The Article 28 contract that governs the personal data barua holds on your behalf. It is part of the terms of service, it applies automatically, and it wins over every other document of ours on any question about personal data.
Status: draft 1.0, version , prepared 30 August 2026. Not in force. Want it countersigned on paper? Write to chris@barua.ai and you will get a PDF back.
For everything barua captures on your site and everything it derives from that, you are the controller and barua is your processor. Your visitors are yours. You decide why the data is collected and what is done with it. barua acts on your instructions.
For one narrow set of data, barua is the controller in its own right: your account, who is on it, what you were billed, and the operational record of how the service ran. That is covered by the privacy page rather than by this agreement.
Where barua uses another company to do part of the job, that company is a subprocessor and barua stays answerable to you for it.
Annex 1 sets out the subject matter, the duration, the nature and purpose, whose data is involved, and what kinds of data. The short version: behaviour on your site, the contact details people hand over, what barua derives from both, and the record of what was sent.
barua processes that data only to run the service for you, and only on your documented instructions. Your instructions are: this agreement, the terms of service, the settings you choose in the app, and anything else you tell us in writing. If we ever think an instruction breaks data protection law, we will tell you rather than quietly follow it.
barua does not use your data for its own purposes. Specifically, and this is a commitment rather than a description: barua does not train models on it, in any form, including aggregated or de-identified, and neither do the model providers barua uses, who are barred from it by contract. barua does not combine your data with another customer's, does not sell it, and does not share it with data brokers.
Only people who need access to run the service have it, they are bound to keep it confidential, and the obligation survives them leaving. barua is a small company, so that set is small, and access is through the same controls described in Annex 2 rather than a side door.
barua keeps appropriate technical and organisational measures in place, taking account of what the processing is and what could go wrong for the people in it. What those measures are today is written out in Annex 2, honestly, including what barua does not have.
Measures change as the service does. They will not get weaker.
You give barua general authorisation to use subprocessors. The current list, with what each one does and where, is at barua.ai/subprocessors.
barua gives you at least 15 days' notice by email before a new subprocessor starts. You can object on reasonable data protection grounds within those 15 days. If we cannot resolve it, you may end the affected part of the agreement without penalty and get back the unused part of what you paid.
Every subprocessor is under written terms at least as protective as this agreement, and barua remains fully liable to you for what they do.
Requests come to you, because you are the controller. If one comes to us instead, we pass it to you and do not answer it ourselves, beyond telling the person to talk to you.
barua helps you answer, and the help is built rather than promised:
One record is deliberately kept when someone is erased: the suppression entry holding their address, so that the request to be left alone can be honoured. It is kept for that purpose alone. Nothing else about them survives once it has finished, and that includes delivery records filed under a different spelling of the same address, which erasure matches the same way it finds the person.
One case where "finished" is doing work: the rows go in one transaction, then the stored replay files are removed separately. If that second step fails, the rows are already gone and the automatic sweep can no longer find the files, so they are reported by name for an operator to remove by hand. Until that happens the erasure is incomplete, and we treat an unfinished one as open rather than done.
barua gives you the information you reasonably need for a data protection impact assessment or a prior consultation with a supervisory authority, and helps you deal with a regulator's questions about processing barua does for you. Ask, and you get a real answer rather than a brochure.
If barua becomes aware of a personal data breach affecting your data, we tell you without undue delay, and in any case within 48 hours of becoming aware. The first message tells you what we know, which is often not much, and we keep telling you as we learn more.
We give you what you need to notify your regulator and the people affected, and we do not notify them on your behalf unless you ask us to. We do not wait until an investigation is finished before telling you it started.
While the agreement runs, the retention rules in Annex 4 apply and run automatically.
When it ends, you have 30 days to ask for a copy of your data, and we delete everything within 30 days of the end. Tell us if you need longer to get your data out and you will have it.
Backups are a separate thing, and we will not put a number on them we cannot show you. They are taken and aged out by our database provider on its own schedule rather than ours, so a deleted row can persist in a backup until that schedule reaches it. A backup is never restored into the live system except to recover from a failure, and if that happened the deletion would be reapplied. Ask and we will tell you the provider's current retention.
Two things are held back from that deletion, and they are the only two. Records the law requires us to keep, which is mainly the accounting trail. And suppression entries, which hold an address that asked never to be written to again: deleting one would mean losing the only proof that the request was made, so they are kept under Article 17(3) for that purpose and used for nothing else. Ask and we will delete them too, and you accept what that means.
barua gives you the information you need to show that this agreement is being complied with, and allows an audit once a year, or after a breach, or when a regulator requires one.
In practice we would rather answer your questionnaire and walk your engineers through the system than have you send auditors, and for most customers that is enough. barua does not hold a SOC 2 report or an ISO 27001 certificate, and this page will not imply otherwise until it does. If you need one to buy, tell us, because that changes what we build next.
An on-site audit needs two weeks' notice, happens in working hours, does not disrupt the service, and is at your cost.
Where barua transfers personal data outside the EEA, it does so under the European Commission's standard contractual clauses or another mechanism the law recognises. Annex 3 says which applies to whom. By accepting this agreement, you and barua enter into those clauses for the transfers described there, with barua acting on your behalf towards its subprocessors.
This agreement lasts as long as barua processes personal data for you. On any conflict about personal data it beats the terms of service and the privacy page. Where standard contractual clauses apply, they beat this agreement.
Liability under this agreement is subject to the cap in the terms of service, except where the law says a cap cannot apply. Norwegian law governs it, and the Oslo District Court is the venue, unless the standard contractual clauses require somewhere else.
