Europe Data Processing Addendum
Updated August 19, 2026
Builder.io, Inc.
European Data Processing Addendum
Effective upon execution of the applicable SaaS Services Agreement or Order Form
This Data Processing Addendum - Europe (the "Addendum") between Builder.io, Inc. ("Builder.io") and the customer accessing or using the Services (the "Customer") is incorporated into the SaaS Services Agreement located at builder.io/legal/terms (if applicable) or such other commercial agreement between Builder.io and the Customer. This Addendum applies with respect to the provision of the Services to Customer where the Processing of Customer Personal Data is subject to European Data Protection Legislation. Builder.io may revise and update this Addendum from time to time when required by applicable law. All changes are effective within 30 days after posting and will apply to all access to and use of the Services thereafter.
§1 Definitions
"Customer Personal Data" means the Personal Data described under Section 2 of this Addendum that is protected under European Data Protection Legislation, in respect of which the Customer is the Controller.
"European Data Protection Legislation" means, as applicable: (i) GDPR; (ii) the EU e-Privacy Directive (Directive 2002/58/EC); (iii) all national implementations of (i) and (ii); (iv) the Swiss Federal Act on Data Protection, as revised, and its corresponding ordinances; (v) in respect of the United Kingdom, the UK GDPR and the Data Protection Act 2018; and (vi) any other laws applicable to the EEA, United Kingdom, or Switzerland relating to the processing, privacy, and use of personal data, in each case as may be amended, superseded, or replaced from time to time.
"EEA" means the European Economic Area.
"GDPR" means the General Data Protection Regulation (EU) 2016/679.
"Personal Data", "Data Subject", "Data Protection Authority", "Data Protection Impact Assessment", "Personal Data Breach", "Process", "Processor", and "Controller" will each have the meaning given to them in the GDPR.
Capitalized terms not otherwise defined herein shall have the meaning given to them in the Agreement.
§2 Processing of Customer Data
The parties acknowledge that in connection with the Agreement, Customer is the Controller of Customer Personal Data and Builder.io is the Processor. Builder.io will only process Customer Personal Data on behalf of and in accordance with Customer's prior written instructions (including as set out in this Addendum and the Agreement) and for no other purpose. Builder.io is hereby instructed to process Customer Personal Data to the extent necessary to provide the Services in accordance with the Agreement.
If Builder.io cannot Process Customer Personal Data in accordance with Customer's instructions due to a legal requirement under European Data Protection Legislation, Builder.io will promptly notify the Customer of such inability and cease all Processing of the affected data until the Customer issues new instructions. If this provision is invoked, Builder.io will not be liable to the Customer under the Agreement for failure to perform the Services until such time as the Customer issues new instructions. Builder.io will immediately inform Customer if, in its opinion, an instruction from Customer infringes European Data Protection Legislation.
Each party will comply with their respective obligations under European Data Protection Legislation. Customer shall ensure it has obtained all required consents and lawful rights and provided all required notices before sharing Customer Personal Data with Builder.io.
Builder.io will not be liable under the Agreement for any claim brought by a Data Subject with respect to Customer Personal Data arising from any action or omission by Builder.io, to the extent that such action or omission resulted directly from Customer's failure to comply with its obligations under the applicable data protection law.
Where the processing activities involve transfers of data from the EEA and/or UK ("Transferred Personal Data") they shall be governed as follows:
(a) for EEA data, by the unchanged version of the standard contractual clauses (applicable module: MODULE TWO: transfer controller to processor) in Commission Decision 2021/914/EU which can be found at https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32021D0914&from=EN (the "EU SCCs"). Clause 7 (Docking Clause), and Clause 9(a) Option 2 (General Authorization), but not the option under Clause 11 (independent dispute resolution), shall apply; and
(b) for UK data, by the EU SCC plus the template Addendum B.1.0 issued by the ICO and laid before Parliament in accordance with s119A of the Data Protection Act 2018 on 2 February 2022 (or as it may be amended or replaced) (the "UK Addendum").
(c) the Annexes to this DPA provide the information required by Annexes I, II and III of the EU SCC and by the UK Addendum as set out in Schedule I to this DPA. The EU SCC may also be annexed to this DPA if appropriate.
(d) if terms in this DPA or the Agreement are inconsistent with the terms of the EU SCC or the UK Addendum, then the terms of the EU SCC or UK Addendum as applicable shall prevail.
With respect to Customer Personal Data that is protected by the Swiss Federal Act on Data Protection, references to member states will refer to Switzerland, and data subjects in Switzerland will be entitled to exercise and enforce their rights under the EU SCCs in Switzerland and references to GDPR refer to the Swiss Federal Act on Data Protection.
Builder.io commits to comply with its obligations under the applicable SCCs with respect to the transfer of Customer Personal Data.
