BETAPro is not billed during beta. Lock in the price and we will honor it at launch.Freeze this price
Draft — this policy has not been approved for production use.

Data Processing Agreement

Starter template — legal review required before signing with any customer. This is the operational shell of a GDPR-compliant DPA. The roles, scope, sub-processors, and security measures are accurate to how BrandBanta works today. The legal commitments (liability caps, indemnification, termination triggers, governing law) must be negotiated and reviewed by counsel for each customer engagement.

Effective date: to be filled at signature


Parties

This Data Processing Agreement ("DPA") forms part of the agreement between:

  • BrandBanta ("Processor", "we", "us") — provider of the BrandBanta service
  • Customer ("Controller", "you") — the legal entity that has subscribed to the BrandBanta service

It applies to the processing of personal data by BrandBanta on behalf of Customer in connection with Customer's use of the service.


1. Roles and scope

1.1. Where Customer's use of the BrandBanta service involves the processing of personal data, Customer acts as the data controller and BrandBanta acts as the data processor within the meaning of GDPR Article 4.

1.2. BrandBanta acts as an independent controller for the limited personal data necessary to operate the service relationship with Customer (account holder name, email, billing details) and for security and abuse-prevention purposes. That processing is governed by the Privacy Policy, not this DPA.

1.3. This DPA applies for the duration of the underlying agreement and survives termination only to the extent of post-termination obligations specified herein (data return, deletion, audit cooperation).


2. Subject matter and duration

| Item | Description | | ------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------ | | Subject matter | Provision of the BrandBanta SaaS platform: AI-assistant scan execution, results analysis, brand visibility reporting, and related features | | Duration | The term of the underlying agreement, plus the deletion/return period in §10 | | Nature of processing | Hosting, storage, transmission, computation, display, and (with Customer's instruction) submission to third-party LLM providers | | Purpose | Delivery of the BrandBanta service as described in the Customer's subscription |


3. Categories of data subjects

The personal data processed under this DPA may include data relating to the following data subject categories, all determined by Customer:

  • Customer's employees, agents, and authorized members of Customer's BrandBanta workspace
  • Third parties whose names, brands, or identifying information Customer chooses to include in scan queries or tracked entities (e.g., competitors, individuals mentioned in tracked content)

BrandBanta does not control which categories appear in Customer's queries. Customer is responsible for ensuring it has a lawful basis to include any personal data in its scan queries.


4. Categories of personal data

The personal data processed may include:

  • Workspace member data — name, email, role, last-active timestamp, authentication credentials (hashed), two-factor authentication state
  • Activity data — scan triggers attributed to a member, inference cost metadata, request counts, timestamps
  • Content data — text Customer chooses to submit (prompts, brand names, query templates) and the resulting AI-assistant responses. To the extent this content includes personal data, that data is processed as part of the service
  • Billing data — billing contact information, payment method tokens (full card data is held by Stripe, not BrandBanta)

BrandBanta does not knowingly process special categories of personal data (GDPR Art. 9) unless Customer affirmatively configures the service to do so. Customer must not submit health, biometric, criminal, religious, or political data through scan queries without prior written agreement on additional safeguards.


5. Customer instructions

5.1. BrandBanta processes personal data only on Customer's documented instructions, including the operational instructions implicit in Customer's use of the service.

5.2. Standing instructions: deliver scan results to authorized members; persist scan history and cost metadata; retain data for the periods stated in the Privacy Policy; surface aggregate workspace metadata to workspace administrators; support member self-access to their own data.

5.3. Customer may issue additional written instructions. BrandBanta will inform Customer if an instruction infringes GDPR or other applicable data-protection law.


6. Confidentiality

BrandBanta ensures that personnel authorized to process Customer's personal data are bound by confidentiality obligations (either by contract or by statute) and have received appropriate training.


7. Security measures

BrandBanta maintains technical and organizational measures appropriate to the risk, including:

  • Encryption in transit — TLS 1.3 for all customer-facing endpoints
  • Encryption at rest — provider credentials sealed with AES-256-GCM using the workspace master key (KEYRING_MASTER_KEY); database storage encrypted by the hosting provider; rotation procedure documented in .apsolut/06-knowledge/runbooks/secret-rotation.md
  • Access control — workspace data is isolated per workspace; cross-workspace access is structurally prevented; administrative access to production systems is limited to authorized personnel and logged
  • Authentication — passwords hashed with Argon2id; passkey (WebAuthn) and TOTP two-factor authentication supported
  • Logging and monitoring — security-relevant events written to an audit log; error monitoring via Sentry with PII suppressed (no sendDefaultPii)
  • Backup and recovery — point-in-time recovery up to 30 days; restore procedures documented in .apsolut/06-knowledge/runbooks/turso-backup.md and tested periodically
  • Incident response — security disclosures accepted at security@brandbanta.com; documented response process; commitment to notify Customer within 72 hours of confirming a breach affecting Customer data
  • Vendor security review — sub-processors are vetted prior to engagement and re-reviewed on contract renewal

A full description of current measures is available on request.


