Data Processing Agreement (DPA)
Effective Date:
Last Updated:
This Data Processing Agreement ("DPA") forms part of the Terms of Service (the "Terms") between BaseDynamics Inc., a Delaware corporation with its principal office at 16192 Coastal Hwy, Lewes, DE 19958 ("BaseDynamics"), and the customer entity that has agreed to the Terms ("Customer," "You"). This DPA applies where BaseDynamics Processes Personal Data on Your behalf as a Processor. In the event of a conflict between this DPA and the Terms, this DPA prevails with respect to the Processing of Personal Data.
1. Definitions
Capitalized terms not defined here have the meaning given in the Terms.
- "Controller" and "Processor" have the meanings given under the GDPR.
- "Data Protection Laws" means all data protection and privacy laws applicable to the Processing of Personal Data under this DPA, including the GDPR, UK GDPR, Swiss FADP, and applicable US state privacy laws (e.g., CCPA/CPRA), as amended or superseded.
- "Data Subject" means the identified or identifiable natural person to whom Personal Data relates.
- "Personal Data" means any Personal Data forming part of Customer Data that BaseDynamics Processes on Your behalf.
- "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data.
- "Standard Contractual Clauses" or "SCCs" means:
- where the GDPR applies, the standard contractual clauses approved by the European Commission under Implementing Decision (EU) 2021/914 of 4 June 2021, available at eur-lex.europa.eu/eli/dec_impl/2021/914 ("EU SCCs");
- where the UK GDPR applies, the UK's International Data Transfer Addendum to the EU SCCs, issued by the UK Information Commissioner ("UK Addendum"); and
- where the Swiss FADP applies, the EU SCCs as adapted for Switzerland in accordance with guidance from the Swiss Federal Data Protection and Information Commissioner ("Swiss SCCs"),
- "Sub-processor" means a third party engaged by BaseDynamics to Process Personal Data in connection with the Services.
2. Scope and Roles
2.1 This DPA applies to Personal Data forming part of Customer Data Processed by BaseDynamics in connection with the Services.
2.2 BaseDynamics acts as Processor (or Sub-processor, where You act as a Processor for a third party) and will Process Personal Data only on Your documented instructions, including as set out in the Terms and this DPA, unless required to do otherwise by law, in which case BaseDynamics will inform You of that legal requirement before Processing, unless prohibited from doing so.
2.3 Each Party is responsible for complying with its own obligations as Controller or Processor under applicable Data Protection Laws.
3. Term
This DPA takes effect on the Effective Date and continues for as long as BaseDynamics Processes Personal Data under the Terms, terminating automatically thereafter.
4. Processing Instructions
BaseDynamics will Process Personal Data only in accordance with Your instructions as set out in this DPA and the Terms. Any Processing outside this scope requires prior written agreement between the Parties. BaseDynamics will promptly notify You if, in its reasonable opinion, an instruction infringes applicable Data Protection Laws.
5. Confidentiality of Processing Personnel
BaseDynamics will ensure that personnel authorized to Process Personal Data are subject to appropriate confidentiality obligations and have received appropriate training on data protection.
6. Sub-processors
6.1 You provide general authorization for BaseDynamics to engage the Sub-processors listed below, and any additional Sub-processors added in accordance with this Section:
| Sub-processor | Purpose | Location |
|---|---|---|
| Amazon Web Services (AWS) | Cloud hosting and infrastructure | US (us-east-1) |
| Microsoft Azure | Cloud infrastructure / services | US |
| OpenAI | AI/ML processing for agentic features | US |
| Anthropic | AI/ML processing for agentic features | US |
| Temporal Cloud | Workflow orchestration | US |
This list may be updated from time to time; the current list will be made available upon request to privacy@basedynamics.com.
BaseDynamics may engage additional AI-model providers in the future (which may include providers such as Google or xAI) to support the Services. Any such addition will follow the Sub-processor notification process in Section 6.2 below.
For clarity: where a Customer or User connects a third-party account (e.g., Gmail/Google Workspace or Microsoft 365) to the Services via OAuth, Google or Microsoft act as the source system from which Customer Data is retrieved at the Customer's direction, and are not thereby engaged as a Sub-processor of BaseDynamics.
6.2 BaseDynamics will notify You of any intended changes to this list (addition or replacement of a Sub-processor) at least fifteen (15) days in advance where required by applicable Data Protection Laws. You may object on reasonable data-protection grounds within that period; if the Parties cannot resolve the objection, either Party may terminate the affected Services.
