Legal

Data Processing Agreement

Last updated: 24 July 2026

This Data Processing Agreement (DPA) supplements the Modou Terms of Service. It applies whenever Modou processes Customer Personal Data on the Customer's behalf to provide the Service.

1. Roles and scope

For Customer Personal Data processed through the Service, the Customer is the controller and Modou is the processor. The Customer decides why and how that personal data is processed, including which connected tools and actions it authorises.

Modou acts as an independent controller only for personal data it needs to run its own business, such as account administration, billing, legal compliance, and security. That processing is described in the Privacy Policy.

2. Documented instructions

Modou will process Customer Personal Data only on the Customer's documented instructions, including the Terms of Service, this DPA, and instructions given through the Service. Modou will inform the Customer if an instruction appears to breach applicable data-protection law, unless the law prevents it from doing so.

Modou may process Customer Personal Data where Union or Member State law requires it. In that case, Modou will tell the Customer before processing unless the law prohibits notification.

3. Confidentiality

Modou ensures that people authorised to process Customer Personal Data are bound by confidentiality obligations or are under an appropriate statutory duty of confidentiality. Access is limited to people who need it to provide, secure, or support the Service.

4. Security

Modou will implement appropriate technical and organisational measures designed to protect Customer Personal Data, taking account of the nature of the processing and the risks involved.

  • Encryption in transit for the Service
  • Access controls that limit users to their own account data
  • Controlled handling of connected-tool authorisation tokens
  • Security reviews and timely security patches

5. Sub-processors

The Customer gives Modou general written authorisation to use sub-processors that are necessary to provide the Service. Modou remains responsible for its sub-processors' data-protection obligations.

Modou maintains its current service-provider list in the Privacy Policy. Before adding or replacing a sub-processor that materially affects Customer Personal Data, Modou will provide reasonable prior notice through the Service, by email, or on this page. The Customer may raise a reasonable data-protection objection during that notice period.

6. Help with data-protection obligations

Taking account of the nature of the processing, Modou will provide reasonable assistance to help the Customer respond to requests from people exercising their data-protection rights. The Customer remains responsible for responding to those requests.

Modou will also provide reasonable information and assistance for the Customer's data-protection impact assessments, prior consultations with supervisory authorities, and other obligations under Articles 32 to 36 GDPR, where the assistance relates to the Service and is required by applicable law.

7. Personal data breaches

If Modou becomes aware of a personal data breach involving Customer Personal Data, it will notify the Customer without undue delay. Modou will share the information reasonably available to help the Customer meet its own breach-notification duties.

8. International transfers

Customer Personal Data is stored in the EU where described in the Privacy Policy. Some service providers, including AI providers, may process data outside the European Economic Area. Where a transfer requires a safeguard under Chapter V GDPR, Modou will use an appropriate lawful transfer mechanism.

9. Return and deletion

At the end of the Service, the Customer may export its data where the Service provides that option. Modou will delete Customer Personal Data within 30 days after account deletion or termination, unless applicable law requires continued storage.

Residual copies in secure backups are isolated and removed in the ordinary backup cycle. Modou will not restore Customer Personal Data from a backup except where necessary for disaster recovery or legal obligations.

10. Information and audits

Modou will make information reasonably necessary to demonstrate compliance with this DPA available to the Customer. On reasonable written notice, the Customer may conduct an audit or appoint an independent auditor, no more than once in any 12-month period unless a material incident or regulator requires otherwise.

Audits must be carried out during normal business hours, avoid unreasonable disruption, protect other customers' confidential information, and follow Modou's reasonable security requirements. The Customer bears its audit costs unless the audit identifies Modou's material breach of this DPA.

11. Term and order of precedence

This DPA starts when the Customer uses the Service and continues for as long as Modou processes Customer Personal Data. If this DPA conflicts with the Terms of Service on a data-processing matter, this DPA takes precedence to that extent.

This DPA does not reduce the Customer's responsibility to have a lawful basis for its instructions, give required notices, and ensure that its use of the Service complies with applicable law.

Annex A: details of processing

This annex describes the processing covered by this DPA.

Subject matter and duration
  • Provision, support, and security of the Modou Service
  • For the Customer's active subscription and the deletion period described in section 9
Nature and purpose
  • Hosting and managing the Customer's account and workspace
  • Accessing Customer-authorised connected tools to perform requested or approved agent actions
  • Generating, storing, and displaying analyses, recommendations, drafts, and activity records
Types of personal data
  • Account and workspace details, such as names, roles, and contact details
  • Personal data included by the Customer in connected tools, instructions, files, and agent outputs
  • Technical and security data needed to operate the Service
Data subjects
  • The Customer's users, employees, contractors, and authorised representatives
  • The Customer's contacts, customers, prospects, suppliers, and other people whose data the Customer places in authorised connected tools
Special-category data
  • The Service is not designed to require special-category personal data. The Customer must not provide it unless it has a lawful basis, gives any required notices, and has agreed the necessary safeguards with Modou in writing.

See also Modou's Privacy Policy and Terms of Service.