Last updated: July 19, 2026
Data Processing Agreement
This Data Processing Agreement ("DPA") is between Index Brain ("Processor") and the customer organization ("Controller") that has accepted the Indexbrain Terms of Service. This DPA applies wherever Indexbrain processes personal data on behalf of the Controller.
Where this DPA conflicts with the Terms of Service on matters relating to personal data processing, this DPA takes precedence.
1. Definitions
"Personal Data" means any information relating to an identified or identifiable natural person that the Controller submits to the service.
"Processing" means any operation performed on Personal Data, including reading, extracting, storing, and transmitting.
"Controller" means the customer organization that determines the purposes and means of processing.
"Processor" means Index Brain, which processes Personal Data on behalf of the Controller.
"Sub-processor" means any third party engaged by the Processor to assist in processing Personal Data.
2. Scope and nature of processing
Indexbrain processes data from integrations the Controller connects. This includes:
- Email content from Gmail (sender, recipient, subject, body)
- Messages from Slack (channel, author, content, timestamps)
- Documents from Notion (page content, authors, metadata)
- Code and activity from GitHub (commits, pull requests, issues)
- Meeting notes from Granola and Fathom
- AI conversation transcripts uploaded by the Controller
Important: Indexbrain does not store raw source content. We read content, extract structured knowledge, and store only the extracted knowledge - not the original emails, messages, or documents.
3. Controller obligations
- Ensure a lawful basis under applicable data protection law for connecting each data source
- Not connect data sources containing special categories of personal data without explicit written agreement
- Promptly inform Index Brain of any data subject requests received
4. Processor obligations
Index Brain agrees to:
- Process Personal Data only on documented instructions from the Controller
- Ensure all personnel with access are subject to confidentiality obligations
- Implement and maintain appropriate technical and organizational security measures
- Assist the Controller in responding to data subject rights requests
- Delete all Personal Data upon termination of the service
- Not process Personal Data for any purpose other than providing Indexbrain
5. Security measures
- Encryption in transit: all data transmitted using TLS 1.2 or higher
- Encryption at rest: all stored data encrypted using AES-256
- Access controls: least-privilege access across all systems
- Data isolation: complete logical separation between customer accounts
- OAuth token security: integration tokens stored encrypted
- Audit logging: all data access and modification events logged
6. Sub-processors
By accepting this DPA, the Controller provides general authorization for the use of the following sub-processors. We will notify the Controller at least 30 days before adding or replacing any sub-processor.
7. Data subject rights
If Indexbrain receives a request from a data subject, we will forward it to the Controller. The Controller is responsible for responding. Indexbrain will assist by providing technical means to access, correct, export, or delete relevant data.
8. Data retention and deletion
Extracted knowledge is retained while the Controller's account is active or until deleted. Raw source content is never stored. Upon account deletion, all data is permanently deleted within 24 hours. Written confirmation is available upon request.
9. Data breach notification
In the event of a confirmed breach, Indexbrain will notify the Controller within 72 hours, including: nature of the breach, categories and approximate number of individuals affected, likely consequences, and measures taken to address it.
10. International data transfers
Personal Data is stored and processed in the United States. For transfers from the EEA, UK, or Switzerland, we rely on standard contractual clauses or other appropriate mechanisms. Controllers subject to GDPR may request a copy by contacting us.
11. Audits
The Controller may request an audit of our data processing practices with at least 30 days notice. Audits must not disrupt our operations or compromise other customers' security. The Controller bears the cost of any audit.
12. Termination
This DPA remains in effect while Indexbrain processes Personal Data on behalf of the Controller. Upon termination, all Personal Data is permanently deleted within 24 hours. The Controller may request a data export before deletion at no charge.
Questions? Email legal@indexbrain.online
Indexbrain © 2026