mvdm.io · legal
Data Processing Agreement
Effective . A later edit replaces this page in place.
This Data Processing Agreement (the “DPA”) forms part of the contract between mvdm.io (sole proprietorship, KvK 86594737) and the customer organisation that uses Compliance (“Customer”). It covers processing of personal data under the EU General Data Protection Regulation (EU GDPR) and the UK GDPR.
1. Roles
mvdm.io is the processor for personal data that Customer stores in Compliance as ISMS content — including People, evidence, Assistant transcripts, and imports — when Customer determines the purposes and means of that processing.
mvdm.io is the controller for sign-in and account administration, billing, first-party request analytics, and the public marketing site. That controller processing is described in the Privacy Notice, not in this DPA’s processor instructions.
2. Subject matter and duration
Subject matter: hosting and operating Compliance so Customer can run its ISMS. Duration: for as long as Customer has a Compliance license, plus the closed-license retention period below, unless the parties agree otherwise in writing.
3. Nature and purpose of processing
mvdm.io processes ISMS personal data only to provide Compliance, including storage, display, search, backup of live systems, Assistant features, import extraction, and snapshot prose generation, and to support Customer on request. mvdm.io does not process that ISMS content for its own marketing.
4. Types of data and data subjects
Categories depend on what Customer uploads or enters. They typically include names, contact details, roles, and other personal data Customer chooses to keep in policies, registers, evidence, imports, and Assistant conversations. Data subjects are people Customer includes in its ISMS (employees, contractors, and others Customer records).
5. Customer instructions
Customer instructs mvdm.io to process ISMS personal data as needed to provide Compliance and as Customer directs through the product. mvdm.io will not process that data for other purposes except as required by law. If an instruction appears to infringe EU GDPR or UK GDPR, mvdm.io will inform Customer.
6. Confidentiality
People authorised to process ISMS personal data for mvdm.io are under confidentiality obligations.
7. Technical and organisational measures
mvdm.io implements appropriate technical and organisational measures, including:
- transport encryption for access to the applications;
- account-scoped tenancy so one customer’s Compliance data is not served to another customer’s users;
- authentication through a dedicated sign-in service and access limited to authorised account users;
- hosting with a professional provider in the EEA and operational access limited to people who need it;
- application logging and first-party request analytics aimed at security and reliability;
- deletion of an account’s Compliance data after the closed-license retention window when no current license remains.
A Platform Administrator may read Assistant conversations for support and quality.
8. Subprocessors
Customer authorises mvdm.io to use the subprocessors listed on the public Subprocessor list. That page is incorporated by reference. mvdm.io remains responsible for subprocessors’ performance of the processing obligations under this DPA.
9. International transfers
Application hosting is with Hetzner in the EEA. The following subprocessors process relevant data in the United States: Stripe (payments), xAI (Assistant content), Anthropic (import extraction and snapshot prose), and Cloudflare Email (email delivery). Where required, transfers rely on appropriate safeguards such as the providers’ standard contractual clauses or other lawful transfer mechanisms they offer.
10. Artificial intelligence subprocessors
Assistant content is sent to xAI. Import extraction and snapshot prose are sent to Anthropic. This DPA does not promise that those providers never use content to train models.
11. Assistance, breach, and audits
Taking into account the nature of the processing, mvdm.io will assist Customer with data-subject requests, security, breach notification, and data-protection impact assessments where reasonably possible through the product or by email. mvdm.io will notify Customer without undue delay after becoming aware of a personal-data breach affecting Customer’s ISMS data. Audit rights are exercised reasonably, no more than once per year unless a breach or competent authority requires otherwise, and in a way that does not compromise other customers’ security.
12. Return and deletion — closed-license retention
Until a full product export exists, Customer may request return of Compliance data by email to michiel@mvdm.io during an active license or the retention window. When a Compliance license ends, mvdm.io keeps that account’s Compliance data for 365 days from the license end date. A new current Compliance license in that window cancels the countdown. If no current license remains after 365 days, mvdm.io deletes that account’s Compliance-schema data and related blobs. Authentication accounts and users are not deleted by that wipe. Backup media are outside the live deletion job described here.
13. Changes to this DPA
mvdm.io may replace this DPA by publishing an updated page with a new effective date. Continued use of Compliance after a replacement is acceptance of the replacement.
14. Governing law
This DPA follows the governing law of the Terms of Service, without prejudice to mandatory data-protection rules.