Draft — pending legal review
This document is a working draft and is not yet effective. It has not been reviewed or approved by a lawyer and does not yet govern your use of Bright Ears.
Last updated: June 14, 2026
Parties
Who this is between
This Data Processing Addendum (“DPA”) is between you, the performer business that subscribes to Bright Ears (the “Controller”), and Bright Ears Co., Ltd., a company registered in Thailand (registration number 0105550096659) (the “Processor”). It is incorporated into the Terms of Service.
Scope
What this DPA covers — and what it does NOT
This DPA applies onlyto the personal data of your leads and end-clients that you process through Bright Ears (“Customer Personal Data”) — the inquiries, contact details and conversation content that arrive at your forwarding address and flow through the product. For that data you are the controller and Bright Ears is the processor.
This DPA does not cover the scraped venue and event-organiser contact data gathered by the proactive Hunt. For that data, Bright Ears is an independent controller with its own lawful basis, transparency duty and deletion path — not your processor. That processing is described in the Privacy Policy. Nor does it cover your own account data, for which Bright Ears is the controller (also the Privacy Policy).
Mandatory particulars
Subject-matter, duration, nature, purpose, data and subjects (Art 28(3) / s.40)
- Subject-matter: processing of Customer Personal Data to provide the Bright Ears service to you.
- Duration: for the term of your subscription, plus the limited period needed to return or delete the data afterwards.
- Nature of the processing: receiving, parsing, triaging, storing, drafting replies to, sending, and following up on inquiries and conversations on your behalf, including AI-assisted drafting.
- Purpose: enabling you to respond to and convert inquiries from your leads and end-clients.
- Types of personal data: names, email addresses, phone numbers, event dates and details, venue references, and the free-text content of inquiries and conversations.
- Categories of data subjects: your leads and your end-clients (the people enquiring about, or booking, your services).
Our obligations
Bright Ears’ processor commitments
- Process Customer Personal Data only on your documented instructions, including those given through your use and configuration of the service, except where required by law (in which case we will inform you, unless legally prohibited).
- Ensure persons authorised to process the data are bound by an appropriate duty of confidentiality.
- Implement appropriate technical and organisational security measures (GDPR Art 32) — including encryption of secrets and stored mailbox tokens, access controls, tenant isolation, and protections against header-injection on outbound mail.
- Assist you, taking into account the nature of the processing, with responding to data-subject requests, and with your security, breach-notification and data-protection-impact-assessment obligations.
- Notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, with the information you need to meet your own notification duties.
- At the end of the service, delete or return Customer Personal Data at your choice, and delete existing copies, except where retention is required by law.
- Make available the information needed to demonstrate compliance and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate, subject to reasonable confidentiality, notice and scheduling terms.
Sub-processors
Authorised sub-processors
You give general authorisation for Bright Ears to engage the sub-processors below to deliver the service. Each is bound by data-protection obligations materially the same as those in this DPA, and Bright Ears remains responsible for their performance.
- Postmark — outbound/inbound email delivery.
- OpenRouter — AI/LLM gateway for parsing, triage and drafting.
- Render — application hosting and managed PostgreSQL database.
- Clerk — authentication and session management.
- Stripe — subscription billing and payment processing.
- Serper / Google Search — search API (used chiefly for the Hunt; listed for completeness).
- Google (Gmail API) — send-only mailbox access where you connect your own mailbox.
We will give you reasonable advance notice of any intended addition or replacement of a sub-processor (a change-notice), and you may object on reasonable data-protection grounds; if we cannot resolve your objection, you may terminate the affected part of the service.
Transfers
International data transfers
Where Customer Personal Data is transferred outside Thailand or outside the EEA/UK (including to the United States), the transfer is made subject to an appropriate transfer mechanism — primarily the Standard Contractual Clauses and, for UK data, the UK International Data Transfer Addendum, together with the relevant sub-processor’s own safeguards. No PDPC adequacy whitelist is relied upon.
Data subjects
Assisting with requests, erasure and breaches
Taking into account the nature of the processing, Bright Ears will assist you in fulfilling your obligation to respond to requests from data subjects exercising their rights (access, rectification, erasure, restriction, portability, objection). If a data subject contacts Bright Ears directly about Customer Personal Data, we will route the request to you as controller. A described deletion/DSAR path is available via info@brightears.io; further automation of erasure is a planned follow-up.
Liability & contact
Liability, order of precedence, and how to reach us
Each party’s liability under this DPA is subject to the limitations and exclusions in the Terms of Service. If there is a conflict between this DPA and the Terms of Service on the subject of data protection, this DPA prevails. To request a countersigned copy once finalised in legal review, or for any question about this addendum, email info@brightears.io.