Legal and trust

DPA

This data processing addendum outlines the terms that apply when Brenix processes personal data on behalf of a customer organization.

Roles and instructions

The customer generally acts as controller and Brenix as processor for customer inspection data. Brenix processes personal data only on documented instructions, including instructions expressed through authorized use of the service.

Confidentiality and security

Personnel and contractors authorized to process customer data must be bound by confidentiality obligations. Technical and organizational measures are summarized on the security page and will be finalized before production contracting.

Subprocessors

Brenix may appoint subprocessors for hosting, storage, email, payments, analytics, and monitoring under written data-protection terms. A production subprocessor list and change-notification mechanism remain required.

Assistance and deletion

Brenix will provide reasonable assistance with data-subject requests, incident response, assessments, and regulator inquiries. Return and deletion procedures must account for legally required inspection-record retention and immutable evidence obligations.

Last updated: 28 July 2026.