This Data Processing Agreement ("DPA") supplements the Terms of Service between MokuHub LLC ("Processor") and you ("Controller"). By using our Service, this DPA is automatically incorporated into your agreement with us. If you require a signed copy, contact legal@mokuhub.com.
1. Definitions
"Controller" means the customer who determines the purposes and means of the processing of Personal Data.
"Processor" means MokuHub LLC, which processes Personal Data on behalf of the Controller.
"Personal Data" means any information relating to an identified or identifiable natural person, as defined by GDPR Article 4(1).
"Processing" means any operation performed on Personal Data, as defined by GDPR Article 4(2).
"Subprocessor" means a third party engaged by the Processor to process Personal Data on behalf of the Controller.
"Data Protection Laws" means the GDPR (Regulation (EU) 2016/679), the UK GDPR, the Swiss Federal Act on Data Protection, and any other applicable data protection legislation.
"Service" means MokuBot and/or MokuField, as described in the Terms of Service.
2. Scope and Purpose of Processing
The Processor shall process Personal Data only to the extent necessary to provide the Service as described in the Terms of Service and as further instructed by the Controller.
Subject matter of processing:
Provision of AI-powered assistance for NetSuite (MokuBot) and/or field service management (MokuField)
Duration of processing:
For the term of the agreement, plus the data retention period specified in our Privacy Policy
Nature and purpose of processing:
Account management, AI query processing, usage tracking, billing, communication delivery, security and abuse prevention
Categories of data subjects:
Controller's employees, contractors, and authorized users of the Service
Types of Personal Data:
Email addresses, names, IP addresses, device identifiers, usage data, and any Personal Data included in content submitted to the Service
3. Obligations of the Processor
The Processor shall:
- Process Personal Data only on documented instructions from the Controller, unless required by law
- Ensure that persons authorized to process Personal Data are bound by obligations of confidentiality
- Implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
- Encryption of data in transit (TLS 1.2+) and at rest
- Hashing of sensitive identifiers (SHA-256)
- Access controls and authentication (Google OAuth 2.0)
- Regular security assessments
- Principle of least privilege for internal access
- Not engage another processor (subprocessor) without prior written authorization of the Controller (see Section 5)
- Assist the Controller in responding to data subject rights requests
- Assist the Controller in ensuring compliance with data breach notification obligations
- At the Controller's choice, delete or return all Personal Data after the end of the provision of the Service
- Make available to the Controller all information necessary to demonstrate compliance with this DPA
4. Obligations of the Controller
The Controller shall:
- Ensure that there is a lawful basis for the processing of Personal Data
- Provide documented instructions to the Processor regarding the processing of Personal Data
- Ensure that data subjects have been informed of the processing in accordance with Data Protection Laws
- Comply with all obligations applicable to controllers under Data Protection Laws
- Not submit sensitive or special categories of data (as defined in GDPR Article 9) to the Service unless explicitly agreed in writing
5. Subprocessors
The Controller provides general written authorization for the Processor to engage the subprocessors listed in our Privacy Policy (Third-Party Service Providers section).
The Processor shall:
- Notify the Controller of any intended changes to subprocessors at least 30 days in advance
- Provide the Controller an opportunity to object to such changes
- Impose the same data protection obligations on subprocessors as set out in this DPA
- Remain fully liable for the acts and omissions of its subprocessors
The current list of subprocessors is maintained in our Privacy Policy.
6. International Data Transfers
Where Personal Data is transferred outside the EEA/UK/Switzerland, the Processor shall ensure that appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission (Commission Implementing Decision (EU) 2021/914)
- Certifications under the EU-US Data Privacy Framework where applicable
- Adequacy decisions by the European Commission
The Processor has implemented supplementary measures where necessary, including encryption of data in transit and at rest, to address potential risks of government access in third countries.
7. Data Breach Notification
The Processor shall notify the Controller without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data breach. The notification shall include:
- A description of the nature of the breach, including categories and approximate number of data subjects affected
- Contact details of the Processor's data protection point of contact
- A description of the likely consequences of the breach
- A description of measures taken or proposed to address the breach and mitigate its effects
8. Data Subject Rights
The Processor shall assist the Controller in fulfilling its obligation to respond to data subject requests under Data Protection Laws. This includes requests for access, rectification, erasure, restriction, portability, and objection. The Processor shall respond to such assistance requests within 10 business days.
9. Data Deletion and Return
Upon termination of the Service or upon request by the Controller:
- The Controller may request export of their data in a structured, machine-readable format (JSON or CSV) within 30 days of termination
- The Processor shall delete all Personal Data within 30 days after the export window, unless retention is required by law
- Backup copies shall be purged within 90 days of deletion
- The Processor shall certify deletion upon request
10. Audits and Compliance
The Processor shall make available to the Controller all information necessary to demonstrate compliance with this DPA and allow for and contribute to audits, including inspections, by the Controller or an auditor mandated by the Controller.
Audit requests should be made with at least 30 days notice and shall be conducted during normal business hours, no more than once per year, unless a data breach or regulatory investigation necessitates additional audits.
11. Liability
Each party's liability under this DPA is subject to the limitations of liability set out in the Terms of Service, except that neither party limits its liability for breaches of its obligations under Data Protection Laws to the extent such limitation is not permitted by applicable law.
12. Term and Termination
This DPA shall remain in effect for as long as the Processor processes Personal Data on behalf of the Controller. The obligations of the Processor under this DPA shall survive termination to the extent necessary to complete the deletion or return of Personal Data.
13. Governing Law
This DPA shall be governed by the laws that govern the Terms of Service, unless Data Protection Laws require the application of the law of another jurisdiction for specific provisions of this DPA.
Contact
For questions about this DPA, to request a signed copy, or to exercise any rights described herein:
MokuHub LLC - Data Protection
Email: legal@mokuhub.com
Address: 0105, Georgia, Tbilisi, Chugureti district, Mikheil Tsinamdzgvrishvili street, N 52, attic