Data Processing Agreement (DPA) - BScale AI
Last updated: 2026-05-27
This Data Processing Agreement is intended for business customers who use the platform to process personal data of their end customers. It is in force in parallel with the Terms of Service whenever the user (Controller) handles third-party data through BScale AI (Processor).
1. Definitions
Controller - you, the business customer using the platform.
Processor - BScale AI, processing personal data on your documented instructions.
Sub-processor - our contracted vendor (Google Cloud, Sentry, AI providers, etc.) as listed in the Privacy Policy.
Personal Data - any information about an identified or identifiable person that you upload.
2. Subject matter and duration
Subject: personal data of your end customers (leads, order details, email recipients, driver details, etc.) you upload or allow us to collect via your connections.
Duration: as long as your account is active, plus retention periods set in our Privacy Policy (Section 7).
3. Purpose of processing
Strictly to provide the service you requested - managing campaigns, audience segmentation, performance analysis, lead and order management, driver payroll, sending notifications.
We will not process personal data for our own purposes without an independent legal basis.
4. Controller instructions
We will process personal data solely on your documented instructions, expressed via your actions in the platform.
If an instruction would violate applicable law, we will notify you before performing it.
5. Staff confidentiality
Every team member with access to customer data is bound by a confidentiality undertaking.
Production access is least-privilege.
6. Security measures (GDPR Art. 32)
Encryption in transit (TLS 1.2+).
Encryption at rest for sensitive credentials (AES-256-GCM).
Salted hashed passwords.
Per-request CSP with nonces, double-submit CSRF, HMAC cron.
RBAC and least-privilege access.
Immutable audit log.
Documented security processes and incident response.
7. Sub-processors
You authorize the sub-processors listed in our Privacy Policy (Google Cloud, Sentry, Anthropic, OpenAI, Google Gemini, Runway, Kling, Seedance, PayPal, connected platforms).
We will give 30 days' notice before adding or replacing a sub-processor. You may object on reasoned grounds.
We ensure each sub-processor enters contractual commitments equivalent to those in this DPA.
8. Assistance with data-subject rights
We will assist you, to the extent reasonable, in responding to your customers' requests under GDPR Arts. 12-22.
Export and deletion tools in Settings > Security & privacy provide the technical foundation for surfacing or removing end-customer data.
9. DPIA and breach notification assistance
We will assist you, to the extent reasonable, with Data Protection Impact Assessments and consultations with supervisory authorities.
In case of a data breach we will notify you without undue delay and no later than 72 hours of becoming aware.
10. International transfers
Primary infrastructure in Europe (Google Cloud europe-west1).
For transfers outside the EEA we rely on the European Commission's SCCs (2021/914), the UK IDTA and Swiss FDPIC clauses.
11. Audits
Upon your written request we will provide reasonable information to demonstrate compliance with this DPA.
Site audits will be coordinated 30 days in advance and subject to reasonable security and operational constraints.
12. Return and deletion upon termination
Upon account termination - you may export your data in JSON via Settings > Security & privacy.
Within 30 days of account closure we will delete personal data, except accounting records the law requires us to keep (7 years).
13. Signature
Using the platform to process your end customers' data constitutes acceptance of this DPA.
If your company requires a counter-signed DPA - contact main@bscale.co.il and we will send a signed copy.