Data Processing Agreement
Contents
This Data Processing Agreement (DPA) is entered into between Mission Growth Limited (Vendor) and the Customer identified in the applicable Order Form. This DPA forms part of, and is incorporated into, the Master Agreement (as defined in the Terms of Service) and governs all processing of Personal Data by Vendor on behalf of Customer in connection with the Service.
In the event of a conflict between this DPA and the Terms of Service on matters of data processing, this DPA prevails. On all other commercial matters, the Terms of Service prevail.
Capitalized terms not defined in this DPA have the meanings given to them in the Terms of Service.
1. Introduction and Relationship of the Parties
1.1 Incorporation. This DPA is incorporated into and forms part of the Master Agreement. All Order Forms referencing the Terms of Service are subject to this DPA.
1.2 Controller and Processor. For the purposes of applicable data protection law, including the EU General Data Protection Regulation (GDPR), the UK GDPR, the Hong Kong Personal Data (Privacy) Ordinance (PDPO), and the Turkish Personal Data Protection Law (KVKK): (a) Customer is the data controller (or, in KVKK terminology, veri sorumlusu) of the Personal Data processed through the Service; and (b) Vendor is the data processor (or, in KVKK terminology, veri işleyeni) acting on Customer's behalf.
1.3 Scope. This DPA applies to all processing of Personal Data carried out by Vendor in connection with the provision of the Service to Customer. It does not apply to data that Vendor processes as a controller for its own purposes (for example, Customer account contact data, billing information, and platform usage analytics governed by Vendor's Privacy Policy).
1.4 Defined Terms. In this DPA: Data Subject means any identified or identifiable natural person whose Personal Data is processed through the Service. Processing (and process, processes, processed) has the meaning given in applicable data protection law. Personal Data Breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data. Standard Contractual Clauses (SCCs) means the standard data protection clauses for the transfer of Personal Data to third countries adopted by the European Commission pursuant to Commission Implementing Decision 2021/914.
2. Subject Matter and Duration
2.1 Subject Matter. The subject matter of the processing governed by this DPA is the provision of the Service by Vendor to Customer, as described in the Terms of Service and the applicable Order Form.
2.2 Duration. Vendor will process Personal Data on behalf of Customer for the duration of the Master Agreement (including any renewal terms). Upon expiry or termination of the Master Agreement, Vendor will process Personal Data only as necessary to facilitate the data return or deletion process described in Section 13, and will cease all other processing.
3. Nature and Purpose of Processing
3.1 Nature of Processing. Vendor carries out the following processing operations on Customer's behalf:
- Storage and hosting of Customer Data (including Personal Data) on cloud infrastructure provided by Vendor's Sub-processors.
- Transmission and routing of Customer Data between the Service components and Sub-processors.
- AI inference operations, including providing Customer inputs to AI language models to generate AI-Generated Outputs.
- Analytics processing to generate reports, insights, and dashboards as part of the Service.
- Execution of automated workflows and integrations initiated by Customer through the Service.
- Technical operations including backup, logging, monitoring, and security scanning.
3.2 Purpose of Processing. Vendor processes Personal Data solely for the purpose of delivering the Service to Customer in accordance with Customer's instructions as set out in the Master Agreement and any supplementary written instructions provided by Customer. Vendor will not process Personal Data for any other purpose, including Vendor's own business purposes, marketing, or AI model training.
4. Categories of Personal Data
4.1 Categories. The categories of Personal Data processed by Vendor on Customer's behalf may include the following, depending on how Customer configures and uses the Service:
- Account and identity data: Names, email addresses, job titles, and employer organization of Customer's Authorized Users.
- Usage data: Platform interaction logs, session identifiers, feature usage records, and audit trails generated by Authorized Users' interactions with the Service.
- Customer-uploaded content: Any data, documents, files, or content uploaded to the Service by Customer or Authorized Users, which may include Personal Data of the Customer's own clients, employees, or contacts.
- AI inputs and outputs: Queries, prompts, and instructions submitted to AI features of the Service, and the AI-Generated Outputs retrieved in response, which may contain Personal Data to the extent included by Customer.
