7BE
    Dienstleistungen
    • KI-Agenten-Entwicklung
    • KI-Sprachagenten
    • KI-Prozessautomatisierung
    • KI-Workflow-Automatisierung
    • KI-Operations
    • KI-interne Tools
    • KI-Wissenssysteme
    Branchen
    • Unternehmensdienstleistungen
    • Informationstechnologie
    • Konsumgüter & Dienstleistungen
    • E-Commerce
    • Medizin
    Länder
    • Vereinigte Staaten
    • Deutschland
    • Vereinigtes Königreich
    • Indien
    • Kanada
    Alle KI-Services entdecken
    Dienstleistungen
    • KI-Vertriebsautomatisierung
    • KI-SEO und Content-Systeme
    • KI-Marketing-Automatisierung
    • KI-gestütztes PPC
    • KI-Social-Media-Marketing
    • KI-E-Mail-Marketing
    • KI-Content-Marketing
    Branchen
    • Unternehmensdienstleistungen
    • Informationstechnologie
    • Konsumgüter & Dienstleistungen
    • E-Commerce
    • Medizin
    Länder
    • Vereinigte Staaten
    • Deutschland
    • Vereinigtes Königreich
    • Indien
    • Kanada
    Alle KI-Services entdecken
    Dienstleistungen
    • KI-SaaS-Entwicklung
    • KI-Produktentwicklung
    • KI-gestützter eCommerce
    • KI-gestütztes IoT (AIoT)
    • KI-gestütztes UX/UI-Design
    • KI-gestütztes Application-Testing
    Branchen
    • Unternehmensdienstleistungen
    • Informationstechnologie
    • Konsumgüter & Dienstleistungen
    • E-Commerce
    • Medizin
    Länder
    • Vereinigte Staaten
    • Deutschland
    • Vereinigtes Königreich
    • Indien
    • Kanada
    Alle KI-Services entdecken
    Dienstleistungen
    • KI-Strategieberatung
    • KI-Beratung
    • KI-Datenintelligenz
    • KI in der Cloud
    • KI-Cybersicherheit
    • KI-gestützte Unternehmensmodernisierung
    • KI-Engineering-Personalaufstockung
    • KI-Übersetzungsdienste
    • KI-Transkriptionsdienste
    Branchen
    • Unternehmensdienstleistungen
    • Informationstechnologie
    • Konsumgüter & Dienstleistungen
    • E-Commerce
    • Medizin
    Länder
    • Vereinigte Staaten
    • Deutschland
    • Vereinigtes Königreich
    • Indien
    • Kanada
    Alle KI-Services entdecken
    • Warum 7BE für Kunden?
    • Wie funktioniert es?
    • Wie bewertet 7BE Agenturen?
    • Warum KI-Projekte scheitern
    • Warum 7BE für Agenturen?
    • Preise und Optionen
    • Zertifizierung
  • Marktplatz
  • Startseite
  • Rechtliches
  • Data Processing Addendum
Rechtliches

Data Processing Addendum

Effective date: July 18, 2026

This Data Processing Addendum, including its Schedules (the “DPA”), forms part of the agreement between the customer identified in an Order or Project Order (“Customer”) and 7BE Inc. (“7BE”) governing Customer’s use of the Services (the “Agreement”).

By accepting the Agreement or a Project Order that refers to this DPA, Customer enters into this DPA on behalf of itself and any authorized Affiliate that is a Controller of Customer Personal Data.

1. Definitions

Applicable Data Protection Law means privacy, data-protection, breach-notification, and security law applicable to the processing of Customer Personal Data, including, where applicable, the GDPR, UK GDPR, CCPA, and US state comprehensive privacy laws.

CCPA means the California Consumer Privacy Act, as amended.

Customer Personal Data means Personal Data that 7BE processes on behalf of Customer to provide the Services, excluding information for which 7BE independently determines the purposes and means as described in the Privacy Policy.

Europe means the European Economic Area, Switzerland, and the United Kingdom.

GDPR means Regulation (EU) 2016/679. UK GDPR has the meaning under UK data-protection law.

Personal Data, Controller, Processor, Data Subject, Processing, and Supervisory Authority have the meanings in Applicable Data Protection Law. Business, Service Provider, Contractor, Sell, and Share have the meanings in the CCPA.

