brockTransform

Data Processing Agreement

Effective date: July 3, 2026

1. Parties and roles

This DPA is between Brock Data, Inc. ("Brock") and the Customer identified in the Terms of Service.

The parties acknowledge that Brock's role depends on how the Customer uses the Service:

Direct use. Where the Customer migrates its own data, the Customer is the Controller (or its business customer is) and Brock is the Processor.

Consultant use. Where the Customer is an implementation consultant migrating data belonging to the consultant's own end client, the end client is the Controller, the Customer (consultant) is the Processor, and Brock is a Sub-processor. In that case the Customer warrants it is authorised by the end client to engage Brock on these terms and to give the instructions in this DPA.

In all cases, the Customer is responsible for the lawfulness of the instructions it gives and the data it provides.

2. Definitions

"Data Protection Laws" means all applicable privacy and data-protection laws, including the EU GDPR, the UK GDPR and Data Protection Act 2018, and US state privacy laws including the CCPA/CPRA. "Controller", "Processor", "Sub-processor", "Personal Data", "Processing", and "Data Subject" have the meanings in the Data Protection Laws. "Customer Personal Data" means Personal Data within Customer Data that Brock Processes under the Terms.

3. Scope and instructions

Brock will Process Customer Personal Data only: (a) to provide the Service under the Terms; (b) in accordance with the Customer's documented instructions (the Terms and this DPA are the Customer's complete instructions unless the parties agree otherwise in writing); and (c) as required by law (in which case Brock will inform the Customer unless legally prohibited). Brock will notify the Customer if, in its opinion, an instruction infringes Data Protection Laws.

The Service is designed for general business-records migration and is not designed or authorised to Process Protected Health Information under HIPAA, cardholder data under PCI-DSS, or other data subject to specialised regulatory regimes as described in the Terms and the Acceptable Use Policy. Brock is not a HIPAA business associate and does not accept those obligations. The Customer will not instruct Brock to Process such data, and Brock's obligations under this DPA do not extend to it.

4. Confidentiality

Brock ensures that personnel authorised to Process Customer Personal Data are bound by confidentiality obligations and are limited to those who need access to provide the Service.

5. Security

Brock implements appropriate technical and organisational measures to protect Customer Personal Data, described in Annex C, taking into account the state of the art, the costs of implementation, and the nature, scope, and risk of the Processing. The Customer acknowledges these measures are appropriate for the Personal Data described in Annex B (which may include financial account numbers).

6. Sub-processors

The Customer provides general authorisation for Brock to engage Sub-processors listed in Annex D (current list maintained at www.brocktransform.com/subprocessors). Brock will: (a) impose data-protection obligations on each Sub-processor that are no less protective than this DPA; (b) remain liable for its Sub-processors' performance; and (c) give the Customer at least 30 days' notice before adding or replacing a Sub-processor — by updating the list at www.brocktransform.com/subprocessors and by email to Customers subscribed to change notifications — during which the Customer may object on reasonable data-protection grounds. If the parties cannot resolve a reasonable objection, the Customer may terminate the affected part of the Service.

7. Data Subject requests

Taking into account the nature of the Processing, Brock will assist the Customer by appropriate technical and organisational measures, insofar as possible, to respond to Data Subject requests (access, rectification, erasure, restriction, portability, objection). If Brock receives a request directly from a Data Subject, it will refer them to the Customer and not respond except on the Customer's instruction or as legally required.

8. Personal Data breach

Brock will notify the Customer without undue delay after becoming aware of a Personal Data breach affecting Customer Personal Data, and will provide information reasonably available to it to help the Customer meet its own notification obligations. Brock's notification is not an acknowledgement of fault.

9. Assistance and DPIAs

Taking into account the information available to it, Brock will provide reasonable assistance to the Customer with data-protection impact assessments and prior consultations with supervisory authorities, where required by Data Protection Laws and relating to the Service.

10. International transfers

Where Customer Personal Data originating in the EEA or UK is transferred to Brock or its Sub-processors in a country without an adequacy decision, the parties incorporate:

the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module appropriate to the parties' roles; and

the UK International Data Transfer Addendum issued by the ICO,

each as completed by the information in the Annexes. In the event of conflict, the SCCs / UK Addendum prevail over this DPA for transfers they govern.

