Data Processing Agreement

Last updated: September 15, 2026

This Data Processing Agreement ("DPA") applies when Modelence, Inc. ("Modelence", "we", "our", or "us") processes personal data contained in Customer Application Data on your behalf. It forms part of the Terms of Service and applies automatically to every customer. You do not need to sign or return anything: by accepting the Terms of Service and using the Services, you accept this DPA.

If your procurement process requires a countersigned copy, or you need this DPA on your own paper, contact [email protected].

1. Scope and roles

This DPA covers Customer Application Data, which means the data your applications collect and store on Modelence, including data about your own end users. It is the same category described in Section 6 of our Privacy Policy.

For that data you are the controller and we are your processor. You decide what data your application collects and why; we hold and process it on your documented instructions in order to provide the Services.

This DPA does not cover the personal information we collect about you as our own customer, such as your account and billing details. For that data we are the controller, and our Privacy Policy describes it.

Where the EU or UK General Data Protection Regulation applies, terms such as "controller", "processor", "personal data", "processing", "data subject" and "personal data breach" have the meanings given in that legislation.

2. Details of the processing

Subject matterHosting and running the applications you build on Modelence, and the managed databases, storage and supporting infrastructure those applications use.
DurationFor as long as your account is open, plus the deletion periods in Section 9.
Nature and purposeStorage, hosting, transmission, backup, and operational access needed to provide, secure and support the Services.
Types of personal dataDetermined by you, through the application you build. Commonly account identifiers, names, email addresses, and any other fields your application chooses to collect.
Categories of data subjectsDetermined by you. Typically the end users of your application.
Special category dataNot required by the Services. If your application collects it, you remain responsible for the additional obligations that attach to it.

3. What we commit to

  • We process Customer Application Data only on your documented instructions. Your use of the Services, and this DPA, are those instructions. We will tell you if an instruction appears to us to breach applicable data protection law
  • We do not sell Customer Application Data, use it for our own purposes, or use it to train AI models
  • Our staff access it only where necessary to operate the Services, to respond to a support request from you, to comply with the law, or to investigate a suspected violation of our Terms
  • Everyone we allow to access it is under a duty of confidentiality
  • We maintain the security measures described in Section 6
  • If we receive a legally binding demand for Customer Application Data, we will tell you before responding unless the law forbids it

4. Subprocessors

You give us general authorization to engage subprocessors. We impose data protection obligations on each of them that are no less protective than this DPA, and we remain responsible to you for their performance.

The current list of subprocessors that may process Customer Application Data, with the purpose and location of each, is published at modelence.com/dpa/subprocessors. That page is incorporated into this DPA and serves as Annex III to the Standard Contractual Clauses in Section 5.

We will give you at least 30 days' notice before adding or replacing a subprocessor that processes Customer Application Data. To receive those notices, email [email protected] and ask to be added to the list. If you have a reasonable, data protection based objection, tell us within those 30 days and we will work with you in good faith; if we cannot resolve it, you may terminate the affected Services and receive a pro rata refund of prepaid fees.

5. International transfers and where data is held

Customer Application Data is stored in the United States. Our personnel may access it remotely from the United States or other countries. Access from any location is subject to the same access controls and confidentiality obligations, and to the transfer safeguards described below.

Where you transfer personal data to us from the European Economic Area, the United Kingdom or Switzerland, the European Commission's Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module Two (controller to processor), are incorporated into this DPA by reference and completed as follows:

  • Data exporter: you, the customer. Data importer: Modelence, Inc.
  • Annex I, description of processing: as set out in Section 2 above. Annex III, subprocessors: the list published at modelence.com/dpa/subprocessors
  • Annex II, technical and organisational measures: as set out in Section 6 below
  • Clause 7 (docking): applies. Clause 9: Option 2, general written authorization, with the 30 day notice period in Section 4
  • Clause 11: the optional independent dispute resolution body does not apply
  • Clause 17: the Clauses are governed by the law of Ireland. Clause 18(b): disputes are to be resolved before the courts of Ireland

For UK transfers, the UK International Data Transfer Addendum applies to the above Clauses, with Modelence as importer and the same selections. For Swiss transfers, references to the GDPR are read as references to the Swiss Federal Act on Data Protection and the competent authority is the Swiss Federal Data Protection and Information Commissioner.

6. Security measures

We maintain technical and organisational measures appropriate to the risk, including:

  • Encryption in transit. Traffic to your applications and to our managed databases is encrypted with TLS
  • Encryption at rest. Managed databases, object storage and database snapshots are encrypted at rest
  • Backups. Dedicated production databases are backed up automatically by snapshot at least every six hours, retained on a rolling schedule, and encrypted at rest. Restores are performed by our support team on request
  • Tenant isolation. Each customer's application data is isolated from every other customer's
  • Access control. Internal access is limited to staff who need it for the purposes in Section 3, over authenticated and logged channels
  • Monitoring. Infrastructure monitoring and alerting, and a public status page at status.modelence.com
  • Credential handling. Passwords are stored hashed. Payment card numbers go directly to our payment processor and are never stored by us

We may update these measures over time, but will not reduce the overall level of security during your subscription.

7. Personal data breach notification

If we become aware of a personal data breach affecting Customer Application Data, we will notify you without undue delay.

The notice will describe what happened, the categories and approximate volume of data affected so far as known, the likely consequences, and the steps we are taking. Where we cannot provide all of that at once, we will provide it in phases as the investigation develops.

We will provide reasonable assistance so that you can meet your own notification obligations to regulators and to data subjects. Notifying your regulators and your end users remains your responsibility as controller. You can reach our security team at [email protected].

8. Assistance and audits

Data subject requests. Because you control the data inside your application, you can normally satisfy access, correction, deletion and portability requests yourself using the database access described in Section 9. Where you cannot, we will provide reasonable assistance. If an end user contacts us directly about data held in your application, we will refer them to you rather than act on it.

Impact assessments. We will provide reasonable assistance with data protection impact assessments and prior consultations, using the information in this DPA and our Privacy Policy.

Audits. We will make available the information reasonably necessary to demonstrate compliance with this DPA, and will respond to reasonable security questionnaires no more than once a year. Where that is not sufficient for your regulator, we will agree an audit scope with you in good faith, at your cost, subject to reasonable notice, confidentiality, and no access to other customers' data.

9. Export, return and deletion

Export at any time. You can connect any standard database client to your production database using the connection string in your environment's Database tab, under Connect External Tool, and take a complete copy whenever you want. You can also download your full source code from the dashboard.

On termination. We will give you a reasonable opportunity to export Customer Application Data before deletion. After that, we delete it, and backup copies age out on their rolling snapshot schedule within 12 months.

We may retain data for longer only where the law requires it, in which case we continue to protect it under this DPA and process it only for that purpose.

10. General

This DPA takes effect when you accept the Terms of Service and continues for as long as we process Customer Application Data for you. If it conflicts with the Terms of Service on the processing of Customer Application Data, this DPA governs. The Standard Contractual Clauses prevail over both to the extent of any conflict.

The liability limits and exclusions in the Terms of Service apply to claims under this DPA, except where applicable data protection law does not permit it.

If we make a material change to this DPA, we will tell you by email or in the product before it takes effect, and we will update the date at the top of this page.

11. Contact

Modelence, Inc.
1 Sansome St, Suite 1400 PMB 10088
San Francisco, CA 94104
United States

Data protection questions: [email protected]
Security reports: [email protected]