1. What this addendum is and how it is used
This addendum sets the terms on which MetaMinds processes personal data on a client’s behalf. It attaches to, and forms part of, the agreement between us for the services, alongside the terms of service. On anything about personal data, this addendum wins over the rest of the agreement.
It is published so your own counsel can read it before you book a call rather than a week after. It is our draft. If you would rather work from your own, send it and we will sign a reasonable one; we do not insist on our paper.
| Processor | NexManas Tech Pvt Ltd, trading as MetaMinds |
|---|---|
| Entity type | Private Limited Company |
| Registered office | Provided on request |
| Corporate Identity Number | Provided on request |
| Processing location | [data processing region pending] |
| Data protection contact | privacy@metaminds.store |
| Controller | [client legal name to be entered on execution] |
The processor is named in full above. Registration numbers are withheld by choice rather than missing: they are public record, are sent on request, and appear on every invoice and engagement letter. Bracketed entries elsewhere in this document are a different thing. Some are the counterparty details a signed copy fills in, and the rest are drafting decisions still with our lawyer. They are printed as visible gaps rather than filled with something plausible, because a processor agreement naming a company that does not exist is not a processor agreement.
2. Definitions
Data Protection Law means every law about personal data that applies to the processing under the agreement, including the EU General Data Protection Regulation 2016/679, the UK GDPR and the Data Protection Act 2018, and India’s Digital Personal Data Protection Act 2023.
Controller, processor, data subject, personal data, processing, special category data and personal data breach carry the meanings the GDPR gives them. Under the DPDP Act, the controller is the Data Fiduciary, the processor is the Data Processor and the data subject is the Data Principal; those terms are read as equivalents here.
Client Personal Data means personal data that MetaMinds processes on the client’s behalf under the agreement. Subprocessor means a third party engaged by MetaMinds to process Client Personal Data.
3. Roles
You are the controller and we are the processor for all Client Personal Data. You decide the purposes and the means; we act on your documented instructions and on nothing else.
Where you are yourself a processor for your own customers, we are a subprocessor, this addendum is read accordingly, and you confirm you have the authority from your controller to appoint us.
You confirm that you have a lawful basis for the processing you ask us to perform, that you have given the notices and obtained the consents your own obligations require, and that your instructions to us do not require us to break Data Protection Law.
MetaMinds is a separate and independent controller for a small set of data: the contact details of your staff who deal with us, our billing records, and the website data described in the privacy notice. This addendum does not cover that; the privacy notice does.
4. Subject matter, nature, purpose and duration
| Subject matter | Provision of the services described in the order form or statement of work. |
|---|---|
| Nature of the processing | Collection, storage, retrieval, indexing, embedding, analysis, testing, evaluation, structuring and deletion, as far as each is needed to deliver the services. |
| Purpose | Building, assessing, testing and improving the AI system named in the order form, and reporting the results back to you. No other purpose. |
| Duration | The term of the engagement, plus the deletion window in section 11. Backup expiry can extend it by up to 30 further days, which is also in section 11. |
| Frequency | Continuous for the term of the engagement, or one-off where the order form describes a single data transfer. |
The order form can narrow any of these for a specific engagement. It cannot widen them without a written amendment signed by both of us.
5. Categories of personal data and data subjects
This is the default set. The order form for your engagement replaces it with the actual list, and that list is what governs.
| Data subjects | Categories of personal data |
|---|---|
| Your employees and contractors | Name, work contact details, job title, system identifiers and access logs |
| Your customers or clients, where their records sit in a corpus under test | Whatever those records contain: identifiers, contact details, account and policy details, correspondence |
| Third parties named inside documents you give us, such as parties to a case, claimants or counterparties | Whatever the documents contain, which we do not control and cannot narrow for you |
Special category data is not accepted by default
Health data, biometric data, data about criminal offenses and the other special categories can appear in legal, insurance and healthcare corpora. We do not accept any of it by default.
