This Data Processing Addendum ("DPA") forms part of the Terms of Service or other written agreement (the "Agreement") between Brook Code Technologies ("Brook Code") and the customer that has agreed to it ("Customer"). It applies whenever Brook Code processes Customer Personal Data on behalf of Customer in providing the Services.
This DPA is accepted automatically when Customer accepts the Terms. Customers who need a countersigned copy can request one from [email protected].
1. Definitions
Terms such as "controller", "processor", "data subject", "personal data", "processing" and "supervisory authority" have the meanings given in the GDPR. In addition:
- "Applicable Data Protection Law" means all laws that apply to the processing of Customer Personal Data under the Agreement, including the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, the California Consumer Privacy Act as amended ("CCPA"), and India's Digital Personal Data Protection Act, 2023 and its rules ("DPDP Act").
- "Customer Personal Data" means personal data contained in Customer Data that Brook Code processes on behalf of Customer.
- "Sub-processor" means any third party engaged by Brook Code to process Customer Personal Data.
- "Security Incident" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data.
- "Standard Contractual Clauses" or "SCCs" means the clauses approved by European Commission Implementing Decision (EU) 2021/914, and "UK Addendum" means the International Data Transfer Addendum issued by the UK Information Commissioner.
2. Roles of the parties
- Customer is the controller (or a processor acting on behalf of its own controller) of Customer Personal Data. Under the DPDP Act, Customer is the Data Fiduciary.
- Brook Code is the processor (or sub-processor) of Customer Personal Data. Under the DPDP Act it is a Data Processor, and under the CCPA it is a service provider.
- Brook Code acts as an independent controller for account, billing and usage data it collects for its own purposes, as described in its Privacy Policy. This DPA does not apply to that data.
3. Scope and details of processing
| Subject matter | Provision of the Services under the Agreement |
|---|---|
| Duration | The term of the Agreement plus the deletion period described in this DPA |
| Nature and purpose | Hosting, storage, backup, retrieval, organisation, analysis, transmission, AI-assisted extraction and deletion of data, to provide fuel station ERP, POS, inventory, accounting, CRM, analytics, messaging and support functions |
| Categories of data subjects | Customer's employees, station staff and managers; Customer's customers, credit parties and fleet drivers; suppliers and vendors; other individuals whose data Customer enters |
| Categories of personal data | Names, phone numbers, email addresses, addresses, employee IDs and roles, attendance and shift records, vehicle registration numbers, transaction, credit and payment records, tax identifiers, and images or documents submitted for AI-assisted entry |
| Special categories | None intended. Customer must not submit special category or sensitive personal data unless agreed in writing |
| Frequency | Continuous, for the duration of the Agreement |
4. Customer responsibilities
- Customer's instructions to Brook Code must comply with Applicable Data Protection Law.
- Customer is responsible for having a lawful basis for processing, for providing privacy notices to data subjects, and for obtaining any consents required, including consents and notices required of a Data Fiduciary under the DPDP Act.
- Customer is responsible for the accuracy, quality and legality of Customer Personal Data and how it was obtained.
- Customer must not submit special category data, children's data or other sensitive data unless agreed in writing.
- Customer is responsible for securing its own accounts, devices and credentials, configuring user permissions, and using the security features the Services provide.
- Customer is responsible for responding to data subject requests, with Brook Code's assistance as set out below.
5. Brook Code responsibilities
Brook Code will:
- Process Customer Personal Data only on Customer's documented instructions, which are given by the Agreement, this DPA and Customer's use and configuration of the Services, unless required to do otherwise by law. In that case Brook Code will inform Customer before processing, unless the law prohibits it.
- Inform Customer promptly if, in its opinion, an instruction infringes Applicable Data Protection Law.
- Ensure that personnel authorised to process Customer Personal Data are bound by confidentiality obligations.
- Implement the technical and organisational measures described in this DPA.
- Taking into account the nature of the processing, assist Customer with data subject requests, data protection impact assessments, prior consultations with supervisory authorities, and breach notifications.
- Maintain records of processing activities as required by Applicable Data Protection Law.
- For CCPA purposes, not sell or share Customer Personal Data; not retain, use or disclose it outside the direct business relationship or for any purpose other than providing the Services; and not combine it with personal information from other sources except as permitted by the CCPA.
6. Security measures
Brook Code implements and maintains appropriate technical and organisational measures to protect Customer Personal Data, as required by Article 32 of the GDPR and the DPDP Act, including:
- Encryption: TLS 1.2 or higher for data in transit; encryption of backups and sensitive data at rest.
- Access control: role-based access, least privilege, unique accounts, multi-factor authentication for administrative access, and prompt removal of access for departing personnel.
- Tenant isolation: logical separation of each customer's data within the Services.
- Network security: firewalls, restricted administrative ports, web application firewall and DDoS protection.
- Monitoring: logging of access and security events, alerting and regular review.
- Vulnerability management: timely patching of operating systems and dependencies, and secure development practices including code review.
- Resilience: daily encrypted backups retained for 30 days, stored separately from primary systems, with a disaster recovery plan targeting a recovery point objective of 24 hours and a recovery time objective of 12 hours.
- Personnel: confidentiality agreements and security awareness training.
- Vendors: due diligence and written data protection terms with Sub-processors.
- Physical security: provided by our hosting providers' certified data centres.
Brook Code may update these measures from time to time, provided the overall level of protection is not reduced.
7. Sub-processors
- Customer gives Brook Code general authorisation to engage Sub-processors. The current Sub-processors are listed below.
- Brook Code will give at least 30 days' notice before adding or replacing a Sub-processor, by updating this page and notifying account administrators by email.
