Data Processing Agreement

How we process personal data on your behalf as a GDPR processor.

Last updated: August 21, 2026

This Data Processing Agreement ("DPA") forms part of the agreement between Brand Armor AI("Processor", see our Imprint for full entity details) and the customer ("Controller") for the provision of the Brand Armor AIServices, and reflects the parties' agreement with regard to the Processing of Personal Data under Regulation (EU) 2016/679 ("GDPR") Article 28.


1. SUBJECT MATTER AND DURATION

The Processor processes Personal Data on behalf of the Controller for the duration of the underlying subscription agreement, solely to provide the Brand Armor AI Services (AI visibility monitoring, brand analytics, and related reporting).


2. NATURE AND PURPOSE OF PROCESSING

The Processor processes Personal Data to operate the Services: authenticating and supporting Controller's users, generating AI-visibility reports, and providing customer support. Categories of data subjects are the Controller's authorized users. Categories of Personal Data are limited to account data (name, email, role) and usage/log data — see our Privacy Policy for the full description.


3. PROCESSOR OBLIGATIONS

The Processor shall: (a) process Personal Data only on documented instructions from the Controller; (b) ensure persons authorized to process the data are subject to confidentiality; (c) implement appropriate technical and organizational security measures; (d) assist the Controller in responding to data subject requests; (e) delete or return Personal Data at the end of the engagement; and (f) make available information necessary to demonstrate compliance.


4. SUB-PROCESSORS

The Controller provides general authorization for the Processor to engage sub-processors, provided the Processor maintains a current list at /sub-processors and notifies the Controller of any intended changes, giving the Controller the opportunity to object.


5. INTERNATIONAL TRANSFERS

Where Personal Data is transferred outside the European Economic Area, the Processor relies on the European Commission's Standard Contractual Clauses (Module Two: Controller to Processor, and Module Three: Processor to Sub-processor, as applicable), incorporated by reference into this DPA, with each sub-processor located outside the EEA, to ensure an adequate level of protection for the transferred Personal Data.


6. SECURITY MEASURES

The Processor maintains the following technical and organizational measures:

  • Encryption in transit: all traffic to the Services is served over HTTPS/TLS.
  • Encryption at rest: the primary database (MongoDB Atlas) and cloud infrastructure (Google Cloud Platform) encrypt data at rest by default; sensitive integration credentials (for example connected third-party access tokens) are additionally encrypted at the application layer before storage.
  • Password security: user passwords are hashed with bcrypt and are never stored or logged in plaintext.
  • Access controls: production infrastructure access is limited to authorized personnel; application-level access is role-based (administrator vs. standard user per company account).
  • Secrets management: API keys and service credentials are stored in a managed secrets store (Google Secret Manager) rather than in source code or plaintext configuration.
  • Session and authentication security: authenticated sessions use signed, expiring tokens; revoked tokens are tracked so access can be immediately terminated; failed-login attempts are rate-limited to mitigate brute-force attacks.
  • Logging and monitoring: application errors and security-relevant events are logged and monitored via our error-tracking sub-processor for detection and incident response.

The Processor reviews these measures periodically and updates them as the Services evolve. This description reflects the measures in place as of the "Last updated" date above and does not itself constitute a warranty that no security incident can occur.


7. AUDITS

The Processor shall make available to the Controller information reasonably necessary to demonstrate compliance with this DPA and shall allow for and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller, subject to reasonable notice and confidentiality.


8. CONTACT

Questions about this DPA can be sent to admin@brandarmor.ai.