Data Processing Agreement
Version 2026-09-30.2 · 30 September 2026
For customers sending personal data to eu/jev on behalf of a controller. Review the agreement and annexes, then complete your details below. Accepted copies stay available from this page.
Related documents: Terms of Service, privacy policy, subprocessors and other providers.
1. Parties, conclusion and precedence
This Data Processing Agreement (DPA) is offered by Bevelites GmbH, Schleißheimer Str. 188, App. 520, 80797 München, Germany, Amtsgericht München, HRB 303590 (Bevel). It supplements the eu/jev service agreement. The customer is the legal person or individual identified in the acceptance record. The representative confirms authority to bind that customer.
The customer concludes this DPA electronically by completing the customer and processing details while signed in, checking the acceptance box and selecting ‘Accept DPA’. Bevel’s standing offer needs no separate countersignature. The acceptance record identifies the parties, account email, version, UTC time and agreement ID. A downloadable copy includes this agreement, the completed processing annexes, the initial subprocessor list and a document hash. No personal data in API content is needed to conclude it.
For customer personal data this DPA prevails over conflicting service terms. GDPR terms retain their statutory meanings. This is an Article 28 agreement, not a certification or the European Commission’s unmodified standard contractual clauses. It does not itself provide a Chapter V transfer mechanism.
2. Roles, scope and instructions
The customer determines the purposes and means of its processing as controller, or acts as a processor with its controller’s authorisation; Bevel is respectively its processor or subprocessor. This DPA covers personal data in API context, questions, criteria, outputs and temporary computational representations. Account administration, billing, necessary security and agreement records processed for Bevel’s own purposes are covered separately by the privacy policy.
Bevel processes customer personal data only to provide the agreed decision API and on documented instructions in this DPA, its completed annex and authorised API requests, including instructions about transfers. Further instructions can be sent to juan@bevel.software. Bevel will inform the customer immediately if an instruction appears to infringe data-protection law, and suspend the affected instruction pending clarification. If EU or Member State law requires other processing, Bevel will inform the customer before processing unless that law prohibits notice for important public-interest reasons.
Bevel does not sell customer personal data, use it for advertising, or train models on customer inputs or outputs. The customer supplies lawful instructions, appropriate notices and a legal basis, and minimises the data it sends. These customer obligations do not remove Bevel’s own obligations.
3. Confidentiality and security
Bevel will ensure that personnel authorised to process customer personal data are bound by confidentiality obligations and have access only as necessary for their duties. Bevel will implement and maintain technical and organisational measures appropriate to the risks under Article 32 GDPR, taking account of the nature, scope, context and purpose of processing and the state of the art. Annex B describes the current service design and its limits.
Bevel will assess security measures regularly, address identified deficiencies and test relevant application safeguards when changing the service. Changes must not materially reduce the agreed protection. The customer must assess whether these measures fit its intended use; additional safeguards for sensitive or high-risk processing must be agreed before that processing. This assessment does not waive Bevel’s Article 32 duties.
4. Subprocessors and changes
The customer gives general written authorisation for the subprocessors listed in Annex C. Before adding or replacing a subprocessor for customer personal data, Bevel will notify the customer at the account contact email at least 30 days before the proposed processing begins, identifying the provider, purpose, location and safeguards. Updating the public list alone is not that notice.
The customer may object on reasonable data-protection grounds within that period by writing to juan@bevel.software. The parties will seek a suitable alternative or safeguard. If the objection cannot be resolved before the change, the customer may terminate the affected service without a termination penalty and receive a proportionate refund of any unused prepaid paid service. The new provider will not process that customer’s data while an unresolved objection prevents lawful authorisation.
Bevel will bind subprocessors by written obligations providing the protection required by Article 28, verify sufficient guarantees and remain fully liable to the customer for their performance of those obligations. The same protection applies down the processing chain. Information needed to understand the relevant onward chain will be made available on request, with unrelated confidential information redacted where appropriate.
5. International transfers
The application, database and model execution are hosted in Germany. The public API connects directly to our Hetzner deployment; no external reverse-proxy provider or hosted model API processes its content in the current configuration. Separate DNS, Google sign-in and request-form services are described in the privacy policy and provider list; they are not used to process customer API content under this DPA.
Bevel will make or authorise a transfer outside the EEA only on documented instructions and with a valid Chapter V basis, such as an applicable adequacy decision or the appropriate EU transfer standard contractual clauses, together with a transfer assessment and supplementary measures where required. Bevel will provide information about the applicable mechanism on request and will suspend a transfer if adequate protection can no longer be ensured. General acceptance of this DPA is not explicit consent to a derogation under Article 49.
6. Data-subject rights and assistance
Bevel will promptly forward requests concerning customer personal data to the customer and will not respond substantively without its instructions unless legally required. Requests to juan@bevel.software should identify the customer account and relevant request references without resending sensitive content. Bevel will help identify retained data, provide available exports, correct or delete data it holds and address residual worker caches where applicable, so the customer can meet its legal deadlines.
Taking account of the processing and information available, Bevel will assist with security assessments, breach notification, data-protection impact assessments and prior consultations under Articles 32–36. Bevel will supply relevant architecture, security, subprocessor and incident information and cooperate with supervisory authorities. Historical prompts or outputs cannot be exported if they were never retained; the customer receives outputs at request time.
7. Personal-data breaches
Bevel will notify the customer without undue delay after becoming aware of a personal-data breach affecting customer personal data. Notice will go to the account contact email and include the nature of the breach, affected data and people and approximate numbers where known, likely consequences, mitigation and a contact for follow-up. Information may be provided in phases as it becomes available; investigation will not postpone the initial notice.
