Article 1 — Parties and acceptance
This Data Processing Agreement ("DPA") is published by Bramm B.V. (i.o.) — Rotterdam, the Netherlands. Email privacy@bramm.it · Website bramm.it.
This DPA is automatically incorporated into and forms an integral part of the Terms of Service. By accepting the Terms — whether by clicking "I agree", completing a sign-up, or activating a subscription — the Customer (the "Controller") also accepts this DPA in full. No separate signature is required.
The most current version of this DPA is always available at bramm.it/dpa. Bramm will notify the Controller of any material changes at least 30 days in advance via email. Continued use of the Services after the effective date of a change constitutes acceptance of the updated DPA.
Enterprise customers who wish to negotiate custom DPA terms may contact info@bramm.it. In the event of any conflict between this DPA and the Terms of Service, this DPA shall prevail with respect to the processing of personal data.
Article 2 — Definitions
- "Personal Data" — any information relating to an identified or identifiable natural person, as defined in Article 4(1) GDPR.
- "Processing" — any operation performed on personal data, as defined in Article 4(2) GDPR.
- "Data Subject" — the natural person to whom the personal data relates.
- "Sub-processor" — any third party engaged by Bramm to process personal data on behalf of the Controller.
- "Privacy Shield" — the technical pseudonymisation layer built into the Bramm platform that replaces identifiable data with stable tokens before any AI model call is made.
- "Services" — the Bramm SaaS platform as described in the Terms of Service.
- "Security Incident" — any breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data.
Article 3 — Subject matter, nature and purpose of processing
3.1 — The Processor processes personal data on behalf of the Controller solely for the purpose of providing the Services as described in the Terms of Service and in Annex 1 of this DPA.
3.2 — The Processor shall process personal data only on documented instructions from the Controller, unless required to do so by applicable EU or Member State law. The Processor shall inform the Controller if, in its opinion, an instruction infringes applicable data protection law.
3.3 — The details of the processing — including the categories of data subjects, categories of personal data, and processing purposes — are set out in Annex 1.
Article 4 — Obligations of the Processor
4.1 — Processing on instructions only. The Processor shall process personal data only on documented instructions from the Controller. This DPA and the Terms of Service constitute the Controller's documented instructions. Any additional instructions shall be agreed in writing.
4.2 — Confidentiality. The Processor shall ensure that all personnel authorised to process personal data are subject to a binding duty of confidentiality, whether contractual or statutory. Access to personal data is limited to personnel who need it to perform the Services.
4.3 — Security measures. The Processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as required by Article 32 GDPR. The measures currently in place are set out in Annex 2. These include at minimum:
- Encryption of personal data in transit and at rest.
- Pseudonymisation of personal data via the Bramm Privacy Shield before any AI model call.
- Ongoing confidentiality, integrity, availability and resilience of processing systems.
- The ability to restore availability and access to personal data in a timely manner in the event of a physical or technical incident.
- A process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures.
- Access control and authentication mechanisms.
- Audit logging of access and processing activities.
4.4 — Sub-processors.
4.4.1 — The Controller grants the Processor general written authorisation to engage sub-processors. The current list is set out in Annex 3 and is also available at bramm.it/sub-processors.
4.4.2 — The Processor shall notify the Controller of any intended changes to the sub-processor list — additions or replacements — at least 30 days in advance. The Controller may object on reasonable data protection grounds within 14 days of notification. If the Processor cannot accommodate the objection, the Controller may terminate the Agreement.
4.4.3 — The Processor shall impose the same data protection obligations on each sub-processor as are set out in this DPA. The Processor remains fully liable to the Controller for the performance of each sub-processor's obligations.
4.5 — Assistance with Data Subject rights. The Processor shall assist the Controller, by appropriate technical and organisational measures, in fulfilling the Controller's obligation to respond to requests from Data Subjects exercising their rights under Chapter III GDPR (access, rectification, erasure, restriction, portability, objection). Given the nature of the processing, the Processor shall respond to such requests forwarded by the Controller within 5 business days.
