Builders Studio B.V. · Version 1.1 · Last updated: 21 September 2026
Builders Studio B.V. Version 1.1 · Last updated: 21 September 2026
This Data Processing Agreement (the "DPA") applies where Builders Studio B.V., registered in the Netherlands, with its registered office at Stationsplein 45, D3.118, 3013 AK Rotterdam, registered with the Dutch Chamber of Commerce under number 62682466 ("Builders", "we", "us"), processes personal data on behalf of a customer in the performance of the VSI (Venture Studio Intelligence) platform (the "Service").
This DPA has no independent existence: it always forms an integral part of a contract between Builders and the Customer (the "Agreement"), and applies only for as long as that Agreement is in force. The Agreement is:
Where a signed Agreement incorporates this DPA, this DPA becomes an integral part of that Agreement and is read together with it. It does not replace, override or reopen anything the Parties negotiated in that Agreement: the commercial, liability, term, governing-law and other provisions of the signed Agreement continue to apply in full, and this DPA supplies only the data protection terms required by article 28 GDPR.
Order of precedence, in descending order:
Where this DPA refers to a provision of the Agreement (such as liability or governing law) and the applicable Agreement contains no such provision, the corresponding provision of the Terms of Service applies.
Builders processes personal data solely on the documented instructions of Customer, including the instructions arising from this DPA and from the use of the Service by Customer and its Authorized Users. The Agreement, together with written instructions provided by Customer, constitutes Customer's documented instruction for the purposes of this DPA. If a statutory obligation requires Builders to disclose personal data, Builders informs Customer in advance, unless that law prohibits such information.
Builders processes Customer Personal Data solely for the delivery and maintenance of the Service as described in the Agreement. Builders does not process Customer Personal Data for any other purpose, including but not limited to training or improving foundation models, benchmarking, or developing products or features for other customers, unless Customer expressly consents in advance and in writing.
The processing activities of Builders comprise: hosting and processing of conversations, signals, artifacts, reflections and memory inputs within the Service; intake and storage of uploaded documents and files; transcription and analysis of conversation content supplied by Customer; synthesis of reflections and portfolio-level insights; and associated operational support.
Categories of personal data that Builders may process: identification and contact details of Authorized Users (name, e-mail, organisation, role); content of conversations and notes that Customer or its Authorized Users submit to the Service or have processed; uploaded documents and files and the personal data contained therein; telephone conversations if supplied by Customer; and usage statistics and logging.
Categories of data subjects include Authorized Users of Customer, external conversation partners of Customer whose content is processed in the Service, and persons named in documents supplied by Customer. Customer does not supply special categories of personal data within the meaning of article 9 GDPR to the Service, unless the Parties make additional written arrangements in advance.
Builders processes Customer Personal Data for the duration of the Agreement, unless an applicable statutory retention obligation prescribes a longer retention period.
Builders ensures that persons processing personal data are subject to a duty of confidentiality. Access to Customer Personal Data is strictly limited to personnel who need that access for the delivery of the Service. Builders takes reasonable measures to ensure the reliability of every employee, contractor or sub-processor with access to Customer Personal Data.
Builders takes appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with article 32 GDPR. These measures include:
In determining the appropriate level of security, Builders takes account of the risks presented by the processing, including the risks of accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data. Security measures are reviewed and updated periodically as the platform develops and threats change. A revision does not materially reduce the level of security compared to the level at the start of the Agreement.
The Service runs in the Frankfurt region (eu-central-1): application and API hosting on Vercel, a managed PostgreSQL database on Supabase and file storage on AWS S3, all in Frankfurt, Germany. Customer Data is stored and processed within the EEA, in line with EU data residency requirements and the GDPR.
Builders deploys third-party Large Language Models (Anthropic Claude and Google Gemini) to deliver intelligence functions, including conversation analysis, signal extraction, artifact generation and reflection synthesis. Builders selects API configurations that exclude training of foundation models on Customer Data where the provider offers that option. Processing by LLM providers is short-lived inference: no long-term data retention takes place at the provider under the enterprise or API terms we use. All transmission to LLM providers takes place over HTTPS.
