Data Processing Addendum

Version 2.1 · effective 2026-07-27 · in force

This Data Processing Addendum (the "DPA") forms part of the Terms of Service & Acceptable Use (the "Terms") between RunMyB, Inc., a Delaware corporation ("RunMyB", "we"), and the customer holding the account under the Terms (the "Customer", "you"). It applies wherever RunMyB processes personal data on the Customer's behalf within the scope of Regulation (EU) 2016/679 (the "GDPR") or equivalent data-protection law. Terms defined in the GDPR (controller, processor, personal data, personal data breach, and so on) have the same meaning here.

1. Scope and roles

RunMyB acts in three distinct capacities:

  1. RunMyB as independent controller. For the platform's own account, identity, billing, credit-ledger, and security/operational data — the direct relationship between RunMyB and the people who use the platform — RunMyB is an independent controller. This DPA does not govern that processing; it is described in the Privacy Policy.
  2. RunMyB as the Customer's processor — end-user data. For personal data that the Customer's applications, ventures, and workspaces process about the Customer's own end-users, the Customer (or the Customer's own client) is the controller and RunMyB is the Customer's processor. RunMyB processes that data only to provide the service, on the Customer's documented instructions.
  3. RunMyB as the Customer's processor — team-member workspace data. Where the Customer admits employees, contractors, or other collaborators to its account, the Customer is the controller of the team-workspace data about those people and RunMyB is the Customer's processor: the Customer's administrators decide admission, roles, disablement, and — through the platform's affordances — what is retained, and RunMyB processes on those instructions.

Boundary with RunMyB's own controllership. Even within a Customer's team, RunMyB remains an independent controller — not the Customer's processor — for each member's own legal-acceptance and consent records, login identity, and the platform's security and operational logs: compliance evidence RunMyB must keep in its own right, recorded append-only.

Capacities 2 and 3 together define the "Customer Personal Data" this DPA governs.

2. Details of processing

3. Processor obligations (Article 28(3) GDPR)

RunMyB will:

4. Sub-processors

Authorization and the published list. The Customer grants RunMyB general written authorization to engage the sub-processors below. Each is engaged under the provider's standard data-protection terms, which impose data-protection obligations consistent with this DPA; RunMyB remains liable to the Customer for its sub-processors' performance. The table in this document is the published sub-processor list:

Sub-processorFunctionNotes
Amazon Web Services (AWS)Cloud infrastructure and hostingCompute, storage, database, and networking for the hosted platform
Anthropic PBCAI model providerRuns the AI assistants and build agents that process workspace content
Neon, Inc.Hosted-product databasesAn isolated, dedicated Postgres database (one Neon project per product) for each data-bearing Customer product, holding that product's data, including any personal data the product processes (US region)
Stripe, Inc.Payments and billingPartially an independent controller for payment data (card data is collected and held by Stripe, not RunMyB)
Cloudflare, Inc.DNS and edge servicesDomain name resolution and edge delivery; no workspace content
Google LLCVoice-dictation transcription relayEngaged only when the Customer uses the voice-dictation feature; audio is relayed under RunMyB's own key and the browser never holds that key
OpenRouter, Inc.Auxiliary AI model routingEngaged for platform-side engine tasks where a platform role is configured to route through it
Zoho CorporationE-mail correspondenceMailboxes for the platform's support, privacy, and legal contact addresses (EU data centre)

Changes to the list. RunMyB will give at least 30 days' advance notice of the addition or replacement of a sub-processor by updating the published list in this document and recording the change in this document's changelog, which is the notice mechanism. In addition, once the platform operates its transactional mailer, sub-processor changes will also be notified by e-mail to the Customer's administrators — a strengthening of the notice mechanism, stated now and effective when that mailer operates. The Customer may object on reasonable data-protection grounds within 14 days of the notice; the parties will then discuss in good faith. If the objection cannot be resolved, the Customer's remedy is to stop using the affected feature or terminate the affected service or account before the change takes effect; continued use after the change takes effect constitutes acceptance of the new sub-processor.

