brightstack AI, Inc.
Data Processing Addendum
This Data Processing Addendum forms part of the agreement between you (the Customer) and brightstack AI, Inc. for the processing of personal data under EU and UK GDPR.
- Effective
- April 27, 2026
- Last updated
- April 27, 2026
Introduction
This Data Processing Addendum ("DPA") is incorporated by reference into the Terms of Service or other written agreement (the "Agreement") between Customer and brightstack AI, Inc. (brightstack) governing Customer's use of the Service. This DPA governs the Processing of Personal Data by brightstack on behalf of Customer in connection with the Agreement.
This DPA is a click-through agreement: by accepting the Agreement and using the Service, Customer accepts this DPA on behalf of itself and any Authorized Affiliates whose Personal Data is Processed by brightstack under the Agreement. Customers requiring a counter-signed version may contact [email protected].
In the event of a conflict between this DPA and the Agreement with respect to the Processing of Personal Data, this DPA controls.
1. Definitions
Capitalized terms not defined in this DPA have the meanings given in the Agreement or in applicable Data Protection Laws. The following terms apply throughout this DPA:
- "Customer Personal Data" means Personal Data that brightstack Processes on behalf of Customer in providing the Service.
- "Data Protection Laws" means all laws and regulations applicable to the Processing of Customer Personal Data, including (i) the EU General Data Protection Regulation 2016/679 ("EU GDPR"); (ii) the UK Data Protection Act 2018 and the UK GDPR ("UK GDPR"); (iii) the Swiss Federal Act on Data Protection ("Swiss FADP"); and (iv) US state privacy laws including the CCPA / CPRA, VCDPA, CPA, CTDPA, and equivalents.
- "Standard Contractual Clauses" or "SCCs" means the standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission in Decision 2021/914 of 4 June 2021 (Module 2: Controller to Processor).
- "UK Addendum" means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, issued by the UK Information Commissioner.
- "Subprocessor" means any Processor engaged by brightstack (or by another Subprocessor) to Process Customer Personal Data.
The terms Controller, Processor, Data Subject, Personal Data, Personal Data Breach, Process/Processing, and Supervisory Authority have the meanings given in the GDPR.
2. Roles and responsibilities
- For the purposes of Data Protection Laws, Customer is the Controller of Customer Personal Data and brightstack is the Processor.
- Where Customer Personal Data originates from a third-party Controller (for example, Customer's own customer or end user), Customer is acting as a Processor or sub-Processor and brightstack is acting as a sub-Processor. Customer is responsible for obtaining the necessary authorizations from the upstream Controller.
- Each party will comply with its obligations under applicable Data Protection Laws.
3. Processing of personal data
3.1 Subject matter and instructions
brightstack will Process Customer Personal Data only on documented instructions from Customer, including with regard to transfers of Customer Personal Data to a third country or international organization, unless required to do so by Union or Member State law to which brightstack is subject (in which case brightstack will inform Customer of that legal requirement before Processing, unless that law prohibits such information on important grounds of public interest).
The Agreement (including this DPA, the Service configuration, any order form, and Customer's use of the Service) constitutes Customer's complete and final instructions to brightstack regarding the Processing of Customer Personal Data.
3.2 Details of Processing
The subject matter, duration, nature and purpose of the Processing, the types of Personal Data, and the categories of Data Subjects are set out in Annex I (Processing details).
3.3 Confidentiality
brightstack will ensure that persons authorized to Process Customer Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. brightstack will limit access to Customer Personal Data to personnel who require such access to perform the Service.
3.4 Customer responsibilities
Customer is responsible for the lawfulness of Customer Personal Data and the instructions Customer provides to brightstack, including providing all required notices to and obtaining all required consents from Data Subjects. Customer will not provide Customer Personal Data to brightstack that is subject to specific legal protections beyond those that apply to Personal Data generally (for example, HIPAA PHI, PCI cardholder data, or government-classified information) unless expressly agreed in writing.
3.5 No model training
brightstack will not use Customer Personal Data to train, fine-tune, or evaluate generally available AI models, and will not permit any Subprocessor to do so. Customer Personal Data is sent to inference Subprocessors only as needed to generate Outputs for Customer.
4. Security
brightstack will implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of Processing as well as the risk to Data Subjects. The current measures are described in Annex II (Technical and organizational measures). brightstack may update these measures from time to time, provided that no update will materially decrease the overall level of protection.
5. Subprocessors
- Customer grants brightstack a general authorization to engage Subprocessors, subject to this Section 5.
- brightstack maintains a current list of Subprocessors at brightstack.ai/legal/subprocessors, which is incorporated into this DPA by reference and reproduced in Annex III.
