Bowerbirds
How it worksPricingDownload
Get the Mac appGet the iPhone app↓

Legal & Privacy

Terms of ServicePrivacy PolicySubscriptions & RefundsLegal NoticeCookie PolicyData Processing AddendumService Providers

Data Processing Addendum

On this page
1. Parties and application2. Customer's instructions and responsibilities3. Confidentiality and security4. Subprocessors5. Assistance and rights requests6. Personal data breaches7. Transfers8. Return and deletion9. Demonstrating complianceSchedule 1 — Processing descriptionSchedule 2 — Technical and organizational measuresSchedule 3 — Subprocessors and international transfersAcceptance record

Effective date: September 18, 2026

1. Parties and application

This Data Processing Addendum ("DPA") forms part of the Bowerbirds Terms of Service where a business or organization identified in an accepted order or account record ("Customer") uses Bowerbirds to process personal data on its behalf and the GDPR applies to that processing.

The service provider and processor is Felipe Ignacio Letelier Basáez, a self-employed professional in Spain trading as Bowerbirds, at C. Río Gargáligas 15, 29002 Málaga, Spain. The privacy and security contact is felipe@bowerbirds.app. Customer's legal identity and authorized contact are those recorded in the accepted order or business account, as updated by Customer.

Customer is the controller, or a processor authorized by its controller to appoint Bowerbirds as a further processor. "Customer Personal Data" means personal data processed by Bowerbirds on Customer's behalf through the service. This DPA does not cover data for which Bowerbirds determines its own purposes, such as its tax records and direct account administration; the Privacy Policy describes that processing.

Terms such as controller, processor, personal data breach, and supervisory authority have their GDPR meanings. This DPA prevails over conflicting commercial terms for its subject matter. It does not restrict an individual's rights or a regulator's powers.

2. Customer's instructions and responsibilities

The agreement, this DPA, Customer's authorized settings and service requests, and additional mutually documented instructions define the permitted processing. Customer is responsible for selecting appropriate data, establishing a lawful basis, giving required notices, and obtaining any necessary authority or consent, including for recordings and connected services.

Bowerbirds processes Customer Personal Data only on those instructions, including instructions about transfers. If Union or Member State law requires other processing, Bowerbirds will notify Customer beforehand unless that law prohibits notice. Bowerbirds will promptly tell Customer if an instruction appears to infringe applicable data protection law and may pause the affected processing while the parties resolve it.

Bowerbirds will not use Customer Personal Data to build advertising profiles, sell it, or train general-purpose models for its own purposes. Any customer-directed model processing must remain within the agreed service and applicable provider conditions. Customer's permission to use an AI feature does not authorize unrelated reuse.

Customer is responsible for the scope of access it gives its users and customer-selected integrations. Bowerbirds remains responsible for the processing and safeguards it undertakes in this DPA.

3. Confidentiality and security

Bowerbirds will limit access to people who need it for an authorized purpose and who are bound by confidentiality duties. It will maintain technical and organizational measures appropriate to the risks, including the measures in Schedule 2, and will not materially reduce the agreed level of protection during the service.

Customer controls its own devices, user invitations, permissions, and the content it supplies. Each party will take reasonable steps to address a security issue within its responsibility. A customer's configuration responsibility does not excuse a defect in Bowerbirds' service controls.

4. Subprocessors

Customer gives general written authorization for the subprocessors identified as applicable to Customer Personal Data in the completed provider register. Bowerbirds will impose contractual data protection duties appropriate to the delegated processing and remains responsible to Customer for its subprocessors' performance of those duties.

Bowerbirds will give Customer's designated contact at least 30 days' advance notice before adding or replacing such a subprocessor. Customer may object during that period on reasonable data protection grounds. The parties will work toward an appropriate alternative. If no suitable solution is available, Customer may end the affected service before the change takes effect and receive a proportionate refund of prepaid fees for the unused affected period. The disputed provider will not receive Customer Personal Data before the notice and objection process is resolved; affected processing may be paused if necessary.

