International Data Processing Addendum
International Data Processing Addendum
This International Data Processing Addendum (“DPA”) forms a part of and is governed by the Agreement between BrainFreeze and Customer to the extent Customer is a legal entity and subject to the Agreement. If Customer is located outside of the United States, this DPA is incorporated into the Agreement by reference and describes the Parties’ obligations regarding the Processing of Personal Information. Customer enters into this DPA on behalf of Customer and, to the extent required under Applicable Data Protection Laws, in the name of and on behalf of Customer’s Authorized Affiliates, if and to the extent that BrainFreeze Processes Personal Information for such Authorized Affiliates that qualify as a Controller. BrainFreeze is acting as a Service Provider and Processor. All capitalized terms not defined shall have the meanings provided in the Agreement. In the event of a conflict between the terms of the Agreement and the DPA, this DPA shall prevail.
“Affiliates” means any legal entity controlling, controlled by or under common control with a party to this DPA, for so long as such Control relationship exists.
“Authorized Affiliates” means Customer’s Affiliates that, if agreed upon by BrainFreeze, are authorized to utilize the Services as Accounts pursuant to the Agreement.
“Applicable Data Protection Law(s)” means any applicable law, ordinance, statute, regulation, or other binding restriction to which the Personal Information is subject, including but not limited to CCPA, GDPR, UK GDPR, Data Protection Act 2018 and Non-EU Data Protection Laws, and all amendments thereof.
“Control” means the ownership of more than 50% of the applicable entity or the ability in fact to direct the management decisions of such entity.
“Customer Personal Information” means Personal Information belonging to Customer or Customer’s User accounts or Guests that is processed by BrainFreeze in the course of providing the BrainFreeze Services under the Agreement.
“Data Controller” means a natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of Personal Information.
“Data Subject” has the meaning assigned to the term “data subject” or “consumer” under Applicable Data Protection Laws and shall include identified or identifiable natural persons to whom the Personal Information relates.
“GDPR” means the EU General Data Protection Regulation 2016/679.
“Non-EU Data Protection Laws” means all other applicable data protection laws, including but not limited to Canada’s Personal Information Protection and Electronic Documents Act, S.C., 2000, ch. 5 (“PIPEDA”) and any provincial legislation deemed substantially similar to PIPEDA pursuant to the procedures set forth within PIPEDA, the Dubai International Financial Centre’s Data Protection Law No. 5 of 2020 (“DIFC DPL”), and Australia’s Privacy Act of 1988 (“Privacy Act of 1988”), and all amendments to PIPEDA , DIFC DPL, Privacy Act of 1988, and similar legislation, as they may be enacted, from time to time.
“Personal Information” means any data provided by Customer or Customer’s Authorized Affiliates to BrainFreeze that identifies or, alone or in combination with any other data, could reasonably be used to identify, locate, or contact a natural person or household, or any other information that is considered “personally identifiable information,” “personal information,” “personal data,” or other similar terms under Applicable Data Protection Laws, but does not include data or information that is publicly available within the meaning of such section or that has been de-identified within the meaning of Applicable Data Protection Laws.
“Process” or “Processing” means any operation or set of operations that are performed upon Personal Information, whether or not by automatic means, such as collection, accessing, processing, use, recording, organization, storage, adaptation or alteration, retrieval, consultation, use, disclosure, dissemination, transmittal, alignment or combination, blocking, erasure, destruction or otherwise used as set out in the Applicable Data Protection Laws.
“Security Incident” means any situation in which BrainFreeze confirms that Personal Information under its direct control has been accessed, acquired, disclosed, altered, lost, destroyed, or used by unauthorized persons in an unauthorized manner having a material impact on Customer or Customer’s Affiliates or on Data Subject rights.
“Sell,” “selling,” “sale,” or “sold” means selling, renting, releasing, disclosing, disseminating, making available, transferring, or otherwise communicating orally, in writing, or by electronic or other means, a Data Subject’s Personal Information to a third party for monetary or other valuable consideration.
“Share”, “sharing”, or “shared” means the provision of Personal Information to support targeted advertising across unaffiliated websites based on online behavioral profiling.
“Service Provider” means an entity that processes information on behalf of Customer and to which Customerdiscloses a Data Subject’s Personal Information for a business purpose pursuant to a written contract.
Categories of data subjects whose personal data is transferred
Data exporter may submit Personal Information into the BrainFreeze Service, the extent of which is determined and controlled solely by the data exporter, and which may include, but is not limited to Personal Information relating to the following categories of data subjects:
Data exporter’s employees, contractors, representatives, agents, and other individuals whom data exporter allows and is permitted to use the BrainFreeze Service, as well as Personal Information relating to the data exporter’s partners, Accounts, vendors, and other categories as otherwise contemplated by the Agreement.
Categories of personal data transferred
Data exporter may submit Personal Information to the BrainFreeze Services, the extent of which is determined and controlled solely by data exporter, and which may include, but is not limited to the following Personal Information:
First and last name, contact information such as address, telephone number, and email address, IP address, user identifier, and other categories as otherwise contemplated by the Agreement.
