Data Processing Agreement

Version 1.0 — in force from 26 August 2026

This Data Processing Agreement ("DPA") is entered into between the account holder ("Customer", the controller) and Radim Sekera, operating BriefGate ("BriefGate", the processor), and forms part of the Terms of Service.

It becomes binding when the Customer creates a BriefGate account. No signature is required: Article 28(9) GDPR provides that the contract "shall be in writing, including in electronic form", and acceptance at sign-up satisfies that. BriefGate records which version of this DPA was accepted, by which user, and when; the Customer can retrieve that record at any time from account settings or by asking support.

Where a Customer's own compliance process requires a countersigned copy, ask support and one will be issued naming the same terms.


1. Adoption of the Commission's standard contractual clauses

BriefGate does not use bespoke processing terms. This DPA adopts, in full and unmodified, the standard contractual clauses between controllers and processors set out in the Annex to Commission Implementing Decision (EU) 2021/915 of 4 June 2021 (the "Clauses").

That decision is used deliberately. Article 1 of it states that those clauses "fulfil the requirements for contracts between controllers and processors in Article 28(3) and (4)" of the GDPR — so compliance follows from the instrument itself rather than from anyone's drafting. Clause 2(b) permits their inclusion in a broader contract, which is what this DPA does.

Where the Clauses offer a choice, the following applies:

Clause Selection
Clause 1(a) Option 1 — Regulation (EU) 2016/679 (GDPR)
Clause 5 (Docking clause) Not applied
Clause 7.7 (Sub-processors) Option 2 — general written authorisation, with 30 days' prior notice of changes (section 2 below)

Annexes I to IV of the Clauses are completed by Annexes I to IV of this DPA and form an integral part of it. In the event of a conflict between the Clauses and any other agreement between the parties, the Clauses prevail (Clause 4).

The full text of the Clauses is published in the Official Journal at eur-lex.europa.eu/eli/dec_impl/2021/915.

2. Sub-processors

The Customer gives BriefGate general written authorisation to engage the sub-processors listed in Annex IV.

BriefGate will notify the Customer in writing at least 30 days before adding or replacing a sub-processor. The Customer may object within that period on reasonable data-protection grounds. If BriefGate cannot offer an alternative, the Customer may terminate the affected part of the service without penalty for the remaining prepaid term.

BriefGate imposes on each sub-processor, by contract, data protection obligations equivalent to those in this DPA, and remains fully liable to the Customer for their performance (Clause 7.7(b) and (d)).

3. International transfers

The Clauses do not by themselves cover transfers outside the EEA — Clause 1(f) says so expressly — so this section governs them.

All storage and primary processing takes place in the EU. Application servers run at netcup GmbH in Nuremberg, Germany; files are stored in Cloudflare R2 buckets carrying the EU jurisdiction restriction.

Transfers do occur to the US-based sub-processors named in Annex IV. For each, the transfer rests on the EU-U.S. Data Privacy Framework adequacy decision (Commission Implementing Decision (EU) 2023/1795), each of those companies being an active participant, and additionally on the standard contractual clauses adopted under Commission Implementing Decision (EU) 2021/914, which each of them incorporates into its own processing terms.

Both bases are maintained on purpose. The adequacy decision is currently subject to an appeal before the Court of Justice (Case C-703/25 P, following the General Court's dismissal of the action in Case T-553/23 on 3 September 2025). Should the adequacy decision cease to apply, the 2021/914 clauses continue to cover the same transfers without interruption, and BriefGate will notify Customers rather than let a transfer continue without a valid basis.

4. Assistance, breaches, and audits

Data subject requests. The Customer is the controller and answers requests from its own clients. BriefGate will not respond to a data subject directly, and will notify the Customer promptly of any request it receives (Clause 8(a)). GET /v1/audit?client_email=…, GET /v1/intakes/:id/results and DELETE /v1/intakes/:id exist so that access, portability and erasure requests can be answered without BriefGate's involvement.

Personal data breaches. BriefGate will notify the Customer without undue delay after becoming aware of a breach affecting data it processes, with the information listed in Clause 9.2, sent to the account's registered email address. Where all facts are not yet available the first notice will carry what is known and the rest will follow.

Audits. BriefGate will make available the information necessary to demonstrate compliance (Clause 7.6(c)). Where that is not sufficient for the Customer's obligations, an audit may be carried out by the Customer or an independent auditor at reasonable notice, no more than once a year except where there are indications of non-compliance.