Providers acting solely as independent controllers and destinations that Customer independently selects are identified separately. Calling a supplier a subprocessor does not determine its legal role; the role follows the actual processing and agreement.

5. Assistance and rights requests

Bowerbirds will provide reasonable technical and organizational assistance enabling Customer to respond to requests for access, correction, erasure, restriction, portability, and other applicable rights. If a request concerning Customer Personal Data arrives directly, Bowerbirds will notify Customer or direct the requester to it, except where law requires a different response.

Taking account of the information available and the processing involved, Bowerbirds will assist Customer with security duties, impact assessments, and prior consultation with a supervisory authority. It will supply information needed to explain the service's relevant processing and safeguards. Any agreed charge for exceptional assistance must not prevent compliance with mandatory duties.

6. Personal data breaches

Bowerbirds will notify Customer without undue delay after becoming aware of a breach affecting Customer Personal Data. Notice will describe, as information becomes available, the incident, affected data and individuals, likely consequences, containment or remediation, and a contact for follow-up. Information may be supplied in stages rather than delaying the first notice until every fact is known.

Bowerbirds will take appropriate containment and remediation steps, preserve relevant evidence, and assist Customer with required notifications. Customer determines its own notification duties, without restricting obligations that apply independently to Bowerbirds. The processor's notice deadline is not replaced by a blanket 72-hour waiting period.

7. Transfers

Processing locations, remote access, and applicable transfer safeguards must be recorded in the completed provider register and Schedule 3. Bowerbirds will not transfer Customer Personal Data in a way that violates the GDPR's international-transfer requirements.

Where standard contractual clauses or another instrument are needed, the parties will ensure the correct instrument and annexes are completed for the actual transfer before it occurs, with required assessments and supplementary measures. This DPA is not itself the European Commission's international-transfer clauses and does not deem an uncompleted transfer agreement signed. A mandatory transfer instrument controls any conflict within its scope.

8. Return and deletion

Customer may retrieve data through the supported export features or request reasonable assistance. On termination, Bowerbirds will, at Customer's choice, return or delete Customer Personal Data and delete remaining copies, except for data that Union or Member State law requires it to retain. Customer should give return instructions before plan retention or an authorized deletion removes the relevant content.

The active-storage completion period is as follows. Sign-in access ends immediately: the account's identity record is deleted as the final step of the deletion request, and a failure at that step is reported to the person rather than recorded as success. Workspaces owned solely by the account are tombstoned in the same request. Their records and payload objects are then removed by the purge sweep, which acts on rows soft-deleted more than 30 days earlier. That 30-day delay is a recovery window, not an erasure period, and should be reconciled with what this policy promises an erasure request will achieve and the backup schedule is as follows, and both windows are short. Objects deleted from the payload bucket remain restorable for 7 days under the bucket's soft-delete policy — a safety net, not an administrator-browsable archive. The database retains 6 hours of point-in-time history, which is the entire window in which a past database state can be restored. Derived media chunks are deleted by lifecycle rule after 7 days. There is no separate long-term backup archive. Confirm this is the intended posture: six hours is a short window for a service that may hold a customer's only copy of a recording. Backups awaiting expiry will be isolated from ordinary use, and required deletions will be reapplied if a backup is restored. Legally retained data will be restricted to the retention purpose and erased when that duty ends. Bowerbirds will confirm completion on request.

An individual leaving a shared workspace is different from the controller ending processing for that workspace. The parties will preserve other people's rights without using ownership arrangements to obstruct a valid erasure request.

9. Demonstrating compliance

Bowerbirds will make available information needed to demonstrate compliance with this DPA and allow and contribute to audits and inspections by Customer or an appropriately qualified auditor it appoints. The parties will coordinate scope, timing, confidentiality, and protection of other customers' data. Existing evidence can be used where sufficient, but it is not a substitute for an inspection that is reasonably necessary.

Reasonable coordination will not prevent urgent investigation of a breach, a regulator's access, or another mandatory right. Customer will avoid unnecessary disruption. Bowerbirds will address substantiated deficiencies within a period appropriate to their risk.

