DATA PROCESSING AGREEMENT

Last updated July 15, 2026

This Data Processing Agreement ("DPA") forms part of the agreement between CMO Success, LLC, a California limited liability company doing business as Bright Growth ("Bright Growth"), and the customer identified in the applicable engagement agreement, order form, or Terms of Service (the "Customer") governing Customer's use of Bright Growth's services, including the AI CMO Operating System Platform at app.brightgrowth.io (the "Agreement"). This DPA applies to the extent Bright Growth processes Customer Personal Data (defined below) on Customer's behalf.

Order of precedence. If there is a conflict, the Standard Contractual Clauses (where they apply) prevail over this DPA, and this DPA prevails over the Agreement with respect to the processing of Customer Personal Data.

1. Definitions

1.1 "Data Protection Laws" means all laws applicable to the processing of personal data under the Agreement, including, as applicable, the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018, the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA"), the Virginia Consumer Data Protection Act, and other comprehensive US state privacy laws.

1.2 "Customer Personal Data" means personal data or personal information contained in Customer Content that Bright Growth processes on Customer's behalf.

1.3 "Customer Content" means documents, information, and materials Customer or its authorized users provide to Bright Growth in connection with an engagement, including materials uploaded to Customer's workspace on the Platform and materials contributed to that workspace by a Specialist Consultant.

1.4 "Platform" means the AI CMO Operating System Platform at app.brightgrowth.io.

1.5 "Specialist Consultant" means a third-party functional expert who participates in Customer's engagement under a direct contract with Customer, as described in Section 6.5.

1.6 "Standard Contractual Clauses" or "SCCs" means the standard contractual clauses approved by European Commission Implementing Decision (EU) 2021/914 for transfers to processors (Module Two).

1.7 "Subprocessor" means a third party engaged by Bright Growth to process Customer Personal Data on Bright Growth's behalf.

1.8 The terms "controller," "processor," "data subject," "personal data," "personal data breach," and "processing" have the meanings given in the GDPR; "business," "service provider," "sell," and "share" have the meanings given in the CCPA.

2. Roles and scope

2.1 Bright Growth as a processor. For Customer Personal Data contained in Customer Content, Customer is the controller (or a processor acting for another controller) and Bright Growth is a processor (and, under the CCPA, a service provider).

2.2 Bright Growth as an independent controller. Bright Growth acts as an independent controller — and this DPA does not apply — for (a) account and administrative data of Customer's users (signup email address, authentication and security logs, internal signup notifications), and (b) data Bright Growth compiles independently of Customer, including its Investor Directory, Partner (Vendor) Directory, and industry benchmark data. Bright Growth's processing as a controller is described in its privacy notice at brightgrowth.io/privacy.

2.3 Details of processing are set out in Annex I.

3. Customer instructions

3.1 Bright Growth will process Customer Personal Data only on Customer's documented instructions, including with regard to international transfers, unless required to do otherwise by law to which Bright Growth is subject (in which case Bright Growth will inform Customer of that legal requirement before processing, unless the law prohibits doing so). The Agreement, this DPA, and Customer's use of the Platform's features constitute Customer's documented instructions.

3.2 Bright Growth will promptly inform Customer if, in its opinion, an instruction infringes Data Protection Laws.

4. Customer obligations

4.1 Customer is responsible for the lawfulness of the Customer Personal Data it provides, including having any necessary notices, consents, and legal bases to share it with Bright Growth for processing under the Agreement — including personal data about Customer's own personnel appearing in uploaded documents or in Specialist Consultant interview notes.

4.2 Data Customer must not provide. Customer will not upload or otherwise provide (a) contact-level records of Customer's own customers or prospects (names, email addresses, phone numbers), or (b) sensitive or special-category personal data (including health information, government identifiers, and financial account numbers). The Platform and the Services are not designed for either. Bright Growth's obligations under this DPA do not extend to data provided in breach of this Section, other than to delete it on discovery or request.

5. Confidentiality

5.1 Bright Growth will ensure that persons it authorizes to process Customer Personal Data are bound by written confidentiality obligations or are under an appropriate statutory duty of confidentiality, and access Customer Personal Data only as needed to deliver the engagement.

6. Subprocessors and other recipients

6.1 General authorization. Customer authorizes Bright Growth to engage the Subprocessors listed in Annex III.

6.2 Changes. Bright Growth will give Customer at least thirty (30) days' written notice (email to Customer's designated contact suffices) before adding or replacing a Subprocessor that will process Customer Personal Data. Customer may object in writing on reasonable data-protection grounds within that period; the parties will work in good faith to resolve the objection, and if they cannot, Customer may terminate the affected services and receive a pro-rata refund of prepaid fees.

6.3 Current list. Bright Growth will maintain the current Subprocessor list in Annex III and keep it consistent with the subprocessor disclosures in its published privacy notice.

