DPA

Version 1.0 – 01/01/2026

This Data Processing Agreement (“DPA”) forms part of and supplements the Client Terms & Conditions between Born Studio, a trading name of Born Solutions, a company duly registered in Brazil (“Processor”), and the client (“Controller”).

This DPA applies where the Processor processes Personal Data on behalf of the Controller in the course of providing services.

Definitions

“Personal Data”, “Processing”, “Controller”, “Processor”, “Data Subject” and “Supervisory Authority” shall have the meanings given to them under Regulation (EU) 2016/679 (General Data Protection Regulation, “GDPR”).

Nature and Purpose of Processing

The Processor shall process Personal Data solely for the purpose of performing the services described in the relevant proposal or agreement, including but not limited to website development, hosting configuration, maintenance, analytics implementation and related digital services.

Categories of Data Subjects

Depending on the nature of the services, Data Subjects may include:

  • Website visitors.
  • Customers of the Controller.
  • Prospective customers.
  • Employees or contractors of the Controller.

Categories of Personal Data

The categories of Personal Data processed may include:

  • Names.
  • Email addresses.
  • Telephone numbers.
  • IP addresses.
  • Technical usage data.
  • Contact form submissions.
  • Any other data collected via the Controller’s website or systems.

Processing activities may include collection, storage, organisation, consultation, transmission, deletion or destruction.

Processor Obligations

The Processor shall:

  • Process Personal Data only on documented instructions from the Controller.
  • Ensure that persons authorised to process Personal Data are subject to confidentiality obligations.
  • Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk.
  • Assist the Controller in responding to Data Subject rights requests.
  • Assist the Controller in ensuring compliance with Articles 32 to 36 of the GDPR where applicable.
  • Notify the Controller without undue delay after becoming aware of a Personal.

Data Breach

Security Measures

The Processor shall implement appropriate technical and organisational measures, including but not limited to:

  • Secure hosting environments.
  • Access control and authentication procedures.
  • Encrypted connections (HTTPS/SSL).
  • Regular software updates and security patches
• Backup and recovery procedures where applicable.

The Controller acknowledges that no system can guarantee absolute security, but reasonable and industry-standard safeguards shall be applied.

Sub-processors

The Processor may engage sub-processors where necessary to provide services, including hosting providers, infrastructure providers, analytics tools or software platforms.

The Processor shall ensure that any sub-processor is bound by contractual obligations that provide at least the same level of data protection as those set out in this DPA.

The Controller authorises the Processor to use such sub-processors as necessary for service delivery.

International Transfers and Standard Contractual Clauses

The Processor is established in Brazil, which is not currently subject to an adequacy decision by the European Commission under Article 45 of the GDPR.

Where the provision of services involves the transfer of Personal Data from the European Economic Area (EEA) to Brazil or any other third country without an adequacy decision, such transfers shall be governed by the Standard Contractual Clauses adopted by the European Commission pursuant to Article 46(2)(c) of the GDPR (Commission Implementing Decision (EU) 2021/914).

For the purposes of such transfers:

  • The Client acts as Data Exporter.
  • Born Studio / Born Solutions acts as Data Importer.
  • Module Two (Controller to Processor) applies.
  • Where applicable, Module Three (Processor to Sub-processor) applies.

The technical and organisational measures described in this DPA shall form Annex II to the Standard Contractual Clauses.

By entering into an agreement for services, the parties agree that the Standard Contractual Clauses are deemed incorporated into this DPA.

Data Subject Rights

The Processor shall, taking into account the nature of the processing, assist the Controller in fulfilling its obligations to respond to requests from Data Subjects exercising their rights under the GDPR.

The Controller remains responsible for responding to Data Subject requests.

Personal Data Breach

In the event of a Personal Data Breach, the Processor shall notify the Controller without undue delay after becoming aware of the breach and shall provide sufficient information to allow the Controller to meet any obligations to report or inform affected Data Subjects.

Deletion or Return of Data

Upon termination of the services, the Processor shall, at the Controller’s choice, delete or return all Personal Data to the Controller unless retention is required by applicable law.

Audit Rights

Upon reasonable notice, the Controller may request information necessary to demonstrate compliance with this DPA. Any audit shall be proportionate and shall not unreasonably disrupt the Processor’s business operations.

Liability

Each party’s liability under this DPA shall be subject to the limitations set out in the Client Terms & Conditions.

Governing Law

This DPA shall be governed by the law specified in the applicable service agreement between the parties.

Severability

If any provision of this DPA is held invalid or unenforceable, the remaining provisions shall remain in full force and effect.

This DPA forms part of and is incorporated into the Client Terms & Conditions.