5. Deletion and return

On termination the Customer chooses whether personal data is deleted or returned; absent a choice within 30 days, it is deleted (Clause 10(d)). Results remain retrievable in machine-readable form through GET /v1/intakes/:id/results until then.

During the term, retention follows what the Customer configures: 90 days after completion by default, adjustable between 1 and 3650 days, or removal roughly 24 hours after the Customer collects the results (retention.mode: "on_delivery"). DELETE /v1/intakes/:id erases an intake, its files and its chase history immediately and irreversibly.

Backups are encrypted and retained for 14 days, so data erased on request may persist in an encrypted backup for up to that period before ageing out.


Annex I — List of parties

Controller (data exporter): the Customer, as identified by the account record — the account name, the registered email address of the owning user, and any other users the Customer authorises. The Customer's acceptance of the Terms of Service constitutes its signature for the purposes of the Clauses, on the date the account was created.

Processor (data importer): Radim Sekera, trading as BriefGate. Contact for data protection matters: [email protected]. Acceptance of a Customer account constitutes BriefGate's signature.

Neither party has designated a data protection officer; neither meets the criteria in Article 37(1) GDPR.

Annex II — Description of the processing

Categories of data subjects

Categories of personal data

Category Contents
Client contact data Email address; name where supplied; telephone number where SMS reminders are used; time zone; language preference
Submitted content Whatever the Customer's item definitions request: text, structured values, colours, URLs, boolean answers, and uploaded files. Files may contain personal data the Customer did not anticipate — photographs of identifiable people, documents naming third parties — because the client chooses what to upload
Credentials Values submitted to secret items — passwords, API keys, hosting logins — held only as libsodium sealed-box ciphertext
Account user data Name, email address, argon2id password hash, session records
Technical records IP addresses attached to sessions, portal sessions and audit entries; timestamps; delivery status and bounce records for reminders

Sensitive data. BriefGate does not request data of the special categories in Article 9 GDPR and none of its item types is designed to collect it. It cannot be excluded that a client uploads a file containing such data on their own initiative. Where the Customer knows an intake will involve special-category data it must say so before creating it, so that additional safeguards can be agreed. The measures in Annex III — encryption at rest, access confined to signed URLs, audit logging of every reveal, configurable short retention — apply to all uploaded content regardless.

Nature of the processing. Collection, storage, validation, structured retrieval, transmission of reminder emails and optional SMS, and erasure — carried out on the Customer's documented instructions, which are given through the API and the account settings.

Purpose. To let the Customer request project material from its clients, chase the client until it arrives, and return it to the Customer in a structured form.

Duration. For the term of the Customer's account, and thereafter as set out in section 5. Per-intake retention is as configured by the Customer.

Frequency. Continuous for the duration of the agreement.

Annex III — Technical and organisational measures

Described concretely, as the explanatory note to the Clauses requires.

Encryption of personal data

Access control and authorisation

Storage and residency

Integrity and event logging

Data minimisation and limited retention

Assistance to the controller

The API endpoints named in section 4 are the mechanism by which BriefGate assists with data subject requests. For breach notification, the contact is the account's registered email address.

Measures not in place. BriefGate holds no ISO 27001 or SOC 2 certification and commissions no external penetration test. It is operated by one person. This is stated because a compliance assessment should rest on what exists.

Annex IV — List of sub-processors

Sub-processor Role Location Basis for transfer
netcup GmbH Application and database hosting Germany (EU) No transfer — processing stays in the EU
Cloudflare, Inc. File storage (R2, EU jurisdiction), website delivery US company, data held in the EU EU-U.S. Data Privacy Framework (active) and SCCs 2021/914
Plus Five Five, Inc. (Resend) Transactional email delivery US EU-U.S. Data Privacy Framework (active, re-certification under review) and SCCs 2021/914
Twilio Inc. SMS delivery, only where the Customer enables it US EU-U.S. Data Privacy Framework (active) and SCCs 2021/914
Stripe, LLC Payment processing — Customer billing data only, never client data US EU-U.S. Data Privacy Framework (active) and SCCs 2021/914

Participation in the Data Privacy Framework was verified against the official list at dataprivacyframework.gov on 26 August 2026. The current list of sub-processors is this page; changes are notified as set out in section 2.


The English text of this DPA governs. Translations are provided for convenience and, where they differ, the English version prevails.