6.4 Flow-down. Bright Growth will impose on each Subprocessor, by written agreement, data protection obligations materially no less protective than those in this DPA, and remains liable to Customer for each Subprocessor's performance.

6.5 Specialist Consultants are not Subprocessors. Specialist Consultants contract directly with the Customer. Where a Specialist Consultant participates in Customer's engagement, Bright Growth may share Customer Content relevant to the consultant's portion of the work, at or with Customer's direction, and the consultant's confidentiality and data-handling obligations are established by Customer's agreement with the consultant. Bright Growth makes no representations or warranties regarding a Specialist Consultant's data practices, and processing performed by a Specialist Consultant outside the Platform is outside the scope of this DPA.

7. Security and personal data breach

7.1 Bright Growth will implement and maintain the technical and organizational measures described in Annex II, and may update them from time to time provided the updates do not materially reduce the overall level of protection.

7.2 Bright Growth will notify Customer without undue delay, and in any event within seventy-two (72) hours of confirming a personal data breach affecting Customer Personal Data. The notification will describe, to the extent then known, the nature of the breach; the categories and approximate volume of data and data subjects affected; the likely consequences; the measures taken or proposed; and a point of contact. Bright Growth will provide timely updates as material information becomes available. Bright Growth's notification is not an admission of fault.

8. Assistance

8.1 Data subject requests. Taking into account the nature of the processing, Bright Growth will assist Customer by appropriate technical and organizational measures in fulfilling Customer's obligations to respond to data subject requests (access, rectification, erasure, restriction, portability, objection). If Bright Growth receives such a request directly and can identify it as relating to Customer, it will forward the request to Customer without undue delay and will not respond substantively except to direct the requester to Customer, unless legally required.

8.2 DPIAs and consultations. Bright Growth will provide reasonable assistance with data protection impact assessments and prior consultations with supervisory authorities, to the extent the required information is in Bright Growth's possession.

9. Return and deletion

9.1 During the engagement, Customer's users may export their uploaded documents on request to privacy@brightgrowth.io.

9.2 Upon termination or expiry of the Agreement, or earlier on Customer's written request, Bright Growth will delete or return (at Customer's choice) Customer Personal Data within thirty (30) days, except to the extent retention is required by law or the data resides in routine backups, in which case Bright Growth will isolate the data from further processing and delete it in the ordinary course of its backup cycle. Bright Growth will confirm completion in writing on request.

10. Audit and information rights

10.1 Bright Growth will make available to Customer information reasonably necessary to demonstrate compliance with this DPA, including by completing Customer's written security questionnaires (no more than once per twelve-month period, absent a personal data breach or material change).

10.2 Bright Growth will provide copies of third-party security attestations or audit reports as and when they become available. (Customer acknowledges that, as of the DPA effective date, Bright Growth has not yet completed a SOC 2 or ISO 27001 audit; its current measures are described in Annex II.)

10.3 Where Data Protection Laws grant Customer a mandatory audit right that cannot be satisfied under 10.1–10.2, Customer (or an independent auditor that is not a Bright Growth competitor, bound by confidentiality) may audit Bright Growth's relevant processing operations, no more than once per twelve-month period, on at least thirty (30) days' notice, during business hours, at Customer's expense, in a manner that does not permit access to any other customer's data.

11. International transfers

11.1 Bright Growth is based in the United States, and Customer Personal Data is processed in the United States (and in other countries where Subprocessors operate, as listed in Annex III).

11.2 Where Customer transfers personal data subject to the GDPR to Bright Growth, the SCCs (Module Two: controller-to-processor) are incorporated into this DPA by reference, completed as follows: Clause 7 (docking) included; Clause 9 Option 2 (general authorization, 30 days' notice); Clause 11 optional language not included; Clause 17 governed by Irish law; Clause 18 courts of Ireland; Annexes I–III of this DPA serve as the SCC Annexes.

11.3 For transfers subject to the UK GDPR, the SCCs apply as amended by the UK International Data Transfer Addendum (mandatory clauses of the ICO Addendum B1.0); for Swiss transfers, the SCCs apply with the adaptations required by the Swiss FDPIC (references to the GDPR read as the Swiss FADP; supervisory authority: FDPIC).

11.4 Bright Growth does not currently rely on the EU-U.S. Data Privacy Framework.

12. CCPA service-provider terms

12.1 Bright Growth is a "service provider" with respect to Customer Personal Data. Bright Growth will not (a) sell or share Customer Personal Data; (b) retain, use, or disclose it for any purpose other than performing the services under the Agreement or as permitted by the CCPA; (c) retain, use, or disclose it outside the direct business relationship with Customer; or (d) combine it with personal information it receives from other sources, except as permitted by the CCPA. Bright Growth certifies that it understands and will comply with these restrictions and will notify Customer if it determines it can no longer meet its CCPA obligations, in which case Customer may take reasonable steps to stop and remediate unauthorized use.

