Legal
Data processing addendum
Effective 25 September 2026. Briare Brothers LLC, 30 N Gould St Ste N, Sheridan, WY 82801.
Scope and roles
This addendum forms part of the terms of service between Briare Brothers LLC ("Badgewright", "we") and the customer ("you"). It applies whenever we process Personal Data contained in Customer Data on your behalf.
You are the controller and the business. We are the processor and the service provider. You determine the purposes and means of processing; we act only on your documented instructions. Where you are yourself a processor for another controller, we are the subprocessor and everything here applies with that reading.
No signature is needed: this is in force for every customer as part of the terms. If your procurement requires an executed copy, write to legal@badgewright.com and we will sign one the same week.
Definitions
"Personal Data", "processing", "controller", "processor" and "data subject" have the meanings given in applicable Data Protection Law. "Personal Information", "business", "service provider", "sell", "share" and "commercial purpose" have the meanings given in the California Consumer Privacy Act as amended.
"Data Protection Law" means every privacy and data protection law applicable to the processing, including the CCPA, the other US state consumer privacy statutes, FERPA and state student data privacy statutes where you are an educational institution, and, where they apply to you, the GDPR and the UK GDPR.
"Customer Data" has the meaning given in section 7 of the terms of service.
Processing instructions
We process Personal Data only on your documented instructions, which consist of this addendum, the terms of service, your configuration of the Service, and anything else you tell us in writing.
We will tell you if, in our opinion, an instruction infringes Data Protection Law, and we may decline to carry it out until it is resolved.
If we are required by law to process Personal Data other than on your instructions, we will tell you before doing so unless the law forbids us from telling you, in which case we will tell you as soon as we lawfully may and will challenge any gag that appears to be unlawful.
We will not:
- use Personal Data for any purpose other than providing the Service to you;
- sell it or share it, as those words are defined by the CCPA;
- retain, use or disclose it outside the direct business relationship between us;
- combine it with personal information from another source, except as necessary to provide the Service to you or as the CCPA permits a service provider to do;
- use it to train, fine-tune, evaluate or improve any machine learning model;
- use it to develop or improve any product or service other than the Service provided to you.
US state privacy law: service provider terms
This section is the one the CCPA requires a contract between a business and a service provider to contain, and it is set out separately so it can be pointed at.
- Personal Information is disclosed to us solely for the limited and specified purpose of providing the Service described in the terms of service.
- We are prohibited from selling or sharing Personal Information.
- We are prohibited from retaining, using or disclosing Personal Information for any purpose other than the business purposes specified in the contract, including retaining, using or disclosing it for a commercial purpose other than those business purposes, or as otherwise permitted by the CCPA.
- We are prohibited from retaining, using or disclosing Personal Information outside the direct business relationship between us.
- We are prohibited from combining Personal Information received from you, or on your behalf, with Personal Information received from or on behalf of anyone else, or collected from our own interaction with a consumer, except as the CCPA permits a service provider to do.
- We certify that we understand the restrictions in this section and will comply with them.
- We will comply with the applicable obligations of the CCPA and provide the same level of privacy protection it requires of you.
- You may take reasonable and appropriate steps to ensure we use Personal Information in a manner consistent with your obligations, as section 10 sets out.
- We will notify you if we determine we can no longer meet our obligations under the CCPA, and you may then take reasonable and appropriate steps to stop and remediate unauthorised use.
- You may take reasonable and appropriate steps to stop and remediate any unauthorised use of Personal Information by us.
These terms apply equally under the comparable statutes of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana and every other state with an equivalent regime, and we will not argue that a term written with California's words does not bind us in another state.
Confidentiality of personnel
Anyone we authorise to process Personal Data is bound by a duty of confidentiality that survives the end of their engagement, is given access only to what their role requires, and is trained on the obligations in this addendum.
Access to production systems is limited to those who need it to operate the Service, and administrative actions capable of affecting Customer Data are logged, delayed and announced to your organization's owners before they take effect, so that you can cancel one you did not expect.
Security measures
We implement and maintain the technical and organisational measures set out in Annex B, which are appropriate to the risk, and we will not materially reduce them during your subscription.
We may change a measure for one at least as protective. Annex B is updated when what we do changes, and the obligation is to the standard it describes, not to any particular implementation of it.
Subprocessors
You give general authorisation for us to engage subprocessors. The current list, with what each does and what it sees, is at badgewright.com/legal/subprocessors.
We will give at least 30 days' notice before a new subprocessor begins processing, by updating that page and emailing your organization's owners. You may object within that period on reasonable data protection grounds; if we cannot resolve your objection, you may terminate the affected part of the Service and we will refund the unused fees.
