Definitions
'Customer Data' means personal data you or your users route through Myndstack in the course of using the service. 'Controller' and 'Processor' carry the meanings given to them under the GDPR and equivalent Indian, UK, EU, and other applicable data-protection laws (including the Digital Personal Data Protection Act, 2023).
Roles
You are the Controller (or, where applicable, the Data Fiduciary) of Customer Data. Myndstack acts as your Processor (or Data Processor) and processes Customer Data only on your documented instructions, which include this DPA and the order form.
Scope of processing
We process Customer Data to operate the service you have subscribed to, to keep it secure, to bill you, and to respond to your support requests. We do not process Customer Data for our own purposes, and we do not use it to train models — ours or anyone else's.
Subprocessors
The current list of subprocessors is published on the subprocessors page. We give at least 30 days' notice before adding a new subprocessor to that list; you can object in writing within that window, and if we cannot accommodate the objection you can terminate the affected service for that reason.
International transfers
Where Customer Data leaves the jurisdiction it was collected in, we rely on Standard Contractual Clauses, the UK International Data Transfer Addendum, or an equivalent transfer mechanism recognised by the receiving country. Region-pinned deployment is available on request and, once agreed, is recorded in the order form.
Security measures
The measures we apply are the ones set out on the security page: least-privilege access, MFA-gated production access, encryption in transit and at rest, dependency and container scanning in CI, and infrastructure defined as code. Any material change to those measures during the term will not degrade the protections in place at signing.
Data subject rights
We help you respond to access, correction, deletion, restriction, and portability requests from your users. Where a request reaches us directly, we route it to you rather than actioning it ourselves.
Incidents
We notify you without undue delay — and in any event within 72 hours of confirming — a security incident affecting your Customer Data, together with what we know, what we are doing, and what we need from you.
Deletion and return
On termination we return or delete Customer Data on your instruction within 30 days, except where we are required by law to retain a copy. Backups are overwritten on their usual cycle.
Audit
You may request our current security posture, penetration-test summaries, and subprocessor list once every twelve months, or after a security incident affecting your data, and rely on third-party audit reports where they cover the control in question.
How to execute this
To sign a copy of this DPA under your paperwork rather than ours, email hello@myndstack.io with the subject line "DPA" and we will countersign within five business days.
Questions about this page? Get in touch.