Data Processing Addendum
Last updated: July 30, 2026. This revision is effective immediately.
This Data Processing Addendum (“DPA”) governs the Processing of Customer Personal Data by Brilliant Design Ltd. (“Brilliant,” “we,” “us,” or the “Processor”) on behalf of the customer that purchases or administers a Team plan (the “Customer” or “Controller”). This DPA is incorporated into and forms part of the Terms of Use (the “Agreement”) for every Team plan. By purchasing a Team plan, the Team Admin, on behalf of the Customer, accepts and enters into this DPA with Brilliant. Customers that require a counter-signed version of this DPA may email legal@brilliant.design.
Table of contents
- 1. Definitions
- 2. Scope and roles
- 3. Processing instructions
- 4. Subject matter, nature, purpose and duration
- 5. Confidentiality
- 6. Security
- 7. Sub-processors
- 8. Data subject rights
- 9. DPIA and prior consultation
- 10. Personal Data Breach
- 11. Return and deletion
- 12. Audits
- 13. International transfers
- 14. Customer responsibilities and Restricted Data
- 15. Liability
- 16. Order of precedence
- 17. Service Data
- 18. Term
- 19. Governing law and jurisdiction
- 20. Entire agreement
- Schedule 1: Data Processing Description
- Schedule 2: Technical and Organizational Measures
- Schedule 3: Sub-processors
- Annex I: Standard Contractual Clauses (2021, Module Two) and UK IDTA
- Annex II: U.S. State Privacy Laws
1. Definitions
Capitalized terms used in this DPA have the meanings set out below. Terms not defined in this DPA have the meanings given to them in the Agreement or in applicable Data Protection Laws.
- “Agreement” means the Terms of Use between Brilliant and the Customer, together with any order form, plan selection, or other document forming the parties' commercial agreement.
- “Controller,” “Processor,” “Data Subject,” “Personal Data,” “Processing” and “Personal Data Breach” have the meanings given to them in the GDPR, or the equivalent meanings under other applicable Data Protection Laws.
- “Customer Data” means Personal Data that Brilliant Processes on behalf of the Customer to provide the Services, as further described in Schedule 1.
- “Data Protection Laws” means all laws and regulations applicable to the Processing of Personal Data under the Agreement, including, as applicable: (a) Regulation (EU) 2016/679 (the “GDPR”) and its implementing laws in the European Economic Area; (b) the GDPR as it forms part of UK domestic law by virtue of the European Union (Withdrawal) Act 2018, together with the UK Data Protection Act 2018 (the “UK GDPR”); (c) the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act (the “CCPA/CPRA”); (d) the Israeli Protection of Privacy Law, 5741-1981, and regulations promulgated under it; and (e) any other applicable law relating to the Processing of Personal Data.
- “EU SCCs” means the Standard Contractual Clauses for the transfer of Personal Data to third countries approved by European Commission Implementing Decision (EU) 2021/914 of 4 June 2021, in the form attached as Annex I to this DPA.
- “Services” means the Brilliant application and associated services made available to the Customer under the Agreement.
- “Sub-processor” means any third party engaged by Brilliant to Process Customer Data in connection with the Services.
- “UK IDTA” means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner's Office and in force on 21 March 2022, as amended from time to time.
2. Scope and roles
This DPA applies to the Processing of Customer Data by Brilliant in the course of providing the Services under the Agreement. The parties acknowledge that, with respect to Customer Data, the Customer is the Controller and Brilliant is the Processor. Where the Customer acts as a processor on behalf of a third-party controller, the Customer represents that it has the authority to instruct Brilliant in respect of such Personal Data, and Brilliant acts as a sub-processor on those terms.
This DPA applies in addition to, and does not replace, the Agreement. It applies only to the extent Brilliant Processes Customer Data on behalf of the Customer. For clarity, content that an individual user chooses to publish to the Brilliant Platform under their personal handle is processed by Brilliant as a controller under our Privacy Policy, at the user's own initiative, and is not Customer Data within the scope of this DPA.
