Data Processing Addendum
The contract governing Brewstiller's processing of personal data for commercial customers.
Last updated: July 4, 2026
Plain-language summary
When you're a commercial customer, Brewstiller stores personal information about people other than you — your employees, customers, vendors, counterparties. You're the "controller" (you decided to collect it); Brewstiller is the "processor" (we process it on your behalf to provide the service). This DPA is the contract governing that relationship:
- We process your personal data only as needed to provide the service, on your documented instructions.
- We don't sell or share it, ever, for anything.
- We secure it per Annex C.
- We publish our subprocessors, give 30 days' notice of new ones, and you can object and terminate.
- We notify you of breaches affecting your personal data within 72 hours of confirmation.
- We help you answer data-subject requests from your people.
- You can audit us under reasonable conditions (§7).
- At termination we return or delete your personal data — except compliance records that alcohol regulations legally require us to retain, which we keep exactly as long as required and no longer.
Enterprise MSAs may supersede parts of this DPA; where silent, this DPA applies.
1. Background and relationship to the Terms
1.1 Purpose
This Data Processing Addendum ("DPA") is part of the Brewstiller Terms of Service (the "Terms") and governs Brewstiller's Processing of Personal Data on behalf of Customer in connection with the Service. In conflict with the Terms on subjects this DPA addresses, this DPA controls (Terms §27.2).
1.2 Applicability
This DPA applies only to Commercial Customers. Hobby customers are not controllers in the DPA sense; Brewstiller processes their data solely as controller of its own service data, per the Privacy Policy. Customer accepts this DPA by accepting the Terms in connection with a Commercial Workspace or by countersigning an Enterprise contract that incorporates it. No separate signature is required for self-serve customers.
1.3 Roles
- Customer is the Controller of Personal Data submitted to or generated through the Service in connection with Customer's operations (employees' data, vendors' contacts, customer records, aggregate end-consumer scan data, etc.).
- Brewstiller is the Processor of such data, acting on Customer's documented instructions.
- For personal data about Customer's own account, billing, and platform usage, Brewstiller is the Controller and the Privacy Policy governs; this DPA does not apply to that data.
2. Definitions
Terms not defined here have the meanings in the Terms.
- "Applicable Data Protection Law" — all laws applicable to Brewstiller's Processing of Customer Personal Data, including the CCPA/CPRA, UCPA, VCDPA, CPA, CTDPA, and other applicable US state privacy laws; expanded to foreign law (GDPR, UK GDPR, PIPEDA) if and when the Service extends internationally.
- "Controller" / "Processor" / "Processing" / "Data Subject" — the standard meanings (Processing covers any operation on Personal Data; Controller determines purposes and means; Processor acts on the Controller's behalf).
- "Customer Personal Data" — Personal Data Processed by Brewstiller on Customer's behalf in connection with the Service; excludes data Brewstiller processes as Controller.
- "Personal Data" — information relating to an identified or identifiable natural person, including "Personal Information" under the CCPA.
- "Personal Data Breach" — a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data.
- "Subprocessor" — a third party engaged by Brewstiller to Process Customer Personal Data on its behalf.
3. Subject matter, duration, details
Subject matter: provision of the Service per the Terms. Duration: the subscription plus post-termination periods per §8. Nature and purpose: operating Customer's Workspace — storage, retrieval, preparation of requested outputs (draft filings, Story Pages, reports), retention operations, support, security. Data and Data Subjects: per Annex A; Customer determines what Personal Data to submit and is responsible for its lawfulness.
4. Brewstiller's obligations as Processor
4.1 Documented instructions
Brewstiller Processes Customer Personal Data only on Customer's documented instructions — the Terms and this DPA, Customer's Service configuration, Customer's data submissions, and specific written instructions through support — unless required otherwise by law (in which case Brewstiller informs Customer unless legally prohibited). If Brewstiller believes an instruction violates Applicable Data Protection Law, it will inform Customer; Customer's post-notice repetition of the instruction is Customer's representation of lawfulness, indemnified per §9.2.
4.2 No sale or sharing
Brewstiller does not sell Customer Personal Data, does not "share" it for cross-context behavioral advertising (CCPA meaning), and does not use it for Brewstiller's own marketing or any commercial purpose outside operating the Service for Customer. Brewstiller represents that it qualifies as a "service provider" under CCPA §1798.140(ag) with respect to Customer Personal Data.