If an engagement will touch special category data, it has to be named in the order form before work starts, with the additional safeguards agreed in writing. Sending it to us without that is a breach of your instructions to us, not ours.
We will always ask for synthetic, redacted or sampled data first. A large part of assessment and evaluation work does not need real personal data at all, and the cheapest way to reduce risk is not to transfer it.
6. What MetaMinds commits to as processor
These are the Article 28(3) obligations, written out rather than cross referenced. We will:
- Process only on your documented instructions, including on any transfer to another country, unless a law we are subject to requires otherwise, in which case we tell you before processing unless that law forbids it on public interest grounds.
- Tell you if we think an instruction breaks the law. We will say so in writing and will not carry it out while the point is open.
- Bind everyone with access to confidentiality, by contract or statutory duty, and give access only to the named people who need it for your engagement.
- Apply the security measures in section 8, and not reduce them during the engagement.
- Use subprocessors only on the terms in section 7, and stay fully liable to you for what they do.
- Help you answer data subject requests, as set out in section 9.
- Help you with security, breach notification, data protection impact assessments and prior consultation under Articles 32 to 36, taking account of the nature of the processing and what we actually know.
- Delete or return the data at the end, on the terms in section 11.
- Give you the information you need to demonstrate compliance with Article 28, and submit to audits on the terms in section 12.
- Never use Client Personal Data to train or fine-tune any model, ours or a provider’s, and never place it in a shared evaluation set. Where a model provider sits in the processing path, the account is configured so that submitted content is not retained for training.
7. Subprocessors
The default arrangement uses no subprocessor for your data at all. Our retrieval stack is self-hostable, and where it runs inside your own infrastructure your documents never leave it. In that arrangement the list below applies only to our own records about the engagement, such as correspondence with your team.
Where processing happens on our side, you give general written authorization for the categories of subprocessor in Annex B, and:
- A current list naming each subprocessor, what it processes and in which country, is published at /legal/subprocessors. That page is the named list operating within the categories authorized in Annex B below; it is not itself an annex, and it is updated on the day a change takes effect. Where an upstream provider gives us less warning than the notice period below, we pass it on as soon as we have it and the shorter period governs, because we cannot commit on a vendor’s behalf to a period it does not offer.
- We give you at least 30 days written notice before adding or replacing one.
- You may object within those 30 days on reasonable data protection grounds. We will try to resolve it, and if we cannot, you may terminate the affected part of the engagement without penalty and we refund fees paid for work not yet done.
- Every subprocessor is bound by written terms that are no weaker than this addendum, and we remain liable to you for their acts and omissions as if they were our own.
8. Security measures
These are the measures we apply to Client Personal Data, and they are Annex C for the purpose of any Standard Contractual Clauses.
- Encryption. All connections carrying Client Personal Data use TLS 1.2 or higher. Where MetaMinds controls the storage, Client Personal Data is encrypted at rest using AES-256 or an equivalent industry-standard cipher. Where processing happens inside the Client’s own tenancy or infrastructure, the Client’s encryption controls apply and MetaMinds does not weaken, disable or work around them. The specific configuration for an engagement is recorded in that engagement’s architecture document, which is provided to the Client and may be audited.
- Access control. Named, least-privilege credentials issued to the specific engineers on your engagement. No shared accounts. Multi-factor authentication on every system that supports it. Access you grant is access you can revoke without asking us first.
- Separation. Your data is not mixed with another client’s working set, and production data is not copied into development or test environments.
- Endpoints. Full-disk encryption, automatic screen lock and current operating system patches on every machine that touches client data.
- Resilience. Where MetaMinds holds Client Personal Data in a system of its own, that system is backed up on a stated schedule and its restores are tested rather than assumed, and the schedule is recorded in the engagement’s architecture document. No such system exists today, so today there is nothing on our side to back up: correspondence sits with the email provider named on the subprocessors page and is covered by their retention.
