OneBee Data Processing Addendum
Version 2.0 · Effective date: August 10, 2026
This Data Processing Addendum (“DPA”) forms part of and is incorporated into the agreement between OneBee, Inc. (“OneBee”) and the customer entity that is a counterparty to that agreement (“Customer”) under which OneBee provides the Services (the “Agreement”). The Agreement may be the OneBee Master Services and Subscription Agreement, the OneBee Terms of Service, an Audit and Trial Services Agreement, an Order, or any other written agreement between the parties into which this DPA is incorporated.
Where this DPA conflicts with the Agreement on the subject of data protection, this DPA controls. In all other respects the Agreement remains in effect.
Contents
Data Processing Addendum
1. Definitions2. Roles and scope3. Processing of Customer Personal Data4. OneBee personnel5. Security6. Agent-specific controls7. Sub-processing8. Assistance9. Security Incident10. Return and deletion11. Audit12. International transfers13. Customer responsibilities and Restricted Data14. Liability15. US State Privacy Laws16. Term, incorporation, and precedence1. Definitions
Terms not defined here have the meaning given in the Agreement.
“Applicable Data Protection Laws” means the privacy and data protection laws applicable to OneBee's processing of Customer Personal Data under the Agreement, including US State Privacy Laws and, where applicable, European Data Protection Laws.
“Controller” means the party that determines the purposes and means of processing Personal Data, including a “business” under the CCPA.
“Customer Personal Data” means Personal Data within Customer Data that OneBee processes on Customer's behalf to provide the Services.
“European Data Protection Laws” means Regulation (EU) 2016/679 (“GDPR”), the UK GDPR and the UK Data Protection Act 2018, and the Swiss Federal Act on Data Protection, in each case as applicable.
“Personal Data,” “process,” “data subject,” and “sensitive data” have the meanings given in Applicable Data Protection Laws.
“Processor” means the party that processes Personal Data on behalf of a Controller, including a “service provider” under the CCPA.
“Restricted Transfer” means a transfer of Customer Personal Data from the European Economic Area, the United Kingdom, or Switzerland to a country not subject to an adequacy decision.
“SCCs” means the Standard Contractual Clauses annexed to European Commission Implementing Decision (EU) 2021/914.
“Security Incident” means a breach of OneBee's security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of, or access to, Customer Personal Data in OneBee's control. It does not include unsuccessful attempts or activity that does not compromise Customer Personal Data.
“Sub-processor” means a third party engaged by OneBee to process Customer Personal Data.
“UK Addendum” means the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner.
“Usage Data” means telemetry and metadata about the configuration, operation, and use of the Services, such as feature and connector usage, agent run counts and volumes, agent action metadata (which agent acted, in which connected system, what action it took, and when), performance and error rates, and active user counts. Usage Data does not include the content of Customer Data, and OneBee does not derive Usage Data from the content of Customer Personal Data.
“US State Privacy Laws” means the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act and its regulations (“CCPA”), together with the comprehensive consumer privacy laws of other US states as they apply to OneBee's processing under the Agreement.
2. Roles and scope
With respect to Customer Personal Data, Customer is the Controller (or a Processor acting on behalf of its own controller) and OneBee is the Processor (or sub-processor). Under US State Privacy Laws, OneBee is a service provider or processor, as those terms are defined.
Where Customer purchased the Services through a reseller, or has authorized a reseller to perform managed services using the Services, that reseller acts on Customer's instructions and not as OneBee's agent. OneBee is not responsible for the reseller's processing of Customer Personal Data outside the Services.
This DPA applies only to OneBee's processing of Customer Personal Data subject to Applicable Data Protection Laws. The details of the processing are set out in Annex 1.
3. Processing of Customer Personal Data
OneBee will process Customer Personal Data only on Customer's documented instructions, including as set out in the Agreement and this DPA, and as needed to provide and support the Services, unless required to act otherwise by law, in which case OneBee will inform Customer unless legally prohibited. Customer's configuration and use of the Services, including the agents, connections, tool permissions, and workflows Customer creates or authorizes, constitutes Customer's documented instructions.
OneBee will not sell or share Customer Personal Data, will not retain, use, or disclose it for any purpose other than providing the Services or as permitted by Applicable Data Protection Laws, will not retain, use, or disclose it outside the direct business relationship with Customer, and will not combine it with data from other sources except as permitted by Applicable Data Protection Laws.
