Data Processing Addendum
This Data Processing Addendum (DPA) is entered into between the Customer and Innovation Bee P.C., registered as INNOVATION BEE ΙΔΙΩΤΙΚΗ ΚΕΦΑΛΑΙΟΥΧΙΚΗ ΕΤΑΙΡΕΙΑ, with registered office at Palaeokastro 0, 50300 Voio, Kozani, Greece, G.E.MI. 164094236000, VAT EL801827709 (Processor). It is incorporated into the Terms of Serviceor other agreement governing Customer’s use of FundyBee (Agreement) and is binding when Processor processes Customer Personal Data on Customer’s behalf.
For a Customer whose commercial agreement predates this version, this DPA must be separately executed or otherwise validly incorporated before Innovation Bee P.C.begins or continues processing Customer Personal Data on that Customer’s behalf. The later transition date for updated commercial Terms does not postpone the GDPR Article 28 requirement. Until the required agreement and provider evidence are in place, the affected Customer Personal Data processing must remain paused.
Contents
- 1. Definitions and precedence
- 2. Roles and instructions
- 3. Processor duties
- 4. Confidentiality
- 5. Security
- 6. Subprocessors
- 7. Restricted transfers
- 8. Rights requests and compliance assistance
- 9. Personal-data breaches
- 10. Information and audits
- 11. Return and deletion
- 12. Term and liability
- Annex A. Processing details
- Annex B. Technical and organisational measures
- Annex C. Authorised subprocessors
1. Definitions and precedence
Customer Personal Datameans personal data contained in Customer Content that Processor handles on Customer’s behalf. Data Protection Lawmeans the GDPR and applicable EEA or Member State data-protection law. The terms controller, processor, data subject, personal data, processing, personal-data breach and supervisory authority have the meanings in the GDPR.
If this DPA conflicts with the Agreement on protection of Customer Personal Data, this DPA prevails. If applicable Standard Contractual Clauses conflict with this DPA, those Clauses prevail. The main Agreement continues to govern commercial matters.
2. Roles and instructions
Customer is a controller or processor, as applicable, and Innovation Bee P.C.acts as Customer’s processor or subprocessor for Customer Personal Data. Each party will comply with the obligations Data Protection Law assigns to it. Where Customer is a processor, Customer confirms that the relevant controller has authorised Customer’s instructions and the engagement of Processor and its subprocessors. Customer or the relevant controller determines the purposes and essential means of processing and is responsible for lawful collection, notices, legal bases, data accuracy, user permissions and its instructions.
The Agreement, Customer’s authorised configuration and use of the Service, support requests and written instructions from an authorised Customer contact are documented instructions. Processor will process Customer Personal Data only on those instructions, including for transfers, unless EU or Member State law requires otherwise. Where legally permitted, Processor will tell Customer before legally required processing.
Processor will promptly inform Customer if, in its opinion, an instruction infringes Data Protection Law and may pause the affected processing while the parties clarify it. Processor is an independent controller for the processing described as its own in the Privacy Notice, including account security, billing and legal compliance.
3. Processor duties
Processor will:
- process Customer Personal Data only to provide, secure, maintain and support the Service under documented instructions;
- ensure persons authorised to process it are limited to those who need access and are subject to confidentiality duties;
- maintain the measures in Annex B and review them as technology and risk change;
- not sell Customer Personal Data or use it for third-party advertising;
- not use Customer Personal Data to train or improve any shared or general-purpose model; customer-specific training is permitted only on documented written instructions and with all required safeguards;
- maintain records and make information available as required by Articles 28 and 30 GDPR.
4. Confidentiality
Processor will ensure that employees and contractors with access to Customer Personal Data are bound by contractual or statutory confidentiality, receive access appropriate to their role and receive data-protection and security guidance. Confidentiality obligations survive the end of access and the Agreement.
5. Security
Taking account of the state of the art, implementation cost, processing nature/scope/context and risks to people, Processor will maintain appropriate technical and organisational measures under Article 32 GDPR. Current measures are in Annex B. Customer is responsible for configuring roles and sharing controls, protecting its endpoints and credentials, and avoiding unnecessary or unlawfully collected personal data.