4.3 No combination
Brewstiller does not combine Customer Personal Data with data from other sources beyond what providing the Service requires, except as CCPA §1798.140(ag)(1)(C) or analogous provisions permit (e.g., aggregation/de-identification with re-identification safeguards, per Privacy Policy §13).
4.4 Personnel confidentiality
Personnel authorized to Process Customer Personal Data are bound by written confidentiality obligations surviving their engagement, trained in data protection, and given access only on a need-to-know basis.
4.5 Security
Brewstiller implements and maintains the technical and organizational measures in Annex C, appropriate to the risk. Measures may be updated if the overall protection is not materially diminished; material reductions require notice.
4.6 Data Subject rights assistance
Taking into account the nature of the Processing, Brewstiller assists Customer in fulfilling Data Subject requests through: in-product tooling (Customer can access, export, modify, and delete Customer Personal Data for routine cases); API access where published; and support assistance for cases beyond tooling (at a reasonable cost where request volume is unusual). Brewstiller refers Data Subject requests it receives directly to Customer; Brewstiller responds directly only for data it controls (per the Privacy Policy).
4.7 Personal Data Breach notification
Upon becoming aware of a Personal Data Breach affecting Customer Personal Data, Brewstiller will: notify Customer without undue delay and in any event within 72 hours of confirming the Breach (to Customer's designated security contact, or the Workspace owner's email); provide reasonably available information on nature, scope, affected categories and approximate numbers, likely consequences, and measures taken or proposed; cooperate in good faith with Customer's own notification obligations; and take reasonable mitigation and prevention steps. Notification is not an admission of fault. Customer, as Controller, owns notifications to regulators and Data Subjects.
4.8 DPIAs
Brewstiller provides reasonable assistance with data protection impact assessments and prior consultations Customer must carry out, given the nature of the Processing and information available to Brewstiller.
4.9 Records
Brewstiller maintains records of Processing on Customer's behalf as Applicable Data Protection Law requires and makes them available on reasonable request to demonstrate compliance.
5. Subprocessing
5.1 General authorization
Customer authorizes Brewstiller to engage Subprocessors subject to this §5.
5.2 Current Subprocessors
Per Annex B and the published Subprocessor List.
5.3 Notice of changes
At least 30 days' written notice before a new Subprocessor Processes Customer Personal Data: an update to the published Subprocessor List (with effective date) plus email to Customer's designated subprocessor-notification address (Workspace owner's email by default). Emergency replacements needed for availability or security take effect on the notice practicable, with explanation.
5.4 Objection right
Customer may object on legitimate data-protection grounds within 30 days of notice. The parties will discuss in good faith (e.g., configuration changes avoiding the Subprocessor for Customer's data). If unresolved, Customer may terminate the affected portion of the Service (or the subscription, if inseparable) by written notice, effective when the new Subprocessor would begin Processing, with prorated refund of prepaid Fees. No objection within 30 days = deemed approval.
5.5 Brewstiller's Subprocessor obligations
Written agreements imposing data-protection obligations substantially equivalent to this DPA; full liability to Customer for Subprocessors' performance as if Brewstiller's own; reasonable due diligence on security practices.
6. International transfers
Brewstiller currently Processes Customer Personal Data only within the United States. International transfer mechanisms (SCCs, UK IDTA/Addendum, adequacy, supplementary measures) will be added by DPA update, with notice, if and when the Service extends internationally.
7. Audit rights
7.1 Information
Brewstiller makes available: current security-measures documentation (Annex C summary; detail on request under confidentiality); independent audit reports if and when commissioned (e.g., SOC 2 — not yet held; released under Brewstiller's standard confidentiality undertaking when they exist); incident-response documentation on a confidential basis; and other reasonable compliance evidence.
7.2 Audit by Customer
Additionally, Customer may audit compliance with this DPA: at most once per 12 months (except supervisory-authority-required or post-Breach audits); on ≥30 days' notice (shorter for the exceptions); during business hours, minimizing disruption; scoped to demonstrating DPA compliance (no source-code access, no other customers' data, no infrastructure beyond verifying Annex C, no third parties' confidential information beyond what they permit); Customer bears its own costs and reimburses Brewstiller's reasonable internal support costs at standard professional-services rates unless the audit reveals Brewstiller's material breach; auditors bound by confidentiality at least as protective as the Terms. §7.1 information should suffice for most verification needs.