11. CCPA / CPRA (service provider terms)

With respect to Personal Information governed by the CCPA/CPRA, Brock acts as a Service Provider. Brock will not: (a) sell or share such Personal Information; (b) retain, use, or disclose it for any purpose other than performing the Service, or outside the direct business relationship, except as permitted by the CCPA; or (c) combine it with Personal Information from other sources except as permitted. Brock certifies it understands and will comply with these restrictions.

12. Deletion and return

On termination of the Service, Brock will, at the Customer's choice, delete or return Customer Personal Data, and delete existing copies, except where law requires retention.

The Customer's documented retention instructions are:

During the subscription term: Brock retains Customer Personal Data associated with each migration project for 12 months after the project is completed or last active, whichever is later, unless the Customer deletes it earlier. Brock will notify the Customer's primary administrator by email and by in-product notification 14 days and again 1 day before any such deletion.

After termination: Brock retains Customer Personal Data for 6 months to allow re-download/export, after which Brock will delete it, unless the Customer has purchased extended retention or requests earlier deletion.

Where the Service provides a retention setting, the Customer's configured setting constitutes the Customer's documented instruction for the purposes of this §12, and the Customer may request earlier deletion at any time via admin@brocktransform.com or in-product controls.

Staged data. Records staged for review during a migration are held in temporary working storage only; they are deleted automatically when the relevant migration step is completed and the workflow advances. Long-term retention applies only to Output Files and associated migration records.

Deletion notice. Before deleting Customer Personal Data at the end of the retention period, Brock will notify the Customer's primary administrator by email at least 14 days in advance, offering the option to purchase extended retention. Absent a response, deletion proceeds.

Backups. Customer Personal Data deleted from active systems is removed from encrypted backups in the ordinary course of backup rotation, within 7 days of deletion from active systems.

AI Sub-processor retention. Portions of Customer Personal Data transmitted to Anthropic for AI processing are retained by Anthropic only transiently under its standard commercial terms: inputs and outputs are deleted within 30 days of receipt or generation (except where longer retention is required by law or to enforce Anthropic's usage policies), and are not used to train Anthropic's models. Brock has not entered into a zero-data-retention arrangement with Anthropic; if one is adopted in future, the Sub-processor list will be updated.

13. Audits

Brock will make available information reasonably necessary to demonstrate compliance with this DPA and allow for audits, including by providing relevant third-party certifications, audit reports, or security documentation where available. On-site audits, if any, will be on reasonable notice, no more than once per twelve-month period absent a breach or regulator requirement, at the Customer's expense, and subject to confidentiality.

14. Liability

Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service.

Annex A — Parties

Controller / Customer: [as identified in the Terms]. Processor: Brock Data, Inc, 345 Glacier Ranch Road, Kalispell, MT 59901. Contact: admin@brocktransform.com.

Annex B — Description of Processing

Subject matter: provision of the data-migration Service.

Duration: the subscription term plus the retention period in §12. Staged records exist only transiently during a migration and are deleted automatically as the workflow advances (§12).

Nature and purpose: reading data from Source Systems; staging; AI-assisted analysis, mapping, and transformation; producing Output Files. AI-assisted analysis operates on schema metadata, representative data samples, and records flagged for review, to generate reusable mapping and transformation rules; the Service is designed to minimise the Customer Personal Data transmitted to AI Sub-processors and does not submit Customer datasets for record-by-record AI processing.

Types of Personal Data: names, addresses, contact details, financial account numbers, and other fields present in the Customer's migration data. No special-category data, and no data subject to HIPAA, PCI-DSS, or similar specialised regimes (the Service is not intended for it; see §3 and the AUP).

Categories of Data Subjects: the Customer's (or end client's) customers, vendors, and employees.

Annex C — Technical and organisational measures

Brock maintains an information security programme aligned to the control objectives of ISO/IEC 27001. Measures include: tenant isolation (row-level security); encryption of stored connection credentials (AES-256-GCM); encryption in transit and at rest; role-based access control and least-privilege access; audit logging; secrets management; signed, short-lived URLs for file downloads; secure software-development practices.

Annex D — Authorised Sub-processors

Supabase (database/auth/storage); Vercel (hosting); Anthropic (AI processing — commercial API; no model training on Customer Personal Data; inputs and outputs deleted within its standard retention period, currently 30 days); AWS Bedrock (AI — private/enterprise tier, planned); Stripe (payments); Resend (transactional email); Squarespace (domain/DNS/site).