customer instructions; as necessary to provide the Services; as described in the agreement; as authorized by Customer configuration; or as required by law.
Use of the Services constitutes instructions to perform the processing reasonably necessary to provide the selected features.
4. Customer Responsibilities
Customer is responsible for: lawfulness of its instructions; establishing an appropriate legal basis; required notices; employee permissions; Customer privacy obligations; configuration decisions; and ensuring it has authority to provide Personal Data to Ruzzler.
5. Processing Details
Subject matter: provision of AI orchestration, routing, workflow automation, document storage, knowledge systems, agent systems, verification, sanitization, Mosaic Mode, APIs, and related enterprise Services.
Duration: for the duration of the applicable Services and any authorized retention period.
Purposes: providing, securing, supporting, maintaining, and administering Services under Customer's instructions.
Data subjects may include: Customer personnel, contractors, users, customers, business contacts, and other persons whose information Customer lawfully submits.
Data may include: business contact information, account information, job-related operational information, prompts, documents, communications, code, workflow information, and other Customer-submitted information.
6. Purpose Limitation
BEE RAD TECH will not use Customer Personal Data for unrelated purposes inconsistent with Customer instructions or this DPA.
7. Generalized AI Training
BEE RAD TECH will not intentionally use private Customer Personal Data to train generalized Ruzzler models for unrelated Customers unless Customer expressly authorizes that use.
8. Confidentiality
Personnel authorized to process Customer Personal Data will be subject to appropriate confidentiality obligations.
9. Security
BEE RAD TECH will maintain reasonable technical and organizational safeguards appropriate to the nature of the processing.
Relevant measures may include: access controls; authentication; encryption where applicable; logging; incident response; vulnerability management; data minimization; secret management; role separation; backup safeguards; sanitizer controls; and compartmentalized processing.
The specific measures reflect Ruzzler's actual technical environment.
10. Subprocessors
Customer authorizes BEE RAD TECH to use subprocessors necessary to provide the Services.
Subprocessor categories may include: cloud infrastructure; AI model providers; authentication providers; communications providers; monitoring/security providers; support services; and related technology providers.
Where required by applicable law or contract, BEE RAD TECH will maintain an applicable subprocessor list and provide notice of material new subprocessors.
11. AI Model Subprocessors
Depending on Customer configuration and routing, AI processing may involve providers such as OpenAI, Anthropic, Google, or other supported model providers.
Not every provider will necessarily receive every Customer workload.
12. Subprocessor Obligations
BEE RAD TECH will impose data-protection obligations on subprocessors appropriate to the processing and applicable law.
BEE RAD TECH remains responsible for its obligations under this DPA subject to the underlying agreement and applicable law.
13. Data Subject Requests
Where legally required, BEE RAD TECH will reasonably assist Customer with requests to exercise applicable rights concerning Customer Personal Data.
If BEE RAD TECH receives a request relating primarily to Customer-controlled Personal Data, it may direct the requester to Customer.
14. Security Incidents
BEE RAD TECH will notify Customer without undue delay after becoming aware of a confirmed Personal Data breach affecting Customer Personal Data where notification is required by applicable law or contract.
Notification may include information reasonably available concerning: nature of the incident; affected information; likely consequences; containment; and mitigation.
Initial notices may be supplemented as investigation continues.
15. Deletion and Return
Upon termination and subject to Customer instructions, BEE RAD TECH will delete or return eligible Customer Personal Data in accordance with the agreement and Retention & Deletion Policy.
Unless otherwise agreed: data may remain recoverable for up to 30 days; and active-system deletion is targeted within 7 additional days after that recovery period.
Legal and backup exceptions may apply.
16. Audits and Information
Where required by law and subject to reasonable confidentiality and security limitations, BEE RAD TECH will make information reasonably necessary to demonstrate compliance with this DPA available to Customer.
The parties may use independent audit reports or certifications when available instead of intrusive Customer audits where legally sufficient.
17. International Data Transfers
Where Customer Personal Data is transferred internationally and applicable law requires a transfer mechanism, the parties will implement an appropriate mechanism.
This may include, where applicable: European Commission Standard Contractual Clauses; UK transfer mechanisms; another approved contractual mechanism; or another lawful transfer basis.
The precise transfer terms are finalized per engagement based on actual hosting and subprocessor locations.
18. U.S. State Privacy Laws
Where BEE RAD TECH processes Customer Personal Data as a Service Provider or Contractor under applicable U.S. state privacy law, BEE RAD TECH will not: sell Customer Personal Data; retain, use, or disclose it outside the permitted business purposes except as allowed by law; or combine it with unrelated personal information where prohibited.
Customer remains responsible for determining whether these provisions apply to its use.
19. Employee Data
Customer acknowledges that Ruzzler employee profiles are intended for operational, productivity, workflow, and business-context purposes.
They are not intended to make employment-status decisions.
Customer is responsible for workplace privacy and employment-law obligations.
20. Private Vaults
Personal Memory and private Vault content are controlled by the individual and are outside Customer's instructions under this DPA, including when Customer pays for, provisions, or administers the user's license. Customer is not the Controller or Business for that content solely by virtue of the employment, payment, or account relationship.
Customer administrators, managers, payers, workflow owners, and support delegates cannot read, search, export, retain, place a Customer legal hold on, or direct processing of Personal Memory. Company workflows cannot retrieve it.
Only a specifically reviewed item that the individual affirmatively copies into a named Customer workspace becomes Customer Personal Data. The source, surrounding context, and future memories remain outside Customer's control.
Termination, offboarding, or mobile-device management may remove Customer-controlled work data but does not transfer the individual's Personal Memory to Customer.
21. Sanitization
Where enabled, Ruzzler may process Customer Personal Data through sanitization systems intended to limit unnecessary disclosure to downstream processors.
Sanitization reduces risk but cannot guarantee complete removal of all sensitive information.
22. Mosaic Processing
Where enabled, Ruzzler may divide workloads among multiple processors or systems to reduce the amount of full-context information provided to any single model.
Mosaic Mode does not eliminate data-protection risk.
23. Self-Hosted Deployments
For Customer-hosted systems, Customer is responsible for security and processing activities occurring within Customer-controlled infrastructure except to the extent expressly assigned to BEE RAD TECH.
24. Regulated Data
Unless expressly agreed in writing, Customer must not use Ruzzler in a manner that requires BEE RAD TECH to assume regulatory obligations it has not agreed to assume.
For example, processing requiring a HIPAA Business Associate Agreement should not occur unless an applicable BAA has been executed.
25. Conflict
If this DPA conflicts with the general Terms on processing of Customer Personal Data, this DPA controls for that subject matter.
26. Liability
Liability arising under this DPA is subject to the limitation-of-liability provisions in the underlying agreement unless applicable law requires otherwise.
27. Governing Terms
This DPA follows the governing-law and dispute provisions of the underlying enterprise agreement unless mandatory data-protection law requires otherwise.