Sensitive data transferred (if applicable) and applied restrictions or safeguards that fully take into consideration the nature of the data and the risks involved, such as for instance strict purpose limitation, access restrictions (including access only for staff having followed specialised training), keeping a record of access to the data, restrictions for onward transfers or additional security measures.
Sensitive Personal Information is not contemplated in the Agreement.
The frequency of the transfer (e.g. whether the data is transferred on a one-off or continuous basis).
Continuous basis until termination or expiration of the Agreement.
Nature of the processing
The performance of the BrainFreeze Services pursuant to the Agreement.
Purpose(s) of the data transfer and further processing
The performance of the BrainFreeze Services pursuant to the Agreement.
The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period
For the duration of the Agreement until it is deleted in accordance with the Agreement.
For transfers to (sub-) processors, also specify subject matter, nature and duration of the processing
ANNEX II: Security Measures
TECHNICAL AND ORGANISATIONAL MEASURES TO ENSURE THE SECURITY OF THE DATA
Description of the technical and organisational measures implemented by the data importer(s) (including any relevant certifications) to ensure an appropriate level of security, taking into account the nature, scope, context and purpose of the processing, and the risks for the rights and freedoms of natural persons.
BrainFreeze’s information security program, as established through its internal controls and procedures, is designed to ensure: (i) Customer Data BrainFreeze processes is protected against accidental, unlawful, or unauthorized loss, access, or disclosure; (ii) reasonably foreseeable risks relating to security and unauthorized access are identified and protected against; and (iii) security risks are minimized by implementing, maintaining, and regularly assessing such controls.
Access Controls
BrainFreeze uses access control management: (i) governing the security of BrainFreeze’s information, networks, applications, and systems aimed to prevent unauthorized access to such items; and (ii) relating to BrainFreeze’s networks, applications, and systems to ensure only authorized users access appropriate information based on their role and to prevent unauthorized access to the same.
Encryption and Key Management
All encryptions for data and relating to key management shall be end-to-end and be performed in accordance with industry standards, including NIST SP 800-57. The below represents BrainFreeze’s encryption methods for at-rest and in-transit data.
Asset Management
BrainFreeze appropriately identifies and classifies its assets to ensure their security and integrity. Protection levels are established pursuant to the corresponding asset’s importance and exposure to sensitive information, and are designed to prohibit unauthorized disclosures, loss, damage, or destruction of information in relation to the asset.
Contingency Planning
BrainFreeze has ensured redundancy controls to eliminate single points of failure and minimize the impact of possible physical and environmental risks are instituted. It also may use Business Continuity and Disaster Recovery Plans to help ensure the BrainFreeze Service’s continuity.
Security Incident Response
BrainFreeze minimizes a security incident’s impact, including as it relates to the availability and confidentiality of the BrainFreeze Services through its security processes. These processes help BrainFreeze to efficiently respond, mitigate, handle, and communicate issues relating to a security incident.
Risk Management
Security Controls
Annex III: Sub-Processor Table
Name of Service Provider with Link to Privacy Policy or relevant privacy documentation |
How does BrainFreeze use the Service Provider? |
What user information is shared or collected by this Service Provider and/or passed back to us from the Service Provider? |
Entity location (country) and country of data storage |
Providing AI tools for teachers and parents as well as BrainFreeze’s internalonly tools. BrainFreeze integrates with Ai21’s large language models (“LLM”), to provide output to students’, parents’, and teachers’ questions. |
Users may provide inputs that include student information and even photos or videos. No direct identifiers are sent – only what’s included in the teacher’s, student’s, or parent’s input. |
Entity Location: United States
Data Storage Location: United States |
|
BrainFreeze integrates with Airia’s Platform to process and execute students’, parents’, and teachers’ questions. |
Users may provide inputs that include student information and even photos or videos. No direct identifiers are sent – only what’s included in the teacher’s, student’s, or parent’s input. |
Entity Location: United States
Data Storage Location: United States |
|
Providing AI tools for teachers and parents as well as BrainFreeze’s internalonly tools. BrainFreeze integrates with Alibaba’s large language models (“LLM”), to provide output to students’, parents’, and teachers’ questions. |
Users may provide inputs that include student information and even photos or videos. No direct identifiers are sent – only what’s included in the teacher’s, student’s, or parent’s input. |
Entity Location: United States
Data Storage Location: United States |
|
Providing AI tools for teachers and parents as well as BrainFreeze’s internalonly tools. BrainFreeze integrates with Amazon’s large language models (“LLM”), to provide output to students’, parents’, and teachers’ questions. |
Users may provide inputs that include student information and even photos or videos. No direct identifiers are sent – only what’s included in the teacher’s, student’s, or parent’s input. |
Entity Location: United States
Data Storage Location: United States |
|
Providing AI tools for teachers and parents as well as BrainFreeze’s internalonly tools. BrainFreeze integrates with Anthropic’s large language models (“LLM”), to provide output to students’, parents’, and teachers’ questions. |