- Deletion. Working copies destroyed at completion, or earlier on your request, and confirmed to you in writing.
- People. Confidentiality obligations for everyone with access, and access removed when someone leaves the engagement.
Where your own security requirements go beyond this list, they go in the order form and they override it. We would rather meet a stricter standard you can name than argue about a general one.
These are commitments, not audited controls
MetaMinds does not hold a SOC 2 Type II attestation and is not certified to ISO/IEC 42001 or ISO/IEC 27001. The measures above are contractual commitments we make and keep. They have not been tested by an external auditor, and we are not going to describe them as if they had been.
If your procurement process requires an audited control environment, say so on the first call. We will tell you plainly whether the engagement is workable, rather than letting it fail at diligence.
9. Helping you answer data subject requests
If a data subject contacts us directly about data we hold for you, we will not answer them substantively. We will forward the request to your named contact without undue delay and in any case within 3 business days, and we will tell the person we have passed it on and to whom.
We will help you meet requests for access, rectification, erasure, restriction, portability and objection, using the tooling and the access we have. For a reasonable volume of requests that help is free. If the volume becomes disproportionate we will agree a charge with you in advance and in writing, never after the fact.
The same applies to the DPDP Act rights of access, correction, erasure, grievance redressal and nomination, where MetaMinds is your Data Processor.
10. Personal data breaches
Notification within 24 hours
We notify your named contact of a personal data breach affecting Client Personal Data without undue delay, and in any event within 24 hours of becoming aware of it.
The first notice will not be complete, and we will not hold it back to make it complete. It will say what we know, what we do not know yet, what we are doing, and when the next update is coming. Updates continue until the matter is closed. A processor who waits for a full picture is a processor who has spent the controller’s statutory deadline for them.
As information becomes available, we will provide:
- the nature of the breach, including what happened and when;
- the categories and approximate number of data subjects and records affected;
- the likely consequences;
- the measures we have taken or propose to take, including to limit the damage;
- a named contact on our side who can answer questions.
Whether to notify a supervisory authority or the data subjects is your decision, not ours. It is a controller decision and we will not make it for you. What we will do is give you what you need to make it inside your own 72 hour deadline under Article 33. Where the DPDP Act applies, we support you as Data Fiduciary in meeting the notification duties owed to the Data Protection Board of India and to affected Data Principals; the exact timings there are set by rules made under the Act and are [DPDP breach timelines pending confirmation].
We keep a record of every breach, its effects and the action taken, and you may see the entries relating to you.
11. Deletion or return at the end
At the end of the engagement, or earlier if you ask in writing, we delete or return Client Personal Data at your choice. The default is deletion, because keeping data we no longer need is a liability for both of us.
- You tell us which you want. If you tell us nothing, we delete after 30 days and remind you before we do.
- Return is in a commonly used, machine readable format, over an encrypted channel.
- Deletion from live systems happens within 30 days of the end of the engagement, and we confirm it to you in writing.
- Where backups exist, an encrypted copy can survive a deletion for up to 30 further days before the backup expires. Backup copies are never restored to live systems except to recover from a failure, they are not accessed for any other purpose, and this addendum keeps applying to them until they expire. This clause is conditional rather than absolute because MetaMinds currently operates no backups of its own; see the resilience item in section 8.
- We keep only what a law requires us to keep. If that happens we tell you what it is, why, and for how long, and it stays protected by this addendum for the whole period.
12. Audit and inspection
- You may verify our compliance with this addendum once in any 12 month period, and more often if a supervisory authority requires it or after a breach affecting your data.
- The first step is a written questionnaire together with our documentation. We answer within 20 business days.
- If that does not answer the question, you may audit us remotely or on site on 30 days notice, during business hours, without unreasonable disruption. You may use an independent auditor who is not a competitor of ours and who signs a confidentiality undertaking.
- You bear your own audit costs and we bear ours, unless the audit finds a material breach of this addendum, in which case we bear both.
