Skip to content

Data Processing Agreement

Brainwaves AI Pty Ltd

Last updated: September 11, 2026


This Data Processing Addendum ("DPA") governs Brainwaves AI Pty Ltd ("BrainWaves") processing of Customer Data provided by Customer to BrainWaves under the terms of BrainWaves' Terms of Service (located at brain-waves.io/terms), Enterprise Agreement, or other agreement between Customer and BrainWaves governing Customer's use of the Services (the "Agreement") and is hereby incorporated into the Agreement. If and to the extent language in this DPA conflicts with the Agreement, the conflicting terms in this DPA shall control.


1. Definitions

Unless expressly stated otherwise, capitalised terms used in this DPA have the meanings given below or, if not defined, have the meanings given in the Agreement. References to "including" mean "including, without limitation".

1.1 "Addendum Effective Date" means the effective date of the Agreement.

1.2 "Affiliate" means any entity that directly or indirectly controls, is controlled by, or is under common control with the subject entity.

1.3 "Controller" means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data.

1.4 "Data Subject" means the identified or identifiable natural person to whom European Customer Data relates.

1.5 "Data Subject Request" means the request of a Data Subject to exercise rights under European Data Protection Laws in respect of European Customer Data in BrainWaves' possession, custody or control.

1.6 "EEA" means the European Economic Area.

1.7 "European Customer Data" means Personal Data of Data Subjects in the EEA, United Kingdom, or Switzerland Processed by BrainWaves or its Subprocessor(s) on behalf of Customer, or otherwise required to be Processed under and subject to European Data Protection Laws, to perform the Services under the Agreement.

1.8 "European Data Protection Laws" means the privacy, data protection and data security laws and regulations applicable to the Processing of European Customer Data in the EEA, United Kingdom and/or Switzerland under the Agreement, including the GDPR.

1.9 "FADP" means the Swiss Federal Act on Data Protection.

1.10 "FDPIC" means the Swiss Federal Data Protection and Information Commissioner.

1.11 "GDPR" means, as and where applicable: (i) the General Data Protection Regulation (Regulation (EU) 2016/679) ("EU GDPR"), (ii) the EU GDPR as it forms part of UK law ("UK GDPR"), including any applicable national implementing or supplementary legislation.

1.12 "Personal Data" means information that relates to an identified or identifiable Data Subject.

1.13 "Personal Data Breach" means a breach of BrainWaves' security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, European Customer Data in BrainWaves' possession, custody or control.

1.14 "Process" and inflections thereof refer to any operation or set of operations performed on Personal Data, whether or not by automated means.

1.15 "Processor" means a natural or legal person, public authority, agency, or other body which Processes Personal Data on behalf of the Controller.

1.16 "Restricted Transfer" means any transfer of European Customer Data to any person located in a country or territory which does not benefit from an adequacy decision, which would be prohibited without a legal basis under the GDPR.

1.17 "SCCs" means the standard contractual clauses approved by the European Commission pursuant to implementing Decision (EU) 2021/914.

1.18 "Services" means those services performed for Customer by BrainWaves pursuant to the Agreement.

1.19 "Subprocessor" means any third party engaged directly or indirectly by or on behalf of BrainWaves to Process European Customer Data.

1.20 "Supervisory Authority" means the relevant data protection authority in the applicable jurisdiction.

1.21 "Transfer Mechanism(s)" means the SCCs, UK Transfer Addendum, and/or Swiss transfer mechanism, as applicable.

1.22 "UK Transfer Addendum" means the template Addendum issued by the UK ICO under s119A of the Data Protection Act 2018.


2. Scope of This Data Processing Addendum

2.1 The Parties acknowledge and agree that the details of BrainWaves' Processing of European Customer Data are as described in Annex 1 to this DPA.

2.2 This DPA applies to BrainWaves' Processing of European Customer Data. It does not apply to Processing of Personal Data conducted by BrainWaves as a Controller, including business relationship administration and system security.


3. Processing of Customer Personal Data

3.1 BrainWaves shall not Process European Customer Data other than on Customer's instructions or as required by applicable laws. Customer instructs BrainWaves to Process European Customer Data to provide the Services and as authorised by the Agreement.

