Brimlo

Brimlo · autonomo.space

Data Processing Agreement (DPA)

Article 28 GDPR terms for personal data Brimlo processes on behalf of professional users.

Last updated: 6 September 2026

1. Parties and scope

This DPA forms part of the Brimlo Terms. The professional user is the controller (or a processor acting under another controller's authority) for personal data the user enters or imports about customers, suppliers and other third parties. The Brimlo operator identified in the Legal Notice acts as processor for that customer data. This DPA applies for as long as Brimlo processes that data on the user's behalf.

2. Subject matter, nature and purpose

Processing consists of receiving, hosting, organizing, backing up, displaying, calculating from, exporting, transmitting to user-authorized integrations and otherwise processing customer data to provide Brimlo's invoicing, expense, accounting, document, tax-workflow, support, automation and AI features requested by the user.

3. Data and data subjects

Data may include names, business/contact details, addresses, tax/VAT identifiers, invoice and transaction information, payment references, countries, communications and supporting documents. Data subjects may include the user's customers, suppliers, contractors, professional contacts and other persons whose data is lawfully included in the user's business records. Users must avoid entering data that is unnecessary for their professional purpose.

4. Documented instructions

Brimlo processes customer data only on documented instructions from the user, including the Terms, configured product actions and user-selected integrations, unless Union or Member-State law requires processing. Where legally permitted, Brimlo will inform the user before processing required solely by law. Brimlo will notify the user if an instruction appears to infringe applicable data-protection law.

5. Confidentiality and security

Persons authorized by Brimlo to process customer data are bound by confidentiality. Brimlo applies technical and organizational measures appropriate to the risk, including access control, transport encryption, least privilege, logging and resilience/backup measures appropriate to the service.

6. Subprocessors

The user gives general authorization for Brimlo to engage subprocessors necessary to provide hosting, database/storage/authentication, email/support, AI and user-selected integration functions. Brimlo remains responsible for imposing data-protection obligations on subprocessors that are no less protective than the relevant Article 28 duties. Material additions or replacements will be notified through the service, legal page or account communication with a reasonable opportunity to object where GDPR requires it.

7. International transfers

Brimlo will ensure that transfers of customer data outside the EEA use a lawful Chapter V GDPR mechanism where required, such as an adequacy decision or European Commission Standard Contractual Clauses, together with supplementary measures where appropriate.

8. Assistance

Taking into account the nature of processing and information available, Brimlo will reasonably assist the user with data-subject requests, security obligations, breach notifications, data-protection impact assessments and consultations with supervisory authorities where the user's processing requires them.

9. Personal-data breaches

Brimlo will notify the user without undue delay after becoming aware of a personal-data breach affecting customer data processed on the user's behalf and will provide information reasonably available to help the user meet its own GDPR obligations.

10. Return and deletion

At the end of the service, the user may export available customer data using product functionality where offered. On account deletion/termination Brimlo will delete or anonymize customer data and allow backups to expire under the normal backup cycle, unless Union or Member-State law requires retention.

11. Demonstrating compliance and audits

Brimlo will make information reasonably necessary to demonstrate compliance with Article 28 available to the user. Audits should first use available documentation and remote evidence. On-site or additional audits may be arranged where legally required, subject to reasonable confidentiality, security, timing and cost safeguards and without exposing other customers' data.

12. Controller obligations

The user is responsible for the lawfulness, accuracy and minimization of customer data; providing required notices; handling data-subject rights as controller; configuring access; and ensuring that instructions to Brimlo comply with GDPR and other applicable law.