This Data Processing Addendum (the "DPA") forms part of the Terms of Service between FluxAI US LLC, trading as Brimley ("Brimley", the "Processor"), and the customer that has accepted the Terms (the "Customer", the "Controller"). It governs Brimley's processing of personal data on Customer's behalf to the extent the EU GDPR, UK GDPR, or another applicable data-protection law applies. Capitalised terms used but not defined here have the meanings given in the Terms of Service or, failing that, in the GDPR.
1. Roles & subject matter
In respect of Customer Data that is personal data and that Brimley processes on Customer's instruction ("Customer Personal Data"), Customer is the Controller and Brimley is the Processor. Brimley processes Customer Personal Data only to provide the Service and as described in this DPA, in the Privacy Policy, and in Customer's documented instructions.
The subject matter of processing is the operation of the Service. The duration of processing is the term of the Customer's subscription plus any period during which Customer Personal Data is retained for contractual or legal reasons. The nature and purpose are described in the Terms. Categories of data subjects include Customer's personnel, prospects, and other business contacts. Categories of data include business contact information, professional role, employer, message content drafted or sent through the Service, reply metadata, and related telemetry.
2. Customer instructions
Brimley will process Customer Personal Data only on documented instructions from Customer, including with regard to international transfers, except where required to do otherwise by applicable law (in which case Brimley will inform Customer of that requirement before processing, unless that law prohibits such information). Customer's use of the Service constitutes its instructions.
3. Confidentiality
Brimley ensures that personnel authorised to process Customer Personal Data are bound by appropriate written confidentiality obligations or professional or statutory obligations of confidentiality.
4. Security
Brimley implements and maintains appropriate technical and organisational measures to protect Customer Personal Data, having regard to the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons. These measures are described in Annex II below and may be updated from time to time provided that the level of security is not materially decreased.
5. Subprocessors
Customer grants Brimley a general authorisation to engage subprocessors to process Customer Personal Data, subject to the conditions in this section. Brimley:
- Imposes data-protection obligations on each subprocessor that are no less protective than those in this DPA;
- Remains liable to Customer for the acts and omissions of its subprocessors as if they were its own;
- Maintains a list of subprocessors at Annex I below, and will provide an updated list on request to [email protected];
- Will give Customer at least 14 days' notice of any new subprocessor or material change to an existing one. Customer may object on reasonable data-protection grounds within that period; if the parties cannot agree a resolution, Customer may terminate the affected portion of the Service for convenience.
6. Data subject rights
Brimley provides Customer with self-service tooling to assist with data-subject access, correction, deletion, restriction, and portability requests. Where a data subject contacts Brimley directly, Brimley will not respond on Customer's behalf unless Customer authorises it; Brimley will instead refer the request to Customer without undue delay. Brimley will not be obliged to take any action requiring more than reasonable assistance.
7. Personal data breaches
Brimley will notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a personal-data breach affecting Customer Personal Data. The notice will include the information required by Article 33(3) GDPR to the extent then known, and Brimley will provide further updates as the investigation progresses.
8. International transfers
To the extent Brimley transfers Customer Personal Data out of the EEA, the United Kingdom, or Switzerland to a country that has not received an adequacy decision, the European Commission's Standard Contractual Clauses (Module Two: Controller-to-Processor) and, where applicable, the UK International Data Transfer Addendum, are incorporated into this DPA by reference, with Customer as the data exporter and Brimley as the data importer. The optional clauses, where applicable, are selected to give effect to the substantive provisions of this DPA; governing law is the law of England and Wales.
9. Audits
Brimley will make available to Customer all information reasonably necessary to demonstrate compliance with this DPA, including by providing a current SOC 2 Type II report or equivalent certification on request. On request, and no more than once per twelve-month period, Brimley will respond to a reasonable Customer questionnaire about Brimley's privacy and security practices. Where the GDPR strictly requires an on-site audit, the parties will agree the scope, timing, and cost in advance and conduct the audit so as to minimise disruption to Brimley's other customers.
10. Deletion or return
At Customer's choice, Brimley will delete or return all Customer Personal Data to Customer at the end of the provision of the Service, and will delete existing copies, unless retention is required by law. Suppression-list entries (do-not-contact records) may be retained indefinitely after deletion of the underlying record so that unsubscribe requests can continue to be honoured platform-wide.
11. Conflicts
In the event of a conflict between this DPA and the Terms of Service, this DPA prevails to the extent the conflict relates to processing of personal data. The Standard Contractual Clauses prevail over any conflicting term of this DPA.
Annex I — Subprocessors
Brimley engages the following categories of subprocessor in providing the Service:
- Cloud hosting and infrastructure — to host the Service and store backups.
- Email delivery — Google LLC (Google Workspace), operating under the OAuth credentials Customer authorises.
- AI inference — third-party large-language-model providers that generate message drafts on a transient basis, contractually prohibited from training on Customer Personal Data.
- B2B contact-data providers — third parties that license business-contact records to the Service.
- Payments — a PCI-DSS Level 1 payment processor.
- Operational tooling — error monitoring and transactional-email vendors used for product operations.
A current list of named subprocessors, including the entity, location, and processing activity, is available on request from [email protected].
Annex II — Security measures
Brimley maintains the following technical and organisational measures. These are kept under review and updated as the threat landscape evolves.
- Access control — least-privilege role-based access; multi-factor authentication on administrative accounts; hardware-key-protected production access for engineering staff.
- Encryption in transit — TLS 1.2+ on all public endpoints; HSTS enforced.
- Encryption at rest — disk-level encryption on production databases; application-layer encryption of OAuth refresh tokens and other high-sensitivity secrets.
- Network segmentation — production isolated from corporate and development networks; egress restricted to known service endpoints.
- Logging and monitoring — centralised audit logs, retained for at least 12 months, with alerting on anomalous access patterns.
- Backups — automated daily backups, encrypted at rest, with periodic restore testing.
- Vulnerability management — dependency scanning, vulnerability triage, and patching against an internal SLA based on severity.
- Incident response — a documented incident-response plan, with breach notification to Customer within 72 hours of becoming aware of a personal-data breach.
- Personnel — background checks where lawful, annual security training, and confidentiality obligations on all personnel with access to Customer Personal Data.
- Sub-processor due diligence — security review and contractual data-protection terms before any new subprocessor is engaged.