3.2 Where BrainWaves receives an instruction from Customer that, in its reasonable opinion, infringes European Data Protection Laws, BrainWaves shall notify Customer.


4. BrainWaves Personnel

BrainWaves shall ensure that all employees or personnel who Process European Customer Data are subject to contractual or statutory obligations of confidentiality.


5. Security

BrainWaves shall implement and maintain technical, organisational and physical measures designed to protect the confidentiality, integrity and availability of European Customer Data and prevent Personal Data Breaches. Such measures include those described in Annex 2 (Security Measures). BrainWaves may update Security Measures from time to time, provided the updated measures do not decrease the overall protection of Personal Data.


6. Restricted Transfers

6.1 Where BrainWaves is certified under a scheme that benefits from an adequacy decision (such as the EU–U.S. Data Privacy Framework), BrainWaves will rely on such scheme for transfers of European Customer Data.

6.2 Where no adequacy decision applies, the Parties shall be deemed to have entered into the SCCs (Module 2 and/or 3 as applicable) for EU Restricted Transfers, varied as necessary for UK and Swiss Restricted Transfers.

6.3 The Annexes to the SCCs shall be populated with the information in Annex 1 and Annex 2 of this DPA.


7. Data Subject Requests

7.1 BrainWaves shall provide Customer with reasonable assistance to fulfil obligations to respond to Data Subject Requests.

7.2 BrainWaves shall promptly notify Customer if it receives a Data Subject Request and shall not respond except to advise the Data Subject to submit the request to Customer, unless required by law.


8. Personal Data Breaches

8.1 BrainWaves shall notify Customer of a Personal Data Breach without undue delay after becoming aware of it.

8.2 BrainWaves' notification of a Personal Data Breach shall not be construed as acknowledgement of fault or liability.

8.3 If Customer determines that a Personal Data Breach must be notified to authorities or Data Subjects, Customer agrees to consult with BrainWaves in good faith regarding the content of such notifications.


9. Subprocessors

9.1 Customer generally authorises BrainWaves to appoint Subprocessors in accordance with this Section.

9.2 BrainWaves uses the following Subprocessors to provide the Services:

SubprocessorPurposeLocation
Cloudflare, Inc.Infrastructure, compute, databases, CDN, encryptionGlobal (US-based)
OpenAI, LLCAI model processing via APIUnited States
Datadog, Inc.Application logging and monitoringUnited States
Langfuse GmbH (Langfuse)AI tracing and performance monitoring, including user, session, workspace and message identifiers, model usage and timing, generated responses, tool inputs and results, and submitted feedback. LLM input-message content is redacted in production; separate trace and feedback fields are not covered by that redaction.EU (Ireland)
PostHog, Inc.Identified product analytics, including user and workspace details and message-submission event metadata; submission events do not include message or generated-output textEU (Frankfurt, Germany; US-based provider)

9.3 When engaging any Subprocessor, BrainWaves shall enter into a written contract containing data protection obligations not less protective than those in this DPA.

9.4 BrainWaves shall notify Customer at least thirty (30) days before engaging any new Subprocessor that Processes European Customer Data. If Customer objects on reasonable grounds relating to data protection, the Parties shall work in good faith to resolve the objection. If resolution is not possible, Customer may terminate the Agreement.


10. Compliance Assistance and Audits

10.1 BrainWaves shall provide reasonable information and assistance to help Customer meet obligations under European Data Protection Laws, including security assessments, breach notifications, and data protection impact assessments.

10.2 BrainWaves shall make available information reasonably requested by Customer to demonstrate compliance with this DPA.

10.3 Customer may conduct audits (at Customer's cost) with reasonable advance notice, no more than once per calendar year, conducted during business hours and in accordance with BrainWaves' security policies.

10.4 If BrainWaves has a current SOC 2 Type 2, ISO 27001, or similar audit report, Customer agrees to accept such report in lieu of an on-site audit.