8. Return or deletion at termination
8.1 Election
At termination, at Customer's option: return (structured, machine-readable export — available throughout the subscription and for a reasonable post-termination window, typically 30 days) and/or deletion per the Privacy Policy timelines. Absent an election, Brewstiller provides the export window, then deletes per standard timelines.
8.2 Regulatory retention carve-out
Notwithstanding §8.1, federal and state alcohol regulations require Brewstiller to retain certain records post-termination: production, gauging, transfer-in-bond, COLA references, tax determinations, compliance filings, and related audit-log entries — for the periods in Privacy Policy §7.2 (typically 7 years from creation; COLA per its own rule). Brewstiller will: identify to Customer at termination exactly which categories are retained and until when; delete each record as its period expires; use retained records solely for the retention obligation; and protect them per Annex C. Everything deletable is deleted; only what law requires is retained.
8.3 Litigation hold
An active hold overrides standard deletion until released, then standard timelines resume.
8.4 Backups
Deleted data may persist in encrypted backups for the documented backup lifecycle (not more than 90 days), inaccessible except for disaster recovery, deleted on the backup's own cycle.
9. Liability and indemnification
9.1 Terms govern
Liability under this DPA is governed by Terms §22 (including §22.3's excluded amounts and §22.5's all-theories application), except as modified below. Claims relating to Filing Outputs are additionally governed by the Compliance Filing Terms.
9.2 Customer indemnification
In addition to Terms §23.1, Customer will defend, indemnify, and hold Brewstiller harmless from third-party claims arising out of: Customer instructions that, followed after Brewstiller's §4.1 notice, violate Applicable Data Protection Law; Customer's failure to lawfully collect Personal Data it submits; Customer's failure to give required notices or obtain required consents; and Customer's failure to respond to Data Subject requests for which it is responsible as Controller.
9.3 No automatic elevation
Brewstiller's breach of this DPA is not automatically "willful misconduct" for Terms §22.4 purposes; specific facts govern. Terms §23.2 (IP indemnity) is unmodified by this DPA.
10. Order of precedence and miscellaneous
10.1 Precedence
- An Enterprise MSA, to the extent it specifically so provides. 2. The Compliance Filing Terms, on filing-feature subjects. 3. This DPA, on subjects it addresses. 4. The Terms. 5. The Privacy Policy governs Brewstiller's controller-capacity disclosures.
10.2 Severability
Standard (invalid provisions severed and reformed; remainder survives).
10.3 Modifications
Material modifications: at least 30 days' written notice to Customer's legal-notices address (Workspace owner's email by default); continued use after effectiveness constitutes acceptance; Customer may instead terminate per Terms §20 with prorated refund of unused prepaid Fees. Modifications driven by legal change take effect on the maximum practicable notice.
10.4 Electronic acceptance
This DPA may be accepted electronically with the effect of a handwritten signature.
10.5 Governing law and disputes
Utah law; Salt Lake County exclusive jurisdiction; no mandatory arbitration; no class-action waiver; two-year claim limit — per Terms §21.
10.6 Survival
§4.4 (for personnel who had access), §4.5 and §4.7 (for data retained per §8.2), §5.5 (for retained data), §8 (until all retained data is deleted), §9, §10, and any provision that by its nature should survive.
Annex A — Details of Processing
A.1 Subject matter: provision of the Brewstiller platform per the Terms and Documentation.
A.2 Duration: the subscription plus §8 post-termination periods.
A.3 Nature and purpose: authenticate and manage Customer's users; store and retrieve Customer Data; prepare requested outputs (draft compliance filings, reports, exports, Story Pages); apply retention and deletion operations; support; security and abuse prevention; Brewstiller's own legal compliance as Processor.
A.4 Categories of Personal Data (Customer determines what it submits; typical categories):
- Identity/contact data of Customer's users and personnel — full legal name, email, phone, mailing address, role, optional internal employee ID.
- Identity/contact data of vendors and counterparties — business and contact names, email, phone, counterparty TTB permit number, business address.
