DPA


Data Processing Addendum

How bear.ai processes data for business customers and dataset licensees — roles, security, sub-processors, and transfers.


Last updated · August 10, 2026

Overview

This page is a pre-contract overview, not an executed Data Processing Addendum and not a promise that a particular data-protection role or transfer mechanism applies. Commercial dataset delivery is disabled. Any future business customer must sign transaction-specific terms, including a DPA where legally required, before receiving data.

For how bear.ai handles personal information of RUB players, see our Privacy Policy.

Roles and scope

bear.ai removes direct identifiers and applies de-identification controls before packaging eligible dataset rows, but free text may retain linkable context and is not represented as anonymous. The parties' controller, business, contractor, or processor roles depend on the actual transaction and must be stated in the signed agreement; this page does not assign them in advance.

Security measures

  • TLS encryption in transit and provider-managed encryption at rest for applicable production data stores.
  • Least-privilege, role-based access with audit logging.
  • Dataset packaging reads only scrubbed message copies, never raw bodies; one flagged message excludes its whole conversation.
  • Secrets encrypted and rotated; no secrets in source control.
  • Documented incident response, with breach notification as required by law.

Sub-processors

bear.ai uses a vetted set of sub-processors to deliver the service. The current public list is at beardata.co/legal/subprocessors; the signed DPA provides a change-notice and objection mechanism where required.

International transfers

The initial consumer release and any dataset program are limited to the approved United States scope; bear.ai does not currently sell datasets containing EEA or UK conversations. Before an international transfer, the parties must identify and execute the legally required transfer mechanism, such as Standard Contractual Clauses where applicable. This page does not claim that such paperwork is already in place.

Requesting the DPA

To discuss transaction-specific terms, a security review, or our sub-processor list, contact hello@beardata.co. No data is delivered until the commercial release gates, diligence, and signatures are complete.