No training. OneBee does not use Customer Personal Data to train machine-learning models, and OneBee's agreements with the model providers on its Sub-processor List prohibit those providers from using Customer Personal Data to train their models.
Zero retention by model providers. Where the Sub-processor List identifies a model provider as operating on a zero-retention basis, that provider processes inputs and outputs only for the duration of the request and does not retain Customer Personal Data afterwards. OneBee will update the Sub-processor List if the retention posture of a model provider changes.
Usage Data. OneBee may collect and use Usage Data to operate, secure, support, and improve the Services, and to produce aggregated statistics about use of the Services. Usage Data is not derived from the content of Customer Personal Data and is not used to train machine-learning models. Where Usage Data includes Personal Data, such as the identifier of an Authorized User associated with a session, OneBee processes that data as a controller in accordance with its Privacy Policy, and it is not Customer Personal Data under this DPA. Any aggregated statistics OneBee publishes or shares will not identify Customer, any Authorized User, or any individual.
OneBee will notify Customer if it determines it can no longer meet its obligations under Applicable Data Protection Laws.
4. OneBee personnel
OneBee will ensure that personnel authorized to process Customer Personal Data are bound by appropriate confidentiality obligations that survive the end of their engagement, have received data protection training appropriate to their role, and process Customer Personal Data only as necessary to provide the Services.
5. Security
OneBee will implement and maintain the technical and organizational measures set out in Annex 2, designed to protect Customer Personal Data against a Security Incident. OneBee may update these measures provided they do not materially reduce the overall level of protection.
6. Agent-specific controls
Because the Services execute actions within Customer's connected systems, the following controls apply in addition to Annex 2. Customer acknowledges that it configures and is responsible for these controls.
Scope of access. Each agent operates under a least-privilege tool allow-list that limits it to the specific systems and actions the task requires. OneBee will not expand an agent's access to a connected system beyond what Customer has authorized.
Credentials and scopes. OneBee accesses connected systems using credentials and authorization scopes Customer grants. OneBee will request the narrowest scopes reasonably necessary, will hold credentials and access tokens in an access-controlled vault, and will revoke stored credentials on Customer's request or on termination.
Approval gates. Customer may require human approval before an agent takes a designated category of action. Customer is responsible for determining which actions require approval and for configuring gates accordingly.
Action logging. OneBee logs agent actions, including tool calls, sub-agent calls, and inter-agent messages, to provide an attributable record of what was done, by which agent, in which system, and when. The record has two parts. The action metadata (which agent acted, in which connected system, what action it took, and when) is Usage Data, contains no Customer Data values, is retained for the term of the Agreement and one year after it ends as an audit record, and is available to Customer for export at any time during the term. The content of agent messages, tool inputs, and tool outputs is Customer Data, is retained for the term of the Agreement without truncation, and is deleted along with other Customer Personal Data in accordance with Section 10. Customer may request a shorter retention period for either part in writing, and OneBee will apply it prospectively.
Third-party platform terms. OneBee's use and transfer of data received from third-party platform APIs complies with the terms of those platforms, including the Google API Services User Data Policy and its Limited Use requirements. OneBee will not use data obtained through a restricted API scope for any purpose other than providing the Services to Customer.
7. Sub-processing
Customer generally authorizes OneBee to engage Sub-processors to provide the Services, including those set out in Annex 3 (the “Sub-processor List”). The Sub-processor List identifies each Sub-processor, the service it provides, its processing location, and any applicable retention, and separately identifies the model providers that process Customer Personal Data.
OneBee will ensure each Sub-processor is bound by data protection obligations substantially similar to those in this DPA, and remains responsible for its Sub-processors' acts and omissions to the same extent OneBee would be responsible for its own.
OneBee will notify Customer at least thirty (30) days before a new Sub-processor begins processing Customer Personal Data, by updating the Sub-processor List and by email to Customer's designated contact where Customer has subscribed to notifications. Customer may object on reasonable data protection grounds within that period. The parties will work in good faith to resolve the objection, which may include OneBee offering a configuration that avoids the objected-to Sub-processor. If the objection cannot be resolved, Customer may terminate the affected Services on written notice and receive a pro-rata refund of prepaid fees for the terminated portion, and this is Customer's sole remedy.
Annex 3 is maintained under this notice process. OneBee may update Annex 3 to add, remove, or change a Sub-processor without issuing a new version of this DPA. Annex 3 states the date it was last updated. This applies to Annex 3 only; every other provision of this DPA changes only by publication of a new version of this DPA.