Bevel will contain and investigate the incident, preserve relevant evidence without unnecessarily retaining content, document remediation and assist the customer with its notifications. The controller decides on regulatory and data-subject notifications unless law requires Bevel to notify directly. The controller’s possible 72-hour deadline is not a waiting period for Bevel.
8. Return, deletion and duration
This DPA applies for the duration of customer personal-data processing under the service agreement. At the customer’s choice, on termination Bevel will return available customer personal data and delete remaining copies, or delete it without return, without undue delay and within 30 days after the customer’s instruction, unless EU or Member State law requires retention. Bevel will identify any legal retention requirement, isolate the relevant data from other use and delete it when that requirement ends.
The application does not archive API prompts or outputs. Transient input-token and intermediate-computation caches may survive individual requests and are shared across requests; they are not written to disk by the application. Deletion instructions cover residual cache data, including a worker cache reset or restart where necessary, and any copies held by subprocessors. Bevel will confirm completion on request. Technical inability to return an already discarded prompt does not authorise recreating or retaining it.
Agreement acceptance and necessary account or legal records are distinct controller records. Their purposes and retention criteria are described in the privacy policy, and they must not become an archive of customer API content.
9. Evidence, audits and non-compliance
Bevel will make available information necessary to demonstrate compliance and allow and contribute to audits and inspections by the customer or its mandated independent auditor. The parties will agree proportionate arrangements that protect other customers and security. Reasonable notice is expected for routine audits, but will not obstruct urgent incident, regulator or substantiated non-compliance investigations. Documents may be used first where sufficient; they do not eliminate inspection rights.
If Bevel cannot meet this DPA, it will inform the customer. The customer may suspend affected processing and terminate it if compliance cannot be restored within a reasonable period, or immediately for a serious breach. Statutory remedies, data-subject rights and supervisory powers remain unaffected. Changes to a concluded DPA require agreement, except subprocessor changes following clause 4 and security improvements consistent with clause 3.
Annex A — Processing details
Subject matter: providing eu/jev decision inference for the customer’s stated purpose. Nature: receiving and transmitting input, tokenising, performing GPU calculations, temporary memory caching and returning predictions. Frequency: on demand for each authorised request. Duration: the service term plus the deletion period in clause 8; there is no promise of erasure immediately after each response.
The completed acceptance record specifies the customer’s business purpose, categories of personal data and categories of data subjects. These can include customers, prospects, users, staff, contractors and other people mentioned in submissions; ordinary identity and contact details, correspondence, support requests and business records, and predictions about those people. Only the categories necessary for the stated purpose are authorised.
Special-category data, criminal-offence data and high-risk processing are excluded from this standard arrangement unless separately agreed in writing with appropriate safeguards. Listing such data in the form alone does not authorise it. The customer has the rights and obligations of its declared controller or processor role, including authority to instruct Bevel and responsibility for lawful collection and use.
Annex B — Security measures and service limits
Data minimisation: prompts and responses are not persisted in application databases or application logs or used for training. Technical logs omit bodies, credentials and query contents. Request metadata supports usage accounting and security. API responses carry Cache-Control: no-store.
Access control: Google sign-in, expiring HTTP-only same-site session cookies, hashed session/API credentials, revocable API keys, server-side account isolation and same-origin checks on browser mutations. Internal usage analytics requires a fresh verified Bevel Workspace identity, expires after 12 hours and contains no prompt or response content. Infrastructure access is restricted to authorised operators.
Network and runtime: public HTTPS; database and inference services are private to the deployment network without directly published database or inference ports. Worker access requires a separate credential. Internal container traffic is not application-layer encrypted. The model runs on the origin GPU. Container memory limits prevent configured containers from using additional swap; these limits do not establish host disk encryption.
Retention and resilience: application-container logs rotate by size, with three 10 MiB files per container. Session and rate-counter cleanup is activity-triggered. Model caches remain in volatile memory until replaced, cleared or restarted. Health checks and restart policies support recovery of running processes. Customer content is not an archive or backup service.
The repository does not establish encryption of underlying disks or backups, a fixed backup schedule or retention period, tested restore targets, or audited host-firewall settings. Those controls must be assessed and evidenced operationally; this annex does not represent them as implemented or waive Article 32 requirements. Request additional security information before a use that depends on those controls.
Organisational commitments: confidential access, incident handling and notification under clause 7, assistance and audits under clauses 6 and 9, subprocessor due diligence and change notices under clause 4, and risk-based review of safeguards. Contact for security and privacy: juan@bevel.software.
Annex C — Initial subprocessors
Hetzner Online GmbH. Industriestr. 25, 91710 Gunzenhausen, Germany. Purpose: Infrastructure hosting for the application, PostgreSQL database and GPU inference worker. Data: API inputs and outputs during processing; account, credential hashes, usage, security and agreement records on the origin server. Location: Origin hosting and model execution in Germany. Provider administration and any onward processing are governed by the applicable hosting agreement. Safeguards: Bevel has accepted Hetzner’s Article 28 processing agreement. The German origin hosting does not itself require a third-country transfer mechanism. Any onward transfer requires a separate valid Chapter V basis. Provider processing terms: https://docs.hetzner.com/general/company-and-policy/data-protection-at-hetzner/ Onward providers: https://www.hetzner.com/AV/subunternehmer.pdf
Loading your account…