Data Processing Addendum

Effective Date: September 8, 2026

How this Addendum applies

This Data Processing Addendum ("DPA") forms part of the Terms of Service or other written agreement (the "Agreement") between the customer identified in the applicable workspace ("Customer") and Brightyard, Inc., a Delaware corporation ("Brightyard"). It applies whenever Brightyard processes Personal Data on Customer's behalf in the course of providing Coherence (the "Service").

This DPA is incorporated into the Agreement automatically. Customers that need a countersigned copy for their records can request one by emailing [email protected] with the workspace name and the legal name of the Customer entity.

1. Definitions

  • "Customer Data" means all data, including Personal Data, that Customer or its Users submit to the Service, including data imported from accounts Customer connects to the Service.
  • "Data Protection Laws" means all laws that apply to the processing of Personal Data under this DPA, including the EU General Data Protection Regulation 2016/679 ("GDPR"), the GDPR as incorporated into United Kingdom law ("UK GDPR"), the Swiss Federal Act on Data Protection, and the California Consumer Privacy Act as amended ("CCPA").
  • "Personal Data", "Controller", "Processor", "Data Subject", "Processing", and "Personal Data Breach" have the meanings given to them in the GDPR. "Sub-processor" means a Processor engaged by Brightyard to process Customer Data.
  • "Standard Contractual Clauses" or "SCCs" means the standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission in Decision (EU) 2021/914.
  • "UK Addendum" means the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018.
  • "Restricted Transfer" means a transfer of Personal Data from the European Economic Area, the United Kingdom, or Switzerland to a country that has not been found to provide adequate protection under the applicable Data Protection Laws.

2. Roles and scope

For Customer Data, Customer is the Controller (or, where Customer acts on behalf of its own clients, a Processor) and Brightyard is a Processor. Annex 1 describes the subject matter, duration, nature and purpose of the Processing, the types of Personal Data, and the categories of Data Subjects.

Brightyard acts as an independent Controller for the account, billing, and usage information it collects to operate the Service, as described in the Privacy Policy. That Processing is outside the scope of this DPA.

3. Customer instructions

Brightyard will process Customer Data only on Customer's documented instructions, which consist of the Agreement, this DPA, Customer's use and configuration of the Service (including its choice of AI provider and the accounts it connects), and any further written instructions agreed between the parties. The one exception is Processing that European Union or Member State law to which Brightyard is subject requires; in that case Brightyard will inform Customer of the legal requirement before the Processing, unless that law prohibits it from doing so on important grounds of public interest. Brightyard will immediately inform Customer if, in its opinion, an instruction infringes the GDPR or other Data Protection Laws.

Customer is responsible for the lawfulness of the Customer Data it provides, for having a valid legal basis and providing any required notices to Data Subjects, and for ensuring that its instructions comply with Data Protection Laws.

4. Confidentiality

Brightyard ensures that personnel authorised to process Customer Data are bound by written confidentiality obligations and access Customer Data only to the extent necessary to provide, support, and secure the Service.

5. Security

Brightyard implements and maintains the technical and organisational measures set out in Annex 2. Brightyard may update those measures from time to time provided the updates do not materially reduce the overall level of protection for Customer Data.

Taking into account the nature of the Processing and the information available to it, Brightyard will assist Customer in meeting Customer's own obligations under Articles 32 to 36 of the GDPR: the security of Processing (this Section and Annex 2), notification of Personal Data Breaches (Section 9), and data protection impact assessments and prior consultation (Section 10).

6. Sub-processors

Customer gives Brightyard general written authorisation to engage Sub-processors. The current list, including each Sub-processor's purpose and processing location, is published at getcoherence.io/subprocessors.

  • Brightyard will give Customer written notice at least 30 days before a new Sub-processor begins processing Customer Data, by email to the owner and administrator accounts of Customer's workspace, and will update the Sub-processors page at the same time. Customer may add further recipients as described on that page.
  • Customer may object to a new Sub-processor on reasonable data protection grounds by notifying Brightyard in writing within 30 days of the notice. The parties will work in good faith to resolve the objection. If no resolution is reached within a further 30 days, Customer may terminate the affected part of the Service and Brightyard will refund any prepaid fees for the unused portion of the term.
  • Brightyard will impose on each Sub-processor data protection obligations no less protective than those in this DPA and remains liable to Customer for the performance of each Sub-processor's obligations.

