07Data processing addendum
Compliance
without the legal opacity.
Effective 2026-05-07
This DPA forms part of the Brain by AIStack Terms of Service. It applies whenever Brain processes personal data on your behalf and is designed to satisfy GDPR Art. 28, the UK GDPR, and CCPA service-provider requirements.
Roles
You are the data controller for the personal data processed through Brain. Brain by AIStack is the data processor. Brain only processes personal data on your documented instructions, including the configuration choices you make in the dashboard.
Sub-processors
Brain by AIStack uses a small number of audited sub-processors for hosting, payment processing, and error tracking. The current list is available at /legal/subprocessors and we provide 30 days notice before adding a new one.
Security measures
- Encryption in transit (TLS 1.3) and at rest (AES-256).
- SSO/MFA for all internal access; least-privilege role-based access controls.
- Continuous logging, intrusion detection, and quarterly third-party penetration tests.
- SOC 2 Type II attestation — see /legal/soc2 for details.
International transfers
Data is hosted in the region you select at project creation (US, EU, or UK). Cross-region transfers occur only when you opt in or when an EU/UK Standard Contractual Clauses-protected sub-processor requires it.
Data subject requests
We help you fulfill data subject access, deletion, portability, and rectification requests through dashboard tooling and a documented API. We respond to your assistance requests within 5 business days.
Breach notification
We notify affected customers without undue delay (and within 72 hours of becoming aware) of any personal data breach involving their data.
Audit rights
You may request a copy of our latest SOC 2 report once per year. Customers on Enterprise plans may also conduct a remote audit on reasonable notice.
Questions? Email legal@aistack.dev.