Data Processing Agreement
This Data Processing Agreement ("DPA") reflects the parties’ agreement with respect to the Processing of Personal Data by Mentrast on behalf of the Customer in connection with the Mentrast Subscription Services under the Mentrast Terms of Service.
1. Preamble
This DPA is an addendum to and forms part of the Master Services Agreement between Mentrast Inc. ("Processor") and the Customer ("Controller"). In the course of providing the Services to Customer pursuant to the Agreement, Processor may Process Personal Data on behalf of Customer. This DPA sets out the rights and obligations of the Parties in relation to such Processing.
2. Definitions
- "CCPA" means the California Consumer Privacy Act of 2018.
- "GDPR" means Regulation (EU) 2016/679 of the European Parliament and of the Council.
- "Personal Data" means any information relating to an identified or identifiable natural person.
- "Processing" means any operation performed on Personal Data, such as collection, recording, storage, adaptation, or destruction.
- "Subprocessor" means any third party appointed by or on behalf of Processor to process Personal Data.
3. Processing Instructions
Processor shall process Personal Data only for the purposes described in the Agreement or as otherwise agreed within the scope of Customer's lawful instructions, except where otherwise required by applicable EU or Member State law. The subject matter, nature, purpose, and duration of the Processing are set out in Annex A.
4. Confidentiality
Processor ensures that persons authorized to process the Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. This obligation survives the termination of the Agreement.
5. Security of Processing (TOMs)
Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of Processing, Processor shall implement appropriate technical and organizational measures ("TOMs") to ensure a level of security appropriate to the risk.
6. Subprocessing
Customer grants Processor general authorization to engage Subprocessors. Processor shall maintain an up-to-date list of Subprocessors in Annex C. Processor shall verify that Subprocessors implement sufficient guarantees to protect the Personal Data. Processor shall notify Customer of any intended changes concerning the addition or replacement of Subprocessors.
7. Data Subject Rights
Taking into account the nature of the Processing, Processor shall assist Customer by appropriate technical and organizational measures, insofar as this is possible, for the fulfillment of Customer's obligation to respond to requests for exercising the Data Subject's rights laid down in Chapter III of the GDPR (including right of access, rectification, erasure, and portability).
8. Personal Data Breach
Processor shall notify Customer without undue delay after becoming aware of a Personal Data Breach. Such notification shall include, at a minimum: (a) the nature of the breach; (b) the categories and approximate number of Data Subjects concerned; and (c) the likely consequences and measures taken to mitigate possible adverse effects.
9. International Transfers
Where Personal Data is transferred from the EEA/UK/Switzerland to a country outside these regions that is not recognized as providing an adequate level of protection, the transfer shall be governed by the Standard Contractual Clauses (SCCs).
10. Audit Rights
Processor shall make available to Customer all information necessary to demonstrate compliance with the obligations laid down in this DPA and allow for and contribute to audits, including inspections, conducted by Customer or an auditor mandated by Customer.
11. Liability
Each party's liability for any breach of this DPA shall be subject to the limitations and exclusions of liability set out in the Main Agreement, except where such limitation is prohibited by applicable Data Protection Laws.
Annex A: Details of Processing
The provision of the Mentrast Learning Platform and learning maps.
The term of the Agreement plus the period from expiry of the Agreement until deletion of all Customer Data.
Employees, contractors, and end-users authorized by the Customer to use the Service.
Annex B: Security Measures
Description of the technical and organizational measures implemented by the Processor:
- Identity & Access Management: Implementation of SSO, MFA, and strong password policies.
- Network Security: Use of firewalls, IDS/IPS, and separation of production and non-production environments.
- Physical Security: Data centers (via AWS/Vercel) compliant with SOC 2 Type II and ISO 27001.
- Incident Response: Maintained Incident Response Plan with defined RTO/RPO objectives.
- Vulnerability Management: Regular container scanning, dependency auditing, and annual penetration testing.
