VSI

Data Processing Agreement

Builders Studio B.V. · Version 1.1 · Last updated: 21 September 2026

Builders Studio B.V. Version 1.1 · Last updated: 21 September 2026

This Data Processing Agreement (the "DPA") applies where Builders Studio B.V., registered in the Netherlands, with its registered office at Stationsplein 45, D3.118, 3013 AK Rotterdam, registered with the Dutch Chamber of Commerce under number 62682466 ("Builders", "we", "us"), processes personal data on behalf of a customer in the performance of the VSI (Venture Studio Intelligence) platform (the "Service").

How this DPA applies

This DPA has no independent existence: it always forms an integral part of a contract between Builders and the Customer (the "Agreement"), and applies only for as long as that Agreement is in force. The Agreement is:

  1. the signed subscription, program or other written agreement between Builders and Customer that incorporates this DPA, whether by attaching it or by referring to it; or
  2. where no such signed agreement exists, the VSI Terms of Service, which incorporate this DPA.

Where a signed Agreement incorporates this DPA, this DPA becomes an integral part of that Agreement and is read together with it. It does not replace, override or reopen anything the Parties negotiated in that Agreement: the commercial, liability, term, governing-law and other provisions of the signed Agreement continue to apply in full, and this DPA supplies only the data protection terms required by article 28 GDPR.

Order of precedence, in descending order:

  1. a data processing agreement attached to or negotiated within the signed Agreement, and any data protection provision expressly agreed in that Agreement, prevails over this DPA;
  2. failing that, this DPA prevails over the signed Agreement and over the Terms of Service on matters of data protection only;
  3. on all other matters, the Agreement prevails over this DPA.

Where this DPA refers to a provision of the Agreement (such as liability or governing law) and the applicable Agreement contains no such provision, the corresponding provision of the Terms of Service applies.

1. Definitions

  • "Controller": the Customer, who determines the purposes and means of the processing of personal data.
  • "Processor": Builders Studio B.V., who processes personal data on behalf of the Controller.
  • "Customer": the organisation that holds the subscription or program participation under which the Service is accessed.
  • "Customer Personal Data": personal data that Builders processes on behalf of Customer under or in connection with the Agreement.
  • "Data Protection Legislation": the General Data Protection Regulation (Regulation (EU) 2016/679, GDPR) and applicable national implementing legislation, as supplemented or replaced from time to time.
  • "Personal Data Breach": a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data.
  • "Sub-processor": any third party engaged by Builders to process Customer Personal Data in connection with the Service.
  • "Authorized User": any person granted access to the Service by Customer or by Builders.
  • "EEA": the European Economic Area.

2. Documented instructions

Builders processes personal data solely on the documented instructions of Customer, including the instructions arising from this DPA and from the use of the Service by Customer and its Authorized Users. The Agreement, together with written instructions provided by Customer, constitutes Customer's documented instruction for the purposes of this DPA. If a statutory obligation requires Builders to disclose personal data, Builders informs Customer in advance, unless that law prohibits such information.

3. Scope and purpose

Builders processes Customer Personal Data solely for the delivery and maintenance of the Service as described in the Agreement. Builders does not process Customer Personal Data for any other purpose, including but not limited to training or improving foundation models, benchmarking, or developing products or features for other customers, unless Customer expressly consents in advance and in writing.

4. Nature of the processing

The processing activities of Builders comprise: hosting and processing of conversations, signals, artifacts, reflections and memory inputs within the Service; intake and storage of uploaded documents and files; transcription and analysis of conversation content supplied by Customer; synthesis of reflections and portfolio-level insights; and associated operational support.

5. Categories of data and data subjects

Categories of personal data that Builders may process: identification and contact details of Authorized Users (name, e-mail, organisation, role); content of conversations and notes that Customer or its Authorized Users submit to the Service or have processed; uploaded documents and files and the personal data contained therein; telephone conversations if supplied by Customer; and usage statistics and logging.

Categories of data subjects include Authorized Users of Customer, external conversation partners of Customer whose content is processed in the Service, and persons named in documents supplied by Customer. Customer does not supply special categories of personal data within the meaning of article 9 GDPR to the Service, unless the Parties make additional written arrangements in advance.

6. Duration

Builders processes Customer Personal Data for the duration of the Agreement, unless an applicable statutory retention obligation prescribes a longer retention period.

7. Processor personnel

Builders ensures that persons processing personal data are subject to a duty of confidentiality. Access to Customer Personal Data is strictly limited to personnel who need that access for the delivery of the Service. Builders takes reasonable measures to ensure the reliability of every employee, contractor or sub-processor with access to Customer Personal Data.