3. Processing instructions
Brilliant will Process Customer Data only on the Customer's documented instructions, including with regard to transfers of Customer Data to a third country or an international organization, unless required to do so by applicable law. Where Brilliant is required to Process Customer Data for a purpose other than to provide the Services, Brilliant will inform the Customer of that legal requirement before Processing, unless the applicable law prohibits that information on important grounds of public interest.
The Agreement (including this DPA, any Customer configuration of the Services, and the Customer's use of the Services) constitutes the Customer's complete documented instructions to Brilliant for the Processing of Customer Data. Additional or alternative instructions must be agreed in writing by the parties. Brilliant will inform the Customer if, in its opinion, an instruction infringes applicable Data Protection Laws.
4. Subject matter, nature, purpose and duration
The subject matter, nature and purpose of the Processing, the types of Personal Data, the categories of Data Subjects, and the duration of the Processing are described in Schedule 1.
5. Confidentiality
Brilliant will ensure that personnel authorized to Process Customer Data are bound by written confidentiality obligations or are under an appropriate statutory duty of confidentiality. Brilliant will limit access to Customer Data to personnel who need such access to perform the Agreement.
6. Security
Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of Processing, as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, Brilliant will implement and maintain appropriate technical and organizational measures designed to ensure a level of security appropriate to the risk. A description of those measures is set out in Schedule 2. Brilliant may update those measures from time to time, provided that the updates do not materially reduce the overall level of security.
7. Sub-processors
The Customer provides a general authorization for Brilliant to engage Sub-processors to Process Customer Data. The current list of Sub-processors is published at /legal/subprocessors and is incorporated into this DPA as Schedule 3.
Brilliant will notify the Customer of any intended changes concerning the addition or replacement of a Sub-processor that Processes Customer Data at least thirty (30) days before the change takes effect. Notice will be given by email to the Team Admin's email of record and by updating the Sub-processor list. The Customer may object to a new Sub-processor on reasonable data-protection grounds by notifying legal@brilliant.design within the notice period, in which case the parties will work in good faith to resolve the objection. If the parties cannot resolve the objection, the Customer may, as its sole remedy, terminate the affected portion of the Services on written notice, and Brilliant will refund any pre-paid fees covering the unused portion of the Services following termination.
Brilliant will impose on each Sub-processor data protection obligations that are, in substance, no less protective than those set out in this DPA. Brilliant remains fully liable to the Customer for the performance of each Sub-processor's obligations.
8. Data subject rights
Taking into account the nature of the Processing, Brilliant will assist the Customer by appropriate technical and organizational measures, insofar as this is possible, to enable the Customer to respond to requests from Data Subjects exercising their rights under Data Protection Laws, including rights of access, rectification, erasure, restriction, portability, and objection. Where Brilliant receives a request from a Data Subject relating to Customer Data, Brilliant will, unless otherwise required by law, refer the Data Subject to the Customer and promptly inform the Customer of the request.
9. DPIA and prior consultation
Brilliant will provide the Customer with reasonable assistance with any data protection impact assessments and prior consultations with supervisory authorities that the Customer reasonably considers required under Articles 35 and 36 of the GDPR (or equivalent provisions of other Data Protection Laws), in each case solely in relation to the Processing of Customer Data and taking into account the nature of the Processing and the information available to Brilliant.
10. Personal Data Breach
Brilliant will notify the Customer without undue delay, and in any event within seventy-two (72) hours after confirming a Personal Data Breach affecting Customer Data. The notification will, to the extent then known, describe: (a) the nature of the Personal Data Breach, including where possible the categories and approximate number of Data Subjects and Personal Data records concerned; (b) the likely consequences of the Personal Data Breach; (c) the measures taken or proposed to be taken to address the Personal Data Breach and to mitigate its possible adverse effects; and (d) contact details for further information. Brilliant will provide updated information as it becomes available.
