Legal

Data Processing

A short data processing summary for SaaS, client and project work where customer-provided data may be involved.

General website text / DPA available before larger engagements / Review before production

This page is a practical summary, not a full Data Processing Agreement. It should be reviewed before production use and completed with the correct legal details.

Roles

For ordinary website enquiries and business records, BrighouseSec may act as a controller. For SaaS, client or project work where a customer provides client, user or project data for BrighouseSec to process on their instructions, BrighouseSec may act as a processor.

Data Processed

Project data may include contact details, domain or product details, scope notes, report content, technical observations and communications needed to deliver the agreed service.

Subprocessors

Subprocessors or providers may include Formspree, hosting provider Netlify, email provider IONOS and Formspree, payment or invoicing provider confirmed after scope is agreed, and Supabase or HandoverSec if used for a specific engagement. This list should be reviewed before paid SaaS use or larger engagements.

Safeguards

BrighouseSec aims to limit project data to what is needed, avoid collecting secrets, keep reports confidential by default and delete or return project data when it is no longer needed for service, security, legal or accounting purposes.

Data Processing Agreement

A fuller Data Processing Agreement can be provided before paid SaaS use or larger engagements. BrighouseSec does not claim ISO 27001, SOC 2, GDPR certification, NIS2 compliance or other formal certification through this page.

Contact

For data processing questions, contact sales@brighousesec.com.