Data Processing Agreement (DPA)
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Mintlyr AI Inc. and you.
1. Purpose and Scope
This DPA applies where Mintlyr processes Personal Data on your behalf in the course of providing the Services. It ensures that our data processing activities comply with GDPR, CCPA, and other applicable data protection laws.
2. Roles and Responsibilities
- Controller: You, the customer, determine the purposes and means of processing.
- Processor: Mintlyr, processing data only on your documented instructions.
3. Technical and Organizational Measures
Mintlyr implements advanced security measures to protect personal data, including:
- Encryption of data in transit (TLS 1.3) and at rest (AES-256).
- Regular vulnerability scanning and security audits.
- Strict access controls based on the principle of least privilege.
4. Data Transfers
We process data on high-performance servers in secure data centers. We ensure that any international data transfers are protected by standard contractual clauses or equivalent safeguards.
5. Sub-processors
Mintlyr uses a limited number of sub-processors (such as Supabase for database management and Cloudflare for CDN) to deliver its services. We maintain a list of all current sub-processors and notify users of any changes.