Skip to content
FIG. L-06 · BranclePlate Nº 06
06/Legal / DPA

Data Processing Addendum that governs project data

When BRANCLE TECHNOLOGIES LLC automates work inside your systems, you are the controller and we act strictly as processor on your documented SOW instructions. This Addendum sets confidentiality, security, subprocessors, transfers, breach notice, and return or deletion for that project personal data — and controls over our Site notices for the same data.

Parties
Client + Brancle
Effective
September 6, 2026
Reading time
≈ 11 min
  • Processor-only role

    You control project data; we process only on your SOW instructions and refuse unlawful ones with notice.

  • 48-hour breach notice

    Processor-to-controller notice within 48 hours of awareness with containment detail and case IDs.

  • 30-day return or deletion

    Delete or return on SOW end, purge backups within 30 days, confidentiality floor survives.

  • Vendors with objection right

    General subprocessor authorization with 14-day objection; project models and tools allowlisted per SOW.

FIG. L-01A · SummaryNº 01SHA · Plain EnglishStart here

01

Agreement — parties and precedence

This Data Processing Addendum (“DPA”) is entered by the client named in the applicable statement of work (“Client,” “you,” controller) and BRANCLE TECHNOLOGIES LLC, a Kentucky limited liability company at 212 N. 2nd St. STE 100, Richmond, KY 40475 (“Brancle,” “we,” processor). It applies whenever an SOW references it or Brancle processes project personal data to perform automation work.

Order of precedence for project personal data: the SOW controls first, then this DPA, then our Terms of Service (Policy #2). For the same project data, this DPA controls over our Privacy Policy (Policy #1), which remains the notice for Site inquiry and booking data where Brancle acts as controller.

02

Subject matter and duration

Subject matter: design, build, deployment, measurement, and support of the agentic workflow named in the SOW, operating inside the systems you designate (such as CRM, ERP, inbox, databases, helpdesk, spreadsheets). Nature and purpose are limited to performing that SOW — including reasoning, tool calls, validation, human checkpoints, logging, and reporting against your baseline.

Duration: from SOW signature through acceptance plus any support period named in the SOW. This DPA is coterminous with the SOW for project data and terminates for that data when return or deletion completes under Section 10.

03

Roles and instructions

Controller / processor split
DataControllerProcessorGoverns
Site inquiries & bookings (brancle.com, hello@brancle.com, Cal.com)BRANCLE TECHNOLOGIES LLCVercel, Cal.comPrivacy (Policy #1) + Cookies (Policy #3)
Project data in your systems under the SOWClientBRANCLE TECHNOLOGIES LLCThis DPA + SOW (controls on conflict)

Brancle processes project personal data only on your documented SOW instructions, including Annex I systems, categories, and purposes. If an instruction appears unlawful under applicable data-protection law, we notify you promptly and suspend the affected processing pending your lawful written instruction, without breaching this DPA for the pause.

04

Client controller duties

  • Lawful basis, data minimization, and authority for every system and category placed in scope.
  • Residency, retention, and approval constraints disclosed before build (including any “environments you control” requirement).
  • Timely least-privilege access plus valid licenses and APIs; named qualified reviewers for checkpoints with coverage and backup.
  • Counsel approval before any solely automated decision with legal or similarly significant effect, and before regulated-industry deployment.
  • Prompt review of escalations, threshold changes, and re-validation after model, tool, or API changes.

05

Confidentiality

Brancle holds project personal data and your non-public business and technical information in confidence, uses it only to perform the SOW and this DPA, and discloses it only to personnel and subprocessors who need to know and are bound by written confidentiality at least as protective. The 3-year confidentiality floor from Terms §11 survives return or deletion (longer for trade secrets).

Carve-outs: already known, public through no fault, independently developed, or lawfully received from a third party. Compelled disclosure requires prompt notice where lawful with disclosure limited to what is required. Aggregated, de-identified learnings are permitted only after removal or hashing of direct identifiers plus suppression of rare quasi-identifiers so re-identification is not reasonably possible.

06

Security — per-SOW controls

Brancle implements appropriate technical and organizational measures for project data as specified in the SOW and Annex II: least-privilege roles with MFA and unique accounts, time-boxed scoped grants revoked at milestone or termination, TLS 1.2+ in transit with platform encryption at rest, secrets in environment variables only, and the audit-trail schema (actor, action, timestamp, input/output reference, confidence or rule applied, approver) retained with the record it governs and reviewable by you.

No SOC 2, HIPAA, PCI, or other certification is implied; regulated-appropriate controls apply only where named in the SOW and approved by your counsel. Full Site-inquiry safeguards are stated separately in our Security page (Policy #4).