Customer grants general authorisation for the engagement of the sub-processors listed in Section 11, which serves as the current reference for the Parties.
Builders announces intended additions or replacements of sub-processors at least thirty (30) days in advance. Customer has the right within that period to object in writing and with reasons on reasonable data protection grounds. The Parties will negotiate in good faith on a solution. If the Parties do not reach a reasonable solution, either Party has the right to terminate the affected part of the Service without compensation as of the date on which the new sub-processor would be engaged.
Builders binds sub-processors by written agreement to at least the obligations resting on Builders under this DPA, including those regarding security and data protection. Builders remains fully liable to Customer for the performance by each sub-processor of its obligations, in accordance with article 28(4) GDPR. The contractual limitations of liability in the Agreement continue to apply to this liability of Builders.
A sub-processor is classified as Critical if permanent unavailability would prevent Builders from delivering the core functionality of the Service, and no functionally equivalent replacement can be deployed within sixty (60) days. All other sub-processors are Non-critical and can be replaced within sixty (60) days without materially affecting the core functionality of the Service.
| Sub-processor | Location | Purpose | Classification | Transfer mechanism |
|---|---|---|---|---|
| Vercel Inc. | US (hosting in Frankfurt, DE) | Application and API hosting | Critical | EU Standard Contractual Clauses |
| Supabase Inc. | US (database in Frankfurt, DE) | Managed PostgreSQL database | Critical | EU Standard Contractual Clauses |
| Amazon Web Services EMEA SARL | Luxembourg (storage in Frankfurt, DE) | S3 object storage for uploaded files and artifacts | Critical | Within EEA |
| Assembly AI Inc. | US (processing in the EU region) | Speech-to-text transcription of call recordings | Non-critical | EU Standard Contractual Clauses |
| Anthropic PBC | US | LLM inference (Claude), short-lived, no long-term retention | Non-critical | EU Standard Contractual Clauses |
| Google Cloud EMEA Limited | Ireland | LLM inference (Gemini), short-lived, no long-term retention | Non-critical | Within EEA |
| OpenAI LLC | US | Embedding generation for search and signal matching | Non-critical | EU Standard Contractual Clauses |
| Cohere Inc. | Canada | Search result reranking | Non-critical | Adequacy decision (Canada) |
Builders provides Customer with reasonable technical and organisational assistance to enable Customer to comply with data subject requests, including requests for access, rectification, erasure, restriction, data portability and objection under applicable Data Protection Legislation. Any additional costs of exceptional or excessive assistance may be reasonably charged by Builders to Customer, following prior consultation.
If a data subject approaches Builders directly with a request to exercise his or her rights under the GDPR in respect of Customer Personal Data, Builders forwards that request to Customer without delay and does not handle the request independently, unless Customer instructs otherwise or the law requires otherwise.
Builders informs Customer without undue delay, and in any event within forty-eight (48) hours of discovery, of a personal data breach within the meaning of the GDPR. The notification contains at least the information referred to in article 33(3) GDPR, to the extent available: a description of the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences of the breach, and the measures taken or proposed.
Builders cooperates with Customer and takes reasonable steps to support Customer in the investigation, mitigation and remediation of a Personal Data Breach, including reasonable support in respect of Customer's own notification obligation to the supervisory authority and, where applicable, to data subjects.
Builders provides Customer with reasonable assistance in data protection impact assessments (DPIAs) carried out by Customer and in prior consultations with supervisory authorities, to the extent Customer reasonably considers these necessary under article 35 or article 36 GDPR and they relate to the processing of Customer Personal Data by Builders.
