LEGAL

Data Processing Addendum

LAST UPDATED · AUGUST 2026

Overview

Our Data Processing Addendum governs how BrainerX Labs processes personal data on behalf of customers. It incorporates GDPR Article 28 processor terms, the EU Standard Contractual Clauses where they apply, and UK and Swiss addenda where relevant.

Roles

For engagement data, the customer is the controller and BrainerX Labs is the processor. We process personal data only on documented instructions, and our personnel are bound by confidentiality.

Security measures

The DPA includes our technical and organizational measures: encryption in transit and at rest, role-based access with least privilege, audit logging, environment isolation per customer, and annual third-party testing under our SOC 2 Type II and ISO 27001 programs.

Sub-processors

A current list of sub-processors, including cloud infrastructure and model providers, is available on request. Customers receive advance notice of material changes and may object on reasonable grounds.

Breach notification and audits

We notify affected customers without undue delay after becoming aware of a personal data breach, and support audits and assessments as described in the DPA.

Requesting the DPA

Email us for an execution-ready copy. We typically respond within one business day.

Contact

Questions about this document? Write to us at contact@brainerxlabs.com.