Data Processing Agreement
Our standard Article 28 terms. Smaller customers can rely on this published version; regulated and enterprise customers get a counter-signed copy with bespoke security schedules.
0. About this document
This is Moksy’s standard Data Processing Agreement ("DPA") under Article 28 of the UK GDPR. It applies whenever a customer (the "Controller") uses our platform to process personal data and we (the "Processor") handle that data on their behalf.
Smaller customers can rely on this published version. Regulated or enterprise customers should email [email protected] for a counter-signed copy with bespoke security schedules.
1. Subject matter and duration
Moksy processes Controller personal data only for the duration of the customer’s active subscription, and only to deliver the services described in the Terms of Service. On termination, data is retained for 30 days for export, then deleted or anonymised per Section 9.
2. Nature and purpose of processing
Storage, derivation, expert review, and report generation of software requirements provided by the Controller. The platform does not enrich data with third-party demographic feeds and does not perform automated decision-making with legal effects on data subjects.
3. Categories of data subjects and personal data
| Data subject | Personal data categories |
|---|---|
| Customer account holders | Email, name, hashed password, role, level grants, project ACL membership. |
| Customer end-users (entered by the Controller) | Whatever the Controller chooses to include in project narratives. Moksy treats this as user content and does not parse it for personal data. |
| Marketplace experts | Public profile (track, level, declared statement), wallet ledger, KYC status flag — no identity-document content is stored. |
4. Controller and Processor obligations
The Controller will:
- Provide the lawful basis for any personal data uploaded.
- Issue and revoke access credentials to its own end-users.
- Notify Moksy of any data subject request requiring Processor action within 5 working days.
Moksy (Processor) will:
- Process personal data only on documented Controller instructions — that is, through the platform.
- Ensure personnel with access are under written confidentiality obligations.
- Take the security measures listed in Schedule A (Section 8).
- Assist the Controller with data subject rights through the export and erasure tools in the account, and through [email protected] for anything those do not cover.
- Return or delete Controller data at the end of the engagement, save for hashed-tombstone audit rows kept under legitimate interest (Section 9).
5. Sub-processors
| Sub-processor | Service | Location |
|---|---|---|
| Stripe Payments Europe Ltd. | Payment processing | Ireland (EEA) |
| OpenAI Ireland Ltd. | Language-model derivation and chat | Ireland (EEA) — zero-day retention |
| MongoDB Atlas | Primary database | London, UK |
| Cloudflare, Inc. | CDN and bot management | Global (TLS-only edge) |
| Postmark / Mailgun | Transactional email | EU regions |
Adding a sub-processor requires 30 days’ advance notice. The Controller may object by email and terminate the affected service if a workaround cannot be agreed.
6. International transfers
No personal data is transferred outside the UK or EEA without an appropriate transfer mechanism — Standard Contractual Clauses and/or the UK International Data Transfer Addendum. Moksy pins all sub-processors to UK/EEA regions where the service supports region pinning.
7. Data subject rights
Moksy provides self-service tools for access (data export) and erasure, under Articles 15 and 17 respectively. For rights requiring human judgement — objection and restriction — the Controller should forward the request to [email protected] and Moksy will respond within one calendar month.
8. Security measures (Schedule A)
- TLS 1.2 or better in transit; AES-256 at rest for the primary database and backups.
- Role-based access control with a per-endpoint audit log.
- Per-track expert level enforcement on every privileged action (UK GDPR Art. 32(1)(b)).
- Rate limiting on AI-spend endpoints, to prevent abuse-driven data exfiltration.
- Quarterly access reviews; mandatory two-factor authentication for the administrator tier.
- Incident response: notification to the Controller within 72 hours of becoming aware of a personal-data breach (UK GDPR Art. 33).
9. Retention and deletion
On termination, Controller-owned data is hard-deleted within 30 days. Audit log rows where the Controller’s users were the actor are anonymised via a SHA-256 hashed tombstone rather than deleted, under the legitimate-interest basis for fraud detection. Credit-ledger rows follow the same anonymisation pattern for financial-record retention.
10. Liability and indemnity
The liability cap under the master Terms of Service applies. This DPA does not increase or decrease that cap; it allocates responsibility for processor-side versus controller-side acts as Article 28 requires.
11. Signature
For smaller tiers, acceptance of the Terms of Service constitutes acceptance of this DPA. Customers requiring a counter-signed copy should email [email protected].