Security Incident means a confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data. It does not include unsuccessful attempts that do not compromise Customer Personal Data.

Subprocessor means a third party appointed by or for 7BE to process Customer Personal Data.

2. Scope and Roles

Customer is a Controller or Processor, as applicable, and appoints 7BE as Processor to process Customer Personal Data solely to provide, secure, support, and improve the contracted Services as instructed by Customer and this DPA.

If Customer is a Processor for another Controller, Customer represents that it has authority to appoint 7BE as a subprocessor and provide all instructions in the Agreement.

7BE is an independent Controller for account, relationship, billing, fraud, security, compliance, and legal-record information that it processes for its own stated purposes. Such information is governed by the Privacy Policy and is not Customer Personal Data under this DPA.

3. Documented Instructions

7BE will process Customer Personal Data only on Customer’s documented instructions, which consist of the Agreement, Project Order, Customer’s authorized configuration and use, and additional lawful written instructions accepted by 7BE.

7BE will not:

  • sell or share Customer Personal Data;
  • retain, use, or disclose Customer Personal Data outside the direct business relationship or for a commercial purpose other than providing the Services;
  • combine Customer Personal Data with personal data received from another person or collected from 7BE’s own interactions, except as permitted by law to provide the Services;
  • use Customer Personal Data for cross-context behavioral advertising; or
  • use Customer Personal Data to train or improve a general-purpose or shared machine-learning model.

7BE may generate service telemetry and aggregated or de-identified information only when it does not identify and cannot reasonably be used to re-identify Customer, a Data Subject, a Project, or Customer Confidential Information. 7BE will not attempt re-identification.

If 7BE believes an instruction violates Applicable Data Protection Law, it will notify Customer unless prohibited and may suspend the affected processing until clarified.

4. Customer Responsibilities

Customer will:

  • provide lawful, documented instructions and all notices, permissions, and lawful bases required for Customer Personal Data;
  • minimize data and avoid submitting data not necessary for the Project;
  • configure access, retention, and integrations appropriately;
  • respond to Data Subjects regarding Customer’s use and decisions;
  • not submit prohibited regulated or highly sensitive data unless expressly approved in a Project Order and sector-specific addendum; and
  • ensure that any Agency or other recipient is authorized and contractually bound to protect Customer Personal Data.

5. Confidentiality and Personnel

7BE will ensure that personnel authorized to process Customer Personal Data are bound by confidentiality obligations, receive appropriate privacy and security instruction, and access the data only as needed for their duties.

7BE will apply least privilege and will periodically review access appropriate to risk.

6. Security

7BE will implement and maintain the technical and organizational measures in Schedule 2, taking into account the state of the art, implementation costs, nature and scope of processing, and risks to Data Subjects.

Customer acknowledges that security measures evolve. 7BE may update them if the overall protection is not materially reduced. On reasonable request, 7BE will provide information needed for Customer’s risk assessment, subject to confidentiality and security restrictions.

7. Security Incidents

7BE will notify Customer without undue delay and, where feasible, within 48 hours after confirming a Security Incident. Notice will include available information about the nature of the incident, affected data and Data Subjects, likely consequences, measures taken or proposed, and a contact for follow-up.

7BE will investigate, mitigate, remediate, preserve appropriate evidence, and provide reasonable cooperation for Customer’s notifications and risk assessment. Notice does not admit fault or liability.

Customer is responsible for determining whether to notify authorities or Data Subjects, except where law imposes a direct duty on 7BE. 7BE may provide information in phases as the investigation develops.

8. Data Subject Requests

Taking into account the nature of processing, 7BE will provide reasonable assistance for Customer to respond to requests to access, correct, delete, restrict, object, or port Customer Personal Data.

If 7BE receives a request concerning Customer Personal Data, it will direct the requester to Customer and notify Customer when permitted. 7BE will not respond substantively unless instructed or legally required.

Additional work outside standard Service functionality may be charged at a pre-agreed reasonable rate.

9. Regulatory and Compliance Assistance

Taking into account the nature of processing and available information, 7BE will reasonably assist Customer with data-protection impact assessments, prior consultations, breach obligations, and demonstrated compliance relating to the Services.

