Processor-only role
You control project data; we process only on your SOW instructions and refuse unlawful ones with notice.
48-hour breach notice
Processor-to-controller notice within 48 hours of awareness with containment detail and case IDs.
30-day return or deletion
Delete or return on SOW end, purge backups within 30 days, confidentiality floor survives.
Vendors with objection right
General subprocessor authorization with 14-day objection; project models and tools allowlisted per SOW.
Nº 01
Agreement — parties and precedence
This Data Processing Addendum (“DPA”) is entered by the client named in the applicable statement of work (“Client,” “you,” controller) and BRANCLE TECHNOLOGIES LLC, a Kentucky limited liability company at 212 N. 2nd St. STE 100, Richmond, KY 40475 (“Brancle,” “we,” processor). It applies whenever an SOW references it or Brancle processes project personal data to perform automation work.
Order of precedence for project personal data: the SOW controls first, then this DPA, then our Terms of Service (Policy #2). For the same project data, this DPA controls over our Privacy Policy (Policy #1), which remains the notice for Site inquiry and booking data where Brancle acts as controller.
Nº 02
Subject matter and duration
Subject matter: design, build, deployment, measurement, and support of the agentic workflow named in the SOW, operating inside the systems you designate (such as CRM, ERP, inbox, databases, helpdesk, spreadsheets). Nature and purpose are limited to performing that SOW — including reasoning, tool calls, validation, human checkpoints, logging, and reporting against your baseline.
Duration: from SOW signature through acceptance plus any support period named in the SOW. This DPA is coterminous with the SOW for project data and terminates for that data when return or deletion completes under Section 10.
Nº 03
Roles and instructions
| Data | Controller | Processor | Governs |
|---|---|---|---|
| Site inquiries & bookings (brancle.com, hello@brancle.com, Cal.com) | BRANCLE TECHNOLOGIES LLC | Vercel, Cal.com | Privacy (Policy #1) + Cookies (Policy #3) |
| Project data in your systems under the SOW | Client | BRANCLE TECHNOLOGIES LLC | This DPA + SOW (controls on conflict) |
Brancle processes project personal data only on your documented SOW instructions, including Annex I systems, categories, and purposes. If an instruction appears unlawful under applicable data-protection law, we notify you promptly and suspend the affected processing pending your lawful written instruction, without breaching this DPA for the pause.
Nº 04
Client controller duties
- Lawful basis, data minimization, and authority for every system and category placed in scope.
- Residency, retention, and approval constraints disclosed before build (including any “environments you control” requirement).
- Timely least-privilege access plus valid licenses and APIs; named qualified reviewers for checkpoints with coverage and backup.
- Counsel approval before any solely automated decision with legal or similarly significant effect, and before regulated-industry deployment.
- Prompt review of escalations, threshold changes, and re-validation after model, tool, or API changes.
Nº 05
Confidentiality
Brancle holds project personal data and your non-public business and technical information in confidence, uses it only to perform the SOW and this DPA, and discloses it only to personnel and subprocessors who need to know and are bound by written confidentiality at least as protective. The 3-year confidentiality floor from Terms §11 survives return or deletion (longer for trade secrets).
Carve-outs: already known, public through no fault, independently developed, or lawfully received from a third party. Compelled disclosure requires prompt notice where lawful with disclosure limited to what is required. Aggregated, de-identified learnings are permitted only after removal or hashing of direct identifiers plus suppression of rare quasi-identifiers so re-identification is not reasonably possible.
Nº 06
Security — per-SOW controls
Brancle implements appropriate technical and organizational measures for project data as specified in the SOW and Annex II: least-privilege roles with MFA and unique accounts, time-boxed scoped grants revoked at milestone or termination, TLS 1.2+ in transit with platform encryption at rest, secrets in environment variables only, and the audit-trail schema (actor, action, timestamp, input/output reference, confidence or rule applied, approver) retained with the record it governs and reviewable by you.
No SOC 2, HIPAA, PCI, or other certification is implied; regulated-appropriate controls apply only where named in the SOW and approved by your counsel. Full Site-inquiry safeguards are stated separately in our Security page (Policy #4).
Nº 07
Subprocessors — general authorization with objection
You grant general authorization for subprocessors under Article 28(2), incorporating our versioned list in Policy #7 (Subprocessors) for Site processors (Vercel hosting, Cal.com scheduling) plus the project-specific allowlist fixed in your SOW for foundation models, tools, and APIs (provider, purpose, data sent, retention, version pin). We impose Article 28(3) terms downstream and remain responsible for subprocessor performance of DPA duties.
