Data Processing Addendum
Last updated: 9 October 2026
Effective date: 9 October 2026
This Data Processing Addendum ("DPA") forms part of the TypeOrb Terms of Service at typeorb.com/terms (the "Terms") between Bedrock Flow, Inc., a Delaware corporation doing business as TypeOrb, with its address at 9450 Southwest Gemini Drive, PMB 54889, Beaverton, OR 97008, USA ("Bedrock Flow", "we", "us"), and the business or organization that has accepted the Terms ("Customer", "you"). By accepting the Terms, you also accept this DPA; you do not need to sign it separately. A countersigned copy is available on request at contact@typeorb.com.
1. Definitions
Capitalized terms not defined in this DPA, such as "Service", "Customer Content", "Authorized Users", and "Output", have the meanings given in the Terms.
"Customer Personal Data" means personal data contained in Customer Content that Bedrock Flow processes on behalf of Customer when providing the Service.
"Data Protection Laws" means all data protection laws that apply to the processing of Customer Personal Data under the Terms, including Regulation (EU) 2016/679 ("GDPR") and the national laws of the member states of the European Economic Area ("EEA") that supplement it, and, where they apply, US state privacy laws such as the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA").
"Controller", "processor", "data subject", "personal data", "personal data breach", "processing", and "supervisory authority" have the meanings given in the GDPR.
"Sub-processor" means a third party engaged by Bedrock Flow that processes Customer Personal Data.
"SCCs" means the standard contractual clauses for the transfer of personal data to third countries approved by the European Commission in Implementing Decision (EU) 2021/914 of 4 June 2021.
2. Scope and roles
2.1 This DPA applies to the processing of Customer Personal Data by Bedrock Flow in providing the Service. Annex I describes the processing.
2.2 Customer is the controller of Customer Personal Data and Bedrock Flow is the processor. If Customer uses the Service on behalf of its own clients and acts as their processor, Bedrock Flow acts as Customer's sub-processor, and Customer confirms that its clients have authorized it to give the instructions and to enter into the commitments in this DPA.
2.3 Customer is responsible for having a lawful basis for the processing, for giving any notices and obtaining any consents required by Data Protection Laws (including for recording and uploading calls and meetings and for using employees' names, writing samples, or likeness), and for the accuracy of Customer Personal Data. Customer will not submit special categories of personal data, payment card data, or children's data to the Service unless Bedrock Flow has agreed in writing.
2.4 Personal data that Bedrock Flow processes as a controller for its own purposes, such as account, billing, and usage data, is described in our Privacy Policy at typeorb.com/privacy and is not covered by this DPA.
3. Instructions
3.1 Bedrock Flow will process Customer Personal Data only on Customer's documented instructions, unless required to do otherwise by applicable law; in that case Bedrock Flow will inform Customer of that legal requirement before processing, unless the law prohibits it. Customer's instructions are set out in the Terms and this DPA, and in Customer's use and configuration of the Service. Additional instructions must be agreed in writing.
3.2 Bedrock Flow will inform Customer without delay if, in its opinion, an instruction infringes Data Protection Laws.
4. No model training
Bedrock Flow does not use Customer Content, including Customer Personal Data, to train or fine-tune artificial intelligence models. We have opted out of model training with the AI routing service and the model providers we use, and our requests are routed only to providers that do not train on the data sent to them. Model providers may retain prompts and outputs for a limited period for abuse and safety monitoring under their own terms.
5. Confidentiality
Bedrock Flow will ensure that persons it authorizes to process Customer Personal Data are bound by an obligation of confidentiality, whether contractual or statutory, and that they process it only as needed to provide the Service.
6. Security
6.1 Bedrock Flow will implement and maintain the technical and organizational measures described in Annex II to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. Bedrock Flow may update these measures, provided that the overall level of protection is not reduced.
6.2 Customer is responsible for the security of its accounts, including keeping login credentials confidential and managing its Authorized Users' access.