Brilliant's notification of, or response to, a Personal Data Breach under this Section is not an acknowledgment by Brilliant of any fault or liability with respect to the Personal Data Breach.
11. Return and deletion
At the Customer's choice, Brilliant will delete or return all Customer Data to the Customer after the end of the provision of Services relating to Processing, and will delete existing copies unless applicable law requires storage of the Personal Data. Deletion or return will be completed within thirty (30) days after termination or expiration of the Agreement. The Customer may request earlier return or deletion at any time during the term of the Agreement by using the available Services functionality or by contacting privacy@brilliant.design.
Notwithstanding the foregoing, Brilliant may retain Customer Data to the extent required by applicable law, in which case Brilliant will continue to protect that Customer Data in accordance with this DPA and will Process it only as necessary for the purpose specified by the applicable law.
12. Audits
Brilliant will make available to the Customer all information reasonably necessary to demonstrate compliance with this DPA. Where Brilliant maintains a SOC 2 Type II (or equivalent) report covering the Services, provision of that report will satisfy audit requests under this DPA, subject to reasonable confidentiality obligations.
Where no such report is available, Brilliant will respond to the Customer's reasonable written security questionnaire relating to the Services within sixty (60) days of receipt, no more than once in any twelve-month period, except where an additional request is (a) required by a supervisory authority, or (b) made following a Personal Data Breach affecting the Customer.
On-site audits will be permitted only for cause (for example, following a Personal Data Breach affecting the Customer or a documented compliance concern that cannot reasonably be resolved through the information described above). Any on-site audit will be conducted on reasonable prior written notice of at least thirty (30) days, during normal business hours, at the Customer's expense, subject to reasonable confidentiality obligations, and in a manner that does not unreasonably interfere with Brilliant's operations or the security of other customers' data.
13. International transfers
Brilliant and its Sub-processors may Process Customer Data in jurisdictions outside the European Economic Area (“EEA”), the United Kingdom, and Switzerland, including in Israel and the United States. Where Customer Data is transferred from the EEA, the United Kingdom, or Switzerland to a country that has not been the subject of an adequacy decision from the relevant authority, the parties agree that:
- For transfers subject to the GDPR, the EU SCCs (Module Two: controller to processor) are hereby incorporated into this DPA by reference and apply, as completed in Annex I.
- For transfers subject to the UK GDPR, the UK IDTA is hereby incorporated into this DPA by reference and applies to such transfers, with the information required by Table 1 of the UK IDTA taken from Annex I, Appendix A and the “Approved Addendum” as published by the Information Commissioner's Office.
- For transfers subject to the Swiss Federal Act on Data Protection, the EU SCCs apply with the adaptations set out in the Swiss Federal Data Protection and Information Commissioner's guidance, including references to the GDPR read as references to the Swiss FADP where applicable.
If any of the transfer mechanisms above is invalidated or replaced, the parties will work together in good faith to implement an alternative lawful mechanism.
14. Customer responsibilities and Restricted Data
The Customer is responsible for its own compliance with applicable Data Protection Laws, including for having an appropriate legal basis for the Processing of Customer Data and for providing any required notices to Data Subjects. The Customer represents that it has the authority to instruct Brilliant to Process the Customer Data and that its instructions are lawful.
The Customer warrants that it will not submit any of the following categories of data (“Restricted Data”) to the Services without a separate written agreement with Brilliant:
- Protected health information subject to HIPAA or equivalent health data privacy laws.
- Genetic data or biometric data used to uniquely identify an individual.
- Personal data of children under 13 (under 16 in the EEA and UK where applicable).
- Payment card numbers or other PCI-in-scope data. Paddle handles payment card data as merchant of record; Brilliant does not process raw card numbers.
- Social Security numbers, national ID numbers, passport numbers, or driver's license numbers.
- Financial account numbers, including bank and brokerage account numbers.