We cannot offer a report in place of an audit
We do not hold a SOC 2 Type II report or an ISO certificate, so we cannot offer one as a substitute for the audit rights above. Most processor agreements do exactly that. We are telling you now, rather than at the point where your auditor asks for the report and discovers it does not exist.
13. International transfers
The application server and the database that hold Client Personal Data run on hardware operated by MetaMinds in [data processing region pending]. The website itself is served from a global content delivery network, which holds no Client Personal Data.
The transfer mechanism is not in place yet
If you are established in the EEA or the UK, sending Client Personal Data to us is a restricted transfer to a country with no European Commission adequacy decision as at the date on this draft.
The mechanism intended is the Commission’s 2021 Standard Contractual Clauses, module two for controller to processor, with the UK International Data Transfer Addendum where the UK GDPR applies, plus a transfer impact assessment. None of those has been executed. The position is [transfer mechanism pending legal review].
Do not treat this section as a transfer mechanism until it is signed. The arrangement that removes the question entirely is a deployment inside your own infrastructure and your own region, which we support and which most regulated buyers choose for this exact reason.
Where the Standard Contractual Clauses are executed between us, they prevail over this addendum on any conflict. Annex A of this addendum serves as their Annex I, Annex C as their Annex II and Annex B as their Annex III, all of which are mapped in section 16. The docking clause is available so an affiliate of yours can join.
14. Liability, precedence and governing law
The limitation of liability in the terms of service applies to this addendum, and a claim under this addendum counts against the same cap rather than creating a second one. Nothing here limits a data subject’s rights under Data Protection Law or a supervisory authority’s powers.
If this addendum conflicts with the rest of the agreement, this addendum wins on anything about personal data. Executed Standard Contractual Clauses win over this addendum.
The governing law and forum follow the agreement, which means they are [governing law pending] and [dispute forum pending] until that is settled. Where Standard Contractual Clauses are executed, the law and forum they specify govern the clauses themselves.
15. Signature
This page is not a signed document
Nothing on this page binds either party. It is a published draft for your counsel to mark up. An executed copy is produced with the order form for your engagement, and it is that copy, signed by both sides, that has effect.
| For the controller | For the processor |
|---|---|
| Entity: [client legal name pending] | Entity: NexManas Tech Pvt Ltd |
| Signatory: [client signatory pending] | Signatory: [MetaMinds signatory pending] |
| Title: [title pending] | Title: [title pending] |
| Date: [date pending] | Date: [date pending] |
16. Annexes
For anyone mapping this document onto the Standard Contractual Clauses, the annexes are these sections rather than separate attachments.
- Annex A, parties and processing description. Section 1 for the parties, section 4 for the subject matter, nature, purpose and duration, and section 5 for the categories of data and data subjects. This is Annex I of the Standard Contractual Clauses.
- Annex B, subprocessors. The table below, with the named list supplied on request under section 7. This is Annex III of the Standard Contractual Clauses.
- Annex C, technical and organizational measures. Section 8. This is Annex II of the Standard Contractual Clauses.
Annex B: authorized categories of subprocessor
| Category | What it processes |
|---|---|
| Website hosting and content delivery | Serving the public website. No Client Personal Data, and request logs only. |
| Application and database hosting | Authorized as a category and currently unused. MetaMinds operates no application server and no database today, so no Client Personal Data is held on our side by this route. If one is introduced, it is named on the subprocessors page and notified under section 7 before it processes anything. |
| Transactional email delivery | Correspondence with your team, and engagement notifications. |
| Calendar booking | Name, email and chosen slot when a call is booked. |
| Large language model API | Text submitted to a model during a build or an evaluation, and messages sent to the on-site assistant. Configured so submitted content is not retained for training. |
| Cookieless website analytics | Aggregate page counts with no per-visitor record. No Client Personal Data. |
Provider names and the country each processes in are in the current subprocessor list, which we give you before contract. Ask privacy@metaminds.store.