4.6 — Assistance with compliance obligations. The Processor shall assist the Controller in ensuring compliance with Articles 32–36 GDPR, taking into account the nature of processing and the information available to the Processor, in particular with respect to:
- Security of processing (Article 32 GDPR).
- Notification of Security Incidents to the supervisory authority (Article 33 GDPR).
- Communication of Security Incidents to Data Subjects (Article 34 GDPR).
- Data Protection Impact Assessments (Article 35 GDPR).
- Prior consultation with the supervisory authority (Article 36 GDPR).
4.7 — Security Incident notification. The Processor shall notify the Controller without undue delay, and in any event within 48 hours, after becoming aware of a Security Incident affecting personal data processed on behalf of the Controller. The notification shall include, to the extent available:
- A description of the nature of the incident, including the categories and approximate number of Data Subjects and records concerned.
- The name and contact details of the Data Protection Officer or other contact point.
- A description of the likely consequences.
- A description of the measures taken or proposed to address the incident.
The Processor shall cooperate with the Controller and take reasonable commercial steps to assist in the investigation, mitigation and remediation of each Security Incident.
4.8 — Deletion or return of data. Upon termination of the Services, the Processor shall, at the Controller's choice, delete or return all personal data, and delete existing copies, unless applicable law requires storage. The Controller has 30 days following termination to export their data. After this period, data will be securely deleted. The Processor shall confirm deletion in writing upon request.
4.9 — Audit rights. The Processor shall make available to the Controller all information necessary to demonstrate compliance with this DPA. Audit requests shall be fulfilled remotely and by documentation. Bramm does not currently operate a physical office and does not accept on-site audits.
In practice, the Controller may exercise its audit rights by: (i) requesting a written compliance summary from Bramm; (ii) reviewing any available third-party audit reports, security certifications or penetration test summaries that Bramm makes available; (iii) submitting specific written questions to privacy@bramm.it, which Bramm will answer within 15 business days. Audits are limited to once per calendar year unless required by a supervisory authority.
Article 5 — Obligations of the Controller
The Controller warrants that:
- It has a valid legal basis for processing personal data and for instructing the Processor to process it on its behalf.
- The personal data it provides to the Processor is accurate and kept up to date.
- It has provided all necessary information to Data Subjects about the processing, including the involvement of Bramm as a processor.
- It will notify the Processor promptly of any changes to the applicable law that may affect the processing.
- It will use the Services in accordance with the Terms of Service and this DPA.
Article 6 — International data transfers
6.1 — The Processor shall not transfer personal data to countries outside the European Economic Area (EEA) unless: the destination country benefits from an adequacy decision by the European Commission pursuant to Article 45 GDPR; appropriate safeguards are in place pursuant to Article 46 GDPR, including Standard Contractual Clauses (SCCs); or a derogation pursuant to Article 49 GDPR applies.
6.2 — The Processor's primary infrastructure is EU-hosted. Where sub-processors are located outside the EEA (for example, certain AI model providers), the Processor ensures that appropriate transfer mechanisms are in place and that personal data is pseudonymised via the Privacy Shield before transfer, so that no identifiable personal data leaves the EEA.
6.3 — A current overview of international transfers and the applicable transfer mechanisms is included in Annex 3.
Article 7 — The Bramm Privacy Shield
7.1 — Bramm has implemented a proprietary Privacy Shield as a technical pseudonymisation layer. Before any question, instruction, or context data leaves the Bramm platform to reach an AI model, the Privacy Shield:
- Replaces all known identifiers (employee names, supplier names, system names, departments, ticket numbers, email addresses) with stable, session-specific tokens (e.g. PERSON_001, SUPPLIER_007).
- Applies the same pseudonymisation to all retrieved context, including policy text, ticket history, and supplier notes.
- Strips free-text PII patterns via regex, including BSN, IBAN, phone numbers, email addresses, postcodes, IPv4 addresses, and credit card numbers.
7.2 — The AI model receives only tokenised data. Bramm re-hydrates the answer with real identifiers before displaying it to the User. The token mapping never leaves the Controller's environment.
7.3 — Every AI interaction is logged in the Bramm audit log, including what was redacted and which Privacy Shield layers were applied. The Controller can inspect the exact redacted prompt sent to the AI model for any interaction.
