Data Processing Agreement
Version 1.0 — in force from 26 August 2026
This Data Processing Agreement ("DPA") is entered into between the account holder ("Customer", the controller) and Radim Sekera, operating BriefGate ("BriefGate", the processor), and forms part of the Terms of Service.
It becomes binding when the Customer creates a BriefGate account. No signature is required: Article 28(9) GDPR provides that the contract "shall be in writing, including in electronic form", and acceptance at sign-up satisfies that. BriefGate records which version of this DPA was accepted, by which user, and when; the Customer can retrieve that record at any time from account settings or by asking support.
Where a Customer's own compliance process requires a countersigned copy, ask support and one will be issued naming the same terms.
1. Adoption of the Commission's standard contractual clauses
BriefGate does not use bespoke processing terms. This DPA adopts, in full and unmodified, the standard contractual clauses between controllers and processors set out in the Annex to Commission Implementing Decision (EU) 2021/915 of 4 June 2021 (the "Clauses").
That decision is used deliberately. Article 1 of it states that those clauses "fulfil the requirements for contracts between controllers and processors in Article 28(3) and (4)" of the GDPR — so compliance follows from the instrument itself rather than from anyone's drafting. Clause 2(b) permits their inclusion in a broader contract, which is what this DPA does.
Where the Clauses offer a choice, the following applies:
| Clause | Selection |
|---|---|
| Clause 1(a) | Option 1 — Regulation (EU) 2016/679 (GDPR) |
| Clause 5 (Docking clause) | Not applied |
| Clause 7.7 (Sub-processors) | Option 2 — general written authorisation, with 30 days' prior notice of changes (section 2 below) |
Annexes I to IV of the Clauses are completed by Annexes I to IV of this DPA and form an integral part of it. In the event of a conflict between the Clauses and any other agreement between the parties, the Clauses prevail (Clause 4).
The full text of the Clauses is published in the Official Journal at eur-lex.europa.eu/eli/dec_impl/2021/915.
2. Sub-processors
The Customer gives BriefGate general written authorisation to engage the sub-processors listed in Annex IV.
BriefGate will notify the Customer in writing at least 30 days before adding or replacing a sub-processor. The Customer may object within that period on reasonable data-protection grounds. If BriefGate cannot offer an alternative, the Customer may terminate the affected part of the service without penalty for the remaining prepaid term.
BriefGate imposes on each sub-processor, by contract, data protection obligations equivalent to those in this DPA, and remains fully liable to the Customer for their performance (Clause 7.7(b) and (d)).
3. International transfers
The Clauses do not by themselves cover transfers outside the EEA — Clause 1(f) says so expressly — so this section governs them.
All storage and primary processing takes place in the EU. Application servers run at netcup GmbH in Nuremberg, Germany; files are stored in Cloudflare R2 buckets carrying the EU jurisdiction restriction.
Transfers do occur to the US-based sub-processors named in Annex IV. For each, the transfer rests on the EU-U.S. Data Privacy Framework adequacy decision (Commission Implementing Decision (EU) 2023/1795), each of those companies being an active participant, and additionally on the standard contractual clauses adopted under Commission Implementing Decision (EU) 2021/914, which each of them incorporates into its own processing terms.
Both bases are maintained on purpose. The adequacy decision is currently subject to an appeal before the Court of Justice (Case C-703/25 P, following the General Court's dismissal of the action in Case T-553/23 on 3 September 2025). Should the adequacy decision cease to apply, the 2021/914 clauses continue to cover the same transfers without interruption, and BriefGate will notify Customers rather than let a transfer continue without a valid basis.
4. Assistance, breaches, and audits
Data subject requests. The Customer is the controller and answers requests
from its own clients. BriefGate will not respond to a data subject directly, and
will notify the Customer promptly of any request it receives (Clause 8(a)).
GET /v1/audit?client_email=…, GET /v1/intakes/:id/results and
DELETE /v1/intakes/:id exist so that access, portability and erasure requests
can be answered without BriefGate's involvement.
Personal data breaches. BriefGate will notify the Customer without undue delay after becoming aware of a breach affecting data it processes, with the information listed in Clause 9.2, sent to the account's registered email address. Where all facts are not yet available the first notice will carry what is known and the rest will follow.
Audits. BriefGate will make available the information necessary to demonstrate compliance (Clause 7.6(c)). Where that is not sufficient for the Customer's obligations, an audit may be carried out by the Customer or an independent auditor at reasonable notice, no more than once a year except where there are indications of non-compliance.
5. Deletion and return
On termination the Customer chooses whether personal data is deleted or
returned; absent a choice within 30 days, it is deleted (Clause 10(d)). Results
remain retrievable in machine-readable form through
GET /v1/intakes/:id/results until then.
During the term, retention follows what the Customer configures: 90 days after
completion by default, adjustable between 1 and 3650 days, or removal roughly
24 hours after the Customer collects the results (retention.mode: "on_delivery"). DELETE /v1/intakes/:id erases an intake, its files and its
chase history immediately and irreversibly.
Backups are encrypted and retained for 14 days, so data erased on request may persist in an encrypted backup for up to that period before ageing out.
Annex I — List of parties
Controller (data exporter): the Customer, as identified by the account record — the account name, the registered email address of the owning user, and any other users the Customer authorises. The Customer's acceptance of the Terms of Service constitutes its signature for the purposes of the Clauses, on the date the account was created.
Processor (data importer): Radim Sekera, trading as BriefGate. Contact for data protection matters: [email protected]. Acceptance of a Customer account constitutes BriefGate's signature.
