Acord de prelucrare a datelor
v2026-08-22
This Data Processing Agreement ("DPA") supplements the Spinrun Terms and Conditions (the "Agreement") between BirdAI S.R.L. and the customer that accepted them ("Customer"). It governs our processing of personal data on Customer's behalf.
Where this DPA and the Agreement disagree about the processing of personal data, this DPA wins. Where this DPA and the Standard Contractual Clauses disagree, the Clauses win.
01Parties
Processor: BirdAI S.R.L., registered office Str. Dinicu Golescu nr. 7, Sector 1, București, Romania. Contact: legal@spinrun.ai.
Controller: the Customer that accepted the Agreement. Customer determines what personal data enters the Service and why; we act on Customer's documented instructions.
02Definitions
Terms not defined here carry the meaning given to them in Regulation (EU) 2016/679 ("GDPR") — personal data, processing, data subject, controller, processor and sub-processor among them.
"Customer Data" means the data Customer, Customer's users, and Customer's agents submit to or generate through the Service: call arguments, responses, artifacts, Brain documents and the connection authorisations that make them reachable.
03Subject matter, nature and duration
Subject matter: providing the Spinrun gateway — holding connection authorisations, executing the calls Customer's agents make, storing the resulting records, and letting Customer see and audit them.
Nature and purpose: hosting, storing, transmitting, retrieving, authenticating, logging, securing and displaying Customer Data, and routing it to model providers where Customer uses a feature that calls one.
Duration: the term of the Agreement, plus the wind-down needed to delete data, except where law requires us to keep a record for longer.
Categories of personal data
What actually flows through the Service, rather than a generic list:
- Identification data — name, email address, workspace membership, role, authentication identifiers.
- Connection credentials — OAuth tokens and API keys for connected applications, the scopes granted, and when each was last used.
- Customer Content — call arguments, response previews, agent-authored artifacts, and documents ingested into Brain — all of which may contain personal data Customer chooses to put there.
- Activity data — which tool ran, the action, the outcome, the duration, and the audit trail built from them.
- Technical data — IP address, user agent, timestamps, error and rate-limit records, abuse signals.
Categories of data subject
Whose data may be involved:
- Customer's authorised users — employees, contractors and workspace members.
- People whose records sit in the applications Customer connects, and which Customer's agents read or write.
- Anyone else whose personal data Customer chooses to process through the Service.
04Processing on documented instructions
We process personal data only on Customer's documented instructions, including as to international transfers, unless EU or Member State law requires otherwise — in which case we tell Customer first, unless that law forbids it.
The Agreement, this DPA, the configuration Customer sets in the Service — connections authorised, permission rules, retention settings, plan — and the calls Customer's agents make together constitute those instructions.
If we believe an instruction infringes the GDPR, we will say so.
05Confidentiality
Everyone we authorise to process personal data is under a written confidentiality obligation or a statutory duty of confidence, and gets access on a need-to-know basis only.
06Security of processing
We implement technical and organisational measures appropriate to the risk. Concretely, and as implemented today:
- Connection credentials are held in an encrypted vault, never in configuration files or environment variables.
- Encryption in transit throughout, and at rest in the primary data stores.
- Tenant isolation enforced at the database row level, so one workspace's queries cannot reach another's rows.
- Read, write and destructive rules enforced at the gateway, before a call leaves for the connected application — in code rather than in a prompt.
- Agent-authored content served from an opaque origin with no session cookie attached, on routes deliberately excluded from the middleware that would set one.
- Private object storage with no pre-signed URLs; every read passes through an authenticated route.
- Least-privilege access, audit logging, and a retention job that authenticates with a shared secret and refuses to run without it.
07Sub-processors
Customer gives general written authorisation for us to engage sub-processors. The current list is published and incorporated into this DPA by reference.
We impose data-protection obligations on each sub-processor at least as protective as those in this DPA, and we remain liable for their acts and omissions as if they were our own.
We give 14 days' notice before a new sub-processor starts processing. Customer may object on reasonable data-protection grounds; if we cannot resolve the objection, Customer may terminate the affected part of the Service.
08Assisting with data subject rights
Taking the nature of the processing into account, we assist Customer by appropriate technical and organisational measures in meeting requests from data subjects — access, rectification, erasure, restriction, portability and objection.
Where a data subject comes to us directly about data we hold as Customer's processor, we do not act on it ourselves: we pass it to Customer. Escalations reach us at legal@spinrun.ai.
09Assisting with obligations under Articles 32 to 36
We assist Customer, taking into account the nature of processing and the information available to us, with security of processing, breach notification, data protection impact assessments, and prior consultation with a supervisory authority.
10Personal data breach
We notify Customer without undue delay, and in any event within 72 hours, of becoming aware of a personal data breach affecting Customer's personal data.
The notice describes what we know: the nature of the breach, the categories and approximate number of data subjects and records involved where we can establish them, the likely consequences, and what we have done or propose to do about it.
11International transfers
Where personal data is transferred outside the European Economic Area to a country without an adequacy decision, we rely on the Standard Contractual Clauses adopted by the European Commission in Decision (EU) 2021/914, incorporated here by reference.
Module Two (controller to processor) applies between Customer and us. Module Three (processor to processor) applies between us and our sub-processors. Supplementary technical measures — encryption in transit and at rest, access control — apply alongside them.
12Audits
We make available the information necessary to demonstrate compliance with Article 28 GDPR.
Customer may audit no more than once in any twelve-month period, on at least 30 days' notice, during business hours, subject to confidentiality and to not disrupting the Service or other customers. Where a current third-party report or certification answers the question, providing it satisfies this obligation. A supervisory authority exercising its own powers is not limited by this clause.
13Return and deletion
On termination of the Agreement we delete Customer's personal data within 30 days, except where EU or Member State law requires us to keep it. Connected authorisations are revoked at the same time.
Backups age out through ordinary rotation rather than being deleted individually. Customer should export what it needs before terminating.
14Liability and precedence
Liability under this DPA is governed by, and subject to the limits in, the Agreement. This DPA prevails over the Agreement on the processing of personal data; the Standard Contractual Clauses prevail over this DPA.
This DPA supplements Terms and Conditions version 2026-08-22 and Privacy Policy version 2026-08-22.
15Execution
This DPA takes effect when Customer accepts it in the Service or in writing. No signature is needed for it to bind us.
If Customer needs a countersigned copy, write to legal@spinrun.ai with the entity's legal name, registered address, and the email of the authorised signatory.
Supervisory authority: Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP) — https://www.dataprotection.ro/, anspdcp@dataprotection.ro, B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, 010336 București, Romania.