Data Processing Addendum
Version 1.0 · Effective August 22, 2026
This Data Processing Addendum (“DPA”) forms part of the agreement governing a customer's use of pdfs.build (the “Agreement”) between that customer (“Customer”) andBrilliminds FZC, License No. 4306832 (“Processor”). It applies when Processor handles Customer Personal Data on Customer's behalf. It is effective when the Customer accepts the Agreement or the parties otherwise agree to it.
1. Definitions and roles
“Customer Personal Data” means personal data contained in Customer Content that Processor processes on Customer's behalf. “Data Protection Laws” means laws applicable to that processing, including, where applicable, the EU GDPR, UK GDPR and Data Protection Act 2018, Swiss Federal Act on Data Protection, and UAE Federal Decree-Law No. 45 of 2021. “SCCs” means the European Commission standard contractual clauses adopted by Decision (EU) 2021/914. Other terms have the meanings given by applicable Data Protection Laws.
Customer is a controller or processor, as applicable. Brilliminds FZC is Customer's processor or subprocessor. Each party will comply with the obligations that apply to it. Processing for which Brilliminds FZC independently determines the purposes and means is governed by the Privacy Policy, not this DPA.
2. Instructions and compliance
Processor will process Customer Personal Data only on Customer's documented instructions, including the Agreement, this DPA, Customer's configuration and use of the Service, and later written instructions consistent with the Agreement. Processor may process data where required by law and, unless prohibited, will inform Customer before doing so. Processor will promptly tell Customer if it believes an instruction infringes Data Protection Laws and may suspend that instruction while the parties resolve it.
Customer is responsible for the lawfulness, accuracy, and minimization of Customer Personal Data; providing required notices; obtaining required rights and consents; responding to data subjects; and ensuring its instructions comply with law. The Service is not intended for sensitive or regulated data unless the parties approve that processing in writing.
3. Confidentiality and security
Processor will ensure that people authorized to process Customer Personal Data are bound by confidentiality and receive access only as needed. Taking into account the state of the art, implementation costs, and the nature, scope, context, purposes, and risk of processing, Processor will maintain appropriate technical and organizational measures under Article 32 GDPR. The current measures are described in Schedule 2 and on theSecurity page. Processor may update them without materially reducing the overall protection of Customer Personal Data.
4. Security incidents
Processor will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. As information becomes available, the notice will describe the nature of the breach, likely consequences, measures taken or proposed, and a contact point. Processor will take reasonable steps to contain and remediate the breach and will provide information reasonably needed for Customer's legal duties. Notice is not an admission of fault. Customer is responsible for notifications legally required from it.
5. Subprocessors
Customer gives general written authorization for the subprocessors on theSubprocessor List. Processor will impose data-protection terms on each subprocessor that are no less protective than the relevant requirements of this DPA and remains responsible for its subprocessors to the extent required by law.
Processor will post intended additions or replacements and notify the account owner at least 15 days before a new subprocessor processes Customer Personal Data. Customer may object during that period on reasonable data-protection grounds. The parties will try in good faith to find a commercially reasonable alternative. If none is available, Customer may stop using the affected feature or terminate it and receive a pro-rata refund of prepaid unused fees for that feature. This is Customer's sole remedy for an unresolved subprocessor objection.
6. Assistance
Taking into account the nature of processing and information available, Processor will reasonably assist Customer with data-subject requests, security obligations, breach notices, data-protection impact assessments, and prior consultations required by Data Protection Laws. If a data subject contacts Processor about Customer Personal Data, Processor will direct the request to Customer unless law requires otherwise. Customer will reimburse reasonable costs for assistance that is unusually burdensome or caused by Customer's instructions, where law permits and after advance notice.
7. Return and deletion
During the Agreement, Customer may retrieve Customer Personal Data through available product features. At the end of the Service, Processor will delete or return Customer Personal Data at Customer's choice and delete remaining copies, unless law requires retention. Customer must make its request before account closure or promptly afterward. Data in backups will be isolated from ordinary use and deleted as the backups rotate, unless restoration is required for disaster recovery or law requires preservation.
