BubblingAlerts

Data Processing Addendum

Last updated: 8 September 2026

This Data Processing Addendum ("DPA") forms part of the Terms of Service or other written agreement (the "Agreement") between Better Run, Inc. ("Bubbling", "Processor") and the customer that uses the Service ("Customer", "Controller").

It applies whenever Bubbling processes personal data on the Customer's behalf. It takes effect when the Customer accepts the Agreement. A Customer that needs a signed copy can request one at support@bubbling.ai.

Order of precedence. For personal data, this DPA controls over the rest of the Agreement. The Standard Contractual Clauses control over this DPA. Annexes I, II, and III form part of this DPA.


1. Definitions

Terms defined in the Agreement keep their meaning. In addition:

Data Protection Law means every law about the processing of personal data that applies to a party, including the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and the UK Data Protection Act 2018, the Swiss Federal Act on Data Protection, the California Consumer Privacy Act as amended by the CPRA ("CCPA"), and comparable US state laws.

Customer Personal Data means personal data within Customer Data that Bubbling processes on the Customer's behalf under the Agreement. Annex I describes it.

Data Subject, Personal Data, Personal Data Breach, Processing, Controller, Processor, and Supervisory Authority have the meanings the GDPR gives them.

SCCs means the Standard Contractual Clauses annexed to European Commission Implementing Decision (EU) 2021/914.

UK Addendum means the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018, version B1.0.

Sub-processor means a third party that Bubbling engages to process Customer Personal Data.


2. Roles

The Customer is the Controller of Customer Personal Data and Bubbling is the Processor. Where the Customer is itself a processor for another controller, Bubbling is a sub-processor, and the Customer confirms it has the authority of that controller to enter this DPA.

Bubbling is the controller of Account Data, as the Privacy Policy describes. This DPA does not apply to Account Data.


3. Instructions

Bubbling will process Customer Personal Data only on the Customer's documented instructions, including about transfers to a third country, unless a law it is subject to requires otherwise. Where such a law requires processing, Bubbling will tell the Customer before it processes, unless that law forbids the notice on important grounds of public interest.

The Agreement, this DPA, and the Customer's use of the Service (the sources it connects, the monitors it writes, the retention it sets, the deletions it requests) are the Customer's complete documented instructions. Any other instruction must be agreed in writing, and Bubbling can charge for the work if it goes beyond the Service.

Bubbling will tell the Customer if, in its opinion, an instruction breaks Data Protection Law. Bubbling can suspend the affected processing until the instruction is withdrawn or amended.

Purpose limitation. Bubbling will not process Customer Personal Data for any purpose other than providing, securing, and supporting the Service. Bubbling will not sell or share it, as the CCPA defines those terms, will not retain, use, or disclose it outside the direct business relationship with the Customer, and will not combine it with personal data received from another source except where the CCPA permits a service provider to do so. Bubbling will not use Customer Personal Data to train generative models, and its AI sub-processors are contractually bound to the same restriction.


4. Duration

This DPA applies for as long as Bubbling processes Customer Personal Data, and it survives termination of the Agreement until the data is returned or deleted under Section 11.


5. Confidentiality of personnel

Bubbling will ensure that every person authorized to process Customer Personal Data is under a duty of confidentiality, contractual or statutory, that survives the end of their engagement. Access is limited to the personnel who need it to perform the Agreement.


6. Security

Bubbling will implement and maintain the technical and organizational measures in Annex II, taking account of the state of the art, the cost of implementation, and the nature, scope, context, and purposes of processing, as well as the risk to Data Subjects.

Bubbling can update the measures over time. It will not reduce the overall level of security.

The Customer is responsible for its own configuration of the Service, for its credentials and API keys, for the users it grants access, and for what it chooses to send. Section 5 of the Terms of Service applies.


7. Sub-processors

The Customer gives general written authorization for Bubbling to engage Sub-processors. The current list is published at Sub-processors.

Bubbling will impose on each Sub-processor, by written contract, data protection obligations that are no less protective than those in this DPA, and Bubbling stays fully liable to the Customer for a Sub-processor's performance.

Notice and objection. Bubbling will give at least 30 days notice before it adds or replaces a Sub-processor, by email to the Customer's notice address and by updating the published list. A Customer can subscribe to that notice at privacy@bubbling.ai. The Customer can object on reasonable data protection grounds within that period. The parties will then discuss a resolution in good faith. If Bubbling cannot offer one, the Customer can terminate the affected part of the Service without penalty and receive a pro-rated refund of prepaid fees.


8. Data subject requests

Taking account of the nature of the processing, Bubbling will assist the Customer with appropriate technical and organizational measures, so far as is possible, to answer a Data Subject exercising a right under Chapter III of the GDPR or an equivalent right under other Data Protection Law. The Service's own export, correction, and deletion functions are the primary means of that assistance.

