Skip to Content Skip to content

BRAINPACK DATA PROCESSING AGREEMENT (DPA)

Version 1.0
Effective Date: 1st July 2026
GDPR / UK GDPR Compliance

This Data Processing Agreement ("DPA") forms part of and is incorporated into the BrainPack Master Terms of Service ("Terms") entered into between Memetech LTD, a company incorporated under the laws of Cyprus ("BrainPack", "Processor"), and the Customer identified in the applicable Order ("Customer", "Controller").

This DPA applies whenever BrainPack Processes Personal Data on behalf of Customer in connection with the Services.

 

1. DEFINITIONS

Unless otherwise defined herein, capitalized terms shall have the meanings assigned to them in the Terms.

"Applicable Data Protection Law" means the GDPR, UK GDPR, Cyprus privacy laws, and any applicable data protection legislation governing the Processing of Personal Data.

"Controller" means the entity that determines the purposes and means of Processing Personal Data.

"Processor" means the entity that Processes Personal Data on behalf of the Controller.

"Personal Data" means any information relating to an identified or identifiable natural person.

"Processing" shall have the meaning assigned under applicable data protection law and includes collection, storage, use, disclosure, transmission, analysis, deletion, and destruction.

"Subprocessor" means any third party engaged by BrainPack to Process Personal Data on behalf of Customer.

"Security Incident" means any confirmed unauthorized access to, acquisition of, disclosure of, alteration of, or destruction of Personal Data.

 

2. SCOPE AND ROLE OF THE PARTIES

The parties acknowledge and agree that:

(a) Customer acts as Controller with respect to Personal Data submitted to the Services;
(b) BrainPack acts as Processor when Processing Personal Data on behalf of Customer;
(c) certain Processing activities may be performed by BrainPack as an independent Controller where required by law or where BrainPack determines its own purposes and means of Processing.

Nothing in this DPA shall prevent BrainPack from Processing information as an independent Controller where such Processing is permitted under applicable law.

 

3. PROCESSING INSTRUCTIONS

BrainPack shall Process Personal Data solely:

(a) to provide the Services;
(b) to comply with documented instructions from Customer;
(c) to comply with applicable law;
(d) to secure, maintain, improve, and support the Services;
(e) to investigate fraud, abuse, security threats, and unlawful activities.

Customer hereby instructs BrainPack to Process Personal Data as necessary to perform the Services and all activities reasonably related thereto.

 

4. NATURE AND PURPOSE OF PROCESSING

Processing activities may include:

  • hosting;
  • storage;
  • transmission;
  • backup;
  • retrieval;
  • organization;
  • indexing;
  • encryption;
  • analytics;
  • customer support;
  • security monitoring;
  • artificial intelligence processing;
  • workflow automation;
  • data export;
  • disaster recovery.

The purpose of Processing is to provide, secure, maintain, improve, and support the Services.

 

5. CATEGORIES OF DATA SUBJECTS

Depending upon Customer's use of the Services, Personal Data may relate to:

  • employees;
  • contractors;
  • customers;
  • prospects;
  • suppliers;
  • website visitors;
  • business contacts;
  • end users;
  • applicants;
  • service providers.


6. CATEGORIES OF PERSONAL DATA

Personal Data may include:

  • names;
  • contact details;
  • email addresses;
  • telephone numbers;
  • user credentials;
  • IP addresses;
  • device identifiers;
  • communications;
  • CRM records;
  • ERP records;
  • support tickets;
  • uploaded files;
  • AI prompts;
  • AI interaction data;
  • operational records;
  • business information.

Customer determines the categories of Personal Data submitted to the Services.

 

7. CONFIDENTIALITY

BrainPack shall ensure that personnel authorized to Process Personal Data:

(a) are subject to confidentiality obligations;
(b) receive appropriate training;
(c) access Personal Data only where necessary to perform their duties.

Such confidentiality obligations shall survive termination of employment or engagement.

 

8. SECURITY MEASURES

BrainPack shall maintain commercially reasonable technical and organizational measures designed to protect Personal Data.

Such measures may include:

  • encryption;
  • access controls;
  • authentication mechanisms;
  • network security controls;
  • monitoring systems;
  • logging systems;
  • backup systems;
  • incident response procedures.

