brett
Product How it works Industries Notes
Log in Book a demo
Product How it works Industries Notes
Log inBook a demo

Data Processing Agreement

Last updated: 5 August 2026

This Data Processing Agreement (DPA) forms part of the agreement between the customer (Customer) and BRETT INTELLIGENCE LIMITED, registered in England and Wales under company number 17381109, with its registered office at 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ (brett).

1. Scope and roles

This DPA applies where brett processes personal data in Customer Content on the Customer's behalf in providing the Services (Customer Personal Data).

The Customer is the controller and brett is the processor. If the Customer acts as a processor for another controller, brett is its subprocessor and the Customer confirms that it is authorised to appoint brett.

Terms such as controller, processor, personal data, processing, data subject and personal data breach have the meanings given in applicable UK data protection law.

2. Instructions

brett will process Customer Personal Data only on the Customer's documented instructions, including this DPA, the agreement, the Customer's configuration and use of the Services, unless UK law requires otherwise. If legally permitted, brett will tell the Customer before processing required by law.

The Customer is responsible for the lawfulness of its instructions and Customer Personal Data. If brett reasonably believes an instruction infringes data protection law, it may suspend the relevant processing while the parties discuss it.

3. brett's obligations

brett will:

  • ensure that people authorised to process Customer Personal Data are subject to confidentiality obligations;
  • implement appropriate technical and organisational measures designed to protect Customer Personal Data against unlawful or unauthorised processing and accidental loss, destruction or damage;
  • taking into account the nature of processing, reasonably assist the Customer with data subject requests;
  • reasonably assist the Customer with security, breach notification, data protection impact assessment and regulatory consultation obligations, taking into account the information available to brett;
  • notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data and provide available information reasonably needed by the Customer; and
  • make available information reasonably necessary to demonstrate compliance with this DPA.

brett will not use Customer Personal Data to train or improve models for other customers or for general model development unless the Customer expressly instructs brett to do so in writing.

4. Subprocessors

The Customer gives general authorisation for brett to appoint subprocessors. brett will maintain an up-to-date list and make it available to the Customer on request. brett will inform the Customer of any intended addition or replacement of a subprocessor and give the Customer a reasonable opportunity to object on data protection grounds.

brett will enter into a written agreement with each subprocessor imposing data protection obligations appropriate to the processing and will remain responsible for the subprocessor's performance of those obligations.

5. International transfers

brett will not transfer Customer Personal Data outside the United Kingdom unless the transfer complies with applicable data protection law. Safeguards may include an adequacy regulation, the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses.

6. Audits

brett will make available information reasonably necessary to demonstrate compliance with this DPA and allow for and contribute to audits by the Customer or an independent auditor as required by applicable data protection law and the agreement. Audits must protect confidential information and avoid unreasonable disruption.

7. Return and deletion

On termination of the Services and at the Customer's written direction, brett will delete or return Customer Personal Data, unless applicable law requires retention. Data retained by law will remain protected and will not be used for another purpose.

8. Liability and general terms

The liability limitations in the Terms of Service apply to this DPA. If this DPA conflicts with the rest of the agreement on a data protection matter, this DPA takes priority.

This DPA ends when brett no longer processes Customer Personal Data, except for terms intended to continue. It is governed by the laws of England and Wales and the courts of England and Wales have exclusive jurisdiction.

Privacy and data protection notices should be sent to privacy@usebrett.com.

Schedule 1 — Processing details

Subject matter and duration

Processing Customer Personal Data to provide the Services for the term of the agreement and any short period needed for return or deletion.

Nature and purpose

Hosting, storing, organising, analysing, retrieving, transmitting and deleting Customer Personal Data to provide AI-assisted review, collaboration, workflows, reporting, integrations, security and support.

Data subjects and personal data

Data subjects may include Authorised Users and people identified in Customer Content. Personal data may include business contact and account information, device and usage data, communications, and any personal data the Customer chooses to include in Customer Content.

The Services are not intended for special category or criminal offence data unless the parties expressly agree otherwise.

Processing occurs as determined by the Customer's use of the Services.

brett.

Digital teammates built for ambition, wired for compliance.

ProductMeet brettRule intelligenceBetter marketingNotesBook a demo
IndustriesFinancial servicesBanking and lendingInsuranceHealthcareMedical devicesLife sciencesSustainabilityConsumer goods
CompanyLinkedInYouTubeContact usLog in
Legal Privacy policy Terms of service Data processing agreement
© 2026 brett. All rights reserved.