11. Data Retention and Deletion

11.1 BrainWaves retains Customer Data for the duration of Customer's engagement with the Services. Customer workspace data, inputs, outputs, and session data are maintained to enable Customer's continued use of the Services.

11.2 Upon expiration or termination of the Agreement, or upon Customer's request, BrainWaves shall delete all European Customer Data in its possession, custody or control, except where retention is required by applicable law.

11.3 Customer may request deletion of specific data or their entire account at any time by contacting support@brain-waves.io.


12. Customer Responsibilities

12.1 Customer is responsible for its use of the Services, including securing account credentials and backing up Customer Data.

12.2 Customer shall ensure there is a valid legal basis for BrainWaves' Processing of European Customer Data under European Data Protection Laws.

12.3 Customer shall ensure that European Customer Data does not contain: (a) government-issued identification numbers; (b) biometric information; (c) payment card information subject to PCI DSS; (d) Personal Data of children under 16; (e) data relating to criminal convictions; or (f) special categories of personal data as defined in the GDPR, unless explicitly agreed in writing.


13. Precedence

In the event of any conflict between this DPA and the Agreement, this DPA shall prevail with respect to the Processing of Personal Data.


Annex 1 — Data Processing Details

Customer / Data Exporter Details

FieldDetails
NameAs specified in the Agreement
ActivitiesUse and receipt of Services under the Agreement
Role

Controller (or Processor where acting on behalf of another Controller)

BrainWaves / Data Importer Details

FieldDetails
NameBrainwaves AI Pty Ltd
Contactsupport@brain-waves.io
ActivitiesAI-powered marketing and strategy platform
RoleProcessor

Categories of Data Subjects

Data Subjects whose Personal Data may be submitted to the Services, as determined by Customer, including:

  • Customer's employees, contractors, and personnel

  • Customer's clients and end-users

  • Customer's suppliers and business contacts

Categories of Personal Data

Personal Data submitted to the Services by Customer, which may include:

  • Personal identifiers (name, email, company)

  • Professional information

  • Content and inputs provided by Data Subjects

  • Technical identifiers (IP addresses, device information)

Sensitive Data

None. Customer agrees that sensitive categories of data (as defined in GDPR Article 9) must not be submitted to the Services unless explicitly agreed in writing.

Processing Details

FieldDetails
FrequencyOngoing, as initiated by Customer
NatureProcessing required to provide the Services
Purpose

Providing AI-powered platform services as described in the Agreement

DurationFor the duration of Customer's engagement with the Services

Data Isolation

Customer workspace data is stored in isolated databases specific to each customer. Each session operates within its own isolated database, with access for authorised workspace members and authorised Brainwaves platform administrators and support personnel to operate, secure and support the Services. Authentication and usage analytics data is stored separately from customer workspace content.


Annex 2 — Security Measures

BrainWaves implements the following security measures:

Access Controls

  • Individual user accounts with no shared credentials

  • Access restricted to authorised personnel on a need-to-know basis

  • Access rights reviewed upon personnel changes

  • Immediate revocation capability for access rights

  • All access events logged and auditable

Authentication

  • Multi-factor authentication (MFA) enforced on all infrastructure access

  • Strong password requirements enforced

  • Authentication events logged for security monitoring

Data Protection

  • Encryption at rest using platform-level encryption (Cloudflare)

  • Encryption in transit using TLS 1.2+

  • Customer workspace data isolated at the database level

  • Session data stored in isolated databases per customer

Infrastructure Security

  • Deployment on Cloudflare Workers with built-in DDoS protection

  • Web Application Firewall capabilities

  • Workload isolation between customers

  • No physical infrastructure managed by BrainWaves personnel

Logging and Monitoring

  • Centralised application logging (Datadog)

  • AI tracing and performance monitoring (Langfuse), as described in Section 9.2

  • Security-relevant events captured and retained

  • Anomaly detection and alerting capabilities

Personnel Security

  • Confidentiality obligations for all personnel with data access

  • Security awareness maintained through regular practices

Incident Response

  • Documented incident response process

  • Customer notification procedures for data breaches

  • Post-incident analysis and remediation


For questions regarding this DPA, contact support@brain-waves.io