Skip to Content Skip to content

GDPR ANNEX I

DESCRIPTION OF PROCESSING
Effective Date: 1st July 2026

Annex I to the BrainPack Data Processing Agreement

A. LIST OF PARTIES

Data Exporter (Controller)

The Customer identified in the applicable Order Form, Subscription Agreement, Enterprise Agreement, or other governing commercial document.

Role: Controller

Activities: Use of the BrainPack Services.

 

Data Importer (Processor)

Memetech LTD
Agiou Pavlou 61
Agios Andreas
Nicosia 1007
Cyprus

Role: Processor

Activities: Provision, operation, maintenance, support, hosting, security, analytics, AI processing, and improvement of the Services.

 

B. DESCRIPTION OF TRANSFER

Subject Matter

Processing of Personal Data through BrainPack SaaS services, including:

• CRM;

• ERP;

• Website Builder;

• Marketing Automation;

• Analytics;

• Dashboards;

• AI Services;

• Workflow Automation;

• Integrations.

 

Duration

For the duration of:

• the applicable Subscription Term;

• any data retention period;

• any legally required retention period.

 

Nature of Processing

Processing may include:

• collection;

• storage;

• organization;

• transmission;

• retrieval;

• consultation;

• disclosure;

• deletion;

• backup;

• AI processing;

• analytics;

• security monitoring.

 

Purposes

Processing necessary to:

• provide Services;

• provide AI functionality;

• provide support;

• maintain security;

• maintain backups;

• perform analytics;

• improve Services;

• comply with legal obligations.

 

Categories of Data Subjects

May include:

• employees;

• contractors;

• customers;

• prospects;

• suppliers;

• website visitors;

• business contacts;

• end users;

• applicants;

• service providers.

 

Categories of Personal Data

May include:

• names;

• email addresses;

• phone numbers;

• business information;

• CRM records;

• ERP records;

• communications;

• support tickets;

• billing records;

• IP addresses;

• device identifiers;

• usage logs;

• uploaded files;

• AI prompts;

• AI interaction data.

 

Special Categories

Customer determines whether Special Categories of Data are submitted.

Unless expressly agreed in writing, BrainPack does not require or request Special Categories of Personal Data.

 

GDPR ANNEX II

TECHNICAL AND ORGANIZATIONAL MEASURES (TOMs)

Annex II to the BrainPack Data Processing Agreement

 

1. INFORMATION SECURITY GOVERNANCE

BrainPack maintains an information security program designed to protect Personal Data against:

• unauthorized access;

• unauthorized disclosure;

• accidental loss;

• accidental destruction;

• unlawful processing.

 

2. ACCESS CONTROL

BrainPack may implement:

• role-based access controls;

• least-privilege access;

• multi-factor authentication;

• privileged access management;

• account monitoring;

• password policies.

 

3. ENCRYPTION

BrainPack may utilize encryption:

In Transit

TLS or successor technologies.

At Rest

Industry-standard encryption mechanisms where reasonably appropriate.

 

4. NETWORK SECURITY

BrainPack may utilize:

• firewalls;

• intrusion detection systems;

• intrusion prevention systems;

• traffic monitoring;

• DDoS protections;

• endpoint protection.

 

5. LOGGING AND MONITORING

BrainPack may maintain:

• security logs;

• access logs;

• audit logs;

• application logs;

• monitoring systems.

 

6. VULNERABILITY MANAGEMENT

BrainPack may implement:

• vulnerability scanning;

• patch management;

• remediation procedures;

• security assessments.

 

7. BACKUP AND RECOVERY

BrainPack may maintain:

• backups;

• snapshots;

• replication;

• disaster recovery systems.

Backups may be encrypted and geographically distributed.

 

8. PERSONNEL SECURITY

BrainPack may implement:

• confidentiality agreements;

• security training;

• access reviews;

• onboarding controls;

• offboarding controls.

 

9. INCIDENT RESPONSE

BrainPack maintains incident response procedures designed to:

• detect incidents;

• investigate incidents;

• mitigate incidents;

• notify customers where required.

 

10. AI SECURITY

Where AI Services are utilized, BrainPack may implement:

• provider due diligence;

• prompt handling controls;

• access controls;

• monitoring;

• model governance controls.

 

11. BUSINESS CONTINUITY

BrainPack may maintain:

• business continuity procedures;

• disaster recovery procedures;

• operational resilience measures.

 

GDPR ANNEX III

AUTHORIZED SUBPROCESSOR CATEGORIES

Annex III to the BrainPack Data Processing Agreement

 

BrainPack may engage Subprocessors within the following categories:

Cloud Infrastructure Providers

Hosting, compute, storage, networking.

 

Artificial Intelligence Providers

LLMs, Generative AI, Machine Learning, Agent Frameworks, Inference Services, Embedding Services, Vector Databases.

 

Analytics Providers

Website analytics, application analytics, user behavior analytics.

 

Communications Providers

Email delivery, SMS delivery, messaging services, customer communications.

 

Payment Processors

Payment collection, invoicing, fraud prevention.

 

Security Providers

Monitoring, threat detection, vulnerability management, identity management.

 

Customer Support Providers

Ticketing systems, support platforms, customer success tools.

 

Backup and Disaster Recovery Providers

Backup storage, recovery systems, redundancy services.

 

Development and DevOps Providers

Deployment, monitoring, observability, infrastructure automation.

 

BrainPack may add, remove, replace, or modify Subprocessors at any time as reasonably necessary to operate the Services.

BrainPack shall impose contractual obligations designed to protect Personal Data in accordance with applicable law.

 

BRAINPACK SECURITY OVERVIEW

Security Measures Schedule

Enterprise Due Diligence Package

 

Security Architecture

BrainPack utilizes a layered security model incorporating:

• authentication controls;

• authorization controls;

• encryption;

• monitoring;

• logging;

• backup systems;

• incident response procedures.

 

Authentication

Supported controls may include:

• strong passwords;

• MFA;

• role-based access;

• session controls.

 

Data Protection

BrainPack may utilize:

• encryption in transit;

• encryption at rest;

• backup encryption;

• access restrictions.

 

Monitoring

BrainPack may monitor:

• infrastructure;

• applications;

• authentication events;

• abnormal activity;

• security alerts.

 

Incident Management

BrainPack maintains procedures for:

• incident identification;

• incident containment;

• incident investigation;

• remediation;

• customer notification where required.

 

Backup Strategy

BrainPack may maintain:

• production backups;

• disaster recovery copies;

• redundancy systems;

• geographically distributed backups.

 

AI Governance Summary

BrainPack may utilize:

• current AI providers;

• future AI providers;

• LLM technologies;

• Generative AI technologies.

BrainPack may replace AI providers without notice.

BrainPack may use anonymized, aggregated, statistical, and de-identified information to improve:

• Services;

• AI systems;

• analytics;

• automation;

• product functionality.

BrainPack does not intentionally disclose Customer Confidential Information to other customers.

 

Retention Guidelines

Typical retention categories:

Billing Records

Up to 10 years or longer where required by law.

Security Logs

Up to 24 months.

Backups

According to operational requirements.

Customer Data

As described in the Privacy Policy and DPA.

 

Contact

Security inquiries may be submitted through the contact channels designated by BrainPack.