GDPR ANNEX I
DESCRIPTION OF PROCESSING
Effective Date: 1st July 2026
Annex I to the BrainPack Data Processing Agreement
A. LIST OF PARTIES
Data Exporter (Controller)
The Customer identified in the applicable Order Form, Subscription Agreement, Enterprise Agreement, or other governing commercial document.
Role: Controller
Activities: Use of the BrainPack Services.
Data Importer (Processor)
Memetech LTD
Agiou Pavlou 61
Agios Andreas
Nicosia 1007
Cyprus
Role: Processor
Activities: Provision, operation, maintenance, support, hosting, security, analytics, AI processing, and improvement of the Services.
B. DESCRIPTION OF TRANSFER
Subject Matter
Processing of Personal Data through BrainPack SaaS services, including:
• CRM;
• ERP;
• Website Builder;
• Marketing Automation;
• Analytics;
• Dashboards;
• AI Services;
• Workflow Automation;
• Integrations.
Duration
For the duration of:
• the applicable Subscription Term;
• any data retention period;
• any legally required retention period.
Nature of Processing
Processing may include:
• collection;
• storage;
• organization;
• transmission;
• retrieval;
• consultation;
• disclosure;
• deletion;
• backup;
• AI processing;
• analytics;
• security monitoring.
Purposes
Processing necessary to:
• provide Services;
• provide AI functionality;
• provide support;
• maintain security;
• maintain backups;
• perform analytics;
• improve Services;
• comply with legal obligations.
Categories of Data Subjects
May include:
• employees;
• contractors;
• customers;
• prospects;
• suppliers;
• website visitors;
• business contacts;
• end users;
• applicants;
• service providers.
Categories of Personal Data
May include:
• names;
• email addresses;
• phone numbers;
• business information;
• CRM records;
• ERP records;
• communications;
• support tickets;
• billing records;
• IP addresses;
• device identifiers;
• usage logs;
• uploaded files;
• AI prompts;
• AI interaction data.
Special Categories
Customer determines whether Special Categories of Data are submitted.
Unless expressly agreed in writing, BrainPack does not require or request Special Categories of Personal Data.
GDPR ANNEX II
TECHNICAL AND ORGANIZATIONAL MEASURES (TOMs)
Annex II to the BrainPack Data Processing Agreement
1. INFORMATION SECURITY GOVERNANCE
BrainPack maintains an information security program designed to protect Personal Data against:
• unauthorized access;
• unauthorized disclosure;
• accidental loss;
• accidental destruction;
• unlawful processing.
2. ACCESS CONTROL
BrainPack may implement:
• role-based access controls;
• least-privilege access;
• multi-factor authentication;
• privileged access management;
• account monitoring;
• password policies.
3. ENCRYPTION
BrainPack may utilize encryption:
In Transit
TLS or successor technologies.
At Rest
Industry-standard encryption mechanisms where reasonably appropriate.
4. NETWORK SECURITY
BrainPack may utilize:
• firewalls;
• intrusion detection systems;
• intrusion prevention systems;
• traffic monitoring;
• DDoS protections;
• endpoint protection.
5. LOGGING AND MONITORING
BrainPack may maintain:
• security logs;
• access logs;
• audit logs;
• application logs;
• monitoring systems.
6. VULNERABILITY MANAGEMENT
BrainPack may implement:
• vulnerability scanning;
• patch management;
• remediation procedures;
• security assessments.
7. BACKUP AND RECOVERY
BrainPack may maintain:
• backups;
• snapshots;
• replication;
• disaster recovery systems.
Backups may be encrypted and geographically distributed.
8. PERSONNEL SECURITY
BrainPack may implement:
• confidentiality agreements;
• security training;
• access reviews;
• onboarding controls;
• offboarding controls.
9. INCIDENT RESPONSE
BrainPack maintains incident response procedures designed to:
• detect incidents;
• investigate incidents;
• mitigate incidents;
• notify customers where required.
10. AI SECURITY
Where AI Services are utilized, BrainPack may implement:
• provider due diligence;
• prompt handling controls;
• access controls;
• monitoring;
• model governance controls.
11. BUSINESS CONTINUITY
BrainPack may maintain:
• business continuity procedures;
• disaster recovery procedures;
• operational resilience measures.
GDPR ANNEX III
AUTHORIZED SUBPROCESSOR CATEGORIES
Annex III to the BrainPack Data Processing Agreement
BrainPack may engage Subprocessors within the following categories:
Cloud Infrastructure Providers
Hosting, compute, storage, networking.
Artificial Intelligence Providers
LLMs, Generative AI, Machine Learning, Agent Frameworks, Inference Services, Embedding Services, Vector Databases.
Analytics Providers
Website analytics, application analytics, user behavior analytics.
Communications Providers
Email delivery, SMS delivery, messaging services, customer communications.
Payment Processors
Payment collection, invoicing, fraud prevention.
Security Providers
Monitoring, threat detection, vulnerability management, identity management.
Customer Support Providers
Ticketing systems, support platforms, customer success tools.
Backup and Disaster Recovery Providers
Backup storage, recovery systems, redundancy services.
Development and DevOps Providers
Deployment, monitoring, observability, infrastructure automation.
BrainPack may add, remove, replace, or modify Subprocessors at any time as reasonably necessary to operate the Services.
BrainPack shall impose contractual obligations designed to protect Personal Data in accordance with applicable law.
BRAINPACK SECURITY OVERVIEW
Security Measures Schedule
Enterprise Due Diligence Package
Security Architecture
BrainPack utilizes a layered security model incorporating:
• authentication controls;
• authorization controls;
• encryption;
• monitoring;
• logging;
• backup systems;
• incident response procedures.
Authentication
Supported controls may include:
• strong passwords;
• MFA;
• role-based access;
• session controls.
Data Protection
BrainPack may utilize:
• encryption in transit;
• encryption at rest;
• backup encryption;
• access restrictions.
Monitoring
BrainPack may monitor:
• infrastructure;
• applications;
• authentication events;
• abnormal activity;
• security alerts.
Incident Management
BrainPack maintains procedures for:
• incident identification;
• incident containment;
• incident investigation;
• remediation;
• customer notification where required.
Backup Strategy
BrainPack may maintain:
• production backups;
• disaster recovery copies;
• redundancy systems;
• geographically distributed backups.
AI Governance Summary
BrainPack may utilize:
• current AI providers;
• future AI providers;
• LLM technologies;
• Generative AI technologies.
BrainPack may replace AI providers without notice.
BrainPack may use anonymized, aggregated, statistical, and de-identified information to improve:
• Services;
• AI systems;
• analytics;
• automation;
• product functionality.
BrainPack does not intentionally disclose Customer Confidential Information to other customers.
Retention Guidelines
Typical retention categories:
Billing Records
Up to 10 years or longer where required by law.
Security Logs
Up to 24 months.
Backups
According to operational requirements.
Customer Data
As described in the Privacy Policy and DPA.
Contact
Security inquiries may be submitted through the contact channels designated by BrainPack.