June 2026

Data Processing Agreement

THIS DATA PROCESSING AGREEMENT (THIS "DPA") FORMS PART OF THE STANDARD TERMS BETWEEN BRIGHTWAVE AND CUSTOMER. CAPITALIZED TERMS USED BUT NOT DEFINED IN THIS DPA WILL HAVE THE MEANINGS SET FORTH IN THE STANDARD TERMS. IF THERE ARE INCONSISTENCIES OR CONFLICTS BETWEEN THE TERMS OF THE STANDARD TERMS AND THIS DPA, THE TERMS OF THIS DPA WILL CONTORL TO THE EXTENT OF THE CONFLICT.

  1. Data Processing; Subject Matter; Roles.

1.1. Data Processing. In the course of providing the Service to Customer pursuant to the Agreement (including the Standard Terms), Brightwave may Process Customer Data that constitutes "personal data," "personal information," "personally identifiable information," or an analogous term under any applicable law ("Personal Data"). The Parties agree to comply with this DPA and all privacy and data protection laws applicable to the Processing of Personal Data under the Agreement (including the Standard Terms), including, as applicable, those of the European Union, the European Economic Area and their member states, Switzerland, the United Kingdom, and the United States ("Data Protection Laws").

1.2. Subject Matter. The subject matter, nature, and purpose of the Processing, the types of Personal Data, and the categories of "Data Subjects" (as such term is defined under applicable Data Protection Laws) are set out in Annex I, which is an integral part of this DPA.

1.3. Roles. Customer is a "Controller" or "Business" (as such terms are defined under applicable Data Protection Law) and appoints Brightwave as a "Processor" or "Service Provider" (as such terms are defined under applicable Data Protection Law) on behalf of Customer. Customer is responsible for compliance with the requirements of Data Protection Law applicable to Controllers and Businesses. If Customer is a Processor on behalf of a Controller for which Customer is a Processor ("Third-Party Controller"), then Customer: (a) is the single point of contact for Brightwave; (b) must obtain all necessary authorizations from such Third-Party Controller; and (c) undertakes to issue all instructions and exercise all rights on behalf of such other Third-Party Controller.

  1. Processing Instructions. Brightwave shall Process Personal Data on behalf of and only in accordance with Customer's documented instructions for the following purposes: (a) Processing in accordance with this DPA or the Agreement (including the Standard Terms); (b) Processing initiated by Users in their use of the Services; and (c) Processing to comply with other documented reasonable instructions provided by Customer (e.g., via email) where such instructions are consistent with the terms of the Agreement (including the Standard Terms).

  2. Personnel. Brightwave will ensure that all personnel authorized to Process Personal Data are subject to an obligation of confidentiality.

  3. CCPA Limitations on Processing. Except as permitted by applicable Data Protection Law, the Agreement (including the Standard Terms), or this DPA, Brightwave is prohibited from: (a) retaining, using, or disclosing Personal Data for any purpose other than for the specific purposes of performing the Services or in accordance with Customer's documented instructions; (b) retaining, using, or disclosing Personal Data outside of the direct business relationship between the Parties; (c) combining Personal Data with "Personal Information" (as such term is defined under the CCPA) obtained from, or on behalf of, sources other than Customer; and (d) "Selling" or "Sharing" (as such terms are defined under the CCPA) Personal Data.

  4. Security; Security Incident.

5.1. Security. Brightwave will implement appropriate technical and organizational measures designed to ensure a level of security appropriate to the risks presented by the Processing of Personal Data, including the measures set forth in Annex I.

5.2. Security Incident. Brightwave will notify Customer without undue delay after becoming aware of any actual or reasonably suspected unauthorized access to, or other Processing of, Personal Data in its possession or control ("Security Incident"). If Brightwave's notification of a Security Incident is delayed, it will be accompanied by reasons for the delay.

  1. Subprocessing.

6.1. Subprocessors. Customer hereby authorizes Brightwave to engage any Processor that processes Personal Data on behalf of Brightwave ("Subprocessor"). A list of Brightwave's current Subprocessors is available here.

6.2. Subprocessor Agreements. Brightwave has entered into a written agreement with each Subprocessors containing, in substance, data protection obligations no less protective that those in this DPA with respect to the protection of Personal Data to the extent applicable to the nature of the Services provided by such Subprocessors.

