Data Processing Addendum
GDPR Art. 28 processor terms, Standard Contractual Clauses by reference, security measures annex, breach notification.
Effective date: 2026-09-25. Operator: Kotoba Labs Inc., a Delaware corporation (United States).
Draft. Published 2026-09-25 and pending review by counsel. It describes how the service works today and may change; the date above changes with every revision. Questions: legal@mithril.fund.
This Data Processing Addendum forms part of the agreement between Customer and Kotoba Labs Inc. (the MSA and Order Forms, or the Terms of Service) when we process Customer Personal Data on Customer's behalf. Request a countersigned copy at legal@mithril.fund.
1. Roles and scope
Customer is the controller (or a processor on behalf of its controller) and we are the processor of personal data contained in content Customer submits to the service (“Customer Personal Data”). Annex I describes the processing.
2. Processor obligations (GDPR Art. 28(3))
- Process Customer Personal Data only on Customer's documented instructions, including for transfers, unless law requires otherwise (and then inform Customer unless prohibited).
- Ensure persons authorised to process it are bound by confidentiality.
- Implement the measures in Annex II (Art. 32).
- Engage subprocessors only as in section 3.
- Assist Customer, by appropriate measures, in responding to data-subject requests.
- Assist Customer with security, breach notification, impact assessments and prior consultation (Arts. 32–36).
- At Customer's choice, delete or return Customer Personal Data at the end of the services, unless law requires storage.
- Make available information necessary to demonstrate compliance and allow for and contribute to audits, as in section 6.
3. Subprocessors
Customer authorises the subprocessors listed on /legal/subprocessors/. We will announce a new subprocessor on that page at least 30 days before it processes Customer Personal Data; Customer may object on reasonable data-protection grounds, and if we cannot address the objection Customer may terminate the affected service. We impose data-protection terms on each subprocessor no less protective than this DPA and remain liable for them.
4. International transfers
Where Customer Personal Data is transferred from the EEA, Switzerland or the UK to a country without an adequacy decision, the parties incorporate by reference the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 — Module 2 (controller to processor) or Module 3 (processor to processor) as applicable — with Annexes I and II below completing their appendices and Clause 9 option 2 (general authorisation, 30 days' notice) selected; the EU Member State whose law and courts apply under Clauses 17 and 18 is named in the Order Form or countersigned DPA; and for the UK, the International Data Transfer Addendum issued by the ICO. Data residency is described on /legal/subprocessors/; no region is pinned today.
5. Personal data breach
We notify Customer without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data, with the information Art. 33(3) requires as it becomes available, and we take reasonable steps to contain and remedy it.
6. Audits
We answer reasonable written security questionnaires once a year. We do not hold a SOC 2 report or ISO certification today (see the Trust Center). Where the information provided is insufficient to demonstrate compliance, Customer may conduct an audit on 30 days' notice, during business hours, at its cost, under confidentiality, no more than once a year unless a breach or regulator requires it.
Annex I — Description of processing
| Item | Description |
|---|---|
| Data subjects | Customer's users; individuals whose data appears in content Customer submits. |
| Categories of data | Account identifiers; content of prompts, messages, code and files submitted for analysis; model output; request metadata. Customer should not submit special-category data unless agreed in an Order Form. |
| Nature and purpose | Providing inference, research, screening and storage services as instructed by Customer. |
| Duration and retention | For the term; research job records are deleted after 6 hours; other retention as in the Privacy Policy section 8. |
| Transfers | To the subprocessors on /legal/subprocessors/, which may be outside the EEA/UK. |
Annex II — Technical and organisational measures
- Encryption in transit (TLS) for every public host; data at rest on Cloudflare storage, which encrypts stored objects.
- Access: passwordless sign-in (email link, Google, GitHub or Passkey; sensitive operations require higher-assurance methods); scoped, revocable API tokens (stored as identifiers only, never the token); operator actions require signed requests on a separate admin origin.
- Isolation: jobs and records are bound to their principal; there is no public route that reads another principal's job text.
- Minimisation: research job records are deleted after 6 hours; card data never reaches our systems (Stripe); the server executes no tools on Customer's behalf.
- Screening: a separate screening model checks requests against the Acceptable Use Policy; blocks are recorded with receipts.
- Logging and monitoring: platform logs on Cloudflare; an audit log of security-relevant events.
- Vulnerability management: a public Vulnerability Disclosure Policy at /security/vdp/ and /.well-known/security.txt.
- Incident response: breach notification as in section 5.
- Subprocessor management: section 3.