For the purposes of the standard contractual clauses: (i) Customer will act as the "data exporter," (ii) Builder.io will act as the "data importer," and (iii) any sub-Processors, will act as "sub-processors" pursuant to the standard contractual clauses.
§3 Processing Details
The categories of data subjects, categories of personal data, subject matter, nature and purpose, and duration of processing are as set forth in Annex I of Exhibit A attached hereto. Customer Personal Data will be processed by Builder.io solely for the purposes provided under Annex I of Exhibit A.
§4 Confidentiality
Builder.io will ensure that any person whom Builder.io authorizes to Process Customer Personal Data on its behalf is subject to confidentiality obligations in respect of that Customer Personal Data.
§5 Security
Builder.io will implement appropriate technical and organizational measures to protect against accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data. Builder.io's security measures are set forth on Annex II to the SCCs.
Builder.io will, at the Customer's reasonable request, provide the Customer with reasonable assistance as necessary for the fulfillment of the Customer's obligation to keep Customer Personal Data secure.
§6 General Authorization of Sub-Processors
6.1 Customer authorizes Builder.io to appoint sub-Processors (including Builder.io's affiliates) to perform specific services on Builder.io's behalf which may require such sub-Processors to Process Customer Personal Data. Information about sub-Processors is available at https://www.builder.io/c/subprocessors. Customer may subscribe to receive updates to such sub-Processor web page.
6.2. If Builder.io engages a new third party sub-Processor to Process any Customer Personal Data, it will, at least 30 days before the new third party sub-Processor Processes any Customer Personal Data, inform Customer of the engagement by adding such sub-Processor to its sub-Processor web page located at https://www.builder.io/c/subprocessors. Customer may reasonably object to such new third party sub-Processor (excluding Builder.io's affiliates) that would cause Customer to be non-compliant with its obligations under applicable European Data Protection Legislation, provided Customer notifies Builder.io in writing explaining the non-compliance no later than 30 days after Builder.io added such sub-Processor to the Sub-Processor web page. Builder.io may address the objection (such as by finding a suitable work around) or allow Customer to terminate the Agreement for the affected Builder.io Service. If Builder.io allows Customer to terminate the Agreement, Customer has 5 days following Builder.io's determination to notify Builder.io of Customer's election to terminate the Agreement effective upon written notice to Builder.io. This termination right is Customer's sole and exclusive remedy if Customer objects to any new third party sub-Processor.
6.3. Builder.io will enter into a binding written agreement with each sub-Processor that imposes on the sub-Processor the same obligations that apply to Builder.io under this Addendum.
6.4. Builder.io shall remain fully liable to the Customer for the performance of its sub-Processor's obligations.
§7 Data Subject Rights
Builder.io will, at the Customer's request and subject to the Customer paying all of Builder.io's fees at prevailing rates and expenses, provide the Customer with reasonable assistance necessary for the fulfillment of the Customer's obligation to respond to requests for the exercise of Data Subjects' rights with respect to Customer Personal Data. Customer shall be solely responsible for responding to such requests.
§8 Personal Data Breach
Builder.io will:
- notify the Customer without unreasonable delay after it becomes aware of any Personal Data Breach affecting any Customer Personal Data; and
- at the Customer's request, promptly provide the Customer with all reasonable assistance necessary to enable the Customer to notify relevant security breaches to the relevant Data Protection Authorities and/or affected Data Subjects, if Customer is required to do so under the European Data Protection Legislation.
§9 Data Protection Impact Assessments
Builder.io will, at the Customer's request and subject to the Customer paying all of Builder.io's fees at prevailing rates and expenses, provide the Customer with reasonable assistance to facilitate: (a) the carrying out of Data Protection Impact Assessments if required by European Data Protection Legislation; and (b) consultation with Data Protection Authorities if required, in each case solely to the extent that such assistance is necessary, reasonable, and relates to the Processing by Builder.io of Customer Personal Data, taking into account the nature of the Processing and the information available to Builder.io.
§10 Data Deletion / Return
Upon termination or expiry of the Agreement or at any time on Customer's request, Builder shall as soon as reasonably practical delete or return all Customer Personal Data, and delete existing copies unless retention is required by law.
§11 Information and Audit Rights
Builder.io will, at Customer's request and subject to the Customer paying all of Builder.io's fees at prevailing rates and expenses, provide the Customer with all information reasonably necessary to demonstrate compliance with its obligations under European Data Protection Legislation, and allow for and reasonably contribute to audits and inspections conducted by the Customer or a mandated auditor, to the extent that such information is within Builder.io's control and Builder.io is not precluded from disclosing it by applicable law, a duty of confidentiality, or any obligation owed to a third party.
