Data Processing Agreement

Last updated: September 3, 2026 · Version 1.1

1. Scope and parties

This Data Processing Agreement ("DPA") forms part of the Brainis Terms of Service between Brainis ("Processor") and the customer ("Controller") and governs Brainis's processing of Personal Data on behalf of the Controller in connection with the Brainis services.

2. Definitions

"GDPR" means Regulation (EU) 2016/679. "Personal Data", "Processing", "Controller", "Processor", "Sub-processor" and "Data Subject" have the meanings given in the GDPR. "Services" means the Brainis platform as described at brainis.ai.

3. Processing details (GDPR Art. 28(3))

  • Subject matter: provision of the Brainis platform.
  • Duration: the term of the underlying subscription agreement.
  • Nature and purpose: hosting, storing, and processing customer data to deliver the Services, including AI-assisted features.
  • Categories of Personal Data: account identifiers, employee records, candidate records, contacts, deals, communications, files uploaded by Controller.
  • Categories of Data Subjects: Controller's employees, customers, candidates, vendors, end users.

4. Processor obligations

The Processor shall:

  • Process Personal Data only on documented instructions from the Controller (including the Services configuration).
  • Ensure persons authorised to process Personal Data are bound by confidentiality.
  • Implement appropriate technical and organisational measures (see §6).
  • Assist the Controller with Data Subject rights requests, breach notifications, and DPIAs.
  • Delete or return Personal Data at the end of the agreement, subject to legal retention requirements.

5. Sub-processors

The Controller authorises Brainis to engage Sub-processors listed at /legal/sub-processors. Brainis will give 30 days' notice of any new Sub-processor; the Controller may object on reasonable data-protection grounds.

6. Security measures

  • Encryption in transit (TLS 1.2+) and at rest (AES-256).
  • Row-Level Security (RLS) enforced on all multi-tenant tables.
  • Per-organisation storage path scoping with policy-level enforcement.
  • Least-privilege IAM and MFA on all administrative accounts; SSO/SAML (post-launch).
  • Centralised audit logging with hash-chain integrity.
  • Backups with point-in-time recovery; documented disaster-recovery procedures.
  • Annual penetration testing and continuous dependency-vulnerability scanning.

7. International transfers

Where Personal Data is transferred outside the EEA / UK, Brainis relies on the EU Standard Contractual Clauses (Module 2: Controller-to-Processor) and the UK International Data Transfer Addendum, supplemented by the technical and organisational measures described above.

8. Personal data breach

Brainis will notify the Controller without undue delay (and in any event within 72 hours) of becoming aware of a Personal Data breach affecting the Controller's data.

9. Audit

The Controller may, on reasonable notice and no more than once per year, audit Brainis's compliance with this DPA. Brainis will satisfy such an audit by answering a reasonable security questionnaire and by making available the current documentation of the technical and organisational measures in §6, together with any independent third-party assessment reports it then holds that cover the scope in question. Where Brainis holds no such report, it will say so rather than imply one. Brainis does not currently hold an independent security certification; certifications will be published, with the date each was obtained, at /trust as and when they are.

10. Liability and term

Liability under this DPA is subject to the limitations of the underlying agreement. This DPA terminates automatically upon termination of the underlying agreement.

11. Signing

For organisations requiring a counter-signed DPA, contact support@brainis.ai. Acceptance of the Brainis Terms of Service also constitutes acceptance of this DPA on behalf of the Controller.