LEGAL
Data Processing Addendum
Overview
Our Data Processing Addendum governs how BrainerX Labs processes personal data on behalf of customers. It incorporates GDPR Article 28 processor terms, the EU Standard Contractual Clauses where they apply, and UK and Swiss addenda where relevant.
Roles
For engagement data, the customer is the controller and BrainerX Labs is the processor. We process personal data only on documented instructions, and our personnel are bound by confidentiality.
Security measures
The DPA includes our technical and organizational measures: encryption in transit and at rest, role-based access with least privilege, audit logging, environment isolation per customer, and annual third-party testing under our SOC 2 Type II and ISO 27001 programs.
Sub-processors
A current list of sub-processors, including cloud infrastructure and model providers, is available on request. Customers receive advance notice of material changes and may object on reasonable grounds.
Breach notification and audits
We notify affected customers without undue delay after becoming aware of a personal data breach, and support audits and assessments as described in the DPA.
Requesting the DPA
Email us for an execution-ready copy. We typically respond within one business day.
Contact
Questions about this document? Write to us at contact@brainerxlabs.com.