Legal
Data Processing Agreement and subprocessors
What we do with personal data in your content, the measures that protect it, and every category of third party involved - including how you get notified when that list changes.
Effective January 15, 2026 · Version 2.0
The short version
- You are the controller, we are the processor, and we act only on your instructions.
- Subprocessors are listed by category and role, with 30 days’ notice and an objection right before any addition.
- Breaches are notified within 72 hours of us becoming aware, with what we know and what we do not.
- Export for 30 days after termination, then documented deletion - certified in writing on request.
- No training of shared models on your content, under any plan.
The summary is a courtesy; the sections below are the document.
01Roles and scope
Our Data Processing Agreement governs our processing of personal data contained in customer content. Your company is the controller and decides what to connect, who may access it, and for what purpose. Bhogar is the processor and acts only on your documented instructions, which include the configuration your administrators apply in the platform.
The DPA is offered as an addendum to your Order Form or master agreement. Where it conflicts with the Terms of Service on data protection, the DPA controls.
02Details of processing
- Subject matter
- Provision of the Bhogar intelligence platform: connecting and indexing organisational content, retrieval, agent and workflow execution, observability, and administration.
- Duration
- The term of your subscription, plus the export and deletion window described below.
- Nature and purpose
- Storage, indexing, embedding generation, retrieval, transmission to the model providers you configure, execution logging, and support.
- Categories of personal data
- Whatever appears in the sources you connect. Typically: identifiers and contact details, employment and role information, correspondence content, customer service records, and any personal data embedded in documents. You control this by choosing which sources to connect.
- Categories of data subjects
- Your employees and contractors, your customers and prospects, and third parties referenced in the content you connect.
- Special category data
- Not required by the platform. If your sources contain it, you remain responsible for the legal basis and for any additional safeguards; tell us so we can advise on configuration.
03Your instructions and responsibilities
- Determining the lawful basis for connecting each source, and providing any notices your own data subjects require.
- Configuring workspaces, roles, and module access so that people see only what they should.
- Choosing model providers, and accepting the data handling terms of any provider whose credentials you configure.
- Setting retention for conversation and execution history in line with your policy.
- Keeping administrator contact details current so breach and change notices reach a person.
We will tell you if an instruction appears to conflict with data protection law, and we will not process customer content for our own purposes, for profiling, or for training shared models.
04Technical and organisational measures
- Encryption of personal data in transit and at rest using managed cloud key infrastructure.
- Tenant scoping enforced server-side on every request, including vector search, so isolation does not depend on prompt content.
- Role-based retrieval: results are filtered by the requesting user’s entitlements before reaching a model.
- Role-based access control with module entitlements, multi-factor authentication including WebAuthn, and session revocation.
- Secrets held in a managed vault and referenced by identifier; never stored in application configuration or prompts.
- Audit and execution traces recording what ran, on whose behalf, and under which policy.
- Change management with peer review, automated tests, and evaluation gates before release.
- Least-privilege internal access with periodic review, logging of administrative action, and background-checked personnel bound by confidentiality.
- Backup and restore procedures, with monitoring and documented incident response.
05Subprocessors
We engage a small number of subprocessors to host, secure, and operate the platform, and to deliver model inference where you have not configured your own provider. Each is bound by written terms no less protective than the DPA, and we remain responsible for their performance.
| Category | Role | Applies when |
|---|---|---|
| Cloud infrastructure and hosting | Compute, managed database, object storage, networking, and key management (Microsoft Azure) | Managed deployment; not applicable if you host the platform yourself |
| Model inference - platform default | Generating responses and agent actions (Azure OpenAI / Microsoft Foundry deployments) | When you use the platform default provider rather than your own credentials |
| Model inference - customer configured | Generating responses under credentials you supply (for example OpenAI, Anthropic, Google, Amazon Bedrock) | When you configure your own provider; governed by your agreement with that provider |
| Observability and telemetry | Application performance monitoring, error diagnostics, and log retention | Platform default; can be pointed at your own OpenTelemetry backend instead |
| Transactional email | Account, invitation, notification, and support email delivery | All deployments that send email through us |
| Payment processing | Card and invoice processing for subscription fees | Paid subscriptions billed by us; the processor is named in your Order Form |
| Website analytics | Usage measurement on public marketing pages only | Where analytics is enabled and consented to; never inside authenticated product pages |
Changes to the list
- We notify subscribed administrators at least 30 days before a new subprocessor begins processing personal data.
- You may object on reasonable data protection grounds during that period. We will work to offer an alternative, and if none is workable you may terminate the affected part of the subscription with a pro rata refund.
- Emergency replacements to maintain security or availability are notified as soon as practicable, with the same objection right applied afterwards.
To subscribe to subprocessor change notices, email privacy@bhogar.ai with the addresses that should receive them.
06International transfers
Your deployment region determines where customer content is stored. Where personal data is transferred out of the EEA, the UK, or Switzerland, the DPA incorporates the European Commission’s Standard Contractual Clauses with the applicable module, the UK Addendum, and the Swiss adaptations, supported by a transfer impact assessment we will share on request.
Supplementary measures include encryption, tenant scoping, access logging, and a documented process for handling government access requests - including notifying you unless legally prohibited.
07Assisting with data subject requests
Administrators can locate, export, correct, and delete records within their tenant using the platform. Where a request cannot be satisfied through those tools, we assist within the timeframe you need to meet your own statutory deadline. If a data subject contacts us directly about content in your tenant, we refer them to you rather than acting on it ourselves.
08Personal data breach notification
- We notify affected customers without undue delay, and within 72 hours of becoming aware of a personal data breach affecting their data.
- The notice states what we know, what we are doing, and what we do not yet know - followed by updates as the investigation progresses.
- We provide the detail you need for your own regulator and data subject notifications, and a post-incident summary once the cause is confirmed.
09Return and deletion
On termination you can export customer content for 30 days using the platform’s export capabilities. After that window we delete or anonymise it on our documented schedule, with backups ageing out on their own cycle. We will certify deletion in writing on request, and we will tell you where a retention obligation prevents deletion instead of quietly keeping data.
10Audits and evidence
We provide the information reasonably required to demonstrate compliance: our security documentation, completed questionnaires, architecture detail under NDA, and the current status of any audit or certification programme. Where a regulator or your own audit obligations require more, we will agree a scope and timing that does not compromise other customers’ security.
11AI-specific processing terms
- Customer content is not used to train shared or foundation models.
- Prompts and retrieved context are sent to the model provider you configure, for the purpose of producing the response or action requested.
- Where you use the platform default provider, we contract for enterprise data handling terms that exclude training on submitted content.
- Guardrails can be configured to detect and block sensitive data before it leaves your tenant boundary.
- Execution traces are retained per your configuration so that automated processing remains explainable after the fact.
12Getting the DPA signed
Email privacy@bhogar.ai with your legal entity name and signing authority and we will send the current DPA for signature, together with the subprocessor annex and transfer documentation. Existing customers can request an updated version at any time, and we will flag whether a change requires re-signature or is covered by the existing addendum.
Need a signed DPA?
Email us with your legal entity name and signing authority. We send the current DPA, subprocessor annex, and transfer documentation.