8. Sub-processors

8.1. Customer authorizes BrandBanta to engage sub-processors for the limited purposes listed below. The current list:

| Sub-processor | Purpose | Location | | ------------- | ---------------------------- | ---------------------- | | Vercel | Application hosting | US / EU | | Turso | Database hosting | EU / US (configurable) | | OpenRouter | Sync LLM inference routing | US | | Anthropic | Batch insight generation | US | | OpenAI | Embedding generation | US | | Stripe | Payment processing | US / EU | | Resend | Transactional email | US | | Sentry | Error monitoring | US / EU | | Inngest | Background job orchestration | US |

8.2. BrandBanta will notify Customer of any intended addition or replacement of sub-processors (by email or in-product notification) at least 30 days in advance. Customer may object on reasonable data-protection grounds within that period; if the objection cannot be resolved, Customer may terminate the affected portion of the service.

8.3. BrandBanta has signed a written data-processing agreement with each sub-processor imposing data-protection obligations no less protective than those in this DPA.


9. International transfers

9.1. BrandBanta may transfer personal data to countries outside the EEA, UK, and Switzerland.

9.2. Where required, transfers are protected by the European Commission's Standard Contractual Clauses (Module 2: Controller-to-Processor; Module 3: Processor-to-Sub-processor) and the UK International Data Transfer Addendum.

9.3. Customer hereby executes the SCCs by accepting this DPA, with BrandBanta as data importer and Customer as data exporter. The relevant docking clauses, optional modules, and Annex content are deemed completed in line with the operational facts of this DPA (categories of data, data subjects, processing purposes, security measures, sub-processors).

9.4. A separately-signed copy of the SCCs is available on request and required for some procurement processes.


10. Return and deletion

10.1. Upon termination of the underlying agreement, BrandBanta will (at Customer's choice) return or delete all personal data processed on Customer's behalf, except where retention is required by law (typically billing records).

10.2. Return: provided in a machine-readable format within 30 days of request.

10.3. Deletion: completed within 30 days of termination or written request, including from active systems and within the next backup cycle of any system where deletion-on-write is not technically possible.

10.4. Deletion is confirmed in writing on request.


11. Audits

11.1. BrandBanta will make available to Customer, upon written request, information necessary to demonstrate compliance with this DPA.

11.2. Customer may audit BrandBanta's compliance with this DPA up to once per calendar year. Audits are conducted on at least 30 days' written notice, during normal business hours, in a manner that does not disrupt the service, and at Customer's expense. BrandBanta may satisfy an audit obligation by providing a recent third-party audit report (e.g., SOC 2 Type II) once one is available.

11.3. For non-routine audits triggered by a documented incident or a regulator request, additional cooperation is provided without limit.


12. Data subject requests

12.1. BrandBanta will assist Customer in fulfilling data subject requests (access, rectification, erasure, restriction, portability, objection) by providing the technical means within the service (/settings/cost, /settings/general, account-deletion flow) and additional cooperation as needed.

12.2. If BrandBanta receives a data subject request relating to Customer's data, BrandBanta will forward the request to Customer without responding to it directly (except to confirm receipt and refer the data subject to Customer).


13. Personal data breaches

13.1. BrandBanta will notify Customer without undue delay and in any case within 72 hours of confirming a personal data breach affecting Customer data.

13.2. The notification will describe: the nature of the breach, the categories and approximate number of data subjects and records affected (to the extent known), likely consequences, and measures taken or proposed to address the breach and mitigate harm.

13.3. BrandBanta will cooperate with Customer in any required notification to data subjects or supervisory authorities.


14. Liability

The liability provisions of the underlying agreement govern claims under this DPA. Customer acknowledges that BrandBanta's overall liability for data-processing claims is subject to the caps and exclusions in that agreement, except where applicable law prohibits such limitations.


15. Order of precedence

In the event of conflict between this DPA and other contractual terms, this DPA prevails for matters of data protection. The SCCs (where applicable) prevail over any conflicting provision of this DPA.


16. Governing law and jurisdiction

This DPA is governed by the law and subject to the jurisdiction specified in the underlying agreement, except where mandatory provisions of GDPR or local data-protection law require otherwise.


Signature

This DPA is incorporated by reference into the underlying agreement and is executed by the parties' acceptance of that agreement. A separately-signed copy is available on request.

For execution requests, contact: privacy@brandbanta.com