Last updated July 2026
Data Processing Agreement
This document is a working draft under founder review. It is not legal advice and is not yet a binding legal notice. It will be finalised before Bureau Audit is offered to paying customers.
This Data Processing Agreement (“DPA”) governs Bureau’s processing of personal data on behalf of a client organisation using Bureau Audit, under Article 28 of the EU General Data Protection Regulation (GDPR). It forms part of the agreement between the Client and Pillet Grenié Bureau (“Bureau”).
For the audit responses of the Client’s employees (“participants”), the Client is the controller and Bureau is the processor. A signable copy can be provided on request. See also the Privacy Policy and Terms of Service.
1.Roles & instructions
The Client determines the purposes and means of processing participant data and is the controller. Bureau processes that data only as a processor and only on the Client’s documented instructions — including the configuration of the audit, the templates enabled, and any transfer of data — unless required otherwise by law, in which case Bureau will inform the Client (unless legally prohibited).
2.Scope of processing (Annex I)
- Subject matter & duration: running organisational audits for the term of the agreement, plus the retention periods below.
- Nature & purpose: collecting employee responses, AI-assisted analysis, and reporting.
- Categories of data subjects: the Client’s employees who take part in an audit.
- Types of personal data: free-text responses; optional voice recordings and their transcripts; AI-generated individual profiles; the participant’s first name, last initial, and department; demographic bands; and a hashed cross-audit identity key (see section 4). On wellbeing-template audits, responses may include information about the participant’s mental wellbeing.
Because wellbeing-template audits can surface data concerning health, the Client should confirm its own lawful basis and safeguards before enabling that template.
3.Confidentiality
Bureau ensures that personnel authorised to process participant data are bound by confidentiality and process it only as needed to provide the service.
4.Security measures (Annex II, Article 32)
Bureau applies the following technical and organisational measures. Each is implemented in the platform today:
- Access control & tenant isolation: row-level security is enabled on every database table, with three separated database roles; organisation data is isolated by an organisation identifier.
- Identity handling: access PINs are hashed with bcrypt and never stored in plaintext. To recognise the same participant across audits in a campaign without storing an email, a per-campaign identity key is derived with SHA-256 and stored only as a hash. A participant’s first name, last initial, and department are stored in order to run the audit and to render the controller’s own results.
- Voice recordings: stored in a private storage bucket accessible only server-side via a service role; never publicly listable.
- k-anonymity gate: aggregated reporting (quotes and band-level statistics) is served only through a database view that suppresses any band with fewer than a configured floor of distinct participants — five by default, and lower only for a Bureau-managed, hand-delivered engagement under that engagement’s terms.
- Encryption in transit for all connections; secrets held as environment secrets, not in code.
- Input validation & sanitisation at every API boundary (identifier, MIME, size, and control-character checks).
- Rate-limiting (Upstash Redis) to mitigate abuse and enumeration.
- Error monitoring privacy posture: the monitoring SDK runs with personal-data capture disabled and strips request bodies, cookies, and authorization headers before any event is sent; only identifiers/enums are attached as tags.
- Data residency: personal data is stored in the EU (Frankfurt).
Automated enforcement of the retention schedule (section 7), including scheduled deletion of raw voice recordings, is being implemented; until then, deletions are performed through a documented internal procedure. commitment
5.Subprocessors (Annex III)
The Client grants a general authorisation for Bureau to engage the subprocessors below for participant data. Bureau imposes data protection obligations on each subprocessor no less protective than this DPA.
| Subprocessor | Purpose | Region |
|---|---|---|
| Supabase | Database, authentication, and private storage of voice recordings — stores all participant data. | EU (Frankfurt) |
| Vercel | Application hosting and serverless compute. All processing transits Vercel. | EU (Frankfurt) |
| Anthropic (Claude) | AI analysis of responses into individual profiles; question generation. | United States † |
| OpenAI (Whisper) | Speech-to-text transcription of participant voice recordings. | United States † |
| Upstash (Redis) | Rate-limiting counters (participant identifiers used only as counter keys). | EU |
| Resend | Delivery of report-ready and wellbeing-escalation emails (finding identifiers only, no response content). | EU-routed † |
| Sentry | Error monitoring — identifiers/enums only, request bodies, cookies and auth headers stripped before send. | EU (Frankfurt) |
| Inngest | Orchestration of the AI analysis pipeline (event identifiers only). | Being formalised † |
Regions marked “†” involve processing outside the EU, or a region / transfer safeguard still being confirmed (see section 6). Additional providers are used for functions that do not process participant response data: Google (administrator sign-in only), Stripe (billing — dormant during early access), and an internal Bureau operations database used for cost/status monitoring, which the Audit application only reads from.
Change notification
Bureau will inform the Client of any intended addition or replacement of a subprocessor with reasonable notice, giving the Client the opportunity to object on reasonable data-protection grounds.commitment
6.International transfers
Personal data is stored in the EU (Frankfurt). Some subprocessors that process data on Bureau’s behalf are established in the United States (Anthropic, OpenAI, Inngest) or route through non-EU infrastructure; such transfers rely on the transfer safeguards in each provider’s data processing terms (such as Standard Contractual Clauses). Bureau is finalising and documenting these safeguards. commitment
The Bureau contracting entity is established in the United Arab Emirates. Where Bureau processes the data of EU-based participants as a processor established outside the EU, Bureau will assess and, if required, appoint a representative in the EU under Article 27 GDPR. This point should be confirmed with qualified counsel before onboarding an EU-based client. commitment
7.Retention
Unless the Client instructs a shorter period, Bureau applies:
- Raw responses: 18 months. commitment
- Findings and verdicts: audit programme lifetime + 24 months. commitment
- Aggregated, k-anonymised results: retained indefinitely (no individual data). commitment
- Raw voice recordings: deleted 30 days after transcription; transcripts follow the response-retention rule. commitment
- Erasure log: 3 years. commitment
8.Assistance with data-subject rights
Bureau assists the Client, by appropriate technical and organisational measures, in responding to participants’ requests to access, rectify, erase, or receive a copy of their data. Because no self-service participant tooling exists yet, requests are handled through a documented procedure: the Client contacts tom@pilletgreniebureau.com and Bureau executes a verified erasure or export. Erasure nullifies the participant’s text responses, cascades to derived quotes, and removes voice files through the storage API; k-anonymised aggregates are retained. commitment
9.Personal data breach
Bureau will notify the Client without undue delay after becoming aware of a personal data breach affecting participant data, with the information the Client reasonably needs to meet its own notification obligations.
10.Return or deletion at end of processing
On termination, and at the Client’s choice, Bureau will return or delete participant personal data, including voice files (removed through the storage API), subject to any retention required by law.commitment
11.Audits & demonstrating compliance
Bureau will make available to the Client the information reasonably necessary to demonstrate compliance with this DPA, and will contribute to audits or inspections as reasonably requested, subject to confidentiality and the security of other clients’ data.
12.Precedence & contact
This DPA prevails over conflicting data-protection terms in the agreement. Contact: tom@pilletgreniebureau.com.
The Bureau processor entity is Pillet Grenie Bureau L.L.C-FZ, a Free Zone Limited Liability Company registered in the Meydan Free Zone, Dubai, U.A.E. (formation no. 2647815; registered address: Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, U.A.E.). Signature blocks for the Client and Bureau are added on execution.