BBrakan

Policy centre

Data processing terms

Last updated: 29 August 2026

Draft Article 28 contract terms for customer-controlled personal information processed through Brakan.

Launch draft — not operative until incorporated into an identified Services Agreement and completed with the contracting parties’ details

Contract status and parties

Once expressly incorporated into an executed or electronically accepted services agreement, order form or equivalent agreement (the “Services Agreement”), these Data Processing Terms form part of that agreement and bind the customer identified there and the identified Brakan supplier entity. They prevail over conflicting general terms only to the extent of the conflict concerning processing of Customer Personal Data.

The contracting Brakan legal name, registered or principal address, company number where applicable, customer identity, effective date and acceptance evidence must appear in the Services Agreement. Those facts are not yet finalised, so this launch draft must not be represented as an operative commercial DPA.

Definitions

  • Customer Personal Data means personal data processed by Brakan on the customer’s behalf through the services.
  • Data Protection Laws means the UK GDPR, Data Protection Act 2018 and other applicable UK laws concerning that processing.
  • Personal Data Breach has the meaning given in the UK GDPR.
  • Subprocessor means another processor engaged by Brakan to process Customer Personal Data.
  • Controller, processor, data subject, personal data, processing and supervisory authority have their meanings under Data Protection Laws.

Roles and separate controller activities

For Customer Personal Data, the customer is controller and Brakan is processor, except where law expressly determines otherwise. Brakan acts as an independent controller for its own contracting contacts, account administration, billing, direct support relationship, service security and fraud-prevention records, legal compliance and establishment or defence of legal claims. Those activities are governed by Brakan’s Privacy Notice, not these processor terms.

Brakan will not use Customer Personal Data for independently determined product development or general-purpose model training. Service improvement under these terms is limited to processing needed to maintain, secure and support the contracted service, plus anonymous or properly aggregated information that is no longer personal data.

Subject matter, duration, nature and purpose

  • Subject matter: hosted property-management, accounting, communication, document, compliance and authorised integration services described in the Services Agreement.
  • Duration: the Services Agreement term and the documented return, deletion, backup-expiry and lawful-hold periods following it.
  • Nature: collection, recording, organisation, structuring, storage, retrieval, consultation, use, transmission to authorised recipients, reconciliation, backup, restriction and deletion, only where necessary to provide the services.
  • Purpose: to provide, secure, maintain and support the customer’s authorised use of Brakan in accordance with the Services Agreement and documented instructions.

People and information covered

  • Data subjects: customer users, landlords, tenants, prospective tenants, guarantors, contractors, agents, correspondents and other people represented in authorised property records.
  • Personal data: identity and contact details; property and tenancy records; rent, expense and bank-transaction records; communications; documents and images; compliance evidence; and service security and audit metadata.
  • Special-category or criminal-offence information may be processed only where necessary for an authorised property-management purpose and where the customer has identified an applicable Article 9 condition, Data Protection Act 2018 condition and appropriate policy document where required.
  • Biometric identification templates, unrelated criminal profiling and personal data unrelated to the services are prohibited unless the parties first agree documented additional controls and lawful instructions.

Documented instructions

Brakan shall process Customer Personal Data only on the customer’s documented instructions, including instructions concerning international transfers, unless applicable UK law requires processing. Where legally permitted, Brakan shall inform the customer of that requirement before processing. The Services Agreement, authorised product configuration, support requests and written directions from authorised customer contacts constitute documented instructions.

Brakan shall immediately inform the customer if, in its opinion, an instruction infringes Data Protection Laws. Brakan may pause the affected processing while the parties clarify or amend that instruction.

Confidentiality and security

Brakan shall ensure that each person authorised to process Customer Personal Data is subject to an appropriate statutory or contractual duty of confidentiality. Taking account of the matters identified in Article 32 UK GDPR, Brakan shall implement and maintain technical and organisational measures appropriate to the risk, as described in the Security Schedule. Brakan will not materially reduce those protections during the Services Agreement term without advance notice.