7. Sub-processors
7.1 General authorization. Customer gives Bedrock Flow general authorization to engage Sub-processors. The Sub-processors engaged at the date of this DPA are summarized in Annex III. The current list, with each Sub-processor's purpose and location, is published at typeorb.com/subprocessors.
7.2 Notice of changes. Bedrock Flow will give at least 30 days' notice before adding or replacing a Sub-processor, by email to Customer's account owner or by updating the list at typeorb.com/subprocessors.
7.3 Right to object. Customer may object to a new Sub-processor on reasonable data protection grounds by emailing contact@typeorb.com within that 30-day period. The parties will discuss the objection in good faith. If Bedrock Flow cannot offer a reasonable alternative, Customer may terminate the affected subscription by written notice before the change takes effect, and Bedrock Flow will refund any prepaid fees for the period after termination.
7.4 Flow-down. Bedrock Flow will engage each Sub-processor under a written contract that imposes data protection obligations no less protective than those in this DPA, to the extent applicable to the services it provides. Bedrock Flow remains responsible to Customer for the performance of its Sub-processors' obligations.
8. Assistance
8.1 Data subject requests. Taking into account the nature of the processing, Bedrock Flow will assist Customer by appropriate technical and organizational measures, insofar as possible, in responding to requests from data subjects to exercise their rights under Data Protection Laws. If Bedrock Flow receives such a request directly, it will not respond on the merits but will promptly forward it to Customer, unless the law requires otherwise.
8.2 Impact assessments and consultations. Bedrock Flow will provide reasonable assistance to Customer with data protection impact assessments and prior consultations with supervisory authorities relating to the Service, taking into account the nature of the processing and the information available to Bedrock Flow.
8.3 Requests from authorities. If Bedrock Flow receives a request from a supervisory authority or other public authority about Customer Personal Data, it will notify Customer unless the law prohibits it.
9. Personal data breaches
9.1 Bedrock Flow will notify Customer without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data. Notice will be sent to Customer's account owner by email.
9.2 The notice will describe, to the extent known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address the breach and mitigate its effects. Where not all information is available at once, Bedrock Flow will provide it in phases without undue further delay.
9.3 Bedrock Flow will take reasonable steps to contain and remedy the breach and will cooperate with Customer in meeting its own notification obligations. Notifying a breach is not an admission of fault or liability.
10. Return and deletion
10.1 During the subscription, Customer can request an export of Customer Content at contact@typeorb.com; Bedrock Flow will provide it within 30 days in a structured, commonly used format.
10.2 Bedrock Flow will delete Customer Personal Data from its active systems within 30 days after the subscription is cancelled or terminated, or after Bedrock Flow issues a refund under Section 5 of the Terms. Copies in backups are purged within 90 days. Customer should export any content it needs before deletion.
10.3 Bedrock Flow may keep Customer Personal Data longer only where the law requires it, in which case it will protect that data under this DPA and process it only for the purpose required by law. On request, Bedrock Flow will confirm deletion in writing.
11. Audits
11.1 Bedrock Flow will make available to Customer the information necessary to demonstrate compliance with this DPA and Article 28 GDPR. On request, Bedrock Flow will provide its documentation, including this DPA, the current Sub-processor list, and a description of its security measures, and will answer one reasonable security and privacy questionnaire per year.
11.2 If this information is not sufficient to demonstrate compliance, or if a supervisory authority requires it, Customer may carry out an audit, itself or through an independent auditor bound by confidentiality, on at least 30 days' written notice, during normal business hours, at Customer's cost, in a way that does not disrupt Bedrock Flow's operations or compromise the security or confidentiality of other customers' data, and not more than once in any 12 months except after a personal data breach or at the request of a supervisory authority. Audits under the SCCs will be carried out in the same way, to the extent the SCCs allow.
12. International transfers
12.1 Location of processing. Bedrock Flow is based in the United States, and Customer Personal Data is processed in the United States. AI processing for the Service, including the processing of prompts that contain Customer Content, takes place only in the United States. Bedrock Flow does not rely on the EU-U.S. Data Privacy Framework.
