Savra

Data Processing Addendum

For customers who need a processing agreement on file. Available on Studio, Unlimited, and Custom plans.

Last updated Aug 3, 2026
On this page

This page sets out the standard terms of the Savra Data Processing Addendum (the “DPA”). It becomes binding for an account when executed as described at the end of this page. Capitalized terms not defined here have the meaning given in the Terms of Service or in applicable data-protection law.

Parties and roles

The DPA is between the customer and Brava Tactical Inc. (doing business as Savra), a British Columbia corporation. For personal data processed through the Service, the customer is the controller and Savra is the processor. Where the customer is itself a processor for another controller, Savra acts as its subprocessor and the same terms apply.

When executed, the DPA is incorporated into and forms part of the Terms of Service (the “Agreement”). If the DPA and the Agreement conflict on the processing of personal data, the DPA prevails.

Scope of processing

Subject matter: the Savra platform and related services described in the Agreement. Duration: the term of the Agreement, plus the deletion window below. Nature and purpose: providing the features the customer configures, including content generation, publishing to connected channels, analytics reporting, email sending, and chatbot conversations, together with support, security, and billing.

The personal data processed depends on how the customer uses the Service, and typically includes:

  • account data of the customer’s team: names, email addresses, roles, and authentication identifiers;
  • content the customer submits, which may itself contain personal data;
  • data from accounts the customer connects: analytics, search, and advertising data from Google, and published-content and performance data from social channels;
  • recipient lists and message content for email the customer sends through the Service; and
  • conversations between the customer’s chatbots and the people who use them.

Data subjects are, correspondingly, the customer’s team members and the customer’s own customers, prospects, subscribers, and end users.

Savra processes personal data only on the customer’s documented instructions: the Agreement, the DPA, and the customer’s configuration and use of the Service. If the law requires Savra to process beyond those instructions, Savra informs the customer before processing unless the law prohibits the notice.

Subprocessors

The customer authorizes the subprocessors listed at Subprocessors, which names what each one does and where it processes data. Savra gives at least 30 days’ notice before a new subprocessor takes effect, by updating that page and by email to customers who have asked to be notified.

A customer may object in writing within the notice period on reasonable data-protection grounds. Savra will work with the customer on an alternative, and if none is workable the customer may terminate the affected part of the Service as the Agreement provides. Every subprocessor is bound by written terms no less protective than this DPA, and Savra remains responsible to the customer for its subprocessors’ performance.

Security measures

Savra maintains technical and organizational measures matching what the trust center states, including: encryption in transit (TLS) and at rest; credentials for connected accounts stored encrypted, never in plain text; tenant isolation so one customer’s data cannot surface in another’s output; least-privilege access internally; and payment handling by Stripe, so Savra never stores card numbers.

Everyone Savra authorizes to process customer personal data is bound by confidentiality obligations. The measures will evolve, and a change must not materially decrease the protection in place during the term.

These measures are summarized on Security & trust.

Assistance with data-subject rights

If a data subject sends Savra a request that concerns the customer’s data, Savra forwards it to the customer without undue delay and does not answer it directly, beyond directing the person to the customer, unless the law requires more.

Savra assists the customer in meeting access, correction, deletion, restriction, portability, and objection requests, taking into account the nature of the processing: through the deletion and disconnection controls in the Service, and through support@savra.ai for anything the product does not yet expose. This assistance is included at no extra charge while the requests stay proportionate to the account.

Breach notification

Savra notifies the customer without undue delay, and in any case within 72 hours, after becoming aware of a personal data breach affecting the customer’s personal data. The notice describes the nature of the breach, the categories and approximate volume of data and data subjects affected, the likely consequences, the measures taken or proposed, and a contact point. Information may follow in stages as the investigation progresses. Notification is not an admission of fault.

International transfers

Savra is a Canadian company, and processing takes place in Canada, the United States, and the locations listed per subprocessor on the Subprocessors page. Where personal data protected by EEA, UK, or Swiss law is transferred to a country without an adequacy decision, the executed DPA incorporates the EU Standard Contractual Clauses (controller-to-processor module) and, where applicable, the UK Addendum. Onward transfers to subprocessors rest on the same safeguards.

Deletion on termination

When the Agreement ends, the customer chooses return or deletion. On request, Savra provides an export of the customer’s data in a commonly used format. Savra deletes personal data from active systems within 30 days of termination, or of the customer’s earlier written request. Copies inside encrypted backups leave the backup set as it cycles and are never used to restore deleted data outside disaster recovery. Data Savra must keep by law is isolated, kept only as long as the law requires, and remains under this DPA’s protections.

Audit

Savra holds no SOC 2 or ISO 27001 certification today, and says so plainly on the trust center rather than implying otherwise. Compliance evidence therefore takes the form of documentation: the Security & trust page, this DPA, the Subprocessors page, and written answers to reasonable security questionnaires, once per 12-month period at no charge.

Where documentation is genuinely insufficient, the customer may audit on at least 30 days’ written notice, once per 12-month period, during business hours, without disrupting the Service, under a scope agreed in advance and at the customer’s cost. An auditor acting for the customer must be bound by confidentiality and must not be a Savra competitor.

Executing this DPA

The DPA is available on Studio, Unlimited, and Custom plans. To put a signed copy in place for your account, contact us with your plan and jurisdiction, and we will send the instrument for signature.

Need a DPA on file?

Tell us your plan and jurisdiction and we will get the paperwork moving.