# Data Processing Agreement

Source: https://www.secondbrain.media/dpa  
Language: en  
Spanish version: https://www.secondbrain.media/dpa.es.md  
Last updated: August 28, 2026

---

This Agreement (the "DPA") governs the processing of personal data that Second Brain carries out on behalf of a customer using the Service for professional purposes. It forms part of the Terms of Service and applies from the moment the Service is contracted, with no separate signature required.

## 1. Roles of the parties

The customer is the controller: they decide what data to put into the Service and why. Second Brain is the processor: it processes that data solely to provide the Service and on the customer's instructions.

Using the Service in accordance with its documentation constitutes the customer's instructions. Any other instruction must be in writing.

Where Second Brain processes data for its own purposes — billing, platform security, legal compliance — it acts as a controller, and that processing is governed by the Privacy Policy.

## 2. Subject matter, duration and nature

> **Processing details**
>
> Subject matter: provision of the Service described in the Terms.
>
> Duration: for as long as the account is active, plus the deletion periods in section 8.
>
> Nature and purpose: storing, organising, indexing and processing the content the customer uploads, including the AI features the customer chooses to use.
>
> Types of data: whatever the customer chooses to upload. Typically notes, tasks, documents, file attachments, meeting recordings and transcripts, calendar events, and contact details of people mentioned in that content.
>
> Categories of data subjects: the customer, their personnel, and any individuals whose data appears in the uploaded content.

The Service is not designed to process special categories of data (health, biometrics, beliefs, among others) or data relating to children. The customer undertakes not to upload them.

## 3. Processor obligations

- Process data only on the customer's documented instructions.
- Ensure that anyone accessing the data is bound by a duty of confidentiality.
- Apply the technical and organisational measures in section 5.
- Assist the customer in responding to data subject requests and in their impact assessments, to a reasonable extent.
- Notify security breaches in accordance with section 7.
- Make available the information needed to demonstrate compliance with these obligations.
- Delete or return the data on termination, in accordance with section 8.

## 4. Sub-processors

The customer gives general authorisation for the use of sub-processors. The current list, including what each one does, is published on the Security page and kept up to date.

Before adding a new sub-processor, at least 30 days' notice is given by email to the account address. If the customer has a reasoned objection grounded in data protection, they may raise it within that period; failing a resolution, they may terminate the affected part of the Service without penalty.

Where the change is necessary to restore or preserve the security or continuity of the Service — for example, if a provider ceases to operate or to comply — the addition may be immediate and notice is sent as soon as possible, with the right to object unaffected.

Second Brain imposes on each sub-processor protection obligations equivalent to those in this DPA and remains liable for their performance.

## 5. Technical and organisational measures

The measures in force are described in detail, and with their real scope, on the Security page. In summary:

- Encryption in transit (TLS 1.2+) and at rest (AES-256), backups included.
- Additional encryption, with the key held outside the database, of the credentials for any integrations the customer connects.
- Workspace isolation enforced in the database itself, not only in the application.
- Role-based access control, verified server-side on every request.
- An access audit log, retained for 12 months and tamper-proof by design.
- Files accessible only through time-limited signed links.
- Effective deletion of data, not soft-delete flags.

Second Brain does not currently hold SOC 2 or ISO 27001 certification, and states so plainly: this DPA does not claim controls that do not exist.

## 6. International transfers

The Service infrastructure is hosted in the United States, and Agustín Gandara operates from Argentina. For customers in the European Economic Area, the United Kingdom or Switzerland, this involves an international transfer.

Those transfers rely on the European Commission Standard Contractual Clauses (Decision 2021/914), controller-to-processor module, incorporated into this DPA by reference and prevailing in the event of conflict. The UK Addendum issued by the ICO applies for the United Kingdom, and the FDPIC adaptations for Switzerland.

If the customer needs a signed copy of the Clauses or a transfer impact assessment, they may request it from the contact in section 10.

## 7. Security breaches

Second Brain will notify the customer without undue delay after becoming aware of a security breach affecting personal data processed on their behalf, with the information available at that time.

Where it is not possible to provide all the information at once, it will be supplied in phases as it becomes available, without further delay. The notification will describe the nature of the incident, the categories and approximate volume of data affected, the likely consequences, and the measures taken or proposed.

This is the deadline the Regulation places on the processor. The 72-hour deadline to notify the supervisory authority rests with the controller — that is, the customer — and runs from when the customer becomes aware.

Notification is not an admission of fault or liability.

## 8. Return and deletion

The customer can export all their data at any time from the application itself, in structured, commonly used formats (JSON and Markdown), without emailing anyone or waiting.

On termination, data is deleted from live systems when the account is deleted, which is immediate and irreversible. Backups are rotated separately and fully purged within 90 days.

Only records that the law requires to be kept, such as billing records, are retained, along with the audit log, which contains no customer content.

## 9. Audits

Second Brain will make available to the customer the information reasonably necessary to demonstrate compliance with this DPA: the published security documentation, the sub-processor list, and answers to a reasonable due-diligence questionnaire.

Where that documentation is not sufficient to demonstrate compliance, the customer may request an audit, at most once per calendar year, with 30 days' notice, limited to the processing carried out on their behalf, subject to a confidentiality agreement and at the customer's cost. The audit may not interfere with operation of the Service or access data, systems or facilities shared with other customers.

An audit prompted by a confirmed and attributable incident is at our cost.

## 10. Contact and precedence

Questions about this DPA, requests for Standard Contractual Clauses or for compliance documentation: hello@secondbrain.media.

In the event of any conflict between this DPA and the Terms, this DPA prevails in respect of the processing of personal data.