We notify you at least 14 days before adding or replacing a project subprocessor with material access to project personal data. You may object in writing on reasonable data-protection grounds within that window; we will propose a safe alternative, and if none is reasonably available either party may terminate the affected SOW portion with a pro-rata refund of prepaid, unaccepted fees as your exclusive remedy for the change.
Nº 08
International transfers
Project data is hosted in the United States by default, or in the environments you control where the SOW elects client-side residency. Where a transfer requires a mechanism under GDPR or UK GDPR, the EU Standard Contractual Clauses (Module Two, controller to processor; UK Addendum where applicable) are incorporated by reference with you as data exporter and Brancle as data importer, supplemented by Annex I–III of this DPA. Onward transfers to subprocessors carry equivalent protections.
Nº 09
Breach notification — within 48 hours to you
On discovering a personal-data breach affecting project data, Brancle notifies you without undue delay and in any event within 48 hours of awareness at hello@brancle.com and security@brancle.com, describing what happened, categories and volume involved, likely consequences, containment taken, and a contact point — supplemented as investigation proceeds, including subprocessor case IDs where a processor is the source.
We contain, preserve logs, and cooperate so you can meet your own duties to individuals and authorities (including 72-hour supervisory notice where GDPR applies). Notices to individuals or regulators about project data are yours to send unless the SOW assigns assistance; we do not notify on your behalf without written direction.
Nº 10
Return or deletion — 30-day purge
At SOW end or on your written direction, we return project personal data in a commonly used format and then delete live copies, at your election, within 30 days — including purge from platform backups within 30 days of the live delete, subject to documented legal-hold exception (time-boxed, with notice). De-identification, where elected instead of deletion, meets the Section 5 bar.
Site inquiry schedules (24-month inquiries and bookings, 90-day server logs, 36-month request history) do not apply to project data. Confidentiality and IP limits survive return or deletion per Terms §§10–11.
Nº 11
Audit and assistance
Brancle keeps records of processing, control changes, and breach cases for project data and assists with data-subject requests, DPIAs, and prior consultations at cost-based, pre-approved rates. Verification runs by questionnaire plus our security summary under NDA with supporting logs on request — sufficient and proportionate for a studio engagement. On-site audits apply only where expressly stated in the SOW with 30 days’ notice, scoped to project systems, and at your expense.
Nº 12
Liability, term, and changes
DPA breach liability sits inside the Terms §13 framework: no indirect or consequential damages, and aggregate liability for the Site plus any SOW capped at fees you paid to Brancle in the six months preceding the event giving rise to the claim. The cap does not limit non-limitable liability, your payment duties, or indemnification for misuse or data-rights failures.
DPA contact
BRANCLE TECHNOLOGIES LLC
212 N. 2nd St. STE 100, Richmond, KY 40475
General: hello@brancle.com
Breach & security notices: security@brancle.com · Site: https://brancle.com
Amendments apply by signed SOW change or posted DPA version incorporated into new SOWs; in-flight SOWs continue on their DPA version unless both parties agree otherwise. This DPA does not constitute legal advice.
Nº A
Annexes — instantiated per SOW
Annexes below are the template every SOW completes. The signed SOW’s filled annexes are the operative record for that workflow.
| Field | SOW entry |
|---|---|
| Systems accessed | Named CRM, ERP, inbox, databases, helpdesk (least-privilege grants) |
| Data categories | Contact, transactional, content, logs as placed in scope; no sensitive identifiers unless listed |
| Data subjects | Client personnel, customers, vendors as applicable to the workflow |
| Purposes | Repetitive automation, orchestration, and bounded judgment work per Sections 3–5 of Responsible AI |
| Duration | SOW term plus support period; DPA coterminous |
| Measure | Standard |
|---|---|
| Access | Unique accounts, MFA, time-boxed scoped grants, revocation at milestone or termination |
| Encryption | TLS 1.2+ in transit, platform encryption at rest, secrets in environment only |
| Logging | Actor, action, timestamp, I/O reference, confidence or rule, approver; reviewable, retained with record |
| Residency | U.S. default or client-controlled environments as elected; transfers per Section 8 |
| Processor | Role |
|---|---|
| Vercel Inc. | Site hosting processor (Site data only) |
| Cal.com, Inc. | Scheduler processor (booking data only) |
| SOW-named models, tools, APIs | Project processors with provider, purpose, data sent, retention, version pin |