- brightstack will provide Customer with at least 10 business days' prior written notice (which may be by email or a notice on the Subprocessors page) of any new Subprocessor or material change to an existing one. Customer may subscribe to change notifications by emailing [email protected] with the subject "subprocessors."
- Customer may object on reasonable grounds related to data protection within the notice period by emailing the address above. brightstack will work in good faith to resolve the objection. If no resolution can be reached, Customer may terminate the affected portion of the Service for convenience without penalty.
- brightstack will impose data protection obligations on each Subprocessor that are no less protective than those in this DPA and remains liable to Customer for the acts and omissions of its Subprocessors as if they were its own.
6. Data subject rights
Taking into account the nature of the Processing, brightstack will assist Customer by appropriate technical and organizational measures, insofar as this is possible, in fulfilling Customer's obligation to respond to requests from Data Subjects to exercise their rights under Data Protection Laws (including rights of access, rectification, erasure, restriction of Processing, data portability, and objection).
If brightstack receives a request directly from a Data Subject relating to Customer Personal Data, brightstack will, unless legally prohibited, promptly forward the request to Customer and will not respond on Customer's behalf except on Customer's documented instructions or as required by law.
7. Personal data breach notification
brightstack will notify Customer without undue delay (and in any event within seventy-two (72) hours) after becoming aware of a Personal Data Breach affecting Customer Personal Data. The notification will, to the extent then known and as such information becomes available, describe: (i) the nature of the Personal Data Breach including the categories and approximate number of Data Subjects and records concerned; (ii) the likely consequences; (iii) the measures taken or proposed to address the Personal Data Breach and to mitigate its possible adverse effects; and (iv) the contact point at brightstack for further information.
brightstack's notification of a Personal Data Breach is not an acknowledgment of fault or liability.
8. Data Protection Impact Assessments and prior consultation
Taking into account the nature of the Processing and the information available to brightstack, brightstack will provide reasonable assistance to Customer with any Data Protection Impact Assessments and prior consultations with Supervisory Authorities that Customer is required to carry out under Data Protection Laws.
9. Return and deletion
On termination or expiration of the Agreement, or upon Customer's written request, brightstack will, at Customer's choice, return or delete all Customer Personal Data in brightstack's possession or control. brightstack will hard-delete Customer Personal Data from active systems within thirty (30) days of termination, unless retention is required by applicable law. Encrypted backups are retired on their normal rotation schedule, no later than ninety (90) days after deletion.
10. Audits and information rights
- brightstack will make available to Customer, upon reasonable request and not more than once per year, the most recent third-party security audit report (for example, SOC 2 Type II) and a summary description of the technical and organizational measures in place. These materials may be provided under NDA.
- To the extent the audit reports made available do not provide sufficient information to demonstrate compliance with this DPA, Customer may, at its own expense, conduct an audit of brightstack's relevant processing activities. Audits will be conducted during business hours, with at least thirty (30) days' prior written notice, no more than once per twelve-month period (except following a Personal Data Breach), and subject to reasonable confidentiality and security requirements. The auditor must not be a competitor of brightstack.
11. International transfers
11.1 EU Standard Contractual Clauses (Module 2)
Where the Processing of Customer Personal Data involves a transfer of Personal Data from the European Economic Area, the United Kingdom, or Switzerland to a third country that has not been recognized as providing an adequate level of protection, the parties agree that the Standard Contractual Clauses, Module 2 (Controller to Processor), are incorporated into this DPA by reference and apply as follows:
- Clause 7 (Docking clause) is included.
- Clause 9 (Use of sub-processors): Option 2 (general written authorization) is selected, with the notice period set to 10 business days as specified in Section 5 of this DPA.
- Clause 11 (Redress): the optional independent dispute resolution body is not selected.
- Clause 17 (Governing law): the SCCs are governed by the law of Ireland.
- Clause 18 (Choice of forum and jurisdiction): the courts of Ireland.
- Annexes I, II, and III to the SCCs are populated by Annexes I, II, and III to this DPA respectively.
11.2 UK International Data Transfer Addendum
For transfers from the United Kingdom, the parties agree that the UK Addendum is incorporated into this DPA by reference. Tables 1, 2, and 3 of the UK Addendum are populated by reference to the SCCs as completed above and by Annexes I-III to this DPA. Table 4 (Ending the Addendum when the Approved Addendum changes): both parties may end the UK Addendum.
11.3 Swiss transfers
For transfers subject to the Swiss FADP, the parties agree that the SCCs apply with the following modifications: (i) references to "Regulation (EU) 2016/679" or "GDPR" mean the Swiss FADP; (ii) the term "Member State" must not be interpreted to exclude Data Subjects in Switzerland from the possibility to enforce their rights in their place of habitual residence; (iii) the supervisory authority is the Swiss Federal Data Protection and Information Commissioner (FDPIC); and (iv) the SCCs are governed by Swiss law.