- Integration data: Data retrieved from third-party platforms connected to the Service by Customer (for example, advertising platform data, CRM records, social media analytics) that may contain Personal Data of Customer's end customers or contacts.
4.2 Special Categories. The Service is not designed or intended for processing special categories of Personal Data (including health data, biometric data, or political opinions as defined under GDPR Article 9). Customer must not submit special categories of Personal Data to the Service unless it has confirmed with Vendor in writing that appropriate safeguards are in place and has obtained explicit consent or identified a valid legal basis under applicable law.
5. Categories of Data Subjects
The categories of Data Subjects whose Personal Data is processed through the Service include:
- Customer's employees and contractors who are granted access to the Service as Authorized Users.
- Customer's end customers, clients, or contacts whose Personal Data is included in Customer Data (for example, CRM records, marketing lists, or advertising audience data uploaded or integrated into the Service).
- Any other natural persons whose Personal Data is included in content or integrations Customer chooses to connect to the Service.
6. Customer (Controller) Obligations
6.1 Lawful Basis. Customer warrants and represents that it has identified and maintains a valid lawful basis under applicable data protection law (including GDPR Article 6, KVKK Article 5, and PDPO DPP1) for each category of Personal Data it submits to the Service, and that such lawful basis remains valid for the duration of the processing.
6.2 Consents and Notices. To the extent required by applicable law, Customer has obtained all necessary consents from Data Subjects and has provided them with all required privacy notices describing the processing of their Personal Data through the Service.
6.3 Instructions. Customer will provide Vendor with documented instructions for the processing of Personal Data. The Master Agreement (including this DPA) constitutes Customer's primary documented instructions. Customer may supplement these instructions by written notice to Vendor. If Customer provides instructions that Vendor reasonably considers to be outside the scope of lawful processing, Vendor will notify Customer before proceeding.
6.4 Data Minimization. Customer is responsible for ensuring that only the minimum Personal Data necessary for the Service is submitted, and for removing Personal Data from Customer Data where it is not required for the purpose of the Service.
7. Vendor (Processor) Obligations
7.1 Processing on Instructions Only. Vendor will process Personal Data only on Customer's documented instructions as set out in this DPA and the Master Agreement, unless processing is required by applicable law, in which case Vendor will inform Customer of such requirement before processing (unless the law prohibits such notification).
7.2 Confidentiality of Processing Staff. Vendor will ensure that all persons authorized by Vendor to process Personal Data are subject to appropriate confidentiality obligations (whether contractual or statutory).
7.3 Security Measures. Vendor will implement and maintain appropriate technical and organizational security measures to protect Personal Data against Personal Data Breaches, as described in Section 14 (Security Measures) and Annex II of this DPA.
7.4 Sub-processors. Vendor will only engage Sub-processors in accordance with Section 8 of this DPA.
7.5 Assistance with Data Subject Rights. Taking into account the nature of the processing, Vendor will provide Customer with reasonable technical and organizational assistance to enable Customer to respond to requests from Data Subjects exercising their rights under applicable data protection law, including rights of access, rectification, erasure, restriction, portability, and objection.
7.6 Assistance with Compliance Obligations. Vendor will provide Customer with reasonable assistance to enable Customer to comply with its obligations under applicable data protection law, including obligations relating to: (a) security of processing (GDPR Article 32); (b) notification and communication of Personal Data Breaches (GDPR Articles 33 and 34); and (c) data protection impact assessments (DPIAs) and prior consultation (GDPR Articles 35 and 36), where the information required for such compliance is held by Vendor and not otherwise available to Customer.
7.7 No Training on Customer Data. Vendor will not use Personal Data processed under this DPA to train, fine-tune, benchmark, or otherwise improve any AI model, whether operated by Vendor or by any Sub-processor.
8. Sub-processors
8.1 General Written Authorization. Customer provides Vendor with general written authorization to engage Sub-processors to assist in providing the Service, subject to the requirements of this Section 8.
