BrandCurb provides a standard Data Processing Agreement (DPA) with every AI automation engagement. The DPA covers scope of processing, security measures, sub-processors, data subject rights, data retention and deletion, and breach notification — aligned with PIPEDA and GDPR. Based in Toronto, Ontario, Canada. Serving clients worldwide.
Data Processing Agreement
Your data. Your rules. In writing.
The standard DPA behind every BrandCurb engagement
This Data Processing Agreement governs how BrandCurb processes personal data on your behalf as part of delivering AI automation services. Every client project includes a signed DPA — this is the standard version.
PIPEDA & GDPR aligned
TLS 1.3 encryption
AES-256 at rest
What the DPA covers by default
Scope of processing
We process your data only on documented instructions — never for our own purposes.
Security measures
TLS 1.3 in transit, AES-256 at rest, role-based access, encrypted credentials.
Sub-processors
Every sub-processor bound by a DPA with equivalent data protection standards.
Data subject rights
We assist with access, rectification, erasure, portability, and restriction requests.
Retention and deletion
Data deleted within 90 days of termination, with written confirmation on request.
Breach notification
We notify you within 72 hours of a confirmed personal data breach.
72 hrs
Breach notification commitment
90 days
Data deleted after project close
AES-256
Encryption at rest, TLS 1.3 in transit
The agreement
Six sections. Zero fine print.
This DPA is included with every engagement and covers exactly what happens to your data — section by section, in plain language.
Scope of processing
As a data processor, BrandCurb processes personal data only on your documented instructions and only to the extent necessary to deliver the agreed AI automation services. We do not process your data for our own commercial purposes, do not sell it, and do not use it to train public AI models. Processing activities are limited to: building and testing AI automation tools, integrating with your specified platforms, and providing post-launch support.
Security measures
BrandCurb implements the following technical and organisational measures for all client data: TLS 1.3 encryption for all data in transit, AES-256 encryption for data at rest, role-based access controls limiting data access to project team members only, encrypted credential storage with regular rotation, and secure deletion of client data within 90 days of project completion.
Sub-processors
We may engage the following categories of sub-processors to deliver our services: cloud infrastructure providers (AWS, Google Cloud), AI model API providers (OpenAI, Anthropic, or open-source alternatives), and project management tools. All sub-processors are subject to data processing agreements that require equivalent data protection standards. We will notify you of any material changes to our sub-processor list with reasonable notice.
Data subject rights
We will assist you in fulfilling your obligations to respond to data subject rights requests (access, rectification, erasure, portability, restriction) within the timeframes required by applicable law. If we receive a data subject request directly relating to your personal data, we will forward it to you within 5 business days.
Data retention and deletion
Client data is retained for the duration of the service agreement and deleted within 90 days of agreement termination unless you request a different timeline in writing. Backup copies are retained for a maximum of 30 days following the primary deletion. We provide written confirmation of deletion upon request.
Breach notification
In the event of a personal data breach affecting your data, BrandCurb will notify you within 72 hours of becoming aware of the breach. The notification will include: the nature of the breach, categories and approximate number of records affected, likely consequences, and measures taken or proposed to address the breach.
Questions about the Data Processing Agreement
Straight answers to the questions every business owner should ask before sharing data with an AI partner.
As a data processor, BrandCurb processes personal data only on your documented instructions and only to the extent necessary to deliver the agreed AI automation services. We do not process your data for our own commercial purposes, do not sell it, and do not use it to train public AI models. Processing is limited to building and testing AI automation tools, integrating with your specified platforms, and providing post-launch support.
As a data processor, BrandCurb processes personal data only on your documented instructions and only to the extent necessary to deliver the agreed AI automation services. We do not process your data for our own commercial purposes, do not sell it, and do not use it to train public AI models. Processing is limited to building and testing AI automation tools, integrating with your specified platforms, and providing post-launch support.
TLS 1.3 encryption for all data in transit, AES-256 encryption for data at rest, role-based access controls limiting data access to project team members only, encrypted credential storage with regular rotation, and secure deletion of client data within 90 days of project completion.
TLS 1.3 encryption for all data in transit, AES-256 encryption for data at rest, role-based access controls limiting data access to project team members only, encrypted credential storage with regular rotation, and secure deletion of client data within 90 days of project completion.
We may engage cloud infrastructure providers (AWS, Google Cloud), AI model API providers (OpenAI, Anthropic, or open-source alternatives), and project management tools to deliver our services. All sub-processors are subject to data processing agreements that require equivalent data protection standards, and we notify you of material changes with reasonable notice.
We may engage cloud infrastructure providers (AWS, Google Cloud), AI model API providers (OpenAI, Anthropic, or open-source alternatives), and project management tools to deliver our services. All sub-processors are subject to data processing agreements that require equivalent data protection standards, and we notify you of material changes with reasonable notice.
We assist you in fulfilling your obligations to respond to data subject rights requests (access, rectification, erasure, portability, restriction) within the timeframes required by applicable law. If we receive a data subject request directly relating to your personal data, we forward it to you within 5 business days.
We assist you in fulfilling your obligations to respond to data subject rights requests (access, rectification, erasure, portability, restriction) within the timeframes required by applicable law. If we receive a data subject request directly relating to your personal data, we forward it to you within 5 business days.
Client data is retained for the duration of the service agreement and deleted within 90 days of agreement termination unless you request a different timeline in writing. Backup copies are retained for a maximum of 30 days following the primary deletion, and we provide written confirmation of deletion upon request.
Client data is retained for the duration of the service agreement and deleted within 90 days of agreement termination unless you request a different timeline in writing. Backup copies are retained for a maximum of 30 days following the primary deletion, and we provide written confirmation of deletion upon request.
In the event of a personal data breach affecting your data, BrandCurb notifies you within 72 hours of becoming aware of the breach. The notification includes the nature of the breach, categories and approximate number of records affected, likely consequences, and measures taken or proposed to address the breach.
In the event of a personal data breach affecting your data, BrandCurb notifies you within 72 hours of becoming aware of the breach. The notification includes the nature of the breach, categories and approximate number of records affected, likely consequences, and measures taken or proposed to address the breach.
Every project ships with a signed DPA. Your data, protected in writing.
Request the standard DPA now, or book a free 30-minute call to walk through your specific data processing needs — no commitment, no pitch.
Free 30-minute call. No commitment. We respond within one business day.