Data Processing Addendum
This Addendum forms part of the agreement between MIOSA and a customer when MIOSA processes personal data on the customer's behalf. It governs that processing alongside our Terms of Service and Privacy Policy, and it applies to the extent data protection law requires terms of this kind.
1. Definitions
The following terms have the meanings below when used in this Addendum.
- Controller means the entity that determines the purposes and means of the processing of personal data.
- Processor means the entity that processes personal data on behalf of, and on the documented instructions of, a controller.
- Subprocessor means a third party engaged by a processor to process personal data on behalf of a controller.
- Personal data means any information relating to an identified or identifiable natural person that is processed under the agreement.
- Processing means any operation performed on personal data, including collection, storage, use, disclosure, transmission, and deletion.
- Standard Contractual Clauses means the standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission, together with the UK International Data Transfer Addendum where it applies.
- Data protection law means the data protection and privacy laws applicable to the processing of personal data under the agreement, including the GDPR, the UK GDPR, and the CCPA/CPRA where they apply.
- Services means the MIOSA platform and the features made available under the agreement, including Sandboxes, Computers, Agents, App Engine, Databases, and Storage.
- Customer data means the personal data that you, as the customer, submit to or store in the Services, or that the Services process on your behalf.
2. Roles of the parties
For customer data that MIOSA processes on your behalf through the Services, you are the controller (or a processor acting on behalf of a controller) and MIOSA is the processor. We process that data only as a processor and only on your documented instructions.
MIOSA acts as a controller in its own right for the account, contact, and billing data that we collect to create and administer your account, to bill you for the Services, and to meet our own legal and operational obligations. Our handling of that data as a controller is described in our Privacy Policy.
3. Scope and processing instructions
We process personal data only on your documented instructions. The agreement, this Addendum, and your configuration and use of the Services together constitute your documented instructions. We do not process personal data for our own purposes, and we do not sell it or share it for cross-context behavioural advertising.
If we believe that an instruction you give us infringes applicable data protection law, we will tell you promptly and may suspend the affected processing until the instruction is confirmed or amended. We will not be liable for a failure to perform an instruction that we have suspended on these grounds.
4. Confidentiality
We limit access to personal data to personnel who need it to deliver and support the Services. Everyone who processes personal data on our behalf is bound by written confidentiality obligations that survive the end of their engagement, and we train them on their data protection responsibilities.
5. Security measures
We maintain technical and organizational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, and unauthorized disclosure or access. The measures currently in place are set out in Annex 2 and include per-workload microVM isolation, encryption in transit with TLS, encryption at rest for credentials and secrets, multi-factor authentication, SAML single sign-on, role-based access control, scoped API keys, audit logging, an egress allowlist, a secrets vault, and signup verification. Our controls are described further in the Trust Center. We may update the measures over time provided the overall level of protection does not materially decrease.
6. Subprocessors
You provide general authorization for MIOSA to engage subprocessors to process personal data in connection with the Services. The current list of subprocessors, with each one's purpose and the data category involved, is published at /legal/subprocessors.
Before a subprocessor processes any personal data, we impose on it data protection obligations that are no less protective than those in this Addendum. We remain responsible to you for the performance of each subprocessor's obligations.
We will give you notice of any intended addition or replacement of a subprocessor. You may object to the change on reasonable data protection grounds. If you object and we cannot accommodate the objection within a reasonable period, you may terminate the affected Services without penalty.
7. Data subject requests
We will assist you, to the extent reasonably possible, in responding to requests from data subjects who seek to exercise their rights under data protection law over customer data. If we receive such a request directly, we will forward it to you promptly and will not respond to it ourselves, except where the law requires us to act or where you have authorized us in writing to respond.
8. Personal data breach
We will notify you without undue delay after becoming aware of a personal data breach affecting customer data. Our notification will include, to the extent known at the time, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences of the breach, and the measures taken or proposed to address it and to mitigate its effects.