- Customer may object on reasonable data protection grounds within that notice period. The parties will discuss the objection in good faith. If it cannot be resolved, Customer may terminate the affected Services and receive a refund of prepaid fees for the unused period.
- Brook Code will impose data protection obligations on each Sub-processor that are no less protective than this DPA, and remains responsible to Customer for its Sub-processors' performance.
| Sub-processor | Purpose | Location |
|---|---|---|
| Hostinger International Ltd. | Cloud servers, storage and backups | Data centre region used for your deployment |
| Cloudflare, Inc. | DNS, content delivery, web application firewall, bot and DDoS protection | Global edge network |
| Google LLC | Firebase (push notifications, authentication support, crash and performance reporting) and AI model APIs used for AI-assisted entry | United States and global |
| WhatsApp LLC / Meta Platforms Ireland Ltd. | WhatsApp Business Platform messaging and notifications | United States, European Union and global |
| Telegram Messenger Inc. | Telegram bot notifications and data entry features | Global |
| Razorpay Software Private Limited | Payment processing for customers in India (billing contact data only) | India |
| Stripe, Inc. / Stripe Payments Europe, Ltd. | Payment processing for international customers (billing contact data only) | United States and European Union |
| Email service provider | Delivery of account, notification and support emails | Details available on request |
8. International data transfers
- Customer Personal Data may be processed in India and in the countries where Brook Code and its Sub-processors operate.
- Where Customer Personal Data subject to the GDPR is transferred to a country without an adequacy decision, the parties agree that the SCCs are incorporated into this DPA by reference: Module 2 (controller to processor) where Customer is a controller, and Module 3 (processor to processor) where Customer is a processor. For the SCCs: the optional docking clause (Clause 7) applies; Option 2 of Clause 9(a) applies with the notice period set out in this DPA; the optional wording in Clause 11 does not apply; Clause 17 and Clause 18 refer to the law and courts of Ireland; and the Annexes are completed by the information in this DPA.
- For transfers subject to the UK GDPR, the UK Addendum applies and is incorporated by reference. For transfers subject to Swiss law, the SCCs apply with the necessary adaptations, and references to the GDPR are read as references to the Swiss Federal Act on Data Protection.
- For personal data subject to the DPDP Act, transfers outside India are made only as permitted by the Act and not to any country or territory restricted by the Government of India.
- If a public authority requests access to Customer Personal Data, Brook Code will challenge requests that are unlawful, disclose only the minimum required, and notify Customer unless legally prohibited.
9. Security incident and breach notification
Brook Code will notify Customer without undue delay, and in any event within 48 hours, after becoming aware of a Security Incident affecting Customer Personal Data. The notice will be sent to Customer's account administrator and will include, as far as known at the time:
- The nature of the Security Incident, including the categories and approximate number of data subjects and records concerned.
- The likely consequences of the Security Incident.
- The measures taken or proposed to address it and mitigate its effects.
- A contact point for more information.
Brook Code will take reasonable steps to contain and remediate the Security Incident, provide updates as more information becomes available, and give Customer the assistance reasonably required to meet its own obligations to notify supervisory authorities, the Data Protection Board of India and affected data subjects. Notification of a Security Incident is not an admission of fault or liability.
10. Data subject requests
If Brook Code receives a request from a data subject relating to Customer Personal Data, it will promptly forward the request to Customer and will not respond directly, except to confirm that the request relates to Customer or as required by law. The Services provide tools that allow Customer to access, correct, export and delete Customer Personal Data. Where Customer cannot fulfil a request using those tools, Brook Code will provide reasonable assistance.
11. Audits
Brook Code will make available to Customer the information reasonably necessary to demonstrate compliance with this DPA, including responses to reasonable security questionnaires. If that information is not sufficient to meet Customer's obligations, Customer may, no more than once in any twelve-month period and with at least thirty (30) days' written notice, conduct an audit itself or through an independent auditor bound by confidentiality. Audits must take place during normal business hours, must not unreasonably disrupt operations or compromise the security of other customers' data, and are at Customer's cost. Additional audits may be carried out where required by a supervisory authority or following a Security Incident.
12. Return and deletion of data
On termination or expiry of the Agreement, Customer may export Customer Personal Data using the export tools in the Services for 30 days. After that period, Brook Code will delete Customer Personal Data from its live systems within a further thirty (30) days. Backups are overwritten in the normal backup cycle within 30 days. Brook Code may retain data where required by law, in which case it will continue to protect it under this DPA and use it only for the purpose required.
Data deletion request process
Customer may ask for deletion of specific data or the whole account at any time during the term:
- The account administrator sends a request to [email protected] from the email address registered on the account, stating the business name, account ID and the data to be deleted.
- Brook Code verifies the requester's identity and authority, and confirms the scope of the request in writing.
- Brook Code recommends that Customer exports any data it needs to keep, since deletion cannot be reversed.
- Brook Code deletes the data from live systems within thirty (30) days after confirmation.
- Brook Code confirms completion in writing and, on request, provides a certificate of deletion. Backup copies expire within the backup retention period.
13. Liability
Each party's liability arising out of or related to this DPA is subject to the limitations and exclusions of liability in the Agreement, except where Applicable Data Protection Law or the SCCs do not permit such limitation.
14. Term and order of precedence
This DPA remains in effect for as long as Brook Code processes Customer Personal Data. If there is a conflict between this DPA and the Agreement, this DPA prevails on matters of data protection. If there is a conflict between this DPA and the SCCs or UK Addendum, the SCCs or UK Addendum prevail.
15. Contact
Questions about this DPA or requests for a countersigned copy can be sent to:
Brook Code Technologies
- Privacy and data protection: [email protected]
- Customer support: [email protected]
- Website: brookcode.com