7. AI model providers

AI features send prompts and the workspace context relevant to a request to the AI model provider selected for the Customer's workspace. The default provider and the alternatives are identified on the Sub-processors page. Customer may change the provider at any time in workspace Settings, and that selection is a documented instruction under Section 3 that Brightyard applies to every AI feature of the Service, including content, site, and image generation. Brightyard's agreements with Anthropic and OpenAI prohibit those providers from using Customer Data to train their models. MiniMax (Nanonoble Pte. Ltd., Singapore) is used under its published terms, which permit it to use API inputs and outputs to provide, maintain, develop, and improve its services and to commercially use a de-identified database; Brightyard has no agreement with MiniMax beyond those terms. A Customer that does not accept them selects Anthropic or OpenAI, after which no Customer Data is sent to MiniMax. A Customer workspace established in the European Economic Area, the United Kingdom, or Switzerland never uses MiniMax under any setting: its default runs only on Anthropic and OpenAI, and MiniMax cannot be enabled for it.

8. Data Subject requests

Brightyard will promptly forward to Customer any request it receives from a Data Subject relating to Customer Data and will not respond except to direct the Data Subject to Customer, unless required by law. Taking into account the nature of the Processing, Brightyard will assist Customer in responding to Data Subject requests through the export, correction, and deletion features of the Service and, where those are insufficient, through reasonable additional assistance.

9. Personal Data Breach

Brightyard will notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Customer Data. The notification will describe, to the extent known, the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed to address it. Brightyard will provide further information as it becomes available and will cooperate reasonably with Customer's investigation and any notifications Customer is required to make.

10. Impact assessments and consultation

Taking into account the nature of the Processing and the information available to it, Brightyard will provide reasonable assistance to Customer with data protection impact assessments and prior consultations with supervisory authorities that relate to the Service.

11. Return and deletion

During the term, Customer can export Customer Data at any time using the Service. On termination or expiry of the Agreement, Customer chooses whether Brightyard returns Customer Data or deletes it. Return is by export from the Service, available for 30 days after termination; Customer may also request a return in another reasonable format within that period. After the 30 days, or earlier at Customer's written request, Brightyard will delete or anonymise all Customer Data and existing copies within 90 days, except to the extent that European Union or Member State law requires retention, in which case Brightyard will continue to protect the retained data under this DPA and process it only for that purpose. Copies held in backups are removed in the ordinary backup rotation cycle. Brightyard will confirm deletion in writing on request.

12. Audits and information

Brightyard will make available the information reasonably necessary to demonstrate compliance with this DPA. Brightyard will first respond to a written security questionnaire and provide relevant documentation, including summaries of independent security assessments where available. Where that is not sufficient to meet a requirement of Data Protection Laws, Customer may conduct, or have an independent auditor bound by confidentiality conduct, an audit of Brightyard's relevant controls no more than once in any 12-month period, on at least 30 days' written notice, during normal business hours, without unreasonable disruption, and at Customer's cost. Customer may audit more frequently following a Personal Data Breach or where required by a supervisory authority.

13. International transfers

The Service is hosted in the United States, and Customer Data is processed there and in the locations listed on the Sub-processors page. Where the Processing involves a Restricted Transfer from Customer to Brightyard, the parties agree as follows:

  • EEA transfers. The SCCs are incorporated into this DPA by reference and form part of the Agreement. Module Two (controller to processor) applies where Customer is a Controller, and Module Three (processor to processor) applies where Customer is a Processor. Clause 7 (docking) is not included. Under Clause 9, Option 2 (general written authorisation) applies with the notice period in Section 6. The optional language in Clause 11 is not included. Under Clause 13, the supervisory authority is that of the EU member state in which Customer is established or, if Customer is not established in the EU, in which its representative is established or the Data Subjects are located. Under Clause 17, Option 1 applies and the SCCs are governed by the laws of Ireland. Under Clause 18, disputes are resolved by the courts of Ireland.
  • Completion of the SCC annexes. Annex I.A (list of parties) is completed as follows: the data exporter is Customer, whose legal name, address, and contact person are those recorded for Customer's workspace and billing account in the Service, acting as a Controller (Module Two) or Processor (Module Three); the data importer is Brightyard, Inc., a Delaware corporation, at its registered office in the State of Delaware, United States (full address supplied with the countersigned copy of this DPA and on request), contact [email protected], acting as a Processor. Each party's activities are the provision and use of the Service described in Annex 1. Annex I.B (description of transfer) and Annex I.C (competent supervisory authority) are completed by Annex 1 and Clause 13 above. Annex II (technical and organisational measures) is completed by Annex 2. Annex III (list of Sub-processors) is completed by the Sub-processors page. The parties are deemed to have signed the SCCs, including their annexes, on the date Customer accepts the Agreement, and the same dates apply to the UK Addendum.
  • Onward transfers. Where Brightyard transfers Customer Data to a Sub-processor outside the EEA, the United Kingdom, or Switzerland, Brightyard does so under the SCCs (Module Three) or another transfer mechanism recognised by the applicable Data Protection Laws, and remains responsible to Customer for that Sub-processor under Section 6. Brightyard's transfer impact assessment for the United States, and a summary of the supplementary measures in Annex 2, are available to Customer on request to [email protected].
  • UK transfers. The SCCs apply as modified by the UK Addendum, with the tables in the UK Addendum completed by the information in this DPA, and either party may end the UK Addendum as set out in its Section 19.
  • Swiss transfers. The SCCs apply with the adaptations required by the Swiss Federal Data Protection and Information Commissioner: references to the GDPR are read as references to the Swiss Federal Act on Data Protection; the competent supervisory authority under Clause 13 is the Commissioner; the term "member state" is read so that Data Subjects in Switzerland are not excluded from suing for their rights in Switzerland under Clause 18(c); and the SCCs also protect the data of legal entities until the Federal Act on Data Protection no longer does so.
  • If Brightyard becomes unable to comply with the SCCs, it will promptly notify Customer, and the parties will cooperate to identify an alternative lawful basis for the transfer or suspend the affected Processing.

