The Bench
RosterDemoPricingDashboardAdd to Slack
Legal

Data Processing Addendum

Last updated September 28, 2026. Draft for design partners; not yet reviewed by counsel.

This Addendum forms part of the Terms of Service between The Bench ("Processor", "we") and the Customer ("Controller", "you") and applies whenever we process personal information on your behalf. If you need a signed copy, email hello@meetthebench.com.

1. Roles

You are the controller (in PIPEDA terms, the organization accountable) of the personal information in your Slack workspace and connected systems. We are the processor acting on your documented instructions, which are: the Terms, your configuration in the dashboard, and the tasks your users request.

2. Scope of processing

ItemDetail
Subject matterFinance, operations, and marketing tasks performed by AI Specialists inside Slack
DurationWhile The Bench is installed in your workspace, plus the deletion period in section 8
Nature and purposeReading connected-system data, analyzing it, drafting outputs, and taking approved actions, solely to complete tasks you request
Categories of data subjectsYour employees who use Slack; your customers and suppliers whose records exist in connected systems
Categories of personal informationNames, contact details, order and transaction history, communications sent to a Specialist, and business records containing such information. No special-category data or protected health information is to be provided.

3. Our obligations

  • Process personal information only on your instructions, and tell you if an instruction appears to breach applicable law.
  • Ensure the people who access it are bound by confidentiality.
  • Maintain the security measures in section 6.
  • Help you respond to requests from individuals about their information, and to privacy impact assessments, at reasonable cost.
  • Delete or return personal information at the end of the service as in section 8.
  • Make available the information needed to show compliance with this Addendum, and allow audits as in section 7.

4. Sub-processors

You authorize the following sub-processors. We will give 30 days' notice on the dashboard before adding one; you may object in writing, and if we cannot address the objection you may terminate without penalty.

Sub-processorPurposeLocation
Anthropic, PBCAI model inference, task sandbox, credential vault, memory storageUnited States
Slack Technologies (Salesforce)Message deliveryUnited States
ComposioOAuth connections to your systems (only if you use one-click connect)United States
VercelWebsite and dashboard hostingUnited States
Neon (or equivalent managed Postgres)DatabaseUnited States
StripePayment processingUnited States and Canada

5. International transfers

Personal information is processed in the United States. For Canadian customers, we rely on PIPEDA's accountability principle and contractual protections with each sub-processor comparable to those in this Addendum. Customers subject to the GDPR should contact us before installing; we do not yet offer EU data residency.

6. Security measures

  • TLS for all data in transit; encryption at rest for stored credentials and the database.
  • Per-workspace isolation: separate credential vault and memory stores per customer; no shared state.
  • Connected-system credentials injected at the network edge and never exposed inside the AI sandbox, prompts, or logs.
  • Human approval required before any action that sends, pays, files, refunds, reprices, publishes, or deletes; every request and decision logged with the approver.
  • Least-privilege access: we ask you to grant read-only scopes where the task allows.
  • Access to production systems limited to named operators with multi-factor authentication.

7. Audit

Once per year, or after a security incident, you may request written answers to a reasonable security questionnaire and evidence of the measures above. On-site audits require 30 days' notice and are at your cost.

8. Deletion

Within 30 days after you uninstall The Bench, we revoke credentials, archive and then delete memory stores, and delete threads and approvals. Task transcripts held by Anthropic expire on their 30-day retention schedule. Billing records are retained as required by tax law. On request we will confirm deletion in writing.

9. Breach notification

We will notify you without undue delay after becoming aware of a breach of security affecting your personal information, and in any case within 72 hours, with what we know about its nature, scope, likely consequences, and the measures taken.

10. Liability

Liability under this Addendum is subject to the limitations in the Terms of Service.

Terms of Service · Privacy Policy · Data Processing Addendum

The Bench runs on Claude Managed Agents. Every specialist works Ask First.TermsPrivacyDPAToronto