- Data subject to export control or sanctions regimes.
- Any “special categories of personal data” under GDPR Article 9 (racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, health, sex life, or sexual orientation).
If the Customer submits Restricted Data, the Customer indemnifies Brilliant for any resulting claims, and Brilliant may suspend or terminate the relevant Services without liability.
15. Liability
Each party's liability arising out of or related to this DPA, whether in contract, tort or under any other theory of liability, is subject to the limitations and exclusions of liability set out in the Agreement. No cap or exclusion in the Agreement will limit a party's liability to Data Subjects under Clause 12 of the EU SCCs or to supervisory authorities where those limitations or exclusions are not permitted by applicable Data Protection Laws.
16. Order of precedence
In the event of a conflict between this DPA and the Agreement with respect to the subject matter covered by this DPA, this DPA will prevail. In the event of a conflict between this DPA and the EU SCCs or the UK IDTA, the EU SCCs or the UK IDTA (as applicable) will prevail with respect to the transfers they govern.
17. Service Data
Processor may collect, use, and retain aggregated and anonymized data derived from the Services (“Service Data”) for the purposes of: (a) providing, operating, maintaining, and improving the Services; (b) detecting, preventing, and responding to security incidents, fraud, and abuse; (c) generating internal product analytics and aggregate benchmarks; and (d) complying with legal obligations. Service Data does not include Customer Data or Personal Data, and Processor will not use Service Data to identify or profile any individual data subject or any Customer.
18. Term
This DPA takes effect on the date the Customer purchases a Team plan (or otherwise first accepts the Agreement for a Team plan) and remains in force for so long as Brilliant Processes Customer Data on behalf of the Customer, after which those provisions that by their nature are intended to survive (such as the obligations in Sections 11 (Return and deletion), 13 (International transfers), 14 (Customer responsibilities and Restricted Data) and 15 (Liability)) will survive.
19. Governing law and jurisdiction
This DPA is governed by the laws of the State of Israel, without regard to its conflict of laws rules, and the parties submit to the exclusive jurisdiction of the competent courts located in the Tel Aviv-Jaffa district of Israel, except that: (a) the EU SCCs and the UK IDTA are governed by, and interpreted in accordance with, the laws specified in those clauses (see Annex I); and (b) where Data Protection Laws grant Data Subjects a mandatory right to bring a claim in another forum, those rights are not limited by this Section.
20. Entire agreement
This DPA, together with the Agreement and its incorporated documents (including the Sub-processors list and the Privacy Policy), constitutes the entire agreement between the parties with respect to the Processing of Customer Data and supersedes any prior or contemporaneous understandings, proposals, or representations with respect to that subject matter.
Schedule 1: Data Processing Description
- Subject matter. The provision of the Services to the Customer under the Agreement.
- Duration. For the term of the Agreement, plus any period during which Brilliant retains Customer Data in accordance with Section 11 (Return and deletion) and applicable law.
- Nature and purpose. Storage, transmission, organization, retrieval, and other Processing as necessary to operate the Services for the Customer, including authentication, team and seat management, billing and subscription administration, abuse and security protection, and customer support.
- Categories of Data Subjects. The Customer's Team Admins and Team Members, and any other individuals whose Personal Data is submitted to the Services by or on behalf of the Customer.
- Categories of Personal Data. Email address; authentication data (including one-time verification codes, which are ephemeral); device identifiers; seat and role metadata (including role, joined date, and administrative events); aggregate usage counts (including counts of AI messages and designs); subscription and billing metadata received from the payment processor; IP address and user-agent metadata collected for rate limiting, security, and abuse detection. Content of designs and prompt text submitted by users through AI features is routed under the Bring-Your-Own-Key (“BYOK”) model described in the Agreement, in which input is transmitted from the user's device directly to the relevant third-party AI provider and is not transmitted through or retained by Brilliant.
