Legal · Data processing
Data processing addendum.
Last updated · 22 September 2026
01Section
Scope and roles
This addendum forms part of the Terms of Service between you (the customer) and Brandlism (operated from New Jersey, United States) (“Brandlism”). It applies when Brandlism processes personal data on your behalf. It needs no signature: it takes effect when you accept the terms. If you need a countersigned copy, email legal@brandlism.com.
You are the controller, and Brandlism is your processor, for the personal data in the client data you add to your workspace. Brandlism is a controller only for its own account and billing records and its website visitors’ data, which the Privacy Policy covers.
02Section
The processing
- Subject matter and purpose. Providing Brandlism to you: scanning public evidence about your client brands, analysing it, and producing findings and recommendations, proof records, and the reports and client pages built from them.
- Duration. For as long as your account is open, then until deletion under section 9.
- Data subjects. Your clients’ staff and contacts, their customers (for example reviewers), your own team members, and people named in public sources about a brand.
- Types of data. Names, business contact details, job titles, the contents of intake notes, voice memo recordings and transcripts, payment records you log, public review and forum content, and data from accounts you connect. Brandlism is not designed for special category data. Please do not add it.
03Section
Our commitments as processor
In line with Article 28 of the GDPR and the UK GDPR, Brandlism will:
- process the data only on your documented instructions (these terms, and how you use the product), unless the law requires otherwise, in which case we will tell you first where the law allows
- tell you if we believe an instruction breaks data protection law
- make sure everyone authorised to process the data is bound by confidentiality
- apply the security measures in section 5
- use subprocessors only as section 4 describes
- help you answer requests from data subjects, and with security, breach notification, impact assessments and consultations with regulators, taking into account the nature of the processing
- delete or return the data at the end of the service, as section 9 describes
- give you the information you need to show compliance with Article 28, as section 8 describes
04Section
Subprocessors
You give general authorisation for Brandlism to use subprocessors. The current list is on our subprocessors page. Each subprocessor is bound by written terms that protect the data at least as well as this addendum. We remain responsible to you for their work.
We will give at least 30 days’ notice before adding or replacing a subprocessor, by updating that page and emailing account owners who ask to be told. You may object on reasonable data protection grounds within that period. If we cannot address the objection, you may end the affected service and receive a pro rata refund of prepaid fees for it.
05Section
Security measures
- Encryption of data in transit and at rest, provided by our hosting and database providers.
- Workspace isolation enforced by row-level access rules in the database, not by application code alone.
- Connected-account tokens sealed with a separate key before they are stored.
- Access by Brandlism staff limited to what support and operations require, with administrative actions logged.
- Secrets kept on the server only, and never sent to the browser.
- Backups kept by our database provider for recovery, rolling off within 35 days.
- Dependency updates and security fixes applied as part of normal releases.
06Section
Personal data breaches
If Brandlism becomes aware of a breach affecting personal data it processes for you, we will notify you without undue delay, and in any case within 72 hours. The notice will describe what happened, the data and people likely affected, the likely consequences, and what we have done and will do about it. Where we do not have all of that at first, we will send what we know and follow up as we learn more.
07Section
Data subject requests
Most requests you can answer yourself: the product lets you view, correct, export and delete the data in your workspace. If a data subject contacts Brandlism directly about data we process for you, we will pass the request to you and not answer it ourselves unless you ask us to.
08Section
Audits
On written request, no more than once a year, we will answer a reasonable security questionnaire and provide the documentation needed to show compliance with this addendum. If a regulator requires it, or after a breach, we will support an audit by you or an independent auditor you appoint, on reasonable notice, during business hours and under confidentiality, at your cost.
09Section
Deletion and return
You can export your workspace data at any time from Settings → Your data. When your account is deleted, Brandlism deletes the personal data it processes for you from its live systems within 30 days, and backups containing it roll off within a further 35 days, unless the law requires us to keep it.
10Section
International transfers
Where the processing involves a transfer of personal data out of the EEA, Switzerland or the UK to a country without an adequacy decision, the Standard Contractual Clauses adopted by European Commission Decision 2021/914 (Module Two, controller to processor, and Module Three where you are yourself a processor) are incorporated into this addendum by reference, with the UK International Data Transfer Addendum for UK transfers. Clause 7 does not apply, the optional wording in Clause 11 does not apply, Clause 9 option 2 (general authorisation) applies, and Clauses 17 and 18 select the law and courts of Ireland. The annexes are completed by sections 2, 4 and 5 of this addendum.
11Section
California: service provider terms
For personal information covered by the CCPA as amended by the CPRA, Brandlism acts as your service provider. We will not sell or share it, will not keep, use or disclose it for any purpose other than providing the service to you, will not combine it with personal information from other sources except as the law permits, and will tell you if we can no longer meet these obligations. You may take reasonable steps to stop and remedy unauthorised use.
12Section
Order of precedence
If this addendum conflicts with the Terms of Service, this addendum wins for the processing of personal data. If it conflicts with the Standard Contractual Clauses, the clauses win. The limitation of liability in the terms applies to this addendum. Questions go to legal@brandlism.com.