Assistance

Taking account of the nature of processing and, where relevant, information available to Brakan, Brakan shall assist the customer through appropriate technical and organisational measures with data-subject requests and with the customer’s obligations concerning security, breach assessment and notification, data-protection impact assessments and prior consultation with supervisory authorities. Brakan shall maintain records and cooperate with the Information Commissioner where Data Protection Laws impose a direct duty on Brakan.

Personal-data breaches

Brakan shall notify the customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, with an operational target of an initial notice within 24 hours. The notice will provide available facts needed to assess, mitigate and report the incident, including its nature, likely consequences, affected data and people where known, containment and contact details. Brakan shall investigate, mitigate and provide material updates as information becomes available.

Brakan shall not notify affected people or a supervisory authority on the customer’s behalf unless the customer instructs it to do so or applicable law requires it. A notification is not an admission of fault or liability.

Subprocessors

The customer gives general written authorisation for the subprocessors on the published Subprocessor List when accepting these terms. Brakan shall provide at least 30 days’ advance notice of an intended addition or replacement and allow a reasonable objection on data-protection grounds, subject to the procedure on that list. Brakan shall impose the same applicable data-protection obligations by written contract and remains responsible to the customer for each subprocessor’s performance.

Return, deletion and legal retention

At the customer’s choice, Brakan shall return Customer Personal Data in an available structured export format or delete it following termination, and shall delete remaining copies, unless applicable law binding Brakan requires retention. The commercial Services Agreement must state the instruction method, export availability period and primary-system deletion timetable before paid launch.

Data remaining in encrypted disaster-recovery backups will be put beyond ordinary use, remain protected, and expire under the published retention schedule. Data subject to a documented legal hold or mandatory legal retention will remain protected, will not be used for another purpose and will be deleted when the hold or requirement ends. Brakan shall provide deletion confirmation on written request where technically and legally possible.

Compliance information and audits

Brakan shall make available all information necessary to demonstrate compliance with Article 28 UK GDPR and shall allow for and contribute to audits and inspections by the customer or its independent auditor. Reasonable notice, confidentiality, security, scope coordination and cost arrangements may apply, but shall not materially restrict a legally required audit or regulator access. Existing independent reports and written evidence may be used first where they adequately address the request.

Customer obligations

  • Give lawful, fair and accurate instructions and maintain an appropriate lawful basis and transparency for Customer Personal Data.
  • Determine whether special-category or criminal-offence processing is necessary and document every additional condition or policy required by UK law.
  • Use suitable roles, secure accounts and respond as controller to data-subject requests and incidents within the customer’s responsibility.
  • Do not instruct Brakan to process unlawfully obtained, prohibited or unrelated information.

Transfers, precedence and survival

The Security Schedule, International Transfer Schedule, Subprocessor List and Services Agreement form part of these terms. The International Transfer Schedule must identify actual processing locations, which party initiates each restricted transfer, any UK adequacy regulation, UK IDTA or UK Addendum, transfer-risk assessment and supplementary safeguards before a paid service involving that transfer begins.

Confidentiality, security, audit, return, deletion and liability obligations survive termination for as long as relevant Customer Personal Data remains. Liability, governing law, jurisdiction, charges for extraordinary assistance and formal notices are governed by the Services Agreement and must be completed before commercial acceptance.

Privacy and security contact

Operational privacy and security notices may be sent to support@mail.brakan.co.uk until a dedicated contractual notice address and the Brakan supplier identity are inserted into the Services Agreement.

BrakanPrivate UK pilot · not yet a public paid service
PricingTermsPrivacyFair usageAcceptable useCookiesSecuritySubprocessorsRetentionComplaintsAccessibilityData processingSecurity scheduleTransfersOpen BankingAI & automationSubscriptions
support@mail.brakan.co.uk