
BRdata DPA Last updated: January 2026
1
BRdata Data Privacy Agreement
This BRdata Data Privacy Agreement (“DPA”) amends the terms and forms, between BRdata (collectively,
“BRdata” or “Service Provider”), and the Customer (“Customer” or “you”) each a “Party” and
collectively the “Parties”. This DPA governs your use of BRdata products and services, including but not
limited to BRdata Cloud. This DPA applies to and takes precedence over any associated contractual
document between the Parties, such as Terms and Conditions, an order form, statement of work, or other
thereunder (collectively, the “Agreement”), to the extent of any conflict.
If you are an individual who consents to the terms of this DPA on behalf of an entity, you represent and
warrant that you have the authority to bind that entity to this DPA and your consent to this DPA will be
treated as the consent of the business.
BRdata and Customer agree as follows:
1. Definitions. For purposes of this DPA:
a. “Data Privacy Laws” means all applicable laws, regulations, and other legal or self-
regulatory requirements in any jurisdiction relating to privacy, data protection, data security,
communications secrecy, breach notification, or the Processing of Personal Data, including
without limitation, to the extent if and when applicable, each of the Consumer privacy acts
listed on Exhibit “A” annexed hereto (each, a “CPA”). For the avoidance of doubt, if
Customer’s processing activities involving Personal Data are not within the scope of a given
Data Privacy Law, such law is not applicable for purposes of this DPA.
b. “Data Controller” or “Controller” means the natural or legal person, public authority,
agency or other body which, alone or jointly with others, determines the purposes and means
of the processing of Personal Data; for the purposes of this DPA, where Customer acts as
processor for another controller, it shall in relation to the BRdata Service be deemed as
additional and independent Controller with the respective controller rights and obligations
under this DPA.
c. “Data Subject” means an identified or identifiable natural person about whom Personal Data
relates.
d. “Personal Data” includes “personal data,” “personal information,” and “personally
identifiable information,” and such equivalent terms as defined by the Data Privacy Laws.
e. “Processing” or “Process” means any operation or set of operations which is performed on
Personal Information, whether or not by automated means, such as collection, recording,
organization, structuring, storage, adaptation or alteration, retrieval, consultation, use,
disclosure by transmission, dissemination or otherwise making available, alignment or
combination, restriction, erasure or destruction.
f. “Security Breach” means any accidental or unlawful acquisition, destruction, loss, alteration,
unauthorized disclosure of, or access to, Personal Data.