7.4 — The Privacy Shield reduces but does not eliminate the risk of personal data transfer to AI model providers. The Controller acknowledges this and remains responsible for its own GDPR compliance obligations as data controller.
Article 8 — Liability
Each Party shall be liable for the damage caused by processing that infringes the GDPR. The Processor shall be exempt from liability if it can prove that it is not in any way responsible for the event giving rise to the damage. The liability of the Processor under this DPA is subject to the limitations set out in the Terms of Service. The Processor's total liability under this DPA shall not exceed the amount paid by the Controller in the twelve months preceding the event giving rise to the liability.
Article 9 — Duration and termination
This DPA is effective from the date the Controller first accesses the Services and remains in force for as long as the Processor processes personal data on behalf of the Controller. This DPA terminates automatically upon termination of the Terms of Service, subject to the data deletion obligations in Article 4.8.
Article 10 — Governing law
This DPA is governed by Dutch law. Any disputes arising from this DPA shall be submitted to the competent court in the district of Rotterdam, unless the Parties agree otherwise in writing.
Annex 1 — Details of processing
Subject matter. The provision of the Bramm AI security and compliance platform, including policy management, workflow automation, authorization matrix management, supplier management, security agenda, incident logging, and AI-powered question answering based on the Controller's own data.
Duration of processing. For the duration of the Agreement between the Parties, plus 30 days for data export after termination.
Nature of processing. Collection, storage, retrieval, pseudonymisation, transmission (to AI models via the Privacy Shield), display, and deletion of personal data.
Purpose of processing. To provide the Services as described in the Terms of Service, including:
- Enabling employees to query company policies, procedures and access rights.
- Automating compliance workflows (onboarding, offboarding, access requests, supplier management, policy changes).
- Maintaining an authorization matrix of employee access rights.
- Managing supplier and third-party risk.
- Supporting the ISO or security responsible person in managing the ISMS.
Categories of data subjects.
- Employees and contractors of the Controller.
- Managers and administrators of the Controller.
- Contact persons at suppliers and third parties of the Controller.
Categories of personal data.
- Identity data: full name, job title, department, email address.
- Access data: which systems and tools an employee has access to, and at what level.
- Workflow data: information submitted in workflows (onboarding forms, access requests, supplier data).
- Communication data: comments and messages within tickets.
- Supplier contact data: names and contact details of supplier representatives.
- Usage data: questions asked to Bramm, timestamps, interactions.
Special categories of personal data. The Processor does not intentionally process special categories of personal data as defined in Article 9 GDPR. The Controller is responsible for ensuring that no special category data is entered into the platform unless specifically agreed in writing.
Annex 2 — Technical and organisational security measures
Access control.
- Role-based access control (RBAC) with four permission levels: User, Manager, ISO, Admin.
- Multi-factor authentication available for all accounts.
- Session management with automatic timeout.
- Audit logging of all access and actions.
Encryption.
- All data encrypted in transit using TLS 1.2 or higher.
- All data encrypted at rest using AES-256.
- Pseudonymisation via the Bramm Privacy Shield before any AI model call.
Infrastructure security.
- Hosted on EU-based infrastructure.
- Regular security patching and updates.
- Vulnerability scanning and penetration testing.
- Backup and disaster recovery procedures.
Organisational measures.
- Confidentiality obligations for all personnel with access to personal data.
- Data protection training for relevant staff.
- Incident response procedures.
- Regular review of security measures.
AI model security.
- All AI model calls processed via the Bramm Privacy Shield.
- No personal data used for AI model training.
- Audit log of all AI interactions including redaction details.
- EU-hosted AI model options available (Mistral Large).
Annex 3 — Approved sub-processors
The current and up-to-date list is available at bramm.it/sub-processors.
Acceptance
This DPA does not require a separate signature. Acceptance occurs automatically when the Customer accepts the Bramm Terms of Service. The version of the DPA in force at the time of acceptance applies. Bramm keeps a record of which version was in force at each point in time at bramm.it/dpa/changelog.
© 2026 Bramm B.V. (i.o.) · Rotterdam, the Netherlands
Read the Terms of Service