This Data Processing Agreement (“DPA”) forms part of the Terms of Service between Stylebase Inc. (“Company”) and the customer (“Customer”) and applies where Company processes Personal Data on Customer’s behalf in connection with the Brandy services (“Services”).
1. Roles of the Parties
For the purposes of applicable data protection laws: Customer acts as the Data Controller. Company (Stylebase Inc.) acts as the Data Processor. Company may engage authorized third-party subprocessors to assist in providing the Services.
2. Scope of Processing
2.1 Subject Matter – Processing relates to the provision of brand asset management software and services.
2.2 Duration – Processing continues for the duration of the Services.
2.3 Categories of Data Subjects – Customer’s end users; Brand asset data & viewers; Authorized users.
2.4 Categories of Personal Data – Contact details; IP addresses and technical data; Related communications. No special category data is intended.
3. Processing Instructions
Company shall process Personal Data solely to provide the Services, on documented instructions from Customer, and in accordance with this DPA and applicable law.
4. Confidentiality
Company ensures that personnel authorized to process Personal Data are subject to confidentiality obligations.
5. Security Measures
Company shall implement appropriate technical and organizational measures designed to protect Personal Data against unauthorized access, disclosure, alteration, or destruction, taking into account the nature of the data and industry standards. See Company’s Security page for further detail.
6. Subprocessors
Customer authorizes Company to engage subprocessors, provided they are bound by data protection obligations no less protective than this DPA, and Company remains responsible for their compliance. Current subprocessors include Company’s cloud hosting, database, and payment processing providers. A current list is available upon request at becky@brandyhq.com.
7. Data Subject Requests
Company shall reasonably assist Customer in responding to requests from data subjects where required under applicable law.
8. Personal Data Breach
Company shall notify Customer without undue delay after becoming aware of a Personal Data Breach and provide information reasonably necessary to enable Customer to comply with its legal obligations.
9. International Data Transfers
Where Personal Data is transferred outside the jurisdiction in which it was collected, Company shall ensure such transfers are subject to appropriate safeguards in accordance with applicable data protection laws. For transfers subject to GDPR or UK GDPR, such safeguards may include approved standard contractual clauses or equivalent mechanisms.
10. Data Return or Deletion
Upon termination of the Services, Company shall delete or return Personal Data, unless retention is required by law.
11. Audit & Compliance
Company shall make available information reasonably necessary to demonstrate compliance with this DPA. Audits shall be limited, reasonable in scope, and subject to confidentiality obligations.
12. Liability
Liability arising from this DPA shall be subject to the limitations set forth in the Terms of Service, except where prohibited by applicable law.
13. Governing Law
This DPA shall be governed by and construed in accordance with the laws of the State of Delaware, United States of America, consistent with the Terms of Service, unless mandatory data protection law requires otherwise.
14. Precedence
In the event of a conflict between this DPA and the Terms of Service, this DPA shall govern with respect to data protection matters.
15. Contact Us
For questions or concerns about this Privacy Policy, please contact us at becky@brandyhq.com