8. Security

Builders takes appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with article 32 GDPR. These measures include:

  • Encryption of data in transit (TLS 1.2+) and at rest, enabled by default on all data storage layers
  • Application and API hosting on Vercel, Frankfurt region (eu-central-1)
  • Managed PostgreSQL database on Supabase, Frankfurt region
  • File storage on AWS S3 in eu-central-1
  • Speech-to-text transcription in the European Union region
  • Role-based access control with multi-factor authentication for administrative access to production systems
  • Logical separation between customer workspaces at database and application level
  • Logging of access to production systems and periodic review
  • Periodic backups and a documented recovery process
  • Least-privilege access controls on all internal systems, and automated dependency scanning prior to deployment

In determining the appropriate level of security, Builders takes account of the risks presented by the processing, including the risks of accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data. Security measures are reviewed and updated periodically as the platform develops and threats change. A revision does not materially reduce the level of security compared to the level at the start of the Agreement.

9. Hosting and AI processing

The Service runs in the Frankfurt region (eu-central-1): application and API hosting on Vercel, a managed PostgreSQL database on Supabase and file storage on AWS S3, all in Frankfurt, Germany. Customer Data is stored and processed within the EEA, in line with EU data residency requirements and the GDPR.

Builders deploys third-party Large Language Models (Anthropic Claude and Google Gemini) to deliver intelligence functions, including conversation analysis, signal extraction, artifact generation and reflection synthesis. Builders selects API configurations that exclude training of foundation models on Customer Data where the provider offers that option. Processing by LLM providers is short-lived inference: no long-term data retention takes place at the provider under the enterprise or API terms we use. All transmission to LLM providers takes place over HTTPS.

10. Sub-processing

Customer grants general authorisation for the engagement of the sub-processors listed in Section 11, which serves as the current reference for the Parties.

Builders announces intended additions or replacements of sub-processors at least thirty (30) days in advance. Customer has the right within that period to object in writing and with reasons on reasonable data protection grounds. The Parties will negotiate in good faith on a solution. If the Parties do not reach a reasonable solution, either Party has the right to terminate the affected part of the Service without compensation as of the date on which the new sub-processor would be engaged.

Builders binds sub-processors by written agreement to at least the obligations resting on Builders under this DPA, including those regarding security and data protection. Builders remains fully liable to Customer for the performance by each sub-processor of its obligations, in accordance with article 28(4) GDPR. The contractual limitations of liability in the Agreement continue to apply to this liability of Builders.

11. Sub-processors

A sub-processor is classified as Critical if permanent unavailability would prevent Builders from delivering the core functionality of the Service, and no functionally equivalent replacement can be deployed within sixty (60) days. All other sub-processors are Non-critical and can be replaced within sixty (60) days without materially affecting the core functionality of the Service.

Sub-processorLocationPurposeClassificationTransfer mechanism
Vercel Inc.US (hosting in Frankfurt, DE)Application and API hostingCriticalEU Standard Contractual Clauses
Supabase Inc.US (database in Frankfurt, DE)Managed PostgreSQL databaseCriticalEU Standard Contractual Clauses
Amazon Web Services EMEA SARLLuxembourg (storage in Frankfurt, DE)S3 object storage for uploaded files and artifactsCriticalWithin EEA
Assembly AI Inc.US (processing in the EU region)Speech-to-text transcription of call recordingsNon-criticalEU Standard Contractual Clauses
Anthropic PBCUSLLM inference (Claude), short-lived, no long-term retentionNon-criticalEU Standard Contractual Clauses
Google Cloud EMEA LimitedIrelandLLM inference (Gemini), short-lived, no long-term retentionNon-criticalWithin EEA
OpenAI LLCUSEmbedding generation for search and signal matchingNon-criticalEU Standard Contractual Clauses
Cohere Inc.CanadaSearch result rerankingNon-criticalAdequacy decision (Canada)

12. Data subject rights

Builders provides Customer with reasonable technical and organisational assistance to enable Customer to comply with data subject requests, including requests for access, rectification, erasure, restriction, data portability and objection under applicable Data Protection Legislation. Any additional costs of exceptional or excessive assistance may be reasonably charged by Builders to Customer, following prior consultation.

If a data subject approaches Builders directly with a request to exercise his or her rights under the GDPR in respect of Customer Personal Data, Builders forwards that request to Customer without delay and does not handle the request independently, unless Customer instructs otherwise or the law requires otherwise.

13. Personal Data Breach

Builders informs Customer without undue delay, and in any event within forty-eight (48) hours of discovery, of a personal data breach within the meaning of the GDPR. The notification contains at least the information referred to in article 33(3) GDPR, to the extent available: a description of the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences of the breach, and the measures taken or proposed.

Builders cooperates with Customer and takes reasonable steps to support Customer in the investigation, mitigation and remediation of a Personal Data Breach, including reasonable support in respect of Customer's own notification obligation to the supervisory authority and, where applicable, to data subjects.