8. Assistance
Data subject requests. Taking into account the nature of the processing, OneBee will provide Customer with reasonable assistance, by appropriate technical and organizational measures, to help Customer respond to requests from data subjects exercising their rights under Applicable Data Protection Laws. If OneBee receives such a request directly, it will, where permitted by law, advise the data subject to submit it to Customer and will not respond except on Customer's instructions or as required by law.
Impact assessments and consultation. Taking into account the nature of the processing and the information available to it, OneBee will provide Customer with reasonable assistance with data protection impact assessments and prior consultations with supervisory authorities relating to Customer's use of the Services, including by making available the information in this DPA, the Sub-processor List, and OneBee's then-current security documentation.
Cost. Assistance under this Section is included at no charge where it can be provided using OneBee's standard functionality and documentation. Where Customer requests assistance that requires materially more effort, OneBee may charge the Professional Services Rate as defined in the MSA, or the rate stated on the applicable Order Form, on prior notice to Customer.
9. Security Incident
OneBee will notify Customer without undue delay, and in any event within seventy-two (72) hours, after confirming a Security Incident affecting Customer Personal Data. The notice will describe, to the extent known and as it becomes available, the nature of the incident, the categories and approximate volume of Customer Personal Data affected, the likely consequences, and the measures taken or proposed.
OneBee will provide information reasonably available to it to help Customer meet its own notification obligations, and will take reasonable steps to investigate, contain, and mitigate the incident. OneBee's notification is not an acknowledgment of fault or liability. Customer is responsible for any notifications it is required to make to authorities, data subjects, or others, and OneBee will not make any notification identifying Customer without Customer's prior written consent unless required by law.
10. Return and deletion
On expiration or termination of the Services, OneBee will, at Customer's written election made within thirty (30) days, return or delete Customer Personal Data in its possession, and will delete remaining copies within thirty (30) days of that election, except where retention is required by law or where copies are held in routine backups that cycle out on OneBee's standard schedule described in Annex 2. Retained data remains subject to this DPA and will not be actively processed. OneBee will certify deletion in writing on Customer's request.
11. Audit
OneBee will make available to Customer information reasonably necessary to demonstrate compliance with this DPA, including its then-current security documentation and, where available, a current SOC 2, ISO, or comparable third-party report. Where the relevant controls are covered by such a report, Customer agrees to accept it in lieu of an on-site audit.
Where a report is not available or does not address a specific control, Customer may audit OneBee's compliance, at Customer's expense, on at least thirty (30) days' prior written notice, no more than once in any twelve-month period except where required by a supervisory authority or following a Security Incident affecting Customer Personal Data. Any audit will be conducted during business hours, will be subject to the confidentiality obligations in the Agreement, will not unreasonably disrupt OneBee's operations or compromise the security or confidentiality of other customers' data, and will not be conducted by a competitor of Onebee.
12. International transfers
This Section applies only where OneBee's processing of Customer Personal Data involves a Restricted Transfer.
European Economic Area. The SCCs are incorporated into this DPA and apply to Restricted Transfers from the EEA, as follows. Where Customer is a controller, Module Two (controller to processor) applies. Where Customer is a processor acting on behalf of its own controller, Module Three (processor to processor) applies. For the purposes of the SCCs: Customer is the data exporter and OneBee is the data importer; the optional docking clause in Clause 7 applies; Clause 9 Option 2 (general written authorization) applies with the notice period in Section 7 of this DPA; the optional language in Clause 11(a) does not apply; Clause 17 is governed by the law of Ireland; Clause 18(b) designates the courts of Ireland; Annex I to the SCCs is populated by Annex 1 to this DPA; Annex II to the SCCs is populated by Annex 2 to this DPA; and Annex III, where required, is populated by the Sub-processor List.
United Kingdom. The UK Addendum is incorporated and applies to Restricted Transfers from the United Kingdom, with the SCCs as the approved addendum. For Table 4 of the UK Addendum, neither party may end the UK Addendum as set out in Section 19 of it.
Switzerland. The SCCs apply to Restricted Transfers from Switzerland, with references to the GDPR read as references to the Swiss Federal Act on Data Protection, references to supervisory authorities read as including the Swiss Federal Data Protection and Information Commissioner, and the term “member state” read so as not to prevent data subjects in Switzerland from exercising their rights in their place of habitual residence.
Alternative mechanisms. If OneBee adopts an alternative lawful transfer mechanism, that mechanism will apply instead of the above to the extent it covers the Restricted Transfer, and OneBee will notify Customer.
