Legal
Data Processing Agreement
One agreement. Both regimes.Our DPA covers GDPR and LGPD in a single signable document, pre-signed by Basient — countersign and you're done.
What it covers
Roles
Customer is controller; Basient is processor/operador. Documented instructions only.
Scope & duration
Workload data and usage metadata, for the life of the contract; deletion or return within 30 days of termination.
Security measures (Annex II)
TLS 1.3, AES-256, vault-held secrets, SOC 2 Type II controls, access reviews, pen tests. Mirrors the Trust Center.
Subprocessors
General authorization with 30-day advance notice and objection right. Model providers are listed subprocessors, bound to zero-retention terms where offered.
Transfers
EU: SCCs (Module 2) incorporated. Brazil: LGPD art. 33 safeguards. Residency pinning available to avoid transfers entirely.
Data subject requests
We forward within 72 h and provide tooling; responding remains the controller's duty.
Breach notification
Without undue delay, no later than 48 h after confirmation, with scope, impact and mitigation.
Audits
SOC 2 report + security packet satisfy audit rights; on-site audits on Enterprise, once per year, 30-day notice.
Questions
privacy@basient.com — or ask for a redline session on Enterprise agreements.