Parties, subject matter, and duration
The customer acts as controller and BIK AI Technologies, S.L.U. as processor when providing the platform. Processing lasts for the service term and the technical period needed to return or delete data under the contract.
Documented instructions
The order form, configuration by authorized users, incorporated documentation, and support requests form the customer's documented instructions within the contracted scope. An instruction that expands purpose, data categories, or recipients may require an amendment to the DPA or order form.
Enabling a model, agent, API, MCP, or integration is an instruction to process and disclose the context needed within its permissions. The customer must avoid granting a broader scope than necessary.
Nature of processing
BIKLABS stores, organises, retrieves, transmits on instruction, and deletes data to provide projects, wiki, BIA, agents, and related functions. Data may include identity, activity, project, document, and communication data entered by the customer about users, collaborators, and third parties.
- Data subjects: users, members, collaborators, customers, suppliers, and third parties whose data the customer submits.
- Data: identity and contact, account and roles, work content, documents, communications, files, prompts, outputs, and activity metadata.
- Operations: instructed collection, hosting, organisation, retrieval, authorised transmission, logging, export, and deletion.
Customer obligations
The customer warrants that its instructions are lawful, informs data subjects where required, configures permissions and oversight, limits data to what is necessary, and handles requests received as controller. It should avoid submitting special-category or high-risk data unless the contracted service and its measures expressly cover that processing.
Instructions and confidentiality
We process data only on documented customer instructions or where required by law. Authorised personnel are bound by confidentiality and receive least-privilege access. We will flag an instruction that appears to breach data-protection law unless legally prohibited.
Security
The documented technical baseline includes TLS 1.2 or later in transit and AWS-managed encryption at rest. Role controls, separate identities for people and agents, scoped MCP tokens, activity, backups, and incident response apply according to the capability, rollout status, and contracted scope.
The contractual technical and organizational measures annex describes current coverage and prevails over this summary. A screenshot, roadmap, or description of a future capability does not expand committed safeguards.
Subprocessors and transfers
We may use AWS in eu-west-3 (Paris), Cloudflare for network and security, and other necessary providers identified in the current contractual annex. We notify material changes and provide the objection mechanism stated in the contract.
When the customer selects a model, provides a key, or connects a tool, it may be instructing a disclosure to a third party it selected. The parties will document whether that party acts as a BIKLABS subprocessor, the customer's direct processor, or an independent controller.
We do not transfer data outside the EEA without a valid GDPR Chapter V safeguard. Region selection reduces transfers but does not replace review of each subprocessor.
Assistance, incidents, and audit
We assist with data-subject requests, impact assessments, and regulatory consultations to the extent permitted by the nature of the processing and information available to us.
We notify personal-data breaches without undue delay after becoming aware, progressively providing available information about their nature, affected categories, likely consequences, and measures taken. Notice of an incident is not an admission of liability.
We provide information reasonably needed to demonstrate Article 28 GDPR compliance. Audits are coordinated in advance, protect the security and confidentiality of other customers, and prioritize available reports or independent evidence before intrusive inspection.
Requests, assessments, and authorities
If we directly receive a request relating to data processed for the customer, we will refer it to the customer unless legally prohibited and will not respond on its behalf. Additional assistance, including extensive export or assessment work, may be subject to agreed terms.
We will reasonably cooperate with the competent authority and the customer on impact assessments or prior consultations relating to the service, without assuming the customer's decision on lawfulness or classification of its use case.
End of service
At the customer's choice and under the contract, we return or delete personal data at the end of service unless retention is legally required. Backups are blocked from active use and expire through their technical lifecycle.