Schedule 1 — Processing description

Item Description
Subject matter Operating Customer's selected Bowerbirds workspace and enabled capture, storage, retrieval, collaboration, AI, and integration features.
Duration The service term and the agreed return/deletion period, with limited legally required retention afterward.
Nature of operations Collection, receipt, recording, organization, storage, retrieval, access control, indexing, transcription or generation where enabled, authorized disclosure, export, and deletion.
Purpose Providing the requested productivity service under Customer's instructions.
Data subjects Customer's authorized users, employees, contractors, contacts, meeting participants, website visitors using a customer-installed capture widget, and other people lawfully included in Customer's content.
Data types Contact identifiers and workspace membership; text, files, images, audio, video, transcripts, prompts, results, associated metadata, and usage information necessary for the instructed processing.
Sensitive data Not required as a condition of using the service. Customer must identify any intended special-category or similarly sensitive processing and agree appropriate safeguards before using the service for it.
Instructions and contacts Customer's accepted order/account identity, authorized workspace settings, documented requests, and current designated privacy contact.

Schedule 2 — Technical and organizational measures

These are the measures to be maintained for processing under this DPA. Their detailed implementation and evidence must be completed in as follows, verified in the deployed configuration: TLS on every endpoint; uniform bucket-level access and public-access prevention on the payload bucket; payload access only through 15-minute signed URLs; third-party credentials sealed with a customer-managed Cloud KMS key; service secrets held in Secret Manager and injected by reference, never present in source; API tokens stored only as hashes; internal endpoints gated by a shared secret; per-key and per-day request fences; and separation of the development, staging and production estates into distinct databases, storage buckets and encryption keys, so that a non-production build cannot reach production data. Organisational measures, incident response and access review must be recorded separately. A supplier's certification does not certify Bowerbirds before execution.

Area Agreed measure
Access Authenticated service access; workspace authorization; restricted and reviewed administrative access; timely removal of access no longer needed.
Confidentiality Confidentiality commitments for authorized personnel; access to customer content limited to necessary service and support purposes.
Transmission and storage Protected network transport and appropriate storage encryption/key management, with the actual products and coverage documented in the security record.
Isolation Controls separating customer workspaces and restricting access from development and test environments.
Reliability Procedures for backup, recovery, and continuity appropriate to the service, with tested restoration and deletion handling.
Secure operation Managed credentials, security updates, logging proportionate to risk, incident response, and regular assessment of the effectiveness of safeguards.
Data lifecycle Documented retention and deletion jobs, export assistance, and controls for purging active data and expiring backups.
Suppliers Due diligence, processing agreements, access limits, and verification of relevant locations and transfers.

This schedule does not assert a security certification, independent audit result, or end-to-end encryption.

Schedule 3 — Subprocessors and international transfers

The completed Service Provider and Subprocessor Register, including its effective version, forms this schedule for the entries identified as processing Customer Personal Data. Attach or retain that version with Customer's accepted agreement. The consolidated locations and safeguards are **All Bowerbirds infrastructure is hosted in the United States, notwithstanding the operator's establishment in Spain: Cloud Run services and the record payload bucket in us-central1 (Iowa); the Postgres database on AWS us-east-2 (Ohio); Vertex AI on the global endpoint, which is not pinned to one region; and Cloudflare's global edge, which processes request metadata nearest the visitor. Personal data of users in the EEA is therefore transferred to the United States in the ordinary course of providing the service. The transfer mechanisms relied upon — Standard Contractual Clauses within each supplier's data processing agreement and, where applicable, that supplier's certification under the EU–US Data Privacy Framework — must be confirmed as executed for these specific accounts before this statement is published**.

Acceptance record

When used through a self-service business account, retain the Customer's legal identity, authorized representative and contact, applicable workspace, accepted document versions, and timestamp. A separately signed order can instead incorporate this DPA. Uploading a draft to a repository does not create an agreement with a customer.

Bowerbirds

Capture anything. Route what matters.

How it worksPricingDownload
© 2026
Terms of ServicePrivacy PolicySubscriptions & RefundsLegal NoticeCookie PolicyData Processing AddendumService Providers