7BE will promptly notify Customer of a legally binding request for Customer Personal Data unless prohibited. Where lawful and reasonable, 7BE will challenge an overbroad request and disclose only the minimum required information.

10. Subprocessors

Customer grants general authorization for the Subprocessors on 7BE’s current Subprocessor List. 7BE will require each Subprocessor to protect Customer Personal Data to a standard materially equivalent to this DPA and remains responsible for its Subprocessor’s performance to the extent required by law.

7BE will provide at least 30 days’ advance notice of a new Subprocessor that will process Customer Personal Data, including its function and location. Customer may object during that period on reasonable data-protection grounds. The parties will work in good faith on a commercially reasonable alternative. If none is available, Customer may terminate the affected Service without penalty before the new Subprocessor begins processing and receive a pro-rata refund of prepaid, unused fees for that affected Service.

An emergency replacement needed to maintain security or availability may occur on shorter notice, with prompt information afterward.

11. International Transfers

Customer authorizes processing in the United States and other locations where 7BE and approved Subprocessors operate, subject to this Section.

For a Restricted Transfer of Customer Personal Data from the EEA to 7BE in a country without an adequate level of protection, the parties incorporate the European Commission Standard Contractual Clauses adopted by Decision 2021/914 (“EU SCCs”) as follows:

  • Module Two applies when Customer is a Controller and 7BE is a Processor; Module Three applies when Customer is a Processor and 7BE is a subprocessor;
  • Clause 7 (docking) applies; in Clause 9, Option 2 and a 30-day notice period apply;
  • in Clause 11, the optional language does not apply;
  • in Clause 17, Option 1 applies and the law of Ireland governs;
  • under Clause 18, the courts of Ireland have jurisdiction;
  • Annex I is completed by Schedule 1, Annex II by Schedule 2, and Annex III by the Subprocessor List; and
  • the competent Supervisory Authority is determined under Clause 13.

For transfers governed by the UK GDPR, the EU SCCs are amended by the then-current UK International Data Transfer Addendum, which is incorporated and completed using the information in this DPA. For Switzerland, references are adapted to the Swiss Federal Act on Data Protection and the competent Swiss authority, while preserving Data Subject rights.

If a valid replacement mechanism applies, it will govern to the extent necessary. 7BE will provide information reasonably needed for a transfer impact assessment and supplementary measures.

12. Audits

No more than once annually, and additionally after a material Security Incident or regulator request, Customer may request information reasonably necessary to demonstrate compliance. 7BE may satisfy the request with a current independent audit, certification, questionnaire, or other documentation where sufficient.

If that information is insufficient, Customer may conduct a proportionate audit by an independent, qualified auditor under confidentiality, on at least 30 days’ notice, during normal business hours, without accessing other customers’ data or creating security risk. Customer bears its audit costs unless the audit identifies a material breach by 7BE, in which case 7BE bears reasonable audit costs.

13. Return and Deletion

During the term, Customer may export Customer Personal Data through available functionality or an agreed process. On completion or termination of the relevant Project or Service, 7BE will return or delete Customer Personal Data according to Customer’s instruction, unless law requires retention.

Unless a Project Order states a shorter period, 7BE will delete raw Verification Data and temporary production extracts within 30 days after final Project resolution. Residual encrypted backups will expire through the ordinary backup cycle within 90 additional days and remain protected and unavailable for ordinary use.

7BE may retain the Project Order, outcome, payment instruction, security record, and limited evidence necessary for legal claims, fraud prevention, tax, audit, or compliance, but will minimize or redact personal data and restrict use. On request, 7BE will confirm completion of deletion.

14. US State Privacy Terms

To the extent the CCPA applies, 7BE acts as a Service Provider or Contractor for Customer Personal Data. The parties acknowledge the restrictions in Section 3. 7BE will notify Customer if it determines it can no longer meet its obligations. Customer may take reasonable steps to stop and remediate unauthorized use, including proportionate assessment rights under Section 12.

For other US state privacy laws, 7BE will comply with applicable processor duties concerning instructions, confidentiality, security, subprocessors, rights assistance, assessments, and deletion. Customer and 7BE will each comply with duties applicable to their role.