07

Subprocessors — general authorization with objection

You grant general authorization for subprocessors under Article 28(2), incorporating our versioned list in Policy #7 (Subprocessors) for Site processors (Vercel hosting, Cal.com scheduling) plus the project-specific allowlist fixed in your SOW for foundation models, tools, and APIs (provider, purpose, data sent, retention, version pin). We impose Article 28(3) terms downstream and remain responsible for subprocessor performance of DPA duties.

We notify you at least 14 days before adding or replacing a project subprocessor with material access to project personal data. You may object in writing on reasonable data-protection grounds within that window; we will propose a safe alternative, and if none is reasonably available either party may terminate the affected SOW portion with a pro-rata refund of prepaid, unaccepted fees as your exclusive remedy for the change.

08

International transfers

Project data is hosted in the United States by default, or in the environments you control where the SOW elects client-side residency. Where a transfer requires a mechanism under GDPR or UK GDPR, the EU Standard Contractual Clauses (Module Two, controller to processor; UK Addendum where applicable) are incorporated by reference with you as data exporter and Brancle as data importer, supplemented by Annex I–III of this DPA. Onward transfers to subprocessors carry equivalent protections.

09

Breach notification — within 48 hours to you

On discovering a personal-data breach affecting project data, Brancle notifies you without undue delay and in any event within 48 hours of awareness at hello@brancle.com and security@brancle.com, describing what happened, categories and volume involved, likely consequences, containment taken, and a contact point — supplemented as investigation proceeds, including subprocessor case IDs where a processor is the source.

We contain, preserve logs, and cooperate so you can meet your own duties to individuals and authorities (including 72-hour supervisory notice where GDPR applies). Notices to individuals or regulators about project data are yours to send unless the SOW assigns assistance; we do not notify on your behalf without written direction.

10

Return or deletion — 30-day purge

At SOW end or on your written direction, we return project personal data in a commonly used format and then delete live copies, at your election, within 30 days — including purge from platform backups within 30 days of the live delete, subject to documented legal-hold exception (time-boxed, with notice). De-identification, where elected instead of deletion, meets the Section 5 bar.

Site inquiry schedules (24-month inquiries and bookings, 90-day server logs, 36-month request history) do not apply to project data. Confidentiality and IP limits survive return or deletion per Terms §§10–11.

11

Audit and assistance

Brancle keeps records of processing, control changes, and breach cases for project data and assists with data-subject requests, DPIAs, and prior consultations at cost-based, pre-approved rates. Verification runs by questionnaire plus our security summary under NDA with supporting logs on request — sufficient and proportionate for a studio engagement. On-site audits apply only where expressly stated in the SOW with 30 days’ notice, scoped to project systems, and at your expense.

12

Liability, term, and changes

DPA breach liability sits inside the Terms §13 framework: no indirect or consequential damages, and aggregate liability for the Site plus any SOW capped at fees you paid to Brancle in the six months preceding the event giving rise to the claim. The cap does not limit non-limitable liability, your payment duties, or indemnification for misuse or data-rights failures.

DPA contact

BRANCLE TECHNOLOGIES LLC

212 N. 2nd St. STE 100, Richmond, KY 40475

General: hello@brancle.com

Breach & security notices: security@brancle.com · Site: https://brancle.com

Amendments apply by signed SOW change or posted DPA version incorporated into new SOWs; in-flight SOWs continue on their DPA version unless both parties agree otherwise. This DPA does not constitute legal advice.

A

Annexes — instantiated per SOW

Annexes below are the template every SOW completes. The signed SOW’s filled annexes are the operative record for that workflow.

Annex I — subject matter (per SOW)
FieldSOW entry
Systems accessedNamed CRM, ERP, inbox, databases, helpdesk (least-privilege grants)
Data categoriesContact, transactional, content, logs as placed in scope; no sensitive identifiers unless listed
Data subjectsClient personnel, customers, vendors as applicable to the workflow
PurposesRepetitive automation, orchestration, and bounded judgment work per Sections 3–5 of Responsible AI
DurationSOW term plus support period; DPA coterminous
Annex II — security measures (per SOW)
MeasureStandard
AccessUnique accounts, MFA, time-boxed scoped grants, revocation at milestone or termination
EncryptionTLS 1.2+ in transit, platform encryption at rest, secrets in environment only
LoggingActor, action, timestamp, I/O reference, confidence or rule, approver; reviewable, retained with record
ResidencyU.S. default or client-controlled environments as elected; transfers per Section 8
Annex III — subprocessors (Policy #7 + SOW allowlist)
ProcessorRole
Vercel Inc.Site hosting processor (Site data only)
Cal.com, Inc.Scheduler processor (booking data only)
SOW-named models, tools, APIsProject processors with provider, purpose, data sent, retention, version pin