Where this Section conflicts with any other part of this DPA or the Agreement, this Section controls with respect to the Restricted Transfer.
13. Customer responsibilities and Restricted Data
Customer is responsible for the accuracy and legality of Customer Personal Data, for having a valid legal basis to provide it to OneBee and to authorize the processing Customer configures, and for providing all notices and obtaining all consents required for OneBee to process it. Customer's instructions will not cause OneBee to violate Applicable Data Protection Laws.
Restricted Data. The Services are not designed to hold or control the following (“Restricted Data”): Social Security numbers, taxpayer identification numbers, driver's license numbers, passport numbers, and other government-issued identifiers; protected health information as defined under HIPAA and other individually identifiable health or medical information; payment card numbers, financial account numbers, and credentials permitting access to a financial account; biometric identifiers and biometric information; account passwords; personal data of individuals known to be under 16; special categories of personal data as defined in the GDPR; and data relating to criminal convictions or offenses.
Unless otherwise agreed in writing, Customer will not intentionally submit Restricted Data to the Services and will not configure agents to seek out, retrieve, or process Restricted Data. Customer acknowledges that Restricted Data may appear incidentally within connected systems, and OneBee's obligations under this DPA apply to that data. Customer will not rely on the Services as a system of record for, or as a control over, Restricted Data. OneBee is not a HIPAA business associate and the Services are not designed to process cardholder data subject to PCI DSS.
Indemnity. Customer will defend and indemnify OneBee against third-party claims, including regulatory proceedings, arising from Customer's breach of this Section, in accordance with the indemnification procedures in the Agreement.
14. Liability
Each party's liability under this DPA is subject to the exclusions and limitations of liability in the Agreement. Claims under this DPA and under the Agreement are subject to a single aggregate cap and do not create separate or cumulative limits. Nothing in this DPA limits any liability that cannot be limited under Applicable Data Protection Laws, or either party's obligations to data subjects under Clause 12 of the SCCs where they apply.
15. US State Privacy Laws
OneBee is a service provider or processor with respect to Customer Personal Data processed under the Agreement. OneBee certifies that it understands and will comply with the restrictions in Section 3, including that it will not sell or share Customer Personal Data, will not retain, use, or disclose it outside the direct business relationship with Customer, and will not use it for any purpose other than the business purposes specified in the Agreement.
Customer may take reasonable and appropriate steps under Section 11 to confirm that OneBee's use of Customer Personal Data is consistent with Customer's obligations under US State Privacy Laws, and may, on notice, take reasonable steps to stop and remediate any unauthorized use. OneBee will make available to Customer information necessary to demonstrate compliance as required by those laws.
16. Term, incorporation, and precedence
This DPA is incorporated into and forms part of the Agreement from its effective date and continues for as long as OneBee processes Customer Personal Data. Sections 3, 10, 13, 14, and 15 survive termination. In the event of conflict between this DPA and the Agreement regarding data protection, this DPA controls.
Notices under this DPA may be sent to [email protected].
Annex 1: Processing details
A. Parties
Data exporter / Controller (or Processor): Customer, as identified in the Agreement. Contact as identified in the Agreement or Customer's account.
Data importer / Processor: OneBee, Inc., 14 Altamont Ave, Melrose, MA 02176, United States. Data protection contact: [email protected].
B. Description of processing
Subject matter. OneBee's provision of the Services under the Agreement, including running the AI agents and workflows Customer configures.
Duration. The term of the Agreement, plus the return-or-deletion period in Section 10.
Nature and purpose of processing. Hosting, storing, and transmitting Customer Personal Data, and processing it to execute the agent actions and workflows Customer configures and authorizes within Customer's connected systems.
Categories of data subjects. Data subjects whose data Customer connects to or submits through the Services, which may include Customer's employees, contractors, customers, prospects, suppliers, and other individuals whose records appear in Customer's connected systems.
Categories of Customer Personal Data. Identification and contact details such as name, email address, role, and company, business communications and records, and other business-record data Customer chooses to connect or submit. Restricted Data as defined in Section 13 must not be submitted.
Sensitive data. None. Special-category data is Restricted Data and must not be submitted to the Services. Where such data appears incidentally in connected systems, the measures in Annex 2 apply.
Frequency of transfer. Continuous, as initiated by Customer's use of the Services.
Retention. As set out in Annex 2 and Section 10.
