Skip to content
Skip to content
Brandex
Enter
Main content

Data Processing Addendum

Last updated: June 24, 2026 · Version 1.0

This Data Processing Addendum ("DPA") forms part of the Terms of Service between Brandex ("Processor") and the Customer ("Controller") and applies whenever Brandex processes Personal Data on the Controller's behalf under the GDPR, UK GDPR, or equivalent laws.

1. Roles and scope

Customer is the Controller of Personal Data uploaded into the Service. Brandex acts as Processor and processes Personal Data solely to provide the Service per documented instructions in the Terms.

2. Categories of data

  • Account data: name, email, workspace metadata.
  • Content data: brand assets, prompts, generated images/video, uploaded media.
  • Usage data: generation logs, credit usage, audit events.

3. Subprocessors

Brandex uses the following subprocessors. We notify Customers of additions/replacements at least 30 days in advance via in-app notice.

  • Supabase (Lovable Cloud) — database, auth, storage. EU/US regions.
  • Cloudflare — CDN, edge compute. Global.
  • Polar.sh — billing, Merchant of Record. EU.
  • Replicate — model inference for image/video generation. US.
  • Google (Gemini), OpenAI — AI model providers via Lovable AI Gateway. EU/US.
  • Resend — transactional email. EU/US.

4. Security measures

  • Encryption in transit (TLS 1.2+) and at rest (AES-256).
  • Row-Level Security on all tenant data with least-privilege roles.
  • Secrets stored in a managed vault, never in source.
  • SSO domain lock available; audit log of admin and security-sensitive actions.
  • Daily database backups; point-in-time recovery available.
  • Annual access review and quarterly secret rotation.

5. International transfers

Where Personal Data is transferred outside the EEA/UK, transfers rely on the EU Standard Contractual Clauses (2021/914) and the UK International Data Transfer Addendum, plus supplementary measures (encryption, access controls).

6. Data subject rights

Brandex assists Controllers in responding to data-subject access, rectification, erasure, restriction, and portability requests via the in-app GDPR tools (Settings → Privacy → Data Subject Requests). Requests are processed within 30 days.

7. Personal Data breaches

Brandex notifies affected Controllers without undue delay and within 72 hours of becoming aware of a confirmed Personal Data breach affecting their data.

8. Retention and deletion

On termination, Personal Data is deleted within 30 days unless retention is required by law. Backups expire within 35 days. Audit logs are retained for 13 months.

9. Audits

Customers may request a security questionnaire annually. On-site audits are available for Business and Enterprise plans under reasonable notice and NDA.

10. Contact

Data Protection contact: privacy@brandex.app

To countersign this DPA for your organisation, email a request to privacy@brandex.app with your legal entity name; we return a signed PDF within 5 business days.