6.3 BaseDynamics will impose data protection obligations on Sub-processors that are substantially equivalent to those in this DPA and remains liable for Sub-processors' performance of those obligations.
7. Data Subject Requests
If BaseDynamics receives a request from a Data Subject relating to Personal Data for which You are the Controller, BaseDynamics will not respond directly (unless legally required) and will forward the request to You without undue delay, and in any event within five (5) business days. BaseDynamics will provide reasonable assistance to help You respond to such requests.
8. Technical and Organizational Measures
BaseDynamics will implement and maintain appropriate technical and organizational measures designed to protect Personal Data against a Personal Data Breach, taking into account the state of the art, cost of implementation, and the risk to Data Subjects. A summary of these measures is available on request to security@basedynamics.com.
9. International Data Transfers
Where the transfer of Personal Data from You to BaseDynamics constitutes a restricted transfer under applicable Data Protection Laws (e.g., from the EEA, UK, or Switzerland to the US), such transfer will be subject to the Standard Contractual Clauses, completed as set out in Exhibit A to this DPA, which is incorporated into and forms an integral part of this DPA. Customer Data is primarily hosted on AWS infrastructure located in the United States (us-east-1 region).
10. Personal Data Breach Notification
BaseDynamics will notify You without undue delay after becoming aware of a Personal Data Breach affecting Personal Data Processed under this DPA, and will provide reasonably available information to help You meet any notification obligations under applicable Data Protection Laws, and will cooperate with You in investigating and remediating the incident.
11. Assistance with Compliance
BaseDynamics will provide reasonable assistance to You, at Your reasonable expense where applicable, in connection with:
- responding to Data Subject requests;
- Data Protection Impact Assessments; and
- consultations with supervisory authorities, to the extent required under applicable Data Protection Laws and relating to BaseDynamics' Processing of Personal Data.
12. Audit and Information Rights
12.1 Upon reasonable written request, and no more than once per year (except following a confirmed Personal Data Breach), BaseDynamics will make available information reasonably necessary to demonstrate compliance with this DPA, which may include summaries of security practices, completed security questionnaires, or, once available, relevant third-party audit reports or certifications.
12.2 BaseDynamics notes that its ISO 27001 and SOC 2 certifications, and formal GDPR compliance program, are currently in progress and not yet obtained; BaseDynamics does not represent that such certifications are currently in effect and will update this DPA and notify Customers upon certification.
13. Deletion or Return of Personal Data
Upon termination of the Terms, BaseDynamics will, at Your election, delete or return Personal Data within thirty (30) days, except to the extent applicable law requires continued retention, in which case BaseDynamics will isolate and protect such data from further Processing.
14. US State Privacy Law Terms
Where applicable US state privacy laws (e.g., CCPA/CPRA) apply, BaseDynamics acts as a "Service Provider" or "Processor" with respect to Personal Information disclosed by You, and will:
- not sell or share such Personal Information;
- not retain, use, or disclose it for any purpose other than providing the Services;
- not combine it with Personal Information from other sources except as permitted by law; and
- assist You in responding to consumer requests as reasonably required.
15. Liability
Each Party's liability arising out of this DPA is subject to the limitation of liability set out in the Terms.
16. Miscellaneous
16.1 In case of conflict between this DPA and the Terms, this DPA prevails with respect to the Processing of Personal Data. In case of conflict between this DPA and the SCCs, the SCCs prevail.
16.2 This DPA does not apply where BaseDynamics is itself a Controller of Personal Data (e.g., account or billing contact data), which is governed by the Privacy Policy.
16.3 Notices under this DPA may be given by email to the contacts below.
16.4 This DPA is governed by the same governing law as the Terms.
Exhibit A: Standard Contractual Clauses
This Exhibit A applies to transfers of Personal Data subject to the GDPR, UK GDPR, and/or Swiss FADP, as applicable, and completes the Standard Contractual Clauses referenced in Section 9 above. The full text of the EU SCCs is available at the European Commission's official source: eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32021D0914.
A.1 EU SCCs (EEA transfers).
Where the EU SCCs apply:
- Module Two (Controller to Processor) applies where Customer is a Controller and BaseDynamics is a Processor; Module Three (Processor to Processor) applies where Customer is a Processor and BaseDynamics is a Sub-processor.
- The optional docking clause in Clause 7 applies.
- In Clause 9(a), Option 2 (general written authorization) applies, with a fifteen (15) business day notice period for Sub-processor changes as described in Section 6.2 of this DPA.
