Data Processing Agreement
Version 1.2 - 8 September 2026
This Data Processing Agreement (“DPA”) forms part of the Master Services Agreement between Bonnard Ltd. (“Processor” or “Bonnard”) and the Customer (“Controller”) and is subject to the terms of that Principal Agreement.
Definitions
- “Applicable Data Protection Laws” means the EU General Data Protection Regulation (EU) 2016/679 (“GDPR”) and its national implementations (including UK GDPR); and any other data protection laws in Europe (e.g., the UK Data Protection Act 2018).
- “Controller's Personal Data” means any Personal Data that Bonnard processes on behalf of the Controller under the Principal Agreement.
- “Personal Data” has the meaning set out in Article 4(1) of the GDPR.
- “Services” means the services that Bonnard provides to the Controller under the Principal Agreement.
1. Compliance with Applicable Data Protection Laws
Both Bonnard and the Controller shall comply with all applicable provisions of the Applicable Data Protection Laws in connection with the Processing of Controller's Personal Data. Each party shall ensure that its employees, agents or Sub-processors abide by the requirements of this DPA and Applicable Data Protection Laws.
2. Details and Scope of Processing
2.1 Subject matter and duration
Bonnard will process Controller's Personal Data solely to provide the Services described in the Principal Agreement. The duration of Processing shall be the term of the Principal Agreement, including any renewals.
2.2 Nature and purpose of Processing
Bonnard will Process Personal Data as strictly necessary to:
- Provide and maintain the Services
- Detect, prevent and resolve technical or security issues
- Respond to Controller's support requests
- Comply with any other documented instructions from the Controller
2.3 Categories of Personal Data
The Controller determines which Personal Data it uploads. Typical categories include:
- Names (e.g., customer name, lead name)
- Email addresses
- Telephone numbers
- IP addresses and device identifiers
2.4 Categories of Data Subjects
Employees, contractors or affiliates of Controller (to the extent their data is processed).
2.5 Controller's Instructions
Bonnard shall Process Personal Data only on documented instructions of the Controller. If Bonnard believes any instruction conflicts with Applicable Data Protection Laws, Bonnard shall inform Controller without undue delay.
2.6 Controller Responsibilities
Controller is responsible for:
- Ensuring it has a valid legal basis for Processing the Personal Data
- Providing accurate instructions and verifying data is lawfully collected
- Limiting the scope of data uploaded to what is necessary for the Services
- Encrypting any Personal Data before transmission if required by law
3. Controller and Processor Roles
For all Processing under this DPA, Controller is the Data Controller and Bonnard is the Data Processor. If the Controller acts as Processor in any context, Bonnard becomes a Sub-processor.
Bonnard's designated Data Protection contact: privacy@bonnard.ai
4. Confidentiality
Bonnard shall ensure that any person it authorises to Process Controller's Personal Data is under a binding confidentiality obligation. All personnel involved shall receive appropriate training on security and data protection.
5. Technical and Organizational Measures
Bonnard has implemented appropriate technical and organizational measures to protect Controller's Personal Data, including:
Access Control
Role-based access controls.
Authentication & Passwords
Enforced password policies and multi-factor authentication where applicable.
Encryption
All in-transit data encrypted via TLS 1.2 or higher. All data at rest encrypted using AES-256 or equivalent.
Vulnerability Management
Automated dependency and supply-chain scanning (Socket Security) runs on every pull request. High and critical findings are tracked to remediation, with patches applied within 30 days.
Backup & Recovery
Automated database backups managed by our infrastructure provider per plan tier. Recovery procedures documented and tested annually.
Incident Detection & Monitoring
Continuous application-level logging and monitoring across all services, including authentication events, API activity, and deployment changes.
Physical Security
Core infrastructure (application, database, and object storage) is hosted in the EU (Amsterdam). Certain sub-processors — for billing, transactional email, and AI processing — operate in the United States under the EU-U.S. Data Privacy Framework and/or Standard Contractual Clauses. See Section 6.2 for the current sub-processor list. Physical security controls are inherited from provider certifications.
Data Retention & Minimization
Personal Data collected is limited to what the Services require. In-life retention is tiered by sensitivity and applied by an automated daily process:
- Query content — the text of queries, backend error messages, tool arguments and any caller-supplied trace identifiers — is erased from the audit record 90 days after the call. The record of the call itself is kept.
