Skip to content
brainattic.ai
Watch Product Use cases Connect Docs How it works Log in
Request a pilot

Data Processing Agreement

Effective date: 9 June 2026 · Last updated: 9 June 2026

This DPA forms part of, and is incorporated into, the brainattic Terms of Service.

This Data Processing Agreement ("DPA") is entered into between Finite Software Systems Ltd. (ФИНИТ Софтуер Системс ЕООД), 4 Gorotzvet Street, Sofia, Bulgaria ("Processor", "FSS") and the customer organisation that has accepted the brainattic Terms of Service ("Controller", "Customer"). It governs the Processing of Customer Personal Data by FSS in connection with the brainattic service (the "Service").

1. Definitions

"GDPR" means Regulation (EU) 2016/679. "Controller", "Processor", "Personal Data", "Processing", "Data Subject", "Personal Data Breach" and "Supervisory Authority" have the meanings given in the GDPR. "Customer Personal Data" means Personal Data contained in Customer Content or otherwise Processed by FSS on the Customer's behalf under the Service. "Sub-processor" means any processor engaged by FSS to Process Customer Personal Data.

2. Roles and scope of processing

The Customer is the Controller (or itself a processor acting for a third-party controller) of Customer Personal Data; FSS is the Processor. FSS will Process Customer Personal Data only to provide and support the Service and only on the Customer's documented instructions, which comprise the Terms of Service, this DPA, and the Customer's configuration and use of the Service. FSS will inform the Customer if, in its opinion, an instruction infringes the GDPR or other data-protection law (without obligation to perform legal review).

The subject matter, duration, nature and purpose of Processing, the types of Personal Data, and the categories of Data Subjects are set out in Annex I.

3. Processor obligations

FSS will:

  1. Process Customer Personal Data only on the Customer's documented instructions, including as to international transfers (§6);
  2. ensure that persons authorised to Process Customer Personal Data are bound by confidentiality;
  3. implement and maintain the technical and organisational measures in Annex II (Art. 32);
  4. engage Sub-processors only in accordance with §5;
  5. taking into account the nature of the Processing, assist the Customer by appropriate measures, insofar as possible, to respond to Data Subject requests under Chapter III of the GDPR;
  6. assist the Customer in ensuring compliance with its obligations under Arts. 32–36 (security, breach notification, data-protection impact assessments, and prior consultation), taking into account the information available to FSS;
  7. at the Customer's choice, delete or return Customer Personal Data at the end of the Service in accordance with §10; and
  8. make available to the Customer information necessary to demonstrate compliance with Art. 28 and allow for and contribute to audits in accordance with §11.

4. Confidentiality and personnel

FSS limits access to Customer Personal Data to personnel who need it to provide the Service, under appropriate confidentiality obligations and least-privilege access controls.

5. Sub-processors

The Customer gives FSS general authorisation to engage the Sub-processors listed in Annex III. FSS will impose data-protection obligations on each Sub-processor that are substantially equivalent to those in this DPA and remains fully liable to the Customer for its Sub-processors' performance. FSS will give the Customer prior notice of any intended addition or replacement of a Sub-processor, and the Customer may object on reasonable data-protection grounds; if the parties cannot resolve the objection, the Customer may terminate the affected part of the Service.

6. International transfers

FSS Processes and stores Customer Personal Data within the European Union. FSS will not transfer Customer Personal Data outside the European Economic Area except as necessary to provide an optional integration the Customer enables (see Annex III — Slack, United States) and subject to an appropriate transfer mechanism under Chapter V of the GDPR (such as Standard Contractual Clauses or an adequacy decision/certified framework). If the Customer does not enable such an integration, no transfer outside the EEA occurs.

7. Security

FSS implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as described in Annex II, and reviews them as the Service evolves.

8. Personal data breach

FSS will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and will provide information reasonably available to it to help the Customer meet its own notification obligations to its Supervisory Authority and Data Subjects under Arts. 33–34.

9. Data subject requests

If FSS receives a request from a Data Subject relating to Customer Personal Data, it will not respond directly (except to confirm the request should be directed to the Customer) and will promptly forward the request to the Customer and assist as described in §3(e).

10. Return and deletion

On termination or expiry of the Service, FSS will, at the Customer's choice, delete or return Customer Personal Data, and delete existing copies, in accordance with the retention periods in the Privacy Policy, unless retention is required by law.

11. Audit

FSS will make available to the Customer information reasonably necessary to demonstrate compliance with this DPA. The Customer may, on reasonable prior notice, no more than once per year (unless required by a Supervisory Authority or following a Personal Data Breach), and subject to confidentiality, audit FSS's compliance — including by FSS responding to a reasonable security questionnaire or providing relevant documentation.

12. Liability, term, and governing law

Each party's liability under this DPA is subject to the limitations in the Terms of Service, except as such limitations cannot lawfully be applied to data-protection liability. This DPA takes effect on acceptance of the Terms and continues for as long as FSS Processes Customer Personal Data. It is governed by the laws of the Republic of Bulgaria.

Annex I — Details of Processing

  • Subject matter: provision of the brainattic knowledge-base service.
  • Duration: the term of the Terms of Service (and any post-termination retention period).
  • Nature and purpose: hosting, storage, indexing, semantic embedding, search and retrieval of Customer Content, and delivery of reminders through the Customer's chosen channels, in order to provide the Service.
  • Types of Personal Data: any Personal Data the Customer includes in Customer Content; Authorised User account data (name, work email, organisation, authentication identifiers); and reminder-recipient identifiers (email address, Slack member ID, and/or mobile phone number) where those features are used.
  • Categories of Data Subjects: the Customer's Authorised Users, and any individuals referenced within Customer Content.
  • Special categories: not intended; the Customer is responsible for any special-category data it chooses to include.

Annex II — Technical and organisational measures

  • Encryption in transit (TLS) for data moving between clients, the Service, and its components.
  • Access control: role-based, least-privilege administrative access; individual authentication for Authorised Users via FSS's own authorisation server.
  • Tenant isolation: logical separation of each customer tenant's data.
  • Network security: segmented internal networks; restricted, firewalled service exposure.
  • Physical security: hosting in a colocation data centre with the provider's physical access controls.
  • Logging & monitoring: operational and security logging on FSS infrastructure (no third-party log or analytics processors); logs capture metadata, not document or prompt content.
  • Backups: regular backups on FSS-controlled infrastructure within the EU.
  • Governance: practices aligned with the principles of ISO/IEC 27001, ISO/IEC 20000 and ISO 9001 (previously certified; certifications not currently maintained).

Annex III — Sub-processors

Sub-processorRoleDataLocationWhen
Telepoint EADData-centre colocation (facility only; no logical access to data)Hardware housing stored dataSofia, Bulgaria (EU)Always
A1 Bulgaria EAD (SPNET)Internet connectivity / IP transitData in transit (encrypted)Bulgaria (EU)Always
Slack Technologies, LLC (a Salesforce company)Optional reminder delivery via Slack DMReminder content + recipient Slack member IDUnited StatesOnly if the Customer enables Slack reminders
Yettel Bulgaria EADOptional reminder delivery via SMSRecipient phone number + message contentBulgaria (EU)Only if the Customer enables SMS reminders
brainattic.ai

The governed knowledge base your team and your agents both trust.

Product

Features Use cases Connect to Claude, ChatGPT & Mistral Docs How it works FAQ Request a pilot

Company

About Security Contact

Legal

Privacy Policy Terms of Service Cookie Policy Data Processing Agreement
© 2026 Finite Software Systems. brainattic is a product of Finite Software Systems. hello@brainattic.ai