§12 Limitation of Liability
Each party's liability towards the other party under, in connection with or arising from this Addendum will be limited in accordance with the provisions of the applicable Agreement.
§13 Venue
This DPA shall be governed by the laws that govern the Agreement and each party consents to exclusive jurisdiction and venue of the courts specified in the Agreement; provided, however that: (a) with respect to the EU SCC, the matter will be governed by Irish law and the parties submit to the exclusive jurisdiction of the courts of Ireland; (b) with respect to the UK Addendum, the matter will be governed by English law and the parties submit to the exclusive jurisdiction of the courts of London, England; and (c) with respect to Switzerland, the matter will be governed by the laws of Switzerland and the parties submit to the exclusive jurisdiction of the courts of Zurich, Switzerland.
§14 General Provisions
With regard to the subject matter of this Addendum, in the event of inconsistencies between the provisions of this Addendum and the Agreement, the provisions of this Addendum shall prevail.
ANNEX I
A. List of Parties
Data Exporter: See order form or online sign up. Role: Controller.
Data Importer: Builder.io, Inc., 95 3rd Street, 2nd Floor, San Francisco CA, 94103. Contact: Kyle Fowler, VP of Engineering, kfowler at builder.io. Activities: Provider of services as set forth in order form or online sign up. Role: Processor.
Signature and date: The parties agree that signing up for the Services and agreeing to the Agreement constitute execution of these clauses by both parties.
B. Description of Transfer
Categories of data subjects whose personal data is transferred:
- Customer's employees and representatives using the Builder.io service on behalf of the Customer
- Customer's end users
Categories of personal data transferred:
- Identifiers such as first and last name, username and password to the Services, email address, contact information including phone number, country of residence, IP address, cookie identifiers, mobile identifiers, and randomly generated identifiers for end users of Customers' websites and mobile applications that use the Services
- Commercial information that Customer provides when purchasing the Services
- Internet or other electronic network activity information, including usage, viewing, metrics, mouse movements, clicks, page views and visits, text entered, device and technical data, other web activities
- Location information provided by a mobile device interacting with Builder's website or when associated with IP address
- Audio and electronic email for business calls, meetings, and communications; professional and employment-related information
- Any other personal data made available by the business customer
Sensitive data transferred: Not applicable, unless the Customer makes sensitive data available to Builder.
Frequency of transfer: Ongoing.
Nature of processing: Automated and manual Processing operations, including collection, use, analysis, transfer, storage, and deletion.
Purpose(s) of the data transfer and further processing:
- Provide application hosting services
- Provide a platform for visual content management
- Process and respond to requests and questions
- Process billing information for payments by Customer
- Tailor the features and content on the Services
- Perform Builder's obligations under the Agreement
- Communicate regarding Customer's account or transactions
- Operate, maintain, analyze, develop, update and improve the Services, including the AI models used by Builder; however, for business customers on Enterprise and Team plans, Builder does not use personal data of our business customers to train, retrain, or fine-tune AI models
- Detect, investigate, and prevent activities that may violate Builder policies, security, or applicable laws
- Protect Builder's operations, comply with law or legal process, pursue remedies, and exercise legal claims
- Send marketing information to Customer representatives
- Evaluate corporate transactions and acquisitions
- Otherwise process Customer Personal Data for the purposes set forth in the Agreement
Builder.io may process Customer Personal Data in such other ways as reasonably requested by Customer where such instructions are consistent with the terms of the Agreement.
Retention period: The duration of the main agreement.
For transfers to sub-processors: Cloud storage and hosting, CRM, metrics reporting, and marketing automation.
Builder has representatives located in the following countries: United States of America, Albania, Argentina, Brazil, Canada, Germany, India, Ireland, Israel, Netherlands, Portugal, Serbia, Spain, UAE, UK.
C. Competent Supervisory Authority
Data Protection Commission — Ireland.
ANNEX II — Technical and Organisational Measures
Builder.io Security: https://www.builder.io/legal/security-addendum
Schedule I — UK International Data Transfer Addendum
VERSION B1.0, in force 21 March 2022.
The parties are as set out in Annex I. The selected SCCs are Module 2 (controller to processor), with Clause 7 (Docking Clause) and Clause 9(a) Option 2 (General Authorization, 30 days), applied. Clause 11 (independent dispute resolution) does not apply.
Annex III (Sub-processors): https://www.builder.io/c/subprocessors
Table 4 — Ending this Addendum when the Approved Addendum changes: Either Importer or Exporter may end this Addendum as set out in Section 19 of the Mandatory Clauses.
Part 2: Mandatory Clauses of the Approved Addendum, being the template Addendum B.1.0 issued by the ICO and laid before Parliament in accordance with s119A of the Data Protection Act 2018 on 2 February 2022, as it is revised under Section 18 of those Mandatory Clauses.