DRAFT — pending legal review. This Data Processing Addendum is a working draft provided for transparency and procurement review. It has not yet been finalised by counsel and is not yet binding. The executed version incorporated into your agreement governs. Email [email protected] for the current signable copy or to raise redlines.
This Addendum forms part of the agreement between Brahmalabs ("Processor") and the customer ("Controller") and applies where Brahmalabs Processes Personal Data on the Controller's behalf in providing the platform. For our SaaS offering, Brahmalabs acts as Processor; the Controller determines the purposes and means of Processing. For self-hosted / on-premises deployments where Personal Data never leaves the Controller's own infrastructure and Brahmalabs has no access to it, Brahmalabs is not a Processor of that data, and this Addendum applies only to any support, telemetry, or license data the Controller chooses to share.
Terms not defined here (Personal Data, Processing, Controller, Processor, Sub-processor, Data Subject, Supervisory Authority) have the meaning given in the GDPR.
Brahmalabs shall:
Brahmalabs shall notify the Controller without undue delay after becoming aware of a Personal-Data Breach affecting the Controller's Personal Data, and provide information reasonably available to assist the Controller's own notification obligations under Art. 33–34. Our append-only audit log and live tracing support timely investigation.
The Controller grants general authorisation for Brahmalabs to engage Sub-processors. Our current Sub-processors are listed at brahmalabs.io/legal/subprocessors. We impose data-protection obligations on each Sub-processor no less protective than this Addendum and remain liable for their performance. We will give advance notice of new Sub-processors and a reasonable period to object on legitimate data-protection grounds.
Where Processing involves transfer of Personal Data outside the EEA, UK, or Switzerland to a country without an adequacy decision, the parties incorporate the EU Standard Contractual Clauses (Module Two: Controller-to-Processor), and the UK International Data Transfer Addendum / Swiss amendments as applicable, together with a transfer-impact assessment. These are appended to and form part of this Addendum.
Brahmalabs will make available compliance documentation (including the SOC 2 report once available) and respond to reasonable security questionnaires. On reasonable notice, no more than once per year (or following a Breach), the Controller may audit Brahmalabs' compliance, subject to confidentiality and minimal disruption.
On termination, at the Controller's choice, Brahmalabs will delete or return all Personal Data and delete existing copies, unless retention is required by law. Backup copies are deleted on their ordinary cycle.
For Personal Information subject to the CCPA/CPRA, Brahmalabs acts as a "service provider" / "contractor": we process such information only to provide the services and on the Controller's documented instructions; we do not sell or share it, retain, use, or disclose it for any other purpose, or combine it with data from other sources except as permitted by the CCPA.
This Addendum prevails over conflicting terms of the agreement with respect to Processing of Personal Data. If any provision is invalid, the remainder stays in effect. Liability is subject to the limitations in the agreement.
Questions or to execute a signed copy: [email protected].