14. California

To the extent the CCPA applies, Brightyard acts as a service provider to Customer. Brightyard will not sell or share Customer Data, will not retain, use, or disclose it for any purpose other than providing the Service or as permitted by the CCPA, will not combine it with personal information from other sources except as permitted, and will notify Customer if it determines it can no longer meet its obligations under the CCPA.

15. Liability, term, and precedence

  • Each party's liability under this DPA is subject to the exclusions and limitations of liability in the Agreement, and the parties' combined liability under the Agreement and this DPA is subject to a single aggregate cap.
  • This DPA remains in force for as long as Brightyard processes Customer Data, and Sections 11 and 13 survive until deletion is complete.
  • In the event of conflict, the SCCs prevail over this DPA, and this DPA prevails over the Agreement with respect to the Processing of Personal Data.
  • Except where the SCCs require otherwise, this DPA is governed by the law that governs the Agreement.

16. Contact

Notices under this DPA should be sent to [email protected]. Data protection questions can be sent to [email protected]. Security reports should go to [email protected].

Annex 1. Details of Processing

Subject matter and duration

The provision of the Service to Customer under the Agreement, for the term of the Agreement and the deletion period in Section 11.

Nature and purpose

Storing, organising, synchronising, analysing, and displaying Customer Data so that Customer can manage customer relationships, communications, calendars, websites, campaigns, workflows, and AI agents; generating content and recommendations with AI features at Customer's direction; sending communications on Customer's behalf; and providing support, security, and backups.

Categories of Data Subjects

  • Customer's employees, contractors, and other authorised Users.
  • Customer's customers, prospects, leads, suppliers, and other business contacts recorded in the Service.
  • Senders, recipients, and attendees of emails, meetings, and calendar events in accounts Customer connects to the Service.
  • Visitors to, and people who submit forms on, websites Customer publishes with the Service.

Types of Personal Data

  • Identification and contact details, such as names, email addresses, phone numbers, postal addresses, job titles, and employers.
  • Business relationship data, such as deal, order, ticket, and interaction history.
  • Communications content and metadata, including email messages, attachments, calendar events, meeting details, chat messages, and notes.
  • Usage and technical data generated by Users' interaction with the Service.
  • Any other Personal Data Customer chooses to record in custom modules and fields.

Special categories of data

The Service is not designed for special categories of Personal Data or for data about criminal convictions. Customer agrees not to submit such data unless the parties have agreed in writing to additional safeguards.

Annex 2. Technical and organisational measures

  • Encryption. Customer Data is encrypted in transit over public networks using TLS 1.2 or higher, and at rest using AES-256 on managed infrastructure. Traffic between Brightyard's own services travels over a private network that is not reachable from the internet.
  • Tenant isolation. Each Customer workspace is logically separated: every data access is scoped to the workspace at the application layer, and database row-level security policies keyed to the workspace are in place and are being enforced progressively across services as a second boundary.
  • Access control. Role-based permissions down to the module and field level for Users; least-privilege, need-to-know access for Brightyard personnel; and multi-factor authentication available to all Users.
  • Credential protection. Tokens for connected accounts are held in a dedicated secrets vault separate from the application database. API keys are shown once at creation and can be scoped and revoked.
  • Logging and monitoring. Audit trails of user actions (Team plans), centralised application logging, and error monitoring with alerting.
  • Availability and backups. Managed database with automatic failover and encrypted daily backups retained on a rolling schedule.
  • Secure development. Code review, automated static analysis and dependency scanning in the release pipeline, and staged deployment before production.
  • Vulnerability management. Regular security assessments and penetration testing by independent third parties, with findings remediated on a risk-based schedule.
  • Incident response. A documented process for detecting, assessing, containing, and notifying security incidents, including the notification commitment in Section 9.
  • Personnel. Confidentiality obligations and security awareness for all personnel with access to Customer Data.
  • Data lifecycle. Self-service export, correction, and deletion in the Service, and deletion after termination as described in Section 11.