Data Processing Agreement

This agreement governs how MythicDot.AI processes personal data on behalf of our customers.

Version 2.1 â€ĸ Last Updated: January 15, 2025

📄 Download PDF âœī¸ Request Signed Copy

1 Definitions

"Controller"

The Customer who determines the purposes and means of the processing of Personal Data.

"Processor"

MythicDot.AI, which processes Personal Data on behalf of the Controller.

"Personal Data"

Any information relating to an identified or identifiable natural person that is processed by MythicDot.AI on behalf of Customer.

"Processing"

Any operation performed on Personal Data, including collection, recording, organization, storage, adaptation, retrieval, consultation, use, disclosure, or erasure.

2 Scope of Processing

This DPA applies to the processing of Personal Data by MythicDot.AI as described in the Service Agreement. The nature and purpose of processing includes:

â„šī¸ Important Note

MythicDot.AI does not use Customer Personal Data to train AI models. All processing is strictly for providing the contracted services.

3 Processor Obligations

MythicDot.AI, as Processor, agrees to:

  1. Process Personal Data only on documented instructions from the Controller
  2. Ensure personnel processing data are bound by confidentiality obligations
  3. Implement appropriate technical and organizational security measures
  4. Engage sub-processors only with prior authorization and equivalent contractual obligations
  5. Assist the Controller with data subject requests and regulatory compliance
  6. Make available all information necessary to demonstrate compliance
  7. Allow and contribute to audits conducted by the Controller
  8. Delete or return all Personal Data upon termination of services

4 Controller Obligations

The Controller agrees to:

  1. Ensure lawful basis for processing Personal Data
  2. Provide clear instructions regarding the processing of Personal Data
  3. Ensure compliance with applicable data protection laws
  4. Notify MythicDot.AI of any data subject requests requiring assistance
  5. Maintain appropriate privacy notices for data subjects

5 Sub-processors

The Controller authorizes MythicDot.AI to engage the following sub-processors:

Sub-processor Purpose Location
Amazon Web Services Cloud infrastructure US, EU, Asia
Google Cloud Platform Cloud infrastructure US, EU
Cloudflare CDN and security Global
Stripe Payment processing US, EU

MythicDot.AI will notify the Controller of any intended changes to sub-processors at least 30 days in advance.

6 Security Measures

MythicDot.AI implements and maintains the following security measures:

7 International Transfers

When Personal Data is transferred outside the European Economic Area, MythicDot.AI relies on:

Enterprise customers may request data residency in specific regions (US, EU, or Asia-Pacific).

8 Data Subject Rights

MythicDot.AI will assist the Controller in responding to data subject requests including:

Requests will be processed within 30 days of receipt.

9 Data Breach Notification

In the event of a Personal Data breach, MythicDot.AI will:

  1. Notify the Controller without undue delay (within 72 hours of becoming aware)
  2. Provide details including nature of breach, categories of data affected, and likely consequences
  3. Describe measures taken or proposed to address the breach
  4. Cooperate with the Controller in investigating and mitigating the breach

10 Data Deletion

Upon termination of the Service Agreement or upon Controller's request:

Execution

Controller (Customer)

Signature
Name
Title
Date

Processor (MythicDot.AI)

Signature
Name
Title
Date

Need a Custom DPA?

Enterprise customers can request customized data processing terms to meet specific requirements.

Contact Enterprise Sales →