Processor may update measures without materially reducing overall protection. No security measure makes a service risk-free.
6. Subprocessors
Customer gives general written authorisation for the subprocessors in Annex C. Processor remains responsible for each subprocessor’s data-protection obligations to the extent required by Article 28 GDPR and will impose written obligations providing substantially the same protection as this DPA for the relevant processing.
For a new subprocessor that will handle Customer Personal Data, Processor will update Annex C and give affected Customers reasonable advance notice by email or in-app notice—normally at least 15 days where practicable. Customer may object during the stated notice period on reasonable, documented data-protection grounds. The parties will seek a reasonable alternative. If none is reasonably available, Customer may stop using the affected feature or terminate it and receive any mandatory refund for prepaid, unused service.
Emergency substitutions needed to protect security or restore availability may take effect sooner; Processor will notify Customer without undue delay. No optional provider receives Customer Personal Data unless the related integration is enabled.
7. Restricted transfers
Processor will not transfer Customer Personal Data outside the EEA to a non-adequate country without a lawful GDPR Chapter V mechanism. Where required, Processor will use the applicable module of the European Commission Standard Contractual Clauses (Decision (EU) 2021/914), the transfer provisions in an authorised provider’s DPA, and supplementary measures supported by the transfer assessment. Processor will provide information about the relevant mechanism and an available copy on request, subject to protection of confidential terms.
8. Rights requests and compliance assistance
Taking account of the nature of processing, Processor will provide reasonable technical and organisational assistance for Customer to respond to data-subject requests. If Processor receives a request relating solely to Customer Personal Data, it will not respond on Customer’s behalf unless authorised or legally required; it will direct the request to Customer where feasible.
Processor will provide reasonable information and assistance for Customer’s security, breach-notification, data-protection impact assessment and prior-consultation duties, taking account of information available to Processor. Customer remains responsible for deciding whether a notification, DPIA or consultation is required.
9. Personal-data breaches
Processor will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data. As information becomes available, notice will describe the nature of the breach, affected data/data-subject categories and approximate numbers where known, likely consequences, measures taken or proposed, and a contact point. Processor will investigate, mitigate and reasonably cooperate. Notification is not an admission of fault. Customer controls notices to authorities and data subjects unless law requires Processor to notify directly.
10. Information and audits
Processor will make available information reasonably necessary to demonstrate compliance, including relevant policies, provider documentation, security summaries and responses to a reasonable questionnaire. If that is insufficient, Customer may request an audit by an independent qualified auditor bound by confidentiality, normally once in a 12-month period, on at least 30 days’ notice, during business hours and without exposing another customer’s data or creating a security risk. More frequent or urgent review is allowed after a material incident, supervisory-authority request or credible evidence of breach. Customer bears reasonable audit cost unless material non-compliance is found.
11. Return and deletion
During the term, Customer can use available export and deletion controls subject to role and security restrictions, or send a documented request to info@innovationbee.gr. On termination or Customer instruction, Processor will promptly initiate deletion or return of Customer Personal Data and delete remaining copies, unless Union or Member-State law requires storage. Deletion from live systems does not require immediate overwrite of protected backups; retained backup copies remain isolated, are not restored to ordinary use, and expire under the applicable provider lifecycle. Transient commercial-model copies are protected from ordinary use and expire under the disclosed provider lifecycle, normally no later than 30 days for the authorised Anthropic API route unless a stated exception applies. Controller-side billing/compliance records are outside Customer Personal Data. Processor retains Customer Personal Data after termination only where Union or Member-State law requires storage, and will isolate and protect it and process it only for that legal purpose.
12. Term and liability
This DPA starts with the Agreement or first processing of Customer Personal Data, whichever is earlier, and continues until Processor no longer processes it. Liability is governed by the Agreement, but no contractual limitation applies where prohibited by Data Protection Law. Sections that must survive to protect retained data continue after termination.