Users may provide inputs that include student information and even photos or videos. No direct identifiers are sent – only what’s included in the teacher’s, student’s, or parent’s input. |
Entity Location: United States
Data Storage Location: United States |
|
Azure serves as BrainFreeze’s managed cloud platform where services are hosted. It provides virtual machine services for web hosting and backend operations, container orchestration through Azure Kubernetes, and transactional databases with backups and redundancy. Azure’s primary data center is located in US-East 2, with capabilities to operate in different locations based on customer requirements. |
Users may provide inputs that include student information and even photos or videos. No direct identifiers are sent – only what’s included in the teacher’s, student’s, or parent’s input. |
Entity Location: United States
Data Storage Location: United States |
|
Providing AI tools for teachers and parents as well as BrainFreeze’s internalonly tools. BrainFreeze integrates with Amazon’s large language models (“LLM”), to provide output to students’, parents’, and teachers’ questions. |
Users may provide inputs that include student information and even photos or videos. No direct identifiers are sent – only what’s included in the teacher’s, student’s, or parent’s input. |
Entity Location: United States
Data Storage Location: United States |
|
Providing AI tools for teachers and parents as well as BrainFreeze’s internalonly tools. BrainFreeze integrates with Compass’ large language models (“LLM”), to provide output to students’, parents’, and teachers’ questions. |
Users may provide inputs that include student information and even photos or videos. No direct identifiers are sent – only what’s included in the teacher’s, student’s, or parent’s input. |
Entity Location: United States
Data Storage Location: United States |
|
Providing AI tools for teachers and parents as well as BrainFreeze’s internalonly tools. BrainFreeze integrates with Google’s large language models (“LLM”), to provide output to students’, parents’, and teachers’ questions. |
Users may provide inputs that include student information and even photos or videos. No direct identifiers are sent – only what’s included in the teacher’s, student’s, or parent’s input. |
Entity Location: United States
Data Storage Location: United States |
|
Providing AI tools for teachers and parents as well as BrainFreeze’s internalonly tools. BrainFreeze integrates with Mistral’s large language models (“LLM”), to provide output to students’, parents’, and teachers’ questions. |
Users may provide inputs that include student information and even photos or videos. No direct identifiers are sent – only what’s included in the teacher’s, student’s, or parent’s input. |
Entity Location: United States
Data Storage Location: United States |
|
Providing AI tools for teachers and parents as well as BrainFreeze’s internalonly tools. BrainFreeze integrates with OpenAI’s large language models (“LLM”), to provide output to students’, parents’, and teachers’ questions. |
Users may provide inputs that include student information and even photos or videos. No direct identifiers are sent – only what’s included in the teacher’s, student’s, or parent’s input. |
Entity Location: United States
Data Storage Location: United States |
|
Providing AI tools for teachers and parents as well as BrainFreeze’s internalonly tools. BrainFreeze integrates with Perplexity’s large language models (“LLM”), to provide output to students’, parents’, and teachers’ questions. |
Users may provide inputs that include student information and even photos or videos. No direct identifiers are sent – only what’s included in the teacher’s, student’s, or parent’s input. |
Entity Location: United States
Data Storage Location: United States |
|
BrainFreeze utilizes Posthog for anonymous metric capture |
|
Entity Location: United States
Data Storage Location: United States |
|
Providing AI tools for teachers and parents as well as BrainFreeze’s internalonly tools. BrainFreeze integrates with Replicate’s large language models (“LLM”), to provide output to students’, parents’, and teachers’ questions. |
Users may provide inputs that include student information and even photos or videos. No direct identifiers are sent – only what’s included in the teacher’s, student’s, or parent’s input. |
Entity Location: United States
Data Storage Location: United States |
|
Sentry serves as Airia’s application monitoring and error tracking platform. |
|
Entity Location: United States
Data Storage Location: United States |
|
Providing AI tools for teachers and parents as well as BrainFreeze’s internalonly tools. BrainFreeze integrates with TogetherAI’s large language models (“LLM”), to provide output to students’, parents’, and teachers’ questions. |
Users may provide inputs that include student information and even photos or videos. No direct identifiers are sent – only what’s included in the teacher’s, student’s, or parent’s input. |
Entity Location: United States
Data Storage Location: United States |
|
Providing resources and content to the BrainFreeze platform to provide content to BrainFreeze users. |
Users may provide inputs that include student information. No direct identifiers are sent – only what’s included in the teacher’s, student’s, or parent’s input. |
Entity Location: United States
Data Storage Location: United States |
|
Providing AI tools for teachers and parents as well as BrainFreeze’s internalonly tools. BrainFreeze integrates with XAI’s large language models (“LLM”), to provide output to students’, parents’, and teachers’ questions. |
Users may provide inputs that include student information and even photos or videos. No direct identifiers are sent – only what’s included in the teacher’s, student’s, or parent’s input. |
Entity Location: United States
Data Storage Location: United States |