Data Processing Agreement

This Data Processing Agreement (“DPA”) forms part of the Terms of Service between Stylebase Inc. (“Company”) and the customer (“Customer”) and applies where Company processes Personal Data on Customer’s behalf in connection with the Brandy services (“Services”).

1. Roles of the Parties

For the purposes of applicable data protection laws: Customer acts as the Data Controller. Company (Stylebase Inc.) acts as the Data Processor. Company may engage authorized third-party subprocessors to assist in providing the Services.

2. Scope of Processing

2.1 Subject Matter – Processing relates to the provision of brand asset management software and services.

2.2 Duration – Processing continues for the duration of the Services.

2.3 Categories of Data Subjects – Customer’s end users; Brand asset data & viewers; Authorized users.

2.4 Categories of Personal Data – Contact details; IP addresses and technical data; Related communications. No special category data is intended.

3. Processing Instructions

Company shall process Personal Data solely to provide the Services, on documented instructions from Customer, and in accordance with this DPA and applicable law.

4. Confidentiality

Company ensures that personnel authorized to process Personal Data are subject to confidentiality obligations.

5. Security Measures

Company shall implement appropriate technical and organizational measures designed to protect Personal Data against unauthorized access, disclosure, alteration, or destruction, taking into account the nature of the data and industry standards. See Company’s Security page for further detail.

6. Subprocessors

Customer authorizes Company to engage subprocessors, provided they are bound by data protection obligations no less protective than this DPA, and Company remains responsible for their compliance. Current subprocessors include Company’s cloud hosting, database, and payment processing providers. A current list is available upon request at becky@brandyhq.com.

7. Data Subject Requests

Company shall reasonably assist Customer in responding to requests from data subjects where required under applicable law.

8. Personal Data Breach

Company shall notify Customer without undue delay after becoming aware of a Personal Data Breach and provide information reasonably necessary to enable Customer to comply with its legal obligations.

9. International Data Transfers

Where Personal Data is transferred outside the jurisdiction in which it was collected, Company shall ensure such transfers are subject to appropriate safeguards in accordance with applicable data protection laws. For transfers subject to GDPR or UK GDPR, such safeguards may include approved standard contractual clauses or equivalent mechanisms.

10. Data Return or Deletion

Upon termination of the Services, Company shall delete or return Personal Data, unless retention is required by law.

11. Audit & Compliance

Company shall make available information reasonably necessary to demonstrate compliance with this DPA. Audits shall be limited, reasonable in scope, and subject to confidentiality obligations.

12. Liability

Liability arising from this DPA shall be subject to the limitations set forth in the Terms of Service, except where prohibited by applicable law.

13. Governing Law

This DPA shall be governed by and construed in accordance with the laws of the State of Delaware, United States of America, consistent with the Terms of Service, unless mandatory data protection law requires otherwise.

14. Precedence

In the event of a conflict between this DPA and the Terms of Service, this DPA shall govern with respect to data protection matters.

15. Contact Us

For questions or concerns about this Privacy Policy, please contact us at becky@brandyhq.com

Scroll to Top