- Usage metadata — app activity and tool-call records — is retained for 13 months attributed to the acting user, so that Controllers can analyse their own usage across a full year-over-year comparison.
- After 13 months the acting-user identifier is removed and the remaining usage metadata is kept in non-attributed form for a further 12 months, then deleted.
- Aggregated usage statistics that contain no user identifier are retained for up to 25 months.
- Billing records are retained for the period required by applicable company and tax law.
Post-termination handling is described in Section 11.
6. Sub-processing
6.1 General Authorization
Controller hereby authorises Bonnard to appoint Sub-processors to provide parts of the Services.
6.2 Current Sub-processors
| Entity | Location | Service |
|---|---|---|
| Railway Corporation | EU (Amsterdam) | Application hosting, database, and object storage |
| Vercel Inc. | EU | Marketing site hosting |
| Posthog, Inc | EU | Product analytics |
| Stripe, Inc. | US (DPF Approved) | Billing |
| Resend, Inc. | US (DPF Approved) | Transactional email |
| Anthropic, PBC | US (SCCs) | AI processing |
| OpenAI, L.L.C. | US (SCCs) | Advertising conversion measurement |
| Bonnard Ltd (UK) | UK | Service Provisioning |
6.3 Notice and Objection
Bonnard will notify Controller at least 14 days in advance of any new Sub-processor appointment. Controller may object in writing within 10 business days.
6.4 Flow-down Requirements
Bonnard will impose on any Sub-processor data protection obligations at least as stringent as those in this DPA. Bonnard remains fully liable for acts or omissions of its Sub-processors.
7. Data Subject Rights
If Bonnard receives a request directly from a Data Subject, Bonnard will promptly (within 5 business days) forward such request to Controller. Bonnard shall provide reasonable assistance to help Controller respond to Data Subject requests.
8. Personal Data Breaches
Bonnard shall notify Controller without undue delay – and in any event within 48 hours – after becoming aware of any Personal Data Breach. Notification shall include:
- Description of the nature of the breach
- Likelihood and severity of any risk to Data Subjects
- Proposed measures taken or to be taken to mitigate adverse effects
- Any other information necessary to fulfill Controller's breach-notification obligations
9. Data Protection Impact Assessments
If Controller determines that a DPIA or prior consultation with a supervisory authority is required, Bonnard shall provide reasonable assistance with the preparation.
10. Audits and Inspections
10.1 Compliance Documentation
Bonnard shall make available to Controller information necessary to demonstrate compliance with this DPA.
10.2 On-site or Third-party Audits
Controller may, once per calendar year and upon at least 30 days' written notice, conduct an audit of Bonnard's facilities insofar as they relate to Processing of Controller's Personal Data.
11. Return or Deletion of Personal Data
For 30 days after termination, Controller may export Controller's Personal Data through the Services or request that Bonnard return it. At the end of that period, Bonnard will delete Controller's Personal Data from its production systems within a further 30 days, and from encrypted backups within 180 days of termination as those backups age out on their ordinary cycle.
Bonnard will retain records it is required to keep by applicable law, and records necessary for the establishment, exercise or defence of legal claims — in practice, billing records and the security-audit trail of administrative actions. Those records are retained under the periods described in Section 5 and are not affected by a deletion request.
12. International Data Transfers
Personal Data may be transferred to and Processed by Bonnard's Sub-processors in the United States and other jurisdictions where Bonnard's Sub-processors operate, as listed in Section 6.2. Wherever Personal Data is transferred outside the UK/EEA, Bonnard will ensure the transfer is made pursuant to the EU-U.S. Data Privacy Framework (including the UK Extension) or the Standard Contractual Clauses, as applicable.
13. Governing Law and Jurisdiction
This DPA and all disputes arising from it are governed by the laws of England and Wales, subject to the exclusive jurisdiction of the courts of England and Wales.
14–16. Precedence, Severability & Termination
If there is any conflict between this DPA and other agreements, this DPA shall prevail. If any provision is unenforceable, the remainder continues in full force. This DPA terminates automatically when the Principal Agreement terminates. Sections 11, 12, 13, 14, and 15 survive expiration or termination.