Last updated: September 15, 2026
This Data Processing Agreement ("DPA") applies when Modelence, Inc. ("Modelence", "we", "our", or "us") processes personal data contained in Customer Application Data on your behalf. It forms part of the Terms of Service and applies automatically to every customer. You do not need to sign or return anything: by accepting the Terms of Service and using the Services, you accept this DPA.
If your procurement process requires a countersigned copy, or you need this DPA on your own paper, contact [email protected].
This DPA covers Customer Application Data, which means the data your applications collect and store on Modelence, including data about your own end users. It is the same category described in Section 6 of our Privacy Policy.
For that data you are the controller and we are your processor. You decide what data your application collects and why; we hold and process it on your documented instructions in order to provide the Services.
This DPA does not cover the personal information we collect about you as our own customer, such as your account and billing details. For that data we are the controller, and our Privacy Policy describes it.
Where the EU or UK General Data Protection Regulation applies, terms such as "controller", "processor", "personal data", "processing", "data subject" and "personal data breach" have the meanings given in that legislation.
| Subject matter | Hosting and running the applications you build on Modelence, and the managed databases, storage and supporting infrastructure those applications use. |
| Duration | For as long as your account is open, plus the deletion periods in Section 9. |
| Nature and purpose | Storage, hosting, transmission, backup, and operational access needed to provide, secure and support the Services. |
| Types of personal data | Determined by you, through the application you build. Commonly account identifiers, names, email addresses, and any other fields your application chooses to collect. |
| Categories of data subjects | Determined by you. Typically the end users of your application. |
| Special category data | Not required by the Services. If your application collects it, you remain responsible for the additional obligations that attach to it. |
You give us general authorization to engage subprocessors. We impose data protection obligations on each of them that are no less protective than this DPA, and we remain responsible to you for their performance.
The current list of subprocessors that may process Customer Application Data, with the purpose and location of each, is published at modelence.com/dpa/subprocessors. That page is incorporated into this DPA and serves as Annex III to the Standard Contractual Clauses in Section 5.
We will give you at least 30 days' notice before adding or replacing a subprocessor that processes Customer Application Data. To receive those notices, email [email protected] and ask to be added to the list. If you have a reasonable, data protection based objection, tell us within those 30 days and we will work with you in good faith; if we cannot resolve it, you may terminate the affected Services and receive a pro rata refund of prepaid fees.
Customer Application Data is stored in the United States. Our personnel may access it remotely from the United States or other countries. Access from any location is subject to the same access controls and confidentiality obligations, and to the transfer safeguards described below.
Where you transfer personal data to us from the European Economic Area, the United Kingdom or Switzerland, the European Commission's Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module Two (controller to processor), are incorporated into this DPA by reference and completed as follows:
For UK transfers, the UK International Data Transfer Addendum applies to the above Clauses, with Modelence as importer and the same selections. For Swiss transfers, references to the GDPR are read as references to the Swiss Federal Act on Data Protection and the competent authority is the Swiss Federal Data Protection and Information Commissioner.
We maintain technical and organisational measures appropriate to the risk, including:
We may update these measures over time, but will not reduce the overall level of security during your subscription.
If we become aware of a personal data breach affecting Customer Application Data, we will notify you without undue delay.
The notice will describe what happened, the categories and approximate volume of data affected so far as known, the likely consequences, and the steps we are taking. Where we cannot provide all of that at once, we will provide it in phases as the investigation develops.
We will provide reasonable assistance so that you can meet your own notification obligations to regulators and to data subjects. Notifying your regulators and your end users remains your responsibility as controller. You can reach our security team at [email protected].
Data subject requests. Because you control the data inside your application, you can normally satisfy access, correction, deletion and portability requests yourself using the database access described in Section 9. Where you cannot, we will provide reasonable assistance. If an end user contacts us directly about data held in your application, we will refer them to you rather than act on it.
Impact assessments. We will provide reasonable assistance with data protection impact assessments and prior consultations, using the information in this DPA and our Privacy Policy.
Audits. We will make available the information reasonably necessary to demonstrate compliance with this DPA, and will respond to reasonable security questionnaires no more than once a year. Where that is not sufficient for your regulator, we will agree an audit scope with you in good faith, at your cost, subject to reasonable notice, confidentiality, and no access to other customers' data.
Export at any time. You can connect any standard database client to your production database using the connection string in your environment's Database tab, under Connect External Tool, and take a complete copy whenever you want. You can also download your full source code from the dashboard.
On termination. We will give you a reasonable opportunity to export Customer Application Data before deletion. After that, we delete it, and backup copies age out on their rolling snapshot schedule within 12 months.
We may retain data for longer only where the law requires it, in which case we continue to protect it under this DPA and process it only for that purpose.
This DPA takes effect when you accept the Terms of Service and continues for as long as we process Customer Application Data for you. If it conflicts with the Terms of Service on the processing of Customer Application Data, this DPA governs. The Standard Contractual Clauses prevail over both to the extent of any conflict.
The liability limits and exclusions in the Terms of Service apply to claims under this DPA, except where applicable data protection law does not permit it.
If we make a material change to this DPA, we will tell you by email or in the product before it takes effect, and we will update the date at the top of this page.
Modelence, Inc.
1 Sansome St, Suite 1400 PMB 10088
San Francisco, CA 94104
United States
Data protection questions: [email protected]
Security reports: [email protected]