6.3. Subprocessor Changes. Brightwave will notify Customer prior to any intended change to Subprocessors. Customer may object to Brightwave's use of a new Subprocessor within thirty (30) days of receipt of Brightwave's notice of the intended change of Subprocessor based on reasonable grounds that the appointment of such Subprocessor will result in a material violation of Data Protection Law by providing written notice to Brightwave detailing the grounds of such objection. Brightwave will use reasonable efforts to make available to Customer a change in the Service or recommend a commercially reasonable change to Customer's configuration or use of the Service to avoid the Processing of Personal Data by the objected-to new Subprocessor without unreasonably burdening Customer. If Brightwave is unable to make available such change within a reasonable period of time, which shall not exceed sixty 60 days, Customer may terminate the relevant parts of the Services or applicable Order with respect only to those Services which cannot be provided by Brightwave without the use of the objected-to new Subprocessor by providing written notice to Brightwave and Brightwave will refund Customer any prepaid fees covering the remainder of the Term following the effective date of termination with respect to such terminated Services, without imposing a penalty for such termination on Customer.

  1. Assistance. Taking into account the nature of the Processing and the information available to Brightwave, Brightwave will provide commercially reasonable assistance to Customer needed to satisfy Customer's obligations under Data Protection Law, including in connection with implementing appropriate technical and organizational measures, comply with Data Subject and "Consumer" (as such term is defined under applicable Data Protection Laws) requests, reply to inquiries, complaints, investigations, and inquiries, conduct data protection impact assessments, conduct data protection assessments, and conduct prior consultations with regulators. To the extent legally permitted, Customer shall be responsible for any costs and expenses arising from Brightwave's provision of such assistance.

  2. Audit. Upon Customer's reasonable written request, Brightwave will permit Customer, at Customer's sole expense, to audit Brightwave's applicable controls and compliance with this DPA (an "Audit"), provided such Audit is (a) conducted by Customer or a third-party auditor designated by Customer and reasonably acceptable to Brightwave that has executed an appropriate confidentiality agreement with Brightwave; (b) in accordance with mutually agreed upon terms between Customer and Brightwave; and (c) a similar Audit has not already been conducted less than twelve (12) months prior, unless it is required by a "Supervisory Authority" (as such term is defined under applicable Data Protection Laws) or other regulatory authority responsible for the enforcement of Data Protection Law. Customer may use the results of an Audit only for the purposes of meeting Customer's regulatory audit requirements or confirming compliance with the requirements of the DPA.

  3. International Data Transfers.

9.1. European Data Transfers. Brightwave will obtain Customer's specific prior written authorization for any transfer of Personal Data subject to European Data Protection Law that is not subject to an adequacy decision by the European Commission ("International Data Transfer"). Customer hereby authorizes Brightwave to conduct International Data Transfers outside the European Economic Area ("EEA") or Switzerland:

  • to any country subject to a valid adequacy decision of the European Commission;
  • on the basis of an organization's binding corporate rules approved by EEA Supervisory Authorities; and
  • to any data importer with whom Brightwave has entered into the clauses annexed to the EU Commission Implementing Decision 2021/914 of June 4, 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council as amended or replaced from time to time ("SCCs").

9.2. European Transfer Mechanisms. Customer and Brightwave conclude Module 2 (Controller-to-Processor) of the SCCs and, to the extent Customer is a Processor on behalf of a Third-Party Controller, Module 3 (Processor-to-Subprocessor) of the SCCs, which are hereby incorporated and completed as follows: the "data exporter" is Customer; the "data importer" is Brightwave; the optional docking clause in Clause 7 is implemented; Option 1 of Clause 9(a) is implemented and the time period therein is specified in Section 6.3 above; the optional redress clause in Clause 11(a) is struck; Option 1 in Clause 17 is implemented and the governing law is the law of Ireland; the courts in Clause 18(b) are the Courts of Ireland; Annex I and II to the SCCs are Annex I, II and III to this DPA respectively. For International Data Transfers from Switzerland, Data Subjects who have their habitual residence in Switzerland may bring claims under the SCCs before the courts of Switzerland.

9.3. UK Data Transfers. Customer hereby authorizes Brightwave to perform International Data Transfers outside the UK subject to the requirements:

  • to any country subject to a valid adequacy decision issued by the UK Government;
  • on the basis of an organization's binding corporate rules approved by the UK Information Commissioner; and
  • to any data importer with whom Brightwave has entered into the addendum to the SCCs issued by the UK Information Commissioner under Section 119A(1) of the UK Data Protection Act 2018 (version B1.0, in force March 21, 2022) ("UK Addendum") or other standard contractual clauses issued by the UK Information Commissioner, as appropriate.

