Skip to content
Home Data Processing Agreement
Legal

Data Processing Agreement

Our GDPR Art. 28 DPA for customers who process personal data through Modilo.

⚠️ Template for review. Replace every [placeholder] with Modilo's real details and have a lawyer review before publishing.
Signable DPA available on request at hello@modilo.io. This page summarises the key terms.

1. Roles

You are the controller; Modilo is the processor acting on your documented instructions.

2. Scope & purpose

We process personal data only to provide the mapping, analysis and recommendation services described in the Terms.

3. AI sub-processing

Process content may be sent to our AI provider solely to generate output. The provider does not train on the data; abuse-monitoring retention is limited and then deleted. Enterprise customers may request Zero Data Retention. [Name provider + link to their DPA].

4. Sub-processors

Current sub-processors: [list hosting + AI provider]. We'll give notice of changes and let you object.

5. Security measures

EU hosting, encryption in transit and at rest, access controls and minimal retention. See Security.

6. International transfers

Data is kept in the EU. Where any transfer occurs, we rely on appropriate safeguards (e.g. SCCs). [Specify].

7. Data subject requests & breach

We assist you with data-subject requests and notify you without undue delay of any personal-data breach.

8. Deletion

On termination we delete or return personal data per your instruction, subject to legal retention.


Last updated: [date].