BrainPack may modify security measures from time to time provided that overall protection is not materially reduced.

 

9. SUBPROCESSORS

Customer grants BrainPack a general authorization to engage Subprocessors in connection with the provision of the Services:

  • cloud infrastructure;
  • hosting;
  • artificial intelligence;
  • analytics;
  • cybersecurity;
  • communications;
  • customer support;
  • payment processing;
  • monitoring;
  • backup services.

BrainPack shall provide Customer with reasonable prior written notice of any intended addition or replacement of a Subprocessor, thereby giving Customer an opportunity to object to such change on reasonable data protection grounds.

BrainPack shall impose contractual obligations on Subprocessors that are materially consistent with the data protection obligations contained in this DPA.

 

10. AI PROCESSING

Customer expressly acknowledges that BrainPack may utilize:

  • Large Language Models (LLMs);
  • Generative AI systems;
  • Machine Learning systems;
  • AI Agents;
  • current and future AI providers;

for the performance of the Services.

Where Personal Data is submitted to AI-enabled Services, Customer instructs BrainPack to Process such Personal Data as necessary to provide AI functionality requested by Customer.

BrainPack may replace, add, remove, or modify AI providers at any time.

BrainPack shall implement reasonable safeguards designed to protect Personal Data processed through AI-enabled Services.

 

END OF DPA – PART IBRAINPACK DATA PROCESSING AGREEMENT (DPA)

PART II

INTERNATIONAL TRANSFERS | DATA SUBJECT RIGHTS | SECURITY INCIDENTS | AUDITS | DATA RETURN & DELETION

 

11. INTERNATIONAL DATA TRANSFERS

11.1 Global Processing

Customer acknowledges and agrees that BrainPack operates a global infrastructure and may Process Personal Data in any jurisdiction worldwide where BrainPack, its Affiliates, Subprocessors, service providers, cloud providers, AI providers, infrastructure providers, or support providers maintain operations.

Customer expressly authorizes such international Processing activities.

 

11.2 Transfer Mechanisms

Where required under Applicable Data Protection Law, BrainPack shall implement appropriate transfer mechanisms, including:

(a) Standard Contractual Clauses approved by the European Commission;
(b) UK International Data Transfer Addendum;
(c) adequacy decisions;
(d) approved certification mechanisms;
(e) other lawful transfer mechanisms recognized by applicable law.

 

11.3 Customer Authorization

Customer expressly authorizes BrainPack to transfer Personal Data internationally where reasonably necessary to:

  • provide Services;
  • provide support;
  • maintain Services;
  • perform AI processing;
  • perform backup and recovery;
  • conduct security monitoring;
  • perform analytics;
  • operate infrastructure.

 

12. DATA SUBJECT REQUESTS

12.1 Customer Responsibility

Customer shall remain primarily responsible for responding to requests from Data Subjects.

Such requests may include:

  • access requests;
  • rectification requests;
  • deletion requests;
  • portability requests;
  • restriction requests;
  • objection requests.

 

12.2 Assistance

Taking into account the nature of Processing and available technology, BrainPackshall provide commercially reasonable assistance to Customer in responding to Data Subject Requests where required by Applicable Data Protection Law.

BrainPack may charge reasonable fees for substantial assistance requests.

 

12.3 Direct Requests

If BrainPack receives a Data Subject Request directly relating to Personal Data Processed on behalf of Customer, BrainPack may:

(a) refer the request to Customer;
(b) notify Customer;
(c) respond where legally required.

 

13. SECURITY INCIDENTS

13.1 Incident Response

BrainPack shall maintain reasonable incident response procedures designed to identify, investigate, mitigate, and respond to Security Incidents.

 

13.2 Notification

Upon becoming aware of a confirmed Security Incident affecting Personal Data Processed on behalf of Customer, BrainPack shall notify Customer without undue delay.

Such notification may include available information concerning:

  • nature of the incident;
  • categories of affected data;
  • known consequences;
  • mitigation measures.

 

13.3 Ongoing Investigation

BrainPack may provide information in phases as information becomes available.

BrainPack shall not be required to disclose information that:

(a) would compromise security;
(b) would violate law;
(c) would compromise ongoing investigations.

