Data Processing Agreement
DRAFT — NOT LEGALLY REVIEWED, AND THIS ONE MATTERS MOST. GDPR Article 28 prescribes mandatory content; an inadequate DPA exposes both parties. Have counsel review before signing anything.
Forms part of the Terms of Service or the Enterprise agreement between Brandmill ("Processor") and the customer ("Controller"). Terms have the meanings given in Regulation (EU) 2016/679 ("GDPR").
1. Roles
The Controller determines purposes and means. The Processor processes only on documented instructions — these terms, the agreement, and the Controller's use of the service. The Processor tells the Controller if an instruction appears to breach data-protection law.
2. Subject matter (Art. 28(3))
| Subject matter | Providing the UAML Studio service |
| Duration | The term of the agreement, plus the deletion period in §9 |
| Nature and purpose | Hosting, storage, transmission, display and processing of models and account data; generating exports and AI-assisted output |
| Personal data | Account data (name, email, credentials); whatever the Controller places in a model; support correspondence |
| Data subjects | The Controller's personnel and any individuals it chooses to include in a model |
| Special categories | Not required by the service. The Controller should not place special-category data in a model, and does so at its own risk |
3. Confidentiality
Everyone the Processor authorises is bound by confidentiality and trained in data protection.
4. Security (Art. 32)
Encryption in transit and at rest; access control on least privilege; segregation of environments; logging and monitoring; backup and restore; vulnerability management; documented incident response; and periodic testing. Measures are described at [security page URL] and may be improved but not materially weakened.
5. Sub-processors (Art. 28(2), 28(4))
The Controller gives general authorisation for the sub-processors listed at [sub-processor URL]. The Processor gives 30 days' notice of any addition or replacement; the Controller may object on reasonable data-protection grounds within that period, and if the parties cannot resolve the objection the Controller may terminate the affected service without penalty for the unused prepaid term. Sub-processors are bound to equivalent obligations, and the Processor stays liable for them.
6. Assistance (Art. 28(3)(e)–(f))
Taking account of the nature of processing, the Processor assists with: data-subject requests; security under Art. 32; breach notification under Arts. 33–34; data-protection impact assessments under Art. 35; and prior consultation under Art. 36.
7. Breach notification
The Processor notifies the Controller without undue delay and in any event within 48 hours of becoming aware of a personal-data breach, with the information available, supplemented as the investigation proceeds.
8. Audit (Art. 28(3)(h))
The Processor makes available the information needed to demonstrate compliance. The Controller may audit once in any twelve months, on 30 days' notice, during business hours, subject to confidentiality and without unreasonable disruption — or accept an independent audit report or certification where one exists. The Controller bears its own costs; the Processor may charge reasonable costs for audits beyond the annual one.
9. Deletion and return (Art. 28(3)(g))
On termination the Controller may export its data for 30 days in the open
.uaml format. After that the Processor deletes it, including from backups
within the backup cycle [state cycle], unless EU or member-state law requires
retention.
10. International transfers (Ch. V)
Transfers outside the EEA rely on an adequacy decision, or on the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module Two (controller to processor), which are incorporated by reference and prevail over this DPA in the event of conflict. A transfer impact assessment is carried out and supplementary measures applied where needed.
11. AI processing — read this clause
Where the Controller uses AI features, model content is transmitted to the model provider named in the sub-processor list, acting as a sub-processor. The Processor contracts so that content is not used to train the provider's models. The Controller decides what goes into a model and therefore what may be transmitted.
An on-premises Controller can avoid this entirely by pointing the product at its own model deployment, so no content leaves its network. Where a Controller's reason for choosing on-premises is data confinement, that configuration is strongly recommended and should be recorded.
12. Liability and precedence
Liability follows the main agreement. In conflict, the order is: the SCCs, then this DPA, then the main agreement.