Every subprocessor is bound by written terms no less protective than this addendum, and we remain fully liable to you for their acts and omissions as though they were our own.
Helping you answer people
The Service is built so you can answer most requests yourself: you can search, correct, export and delete any record without us. That is deliberate, because a request answered by the controller directly is answered faster and with less disclosure than one routed through a vendor.
Where you cannot, we will help, at no charge, taking into account the nature of the processing. If a data subject contacts us directly about Customer Data, we will not respond substantively; we will tell them to contact you and tell you they got in touch, promptly.
We will also give you reasonable help with data protection impact assessments and with any prior consultation with a regulator, to the extent the information is ours to give.
Security incidents
We will notify you without undue delay, and in any event within 72 hours, of becoming aware of a Personal Data Breach: a breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorised disclosure of or access to Customer Data.
Notification will be to your organization's owners by email and will describe, as far as we know it:
- what happened and when, and when we found out;
- the categories and approximate number of data subjects and records affected;
- the likely consequences;
- what we have done and are doing about it, including to mitigate harm;
- who to talk to for more.
Incomplete information is not a reason to delay: we will tell you what we know inside 72 hours and update you as we learn more. We will preserve evidence, help you meet your own notification duties, and not make a public statement identifying you without your consent unless the law requires it.
An unsuccessful attempt that we blocked, and ordinary background noise like scanning and failed sign-ins, is not a Personal Data Breach and we will not send you an alert for each one. If you want that detail, the audit log and the account security page are yours to read whenever you like.
Assessments, audits and questionnaires
We will make available the information reasonably necessary to demonstrate compliance with this addendum, and will complete your security questionnaire. We would rather do that once, properly, than send you a certification that answers a different question.
Badgewright does not hold a SOC 2 report or an ISO 27001 certificate, and we will not imply otherwise. If one is a hard requirement of your procurement, tell us and we will tell you honestly whether and when we expect to have it.
You may audit our compliance no more than once a year, and at any time after a Personal Data Breach affecting your data, on 30 days' notice, during business hours, without disrupting the Service and without access to another customer's data or to our confidential information. Each party bears its own costs. Where an audit would require access to shared infrastructure operated by a subprocessor, we will provide that subprocessor's own audit reports instead, which is the most either of us can obtain.
Return and deletion
You may export Customer Data at any time during your subscription and during the retention window after it: any dataset as a CSV file from within the Service, and a complete export, photographs and card designs included, produced on request to support@badgewright.com. Export is available on every plan and is never charged for.
On termination we retain Customer Data for 90 days so you can retrieve it, then delete it. You may ask us to delete sooner, at any time, and we will. Today that request is made by email to support@badgewright.com from an owner of the organization and carried out by us; asking from within the Service is planned. Where the student data addendum applies, its shorter timetable governs instead.
Deletion means:
- before anything is deleted we offer a complete export, on request, so nothing is deleted that you have no copy of;
- the deletion is scheduled rather than immediate, normally 30 days out, and every owner of the organization is emailed with what was requested, when it will happen, and a link to cancel it;
- then a real delete, in one transaction: records, datasets, templates and versions, printer profiles, print jobs and items, users, invitations, audit events and the organization itself;
- and the photographs, deleted from object storage. A deletion that clears the database and leaves the images behind is not one.
11.1 Backups
Deleted data remains within our backup window for up to seven days after erasure, because a backup cannot have a single tenant surgically removed from it without corrupting it. The commitment, in full: live data is erased within the stated period, backups roll off within seven days after that, and if a backup is ever restored, the erasure is re-applied to the restored copy before it serves traffic.
11.2 What we keep, and why
Only: billing records and invoices for seven years, as tax law requires; security event records with the account identifier and IP address removed, so the history survives without the person; and the record that a deletion happened and when, which is the evidence that this clause was honoured. No archive copy is kept for any other purpose.
We will certify deletion in writing if you ask.
International transfers
Customer Data is stored and processed in the United States, in a single Google Cloud region, and is not replicated elsewhere. We will not move it to another country without telling you first.
GDPR-specific terms
Where the GDPR or the UK GDPR applies to your processing, sections 3 to 11 are intended to satisfy Article 28, and the details required by Article 28(3) are in Annex A.
Read this before transferring EU or UK personal data. Badgewright is sold to organizations in the United States. We are not certified under the EU-US Data Privacy Framework, and we do not currently have standard contractual clauses in place. If you need to transfer personal data subject to the GDPR, write to legal@badgewright.com before you do, so we can put a lawful transfer mechanism in place first. We would rather turn away work than let you make a transfer that has no basis.
Liability, and this document
Our liability for breach of this addendum is not subject to the cap in section 16 of the terms of service. That exclusion is stated in the terms themselves and is repeated here so it is not missed.
