Data Processing Agreement

Our standard Article 28 terms. Smaller customers can rely on this published version; regulated and enterprise customers get a counter-signed copy with bespoke security schedules.

0. About this document

This is Moksy’s standard Data Processing Agreement ("DPA") under Article 28 of the UK GDPR. It applies whenever a customer (the "Controller") uses our platform to process personal data and we (the "Processor") handle that data on their behalf.

Smaller customers can rely on this published version. Regulated or enterprise customers should email [email protected] for a counter-signed copy with bespoke security schedules.

1. Subject matter and duration

Moksy processes Controller personal data only for the duration of the customer’s active subscription, and only to deliver the services described in the Terms of Service. On termination, data is retained for 30 days for export, then deleted or anonymised per Section 9.

2. Nature and purpose of processing

Storage, derivation, expert review, and report generation of software requirements provided by the Controller. The platform does not enrich data with third-party demographic feeds and does not perform automated decision-making with legal effects on data subjects.

3. Categories of data subjects and personal data

Data subjectPersonal data categories
Customer account holdersEmail, name, hashed password, role, level grants, project ACL membership.
Customer end-users (entered by the Controller)Whatever the Controller chooses to include in project narratives. Moksy treats this as user content and does not parse it for personal data.
Marketplace expertsPublic profile (track, level, declared statement), wallet ledger, KYC status flag — no identity-document content is stored.

4. Controller and Processor obligations

The Controller will:

Moksy (Processor) will:

5. Sub-processors

Sub-processorServiceLocation
Stripe Payments Europe Ltd.Payment processingIreland (EEA)
OpenAI Ireland Ltd.Language-model derivation and chatIreland (EEA) — zero-day retention
MongoDB AtlasPrimary databaseLondon, UK
Cloudflare, Inc.CDN and bot managementGlobal (TLS-only edge)
Postmark / MailgunTransactional emailEU regions

Adding a sub-processor requires 30 days’ advance notice. The Controller may object by email and terminate the affected service if a workaround cannot be agreed.

6. International transfers

No personal data is transferred outside the UK or EEA without an appropriate transfer mechanism — Standard Contractual Clauses and/or the UK International Data Transfer Addendum. Moksy pins all sub-processors to UK/EEA regions where the service supports region pinning.

7. Data subject rights

Moksy provides self-service tools for access (data export) and erasure, under Articles 15 and 17 respectively. For rights requiring human judgement — objection and restriction — the Controller should forward the request to [email protected] and Moksy will respond within one calendar month.

8. Security measures (Schedule A)

9. Retention and deletion

On termination, Controller-owned data is hard-deleted within 30 days. Audit log rows where the Controller’s users were the actor are anonymised via a SHA-256 hashed tombstone rather than deleted, under the legitimate-interest basis for fraud detection. Credit-ledger rows follow the same anonymisation pattern for financial-record retention.

10. Liability and indemnity

The liability cap under the master Terms of Service applies. This DPA does not increase or decrease that cap; it allocates responsibility for processor-side versus controller-side acts as Article 28 requires.

11. Signature

For smaller tiers, acceptance of the Terms of Service constitutes acceptance of this DPA. Customers requiring a counter-signed copy should email [email protected].

Related documents

The privacy policy covers what we do as a controller; this covers what we do as a processor.