If a Data Subject contacts Bubbling directly about Customer Personal Data, Bubbling will not answer the substance. It will tell the Data Subject to contact the Customer, and it will notify the Customer promptly where it can identify which customer the request concerns.


9. Assistance with obligations

Taking account of the nature of the processing and the information available to it, Bubbling will assist the Customer in meeting its obligations under Articles 32 to 36 of the GDPR: security, breach notification, data protection impact assessments, and prior consultation with a Supervisory Authority. Bubbling can charge a reasonable fee for assistance that goes beyond the Service and beyond what Data Protection Law requires of a processor.


10. Personal data breach

Bubbling will notify the Customer without undue delay, and in any event within 72 hours, after it becomes aware of a Personal Data Breach affecting Customer Personal Data. The notice will describe the nature of the breach, the categories and approximate number of Data Subjects and records concerned so far as known, the likely consequences, the measures taken or proposed, and a contact point for further information. Where Bubbling cannot provide all of that at once, it will provide it in phases without undue delay.

Bubbling will take reasonable steps to contain and remediate the breach, and will cooperate with the Customer's own notification duties. A notice under this Section is not an admission of fault or liability.

Notification of the Data Subjects and of a Supervisory Authority is the Customer's responsibility as Controller.


11. Return and deletion

On termination of the Agreement, and at the Customer's choice, Bubbling will return or delete Customer Personal Data.

The Customer can export its data through the Service for 30 days after termination. After that period Bubbling deletes Customer Personal Data from its production systems within 90 days, and backups holding it are overwritten within their ordinary cycle, currently 7 days. Bubbling can retain data where a law it is subject to requires it, and in that case it will continue to protect the data under this DPA and process it only for that purpose.

Bubbling will certify the deletion in writing on request.


12. Audit and information

Bubbling will make available to the Customer the information necessary to demonstrate compliance with Article 28 of the GDPR, and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates.

In the first instance Bubbling will satisfy this by providing its current security documentation and by answering a reasonable security questionnaire, once per year. Where that is not sufficient for the Customer to demonstrate compliance, or where a Supervisory Authority or a Personal Data Breach requires more, the Customer can conduct an on-site audit, on 30 days written notice, during business hours, no more than once in any 12 months, subject to confidentiality, and without access to another customer's data or to information that would compromise Bubbling's security. Each party bears its own costs, and the Customer bears Bubbling's reasonable costs for an audit beyond the annual one.


13. International transfers

Where Bubbling processes Customer Personal Data that is transferred out of the EEA, the United Kingdom, or Switzerland to a country without an adequacy decision, the following applies and is incorporated into this DPA by reference:

EEA transfers. The SCCs apply. Module Two (controller to processor) applies where the Customer is a controller. Module Three (processor to processor) applies where the Customer is itself a processor. For the purposes of the SCCs:

  • Clause 7, the docking clause, applies.
  • Clause 9, sub-processors, Option 2, general written authorization, with the notice period in Section 7 of this DPA.
  • Clause 11, the optional independent dispute resolution body, does not apply.
  • Clause 17, governing law: the law of Ireland.
  • Clause 18(b), forum: the courts of Ireland.
  • Annex I of the SCCs is Annex I of this DPA. Annex II of the SCCs is Annex II of this DPA. The list of sub-processors is Annex III of this DPA.

UK transfers. The UK Addendum applies to the SCCs. Table 1 is completed by Annex I of this DPA. Table 2 selects the SCCs and the module above. Table 3 is completed by Annexes I and II of this DPA. In Table 4, neither party can end the UK Addendum under Section 19.

Swiss transfers. The SCCs apply with these adaptations: references to the GDPR read as references to the Swiss Federal Act on Data Protection, the competent authority is the Federal Data Protection and Information Commissioner, and "Member State" does not prevent a Data Subject in Switzerland from suing in Switzerland.

Alternative mechanism. If Bubbling adopts a different lawful transfer mechanism, such as certification under a valid adequacy framework, that mechanism applies instead, to the extent it covers the transfer.


14. CCPA and US state laws

For personal information subject to the CCPA, Bubbling is a service provider. Bubbling will not sell or share that information, will not retain, use, or disclose it for any purpose other than performing the Service, will not retain, use, or disclose it outside the direct business relationship with the Customer, and will not combine it with personal information from another source, except where the CCPA permits. Bubbling certifies that it understands and will comply with these restrictions.

Bubbling will notify the Customer if it determines that it can no longer meet these obligations, and the Customer can then take reasonable steps to stop and remediate unauthorized use. Where equivalent US state laws apply, Bubbling acts as a processor or service provider under them on the same terms.


15. Liability

Each party's liability under this DPA is subject to the limitations and exclusions in the Agreement, to the extent Data Protection Law allows. Nothing in this DPA limits a Data Subject's rights under Data Protection Law or under the SCCs.


16. Governing law

This DPA is governed by the law that governs the Agreement, except where the SCCs, the UK Addendum, or Data Protection Law requires another law. Section 13 states the law that governs the SCCs.



