Data Processing Agreement
When you use Briedo to manage workflows that involve personal data belonging to your clients or leads, Briedo acts as a data processor on your behalf, and you remain the data controller. Under the GDPR (and similar privacy laws), this relationship must be governed by a written Data Processing Agreement (DPA).
Briedo can provide a DPA to customers whose use of the platform falls within scope. DPAs are available on request, see How to request a DPA below.
What is a Data Processing Agreement?
A DPA is a contract between a data controller (you, the customer) and a data processor (Briedo) that sets out the terms under which personal data may be processed. It is a legal requirement under GDPR Article 28 whenever a processor handles personal data on a controller's behalf.
The agreement ensures both parties understand their responsibilities, the purposes of processing, the safeguards in place, and the rights of the individuals whose data is involved.
What the DPA covers
Briedo's DPA addresses the standard obligations required by GDPR Article 28. In plain terms, this includes:
- Roles and responsibilities, clearly identifying you as the data controller and Briedo as the data processor
- Processing instructions, Briedo only processes personal data according to your documented instructions
- Purpose limitation, data processed through Briedo is used solely to deliver the platform services
- Confidentiality, personnel with access to personal data are bound by confidentiality obligations
- Security measures, the technical and organisational measures Briedo has in place to protect data (see our Security page)
- Subprocessors, authorisation and notification obligations for third-party subprocessors (see our Subprocessors page)
- Data subject rights, Briedo's commitment to assist you in responding to requests from individuals exercising their GDPR rights
- Breach notification, obligations to notify you in the event of a personal data breach without undue delay
- Deletion or return of data, how personal data is handled at the end of the customer relationship. In summary: raw intake conversation and operational session data is retained for up to 180 days and then deleted automatically; submitted briefs and lead data are processed on the agency's behalf for the life of the account and removed on the agency's instruction, on a data deletion request, or on workspace or account deletion; and data deleted from active systems may persist temporarily in access-controlled backups until they expire on their normal recovery lifecycle.
Who should request a DPA?
A DPA is relevant to you if any of the following apply:
- You are an agency using Briedo to manage briefs, leads, or client information on behalf of your clients
- Your organisation is established in the EU/EEA, the UK, or another jurisdiction with similar data protection requirements
- You process personal data belonging to EU/EEA residents, regardless of where your organisation is based
- Your internal procurement, legal, or privacy team requires a signed DPA before using third-party software
- You have a client contract that requires your own vendors to have a DPA in place
If you are a solo user with no client data involved, a formal DPA may not be required, but you are welcome to request one regardless.
How to request a DPA
DPAs are available on request. To initiate the process, send an email to privacy@briedo.com with:
- Your organisation's name and contact details
- A brief description of how you use Briedo and the type of personal data involved
- Any specific requirements from your legal or compliance team
We will review your request and respond with a draft DPA as soon as reasonably practicable. There is no automated signing portal at this time, the process is handled directly via email.