Data processing agreement

Version 2.0 · Last updated: August 6, 2026

This Data Processing Agreement (“DPA”) forms part of the Biel.ai Terms of Service or another written agreement between the customer (“Customer”) and Volcanic Labs SLU, operating Biel.ai (“Biel”). It applies when Biel processes personal data on Customer's behalf in connection with the Services. Customer is the controller and Biel is the processor, except where applicable law assigns a different role.

1. Definitions and interpretation

“Applicable Data Protection Law” means the GDPR and other data-protection laws applicable to the processing. “Customer Personal Data” means personal data processed by Biel on Customer's behalf. The terms controller, processor, data subject, personal data, processing, personal data breach and supervisory authority have the meanings given in the GDPR.

2. Processing details

Biel will process Customer Personal Data only to provide, secure, support and maintain the Services, in accordance with Customer's documented instructions and the processing details in Schedule 1. This DPA and Customer's use and configuration of the Services constitute documented instructions. Additional instructions must be consistent with the agreement and may be subject to reasonable fees where they require work beyond the Services.

If Biel believes an instruction infringes Applicable Data Protection Law, Biel will inform Customer without undue delay and may suspend the affected processing until the parties resolve the issue, unless the law prohibits that notice.

3. Customer responsibilities

Customer is responsible for the lawfulness, accuracy and quality of Customer Personal Data and its processing instructions. Customer will provide required notices, establish a lawful basis, configure the Services appropriately and avoid submitting special-category or highly sensitive personal data unless the parties have expressly agreed appropriate safeguards in writing.

4. Confidentiality

Biel will ensure that personnel authorized to process Customer Personal Data are bound by confidentiality obligations and receive appropriate data-protection and security guidance.

5. Security

Taking into account the state of the art, implementation costs, and the nature, scope, context and purposes of processing, Biel will maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure or access. The current categories of measures are described in Schedule 2 and the Security Overview. Biel may update these measures provided the overall level of protection is not materially reduced.

6. Personal data breaches

Biel will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. The notice will include the information reasonably available to Biel that Customer needs to meet its notification obligations. Biel may provide information in phases as it becomes available and will take reasonable steps to contain, investigate and mitigate the breach. Notification is not an admission of fault or liability.

7. Data-subject requests and regulatory assistance

Taking into account the nature of the processing, Biel will provide reasonable assistance for Customer to respond to data-subject requests. If Biel receives a request relating to Customer Personal Data, Biel will redirect it to Customer unless legally required to respond. Biel will also provide reasonable assistance with Customer's obligations concerning security, breach notifications, data-protection impact assessments and prior consultation, taking into account the information available to Biel. Biel may charge reasonable fees for assistance requiring material work beyond the standard Services, except to the extent the assistance is required because of Biel's breach of this DPA.

8. Subprocessors

Customer grants Biel general written authorization to use subprocessors. Biel maintains a current list in its provider documentation and will give advance notice of a new subprocessor that will process Customer Personal Data. Customer may object on reasonable data-protection grounds within 14 days of that notice. The parties will work in good faith to resolve the objection. If no reasonable alternative is available, either party may terminate the affected Services.

Biel will impose data-protection obligations on each subprocessor that are no less protective in substance than the relevant obligations in this DPA. Biel remains responsible for each subprocessor's performance of those obligations to the extent required by Applicable Data Protection Law.

9. International transfers

Biel will ensure that transfers of Customer Personal Data outside the European Economic Area are supported by a lawful transfer mechanism, such as an adequacy decision or the European Commission's Standard Contractual Clauses, together with supplementary measures where required. On request, Biel will provide information reasonably necessary for Customer to assess the applicable transfer safeguards.

10. Information and audits

Biel will make available information reasonably necessary to demonstrate compliance with this DPA. Customer may request relevant independent reports, certifications or written responses first. If those materials are insufficient, Customer may conduct an audit no more than once per year, or more frequently following a confirmed breach or where required by a supervisory authority. Audits require reasonable advance notice, must protect other customers and Biel's confidential information, and must not unreasonably disrupt operations. Customer is responsible for its auditor's fees and expenses.

11. Return and deletion

At the end of the Services, Biel will, at Customer's choice, return or delete Customer Personal Data within a reasonable period, unless applicable law requires retention. Data may remain in protected backups until overwritten under Biel's normal retention cycle and will not be restored except for disaster recovery or legal requirements.

12. Liability and order of precedence

The liability provisions in the agreement governing the Services apply to this DPA to the extent permitted by law. Nothing in this DPA limits obligations or rights that cannot lawfully be limited. If this DPA conflicts with the agreement on the processing of Customer Personal Data, this DPA controls. If applicable Standard Contractual Clauses conflict with this DPA, those clauses control.

13. Duration

This DPA remains in effect for as long as Biel processes Customer Personal Data on Customer's behalf.

Schedule 1 — Processing details

Subject matter and purpose

Providing, securing, supporting and maintaining Biel's documentation chat, search, analytics, integrations, API and related services configured by Customer.

Duration

The subscription term and the limited period required for return, deletion, backup expiry or legally required retention after termination.

Nature of processing

Collection, transmission, ingestion, organization, indexing, storage, retrieval, consultation, generation, display, logging, support, deletion and other processing needed to provide the Services.

Categories of data subjects

  • Customer's account administrators, team members and contractors.
  • People who use Customer's chatbot, search, team-chat integrations, API or other Biel-powered experiences.
  • People whose personal data Customer includes in connected documentation or other submitted content.

Types of personal data

  • Names, email addresses, account identifiers and organization details.
  • Questions, prompts, messages, feedback and other content submitted through the Services.
  • Documentation and connected-source content, which may incidentally contain personal data.
  • IP addresses, device and browser information, timestamps, authentication records and security or usage logs.
  • Support communications and configuration information supplied by Customer.

Special-category data

The Services are not intended for special-category data or data relating to criminal convictions. Customer must not submit such data unless expressly agreed in writing with Biel and permitted by law.

Schedule 2 — Technical and organizational measures

  • Access controls designed to restrict production and customer data to authorized personnel and services.
  • Encryption of data in transit and at rest using current industry-standard protocols.
  • Logical separation of customer projects and scoped credentials for service access.
  • Logging, monitoring, incident-response and recovery procedures proportionate to the Services.
  • Backup, availability and restoration controls appropriate to hosted services.
  • Secure development, dependency management and vulnerability remediation practices.
  • Confidentiality commitments and security guidance for authorized personnel.
  • Vendor assessment and contractual controls for subprocessors.
  • Retention and deletion controls for Customer Personal Data and credentials.

Contact

Volcanic Labs SLU

Plaza de Galicia, Local 7, 38612, Santa Cruz de Tenerife, Spain

Email: [email protected]

Try me ↓