Annex I: Details of processing

A. The parties

Data exporter (Controller). The Customer, as identified in its Bubbling account. Its activity is the operation of a chat assistant and the analysis of the resulting conversations. Its contact is the account administrator and the notice address in its account. Its role is Controller, or Processor where Module Three applies.

Data importer (Processor). Better Run, Inc., 651 N Broad St, Suite 201, Middletown, DE 19709. Its activity is the provision of Bubbling, a conversation analytics service. Its contact is privacy@bubbling.ai. Its role is Processor.

B. Description of the transfer

Categories of Data Subject

  • End Users who hold a conversation with the Customer's chat assistant.
  • The Customer's own personnel who use the Service.
  • Any individual an End User names or describes in the text of a conversation.

Categories of personal data

  • Conversation content: the full text of the messages an End User and an assistant exchange, and the time of each.
  • Identifiers the Customer supplies for an End User, such as a visitor id, a session id, a user id, an email address, or a name.
  • Technical metadata about the session, such as the channel, the source system, the locale, and the IP address where the Customer sends one.
  • Results derived from the above: summary, outcome, sentiment, intent, product area, friction, and monitor matches.
  • Contact details for the Customer's personnel who receive alerts.

Special categories of data. None. The Agreement forbids the Customer from sending special categories of personal data without a separate written agreement. Because conversation content is free text, an End User can nonetheless type such data unprompted. Bubbling applies the measures in Annex II to all conversation content without distinction, and the Customer is responsible for its own lawful basis for what its End Users write.

Frequency of the transfer. Continuous, for as long as the Customer's sources are connected.

Nature and purpose of the processing. Collection, recording, storage, structuring, automated analysis using a large language model, generation of alerts and analytics, delivery of those results to the Customer by email, in Slack, and in the dashboard, and erasure. All of it for the sole purpose of providing the Service to the Customer.

Retention. For as long as the Customer instructs, and after termination as Section 11 of this DPA states.

Sub-processors. As Annex III states. Each processes for the duration of its engagement and for the purpose listed there.

C. Competent supervisory authority

The supervisory authority of the EEA Member State in which the data exporter is established, or, where the exporter is not established in the EEA, the supervisory authority of the Member State in which its Article 27 representative is established. For UK transfers, the Information Commissioner's Office. For Swiss transfers, the Federal Data Protection and Information Commissioner.


Annex II: Technical and organizational measures

Pseudonymization and encryption. Data is encrypted in transit with TLS 1.2 or above, and at rest with AES-256 or equivalent, on managed cloud storage. Secrets and API keys are held in a managed secret store, never in source code. Passwords are stored only as salted hashes.

Confidentiality, integrity, availability, and resilience. Production runs on Google Cloud Platform, a managed cloud platform, in the us-central1 region. The application layer runs across several instances and scales automatically. The database is backed up automatically every day, backups are encrypted and retained for 7 days, and transaction logs are retained for 7 days. Capacity and error rates are monitored with alerting.

Restoring availability after an incident. Documented backup and restore procedures, with a recovery point objective of 24 hours and a recovery time objective of 24 hours.

Testing and evaluating effectiveness. Dependency and vulnerability scanning, code review before merge, and security review of significant changes.

Access control. Least privilege by role. Multi-factor authentication on every administrative account. Individual named accounts, never shared. Access is granted on a documented business need and removed on the day an engagement ends. Access to production data is logged.

Identification and authorization of users. Customers authenticate to the dashboard with their own credentials. Ingestion uses per-project API keys that a customer can rotate or revoke at any time. Every project's data is logically separated and scoped by project identifier on every query.

Protection during transmission and storage. TLS on every network path, internal paths included. No production data is copied to a developer machine or to an environment outside production.

Physical security. Processing runs in cloud data centres operated by our hosting sub-processor under recognized certifications. Bubbling holds no on-premises servers.

Logging. Application, access, and administrative actions are logged with timestamps, and logs are retained for 12 months and protected against alteration.

System configuration and default settings. Production is separated from development and staging. Infrastructure is defined as code and changes are reviewed. Default settings are the restrictive ones.

Governance and management. Written security and privacy policies. Security training for personnel on joining and annually. Confidentiality agreements for every employee and contractor. A documented incident response procedure with defined roles. An annual review of the whole set.

Sub-processor governance. Security and privacy review before engagement, a written data protection contract with each one, and periodic review of their controls.

Measures for AI processing. Conversation content sent to a model provider is subject to a contractual prohibition on training. No zero-retention exception is claimed unless it is stated in Annex III. Prompts and outputs are scoped to the one project being analysed.


Annex III: Sub-processors

The current list, with the purpose, the location, and the data each one processes, is published at Sub-processors and forms part of this DPA. Section 7 states how Bubbling gives notice of a change and how a Customer can object.

Bubbling© Bubbling
Help CenterContactSupportTerms of UsePrivacy Policy