Sub-processors. As set out in Annex 3, together with the subject matter, nature, and duration of their processing.
C. Competent supervisory authority
Where the SCCs apply, the supervisory authority of the EEA member state in which the data exporter is established, or, where the exporter is not established in the EEA, the supervisory authority of the member state in which the exporter's representative is established or in which the relevant data subjects are located.
Annex 2: Security measures
OneBee implements and maintains the following technical and organizational measures, which it may update provided the overall level of protection is not materially reduced.
Hosting and isolation. The Services run on Google Cloud Platform, with tenant-isolated infrastructure and no cross-customer data access. Primary processing location is the United States.
Encryption. Customer Personal Data is encrypted in transit using TLS 1.2 or higher and at rest using AES-256. Encryption keys are managed within Google Cloud.
Access control. Role-based access control and least-privilege tool allow-lists scope each agent to only the specific actions and systems a task requires. Access to production systems is restricted to personnel who need it, is logged, and is reviewed periodically. Multi-factor authentication is required for administrative access.
Secrets management. Secrets, credentials, and access tokens are held in a dedicated, access-controlled vault, not in application code or configuration. Tokens are revoked on Customer request or on termination.
Human-in-the-loop controls. Approval gates can be required on agent actions, allowing Customer to determine what an agent may do autonomously and what requires human approval.
Audit logging. Agent actions, including tool calls, sub-agent calls, and inter-agent messages, are logged to provide an attributable, auditable record. Action metadata is retained for the term of the Agreement and one year after it ends and is available to Customer for export at any time during the term. The content of agent messages and tool calls is Customer Data and is retained for the term of the Agreement, as described in Section 6.
Use limitation. Customer Personal Data is not used to train machine-learning models and is not used or disclosed for any purpose beyond providing the Services.
Retention and deletion. Application, container, and load balancer logs are retained for 90 days. Security and cloud audit logs are retained for up to 13 months. Both are distinct from the agent action records described above and are held as Usage Data under OneBee's Privacy Policy. Database backups are retained for 14 days with 7-day point-in-time recovery, after which older copies are purged. Customer Personal Data, including the content of agent messages and tool calls, is deleted within 30 days of Customer's election as described in Section 10. Agent action metadata is retained for one year after the Agreement ends and then deleted.
Resilience and operations. Change management, configuration monitoring, vulnerability management, incident response, and business continuity procedures appropriate to the Services.
Personnel. Background checks where permitted by law, confidentiality obligations, and data protection and security training appropriate to role.
Annex 3: Sub-processors
This Annex is the Sub-processor List. It is maintained under the notice process in Section 7 and may be updated without a new version of this DPA.
Last updated: September 18, 2026.
A. Model providers
These Sub-processors process Customer Personal Data as model providers. Zero retention has the meaning given in Section 3.
| Sub-processor | Service | Processing location | Retention | Zero retention |
|---|---|---|---|---|
| Microsoft Azure | Frontier models; no training on Customer Personal Data | United States | Up to 30 days for abuse monitoring, debugging, and service reliability; purged within 48 hours of deletion | No |
| Anthropic | Frontier models; no training on Customer Personal Data | United States | Zero-data-retention agreement in place | Yes |
| OpenAI | Frontier models; no training on Customer Personal Data | United States | Zero-data-retention agreement in place | Yes |
| xAI | Frontier models; no training on Customer Personal Data | United States | Zero-data-retention agreement in place | Yes |
| Baseten | Open-weight model inference on shared serverless infrastructure | Global | Inputs and outputs not stored by default | Yes |
| Fireworks AI | Open-weight model inference on shared serverless infrastructure, directly and through Microsoft Azure AI Foundry | Global | Inputs and outputs not stored by default | Yes |
B. Other Sub-processors
| Sub-processor | Service | Processing location | Retention |
|---|---|---|---|
| Google Cloud Platform | Hosting and infrastructure; the Services, agents, and Customer Personal Data run here | United States (us-central1; logs in the US multi-region) | Retained for the subscription term and deleted under Section 10; backups 14 days, logs 30 days |
| Cloudflare | Edge network, DDoS protection, and web application firewall; hosting for desktop client release artifacts | Global edge network | Customer Personal Data in transit only; not stored |
| Brave Search | Independent web search; no training on queries | Global | 90-day retention |
| Resend | Transactional email delivery | United States | Retained for the subscription term; deleted within 90 days of account termination |
OneBee's agreements with its Sub-processors prohibit the use of Customer Personal Data to train their models.