- Special categories of Personal Data. None expected. The Customer will not submit special categories of Personal Data (as defined in Article 9 of the GDPR) or data concerning criminal convictions and offenses to the Services without Brilliant's prior written agreement to additional terms governing that Processing.
- Frequency of transfer. Continuous, for the duration of the Agreement.
- Retention. Customer Data is retained for the duration of the Agreement and deleted or returned in accordance with Section 11. Short-lived authentication artifacts (such as one-time verification codes) are retained only for the period required to complete the authentication flow.
- Hosting locations. The Services are hosted on Google Cloud Platform (Cloud Run) in the us-central1 region, with realtime collaboration running on Google Compute Engine in us-central1, and with the primary database hosted on MongoDB Atlas on Google Cloud in us-central1 (Council Bluffs, Iowa). Signed installer downloads are served from AWS S3 in eu-north-1 (Stockholm). For the current list of Sub-processors and their processing locations, see Schedule 3.
Schedule 2: Technical and Organizational Measures
Brilliant maintains the following technical and organizational measures to protect Customer Data. These measures may be updated from time to time, provided that the updates do not materially reduce the overall level of security.
- Access control. Role-based access control, least-privilege provisioning, and periodic access reviews for systems that store or Process Customer Data.
- Authentication. Multi-factor authentication is required for administrative access to production systems.
- Encryption in transit. TLS 1.2 or higher is used for all external network connections that carry Customer Data.
- Encryption at rest. Customer Data is encrypted at rest using AES-256 or equivalent, via the encryption facilities provided by the underlying infrastructure providers (Google Cloud Platform and MongoDB).
- Secrets management. Production credentials and API keys are stored in managed secret stores and are not hardcoded into source code or distributed artifacts.
- Logging and monitoring. Administrative and security-relevant events in the production environment are logged, retained, and monitored for anomalies.
- Backups. Regular backups of production databases are maintained, with integrity checks.
- Personnel. Employees and contractors with access to Customer Data are subject to written confidentiality obligations and receive guidance on the secure handling of Personal Data.
- Vendor management. Prospective Sub-processors are reviewed for security and privacy practices before engagement, and are bound by data protection obligations that are, in substance, no less protective than those in this DPA. See Schedule 3.
- Incident response. Brilliant maintains a documented incident response procedure that includes triage, containment, and the notification obligation in Section 10 of this DPA.
- Secure development. Changes to code affecting Customer Data are subject to code review. Security patches for dependencies and infrastructure components are applied in a timely manner based on severity.
- Data minimization. Brilliant collects and retains only the Personal Data described in Schedule 1 as necessary to provide the Services.
Brilliant does not currently hold a SOC 2, ISO 27001, or equivalent third-party certification, and does not operate a scheduled external penetration testing program. If that changes, this Schedule will be updated and this DPA's “Last updated” date will reflect the change.
Schedule 3: Sub-processors
The authoritative, current list of Sub-processors engaged by Brilliant to Process Customer Data is published at /legal/subprocessors. That page is incorporated into this DPA by reference and forms Schedule 3. Brilliant will maintain the list, reflecting additions, replacements, and removals as they occur, and will provide the 30-day advance notice described in Section 7 for any addition or replacement of a Sub-processor that Processes Customer Data.
Annex I: Standard Contractual Clauses (2021, Module Two) and UK IDTA
For transfers of Customer Data from the EEA subject to the GDPR, the parties agree to the Standard Contractual Clauses approved by Commission Implementing Decision (EU) 2021/914 of 4 June 2021, Module Two (controller to processor), which are hereby incorporated into this DPA by reference. The optional docking clause in Clause 7 is not applied. The optional language in Clause 11(a) (independent dispute resolution body) is not applied. The information required by the Annexes to the SCCs is set out below.
- Clause 9 (Use of sub-processors). Option 2 (general written authorization) applies. Brilliant will provide the Customer with at least thirty (30) days' prior notice of any intended addition or replacement of Sub-processors, as described in Section 7 of this DPA.