We will cooperate reasonably with you in meeting your own obligations to notify supervisory authorities and affected data subjects. Our obligation to notify is not, and does not relieve you of, your own notification obligations as controller.
9. Data protection impact assessments
Where data protection law requires it, we will provide reasonable assistance to help you carry out a data protection impact assessment and any related prior consultation with a supervisory authority in connection with the Services, taking into account the nature of the processing and the information available to us.
10. Deletion and return of data
On termination or expiry of the agreement, and on your request, we will delete or return customer data within the period agreed between us, except where applicable law requires us to retain it. The deletion period that applies to account data is described in the Privacy Policy. Backups are retained for a limited period and expire on their normal cycle; we do not restore deleted customer data from backups other than to recover the Services from a fault.
11. Audits and information
We make available the information reasonably necessary to demonstrate our compliance with this Addendum. Where a customer requires audit assurance, we make an independent SOC 2 Type I report available in lieu of an on-site audit, together with the security documentation published in the Trust Center.
Where applicable law requires an on-site audit, we will allow one on reasonable prior notice, during business hours, subject to written confidentiality obligations and to reasonable scheduling, so that the audit does not compromise the security or availability of the Services or of other customers' data.
12. International transfers
We process personal data in the United States. Where personal data is transferred to us from the European Economic Area, the United Kingdom, or Switzerland, we rely on the Standard Contractual Clauses and, for the United Kingdom, the UK International Data Transfer Addendum, together with any supplementary measures required to protect the data.
13. CCPA service-provider terms
For the purposes of the CCPA and CPRA, MIOSA acts as a service provider with respect to customer data. We do not sell or share personal information, and we do not retain, use, or disclose personal information for any purpose other than the business purposes set out in the agreement, except as permitted by law. We comply with the applicable obligations that data protection law places on service providers, and we will notify you if we determine that we can no longer meet those obligations.
14. Liability
Each party's liability under this Addendum is subject to the limitations of liability in the agreement between us. Nothing in this Addendum limits a data subject's rights under applicable data protection law, and nothing in it limits either party's liability where the law does not permit limitation.
15. Annex 1: Details of processing
| Element | Detail |
|---|---|
| Subject matter | Provision and operation of the Services, including Sandboxes, Computers, Agents, App Engine, Databases, and Storage. |
| Duration | For the term of the agreement, plus the deletion period described in section 10. |
| Nature and purpose | Hosting, computing, storage, networking, authentication, and support necessary to deliver the Services. |
| Categories of data subjects | Your account users and any end users whose data you process in your workloads. |
| Categories of personal data | Account and contact data, authentication data, workload metadata, and any personal data you choose to store in your workloads. |
16. Annex 2: Technical and organizational measures
The following measures are maintained to protect personal data.
- Per-workload microVM isolation, so that each workload runs in its own virtual machine with a dedicated kernel and cannot reach another customer's data or processes.
- Encryption of data in transit using TLS, with HTTPS enforced for all platform endpoints.
- Encryption at rest for credentials and secrets before they are written, decrypted only at the boundary where they are needed and never returned in plaintext.
- Multi-factor authentication for account and administrative access.
- SAML single sign-on for organizations that require it.
- Role-based access control, so that access to systems and data follows least privilege.
- Scoped API keys, which limit what a key can reach and can be revoked.
- Audit logging of security-relevant actions.
- An egress allowlist that restricts outbound network access from workloads.
- A secrets vault for the storage and controlled retrieval of sensitive values.
- Signup verification, to reduce automated account creation and abuse.
17. Annex 3: Subprocessors
The authorized subprocessors, each with its purpose and the data category involved, are listed at https://miosa.ai/legal/subprocessors.
18. Request the executable DPA
An executable copy of this Addendum, including the Standard Contractual Clauses where they apply, is available on request. Request it from the Trust Center or email enterprise@miosa.ai.