Legal
Data Processing Addendum
Last updated: October 2, 2026
This Data Processing Addendum ("DPA") is part of the BrightSite Terms of Service between BrightSite, Inc. ("BrightSite," "we") and the customer ("you"). It applies automatically when BrightSite processes End User Data for you. No signature is needed.
Definitions
- End User Data means personal information about your site visitors, form submitters, email contacts, shoppers, reviewers, and other people that BrightSite processes on your behalf through the Service.
- Privacy Laws means U.S. federal and state laws that apply to the processing of End User Data, including the California Consumer Privacy Act and similar state laws, and, where they apply, other countries' data protection laws.
- Subprocessor means a third party BrightSite engages to process End User Data.
Roles
You are the business (or controller) for End User Data, and BrightSite is your service provider (or processor). You decide what End User Data your sites collect and why. You're responsible for having a lawful basis, giving required notices, and getting required consents, as described in the Terms.
Our commitments
BrightSite will:
- Process End User Data only to provide the Service to you, following your instructions, which are these Terms, this DPA, and how you configure and use the Service, and as the law requires. We'll tell you if we believe an instruction breaks the law.
- Not sell or share End User Data, not use it for targeted advertising, and not retain, use, or disclose it for any purpose other than providing the Service, or outside our direct relationship with you, except as Privacy Laws allow for service providers (for example, to detect security incidents, prevent fraud and spam, and improve the Service without building profiles for anyone else). We won't combine it with personal information from other sources except as Privacy Laws allow.
- Not use End User Data to train AI models, and use AI providers' paid business services, which don't use API data to train their models.
- Keep it confidential, and give access only to staff who need it to run, support, or secure the Service and who are bound by confidentiality.
- Protect it with reasonable technical and organizational measures, described below.
- Help you respond to requests from your end users to access, correct, or delete their information, mainly through the tools in the Service, and otherwise if you email us. If an end user contacts us directly, we'll refer them to you.
- Notify you of a security breach affecting End User Data without undue delay, and within 72 hours of confirming it where feasible, with the information you reasonably need to meet your own obligations.
- Delete End User Data when your organization is closed, within 30 days after the export period in the Terms, except copies in backups (overwritten on a rolling schedule) and data we must keep by law.
- Give you information reasonably needed to show compliance with this DPA, such as answers to security questionnaires, once a year or after a breach. You may object if we cease to comply, and we'll work with you to fix it.
- Comply with Privacy Laws that apply to us as your service provider, and tell you if we can no longer meet our obligations under them.
Security measures
- Encryption in transit for all traffic to sites and the dashboard
- Hosting in the United States behind a network firewall and DDoS protection
- Encrypted backups
- Encryption of connected-account tokens and secrets
- Hashed passwords and API keys, two-factor authentication, and role-based access
- Logged staff access to customer accounts
- Typed text in session recordings is always masked
- Spam screening on forms, and sending limits on email
Subprocessors
You authorize BrightSite to use subprocessors for hosting, network security, storage, email delivery, payments, AI features, and search and review data. We require each to protect End User Data with obligations at least as protective as this DPA, and we're responsible for their compliance. Our current list is available on request at support@onbrightsite.com.
Services you choose to connect (such as analytics tools, social networks, and your own form webhooks) receive data at your direction and aren't our subprocessors.
We'll notify you at least 30 days before adding a new subprocessor that will process End User Data, except in an emergency. To be notified, email support@onbrightsite.com with "Subprocessor updates" in the subject line. You can object on reasonable data protection grounds by emailing us within that period. If we can't resolve your objection, you can close your organization, and we'll refund prepaid fees for the remaining period.
International transfers
We process End User Data mainly in the United States. If you're subject to data protection laws outside the United States that require a transfer mechanism, contact us before you collect that data through BrightSite.
Liability and term
This DPA lasts as long as we process End User Data for you. Each party's liability under this DPA is subject to the limitations in the Terms. If this DPA conflicts with the Terms about End User Data, this DPA controls.
Contact
BrightSite, Inc.
support@onbrightsite.com (subject "Data protection")
(617) 682-9368