Back to Brewyard

Data Processing Agreement

Draft of 2026-08-20. Owner: Fincard Ltd.

Draft — subject to counsel review. This DPA has not yet been reviewed by qualified UK counsel and is published for transparency and early procurement review only. It is not yet offered for execution; contact us if your review depends on a signed DPA.

This Data Processing Agreement (“DPA”) describes how Fincard Ltd processes personal data on behalf of business customers using Brewyard, as required by Article 28 of the UK GDPR. It is designed to be read together with our sub-processor list and data-flow reference, which are incorporated by reference.

1. Parties and role of this DPA

This DPA is between Fincard Ltd, a company registered in England and Wales (“Brewyard”, the processor), and the business customer that accepts the Terms of Service on behalf of an organisation (the “Customer”, the controller). For Business-plan customers this DPA forms part of the Terms of Service. Where the Customer is itself a processor for a third-party controller, Brewyard acts as its sub-processor.

2. Scope, nature and purpose of processing

Brewyard processes personal data solely to provide the Brewyard service: hosting workspaces, orchestrating AI agent teams, storing generated artifacts, operating billing and support, and securing the platform. The systems the data moves through — browser, web BFF, API, Key Vault, per-workspace runtime, and the Customer's own Anthropic API relationship — are described in the data-flow reference.

3. Categories of data and data subjects

Data subjects: the Customer's authorised users, and any individuals whose personal data the Customer or its users include in prompts, workspace content or uploaded material. Categories: account and contact data (name, email), workspace configuration and content, agent inputs and outputs, billing records, and technical logs. The Customer is responsible for not submitting special-category data unless strictly necessary and lawful.

4. Duration

Processing continues for the term of the Customer's subscription and until deletion or return of personal data under section 11.

5. Processing on documented instructions

Brewyard processes personal data only on the Customer's documented instructions — the Terms of Service, this DPA, and the Customer's use of the product controls — including with regard to international transfers, unless required to do otherwise by law to which Brewyard is subject. In that case Brewyard informs the Customer before processing, unless the law prohibits it. Brewyard will inform the Customer if, in its opinion, an instruction infringes the UK GDPR.

6. Confidentiality

Persons authorised to process personal data — Brewyard staff and contractors — are bound by contractual confidentiality obligations. Access to customer content is restricted to what operating the service requires (see the trust-and-safety scanning description in the Terms of Service and the audit-logged staff access controls).

7. Security measures

Brewyard implements appropriate technical and organisational measures under Article 32, including: encryption in transit, customer API keys held in Azure Key Vault rather than the application database, per-workspace runtime isolation, role-based staff access with tamper-evident audit logging, and vulnerability-gated dependency management in CI. Measures evolve with the threat landscape; material reductions in protection will not be made during a subscription term.

8. Sub-processors

The Customer gives general written authorisation to the sub-processors on the published sub-processor list, which identifies each vendor, its role and its region. Brewyard gives notice of additions or replacements via that page (see its change-process note) and imposes data-protection obligations on each sub-processor equivalent to those in this DPA. Brewyard remains liable for its sub-processors' performance. Note: the Customer's Anthropic API usage runs on the Customer's own key under its direct agreement with Anthropic — see the note on the sub-processor page.

9. Assistance with data subject rights

Taking into account the nature of the processing, Brewyard assists the Customer with appropriate technical and organisational measures to respond to data subject requests (access, rectification, erasure, restriction, portability, objection). Requests received directly by Brewyard that concern the Customer's data are forwarded to the Customer without undue delay.

10. Personal data breach notification

Brewyard notifies the Customer without undue delay after becoming aware of a personal data breach affecting the Customer's personal data, and provides the information reasonably required for the Customer's own Article 33/34 obligations as it becomes available.

11. Deletion or return of data

On termination of the service, Brewyard deletes or returns (at the Customer's choice) the personal data processed on the Customer's behalf, and deletes remaining copies within the retention windows described in the Privacy Policy, unless UK law requires longer storage (e.g. billing records).

12. Audits and information

Brewyard makes available the information necessary to demonstrate compliance with Article 28 — starting with this DPA, the sub-processor list and the data-flow reference — and allows for and contributes to audits, including inspections, conducted by the Customer or its mandated auditor, on reasonable notice and no more than annually unless a supervisory authority requires otherwise or a breach has occurred.

13. International transfers

Personal data is hosted in the UK (Azure UK South). Where a restricted transfer arises — for example a sub-processor operating from the United States — it is made under the transfer mechanisms identified on the sub-processor list: the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, or an adequacy regulation where one applies. The Customer's own Anthropic relationship is governed by the Customer's agreement with Anthropic, including its transfer terms.

14. Optional web research by agents

Web research is off by default. A Customer may enable it during workspace setup, and only after confirming that they have read the notice shown at that point; the confirmation, the version of the notice, the language it was displayed in and the date are recorded in the workspace. Where it is enabled, the roles that carry it (finance, analysis and marketing) may issue search queries that Brewyard's runtime composes from workspace content, including the Customer's project description. Those queries are transmitted to Anthropic and its search provider under the Customer's own Anthropic agreement and are billed to the Customer's Anthropic key; the transfer considerations in section 13 apply. Agents may not retrieve a web address of their own choosing. Content returned from the web is untrusted input: Brewyard instructs agents to treat it as evidence to verify rather than as instruction, but makes no warranty as to its accuracy. A Customer who has not enabled web research is not subject to this processing, and a Customer who has may disable it by reconfiguring the workspace.

15. Liability and order of precedence

Liability under this DPA is subject to the limitations in the Terms of Service, except where the UK GDPR does not permit them to be limited. If this DPA conflicts with the Terms of Service on the processing of personal data, this DPA prevails.

16. Contact

Privacy questions and DPA execution requests: privacy@brewyard.ai.