Where this addendum and the terms of service conflict, this addendum governs for the processing of Personal Data. Where this addendum and the student data addendum conflict, the student data addendum governs for student data.
We may update this addendum to reflect a change in law or in what we do, on 30 days' notice, and never in a way that reduces your protection.
Annex A: details of processing
- Subject matter
- Providing the Badgewright identity card service.
- Duration
- The term of your subscription, plus the retention window in section 11.
- Nature and purpose
- Storing and organising records about your people; storing photographs; rendering both onto a card design; producing print output; keeping a history of what was printed and an audit log of what was changed.
- Categories of data subject
- Your staff, faculty, students, contractors and visitors, whoever you issue cards to; and the users you invite to operate the Service.
- Categories of personal data
- Determined by you, because you define the fields. Typically: name, an organization-issued identifier, job title or grade, photograph, issue and expiry dates. For users of the Service: name, email address, authentication credentials, IP address and browser user agent.
- Special category or sensitive data
- None is intended, and the acceptable use policy prohibits health data, government identifiers, financial account numbers and biometric identifiers. A photograph is processed as an image for printing, and no biometric identifier is derived from it.
- Children's data
- Where you are a school, records about pupils, including under-13s. See the student data addendum.
- Frequency
- Continuous, for the duration of the subscription.
- Processor contact
- Briare Brothers LLC, 30 N Gould St Ste N, Sheridan, WY 82801. privacy@badgewright.com.
Annex B: technical and organisational measures
These are the measures in place, not the measures aspired to.
Access control
- Every user is a named individual. Passwords are hashed with argon2id, with a 12-character minimum and a check against a database of publicly breached passwords, performed so that the password itself is never transmitted.
- Two-factor authentication by authenticator app, passkey or emailed code is available on every plan, and an organization can require it of everyone. Authenticator secrets are encrypted at rest.
- Nine granular permissions with role presets, and per-dataset access limits.
- Sessions expire 30 days after sign-in and after 8 hours idle by default, which an organization may set to any of eight values from 15 minutes to 24 hours. Sensitive actions require re-authentication. Users can see and revoke their own devices.
Tenant isolation
- Each organization's data is separated by PostgreSQL row-level security, so isolation is enforced by the database rather than by application code remembering to filter, and a missing filter fails closed.
- An automated test suite exists whose only purpose is to attempt cross-tenant reads and writes and confirm they fail. It runs on every change.
- Stored files are namespaced by organization, and an organization's images are a single prefix that can be deleted as a unit.
Encryption
- TLS in transit, with HTTP Strict Transport Security.
- Encryption at rest for the database, object storage and backups, provided by Google Cloud.
- Application secrets held in a managed secret store, never in source control or in an image.
Storage of photographs
- A private bucket with uniform bucket-level access and public access prevention enforced, so no object can be made publicly readable, whether by configuration or by mistake.
- No cross-origin configuration and no public path. A browser never contacts the storage bucket: the application reads the bytes, authorises the request against the signed-in user, and serves them itself under a restrictive content security policy.
- Uploaded photographs are rebuilt before storage: JPEG, PNG and WebP are reassembled from their own containers, so EXIF and the location in it, XMP, IPTC, colour profiles, embedded thumbnails and anything trailing the end of the picture are left behind. GIF and SVG are validated rather than rebuilt, so an SVG that carries its own metadata keeps it. Script, event handlers, XML entity declarations and files that do not hold together as the format they claim are refused rather than sanitised.
Resilience and recovery
- Daily database backups retained seven days, with point-in-time recovery over a seven-day window of transaction logs.
- Soft delete on object storage: a deleted or overwritten file is recoverable for seven days.
- Restores are made to a cloned instance, never onto production; the first rehearsal is scheduled before there is customer data to lose.
- Uptime and deep health checks with alerting. There is no published uptime commitment, and section 12 of the terms says so rather than implying one.
Logging and audit
- An audit log of every change, import, export, print and sign-in, searchable by you, retained with your organization's data and deleted with it.
- Separate authentication event records covering sign-ins, failures, lockouts and credential changes.
- Administrative actions capable of affecting Customer Data are delayed, cancellable, announced to every owner by email, and recorded.
Development and change
- Every change goes through version control and an automated test suite, including the cross-tenant tests, before it can be deployed.
- Dependencies are audited automatically.
- Infrastructure is defined as code, so its configuration is reviewable and its history is recorded.
- Production refuses to start if a required security-relevant setting is missing, rather than starting with an unsafe default.
Questions about this document: legal@badgewright.com. Questions about your own data: privacy@badgewright.com. To report a security problem: security@badgewright.com.