Annex A. Processing details
| Subject matter | Provision, security, support and maintenance of the FundyBee AI-assisted proposal workspace. |
|---|---|
| Duration | The Agreement term plus the deletion/return period and any lawful retention described above. |
| Nature and purpose | Collection, recording, organisation, storage, retrieval, consultation, transmission to authorised AI/providers, generation, extraction, collaboration, signing, export, restriction and deletion as instructed through Service features. |
| Frequency | Continuous or as initiated by authorised users during the Agreement. |
| Data subjects | Customer users, invited collaborators, consortium/partner representatives, professional contacts, signers, proposal participants or beneficiaries described by Customer, and other people whose data Customer lawfully includes. |
| Personal-data categories | Identity/contact and professional data; account/team identifiers; proposal, partner, chat and research content; files and signatures; collaboration/activity data; technical/security metadata. Payment-card numbers are handled by Stripe rather than FundyBee. |
| Special categories | None required or intentionally requested. Customer must not submit special-category or criminal-conviction data unless separately lawful, strictly necessary, safeguarded and agreed in writing where required. |
| Customer instructions | The Agreement, authorised configuration/use, support requests and additional lawful written instructions accepted under this DPA. |
Annex B. Technical and organisational measures
- Access control: individual authentication, workspace roles, least-privilege administrative access and server-only privileged credentials.
- Tenant separation: account/project scoping and Postgres row-level security on customer-facing data paths.
- Transmission and storage: TLS in transit; provider encryption at rest where supported; private buckets for customer files except explicitly public avatars.
- Application security: input validation, rate limits, secret separation, dependency review, access checks, share-token expiry and security logging.
- Availability: managed infrastructure, worker separation, service-health checks and controlled deployment procedures. A backup or restore capability is relied on only where the active provider configuration has been verified.
- Monitoring and response: operational/error monitoring where configured, incident triage, breach escalation and post-incident corrective action.
- Data minimisation: relevant-context selection for AI, bounded uploads, purpose-limited public-contact fields and suppression controls.
- People: confidentiality duties and role-based access for authorised personnel.
- Lifecycle: account/project deletion paths, expiring share links and short-lived browser/session storage.
Annex C. Authorised subprocessors
| Subprocessor | Service / Customer Personal Data | Processing location and transfer basis |
|---|---|---|
| Hetzner Online GmbH | Production origin, web/worker and internal-service hosting; encrypted traffic and hosted application data. | European data-centre infrastructure used by the current origin. |
| Cloudflare, Inc. | DNS, proxy, content delivery and security; connection/security metadata and proxied request/response traffic. | Global edge; provider data terms and the applicable adequacy decision or EU Standard Contractual Clauses for restricted transfers. |
| Supabase, Inc. | Authentication, Postgres database, storage and realtime; account and Customer Content. | The active project region must be confirmed in the Order or service-specific compliance evidence before processing. Provider support and listed subprocessors may process elsewhere only under the documented transfer mechanism. |
| Anthropic Ireland, Limited / Anthropic, PBC | Authorised commercial-API AI inference and hosted web search; prompts, relevant context, extracted text and supported files. | EEA, United States and listed subprocessors; Anthropic DPA and applicable Chapter V safeguard for restricted transfers. Subscription/consumer routes are not authorised for Customer Personal Data. |
| Resend, Inc. | Registration/contract confirmations, transactional/service email and authorised campaigns; recipient, message content and delivery events. | Provider/subprocessor locations under Resend DPA and its transfer mechanism. |
| DocuSeal (when enabled) | E-signature workflow; signer details, signature statements and documents. | Enabled only after the selected endpoint, role, location, retention, processor terms and transfer mechanism are recorded. |
| Functional Software, Inc. (Sentry, when enabled) | Error monitoring; error message, route, account identifier and limited diagnostic context. | Configured Sentry region/subprocessors under its DPA and transfer mechanism. |
The self-hosted Coolify, Traefik and Manifest components run within our managed Hetzner environment and are not separate subprocessors. Fonts and icon assets are self-hosted; a public landing-page demo may load an animation library from jsDelivr, but it is not sent Customer Personal Data and is disclosed in the Privacy Notice. Optional Google Analytics is Innovation Bee controller processing of consented website measurement. It is not an authorised destination for Customer Personal Data under this DPA. Every optional provider above is authorised only while the required Article 28 terms and transfer safeguard are in force. For DPA or subprocessor questions, email info@innovationbee.gr.

