Legal
Data Processing Addendum
This Data Processing Addendum ("DPA") forms part of the agreement between HEOSSI (Pte.) Ltd. ("Processor") and the Customer ("Controller"). It governs the processing of Personal Data (as defined under the GDPR, UK GDPR, and Singapore PDPA) submitted to Bee by the Controller. This DPA auto-incorporates into all paid Bee contracts; an executed counter-signed copy is available on request.
1. Roles and definitions
Where Customer Data contains Personal Data, the Customer is the Controller and HEOSSI is the Processor. HEOSSI may engage Sub-processors as listed in Schedule A. 'Personal Data', 'Processing', 'Data Subject', and 'Controller' have the meanings given in the GDPR.
2. Subject matter, duration, nature and purpose
- Subject matter: provision of the Bee service per the Terms.
- Duration: for the life of the subscription, plus a 30-day post-termination period for return / deletion.
- Nature and purpose: hosting, transmitting, storing, retrieving, executing inference on, and securing inputs and outputs.
- Categories of data subjects: end users authorised by the Controller (employees, contractors, customers).
- Categories of personal data: contact information, account credentials, content of prompts and outputs, document uploads, telemetry tied to user identifiers.
3. Customer instructions
We process Personal Data only on documented instructions from the Controller (these Terms, the Workspace, written instructions). If we cannot follow an instruction (e.g. it would breach law), we will inform the Controller without undue delay.
4. Sub-processors (Schedule A)
We use the following Sub-processors. Material changes are announced via the changelog and email to the account owner at least 14 days before taking effect, during which time Controllers may object on reasonable grounds. • Hugging Face — Model and adapter artifact hosting (EU / US) • Modal — Model inference and governed training jobs (US) • Vercel — Marketing site + workspace web hosting + edge (Global edge) • Supabase — Authentication, database (Postgres) (EU / US) • Stripe — Billing, payment processing, invoices (Global) • Sentry — Error monitoring (anonymised) (EU / US) • Namecheap Private Email — Transactional email (SMTP) (US) • Google LLC (Firebase Cloud Messaging) — Optional Android push delivery (effective 27 July 2026) (Global) • OpenQuantum — Optional, explicitly invoked real-QPU execution (Multi-region / hardware-provider dependent)
5. International transfers
- Where transfers of Personal Data leave the EEA, the UK, or another adequacy region, the EU Standard Contractual Clauses (Decision 2021/914) apply, supplemented by the UK Addendum where the data subject is in the UK.
- For transfers governed by the Singapore PDPA, we ensure a comparable standard of protection per the PDPC's transfer requirements.
- Hive-plan and above support a region-pinning option (EU only, US only, or Singapore only).
6. Confidentiality and personnel
Personnel authorised to process Personal Data are bound by written confidentiality. Access is just-in-time, audited, requires a signed reason, and is gated behind hardware-backed FIDO2.
7. Security measures (Annex II)
- Encryption in transit: TLS 1.3 minimum on the Bee API path by default.
- Encryption at rest: AES-256-GCM under service-managed per-tenant keys on shared cloud. Customer-controlled key arrangements require a separately contracted Enclave Regulated or Sovereign deployment and are not enabled merely by selecting a self-service plan.
- Network: VPC isolation, private subnets, default-deny egress.
- Access: SSO via Supabase, MFA required, scoped to tenant.
- Logging: tamper-evident audit logs (Hive+).
- Secure SDLC: code review on every change, dependency scanning, SAST, secret-scanning in CI.
8. Data subject rights and assistance
We assist the Controller — taking into account the nature of processing — in fulfilling its obligation to respond to data-subject requests. Workspace admin tooling allows the Controller to export, delete, and rectify Personal Data for its tenant.
9. Personal data breaches
We notify the Controller without undue delay (and in any event within 72 hours) of becoming aware of a Personal Data breach affecting Customer Data, with the information reasonably available at that time. We will provide reasonable cooperation with the Controller's notification obligations to supervisory authorities and data subjects.
10. Audits
We make available all information necessary to demonstrate compliance with this DPA and allow the Controller (or an appointed third-party auditor) to conduct audits no more than once per year, on at least 30 days' notice, during business hours, subject to reasonable confidentiality. Where we hold a current independent audit report (e.g. CSA STAR, ISO 27001 once attained) we will provide it in lieu, where the Controller agrees the report covers the request.
11. Return and deletion
Within 30 days of contract termination we will, at Controller's choice, return Personal Data and delete remaining copies, unless retention is required by law. Backups containing Personal Data expire on the standard 35-day rolling window.
12. Liability
Liability under this DPA is governed by, and is subject to, the limitations and exclusions in the Terms.
13. EU transfer SCC selections
- For restricted transfers from an EEA controller to HEOSSI in Singapore, the parties incorporate the European Commission Standard Contractual Clauses adopted by Decision (EU) 2021/914, Module Two (controller to processor). The optional docking clause applies; Option 2 general written authorisation applies to sub-processors with the 14-day notice period in section 4.
- The governing Member-State law for the SCCs is Ireland, and the courts of Ireland have jurisdiction under Clause 18. These SCC selections govern only the SCCs and do not replace the Singapore-law commercial terms where the SCCs do not require otherwise.
- For UK restricted transfers, the then-current UK International Data Transfer Addendum is incorporated with HEOSSI as importer and the customer as exporter; either party may end the Addendum as its mandatory tables permit following an approved change.
14. SCC Annex I — parties and transfer
- Exporter: the customer identified in the Bee account or Order Form. Importer: HEOSSI (Pte.) Ltd., Singapore; privacy contact bee-privacy@heossi.com.
- Data subjects: customer personnel, authorised end users, and persons whose personal data the customer lawfully submits. Data: account identifiers, prompts, outputs, uploaded documents, support content, and usage metadata. Sensitive data is not intended for shared tiers and requires an approved enterprise deployment.
- Frequency: continuous for the subscription term. Nature and purpose: hosting, inference, retrieval, support, security, and other documented customer instructions. Retention follows section 11 and the Privacy Policy. Competent supervisory authority: determined under Clause 13 of the SCCs.
15. SCC Annex II — technical and organisational measures
The measures in section 7 and the Security Practices document form Annex II, including encryption, tenant isolation, access control, logging, secure development, incident response, recovery, vendor review, deletion, and assistance with data-subject rights. Measures are applied according to service tier and the risk of the processing; features advertised only for Enclave or Hive+ are not implied for lower tiers.
16. SCC Annex III — sub-processors
The names, purposes, and regions in Schedule A (section 4) form Annex III. The account-owner email and changelog are the agreed notification mechanisms. A reasonable objection must identify a material data-protection risk; the parties will work in good faith on an alternative, and the customer may terminate the affected service if no reasonable alternative is available.
Questions about this document? Contact bee-privacy@heossi.com. Service of process: bee-legal@heossi.com (HEOSSI (Pte.) Ltd., Singapore).
Counter-signed copies on request. The text on this page is the canonical published version. For procurement teams that need a counter-signed copy of the Terms, DPA, or Order Form, email bee-legal@heossi.com. Where there is conflict between this page and an executed counter-signed agreement, the counter-signed agreement controls.