Legal
Data Processing Addendum
Effective September 2, 2026
This Data Processing Addendum (“DPA”) supplements the BriefLoft Terms of Service when Media Yard LLC processes personal data on behalf of a business customer.
Parties and scope
This DPA is between the customer using BriefLoft (“Customer”) and Media Yard LLC, doing business as BriefLoft, PO Box 73, Pennsauken, NJ 08110 (“BriefLoft”). It applies to personal data contained in proposals, client emails, notes, links, recorded responses, and related customer content that BriefLoft processes to provide the service. Capitalized terms not defined here have the meaning given in the Terms of Service.
Roles and instructions
Customer is the controller or business and BriefLoft is the processor or service provider for customer content. If Customer prepares proposals for another organization, Customer may be a processor and BriefLoft its subprocessor. Customer instructs BriefLoft to process personal data only to provide, secure, support, and maintain the service; comply with documented lawful instructions; and meet legal obligations. Customer is responsible for the lawfulness of its instructions and submitted data.
Processing details
- Subject matter: creation, delivery, review, and management of client proposals.
- Duration: the account term plus the limited retention described in our Privacy Policy.
- Data: names, email addresses, business names, proposal titles, scope, deliverables, pricing, timelines, terms, notes, client responses, proposal history, and link settings.
- People: Customer users, clients, and other people Customer identifies in a proposal.
- Operations: collection, storage, organization, retrieval, AI-assisted drafting at Customer’s request, email delivery, controlled sharing, response recording, export, and deletion.
BriefLoft is not intended for passwords, payment-card data, health information, government identifiers, or special-category or highly sensitive personal data. BriefLoft does not act as a HIPAA business associate. A recorded response is not an electronic signature.
BriefLoft commitments
BriefLoft will:
- process customer personal data only on documented instructions unless law requires otherwise;
- require personnel with access to keep it confidential;
- maintain appropriate technical and organizational safeguards;
- notify Customer without undue delay after confirming a personal-data breach affecting customer content;
- reasonably assist Customer with data-subject requests, security inquiries, and legally required assessments; and
- make information reasonably necessary to demonstrate compliance available on request, subject to confidentiality and security limits.
Security
Safeguards include access controls, authenticated sessions, database row-level security, encryption in transit and provider-managed encryption at rest, restricted production access, logging and monitoring, and backup and recovery measures appropriate to the service. Drafts are private by default and published client links can be revoked. No system can guarantee absolute security.
Subprocessors
Customer authorizes BriefLoft to use subprocessors necessary to provide the service. Principal subprocessors are Vercel for hosting, Supabase for authentication and database services, Resend for email delivery, and OpenAI for AI-assisted features. Stripe independently processes billing information and generally does not process customer proposal content. We remain responsible for subprocessors to the extent required by applicable data-protection law.
International transfers
Data may be processed in the United States and other countries where our providers operate. When applicable law requires a transfer mechanism, the relevant EU Standard Contractual Clauses and UK transfer addendum are incorporated to the extent legally required, using the module appropriate to the parties’ roles. Contact us for information about the mechanism applicable to your account.
US state privacy laws
Where US state privacy law applies, BriefLoft acts as a service provider or processor and will not sell or share customer personal data for cross-context behavioral advertising, retain or use it outside the business purposes described here, or combine it with unrelated personal data except as permitted by law.
Return, deletion, and precedence
Customer can export or request deletion of account data through the service. At termination, BriefLoft will delete or return customer personal data in accordance with the Privacy Policy, subject to legal, security, fraud-prevention, backup, and shared-workspace exceptions. If this DPA conflicts with the Terms regarding processing of customer personal data, this DPA controls.
Contact
Questions or requests regarding this DPA may be sent to privacy@briefloft.com or mailed to Media Yard LLC, PO Box 73, Pennsauken, NJ 08110.