8. Information and audits
Processor will provide information reasonably necessary to demonstrate compliance with this DPA. Customer may request an audit no more than once per year, unless a breach or regulator requires more. The parties will first use current third-party reports, questionnaires, and documentation where sufficient. Any further audit must be scoped, confidential, during normal business hours, avoid disruption and other customers' data, and be performed by an independent auditor who is not a competitor. Customer bears its costs unless the audit finds a material breach by Processor.
9. International transfers
If Customer Personal Data protected by the EU GDPR is transferred to a country without an applicable adequacy decision, the SCCs are incorporated by reference. Module Two applies where Customer is a controller and Module Three where Customer is a processor. Clause 7 applies; Clause 9 uses Option 2 with the 15-day notice period above; the optional wording in Clause 11 does not apply; under Clause 17 the law is Ireland; and under Clause 18 the courts are Ireland. The competent authority under Clause 13 is determined by the SCCs. Schedules 1–3 of this DPA complete the relevant SCC annexes. If the SCCs conflict with this DPA, the SCCs control.
For restricted transfers under the UK GDPR, the then-current UK International Data Transfer Addendum to the EU SCCs issued by the Information Commissioner's Office is incorporated and completed using the parties and information in this DPA; neither party may terminate it solely because the ICO issues a revised template. For Swiss transfers, references in the SCCs are adapted to the Swiss Federal Act on Data Protection, Switzerland and the competent Swiss authority as required. The parties will implement additional safeguards reasonably necessary for a lawful transfer.
10. General
The Agreement's liability limits apply to this DPA to the maximum extent permitted by law. This DPA controls over conflicting terms concerning Customer Personal Data. The Agreement's governing law applies except where the SCCs or mandatory Data Protection Laws require otherwise.
Schedule 1 — Processing details
- Data exporter: Customer, using the legal name, address, account-owner contact, and activities identified in its account or order. Customer is a controller or processor as described above.
- Data importer: Brilliminds FZC, Business Centre, Sharjah Publishing City Free Zone, Sharjah, United Arab Emirates, postal code 519285; [email protected]. Brilliminds FZC provides the Service and is a processor.
- Subject and purpose: hosting and delivering document design, rendering, storage, collaboration, AI assistance, search, forms, embeds, APIs, support, security, and related Service functions selected by Customer.
- Duration: the Agreement plus the deletion period described above.
- Nature and frequency: collection, recording, organization, storage, retrieval, consultation, transmission, generation, alteration, restriction, and deletion, on an ongoing or Customer-initiated basis.
- Data subjects: Customer's personnel, customers, prospects, suppliers, form respondents, document recipients, and other people whose data Customer submits.
- Data types: identity and contact data; organization and employment data; document and transaction data; prompts, messages, images and files; identifiers, IP addresses and device data; and any other personal data Customer chooses to submit.
- Sensitive data: not intended unless separately agreed in writing. If approved, applicable safeguards include strict purpose limitation, feature-specific minimization, confidentiality duties, and access restrictions.
- Customer instructions: the Agreement, configuration, feature and model selections, API requests, support requests, and lawful written instructions.
Schedule 2 — Technical and organizational measures
- HTTPS for public application and website traffic and configured browser security headers.
- One-way password and API-key hashing, HTTP-only production session cookies, and scoped authorization for organizations, workspaces, APIs, and sharing.
- Logical separation through account and organization identifiers and application authorization checks.
- Containerized application services, environment-supplied secrets, and separate database, cache, and object-storage components.
- Configurable AI providers and minimization of data sent to a selected feature.
- Diagnostic monitoring that, when enabled, disables default PII collection and browser session replay in the application configuration.
- Security-incident investigation and customer notification obligations described in this DPA.
- Regular review and improvement appropriate to risk; Customer remains responsible for its users, content, access settings, public links, and connected services.
Schedule 3 — Subprocessors
The names, purposes, locations, and feature conditions are maintained on the currentSubprocessor List, which is incorporated into this DPA.
Contact
DPA and privacy requests: [email protected].
Brilliminds FZC, Business Centre, Sharjah Publishing City Free Zone, Sharjah, United Arab Emirates, postal code 519285.