8.2 Current Sub-processors. The current list of Vendor's Sub-processors is maintained at missiongrowth.io/legal/subprocessors and is incorporated into this DPA by reference as Annex III. As of the date of this DPA, Vendor's approved Sub-processors include: Supabase Inc. (EU, database infrastructure), Hetzner Online GmbH (Germany, server infrastructure), Vercel Inc. (USA, frontend hosting and CDN), Airwallex Limited (Hong Kong, payment processing), OpenAI LLC (USA, AI model inference), Together AI Inc. (USA, AI model inference), Composio Inc. (USA, integration automation), and PostHog Inc. (EU/USA, product analytics).
8.3 Notice of New Sub-processors. Vendor will provide Customer with at least 30 days' prior written notice (by email or by updating the Sub-processor list at missiongrowth.io/legal/subprocessors) before engaging any new Sub-processor that will process Customer Personal Data.
8.4 Objection to New Sub-processors. Customer may object to Vendor's use of a new Sub-processor on reasonable data protection grounds by notifying Vendor in writing within 30 days of receiving notice under Section 8.3. If Customer raises a reasonable objection, Vendor will use commercially reasonable efforts to resolve the concern. If Vendor is unable to resolve the objection within 30 days, Customer may terminate the affected portion of the Service (where technically separable) with a pro-rata refund of prepaid Fees, without liability to either party for such termination.
8.5 Sub-processor Contracts. Vendor will impose on each Sub-processor data protection obligations that are substantially equivalent to those set out in this DPA. Vendor remains responsible for the acts and omissions of its Sub-processors to the same extent as if Vendor had performed the processing directly.
9. International Data Transfers
9.1 EEA and UK Transfers. Where Customer is established in the European Economic Area (EEA) or the United Kingdom and Personal Data is transferred to Vendor (located in Hong Kong, which does not benefit from a European Commission adequacy decision) or to Sub-processors in non-adequate third countries, the parties rely on the following transfer mechanisms:
- EU SCCs (Module 2): The Standard Contractual Clauses for the transfer of Personal Data from the EEA to third countries (Controller-to-Processor, Module 2), adopted by Commission Implementing Decision 2021/914, are hereby incorporated into this DPA. Customer acts as data exporter and Vendor acts as data importer. A copy of the applicable SCCs is available upon request at contact@missiongrowth.io.
- UK Addendum: For transfers of Personal Data from the United Kingdom, the International Data Transfer Addendum to the EU SCCs (UK IDTA) issued by the Information Commissioner's Office is incorporated into this DPA and applies in addition to the EU SCCs (Module 2).
9.2 KVKK Transfers. For Personal Data relating to Data Subjects in Turkey, Vendor is implementing the Standard Contractual Clauses published by the Turkish Personal Data Protection Authority (KVKK) pursuant to Board Decision No. 2024/959 (effective 10 July 2024). Until such implementation is complete for all relevant Sub-processors, Vendor will not onboard new Turkish data subjects without notifying Customer and confirming the applicable transfer mechanism. Customer acknowledges that KVKK SCC implementation is an ongoing compliance process.
9.3 HK PCPD Recommended Clauses. For transfers of Personal Data collected in Hong Kong to overseas Sub-processors (including US-based Sub-processors), Vendor incorporates the PCPD Recommended Model Clauses for Cross-border Data Transfer (May 2022) in its contracts with applicable Sub-processors as a matter of good-faith compliance practice, in anticipation of mandatory cross-border transfer requirements under pending PDPO reform.
9.4 Transfer Impact Assessments. Where required by applicable law (including KVKK for transfers to countries without an adequacy decision), Vendor maintains Transfer Impact Assessments (TIAs) for the relevant transfer destinations. Copies of TIAs are available to Customer upon reasonable written request.
10. Data Subject Rights Assistance
10.1 Obligation to Assist. Vendor will provide Customer with reasonable technical assistance to enable Customer to respond to Data Subject rights requests within the applicable legal timeframes. Vendor will forward to Customer any Data Subject rights requests received directly by Vendor that relate to Personal Data for which Customer is the controller, without undue delay.
10.2 Response Timeframes. Customer acknowledges the following applicable response deadlines under each relevant law:
- GDPR (EEA): 30 days from receipt of a valid request, extendable by a further 60 days for complex requests with prior notice to the Data Subject.