Neither party has designated a data protection officer; neither meets the criteria in Article 37(1) GDPR.
Annex II — Description of the processing
Categories of data subjects
- The Customer's own clients — the people invited to a portal to supply project material, and any individual identifiable from what they submit.
- The Customer's users — the people who hold seats on the account.
Categories of personal data
| Category | Contents |
|---|---|
| Client contact data | Email address; name where supplied; telephone number where SMS reminders are used; time zone; language preference |
| Submitted content | Whatever the Customer's item definitions request: text, structured values, colours, URLs, boolean answers, and uploaded files. Files may contain personal data the Customer did not anticipate — photographs of identifiable people, documents naming third parties — because the client chooses what to upload |
| Credentials | Values submitted to secret items — passwords, API keys, hosting logins — held only as libsodium sealed-box ciphertext |
| Account user data | Name, email address, argon2id password hash, session records |
| Technical records | IP addresses attached to sessions, portal sessions and audit entries; timestamps; delivery status and bounce records for reminders |
Sensitive data. BriefGate does not request data of the special categories in Article 9 GDPR and none of its item types is designed to collect it. It cannot be excluded that a client uploads a file containing such data on their own initiative. Where the Customer knows an intake will involve special-category data it must say so before creating it, so that additional safeguards can be agreed. The measures in Annex III — encryption at rest, access confined to signed URLs, audit logging of every reveal, configurable short retention — apply to all uploaded content regardless.
Nature of the processing. Collection, storage, validation, structured retrieval, transmission of reminder emails and optional SMS, and erasure — carried out on the Customer's documented instructions, which are given through the API and the account settings.
Purpose. To let the Customer request project material from its clients, chase the client until it arrives, and return it to the Customer in a structured form.
Duration. For the term of the Customer's account, and thereafter as set out in section 5. Per-intake retention is as configured by the Customer.
Frequency. Continuous for the duration of the agreement.
Annex III — Technical and organisational measures
Described concretely, as the explanatory note to the Clauses requires.
Encryption of personal data
- Values submitted to
secretitems are encrypted in the client's browser with a libsodium sealed box before transmission. The private key exists only in the server environment and is never stored in the database, so a complete database dump yields ciphertext alone. - Account passwords and API keys are stored as argon2id hashes; the plaintext of an API key is never retained after creation.
- All connections use TLS; certificates are issued and renewed automatically.
- Database backups are encrypted with
ageto a public key before they leave the host, so the machine that writes a backup cannot read it back.
Access control and authorisation
- Client access to a portal is by single-use magic link, exchanged for a session cookie scoped to that one intake and valid for 14 days.
- Files are served only through signed URLs valid for 24 hours; the URLs are not guessable and are not listable.
- A
secretvalue is released once. The retrieval token is invalidated on first reveal, and the API key used must carry thesecrets:readoradminscope. - Login and sign-up are limited to 10 attempts per hour per IP address.
- API requests are limited per key and per plan (60, 600 or 3000 per hour).
Storage and residency
- Application servers: netcup GmbH, Nuremberg, Germany.
- Files: Cloudflare R2 with the EU jurisdiction restriction, which confines objects to buckets in the EU.
Integrity and event logging
- Sensitive operations are written to an append-only audit log recording the actor, the action, the IP address and the timestamp. The application exposes no path that deletes from it.
- Uploaded files are scanned for malware before they are made available. A file whose scan errors or times out is withheld rather than served unscanned.
- Every uploaded file carries a SHA-256 checksum, returned with the results, so the Customer can verify that what it received is what the client sent.
Data minimisation and limited retention
- Item definitions are declared by the Customer, so only the data the Customer asked for is collected.
- Default retention is 90 days after completion;
retention.mode: "on_delivery"removes contents roughly 24 hours after the Customer collects the results, with a grace window so that one crashed agent does not force the client to do the work twice. anonymize: truedeletes everything belonging to the client while keeping the Customer's own project record.- IP addresses are used only for deduplication, rate limiting and fraud signals, and are never included in webhook payloads.
Assistance to the controller
The API endpoints named in section 4 are the mechanism by which BriefGate assists with data subject requests. For breach notification, the contact is the account's registered email address.
Measures not in place. BriefGate holds no ISO 27001 or SOC 2 certification and commissions no external penetration test. It is operated by one person. This is stated because a compliance assessment should rest on what exists.
Annex IV — List of sub-processors
| Sub-processor | Role | Location | Basis for transfer |
|---|---|---|---|
| netcup GmbH | Application and database hosting | Germany (EU) | No transfer — processing stays in the EU |
| Cloudflare, Inc. | File storage (R2, EU jurisdiction), website delivery | US company, data held in the EU | EU-U.S. Data Privacy Framework (active) and SCCs 2021/914 |
| Plus Five Five, Inc. (Resend) | Transactional email delivery | US | EU-U.S. Data Privacy Framework (active, re-certification under review) and SCCs 2021/914 |
| Twilio Inc. | SMS delivery, only where the Customer enables it | US | EU-U.S. Data Privacy Framework (active) and SCCs 2021/914 |
| Stripe, LLC | Payment processing — Customer billing data only, never client data | US | EU-U.S. Data Privacy Framework (active) and SCCs 2021/914 |
Participation in the Data Privacy Framework was verified against the official list at dataprivacyframework.gov on 26 August 2026. The current list of sub-processors is this page; changes are notified as set out in section 2.
The English text of this DPA governs. Translations are provided for convenience and, where they differ, the English version prevails.