- In Clause 11(a), the optional language on independent dispute-resolution bodies does not apply.
- In Clause 17, Option 1 applies; the EU SCCs are governed by the laws of Ireland.
- In Clause 18(b), disputes will be resolved before the courts of Ireland.
- Annexes I, II, and III of the EU SCCs are deemed completed with the information in Sections A.4–A.6 below.
A.2 UK Transfers.
Where Personal Data is transferred from the UK, the UK Addendum is incorporated by reference and applied to the EU SCCs completed under Section A.1, in accordance with the template issued by the UK Information Commissioner (Version B1.0). The competent authority is the UK Information Commissioner's Office, and disputes are subject to the courts of England and Wales.
A.3 Swiss Transfers.
Where Personal Data is transferred from Switzerland, the EU SCCs completed under Section A.1 apply with the following adaptations:
- references to the "GDPR" are read as references to the Swiss FADP;
- the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner; and
- disputes are subject to the competent courts of Switzerland, in each case to the extent required by Swiss law.
A.4 Annex I: List of Parties
Data Exporter: Customer, as identified in the Order Form or Account registration for the Services. Role: Controller (or Processor, where Customer is a Processor acting on behalf of a third-party Controller). Contact: The Customer's designated account administrator or the contact provided at sign-up.
Data Importer: Name: BaseDynamics Inc. Address: 16192 Coastal Hwy, Lewes, DE 19958, USA Contact: privacy@basedynamics.com Role: Processor (or Sub-processor, as applicable). Activities relevant to the data transferred: Provision of the BaseDynamics customer intelligence platform, including hosting, storage, and AI-assisted analysis of Customer Data, as described in the Terms.
A.5 Annex I.B: Description of Transfer
- Categories of Data Subjects: Customer's employees, contractors, and end customers (including individual contacts at Customer's business accounts) whose data is included in Customer Data.
- Categories of Personal Data: Name, business email address, phone number, job title, company affiliation, product usage data, support/feedback content, and other Customer Data fields Customer chooses to submit to the Services. Where Customer or its Users connect a Gmail/Google Workspace or Microsoft 365 account, categories also include email content and metadata, and calendar event details (including attendee names and email addresses) accessed via OAuth at Customer's direction. No special categories of data are intended to be transferred; Customer agrees not to submit special/sensitive categories of Personal Data to the Services.
- Frequency of transfer: Continuous, for the duration of the Subscription Term.
- Nature of processing: Hosting, storage, transmission, and AI-assisted analysis (including by Sub-processors) necessary to provide, maintain, secure, and improve the Services, including analysis of connected email and calendar data (where enabled) to generate Customer Voice insights (topic, sentiment, intent, keyphrase, and competitor-mention data) and to send email or schedule calendar events at Customer's direction.
- Purpose of transfer: To provide the Services to Customer in accordance with the Terms.
- Retention period: For the duration of the Subscription Term and, thereafter, in accordance with Section 13 of this DPA.
- Sub-processors: As listed in Section 6 of this DPA (Amazon Web Services, Microsoft Azure, OpenAI, Anthropic, Temporal Cloud), each located in the United States.
A.6 Annex II: Technical and Organizational Measures
BaseDynamics maintains technical and organizational measures designed to protect Personal Data, including: encryption of data in transit and at rest; role-based access controls and the principle of least privilege; logging and monitoring of production systems; a documented incident response process; regular vulnerability management; and vendor/Sub-processor security review. A current summary of these measures is available on request to security@basedynamics.com. (BaseDynamics' ISO 27001 and SOC 2 certifications are in progress; this summary will be supplemented with the relevant audit reports once available.)
A.7 Annex III: List of Sub-processors
As set out in Section 6 of this DPA. The current list is also available on request to privacy@basedynamics.com.
A.8 Competent Supervisory Authority.
Where Module Two applies, the competent supervisory authority is the supervisory authority of the EU member state in which Customer, as data exporter, is established (or, where Customer is not established in the EU, the supervisory authority determined in accordance with Clause 13 of the EU SCCs).
Contacts
BaseDynamics Inc.
16192 Coastal Hwy, Lewes, DE 19958
- Data protection inquiries: privacy@basedynamics.com
- Security inquiries: security@basedynamics.com
- Legal inquiries: legal@basedynamics.com
Note to Customer: please provide your entity name and notice address for completion of the Parties block prior to execution.