Legal
Last updated: [DATE].
For personal data in customer content, the customer is the controller and Begrasp is the processor. Begrasp processes such data only on documented instructions to provide the Service.
We implement appropriate technical and organizational measures (encryption in transit and at rest, per-tenant row-level isolation, least-privilege access); ensure personnel confidentiality; assist with data-subject requests and security obligations; delete or return data on termination; and notify you without undue delay of a personal-data breach.
We engage the following subprocessors, each under a DPA. We'll give notice before adding a new one so you can object.
| Subprocessor | Purpose | Data |
|---|---|---|
| Vercel | Application hosting | App traffic, logs |
| Cloudflare | DNS, CDN, security | Network metadata |
| Supabase | Database, auth, file storage | Accounts, brands, diagnoses |
| Stripe | Payments & subscriptions | Billing data (PCI) |
| Resend | Transactional email | Email address, message content |
| Modal | Engine compute (diagnoses) | Brand intake, engine I/O |
| Anthropic | AI model (analysis) | Prompts derived from your data |
| PostHog | Product analytics | Usage events |
| Sentry | Error monitoring | Diagnostic error data |
Where data is transferred outside your region, we rely on appropriate safeguards (e.g. Standard Contractual Clauses) with each subprocessor.
To sign the DPA or ask a security question: security@begrasp.com.