US Data Processing Addendum
Updated August 19, 2026
Builder.io, Inc.
U.S. Data Processing Addendum
Effective upon execution of the applicable SaaS Services Agreement or Order Form
This U.S. Data Processing Addendum (the "Addendum") between Builder.io, Inc. ("Builder.io") and the customer accessing or using the Services (the "Customer"), is incorporated into the SaaS Services Agreement located at https://builder.io/legal/terms or such other commercial agreement between Builder.io and the Customer whereby Builder.io provides the Customer with access to the Services (the "Agreement"). "Services" is defined in the Agreement. This Addendum applies with respect to the provision of the Services to Customer, if the Processing of Customer Personal Data is subject to Applicable US Laws. Builder.io may revise and update this Addendum from time to time when required by applicable law. All changes are effective within 30 days after we post them, and will apply to all access to and use of the Services thereafter.
1. Definitions
"Applicable US Laws" means all applicable US data privacy and security laws, including, as applicable, the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020 ("CCPA"), and their regulations, each as amended from time to time.
"Customer Personal Data" means the personal information or personal data provided or made available or accessible by Customer to Builder.io in connection with the Agreement.
The terms "business", "business purpose", "commercial purpose", "consumer", "controller", "personal data", "personal information", "process", "processing", "processor", "sell", "service provider", and "share" as used in this Addendum have the meanings given in the Applicable US Laws.
2. Processing
2.1 Details of Processing
The parties acknowledge and agree that: (a) Builder.io is a service provider and processor of Customer Personal Data under Applicable US Laws; and (b) Customer is a business and controller of Customer Personal Data under Applicable US Laws. Each party will comply with the obligations applicable to it under Applicable US Laws with respect to the processing of Customer Personal Data.
The parties further agree that:
- the nature of the processing is collecting, organizing, structuring, storing, altering, using, disclosing, combining, deleting, and destroying data;
- the purpose of the processing is for Builder.io to provide the Services to Customer, including providing platform hosting services, a platform for visual development, providing support, processing billing, tailoring features of the Services, performing Builder.io's obligations, operating, maintaining, analyzing, developing, updating and improving the Services (including the AI models used by Builder; however, for business customers on Enterprise and Team plans, Builder does not use personal data of our business customers to train, retrain, or fine-tune AI models), detecting and preventing illegal acts and security threats, sending marketing information to Customer representatives, and otherwise processing Customer Personal Data as reasonably requested by Customer;
- the types of personal information subject to processing include name, email address, phone number, IP address, device identifier, cookie identifier, account login information, usage and page view information, text entered, movements, audio and electronic email for business communications, location information, professional and employment-related information, and other information made available by Customer;
- the types of consumer whose personal information is being processed are representatives of Customer using the Services on behalf of Customer and Customer's end users; and
- the duration of processing is the term of the Agreement until Customer Personal Data is deleted.
2.2 Instructions
Customer instructs Builder.io to process Customer Personal Data in accordance with the following, and Builder.io will comply to the extent not prohibited under Applicable US Laws: (a) to provide the Services; (b) as set forth in the Agreement and specifically in this Addendum; (c) as set forth in any other written instructions given by Customer; and (d) to process Customer Personal Data as permitted under Applicable US Laws for service providers and processors.
2.3 Confidentiality
Builder.io will ensure that all persons authorized to process Customer Personal Data are subject to a duty of confidentiality with respect to the Customer Personal Data.
2.4 Data Deletion
Customer instructs Builder.io to delete all Customer Personal Data from Builder.io's systems upon termination of the Agreement within ninety (90) days of termination, except to the extent retention is required by applicable law.
2.5 Demonstration of Compliance
Upon Customer's reasonable request, Builder.io will make available to Customer all information in its possession necessary to demonstrate Builder.io's compliance with its obligations under Applicable US Laws.
2.6 Security; Data Incidents
2.6.1. Builder.io will implement and maintain reasonable and appropriate administrative, technical, physical, and organizational measures on systems managed by or otherwise controlled by Builder.io to protect against unauthorized or illegal access to or acquisition of Customer Personal Data, and accidental loss, destruction, or damage to Customer Personal Data, and to protect the confidentiality, integrity, and accessibility of Customer Personal Data.
2.6.2. Taking into account the nature of processing and the information available to Builder.io, Builder.io will reasonably assist Customer in meeting its obligations in relation to the security of processing the Customer Personal Data and in relation to the notification of a Data Incident pursuant to Applicable US Laws. If Builder.io becomes aware of a Data Incident, Builder.io will notify Customer without unreasonable delay and take reasonable steps to minimize harm and secure Customer Personal Data. "Data Incident" means a breach of the security of the system (as defined under Applicable US Laws) of Builder.io, including a breach of security leading to the unauthorized access to or acquisition of (or reasonable belief of such unauthorized access to or acquisition of) Customer Personal Data on systems managed by or otherwise controlled by Builder.io, excluding unsuccessful attempts that do not compromise the security of Customer Personal Data such as unsuccessful pings, log-in attempts, and other network attacks on firewalls or networked systems. Builder.io's notification of or response to a Data Incident will not be construed as an acknowledgement by Builder.io of any fault or liability with respect to the Data Incident. For the avoidance of doubt, Builder.io is not responsible or liable for any personal data breach or incident to the extent the breach or incident arose from the actions, omissions, personnel, users, service providers, or systems of Customer. Customer is responsible for complying with breach and incident notification laws applicable to Customer and fulfilling any third party notification obligations related to any Data Incident.