9.4. UK Transfer Mechanism. Customer and Brightwave conclude the UK Addendum which is hereby incorporated and applies to International Data Transfers outside the UK. Part 1 of the UK Addendum is completed as follows: (a) in Table 1, the "Exporter" is Customer and the "Importer" is Brightwave, their details are set forth in this DPA and the Agreement; (b) in Table 2, the first option is selected and the "Approved EU SCCs" are the SCCs referred to in Section 9.2 of this DPA; (c) in Table 3, Annexes 1 (A and B), II, and III to the "Approved EU SCCs" are Annex I, II, and III to this DPA respectively; and (d) in Table 4, both the "Importer" and the "Exporter" can terminate the UK Addendum.

9.5. Other Transfer Mechanisms. If Brightwave's compliance with Data Protection Law applicable to international data transfers is affected by circumstances outside of Brightwave's control, including if a legal instrument for international data transfers is invalidated, amended, or replaced, then Customer and Brightwave will work together in good faith to reasonably resolve such non-compliance. In the event that additional, replacement or alternative standard contractual clauses or UK standard contractual clauses are approved by Supervisory Authorities, Brightwave reserves the right to amend the Standard Terms and this DPA by adding to or replacing, the standard contractual clauses or UK standard contractual clauses that form part of it at the date of signature in order to ensure continued compliance with Data Protection Law.

  1. Return; Deletion. Customer may request return of Personal Data upon expiration or termination of the Agreement. Personal Data may be retained by Brightwave if required or permitted by applicable law or in Brightwave's standard backups notwithstanding any obligation to delete the applicable Personal Data but will remain subject to the Agreement's confidentiality restrictions and the protections of this DPA.

Exhibit A – Data Processing Agreement

ANNEX I

DESCRIPTION OF THE TRANSFER

A. LIST OF PARTIES

Data exporter:

  • Name: Customer
  • Activities relevant to the data transferred under these Clauses: Customer receives Brightwave's Service as described in the Agreement (including the Standard Terms) and Customer provides Personal Data to Brightwave in that context.
  • Role (controller/processor): Controller, or Processor on behalf of Third-Party Controller

Data importer:

  • Name: Brightwave
  • Activities relevant to the data transferred under these Clauses: Brightwave provides its Service to Customer as described in the Agreement (including the Standard Terms) and Processes Personal Data on behalf of Customer in that context.
  • Role (controller/processor): Processor on behalf of Customer, or Subprocessor on behalf of Third-Party Controller

B. CATEGORIES OF DATA SUBJECTS WHOSE PERSONAL DATA IS TRANSFERRED

  • Customer's Customers or end-users
  • Customer's personnel, staff, and contractors

C. CATEGORIES OF PERSONAL DATA TRANSFERRED

  • (Professional) contact details
  • Login details
  • Financial information

D. SENSITIVE DATA TRANSFERRED (IF APPLICABLE)

Sensitive data transferred (if applicable) and applied restrictions or safeguards that fully take into consideration the nature of the data and the risks involved, such as for instance strict purpose limitation, access restrictions (including access only for staff having followed specialized training), keeping a record of access to the data, restrictions for onward transfers or additional security measures: N/A.

E. FREQUENCY OF THE TRANSFER

The frequency of the International Data Transfer (e.g. whether the Personal Data is transferred on a one-off or continuous basis): On a continuous basis.

F. NATURE OF THE PROCESSING

The Personal Data will be processed and transferred as described in the Agreement (including the Standard Terms).

G. PURPOSE(S) OF THE INTERNATIONAL DATA TRANSFER AND FURTHER PROCESSING

The Personal Data will be transferred and further processed for the provision of the Service as described in the Agreement (including the Standard Terms).

H. DURATION OF PROCESSING

The period for which the Personal Data will be retained, or, if that is not possible, the criteria used to determine that period: Personal Data will be retained for as long as necessary taking into account the purpose of the Processing, and in compliance with applicable laws, including laws on the statute of limitations and Data Protection Law.

I. SUB-PROCESSOR TRANSFERS

For International Data Transfer to (Sub)Processors, also specify subject matter, nature and duration of the Processing: For the subject matter and nature of the Processing, reference is made to the Agreement (including the Standard Terms) and this DPA. The Processing will take place for the duration of the Standard Terms.

J. COMPETENT SUPERVISORY AUTHORITY

The competent authority for the Processing of Personal Data relating to Data Subjects located in the EEA is the Supervisory Authority of Ireland.

The competent authority for the Processing of Personal Data relating to Data Subjects located in the UK is the UK Information Commissioner.

The competent authority for the Processing of Personal Data relating to Data Subjects located in Switzerland is the Swiss Federal Data Protection and Information Commissioner.

K. TECHNICAL AND ORGANIZATIONAL MEASURES

Brightwave will implement security safeguards designed to protect Personal Data from unauthorized access, acquisition, or disclosure, destruction, alteration, accidental loss, misuse, or damage.

Professional-grade AI for the world's most complex challenges.

Schedule a trial