Brucely
Legal

Data Processing Agreement.

Versão 2026-10-01 · Brucely (demo entity), [Registered address] ([Tax ID])

Este documento está disponível em inglês. Em caso de dúvida, contacte-nos.

This Data Processing Agreement ("DPA") forms part of the Terms of Service between the Customer (controller) and Brucely (demo entity) (processor) and applies to personal data processed in the Service on the Customer's behalf, in accordance with Article 28 GDPR.

1. Subject matter and duration

Processing personal data of the Customer's instructors, staff and partner-company personnel to provide scheduling, session logging, payroll calculation, notifications and reporting, for the term of the Customer's subscription and until deletion under section 9.

2. Categories

Data subjects: the Customer's users, instructors and staff. Personal data: identification and contact details, work schedules and attendance, pay rates and payment amounts, tax status and tax IDs, audit metadata (who changed what, when, from which IP). No special categories of data are intended to be processed.

3. Instructions

We process personal data only on the Customer's documented instructions, which are these Terms and the Customer's use and configuration of the Service, unless law requires otherwise, in which case we inform the Customer unless prohibited.

4. Confidentiality and security

Personnel with access are bound by confidentiality. We apply appropriate technical and organisational measures (Art. 32), including: a separate database per customer organisation, encryption in transit, hashed passwords, per-request authorisation, an audit trail of changes, access restricted to authorised staff, and backups.

5. Sub-processors

The Customer authorises the sub-processors listed in the Privacy Policy. We will give notice of new sub-processors, and the Customer may object on reasonable grounds. We impose equivalent data protection obligations on sub-processors and remain liable for them.

6. Data subject requests

The Service gives administrators tools to export a person's data and to anonymise a person on request (Privacy page). We help with other requests where reasonably needed.

7. Personal data breaches

We notify the Customer without undue delay, and where feasible within 48 hours, after becoming aware of a personal data breach affecting Customer Data, with the information the Customer needs to meet its obligations.

8. Assistance and audits

We assist with data protection impact assessments and consultations where required, and make available the information needed to demonstrate compliance. On-site audits are allowed once a year with 30 days' notice, at the Customer's cost, subject to confidentiality.

9. Return and deletion

The Customer can export all its data at any time. On closure of the organisation we delete Customer Data within 30 days, except where law requires retention.

10. International transfers

Transfers outside the EEA are made only with adequate safeguards (adequacy decision or Standard Contractual Clauses).

Dúvidas sobre este documento? angryventures@gmail.com