- Identity/contact data of Customer's customers (where Customer records them — DTC sales, clubs, recall response) — name, email, phone, address, purchase history.
- Operator identity on regulated records — full legal name and role on gauging records, stage transitions, transfer confirmations, per TTB/state record-keeping rules.
- Aggregate end-consumer scan data (country/US state, referrer class, device class, timestamp) — deliberately minimized; no individual identification; included for transparency though borderline as Personal Data.
- Any other Personal Data Customer chooses to submit (notes, attachments, communications).
A.5 Categories of Data Subjects: Customer's employees/contractors/authorized users; vendors and suppliers and their personnel; counterparties and their personnel; Customer's customers; end consumers (aggregate only); other individuals whose data Customer submits.
A.6 Frequency: continuous during the subscription; specific operations on Customer interaction, scheduled jobs (retention, aggregation, draft-filing preparation), and new submissions.
A.7 Recipients: Customer's authorized users per its role configuration; Brewstiller personnel per §4.4; Subprocessors per §5/Annex B; regulated-transaction counterparties (only what regulation requires); recipients Customer directs (its own submissions to regulators; its accounting integrations); authorities under legal process (Privacy Policy §6.7).
Annex B — Subprocessors
Current list maintained as the Subprocessor List. As of this DPA's date:
| Subprocessor | Service provided | Status | Location |
|---|---|---|---|
| Clerk, Inc. | Authentication and identity management | Active | United States |
| DigitalOcean, LLC | Cloud infrastructure: application hosting (App Platform — web + worker runtimes), managed PostgreSQL database, object storage (Spaces) — all Customer Personal Data is stored and processed on DigitalOcean infrastructure | Active | United States |
| Resend, Inc. | Transactional email delivery | Active | United States |
| Functional Software, Inc. d/b/a Sentry | Error tracking and performance monitoring (environment-gated: armed only in production/staging by explicit configuration; sensitive fields scrubbed; session replay strictly opt-in per Workspace) | Active (production/staging) | United States |
| Stripe, Inc. | Payment processing, subscription billing, tax calculation | Engaged from the launch of paid tiers — no Customer data flows to Stripe before then | United States |
Per-subprocessor data categories are detailed in the published Subprocessor List. 30 days' notice of changes per §5.3.
Annex C — Technical and organizational security measures
Summary of measures in place at v1 (detail available on request under confidentiality, §7.1):
C.1 Confidentiality. Individual authentication for systems Processing Customer Personal Data; MFA for administrative access; role-based, need-to-know, logged and audited personnel access; TLS 1.2+ in transit; encryption at rest (DigitalOcean managed database and Spaces); written personnel confidentiality undertakings.
C.2 Integrity. Workspace isolation on every row (workspace_id), enforced at the application layer and by PostgreSQL row-level security at the database layer (defense in depth); append-only audit logging of significant operations; peer-reviewed, documented change management for production changes.
C.3 Availability and resilience. Regular encrypted backups; documented disaster-recovery procedures; managed infrastructure redundancy at the current service tier (scaling with load); automated availability monitoring with alerting.
C.4 Restoration. Backup restoration for data-loss events; cold-archived records restorable on request.
C.5 Testing and evaluation. Dependency vulnerability monitoring with severity-based patching; security review of material changes; periodic security assessments.
C.6 Incident response. Documented incident-response plan (identification, containment, investigation, notification, post-incident review); Breach notification per §4.7.
C.7 Subprocessor management. Pre-engagement due diligence; contractual flow-down per §5.5; periodic posture review.
C.8 Minimization. Minimum-PII defaults platform-wide; aggregation/de-identification with re-identification safeguards (Privacy Policy §13).
Brewstiller does not currently hold SOC 2 or ISO 27001 certification and this Annex does not claim otherwise. Certifications, when obtained, will be added to §7.1.
Effective date for a Customer: acceptance of the Terms with a Commercial Workspace, or the effective date of an incorporating Enterprise contract. · Version: v1.1
| Version | Effective date | Summary |
|---|---|---|
| v1.0 | — (never published) | Initial draft. |
| v1.1 | July 4, 2026 | Cross-reference fixes; Annex B aligned to deployed reality; Annex C scoped to actual v1 measures; Terms v1.1 liability architecture referenced. |