Data Processing Agreement
How we process personal data on your behalf as a GDPR processor.
[DRAFT — needs legal review before publishing. This is a standard-shape Data Processing Agreement scaffold; it has not been reviewed by counsel, and the placeholders below must be filled in with Brand Armor AI's actual entity details.]
Last updated: [NEEDS: publish date]
This Data Processing Agreement ("DPA") forms part of the agreement between Brand Armor AI("Processor", see our Imprint for full entity details) and the customer ("Controller") for the provision of the Brand Armor AIServices, and reflects the parties' agreement with regard to the Processing of Personal Data under Regulation (EU) 2016/679 ("GDPR") Article 28.
1. SUBJECT MATTER AND DURATION
The Processor processes Personal Data on behalf of the Controller for the duration of the underlying subscription agreement, solely to provide the Brand Armor AI Services (AI visibility monitoring, brand analytics, and related reporting).
2. NATURE AND PURPOSE OF PROCESSING
The Processor processes Personal Data to operate the Services: authenticating and supporting Controller's users, generating AI-visibility reports, and providing customer support. Categories of data subjects are the Controller's authorized users. Categories of Personal Data are limited to account data (name, email, role) and usage/log data — see our Privacy Policy for the full description.
3. PROCESSOR OBLIGATIONS
The Processor shall: (a) process Personal Data only on documented instructions from the Controller; (b) ensure persons authorized to process the data are subject to confidentiality; (c) implement appropriate technical and organizational security measures; (d) assist the Controller in responding to data subject requests; (e) delete or return Personal Data at the end of the engagement; and (f) make available information necessary to demonstrate compliance.
4. SUB-PROCESSORS
The Controller provides general authorization for the Processor to engage sub-processors, provided the Processor maintains a current list at /sub-processors and notifies the Controller of any intended changes, giving the Controller the opportunity to object.
5. INTERNATIONAL TRANSFERS
Where Personal Data is transferred outside the European Economic Area, the Processor relies on [NEEDS: name the transfer mechanism actually in use — e.g. the European Commission's Standard Contractual Clauses with each relevant sub-processor] to ensure an adequate level of protection.
6. SECURITY MEASURES
[NEEDS: describe the technical and organizational measures actually in place — encryption in transit/at rest, access controls, secrets management, incident response process.]
7. AUDITS
The Processor shall make available to the Controller information reasonably necessary to demonstrate compliance with this DPA and shall allow for and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller, subject to reasonable notice and confidentiality.
8. CONTACT
Questions about this DPA can be sent to admin@brandarmor.ai.