- UK GDPR: Same as GDPR above.
- HK PDPO (DPP6): 40 days from receipt of a valid access or correction request. No statutory extension; Vendor targets a 35-day internal SLA.
- KVKK (Article 13): 30 days from receipt of a valid request by the data controller.
10.3 Scope of Assistance. Vendor's assistance obligations are limited to: (a) providing Customer with information or access to Personal Data held within the Service platform; and (b) implementing technical deletions, restrictions, or exports where technically feasible within the Service. Vendor is not responsible for Customer's legal assessment of Data Subject requests or for communicating with Data Subjects directly on Customer's behalf.
11. Personal Data Breach Notification
11.1 Notification Obligation. Vendor will notify Customer of a Personal Data Breach without undue delay and, where feasible, within 72 hours of Vendor becoming aware of the breach, to the extent the breach affects Personal Data processed on Customer's behalf under this DPA.
11.2 Notification Content. Vendor's initial notification will include (to the extent available at the time): (a) a description of the nature of the Personal Data Breach; (b) the categories and approximate number of Data Subjects affected; (c) the categories and approximate volume of Personal Data records affected; (d) the likely consequences of the breach; and (e) the measures taken or proposed by Vendor to address the breach and mitigate its possible adverse effects.
11.3 Supplementary Information. If all required information is not available at the time of initial notification, Vendor will provide the remaining information as soon as it is reasonably available, in supplementary notifications.
11.4 Customer Responsibility. Customer is responsible for complying with its own breach notification obligations under applicable data protection law (including notifying the relevant supervisory authority and Data Subjects where required). Vendor's notification to Customer under this Section 11 does not constitute an acknowledgment of fault or liability by Vendor.
11.5 No Applicable Breach. Not every security incident constitutes a Personal Data Breach triggering notification obligations. Vendor will assess incidents against applicable legal thresholds and notify Customer of those incidents that meet the threshold for a reportable Personal Data Breach.
12. Audit Rights
12.1 Audit Frequency. Customer may audit Vendor's compliance with this DPA no more than once per calendar year, except where a Personal Data Breach has occurred or where required by a supervisory authority.
12.2 Audit Procedure. Audits require at least 30 days' prior written notice to Vendor, specifying the scope and proposed timeframe of the audit. Audits must be conducted during normal business hours, in a manner that minimizes disruption to Vendor's operations, and at Customer's expense (including reasonable Vendor staff time costs).
12.3 Audit Reports as Substitute. Vendor may satisfy all or part of its audit obligations under this Section 12 by providing Customer with relevant third-party audit reports, certifications, or attestations (for example, SOC 2 Type II reports from Vendor's Sub-processors such as Supabase), to the extent such reports cover the processing operations relevant to this DPA. Vendor will provide such reports upon reasonable written request.
12.4 Confidentiality of Audit Results. All audit results and reports produced in connection with an audit under this Section 12 are Confidential Information of both parties.
13. Data Return and Deletion
13.1 Return or Deletion on Termination. Within 30 days of the expiry or termination of the Master Agreement, Vendor will, at Customer's written election: (a) make Customer Data available for export using the self-serve export tools within the Service; or (b) securely delete Customer Data from Vendor's systems and, to the extent technically feasible, instruct Sub-processors to delete Customer Data.
13.2 Certificate of Deletion. Upon Customer's written request, Vendor will provide Customer with a written certificate confirming the deletion of Customer Data within a reasonable time after completion of the deletion process.
13.3 Backup Deletion. Customer Data retained in automated backup systems will be deleted on Vendor's routine backup cycle within 90 days of the expiry or termination of the Master Agreement.
13.4 Legal Retention Requirements. Notwithstanding Sections 13.1 and 13.2, Vendor may retain Customer Data (or anonymized aggregates thereof) to the extent required by applicable law, provided that Vendor maintains the confidentiality of such retained data and limits its processing to the purposes required by law.
