Brightidea Sub-processors


Last Modified: 05/10/2024

Brightidea Sub-Processors

Brightidea, Inc. (“Brightidea”) uses certain Sub-processors and content delivery networks to assist it in delivering the Services described in the Master Services Subscription Agreement (MSA), Order Form, SoW or similar commercial agreement.

What is a Sub-processor:

A Sub-processors is a third-party data processor engaged by Brightidea, who has or potentially will have access to or Process Customer Data (which may contain Personal Data). Brightidea engages different types of Sub-processors to perform various functions as explained in the table below.

Due Diligence:

Brightidea undertakes to use a commercially reasonable selection process by which it evaluates the security, privacy, and confidentiality practices of proposed Sub-processors that will or may have access to or Process Customer Data.

Contractual Safeguards:

Brightidea requires its Sub-processors to satisfy equivalent obligations as those required from Brightidea (as a Data Processor) as set forth in Brightidea’s Data Processing Agreement (DPA), including but not limited to the requirements to:

  • Process Personal Data in accordance with data controller’s (i.e. Customer's) documented instructions;
  • In connection with their Processing activities, use only personnel who are reliable and subject to a contractually binding obligation to observe data privacy and security, to the extent applicable, pursuant to applicable Data Protection Laws and Regulations;
  • Provide regular training in security and data protection to personnel to whom they grant access to Personal Data;
  • Implement and maintain appropriate technical and organizational measures (including measures consistent with those to which Brightidea is contractually committed to adhere insofar as they are equally relevant to the Sub-processor’s Processing of Personal Data on Brightidea’s behalf) and provide certification that evidences compliance with this obligation. In the absence of such certification Brightidea reserves the right to audit the Sub-processor;
  • Promptly inform Brightidea about any actual or potential security breach; and
  • Cooperate with Brightidea in order to deal with requests from data controllers, data subjects or data protection authorities, as applicable.

This article does not give Customers any additional rights or remedies and should not be construed as a binding agreement. The information herein is only provided to illustrate Brightidea’s engagement process for Sub-processors as well as to provide the list of Sub-processors and content delivery networks used by Brightidea as of the date of this article (which Brightidea may use in the delivery and support of its Services).

If you are a Brightidea Customer and wish to enter into our DPA, please email us at data-privacy@brightidea.com.

Process to Engage New Sub-processors:

For all Customers who have executed Brightidea’s standard DPA, Brightidea will provide notice via the Brightidea Support portal of updates to the list of sub-processors that are utilized or which Brightidea proposes to utilize to deliver its Services as described in section 5.2 of Brightidea's DPA. Brightidea undertakes to keep this list updated regularly to enable its Customers to stay informed of the scope of Sub-processing associated with the Brightidea Services.

Pursuant to the DPA, a Customer can object in writing to the Processing of its Personal Data by a new Sub-processor within thirty (30) days after the updating of this article and shall describe its legitimate reason(s) for objection. If Customer does not object during such time period, the new Sub-processor(s) shall be deemed accepted.

If a Customer objects to the use of a new Sub-processor pursuant to the process provided under section 5.3 of the DPA, Brightidea shall have the right to cure the objection through one of the following options (to be selected at Brightidea’s sole discretion):

  • Brightidea will cease to use the new Sub-processor with regard to Personal Data;
  • Brightidea will take the corrective steps requested by Customer in its objection (which steps will be deemed to resolve Customer’s objection) and proceed to use the Sub-processor to Process Personal Data; or
  • Brightidea may cease to provide or Customer may agree not to use (temporarily or permanently) the particular aspect of a Brightidea Service that would involve use of the Sub-processor to process Personal Data.

The following is an up-to-date list (as of the date of this policy) of the names and locations of Brightidea Sub-processors and content delivery networks: 

Infrastructure Sub-Processors:

Brightidea owns or controls access to the infrastructure that Brightidea uses to host Customer Data submitted to the Services, other than as set forth below. Currently, the Brightidea production systems for the Services are located in co-location facilities in the United States and Europe and in the infrastructure Sub-processors listed below. Customer accounts are typically established in one of these regions based on where the Customer is located but may be shifted among locations to ensure performance and availability of the Services. The following table describes the countries and legal entities engaged by Brightidea in the storage of Customer Data. Brightidea also uses additional services provided by these Sub-processors to Process Customer Data as needed to provide the Services.

 Entity Name

 Entity Type

 Entity Country

 Amazon Web Services, Inc.

 Cloud Service Provider

 United States, Ireland

 

Service Specific Sub-Processors:

Brightidea works with certain third parties to provide specific functionality within the Services. These providers are the Sub-processors set forth below. In order to provide the relevant functionality these Sub-processors may access or process Service Data. Their use is limited to the indicated Services.

 Entity Name

 Purpose

 Entity Country

 SolarWinds Worldwide, LLC

Connectivity logging and monitoring via Papertrail

 United States

 Functional Software, Inc

Error reporting via Sentry

 United States

 Intercom, Inc.

Live Support and customer engagement

 United States

 Box, Inc.

Storage

 United States

 Mailgun Technologies, Inc.

Email service provider

 United States

Zoominfo

Conversation Intelligence Tool

United States

Appcues

Customer education

United States

Heap

OPTIONAL: Analytics

United States

OpenAI, L.L.C

OPTIONAL: Generative Artificial Intelligence

No Hosting of Service Data

 

Content Delivery Networks:

Brightidea’s Services use content delivery networks (“CDNs”) to provide the Services, for security purposes, and to optimize content delivery. CDNs do not have access to Customer Data but are commonly used systems of distributed services that deliver content based on the geographic location of the individual accessing the content and the origin of the content provider. Website content served to website visitors and domain name information may be stored with a CDN to expedite transmission, and information transmitted across a CDN may be accessed by that CDN to enable its functions. The following describes use of CDNs by Brightidea’s Services.

 CDN Provider

 CDN Location

 Description of CDN Services

 Amazon Web Services, Inc.

 Global

 Public website content served to website visitors may be stored with Amazon   Web Services, Inc., and transmitted by Amazon Web Services, Inc., to website   visitors, to expedite transmission.

Was this article helpful?
0 out of 0 found this helpful
Have more questions? Submit a request

Comments