This page is a practical summary, not a full Data Processing Agreement. It should be reviewed before production use and completed with the correct legal details.
Roles
For ordinary website enquiries and business records, BrighouseSec may act as a controller. For SaaS, client or project work where a customer provides client, user or project data for BrighouseSec to process on their instructions, BrighouseSec may act as a processor.
Data Processed
Project data may include contact details, domain or product details, scope notes, report content, technical observations and communications needed to deliver the agreed service.
Subprocessors
Subprocessors or providers may include Formspree, hosting provider Netlify, email provider IONOS and Formspree, payment or invoicing provider confirmed after scope is agreed, and Supabase or HandoverSec if used for a specific engagement. This list should be reviewed before paid SaaS use or larger engagements.
Safeguards
BrighouseSec aims to limit project data to what is needed, avoid collecting secrets, keep reports confidential by default and delete or return project data when it is no longer needed for service, security, legal or accounting purposes.
Data Processing Agreement
A fuller Data Processing Agreement can be provided before paid SaaS use or larger engagements. BrighouseSec does not claim ISO 27001, SOC 2, GDPR certification, NIS2 compliance or other formal certification through this page.
Contact
For data processing questions, contact sales@brighousesec.com.