Data Processing Addendum - Braintrust

Data Processing Addendum

This Data Processing Addendum ("DPA") supplements the Terms of Service (the "Agreement") entered into by and between Customer, as identified in the Agreement, ("Customer") and Braintrust Data, Inc. ("Company"), (together with Customer, the "Parties"). This DPA incorporates the terms of the Agreement. Company may update this DPA from time to time, and we will provide reasonable notice of any such updates. Any terms not defined in this DPA shall have the meaning set forth in the Agreement.

1. Definitions

  1. "Authorized Subprocessor" means a third-party entity engaged by Company to process Personal Data in order to provide the Services and that has been approved by Customer in accordance with Section 6.

  2. "Company Account Data" means personal data that relates to Company's relationship with Customer, including the names or contact information of individuals authorized by Customer to access Customer's account and billing information of individuals that Customer has associated with its account.

  3. "Company Usage Data" means the Usage Data, as defined in the Agreement.

  4. "Control Plane" means the authentication and authorization functions in the Service, which collect and manage end-user identity information such as the user's name, email as userid, and the IP address for the user's session. The Control Plane stores only account-level metadata and identity information required to operate the Service. It does not store Customer's AI evaluation data, prompts, model outputs, datasets, or traces generated by customer applications.

  5. "Data Plane" means the portion of the Service where Braintrust collects, manages, and supports the analysis of the customer's AI activity. The Data Plane stores Customer's AI evaluation data, prompts, model outputs, datasets, or traces generated by customer applications. It organizes AI telemetry data as structured events and relationships, allowing Braintrust to reconstruct the execution history of an AI system and compare outcomes across models.

  6. "Data Privacy Framework" means, as applicable, EU-U.S. Data Privacy Framework, the UK Extension to the EU-U.S. Data Privacy Framework, and/or the Swiss-U.S. Data Privacy Framework.

  7. "Data Subject" means a natural person whose Personal Data is protected by Privacy Laws. For the avoidance of doubt, "Data Subject" includes the term "Consumer" under Privacy Laws.

  8. "Data Subject Request" means a request from a Data Subject to exercise their rights over Personal Data afforded pursuant to Privacy Laws.

  9. "EU SCCs" means standard contractual clauses approved by the European Commission for transfers of personal data to countries not otherwise recognized as offering an adequate level of protection for personal data by the European Commission (as amended and updated from time to time).

  10. "ex-EEA Transfer" means the transfer of Personal Data subject to the GDPR from the European Economic Area (the "EEA"), to a country where the transfer is not governed by an adequacy decision made by the European Commission.

  11. "ex-UK Transfer" means the transfer of Personal Data subject to Chapter V of the UK GDPR from outside the United Kingdom (the "UK") where such transfer is not governed by an adequacy decision made by the Secretary of State.

  12. "Personal Data" means any information provided to Company by or on behalf of Customer in connection with the Services that relates to an identified or identifiable Data Subject and constitutes "personal data," "personal information," or equivalent term under Privacy Laws.

  13. "Privacy Laws" means any applicable laws and regulations in any relevant jurisdiction relating to the processing of Personal Data including the General Data Protection Regulation and U.S. state comprehensive privacy laws.

  14. "Standard Contractual Clauses" means, as applicable, the EU SCCs and the UK SCCs.

  15. "Topics" means the AI analysis feature that identifies patterns and themes within evaluation results.

  16. "UK Addendum" means the template International Data Transfer Addendum issued by the Information Commissioner.

  17. "UK SCCs" means the EU SCCs, as amended by the UK Addendum.

2. Role of the Parties; Description of Processing

  1. Customer is the Controller and Company is a Processor.

  2. Company shall process Personal Data only (i) for purposes set forth in the Agreement, (ii) consistent with Customer’s documented instructions, and (iii) as required by Privacy Laws.

3. Compliance with Privacy Laws

Customer shall process Personal Data in compliance with Privacy Laws and ensure processing will not cause Company to be in breach of such laws.

4. Use of Personal Data

Company shall not sell or share Personal Data and will only use it as necessary to perform the Services for Customer.

5. Audit

Company shall maintain records to demonstrate compliance. Upon Customer's written request, Company shall provide certifications or allow audits of its data security infrastructure.

6. Authorized Subprocessors

Customer acknowledges that Company may engage Authorized Subprocessors to process Personal Data in connection with the Services.

7. Confidentiality; Security of Personal Data

Company shall protect Personal Data in accordance with Company's confidentiality obligations.

8. Personal Data Breach

In the event of a Personal Data Breach, Company shall inform Customer without undue delay and assist Customer in meeting its obligations under Privacy Laws.

9. Transfers of Personal Data

The parties agree that Company may transfer Personal Data processed under this DPA outside the EEA, the UK, or Switzerland as necessary to provide the Services.

10. Data Protection Assessments

Company shall cooperate with Customer to conduct any required data protection or privacy impact assessments.

11. Data Subject Request

If Company receives a Data Subject Request, it shall notify Customer. Customer is responsible for responding to such requests.

12. Return or Destruction of Personal Data

Upon termination of the Agreement, Company shall return or delete Personal Data unless further storage is required by applicable law.

13. Company's Role as a Controller

Company is an independent controller with respect to Company Account Data and Company Usage Data.

14. Miscellaneous

In the event of any conflict among the DPA, the Agreement, and Company’s privacy policy, the order of precedence will apply.