13. AI processing

13.1 Bright Growth may use AI-assisted tools, including large language models accessed through a commercial Anthropic (Claude) account, on or off the Platform, to augment the services — including analyzing Customer Content and drafting Customer's audit, plan, and execution deliverables.

13.2 Bright Growth will use only AI provider accounts whose commercial terms provide that customer-submitted content is not used to train the provider's models absent a separate opt-in, and Bright Growth will not opt Customer Content into any such training.

13.3 Deliverables are prepared and reviewed by Bright Growth personnel. Bright Growth does not use Customer Personal Data to make automated decisions producing legal or similarly significant effects concerning any individual (GDPR Art. 22).

13.4 Any addition of a new AI provider that will process Customer Content is a Subprocessor change subject to Section 6.2.

14. Liability, term, and general

14.1 Each party's liability arising out of or related to this DPA (including the SCCs) is subject to the exclusions and limitations of liability in the Agreement, except where Data Protection Laws do not permit such limitation.

14.2 This DPA takes effect on the effective date of the Agreement and remains in force as long as Bright Growth processes Customer Personal Data, surviving termination of the Agreement until all Customer Personal Data is deleted or returned under Section 9.

14.3 This DPA is governed by the law governing the Agreement (California), except where the SCCs require otherwise.

Annex I — Details of processing

A. List of parties. Data exporter: Customer (controller), as identified in the Agreement; contact per the Agreement. Data importer: CMO Success, LLC dba Bright Growth (processor), 946 Teresita Blvd, San Francisco, CA 94127, USA; privacy@brightgrowth.io.

B. Description of transfer/processing.

  • Subject matter and nature: hosting, storage, organization, analysis (including AI-assisted analysis per Section 13), and preparation of deliverables from Customer Content to deliver marketing audit, plan, and execution services.

  • Duration: the term of the Agreement, plus the deletion period in Section 9.

  • Categories of data subjects: Customer's employees and other personnel; Customer's authorized Platform users; individuals incidentally referenced in Customer Content (e.g., personnel named in documents or in Specialist Consultant interview notes).

  • Categories of personal data: business contact and professional information (names, titles, work contact details); personal data incidentally contained in business documents; Platform user account data to the extent processed on Customer's behalf.

  • Excluded data (per Section 4.2): contact-level records of Customer's own customers or prospects; sensitive/special-category data. Not intentionally processed.

  • Frequency: continuous during the engagement.

  • Retention: duration of active engagement; deletion per Section 9.

C. Competent supervisory authority (where the SCCs apply): determined per SCC Clause 13 based on the data exporter's establishment or representative.

Annex II — Technical and organizational measures

Stated as actually implemented as of 2026-07-15; updated as Bright Growth's security roadmap progresses.

  • Tenant isolation: database-level, row-level security that scopes every read and write to the user's organization; each customer workspace is isolated from every other customer's, enforced per-command in the database, not only in application code.

  • Storage access control: customer documents reside in private, organization-scoped storage; object downloads are gated by the same database-level access rules (an object is retrievable only if the caller can see its catalog record).

  • Role-based access: owner/admin/member roles with per-document minimum-role gating; unclassified documents default to deny.

  • Access provisioning: accounts obtain workspace membership only through Bright Growth-issued invitations; no self-service joining of another organization's workspace. New-account creation triggers an internal notification for review.

  • Encryption in transit: HTTPS/TLS across the Platform and websites.

  • Authentication: passwords are hashed and managed by the authentication provider; Bright Growth has no access to plaintext credentials.

  • Least-privilege internal access: internal access is limited to personnel who need it to operate the services and deliver the engagement.

  • Infrastructure: hosted on the providers listed in Annex III, each operating its own certified data centers and platform security programs.

  • Certifications: Bright Growth itself does not yet hold SOC 2 or ISO 27001; a certification roadmap is in progress, and reports will be made available under Section 10.2 when they exist.

Annex III — Subprocessors

Supabase, Inc. — authentication, database, and private file storage for Platform workspaces. Location: USA (us-east-1).

Netlify, Inc. — hosting and serving of the Platform. Location: USA.

Resend, Inc. — transactional email (confirmations, password resets, invitations) and internal account-creation notifications. Location: USA.

Anthropic, PBC — AI-assisted analysis and drafting via a commercial account, used by Bright Growth on or off the Platform (Section 13). Location: USA.

Note: Platform pages load open-source script libraries and fonts from content delivery networks (currently jsDelivr and Google Fonts), which receive user IP addresses and standard technical request data to serve those files; they do not receive Customer Content. Google (Analytics/Tag Manager) and Squarespace serve only Bright Growth's marketing site and do not process Customer Content.

Execution. This DPA is incorporated by reference into the Agreement and takes effect without signature. Customers who require a countersigned standalone copy for their records may request one at privacy@brightgrowth.io.