Data Processing Addendum
Last updated October 6, 2026.
This addendum is part of the Terms of Service between you (the “customer”) and ATERNA LLC, which operates BizBee. It applies when we process personal information about your customers and other people your bee talks to (“customer personal data”). It applies automatically. If you need a countersigned copy, email legal@bizbeebot.com.
1. Roles
You are the controller (or a processor acting for your own client). We are your processor and, under US state privacy laws, your service provider. You decide why customer personal data is processed. We process it only to provide BizBee to you.
2. Your instructions
We process customer personal data only on your documented instructions: these terms, how you set up your bee, and the requests you send us. If we believe an instruction breaks the law, we will tell you.
3. Service provider commitments
- We do not sell or share customer personal data, including for targeted advertising.
- We do not keep, use or disclose it for any purpose other than providing BizBee to you, or outside our direct relationship with you.
- We do not combine it with personal data from other sources, except as the law allows for providing the service.
- We do not use it to train AI models for anyone else.
- We will tell you if we can no longer meet these obligations, and you may take reasonable steps to stop unauthorized use.
4. Our people
Everyone at BizBee who can access customer personal data is bound by confidentiality and accesses it only when needed to run the service.
5. Security
- Encrypted connections for all data in transit.
- Stored data encrypted by our hosting and database providers.
- Passwords hashed with scrypt. Session tokens stored only as hashes.
- Each customer's data is kept separate from other customers' data and served only to that customer's account and bees.
- Production access limited to the people who run the service.
6. Subprocessors
You authorize us to use the providers below. Each is bound by a written agreement that protects customer personal data at least as well as this addendum. We will update this list at least 14 days before adding a new subprocessor, and paid customers who email us asking to be notified will get those updates by email. If you object on reasonable data protection grounds and we cannot resolve it, you may cancel and we will refund any prepaid fees for the unused period.
| Provider | Purpose | Data involved |
|---|---|---|
| Vercel | Application hosting | All service data in transit and in use |
| Neon | Database | Accounts, business content, conversations, memories, leads |
| Vapi | Phone and browser voice calls | Call audio, transcripts, caller phone numbers |
| Deepgram | Speech to text for calls | Call audio |
| Anthropic | AI models for replies | Conversation text and relevant business content |
| Amazon Web Services | AI models for voice replies (Amazon Bedrock) | Conversation text and relevant business content |
| OpenAI | AI voice models, for bees set up with them | Call audio and conversation text |
| Resend | Email delivery and inbound email | Email addresses and message contents |
| Polar | Payments and merchant of record | Customer account and billing details only |
Customer personal data is processed in the United States.
7. Helping with requests
Your dashboard lets you delete conversations, memories and contacts. If someone sends a privacy request to us about your bee, we will pass it to you. We will help you respond to requests and with data protection assessments where the law requires it.
8. Security incidents
If we confirm a breach affecting your customer personal data, we will notify you without undue delay, and within 72 hours of confirming it. We will share what we know, what we are doing about it and what you may need to tell affected people. We will update you as we learn more.
9. When the agreement ends
You can ask us to export your conversations and leads within 30 days of your account closing. After that, we delete customer personal data within 30 days, except where the law requires us to keep it. Copies in backups expire on their normal schedule.
10. Audits
Once a year, or after a security incident, we will answer a reasonable written security questionnaire. We will also give you the information you reasonably need to show you are complying with data protection law.
11. International transfers
If you send us personal data from the EU, the EEA, the UK or Switzerland, the applicable Standard Contractual Clauses (or the UK Addendum) apply to that transfer, with you as data exporter and us as data importer. Email us for a signed copy.
12. Liability
Each party's liability under this addendum is subject to the limits in the Terms of Service.
