BrieflyWorks

Data Processing Agreement

Article 28 GDPR terms for customer content processed through BrieflyWorks.

Version and effective date: 2026-08-24

1. Parties and incorporation

This Data Processing Agreement (DPA) forms part of the Terms between the business customer as controller (Customer) and Louay Aousaji and Aziz Abderrahmane Ben Othmane as processor (BrieflyWorks). It applies where BrieflyWorks processes personal data in customer content on the Customer's behalf.

2. Instructions and purpose

BrieflyWorks will process customer personal data only on documented instructions expressed through the Terms, product configuration, and lawful support requests, unless Union or Member State law requires otherwise. Processing is limited to hosting, securing, retrieving, structuring, analysing, summarising, and presenting content to provide the subscribed service.

3. Customer obligations

The Customer is responsible for lawful instructions, legal bases, transparency notices, data minimisation, accuracy, retention choices, data-subject communications, and any employee-representation consultation. The Customer must not instruct processing that violates data-protection law and must promptly respond if BrieflyWorks identifies an apparently unlawful instruction.

4. Confidentiality and personnel

BrieflyWorks will limit access to authorised persons who need it to provide or secure the service and who are bound by confidentiality obligations. Access will be reviewed and removed when no longer required.

5. Security measures

  • Encrypted HTTPS transport and provider-managed encryption at rest where supported.
  • Role-based application access, tenant identifiers, authentication, and database access controls.
  • Server-side protection of service credentials and payment secrets.
  • Webhook signature verification for supported payment and email events.
  • Dependency maintenance, logging, backups supplied by configured infrastructure, and incident investigation procedures.
  • Data minimisation through context limits and restricted AI prompts.

Security is risk-based and will be reviewed as the service changes. No system can guarantee absolute security.

6. Subprocessors

The Customer gives general authorisation for the subprocessors below. BrieflyWorks will impose appropriate data-protection obligations and remains responsible for its processor obligations. Material additions or replacements will be announced through the service or account email, allowing a reasonable opportunity to object on substantiated data-protection grounds.

  • Vercel: application hosting, serverless execution, delivery, and operational logs.
  • Supabase and configured infrastructure: database, authentication, and storage.
  • Anthropic: AI model inference for customer-requested features.
  • Resend and its infrastructure: inbound email receipt and delivery events.
  • Firecrawl: customer-requested public website retrieval when direct retrieval is unavailable.
  • Notion: access to workspace pages explicitly selected by the Customer through the optional integration, including storage, change-aware analysis, summarisation, and preparation of customer-reviewed operational suggestions.

Stripe and PayPal principally process payment data under their own obligations and are not used to analyse customer content.

7. International transfers

BrieflyWorks will use a lawful transfer mechanism where protected data is transferred outside the EEA, such as an adequacy decision or Standard Contractual Clauses, and will make relevant safeguard information available on reasonable request.

8. Assistance

Taking account of the nature of processing and information available, BrieflyWorks will reasonably assist the Customer with data-subject requests, security obligations, breach notifications, impact assessments, and consultations. Additional work beyond standard product functionality may be charged at an agreed reasonable rate where legally permitted.

9. Personal-data breaches

BrieflyWorks will notify the Customer without undue delay after becoming aware of a personal-data breach affecting customer content and will provide information reasonably available for the Customer's assessment and notification duties.

10. Return, deletion, and audits

At the end of services, BrieflyWorks will delete or return customer personal data on request unless law requires retention. Protected backup copies may remain until overwritten under the normal backup cycle. BrieflyWorks will provide information reasonably necessary to demonstrate compliance and permit proportionate audits subject to confidentiality, security, advance notice, and avoidance of disruption.

Annex A: Processing details

  • Duration: the subscription term plus deletion, backup, dispute, and mandatory retention periods.
  • Data subjects: customer users, staff, customers, prospects, suppliers, correspondents, and other persons mentioned in submitted business content.
  • Data types: identifiers, contact and employment information, business communications, notes, tasks, follow-ups, website content, and usage metadata.
  • Special data: prohibited by default unless separately and expressly agreed in writing with suitable safeguards.
  • Frequency: continuous or user-initiated during account use.