12.2 SCCs. To the extent that the processing of Customer Personal Data under the Terms involves a transfer of personal data from Customer, as data exporter subject to the GDPR, to Bedrock Flow in the United States, the SCCs (Module Two: transfer controller to processor) are incorporated into this DPA by reference and apply between Customer as data exporter and Bedrock Flow as data importer, with the following choices:
(a) Clause 7 (docking clause) applies.
(b) Clause 9(a): Option 2 (general written authorization) applies, and the time period for prior notice of Sub-processor changes is 30 days, as described in Section 7.
(c) Clause 11(a): the optional language does not apply.
(d) Clause 13: the competent supervisory authority is the supervisory authority of the Member State in which the data exporter is established, as set out in Annex I.C.
(e) Clause 17: Option 1 applies, and the SCCs are governed by the law of Ireland.
(f) Clause 18(b): disputes arising from the SCCs will be resolved by the courts of Ireland.
(g) Annexes I, II, and III of the SCCs are completed with the information in Annexes I, II, and III of this DPA.
12.3 Onward transfers. Onward transfers of Customer Personal Data to Sub-processors are made in accordance with Clauses 8.8 and 9 of the SCCs.
12.4 United Kingdom and Switzerland. The Service is offered only to businesses in the United States and in the European Union and the wider EEA. It is not offered in the United Kingdom or Switzerland, so the UK International Data Transfer Addendum and Swiss-specific adaptations of the SCCs do not apply.
13. US state privacy laws
To the extent the CCPA or a similar US state privacy law applies to Customer Personal Data, Bedrock Flow acts as Customer's service provider (or processor) and will: (a) process Customer Personal Data only for the business purposes set out in the Terms and this DPA; (b) not sell or share Customer Personal Data, as those terms are defined in the CCPA; (c) not retain, use, or disclose Customer Personal Data for any purpose other than those business purposes, or outside the direct business relationship between Customer and Bedrock Flow; (d) not combine Customer Personal Data with personal information it receives from other sources, except as the CCPA permits; (e) comply with the CCPA and provide the same level of privacy protection it requires; and (f) notify Customer if it can no longer meet these obligations. Customer may take reasonable and appropriate steps to stop and remediate unauthorized use of Customer Personal Data. Bedrock Flow certifies that it understands and will comply with these restrictions.
14. Liability
Each party's liability arising out of or relating to this DPA is subject to the limitations and exclusions of liability in the Terms, except to the extent that the SCCs or Data Protection Laws do not allow such limitations. Nothing in this DPA limits either party's liability to data subjects under Clause 12 of the SCCs.
15. Order of precedence
If there is a conflict, the following order applies: (1) the SCCs, where they apply; (2) this DPA; (3) the Terms. Otherwise, the Terms continue to apply.
16. Term, governing law, and changes
16.1 This DPA takes effect when Customer accepts the Terms and continues for as long as Bedrock Flow processes Customer Personal Data. Sections 9, 10, 11, and 14 survive until all Customer Personal Data has been deleted.
16.2 This DPA is governed by the law that governs the Terms, except that the SCCs are governed by the law set out in Section 12.2(e).
16.3 Bedrock Flow may update this DPA as described in Section 21 of the Terms. An update will not reduce the level of protection for Customer Personal Data unless required by law.
17. Contact and EU representative
Data protection questions and notices: contact@typeorb.com, or Bedrock Flow, Inc., 9450 Southwest Gemini Drive, PMB 54889, Beaverton, OR 97008, USA.
EU representative under Article 27 GDPR: FOCUS ON TARGET sp. z o.o., ul. Gospodarcza 26, 20-213 Lublin, Poland, eu-rep@typeorb.com.
Annex I. Description of the processing
A. List of parties
Data exporter: the Customer that has accepted the Terms, with the name, address, and contact details given in its TypeOrb account. Activities relevant to the data transferred: use of the TypeOrb Service. Role: controller (or, where Customer acts for its own clients, processor). Signature and date: Customer's acceptance of the Terms, which incorporate this DPA, on the date of acceptance.