On termination or expiry of the Agreement, Builders makes Customer Data available for export in a common machine-readable format for a period of thirty (30) days after the termination or expiry date (the "export window"). Within the export window Customer indicates in writing whether Builders should return or delete the personal data. Builders deletes or returns the personal data, at Customer's option, within thirty (30) days after the end of the export window. This obligation applies to all copies of Customer Personal Data processed by Builders and its sub-processors, except to the extent a statutory retention obligation applies. If Customer does not indicate a choice within the export window, Builders deletes the personal data after expiry of the periods set out in this paragraph.
Builders is not obliged to delete Customer Personal Data to the extent a statutory retention obligation applies. In that case Builders informs Customer and the obligations of security and confidentiality under this DPA continue to apply for as long as the data is retained.
Builders makes available to Customer, on reasonable written request, all information necessary to demonstrate compliance with this DPA and with article 28 GDPR.
Customer has the right to carry out or have carried out an audit, including inspections, of Builders' compliance with this DPA at most once per calendar year. The costs of the audit are borne by Customer, except where the audit reveals a material non-compliance by Builders. Audits are subject to the following conditions:
To the extent Builders has obtained relevant third party certifications or independent security assessments, Builders may satisfy audit requests by making the relevant reports or certifications available for inspection, to the extent these cover the scope of Customer's audit request.
Builders stores and processes all Customer Personal Data on infrastructure physically located within Germany and the EEA, namely Vercel (Frankfurt), Supabase (Frankfurt) and AWS (Frankfurt). Speech-to-text transcription is performed in the European Union region. Customer Personal Data is not stored outside the EEA as part of Builders' core hosting and database operations.
Builders acknowledges that Vercel Inc., Supabase Inc. and Assembly AI Inc. are incorporated in the United States and that any access to Customer Personal Data by these entities or their US parent companies qualifies as a transfer outside the EEA within the meaning of Chapter V GDPR. For these sub-processors Builders applies the EU Standard Contractual Clauses, supplemented with appropriate technical and organisational measures, including encryption in transit and at rest and restriction of access rights. Builders has carried out a transfer impact assessment in respect of these sub-processors and makes it available to Customer on reasonable written request.
Certain sub-processors may process limited data outside the EEA in the context of specific services, such as LLM inference via Anthropic PBC (United States) and embedding generation via OpenAI LLC (United States). For sub-processors outside the EEA, Builders applies the EU Standard Contractual Clauses or another transfer mechanism valid under the GDPR. The applicable transfer mechanism per sub-processor is stated in Section 11.
Builders does not transfer Customer Personal Data to any country outside the EEA without the prior written consent of Customer, except to the extent this is required under applicable law or covered by an approved transfer mechanism as described in this Section.
The liability of the Parties for damage arising from or in connection with this DPA is governed by and subject to the liability provisions of the Agreement, including any increased liability cap that applies to damage arising from a Personal Data Breach or another breach of this DPA. Nothing in this DPA limits the rights of a data subject or the powers of a supervisory authority under Data Protection Legislation.
This DPA is governed by the same law, and disputes are submitted to the same forum, as the Agreement of which it forms part. Where the Agreement makes no such choice, this DPA is governed exclusively by Dutch law and disputes are submitted exclusively to the competent court in Rotterdam.
Builders may update this DPA to reflect changes in the Service, in its sub-processors or in applicable law. Material changes are communicated to Customer in advance. Changes to the sub-processor list follow the notice and objection procedure in Section 10.
Each published version of this DPA carries a version number, shown at the top of this document, which identifies the text of that version. Where a signed Agreement incorporates this DPA by reference, the version applicable to that Agreement is the version in force at the time the Agreement is entered into, which the Agreement may identify by that version number, unless the Parties agree otherwise in writing or the Agreement states that the DPA applies as amended from time to time. Builders retains every published version and provides the applicable version on request.
For questions regarding data protection, requests under this DPA or the exercise of rights by data subjects:
Builders Studio B.V. Stationsplein 45, D3.118, 3013 AK Rotterdam, The Netherlands General: compliance@builders.studio Data Protection Officer: dpo@builders.studio
See also the VSI Privacy Policy and the VSI Terms of Service.