12. Liability, term, and order of precedence
- Each party's liability arising out of or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Agreement.
- This DPA will continue in force for as long as brightstack Processes Customer Personal Data on behalf of Customer.
- In the event of any conflict between this DPA and the SCCs, the SCCs prevail to the extent strictly necessary to comply with applicable Data Protection Laws.
Annex I - Processing details
A. List of parties
- Data exporter (Controller): Customer, as identified in the Agreement.
- Data importer (Processor): brightstack AI, Inc..
- Contact: [email protected].
- Activities relevant to the data transferred: Provision of the brightstack AI productivity platform.
- Role: Customer is Controller; brightstack is Processor.
B. Description of Processing
| Item | Description |
|---|---|
| Categories of data subjects | Customer's authorized users, end users, customers, employees, and other individuals whose personal data is contained in Inputs or in connected third-party services authorized by Customer. |
| Categories of personal data | Identifiers (name, email, profile photo); professional information (job title, company); communications content (when Customer enables email or chat features); calendar metadata; usage and log data; OAuth tokens for connected services. |
| Sensitive data | Not intended to be processed. Customer is responsible for not submitting sensitive or special category data outside what the Agreement permits. |
| Frequency of transfer | Continuous, for the duration of the Agreement. |
| Nature of processing | Hosting, storage, indexing, retrieval, summarization, agentic actions on connected services, observability, and customer support. |
| Purpose of processing | Providing the Service as described in the Agreement. |
| Retention period | For the duration of the Agreement, with deletion in accordance with Section 9 of this DPA. |
| Sub-processor transfers | See Annex III. |
C. Competent supervisory authority
The competent Supervisory Authority is the Irish Data Protection Commission for EU transfers; the UK Information Commissioner's Office (ICO) for UK transfers; and the Swiss Federal Data Protection and Information Commissioner (FDPIC) for Swiss transfers.
Annex II - Technical and organizational measures
brightstack maintains the following measures, which may evolve over time provided they do not materially decrease the overall level of protection.
- Encryption. All Customer Personal Data in transit is protected with TLS 1.2 or higher. All Customer Personal Data at rest is encrypted with AES-256 or equivalent.
- Access control. Production access is restricted to authorized personnel, gated by single sign-on with mandatory multi-factor authentication and short-lived credentials. Access follows least privilege and is reviewed at least quarterly.
- Network and infrastructure security. Production workloads run on hardened cloud platforms (Fly.io, Neon, Upstash) with network isolation, rate limiting, and continuous monitoring.
- Logging and monitoring. Centralized logging and metrics in Datadog with alerting on security-relevant events; logs are retained for at least 90 days.
- Secure software development. Code review for production changes, automated dependency scanning, static analysis on the main branch, and a documented release process.
- Vulnerability management. Regular vulnerability scanning, patching of critical findings on a defined SLA, and an internal program to triage external reports.
- Backups. Encrypted backups of primary data stores with periodic restore testing.
- Incident response. Documented incident response plan with defined roles, escalation paths, and breach notification procedures aligned with Section 7 of this DPA.
- Personnel. Background checks where permitted by law, security training at onboarding and at least annually, and contractual confidentiality obligations for all personnel with access to Customer Personal Data.
- Vendor management. Subprocessors are reviewed before engagement and contractually bound to data protection obligations no less protective than this DPA.
- Business continuity. Disaster-recovery procedures with defined RTO and RPO targets and periodic testing.
- Data minimization. Customer Personal Data is collected and retained only as necessary to provide the Service.
Annex III - Subprocessors
The following Subprocessors are authorized as of the effective date of this DPA. The current list is maintained at brightstack.ai/legal/subprocessors.
| Subprocessor | Purpose | Location | Categories of data |
|---|---|---|---|
| Vercel, Inc. | Marketing site hosting and CDN | USA (global edge) | Marketing site analytics, IP addresses, request metadata |
| Fly.io, Inc. | Application hosting and compute | USA / multi-region | Customer Data, User Content, request metadata |
| Fireworks AI, Inc. | AI model inference (LLM completions) | USA | Prompts and completions; not used for model training |
| Datadog, Inc. | Logs, metrics, error tracking, and observability | USA / EU | Operational logs, IP addresses, user IDs, error traces |
| Neon, Inc. | PostgreSQL database (primary data store) | USA | Customer Data and User Content at rest |
| Upstash, Inc. | Redis cache and rate limiting | USA | Session tokens, ephemeral cache entries, rate-limit counters |
subprocessors.