14. Data protection impact assessments

Builders provides Customer with reasonable assistance in data protection impact assessments (DPIAs) carried out by Customer and in prior consultations with supervisory authorities, to the extent Customer reasonably considers these necessary under article 35 or article 36 GDPR and they relate to the processing of Customer Personal Data by Builders.

15. Deletion and return of personal data

On termination or expiry of the Agreement, Builders makes Customer Data available for export in a common machine-readable format for a period of thirty (30) days after the termination or expiry date (the "export window"). Within the export window Customer indicates in writing whether Builders should return or delete the personal data. Builders deletes or returns the personal data, at Customer's option, within thirty (30) days after the end of the export window. This obligation applies to all copies of Customer Personal Data processed by Builders and its sub-processors, except to the extent a statutory retention obligation applies. If Customer does not indicate a choice within the export window, Builders deletes the personal data after expiry of the periods set out in this paragraph.

Builders is not obliged to delete Customer Personal Data to the extent a statutory retention obligation applies. In that case Builders informs Customer and the obligations of security and confidentiality under this DPA continue to apply for as long as the data is retained.

16. Audit rights

Builders makes available to Customer, on reasonable written request, all information necessary to demonstrate compliance with this DPA and with article 28 GDPR.

Customer has the right to carry out or have carried out an audit, including inspections, of Builders' compliance with this DPA at most once per calendar year. The costs of the audit are borne by Customer, except where the audit reveals a material non-compliance by Builders. Audits are subject to the following conditions:

  1. Customer gives reasonable written notice of at least thirty (30) days;
  2. the audit takes place within office hours and is conducted in a manner that respects the business interests of Builders and the confidentiality of other Builders customers;
  3. if an audit reveals a serious shortcoming, Builders is given a reasonable period for remediation before Customer takes further steps.

To the extent Builders has obtained relevant third party certifications or independent security assessments, Builders may satisfy audit requests by making the relevant reports or certifications available for inspection, to the extent these cover the scope of Customer's audit request.

17. International transfers

Builders stores and processes all Customer Personal Data on infrastructure physically located within Germany and the EEA, namely Vercel (Frankfurt), Supabase (Frankfurt) and AWS (Frankfurt). Speech-to-text transcription is performed in the European Union region. Customer Personal Data is not stored outside the EEA as part of Builders' core hosting and database operations.

Builders acknowledges that Vercel Inc., Supabase Inc. and Assembly AI Inc. are incorporated in the United States and that any access to Customer Personal Data by these entities or their US parent companies qualifies as a transfer outside the EEA within the meaning of Chapter V GDPR. For these sub-processors Builders applies the EU Standard Contractual Clauses, supplemented with appropriate technical and organisational measures, including encryption in transit and at rest and restriction of access rights. Builders has carried out a transfer impact assessment in respect of these sub-processors and makes it available to Customer on reasonable written request.

Certain sub-processors may process limited data outside the EEA in the context of specific services, such as LLM inference via Anthropic PBC (United States) and embedding generation via OpenAI LLC (United States). For sub-processors outside the EEA, Builders applies the EU Standard Contractual Clauses or another transfer mechanism valid under the GDPR. The applicable transfer mechanism per sub-processor is stated in Section 11.

Builders does not transfer Customer Personal Data to any country outside the EEA without the prior written consent of Customer, except to the extent this is required under applicable law or covered by an approved transfer mechanism as described in this Section.

18. Liability

The liability of the Parties for damage arising from or in connection with this DPA is governed by and subject to the liability provisions of the Agreement, including any increased liability cap that applies to damage arising from a Personal Data Breach or another breach of this DPA. Nothing in this DPA limits the rights of a data subject or the powers of a supervisory authority under Data Protection Legislation.

19. Governing law

This DPA is governed by the same law, and disputes are submitted to the same forum, as the Agreement of which it forms part. Where the Agreement makes no such choice, this DPA is governed exclusively by Dutch law and disputes are submitted exclusively to the competent court in Rotterdam.

20. Changes to this DPA

Builders may update this DPA to reflect changes in the Service, in its sub-processors or in applicable law. Material changes are communicated to Customer in advance. Changes to the sub-processor list follow the notice and objection procedure in Section 10.

Each published version of this DPA carries a version number, shown at the top of this document, which identifies the text of that version. Where a signed Agreement incorporates this DPA by reference, the version applicable to that Agreement is the version in force at the time the Agreement is entered into, which the Agreement may identify by that version number, unless the Parties agree otherwise in writing or the Agreement states that the DPA applies as amended from time to time. Builders retains every published version and provides the applicable version on request.

21. Contact

For questions regarding data protection, requests under this DPA or the exercise of rights by data subjects:

Builders Studio B.V. Stationsplein 45, D3.118, 3013 AK Rotterdam, The Netherlands General: compliance@builders.studio Data Protection Officer: dpo@builders.studio

See also the VSI Privacy Policy and the VSI Terms of Service.

Terms of Service·Privacy Policy·Data Processing Agreement·Sign in