Processing personal data about your site's visitors and customers so that barua can build a profile of each person, decide whether a message would help them, write it, and send it once you approve. It runs for as long as your account is open, plus the deletion window in clause 9.
People who visit a website you run with the barua tag installed. Depending on your business that means prospective customers, customers, trial users, and account holders on your product.
| Category | What it is |
|---|---|
| Identifiers | An anonymous id for the browser, a session id, and where you supply one, your own customer id |
| Contact details | Email address, and where handed over, first name, last name and phone number |
| Masked session replay | A recording of the visit with every input value and every piece of rendered text replaced in the browser before it is sent |
| Behaviour | Pages seen and for how long, clicks and the labels on what was clicked, scrolling, page titles, product names and prices, cart and order events your site publishes, and script errors |
| Device and browser | Window size, whether it is a phone, tablet or desktop, whether the screen is touch, the browser's language, and its timezone |
| How they arrived | The full referring address including its path, scrubbed and
capped at 300 characters, a label for what kind of source it was, the landing path, the
utm_ parameters, and click identifiers from a fixed list |
| On-site search | What someone searched for on your site, read from the URL and capped at 120 characters |
| Approximate location | Country code, country name, region and city, resolved at the network edge. The IP address itself is never stored |
| Household | Where two identified people use the same device, barua infers that they share one and records the link. A person's profile then carries the other people's email addresses, and those travel with it to the model provider that writes the message. Nothing else of theirs does, and the composer is instructed never to write a sentence that depends on the other person's activity |
| Derived profile | What barua concluded from the above: durable facts about the person, a narrative of each visit, and where they got to in your funnel |
| Messaging record | What was decided and why, what was drafted, what was sent, what happened afterwards, and whether the person is suppressed |
| Email click reports | Where a site reports an email-link visit from its own server, so a click still counts when the tag never ran: one scrubbed page address with a time, plus the token from the link. The token carries no name, and it is what ties the click to the message that caused it, so the report resolves to the person who was written to |
barua is not built to process special-category data and asks you not to send it. The acceptable use policy explains how it can still arrive by accident. Every field the pixel keeps in the clear is a route: a page title, a product name, the label on a control someone clicked, and what they typed into the site's own search. A search is the sharpest of them, because it is the visitor's own words rather than the site's.
Capture is continuous while a visitor is on your site. The pipeline runs on a schedule, at least daily.
What is actually in place today. Nothing here is aspirational.
data-cg-block leaves only an empty placeholder.No SOC 2 report, no ISO 27001 certificate, no completed third-party penetration test, and no 24/7 security operations team. barua is early, and this annex will grow. It will not claim something before it is true.
| Where | What goes there | Mechanism |
|---|---|---|
| United Kingdom database, storage, all pipeline compute |
Everything barua holds for you | The European Commission's adequacy decision for the United Kingdom, renewed 19 December 2025 and running to 27 December 2031. An adequacy decision needs no clauses and no transfer assessment; if it were ever withdrawn we would move the data or fall back to standard contractual clauses, and tell you before either |
| United States database support access |
Whatever a support engineer needs to see to fix a database problem, which can be any of the stored data. It is not routine and it is not bulk | Our database provider's own transfer terms, which the subprocessor list names |
| United States Anthropic, deciding and writing |
The distilled profile and the brand information needed to decide on a message and write it, never the raw replay | Standard contractual clauses, modules two and three |
| United States OpenAI, the monthly learn |
The monthly summary of the site described in the subprocessor list | Being confirmed. We have verified the mechanism for the provider above and not yet for this one, and would rather say so than name a safeguard we have not read |
| United States delivery provider |
The recipient's address and the message itself, plus delivery events | Standard contractual clauses, or the provider's certification under an approved framework |
Where a transfer runs on standard contractual clauses, barua has carried out a transfer impact assessment and will share it on request. The UK addendum applies where UK data protection law governs the transfer.
| What | How long | Why that long |
|---|---|---|
| Session replays | 30 days is when a replay becomes due for deletion, and the sweep that
removes it runs hourly |
Long enough to understand a visit, short enough that a recording is not a standing liability. The limit is a ceiling in code, so a misconfiguration cannot extend it. Being honest about the rest: the sweep is bounded per run, so a large backlog or a failing storage call leaves a replay past 30 days until a later run reaches it. Failures are recorded and alerted rather than passed over |
| Activity log | While your account is open, with a fixed maximum age being introduced | It is what a profile is rebuilt from. The maximum age lands here before this agreement comes into force |
| Profiles and derived facts | While the person exists on your account | This is the thing barua writes from. Deleted when they are erased or the account closes |
| Messaging record | While your account is open | It is how repeat messages are prevented, how the control group stays honest, and how you can see why something was sent |
| Suppressions | Indefinitely, per account | An address that asked to be left alone can only be kept off future sends by remembering it. It holds the address and nothing else |
| Email click reports | Until the person is erased | They exist to count a click against the message that caused it, so they live as long as the person does. Erasing someone removes the reports their clicks created |
| Sending traces | About 2 days | Short-lived operational rows that space outgoing mail. They clear themselves |
| Forwarded template emails | About 3 days at the delivery provider. Our own copy is kept until you ask us to delete it, and a fixed window is being introduced | The message is stored so the layout can be pulled out of it and pulled out again when the template changes. There is no automatic purge yet, which is why this row says so rather than naming a number the code does not enforce |
An anonymous visitor who never identifies themselves has no contact details on record at any point, so nothing that outlives the 30-day replay expiry can be used to reach them. What does outlive it is the anonymous browser id, the session rows, the activity log, and the profile written from them. Those have no age-based purge today, which is the same gap as the activity log above and is fixed by the same work.