Data importer: Bedrock Flow, Inc., d/b/a TypeOrb, 9450 Southwest Gemini Drive, PMB 54889, Beaverton, OR 97008, USA. Contact person's details: contact@typeorb.com. EU representative: FOCUS ON TARGET sp. z o.o., ul. Gospodarcza 26, 20-213 Lublin, Poland, eu-rep@typeorb.com. Activities relevant to the data transferred: providing the TypeOrb Service under the Terms. Role: processor. Signature and date: by making the Service available under the Terms that incorporate this DPA, on the date of Customer's acceptance.
B. Description of the transfer
Categories of data subjects: Customer's employees, contractors, and other Authorized Users; individuals whose public information Customer provides to the Service (for example, public professional profile information); and other individuals whose personal data Customer includes in Customer Content (for example, participants in recorded calls or meetings).
Categories of personal data: names; work contact data (such as work email address, job title, and company); content containing personal data, such as documents, call and meeting recordings and transcripts, writing samples, prompts and other inputs, and Output; and LinkedIn profile data and other public professional profile information that Customer provides.
Sensitive data: none intended. Customer must not submit special categories of personal data unless Bedrock Flow has agreed in writing.
Frequency of the transfer: continuous, for the duration of Customer's subscription.
Nature of the processing: hosting and storage; analysis and organization of Customer Content; AI-assisted research, planning, drafting, and evaluation of content, including sending prompts that contain Customer Content to AI models; publishing to connected platforms at Customer's direction; and support.
Purpose of the processing: providing, securing, supporting, and maintaining the Service for Customer under the Terms.
Retention period: for the duration of Customer's subscription; then deletion from active systems within 30 days after cancellation, termination, or a refund under Section 5 of the Terms, and from backups within 90 days, as set out in Section 10 of this DPA and Section 7.7 of the Terms.
Transfers to Sub-processors: the Sub-processors listed in Annex III, for the subject matter, nature, and duration described in this Annex I.
C. Competent supervisory authority
The supervisory authority of the Member State in which the data exporter is established.
Annex II. Technical and organizational measures
Encryption in transit: connections to the Service are encrypted using HTTPS (TLS).
Access controls: access to production systems and Customer Personal Data is restricted to authorized personnel who need it to provide, secure, and support the Service, and is removed when no longer needed.
Separate environments: development and production environments are kept separate.
Service providers: Sub-processors are engaged under written data processing agreements, as described in Section 7.
Confidentiality: personnel with access to Customer Personal Data are bound by confidentiality obligations.
Incident response: suspected personal data breaches are investigated and handled, and Customer is notified as described in Section 9.
Deletion: Customer Personal Data is deleted from active systems and backups within the periods in Section 10.
Data minimization in analytics: AI prompts and outputs are not sent to our product analytics tool.
Assistance with data subject requests: Customer can view, edit, and delete content in the Service and can request an export under Section 10.1.
Annex III. Sub-processors
All Sub-processors listed below process personal data in the United States. AI processing takes place only in the United States. The current list is published at typeorb.com/subprocessors and is updated as described in Section 7.
| Sub-processor | Purpose | Location |
|---|---|---|
| Fly.io | Application hosting | United States |
| Turso | Database, including vector database | United States |
| Upstash | Redis job queues | United States |
| Backblaze B2 | File storage | United States |
| Railway (hosting for SigNoz and Chatwoot) | Hosts our self-hosted SigNoz (logs and traces for monitoring and debugging) and our self-hosted Chatwoot (customer support chat for signed-in users). Chatwoot holds no Customer Content; it holds users' names, email addresses, user IDs, and the messages and attachments they send in the chat | United States |
| OpenRouter | AI model routing (US endpoint only) | United States |
| Replicate | Image and media models | United States |
| Clay | Profile enrichment at onboarding | United States |
| Sentry | Error monitoring and, with consent, session replay | United States |
| Resend | Transactional email | United States |
| Stripe | Payments and billing, where relevant | United States |