top of page

i-broS™ Data Processing Addendum ("DPA")

Version: 1.0
Effective Date: [01/08/2026]

This Data Processing Addendum ("DPA") forms part of the agreement between i-broS™ ("Processor") and the Customer ("Controller") governing the use of the i-broS™ platform.
Where applicable, this DPA satisfies the requirements of Article 28 of Regulation (EU) 2016/679 ("GDPR").
 
1. Definitions
Unless otherwise defined, terms such as Controller, Processor, Personal Data, Processing, Data Subject, Supervisory Authority, Personal Data Breach, and Sub-processor shall have the meaning given in the GDPR.
 
2. Scope
This DPA applies whenever i-broS™ processes Personal Data on behalf of the Customer in connection with the Services.
Nothing in this DPA transfers ownership of Customer Data to i-broS™.
 
3. Roles of the Parties
Unless otherwise expressly agreed in writing:

  • the Customer acts as the Controller;

  • i-broS™ acts as the Processor.

For specific processing activities, each party may independently act as an independent Controller where required by applicable law.
 
4. Subject Matter
The Processor provides enterprise AI governance, identity governance and related cloud services.
Processing activities may include:

  • authentication;

  • user management;

  • workspace administration;

  • governance configuration;

  • audit logging;

  • Identity Kernel™ execution;

  • Sentinel™ validation;

  • iD-SIG™ generation;

  • privacy-preserving processing;

  • customer support.

 
5. Duration
Processing shall continue only for the duration necessary to provide the Services or as otherwise required by law.
 
6. Categories of Personal Data
Depending on Customer use, Personal Data may include:

  • names;

  • business email addresses;

  • user identifiers;

  • authentication information;

  • IP addresses;

  • audit records;

  • customer-generated content;

  • documents;

  • prompts;

  • other data uploaded by the Customer.

 
7. Categories of Data Subjects
Data Subjects may include:

  • employees;

  • contractors;

  • consultants;

  • customers;

  • suppliers;

  • authorized users;

  • business contacts.

 
8. Processor Obligations
The Processor shall:

  • process Personal Data only on documented instructions from the Controller, unless otherwise required by law;

  • ensure confidentiality obligations for authorized personnel;

  • implement appropriate technical and organizational measures;

  • assist the Controller where reasonably required;

  • notify the Controller of confirmed Personal Data Breaches without undue delay after becoming aware of them;

  • cooperate with competent supervisory authorities where legally required.

 
9. Technical and Organizational Measures
The Processor implements security measures appropriate to the nature of the Services, which may include:

  • identity and access management;

  • role-based access control;

  • multi-factor authentication where enabled;

  • encryption in transit;

  • encryption at rest where applicable;

  • tenant isolation;

  • logging;

  • audit trails;

  • monitoring;

  • vulnerability management;

  • backup procedures;

  • incident response procedures;

  • privacy-preserving processing mechanisms.

Security measures may evolve over time to reflect technological developments.
 
10. Privacy-Preserving Processing
Where enabled by Customer configuration, i-broS™ may apply privacy-preserving processing before selected information is transmitted to supported AI models.
Such processing may include:

  • masking;

  • tokenization;

  • pseudonymization;

  • anonymization where technically feasible;

  • controlled re-association after AI processing where required by the authorized workflow.

These mechanisms are intended to reduce unnecessary disclosure of personal information.
The Customer remains responsible for determining whether the selected configuration is appropriate for its legal obligations.
 
11. Sub-processors
The Customer authorizes i-broS™ to engage Sub-processors where reasonably necessary for providing the Services.
Current Sub-processors may include cloud infrastructure, authentication providers and other technology providers supporting the operation of the Service.
i-broS™ shall require Sub-processors to provide data protection obligations substantially equivalent to those contained in this DPA.
An up-to-date list of Sub-processors shall be made available upon request or through the Website.
 
12. International Transfers
Where Personal Data is transferred outside the European Economic Area, appropriate safeguards shall be implemented, including where appropriate:

  • adequacy decisions;

  • Standard Contractual Clauses;

  • other lawful transfer mechanisms.

 
13. Assistance
Taking into account the nature of the Processing, the Processor shall reasonably assist the Controller in responding to requests relating to:

  • access;

  • rectification;

  • erasure;

  • restriction;

  • portability;

  • objection;

  • other applicable Data Subject rights.

 
14. Personal Data Breaches
Following confirmation of a Personal Data Breach affecting Customer Data, i-broS™ shall notify the Customer without undue delay and provide available information reasonably necessary to support the Customer's legal obligations.
 
15. Audit
Where required by applicable law or contract, the Customer may request reasonable information demonstrating compliance with this DPA.
Audits shall:

  • be reasonable in scope;

  • avoid disruption of operations;

  • protect confidential information and security;

  • be subject to appropriate confidentiality obligations.

 
16. Deletion or Return of Data
Upon termination of the Services and subject to legal retention obligations, Customer Data shall be deleted or returned according to the Customer's documented instructions and the applicable Service configuration.
Backup systems may retain information temporarily until normal overwrite cycles complete.
 
17. Confidentiality
All Personal Data processed under this DPA shall be treated as confidential.
Personnel authorized to process Personal Data shall be bound by appropriate confidentiality obligations.
 
18. Liability
Liability relating to Personal Data shall be governed by the limitation of liability provisions contained in the applicable Master Agreement or Enterprise Software License Agreement, except where prohibited by applicable law.
 
19. Order of Precedence
In the event of conflict:

  1. this DPA;

  2. the Enterprise Software License Agreement;

  3. any applicable Order Form.

 
20. Governing Law
This DPA shall be governed by the law specified in the applicable Master Agreement unless mandatory data protection law requires otherwise.
 
Appendix A – Nature of Processing
The Service is designed to provide enterprise AI identity governance, governance enforcement, privacy-preserving processing, auditability and related functionality.
Processing is limited to what is reasonably necessary to provide the contracted Services.
 
Appendix B – Security Principles
The platform is designed according to principles including:

  • Privacy by Design

  • Security by Design

  • Least Privilege

  • Zero Trust principles where applicable

  • Tenant Isolation

  • Auditability

  • Identity Governance

  • AI Governance

  • Privacy-Preserving AI Processing

  • Continuous improvement of security controls.

Nothing in this Appendix shall be interpreted as creating an absolute guarantee of security or regulatory compliance.

logo_i-bros_black.png

i-broS™ is a technology protected by 6 industrial patents.

Available only to enterprises demanding absolute sovereignty over their intelligence.

© 2026 by i-broS™

bottom of page