Services the Customer connects are not sub-processors. Services that the Customer connects to its account under the Customer's own credentials or authorization — git providers, Google Drive, Gmail, and Google Calendar via the Customer's OAuth grant, Trello, Notion, and AI providers used under the Customer's own keys — are recipients chosen and instructed by the Customer, not RunMyB sub-processors. RunMyB transmits data to them only at the Customer's direction, within the scope the Customer authorized; the Customer's own relationship and terms with each such service govern that processing. The team feature introduces no additional sub-processor: team-member data rides the same infrastructure listed above.

5. International transfers

Processing takes place in the United States: the platform's cloud infrastructure (AWS), the hosted-product databases (Neon), the AI providers (Anthropic, OpenRouter), and the payment processing (Stripe) all process there. The one EU exception is e-mail correspondence: Zoho hosts the platform's mailboxes in an EU data centre (with the Clauses below covering any extra-EEA access). For personal data subject to the GDPR, the UK GDPR, or the Swiss FADP, transfers to RunMyB and onward to its sub-processors are protected as follows:

6. Technical and organisational measures

RunMyB implements the following measures for Customer Personal Data:

RunMyB reviews and updates these measures as the platform evolves; changes will not materially reduce the overall level of protection.

7. No use of Customer Data for AI/ML training

Stated in its own clause so it is findable: RunMyB does not use Customer Personal Data — or Customer content more broadly — to create, train, or improve any machine-learning or artificial-intelligence model, whether RunMyB's own or a third party's, and does not permit its sub-processors to do so on RunMyB's behalf. This restates, in one place, what Section 2 of this DPA and Section 10 of the Terms of Service & Acceptable Use already provide; it would not change without the Customer's express opt-in.

8. Liability

Each party's liability arising out of or related to this DPA, including under the Standard Contractual Clauses, is subject to the exclusions and limitations of liability set out in the Terms of Service & Acceptable Use, except where the Standard Contractual Clauses or applicable data-protection law provide otherwise. Nothing in this DPA or the Terms limits either party's liability toward data subjects or supervisory authorities where such liability cannot lawfully be limited.

9. Precedence and duration

This DPA forms part of the Terms. In the event of a conflict concerning the processing of personal data, this DPA prevails over the Terms, and the Standard Contractual Clauses prevail over this DPA for the transfers they govern. This DPA takes effect with the Terms and remains in force for as long as RunMyB processes Customer Personal Data, surviving termination of the Terms until that processing ends under Section 3(g).

Version history (the document's changelog)

1.0 — initial draft outline. 2.0 — the operative tenant-facing DPA replacing the 1.0 outline: full Article 28(3) obligation set, processing details, published sub-processor list with change-notice and objection mechanics, technical and organisational measures annex, SCC/DPF transfer terms; the employee/team-member (third-hat) rider folded in; final in-force edition (0529). 2.1 — corrections and strengthenings (non-material for the Customer; effective on posting): Neon, Inc. added to the Section 4 sub-processor table — this corrects an omission: the vendor was already in use for hosted-product databases and should have been listed when that feature went live; the Section 4 notice-and-objection machinery applies to this addition from this posting; the Section 5 processing-locations statement corrected to name locations truthfully and to cover Neon (SCCs); the Section 6 tenant-isolation measure restated accurately (RLS on tenant-scoped tables, role-scoped grants on platform-owned registers) and the annex extended with the verifiable backup, IAM, and change-control measures; Section 3(f)'s self-imposed 48-hour figure re-expressed as a stated aim inside the without-undue-delay duty, with the Customer's 72-hour window expressly protected; Section 4 commits to additional e-mail notice of sub-processor changes once the platform operates its transactional mailer; Section 3(e) carves out the categories where RunMyB is independent controller; the no-AI-training commitment promoted into its own headed clause (Section 7).