 

13.4 No Admission

Notification of a Security Incident shall not constitute:

  • admission of liability;
  • admission of fault;
  • admission of breach.

 

14. AUDIT RIGHTS

14.1 Audit Requests

Where required under Applicable Data Protection Law, Customer may request information reasonably necessary to demonstrate BrainPack's compliance with this DPA.

 

14.2 Alternative Compliance Evidence

BrainPack may satisfy audit requests by providing:

  • security certifications;
  • compliance reports;
  • audit reports;
  • questionnaires;
  • policy summaries;
  • independent assessments.

 

14.3 Audit Limitations

To protect:

  • confidential information;
  • trade secrets;
  • intellectual property;
  • security systems;

BrainPack may impose reasonable restrictions on audit activities.

 

14.4 Audit Costs

Unless otherwise required by law, Customer shall bear its own audit costs.

BrainPack may charge reasonable fees for excessive, repetitive, or burdensome audit requests.

 

15. RETURN OF PERSONAL DATA

15.1 Return Upon Request

Following termination or expiration of Services, Customer may request return of Personal Data during the applicable data retention period.

Data may be provided in a format determined by BrainPack.

 

15.2 Exclusions

BrainPack shall have no obligation to provide:

  • source code;
  • proprietary databases;
  • internal architectures;
  • AI models;
  • algorithms;
  • derived analytics;
  • system metadata;
  • proprietary configurations.

 

15.3 Export Fees

BrainPack may charge reasonable fees for extensive export requests requiring substantial resources.

 

16. DELETION OF PERSONAL DATA

16.1 Deletion Following Retention Period

Subject to legal, regulatory, contractual, security, backup, operational, and compliance obligations, BrainPack may delete Personal Data following expiration of applicable retention periods.

 

16.2 Retained Information

BrainPack may retain information where necessary for:

  • legal compliance;
  • regulatory compliance;
  • tax obligations;
  • dispute resolution;
  • enforcement of agreements;
  • security investigations;
  • backup systems.

 

16.3 Backup Systems

Personal Data may remain within backup systems for a reasonable period following deletion from production systems.

 

17. CUSTOMER OBLIGATIONS

Customer represents, warrants, and covenants that:

(a) Customer possesses a lawful basis for Processing Personal Data;
(b) Customer has provided all required notices;
(c) Customer has obtained all required consents;
(d) Customer complies with Applicable Data Protection Law;
(e) Customer's instructions do not violate applicable law.

Customer shall be solely responsible for the legality, quality, accuracy, and appropriateness of Personal Data submitted to the Services.

 

18. LIABILITY

The liability of the parties under this DPA shall be governed exclusively by the liability provisions contained in the BrainPack Master Terms of Service.

Nothing in this DPA shall expand BrainPack's liability beyond the limitations expressly set forth in the Terms.

 

19. ORDER OF PRECEDENCE

In the event of conflict between:

(a) this DPA;

and

(b) the BrainPack Master Terms of Service,

this DPA shall prevail solely with respect to Personal Data Processing obligations.

For all other matters, the Terms shall prevail.

 

20. TERM

This DPA shall remain effective for so long as BrainPack Processes Personal Data on behalf of Customer.

Termination of the Services shall automatically terminate this DPA except for provisions that by their nature survive termination.

 

21. GOVERNING LAW

This DPA shall be governed by and construed in accordance with the laws of the Republic of Cyprus, except where Applicable Data Protection Law mandates otherwise.

 

22. JUR​ISDICTION

Subject to mandatory provisions of Applicable Data Protection Law, the courts of Cyprus shall have exclusive jurisdiction over disputes arising from or relating to this DPA.

 

23. FINAL ACKNOWLEDGEMENT

Customer acknowledges and agrees that:

(a) BrainPack may engage current and future AI providers;
(b) BrainPack may utilize Generative AI and Large Language Models as part of the Services;
(c) BrainPack may engage global Subprocessors;
(d) Personal Data may be Processed internationally;
(e) BrainPack may utilize anonymized, aggregated, statistical, and de-identified information for service improvement, analytics, benchmarking, research, development, and proprietary AI model enhancement, to the extent permitted by applicable law.

 

END OF BRAINPACK DATA PROCESSING AGREEMENT (DPA) – Version 1.0