Data Processing Addendum
Last updated: 18 July 2026
1. Scope and Roles
This Data Processing Addendum ("DPA") forms part of the Terms of Service between 4 BEES D.O.O. ("grappes", "Processor") and the customer entity agreeing to it ("Customer", "Controller"). It applies where grappes processes personal data on behalf of the Customer ("Customer Personal Data") in the course of providing grappes.ai (the "Service").
Where grappes processes personal data for its own purposes (e.g. account administration, security, service improvement), grappes acts as a controller and that processing is governed by the Privacy Policy, not this DPA.
This DPA is designed to support compliance with the GDPR and the Serbian Law on Personal Data Protection.
2. Processing Details
- Subject matter: provision of the Service.
- Duration: for the term of the Customer's subscription and as set out in Section 9.
- Nature and purpose: hosting, processing, transmitting to AI providers, and returning AI Outputs, plus related features (sessions, projects, memory) as instructed by the Customer through use of the Service.
- Types of personal data: as determined by the Customer through its Inputs — see Annex I.
- Categories of data subjects: as determined by the Customer — see Annex I.
3. Customer Instructions
grappes will process Customer Personal Data only on the Customer's documented instructions, including as set out in this DPA and as given through the Customer's use of the Service, unless required to do otherwise by law (in which case grappes will, where lawful, inform the Customer). The Customer is responsible for ensuring it has a lawful basis and any required consents for the data it submits.
4. Confidentiality
grappes ensures that personnel authorized to process Customer Personal Data are bound by appropriate confidentiality obligations.
5. Security
grappes implements appropriate technical and organizational measures to protect Customer Personal Data, as described in Annex II, taking into account the state of the art, costs, and the risks of the processing.
6. Sub-processors
The Customer authorizes grappes to engage sub-processors to provide the Service, including infrastructure/hosting, AI providers, and the Merchant of Record, as listed in Annex III. grappes will impose data-protection obligations on sub-processors substantially similar to those in this DPA and remains responsible for their performance. grappes will give the Customer notice of intended changes to sub-processors and an opportunity to object on reasonable data-protection grounds.
7. Assistance to the Customer
Taking into account the nature of processing, grappes will provide reasonable assistance to the Customer in:
- Responding to data-subject rights requests (access, rectification, erasure, portability, objection, restriction).
- Meeting obligations regarding security, breach notification, data-protection impact assessments, and prior consultation with supervisory authorities.
8. Personal Data Breach
grappes will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and will provide information reasonably available to assist the Customer in meeting its notification obligations.
9. Return and Deletion
Upon termination of the Service, or earlier on the Customer's request, grappes will delete or return Customer Personal Data, subject to retention required by law and to standard backup cycles after which data is deleted, as described in the Privacy Policy.
10. Audits
grappes will make available information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer, subject to reasonable confidentiality, notice, and frequency limits.
11. International Transfers
Where grappes transfers Customer Personal Data outside Serbia or the EEA, it will ensure an appropriate transfer mechanism is in place, such as the European Commission's Standard Contractual Clauses (which the parties agree to incorporate by reference where applicable) or an adequacy decision.
12. Liability and Precedence
Liability under this DPA is subject to the limitations in the Terms of Service. In the event of a conflict between this DPA and the Terms regarding the processing of Customer Personal Data, this DPA prevails.
Annex I — Description of Processing
- Categories of data subjects: as determined by the Customer — for example, the Customer's end users, employees, and contacts.
- Categories of personal data: identifiers and any content the Customer chooses to submit as Inputs.
- Special categories: none are required by the Service; the Customer should avoid submitting special-category data unless necessary and with appropriate safeguards.
- Processing operations: storage, transmission to AI providers, generation of Outputs, personalization, and logging.
Annex II — Technical and Organizational Security Measures
- Encryption of data in transit (TLS).
- Access controls and authentication; passwords stored hashed.
- Network and application security controls, including monitoring.
- Rate limiting and abuse prevention.
- Regular backups and a defined incident-response process.
Annex III — Approved Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| 4 BEES D.O.O. server | Infrastructure / application hosting and storage | Serbia |
| Anthropic | AI generation (text) and context/orchestration model | United States |
| OpenAI | AI generation (text, image) and voice-audio transcription (Whisper) | United States |
| AI generation (text, image) and sign-in (OAuth) | United States / EU | |
| xAI | AI generation (text) and web retrieval (Deep Web Inspect) | United States |
| Moonshot AI (Kimi) | Context/intent processing and app/site build generation (text, vision) | International (incl. China) |
| Recraft | Logo and vector-graphics generation | United States |
| Runway | Video generation | United States |
| Seedance (BytePlus) | Video generation | International (Asia-Pacific) |
| Polar (Polar Software, Inc.) | Payments (Merchant of Record) | European Union |
| Cloudflare | DNS, CDN, and reverse-proxy / security (traffic and IP metadata) | United States / global |
| DigitalOcean Spaces | Object storage for generated media and published static sites | Amsterdam, EU |
| Porkbun | Domain registration (only if a domain is purchased through the Service) | United States |
| Slack (Slack Technologies) | Internal operational notifications (account / billing email) | United States |
To request a DPA for your organization or to ask about sub-processors, contact [email protected].