Begrasp.

Legal

Data Processing Agreement & Subprocessors

Last updated: [DATE].

Roles

For personal data in customer content, the customer is the controller and Begrasp is the processor. Begrasp processes such data only on documented instructions to provide the Service.

Our commitments

We implement appropriate technical and organizational measures (encryption in transit and at rest, per-tenant row-level isolation, least-privilege access); ensure personnel confidentiality; assist with data-subject requests and security obligations; delete or return data on termination; and notify you without undue delay of a personal-data breach.

Subprocessors

We engage the following subprocessors, each under a DPA. We'll give notice before adding a new one so you can object.

SubprocessorPurposeData
VercelApplication hostingApp traffic, logs
CloudflareDNS, CDN, securityNetwork metadata
SupabaseDatabase, auth, file storageAccounts, brands, diagnoses
StripePayments & subscriptionsBilling data (PCI)
ResendTransactional emailEmail address, message content
ModalEngine compute (diagnoses)Brand intake, engine I/O
AnthropicAI model (analysis)Prompts derived from your data
PostHogProduct analyticsUsage events
SentryError monitoringDiagnostic error data

International transfers

Where data is transferred outside your region, we rely on appropriate safeguards (e.g. Standard Contractual Clauses) with each subprocessor.

Contact

To sign the DPA or ask a security question: security@begrasp.com.

Terms · Privacy · Refund · Home