Back to home

Data Processing Addendum

Last updated: September 30, 2026

Using This DPA

This Data Processing Addendum (“DPA”) has two parts:

  1. the Key Terms on this Cover Page; and
  2. the Common Paper DPA Standard Terms Version 1.1 posted at https://commonpaper.com/standards/data-processing-agreement/1.1/ (“DPA Standard Terms”), which are incorporated by reference.

If the parts of the DPA are inconsistent, this Cover Page controls over the DPA Standard Terms. Capitalized words have the meanings given on this Cover Page, in the DPA Standard Terms or in the Agreement. In this DPA, “Provider” means Basebright Inc. and “Customer” means the customer that has accepted the Agreement.

Acceptance. This DPA forms part of the Agreement. Customer accepts it electronically by accepting the Agreement, and no signature is required. A countersigned copy is available on request from [email protected].

Key Terms

Agreement

This DPA supplements the Basebright Terms of Service available at https://basebright.ai/terms, and any Order that references them (together, the “Agreement”).

Scope

This DPA applies to Personal Data that Provider Processes on Customer’s behalf as part of the Service (“Customer Personal Data”), as described in Annex I(B).

It does not apply to Personal Data that Provider processes as a controller, such as the account, billing and support data of Customer’s Users. That data is covered by Provider’s Privacy Policy at https://basebright.ai/privacy.

Approved Subprocessors

SubprocessorCountry of locationAnticipated Processing task
DigitalOcean, LLCUSAHosting of Provider’s application servers, including Provider’s self-hosted logging and AI-assistant tracing tools
Supabase, Inc. (on Amazon Web Services)USADatabase hosting and storage
Cloudflare, Inc.Global networkNetwork delivery, encryption and DDoS protection for traffic to the Service, including data sent by the Tracking Code
OpenAI, L.L.C.USAProcessing prompts, AI Responses and web page content: analysis runs, extraction of brand mentions and cited sources, classification of sources
Anthropic, PBCUSAAnalysis runs, web page summaries, content suggestions and the in-product AI assistant
Google LLCUSAAnalysis runs (Gemini API)
Perplexity AI, Inc.USAAnalysis runs
X.AI LLC (xAI)USAAnalysis runs (Grok API)
Exa Labs Inc.USAWeb search and retrieval of web page content for content features and the AI assistant
DataForSEO OÜEstonia (servers in Germany and the USA)Search, keyword and website traffic data for domains and pages (normally no Personal Data)

Provider Security Contact

[email protected]

Security Policy

Provider will use commercially reasonable efforts to secure the Service from unauthorized access, alteration, or use and other unlawful tampering, including through the measures described in Annex II.

Provider does not currently hold third-party security certifications or audit reports. Section 5.2 (Security Reports) of the DPA Standard Terms therefore does not apply. Customer exercises its audit rights under Sections 5.1 and 5.3 of the DPA Standard Terms.

Service Provider Relationship

To the extent California Consumer Privacy Act, Cal. Civ. Code § 1798.100 et seq (“CCPA”) applies, the parties acknowledge and agree that Provider is a service provider and is receiving Personal Data from Customer to provide the Service as agreed in the Agreement and detailed below (see Nature and Purpose of Processing), which constitutes a limited and specified business purpose. Provider will not sell or share any Personal Data provided by Customer under the Agreement. In addition, Provider will not retain, use, or disclose any Personal Data provided by Customer under the Agreement except as necessary for providing the Service for Customer, as stated in the Agreement, or as permitted by Applicable Data Protection Laws. Provider certifies that it understands the restrictions of this paragraph and will comply with all Applicable Data Protection Laws. Provider will notify Customer if it can no longer meet its obligations under the CCPA.

Restricted Transfers

Governing Member State — EEA Transfers: Ireland.

UK Transfers are not selected.

Annex I(A): List of Parties

Data Exporter

  • Name: Customer, as identified in its account in the Service or in the Order.
  • Address: Customer’s address as provided in its account, invoices or Order.
  • Contact person: the owner(s) of Customer’s Organization in the Service.
  • Activities relevant to the transfer: see Annex I(B).
  • Role: Controller. Where Customer uses the Service on behalf of its own clients (for example, as an agency), Customer is a Processor.

Data Importer

  • Name: Basebright Inc.
  • Address: 2810 N Church St, Wilmington, Delaware 19802, USA.
  • Contact person: privacy and security contact, [email protected].
  • Activities relevant to the transfer: see Annex I(B).
  • Role: Processor. Where Customer is a Processor, Provider is a Subprocessor.

Annex I(B): Description of Transfer and Processing Activities

Service

The Basebright AI visibility analytics platform at app.basebright.ai, including the Tracking Code, as described in the Agreement.

Categories of Data Subjects

  • Visitors to Customer’s websites on which Customer installs the Tracking Code.
  • Individuals whose Personal Data is contained in content that Customer or its Users submit to the Service, such as prompts, brand and competitor information, and conversations with the in-product AI assistant.
  • Individuals whose Personal Data is contained in AI Responses and web pages that the Service collects for Customer, such as founders, experts or other people named in them.

Categories of Personal Data

For website visitors:

  • IP address. It is used only to derive a pseudonymous daily visitor identifier and is not stored.
  • User agent.
  • Requested page path and URL parameters.
  • Referring page.
  • Time of the visit.
  • The pseudonymous daily visitor identifier and the visitor classification (for example, the name of an AI crawler).

For other data subjects: names, professional or biographic information, and any other Personal Data contained in the content described above.

Special Category Data

Is special category data Processed? No. Section 6(o) of the Terms of Service prohibits submitting it.

