Bacenik Decide
Decision intelligence
How it worksExamplePricingTrustSign in

Menu

How it worksExamplePricingTrustSign in

Data Processing Addendum

Standard DPA terms for customers using Bacenik Decide with organizational data.

Last updated · June 2026

Roles

You are the data controller for decision content and user accounts in your organization. Bacenik is the processor for data you submit to operate the service.

Processing scope

We process account identifiers, decision artifacts, audit logs, and billing metadata solely to provide, secure, and support the service.

Sub-processors

Hosting, database, email, and payment providers — the current list, including purpose and region for each, is published at /trust. We will give enterprise customers at least 30 days' notice before engaging a new material sub-processor, and you may object on reasonable data protection grounds by contacting enterprise@bacenik.com; if we cannot resolve the objection, you may terminate the affected service.

International transfers

Where processing your data involves a transfer outside the EEA, UK, or Switzerland, we rely on the European Commission's Standard Contractual Clauses (or an equivalent recognized transfer mechanism) with the relevant sub-processor.

Security measures

Access controls, encryption in transit, audit trails, and incident response per our security runbooks. See /enterprise for OIDC, RBAC, and audit export capabilities.

Data subject requests

We assist controllers with verified requests within reasonable timelines. Contact info@bacenik.com with your workspace identifier.

Audit rights

On reasonable written notice, and no more than once per 12 months absent a security incident, we will provide you with our latest security documentation and answer reasonable written questions to help you verify our compliance with this DPA.

Return or deletion of data

On termination of your subscription, you may export your data for 30 days. After that window, we will delete or anonymize your data within a reasonable period, except where retention is required for billing, legal, or security-incident records.

Governing law

This DPA is governed by the laws of the State of Delaware, consistent with our Terms of Service, without prejudice to any data protection law that applies to you as controller.

Executed agreements

Enterprise customers may request a countersigned DPA and security questionnaire package at enterprise@bacenik.com or visit Enterprise.
How it worksExampleGuidePricingFounding PilotTeamTrustSupportTermsPrivacy

© 2026 Bacenik · Not legal advice