15. Liability, Term, and Conflict

This DPA continues while 7BE processes Customer Personal Data. Liability under this DPA is subject to the Agreement’s exclusions and limitations to the extent permitted by Applicable Data Protection Law. Nothing limits Data Subject rights or regulatory powers that cannot lawfully be limited.

If this DPA conflicts with the Agreement regarding Customer Personal Data, this DPA controls. The EU SCCs control over both where required.

16. Contact

Data-protection notices and requests: privacy@7be.io

7BE Inc.
Attn: Privacy
2055 Limestone Road, Suite 200-C
Wilmington, Delaware 19808, USA

Schedule 1 — Processing Details

A. Parties

Data exporter / Customer: The entity identified in the Agreement or Project Order, at the address and with the contact stated there. Activities: use of the Services and submission of Customer Personal Data. Role: Controller or Processor as applicable.

Data importer / 7BE: 7BE Inc., address above; privacy@7be.io. Activities: marketplace, project administration, payment coordination, support, security, and Verification. Role: Processor or subprocessor.

The parties’ acceptance of the Agreement constitutes signature of the incorporated transfer clauses.

B. Processing

Subject matter and nature: Hosting, transmission, organization, retrieval, analysis, testing, comparison, support, security, deletion, and other processing necessary to provide the contracted Services and perform Verification.

Purpose: To administer the Project or Services, apply Verification Criteria, support Users, protect systems, and follow Customer’s documented instructions.

Duration: The term of the affected Service or Project plus the deletion and legally required retention periods in this DPA.

Data Subjects: Customer personnel, users, clients, prospects, vendors, contractors, website users, or other individuals whose data Customer is authorized to provide and who are described in the Project Order.

Categories of Personal Data: Business identifiers and contacts; account and access data; communications; usage and event data; transaction references; prompts and outputs; test datasets; model, system, and performance logs; and other categories expressly described in the Project Order.

Sensitive Data: Not permitted by default. If expressly authorized, the Project Order must identify the categories, necessity, legal basis, restrictions, and safeguards. Credentials and financial-account access must be handled through approved secure methods.

Frequency: Continuous or episodic as initiated by Customer during the Service or Project.

Subprocessor transfers: As necessary for the functions and locations in the current Subprocessor List, subject to Section 10.

Schedule 2 — Technical and Organizational Measures

7BE maintains measures appropriate to the applicable risk, including:

  • documented security ownership, risk review, and personnel confidentiality;
  • role-based and least-privilege access, unique accounts, privileged-access controls, and multi-factor authentication where appropriate;
  • encryption in transit using current secure protocols and encryption at rest where supported by the relevant system;
  • restricted production access and logical separation of customer records;
  • secure credential and secret storage, rotation, and revocation;
  • change review, code review, dependency management, testing, and controlled deployment for material systems;
  • logging and monitoring of authentication, privileged actions, errors, and material security events;
  • vulnerability intake, prioritization, remediation, and disclosure handling;
  • encrypted or otherwise protected backups, restoration procedures, and continuity planning proportionate to the Service;
  • incident detection, containment, investigation, communication, and improvement;
  • vendor due diligence, contractual data-protection terms, and Subprocessor change management;
  • data minimization, retention controls, secure deletion, and restricted legal-hold procedures;
  • physical and environmental protections inherited from vetted hosting providers; and
  • periodic review and improvement of safeguards based on material changes and risk.
7BE

Kaufen Sie geprüfte KI-Ergebnisse, keine Versprechen. Sie definieren das Ergebnis, wir beweisen, dass es funktioniert, und Sie zahlen erst, wenn es das tut.

447 Broadway, 2nd Floor
New York City, NY10013
Über unsHilfecenterBlogSitemapKontakt
FallstudienKI-SDR-PipelineKI-Support-AgentEinen 40.000-$-KI-Fehlschlag vermeiden
MarktplatzGeprüfte Aufträge ansehenEntwicklungDesignMarketingBusinessKI
Für KundenWarum 7BE für Kunden?Wie funktioniert es?Wie bewertet 7BE Agenturen?Warum KI-Projekte scheitern
Für AgenturenWarum 7BE für Agenturen?Preise und OptionenZertifizierung

© 2026 7BE Inc. Alle Rechte vorbehalten.

EnglishDeutsch
DatenschutzrichtlinieNutzungsbedingungenRechtliches