Frequency of Transfer

Continuous.

Nature and Purpose of Processing

Provider will Process Customer Personal Data as instructed in Section 2.3 of the DPA Standard Terms. The nature of processing includes:

  • Receiving data: collection through the Tracking Code, and retrieval of AI Responses and publicly available web pages.
  • Holding data: storage, organization and structuring.
  • Using data: analysis, classification of visitors and AI crawlers, aggregation into reports, and processing by AI providers to extract mentions, sources and summaries and to answer questions in the AI assistant.
  • Protecting data: pseudonymization, access restriction and encryption.
  • Sharing data with Approved Subprocessors, as needed to provide the Service.
  • Erasing data: deletion on Customer’s request and after the Agreement ends.

The purpose of the Processing is to provide the Service to Customer. That means measuring visits to Customer’s websites by AI crawlers and AI-referred visitors, and analyzing and reporting how brands appear in AI Responses.

Duration of Processing

Provider will process Customer Personal Data as long as required (i) to conduct the Processing activities instructed in Section 2.2(a)-(d) of the Standard Terms; or (ii) by Applicable Laws.

Customer Personal Data is kept while Customer’s Organization exists, unless Customer asks for earlier deletion. It is deleted within 30 days after Customer’s verified deletion request or the closure of the Organization (see Section 8.7 of the Terms of Service). Backups are overwritten within 7 days.

Annex I(C): Competent Supervisory Authority

The supervisory authority will be the supervisory authority of the data exporter, as determined in accordance with Clause 13 of the EEA SCCs.

Annex II: Technical and Organizational Security Measures

Pseudonymization and encryption of personal data.

  • Website visitors’ IP addresses are not stored. The Service combines the IP address and user agent with the date and keeps only a truncated SHA-256 hash as a pseudonymous daily identifier.
  • Data is encrypted in transit.
  • Data is encrypted at rest by the database provider.

Ensuring ongoing confidentiality, integrity, availability, and resilience of processing systems and services.

  • Access to Customer Personal Data is limited to authenticated Users of the relevant Organization and to Provider personnel who need it to operate the Service.
  • Services run as isolated containers with health checks and automatic restarts.
  • Traffic to the Service passes through Cloudflare, which provides DDoS protection.

Ability to restore the availability of and access to Customer Personal Data in a timely manner following a physical or technical incident.

  • The database provider backs up the database daily, and backups are kept for 7 days.
  • Application releases are tagged so that the previous version can be restored quickly.

Regular testing, assessment, and evaluation of the effectiveness of technical and organizational measures used to secure Processing.

  • Security-relevant code paths, including access control between Organizations, are covered by automated tests.
  • Provider reviews the security of the Service when it makes significant changes.

User identification and authorization process and protection.

  • Users sign in with one-time email links or with Google through Provider’s authentication provider. The Service does not ask for passwords.
  • Every request made to the Service’s API on behalf of a User carries a signed token that is verified.
  • On each request, the Service checks that the User belongs to the Organization whose data is being accessed.
  • Administrative access to production systems is limited to the personnel who operate the Service.

Protecting Customer Personal Data during transmission (in transit).

  • TLS is used between browsers and Cloudflare, and between Cloudflare and Provider’s servers (Cloudflare origin certificate).
  • Calls to Subprocessors’ APIs use HTTPS.

Protecting Customer Personal Data during storage (at rest). The database provider encrypts stored data, including backups.

Physical security where Customer Personal Data is processed. Provider operates no data centers of its own. Physical security is provided by DigitalOcean, Amazon Web Services (for the database provider) and Cloudflare under their own security programs.

Events logging.

  • Application and web server logs record requests and events for security and troubleshooting.
  • Web server logs do not record URL query strings.
  • Application logs mask email addresses and remove access tokens and credential-like parameters.
  • Logs are kept for up to 30 days.

Systems configuration, including default configuration.

  • Services are deployed as containers from version-controlled configuration.
  • Web traffic reaches the Service only through a reverse proxy, which accepts it only from Cloudflare. Application services are not exposed to the internet directly.

Internal IT and IT security governance and management.

  • Responsibility for security rests with Provider’s management.
  • Everyone with access to Customer Personal Data is bound by confidentiality obligations.

Ensuring data minimization.

  • Website visitors’ IP addresses are not stored.
  • Customer Personal Data is not used to train AI models, by Provider or, under their API terms, by the AI providers Provider uses.

Ensuring limited data retention.

  • Customer Personal Data is kept while Customer’s Organization exists. It is deleted on Customer’s request, or when the Organization is closed.
  • Backups are overwritten within 7 days.
  • Logs are kept for up to 30 days.

Ensuring accountability.

  • Provider maintains the list of Approved Subprocessors.
  • Provider keeps records of its compliance with this DPA for 3 years after the DPA ends (Section 5.1 of the DPA Standard Terms).

Allowing data portability and ensuring erasure.

  • Customer can export data as CSV files from the Service, and can request a full copy in a machine-readable format.
  • Conversations with the AI assistant can be deleted in the Service.
  • Customer can request deletion of any other Customer Personal Data at [email protected].

Annex III: List of Subprocessors

See “Approved Subprocessors” above. Provider will notify Customer of intended changes at least 10 business days in advance, by email to the owners of Customer’s Organization, as described in Section 2.6 of the DPA Standard Terms.

Changes to the DPA Standard Terms

Provider and Customer have not changed the DPA Standard Terms except for the details on this Cover Page.


The DPA Standard Terms are published by Common Paper. This Cover Page is based on the Common Paper DPA Cover Page, adapted for electronic acceptance and completed with Basebright’s details. Both are used under CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/).