Legal
Data Processing Addendum
The Article 28 terms on which we process personal data on your behalf. Forms part of the Terms of Service for any customer acting as a controller.
This Addendum forms part of the Terms of Service between you ("Controller") and PLACEHOLDER_BEFORE_LAUNCH — registered company name ("Processor", "we"). It applies where we process personal data on your behalf. Where it conflicts with the Terms, this Addendum prevails for data protection matters.
If you need a countersigned copy, email hello@brayn.tech.
1. Roles
You are the controller of personal data contained in the sources you connect. We are the processor of that data. For account data — the identity records needed to operate your workspace — we act as an independent controller under the Privacy Policy.
2. Subject matter and duration
Subject matter: provision of the Brain platform — ingesting content from your connected sources, structuring it into a knowledge graph, and generating Skills from it.
Duration: for as long as your workspace exists, plus up to 30 days for deletion.
Nature and purpose: collection, storage, structuring, analysis by language model, retrieval and deletion, solely to provide the service to you.
Types of personal data: names, usernames, email addresses, source-native user identifiers, and the free-text content of messages, comments, issues, tickets and emails, which may contain any personal data your users have written into your source systems.
Categories of data subject: your personnel, and third parties appearing in your source systems — customers, correspondents, ticket reporters and external contributors.
3. Our obligations
We will:
a. Process personal data only on your documented instructions, including for transfers, unless required otherwise by law — in which case we will tell you first unless the law forbids it. b. Ensure personnel authorised to process the data are bound by confidentiality. c. Implement appropriate technical and organisational measures — described in Security, which forms part of this Addendum and honestly states current limitations. d. Respect the conditions in section 5 for engaging sub-processors. e. Assist you, so far as possible, in responding to data subject rights requests. f. Assist you with your obligations on security, breach notification, impact assessments and prior consultation, taking into account the information available to us. g. Delete personal data at the end of the service as set out in section 7. h. Make available the information needed to demonstrate compliance with Article 28, and allow and contribute to audits as set out in section 9.
4. Your obligations
You will ensure you have a lawful basis for the processing you instruct, including for third parties appearing in your connected sources, and that you have met your transparency obligations to them. You will not instruct processing of the categories excluded by the Acceptable Use Policy.
You acknowledge that we do not automatically redact personal data before it is sent to the model providers in section 5, and that you have taken this into account in selecting which sources to connect.
5. Sub-processors
You give general written authorisation for us to engage sub-processors. Those currently engaged are listed at /sub-processors, with what each receives.
We will update that page before engaging a new sub-processor. To be notified in advance, email hello@brayn.tech and we will add you to the notification list. If you reasonably object to a new sub-processor on data protection grounds, tell us within 30 days; if we cannot accommodate you, you may terminate and request deletion.
We remain fully liable for the performance of our sub-processors' obligations.
6. Security and breach
Our measures are described in Security. We will notify you without undue delay, and in any event within 48 hours, of becoming aware of a personal data breach affecting your data, with the information available to us at the time and updates as we learn more.
7. Deletion and return
On termination, or on your written request, we will delete all personal data we process on your behalf within 30 days and confirm in writing. Before deletion you may export your Skills through the product.
Two limitations we state rather than conceal:
- Content already transmitted to a model provider cannot be recalled.
- Where we are legally required to retain data, we will retain only what is required and continue to protect it.
8. International transfers
Personal data is stored in London, United Kingdom. It is transferred outside the UK for language model processing, to the recipients identified at /sub-processors, which also explains that the ultimate processing location can vary per request because our provider is a router.
Transfers are made under the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or the UK IDTA, together with a transfer risk assessment. If you require confirmation of the executed transfer mechanism for a specific recipient before connecting a source, contact us at hello@brayn.tech and we will provide it.
9. Audit
We will respond to reasonable written questionnaires about our processing, at most annually, and will provide the documentation we hold. Given our size, we ask that on-site audits be requested only where genuinely necessary, on reasonable notice, at your cost, and subject to confidentiality.
10. Liability
Each party's liability under this Addendum is subject to the limitations in the Terms of Service.
11. Governing law
This Addendum is governed by the law of PLACEHOLDER_BEFORE_LAUNCH — place of registration (UK Ltd vs Delaware C-Corp).