This Data Processing Agreement ("DPA") governs how Brazilnut processes personal data on your behalf. For enterprise customers requiring custom terms, please contact us.
Brazilnut processes Personal Data solely for providing the Services, including:
Brazilnut agrees to:
| Measure | Implementation |
|---|---|
| Encryption in transit | TLS 1.3 for all data transmission |
| Encryption at rest | AES-256 for stored files |
| Credential encryption | Fernet symmetric encryption |
| Authentication | Passwordless: single-use email codes (hashed at rest) and Google OAuth; no passwords stored |
| Access logging | Comprehensive audit trail |
| Tenant isolation | Logical separation via tenant_id |
We use the following subprocessors to deliver our Services:
| Subprocessor | Purpose | Security |
|---|---|---|
| Render.com | Application hosting | SOC 2 Type II certified |
| Cloudflare R2 | Object storage | SOC 2, ISO 27001 certified |
| PostgreSQL (Render) | Database | Encrypted connections |
If we become aware of a Personal Data breach, we will notify you without undue delay and provide: the nature of the breach, categories of data affected, likely consequences, and remediation steps taken.
Personal Data may be transferred to and processed in the United States. For transfers outside the EEA, we rely on Standard Contractual Clauses where applicable and our subprocessors' compliance certifications.
For DPA-related inquiries or to request a signed copy, contact us at security@brazilnut.ai
Last updated: January 2026