2.7 Consumer Requests
2.7.1. As between the parties, Customer is responsible for responding to consumer requests or informing Builder.io of consumer requests that Builder.io must comply with.
2.7.2. Builder.io will provide Customer with reasonable assistance as necessary for Customer to fulfill its obligation under Applicable US Laws to respond to consumer requests, taking into account the nature of processing and the information available to Builder.io.
2.8 Assessments; Audits
Builder.io will provide Customer with reasonably necessary information to enable Customer to conduct and document data protection assessments required by Applicable US Laws. Builder.io will allow and cooperate with reasonable assessments, audits, or inspections by Customer (or Customer's designated third party, subject to execution of a confidentiality agreement with Builder.io), not to exceed once per year; provided that Builder.io may, in the alternative, arrange for a qualified and independent assessor or auditor to conduct an assessment or audit of Builder.io's policies and technical and organizational measures in support of the obligations under Applicable US Laws using an appropriate and accepted control standard or framework and assessment and audit procedure for such assessments and audits. If Builder.io arranges for such independent assessment or audit, Builder.io shall provide Customer a report upon Customer's request.
2.9 Subprocessors
If Builder.io engages any subprocessor to process Customer Personal Data on Builder.io's behalf, Builder.io will enter into a written contract with such subprocessor that requires the subprocessor to meet the obligations of Builder.io under Applicable US Laws with respect to the Customer Personal Data.
Builder.io's current list of applicable subprocessors is located at https://www.builder.io/c/subprocessors. Customer may subscribe to receive updates to such web page. Builder.io will notify Customer if Builder.io engages any other subprocessors to assist it in processing Customer Personal Data on behalf of Customer, by updating its subprocessor web page. Customer acknowledges and agrees that updating the web page is sufficient notice hereunder.
Where objection rights are required by Applicable US Laws, Builder.io will provide Customer an opportunity to reasonably object to the engagement of a new sub-processor. In such event, Customer must notify Builder.io of its reasonable objection no later than 30 days after notice is provided hereunder.
2.10 Deidentified Data
"Deidentified Data" is defined under Applicable US Laws and, under the CCPA, is data that is "deidentified" as defined under the CCPA when disclosed by one party to the other party hereunder. Each party will comply with the requirements for processing Deidentified Data as set out in the Applicable US Laws, including taking reasonable measures to ensure the information cannot be associated with a consumer, publicly committing to processing the Deidentified Data solely in deidentified form and not attempting to reidentify the information, and contractually obligating any recipients of Deidentified Data to comply with such requirements and Applicable US Laws.
3. Additional CCPA Obligations
To the extent that CCPA applies to the processing of Customer Personal Data, Builder.io will act as Customer's service provider, and as such, unless otherwise permitted for service providers under CCPA:
3.1. Builder.io will not sell or share any Customer Personal Data.
3.2. Builder.io will not retain, use, or disclose Customer Personal Data for any purpose other than the business purposes specified in the Agreement and this Addendum or as permitted under CCPA.
3.3. Builder.io will not retain, use, or disclose Customer Personal Data for any commercial purpose other than the business purposes specified in the Agreement and this Addendum or as permitted under CCPA.
3.4. Builder.io will not retain, use, or disclose Customer Personal Data outside of the direct business relationship between Builder.io and Customer, unless permitted by CCPA.
3.5. Builder.io will not combine or update Customer Personal Data that Builder.io receives from, or on behalf of, Customer with (i) personal information that Builder.io receives from, or on behalf of, another person or persons, or (ii) personal information collected from Builder.io's own interaction with a consumer.
3.6. Builder.io will comply with applicable obligations under CCPA and will provide the same level of privacy protection as is required by CCPA.
3.7. Builder.io grants Customer the right to take reasonable and appropriate steps to ensure that Builder.io uses Customer Personal Data in a manner consistent with Customer's obligations under CCPA, including ongoing manual reviews, automated scans (subject to notification and mutual agreement with respect to the method), and regular assessments, audits, or other technical and operating testing (not to exceed once per year).
3.8. Builder.io will promptly notify Customer if Builder.io makes a determination that it can no longer meet its obligations under CCPA.
3.9. Builder.io grants Customer the right, upon written notice, to take reasonable and appropriate steps to stop and remediate Builder.io's use of Customer Personal Data.
4. Additional Customer Responsibilities
As required by Applicable US Laws, Customer agrees to comply with the following controller obligations:
4.1. Customer will limit the collection of Customer Personal Data to what is adequate, relevant, and reasonably necessary in relation to the purposes for which such data is processed, as disclosed to the consumer.
4.2. Customer will not request Builder.io to process Customer Personal Data for purposes that are neither reasonably necessary to nor compatible with the disclosed purposes for which such Customer Personal Data is processed, unless Customer obtains the consumer's consent.
4.3. Customer will establish, implement, and maintain reasonable administrative, technical, and physical data security practices to protect the confidentiality, integrity, and accessibility of Customer Personal Data, appropriate to the volume and nature of the personal data at issue.
4.4. Customer will not process Customer Personal Data in violation of Applicable US Laws that prohibit unlawful discrimination against consumers.
4.5. Customer will provide consumers with a reasonably accessible, clear, and meaningful privacy notice with all disclosures required by Applicable US Laws and the means for consumers to submit requests and to opt out and opt in to certain data practices, as required by Applicable US Laws.
5. Transfers
Customer acknowledges and agrees that Customer Personal Data may be stored and processed in the United States and other countries where Builder and its service providers maintain facilities.