- Clause 17 (Governing law). The SCCs are governed by the law of Ireland.
- Clause 18 (Choice of forum and jurisdiction). Any dispute arising from the SCCs will be resolved by the courts of Ireland.
Appendix A: Annex I.A (List of Parties)
Data exporter: the Customer identified at checkout or in the applicable order document (name, address, and contact details of the data protection officer or person responsible for data protection as provided by the Customer). The Customer acts as Controller. The activities relevant to the data transferred are the Customer's use of the Services under the Agreement. The Customer's acceptance of the Agreement and this DPA constitutes signature for the purposes of the SCCs.
Data importer: Brilliant Design Ltd., acting as Processor. Contact: legal@brilliant.design. Activities relevant to the data transferred: provision of the Services as Processor on the Customer's behalf. Brilliant's acceptance of the Agreement and publication of this DPA constitutes signature for the purposes of the SCCs.
Appendix B: Annex I.B (Description of Transfer)
The categories of Data Subjects, categories of Personal Data, special categories of Personal Data, frequency of transfer, nature and purpose of Processing, retention, and the subject matter of the onward transfers to Sub-processors are set out in Schedule 1 and in Schedule 3 of this DPA.
Appendix C: Annex I.C (Competent Supervisory Authority)
The competent supervisory authority is the supervisory authority of the EU member state in which the Customer's EU representative is established or, where the Customer is itself established in the EEA, the supervisory authority of the Customer's main establishment, determined in accordance with Article 55 or 56 of the GDPR. Where no such authority can be identified, the Irish Data Protection Commission will act as the competent supervisory authority.
Appendix D: Annex II (Technical and Organizational Measures)
The technical and organizational measures, including those to ensure the security of the data, are set out in Schedule 2 of this DPA and apply for the purposes of Annex II of the SCCs.
Appendix E: Annex III (List of Sub-processors)
The list of Sub-processors authorized by the Customer under Option 2 of Clause 9 is set out in Schedule 3 of this DPA, which is maintained at /legal/subprocessors.
UK International Data Transfer Addendum
For transfers of Customer Data subject to the UK GDPR, the parties agree to the UK IDTA, which is incorporated by reference. Table 1 of the UK IDTA is populated from Appendix A above (parties); Table 2 selects the “Approved EU SCCs” as the version in force and Module Two; Table 3 is populated from Appendices B, D, and E above; and Table 4 permits either party to end the UK IDTA in accordance with its Section 19.
Annex II: U.S. State Privacy Laws
This annex applies where the Customer is subject to a comprehensive U.S. state privacy law, including (as of the effective date of this DPA) California (CCPA/CPRA), Virginia, Colorado, Connecticut, Utah, and the other comprehensive state privacy laws then in effect. This annex will extend to new states' laws as they take effect.
- Role of the parties. Brilliant acts as a “Service Provider” under the CCPA/CPRA and as a “Processor” under other applicable state laws.
- Limited and specified purpose. Personal Information (as defined under applicable state law) is disclosed to Brilliant only for the limited and specified purposes set out in the Agreement.
- Restrictions on use. Brilliant shall not: (i) sell or share Personal Information, including for cross-context behavioral advertising; (ii) retain, use, or disclose Personal Information for any purpose other than the specific purpose of performing the Services; (iii) retain, use, or disclose Personal Information outside the direct business relationship with the Customer; or (iv) combine Personal Information received from the Customer with Personal Information received from other sources, except as necessary to perform the Services.
- Certification. Brilliant certifies that it understands the restrictions in this annex and will comply with them.
- Verification. The Customer may take reasonable and appropriate steps to verify Brilliant's compliance. The audit rights set out in Section 12 of this DPA satisfy this requirement.
- Notice of inability to comply. If Brilliant determines that it can no longer meet its obligations under applicable state law, it will notify the Customer.
Last updated: July 30, 2026