BrewMy{Code}
Last updated 19 September 2026

Data Processing Agreement

This Data Processing Agreement ("DPA") forms part of the Terms of Service between BrewMyCode, Business ID 3518342-5, Laviontie 78, 19950 Luhanka, Finland ("Processor") and the Customer ("Controller") and applies to personal data in Customer Content processed by the Processor on behalf of the Controller in connection with the BrewMy{Code} Service.

1. Subject matter, duration, nature and purpose

The Processor processes personal data contained in content the Controller connects to or uploads into the Service, for the purpose of providing the Service: indexing content into knowledge bases, answering users' questions, running agents configured by the Controller, producing traces and logs, and providing support. Processing lasts for the term of the agreement and the deletion period in section 9.

2. Types of data and data subjects

Types of data depend on what the Controller connects and typically include contact details, employment and role information, business communications, customer and supplier records, and any other personal data contained in documents, messages and business systems. Data subjects typically include the Controller's employees, customers, suppliers and other business contacts.

3. Instructions

The Processor processes personal data only on the Controller's documented instructions, which consist of the agreement, this DPA and the Controller's configuration of the Service (connected sources, permissions, agents, retention settings). The Processor will inform the Controller if it believes an instruction infringes data protection law.

4. Confidentiality and personnel

Personnel with access to personal data are bound by confidentiality obligations and receive data protection training. Access to Customer Content is limited to what is necessary for support and is logged.

5. Security

The Processor implements technical and organisational measures appropriate to the risk, including: encryption in transit (TLS 1.2+) and at rest (AES-256); permission-aware retrieval that filters results per user; role-based access control and multi-factor authentication; network segregation; logging and monitoring; secure software development practices and dependency scanning; independent security testing; encrypted backups with tested restore procedures; and business continuity procedures. Details are described on the security page.

6. Sub-processors

The Controller authorises the use of the following sub-processors. The Processor will notify the Controller at least 30 days before adding or replacing a sub-processor; the Controller may object on reasonable data-protection grounds, in which case the parties will seek a solution and the Controller may terminate the affected Service if none is found.

CategoryPurposeLocation
Cloud infrastructure providerCompute, storage, backupsEU (Stockholm, eu-north-1)
Cloud infrastructure & model hosting providerCloud infrastructure and model hostingEU (Sweden Central, North Europe)
Language model provider (zero data retention)Language models via APIEU / US*
Language model provider (zero data retention)Language models via APIEU / US*
EU-hosted model providerEU-hosted language modelsEU (France)
Website hosting providerWebsite and web application hostingEU edge / US*
Transactional email providerTransactional email deliveryUS*
Meeting scheduling providerMeeting scheduling for customer callsUS*

The named entity behind each category is available on request to customers with a signed Data Processing Agreement.

* Transfers outside the EU are covered by the European Commission's Standard Contractual Clauses and, where the recipient is certified, the EU–US Data Privacy Framework.

7. Assistance to the Controller

Taking into account the nature of processing, the Processor assists the Controller with responding to data subject requests (access, rectification, erasure, restriction, portability, objection) within 10 business days of a request, and with security, breach notification, data protection impact assessments and prior consultation.

8. Personal data breaches

The Processor notifies the Controller without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting the Controller's data, and provides the information reasonably required for the Controller to meet its obligations under GDPR articles 33 and 34.

9. Deletion and return

On termination, the Processor makes Customer Content and configurations available for export for 30 days and then deletes all personal data within a further 35 days, including from backups as they rotate, unless retention is required by law. The Controller may also delete individual sources, knowledge bases or agents at any time through the Service.

10. Audits

The Processor makes available information necessary to demonstrate compliance, including security documentation and results of independent testing. The Controller may audit the Processor once per year, or after a breach, on 30 days' notice, during business hours, subject to confidentiality and without unreasonable disruption.

11. International transfers

The Processor stores and processes personal data in the EU. Any transfer to a third country is made only through sub-processors listed in section 6, under Standard Contractual Clauses or another valid transfer mechanism, with supplementary measures where required.

12. Liability and governing law

Liability is governed by the agreement. This DPA is governed by the laws of Finland. In case of conflict between this DPA and the agreement regarding personal data, this DPA prevails.

Contact

Data protection contact: privacy@brewmycode.com · BrewMyCode, Laviontie 78, 19950 Luhanka, Finland