Last updated: 13 June 2026
[bracketed] placeholders) before launch.
[Legal entity name] ("BuildPaza", "we", "us") operates buildpaza.com. Registered address: [Registered address]. We are the data controller for personal data processed about visitors and account holders. Contact: privacy@buildpaza.com.
When you use BuildPaza to build an app that itself processes other people's personal data, you are the controller of that data and BuildPaza acts as your processor — see our Data Processing Addendum.
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Provide the builder, store your builds, run the AI team | Performance of a contract |
| Sign-in, security, fraud & abuse prevention, rate limiting | Legitimate interests |
| Billing, credits, subscriptions | Performance of a contract |
| Keeping invoices/tax records | Legal obligation |
| Optional product analytics (only if enabled, privacy-friendly & cookieless) | Legitimate interests / consent |
Your prompts and build content are sent to EU-sovereign large-language models served via Depaza on European infrastructure to generate your app. We do not sell your content, and we do not use it to train third-party foundation models. See our sovereignty page and sub-processor list.
We use a small number of vetted sub-processors (e.g. AI inference, email delivery, payments, hosting, CDN/TLS). The current list, their function and location is at /subprocessors. Where a sub-processor is outside the EEA (e.g. Stripe), transfers are covered by appropriate safeguards such as the EU Standard Contractual Clauses.
We aim to keep processing within the EU/EEA. Where a transfer to a third country is necessary, we rely on adequacy decisions or Standard Contractual Clauses with supplementary measures.
Under the GDPR you may access, rectify, erase, restrict, or object to processing, and request portability. You can do the two most important ones yourself, instantly, from your account settings:
For anything else, email privacy@buildpaza.com. You also have the right to lodge a complaint with your local supervisory authority.
We use TLS in transit, hashed single-use sign-in tokens, session-id rotation on login, scoped per-build isolation, least-privilege database access, and rate limiting. No system is perfectly secure, but we take reasonable, industry-standard measures.
BuildPaza is not directed at children under 16 and we do not knowingly collect their data.
We will update this page and revise the "last updated" date when this policy changes; material changes will be communicated to account holders.
We use a single essential cookie to keep you signed in — no advertising or cross-site tracking. Details.