Bench
BLOGTALK TO FOUNDERS

BENCH LEGAL

DATA PROCESSING AGREEMENT

LAST UPDATED 19 SEPTEMBER 2026 · VERSION 2026-09-19.1

Before connecting personal data

These terms describe the data processing agreement for Bench business customers. An effective agreement consists of these terms, the applicable service agreement, and completed processing, security and subprocessor schedules accepted by both parties. Reading this page or acknowledging a connection notice does not, by itself, complete that agreement.

Before providing personal data, request your completed agreement and deployment-specific schedules at privacy@usebench.ai. Until then, use synthetic or non-personal test data. Do not include secrets, payment-card details, health information or other sensitive personal data without an expressly agreed scope and safeguards.

1. Parties and roles

The processor is BENCH UG, Jachenauerstr 17, 81369 Munich, Germany, as identified in our imprint. The customer is the entity identified in the service agreement. The customer determines the purposes and means of processing its personal data. Bench acts as its processor, or subprocessor where the customer itself acts for a controller.

These terms apply to personal data processed on the customer's behalf through Bench. Processing for Bench's own account administration, billing and website purposes is addressed separately in the Privacy Policy.

2. Purpose, scope and duration

Bench processes authorized repositories, prompts, context documents, selected datasets and connected execution records to identify AI systems, prepare criteria and test cases, evaluate behavior, compare prompt or model candidates and provide findings for customer review. Relevant content may be sent to the model providers included in the agreed processing schedule.

Processing operations can include collection, transfer, organization, storage, analysis, inference, evaluation, retrieval, export and deletion. Processing lasts for the service term and the deletion or return period agreed in the schedule, subject to legal retention requirements.

The schedule must identify the relevant data subjects and data categories for the actual use case, including whether employees, end users or customers appear in repository metadata, conversations, documents or labels. Special-category data and criminal-offence data are excluded unless specifically agreed with suitable safeguards.

3. Documented instructions and customer responsibilities

Bench shall process customer personal data only on documented instructions, including authorized configuration and source selection, unless legally required otherwise. Bench shall notify the customer of such a legal requirement before processing unless the law prohibits notification, and shall inform the customer immediately if an instruction appears to infringe applicable data protection law.

The customer is responsible for the legal basis, notices, necessary authorizations, accuracy and minimization of the data it provides. Source-connection authorization is not consent from the individuals whose data may be contained in that source. Connecting a repository does not authorize Bench to deploy changes or merge code.

Use for unrelated purposes or model training is not authorized by these terms. Any such use would require a separate valid legal basis and agreement. Provider-specific retention and processing terms must be recorded in the completed schedule.

4. Confidentiality and security

Bench shall ensure that authorized personnel are subject to confidentiality obligations and have access only as required for their duties. Bench shall implement and maintain appropriate technical and organizational measures under Article 32 GDPR, taking account of the nature of the data, processing risks and the state of the art.

The agreed security schedule must describe access controls, tenant separation, credential management, encryption and key management, logging, resilience, recovery, incident response, retention and deletion procedures, and regular effectiveness testing. This page is not an assertion of a certification, a completed security audit, exclusive EU hosting or a verified control that is not listed in that schedule.

5. Subprocessors

Bench shall engage subprocessors only under the customer's prior specific or general written authorization. The completed subprocessor schedule must identify each legal entity, service, processing purpose, data involved, processing locations and applicable transfer mechanism. Under general authorization, Bench shall provide at least 30 days' advance notice of proposed additions or replacements, giving the customer an opportunity to object on reasonable data protection grounds before access is granted.

The parties shall work to resolve an objection. If no compliant alternative is agreed, the affected processing must not begin or must be suspended; the customer may terminate the affected service without penalty for that termination. Bench shall impose equivalent data protection obligations on subprocessors and remain responsible for their performance as required by Article 28 GDPR.

6. International transfers

Personal data may be transferred outside the EEA only where an applicable Chapter V GDPR mechanism and any necessary supplementary measures are in place. The schedule must identify destinations, recipients and safeguards. Where standard contractual clauses are needed, the appropriate European Commission clauses and completed annexes must be agreed before the transfer. These terms alone do not complete those clauses or authorize an unspecified destination.

7. Rights and regulatory assistance

Taking account of the nature of processing and information available, Bench shall assist the customer with data-subject requests, security obligations, personal-data breach assessments, data protection impact assessments and prior consultation with supervisory authorities. Bench shall forward requests concerning customer-controlled data to the customer without undue delay and shall not independently determine their outcome unless legally required.

8. Personal-data breaches

Bench shall notify the customer without undue delay after becoming aware of a personal-data breach affecting data processed on the customer's behalf. Notification shall include available information about the nature and scope of the breach, likely consequences, contact point and measures taken or proposed. Information may be provided in phases as the investigation proceeds.

Bench shall cooperate with the customer's response and reporting obligations. The controller's statutory notification deadline does not grant Bench a waiting period before notifying the customer.

9. Return, deletion and retention

At the customer's choice, Bench shall return or delete customer personal data when the relevant processing services end, and delete existing copies unless applicable law requires retention. The completed schedule must specify export arrangements, active-storage deletion times, backup expiry, applicable legal exceptions and verification of deletion. Disconnecting a source stops access but is not a promise that all prior records, evaluation artifacts or backups have already been erased.

10. Demonstrating compliance and audits

Bench shall make available the information necessary to demonstrate its Article 28 obligations and allow and contribute to audits, including inspections, by the customer or its mandated auditor. Reasonable confidentiality, security and scheduling arrangements may be agreed but must not prevent statutory rights, necessary incident-related checks or supervisory-authority access.

11. Governing law and precedence

German law applies, subject to mandatory European and national data protection law. This agreement prevails over conflicting service terms concerning customer personal-data processing. Applicable standard contractual clauses prevail where required. Nothing limits data subjects' statutory rights or supervisory authorities' powers.

12. Obtain your completed schedules

Contact privacy@usebench.ai with your organization and intended sources. The agreement must include the customer identity and authorized representatives, processing description and duration, data categories and subjects, technical and organizational measures, retention and deletion arrangements, subprocessors, and any international transfer documentation.

A contract and an acknowledgment are only part of data protection compliance. The controls, lawful basis and operating practices must also be implemented and verified for the actual deployment.

Bench

HIGHER QUALITY, LOWER COST

© 2026 BENCH
COMPANYABOUT USBLOGHOW IT WORKSTALK TO FOUNDERS
LEGALIMPRINTPRIVACY POLICYDATA PROCESSINGTERMS AND CONDITIONS
FOLLOWXLINKEDININSTAGRAM