14. Security Measures (Annex II)
This Section constitutes Annex II to this DPA and describes the technical and organizational measures (TOMs) implemented by Vendor to ensure a level of security appropriate to the risk to Personal Data processed under this DPA.
14.1 Encryption.
- Data at rest: Customer Data is encrypted at rest using AES-256 encryption, implemented through Supabase (PostgreSQL) storage with encryption enabled by default.
- Data in transit: All data transmitted between the Service and users or Sub-processors is encrypted using TLS 1.3 or higher. Connections that do not support TLS 1.2 minimum are rejected.
14.2 Access Control.
- Multi-tenant isolation: Row-Level Security (RLS) policies enforced at the database layer ensure that each Customer's data is logically isolated and inaccessible to other Customers.
- Authentication: Access to the Service is protected by JWT-based authentication with bcrypt password hashing. API keys are hashed before storage.
- Principle of least privilege: Vendor staff access to production systems is limited to authorized personnel on a need-to-know basis. Access rights are reviewed periodically.
- Multi-factor authentication (MFA): Vendor staff with access to production systems are required to use MFA.
14.3 Infrastructure Security.
- Cloud infrastructure is hosted on Hetzner Online GmbH (Germany) and Supabase (EU-Frankfurt region), both of which implement physical and logical security controls consistent with ISO 27001 standards.
- Frontend infrastructure is hosted by Vercel Inc., which maintains SOC 2 Type II certification.
- Network-level protections including firewalls, intrusion detection systems, and DDoS mitigation are applied at the infrastructure level.
14.4 Logging and Monitoring.
- Structured application logging is implemented using industry-standard logging frameworks. Logs include access events, API calls, and error events, and are retained for security monitoring purposes.
- Logs do not include the full content of Customer Data or Personal Data (such as message bodies), but may include metadata such as timestamps, user identifiers, and action types.
- Anomaly detection and alerting are configured to identify unusual access patterns.
14.5 Vulnerability Management.
- Vendor conducts ongoing dependency vulnerability scanning using automated tooling.
- Critical security patches are applied on a priority basis. Vendor targets remediation of critical vulnerabilities within 72 hours of identification.
14.6 Incident Response.
- Vendor maintains an internal incident response procedure that includes detection, classification, containment, notification (as per Section 11), remediation, and post-incident review.
14.7 Sub-processor Security Inheritance.
- Vendor selects Sub-processors that maintain recognized security certifications (SOC 2 Type II, ISO 27001, or equivalent). Relevant Sub-processor certifications include: Supabase (SOC 2 Type II), Hetzner (ISO 27001), Vercel (SOC 2 Type II), OpenAI (SOC 2 Type II), PostHog (SOC 2 Type II).
- Vendor contractually requires Sub-processors to maintain appropriate security measures consistent with applicable data protection law.
14.8 Personnel Training.
- Vendor personnel with access to Personal Data receive privacy and security awareness training appropriate to their role.
15. Liability and Limitations
15.1 Incorporation of Master Agreement Caps. Each party's liability under or in connection with this DPA is subject to the limitations of liability set out in Section 12 of the Terms of Service.
15.2 Data Breach Super-Cap. Vendor's liability for claims arising from a Personal Data Breach due to Vendor's failure to maintain the security measures described in Section 14 (Annex II) is subject to the elevated cap set out in Section 12.3 of the Terms of Service (2 times the general liability cap).
15.3 Mutual Liability. The limitations of liability in the Terms of Service apply mutually. Neither party will be liable for the other party's failure to comply with applicable data protection law where such failure results from the first party's documented instructions or acts or omissions.
15.4 Regulatory Fines. Nothing in this DPA limits either party's liability to a supervisory authority under applicable data protection law, which is governed by applicable statutory provisions and not by these Terms.
16. Conflict and Order of Precedence
16.1 DPA Prevails on Data Processing. In the event of a conflict between this DPA and the Terms of Service on any matter relating to the processing of Personal Data, this DPA prevails.
16.2 Terms of Service Prevails on Commercial Matters. In the event of a conflict between this DPA and the Terms of Service on any commercial matter (including Fees, payment, Term, and termination), the Terms of Service prevail.
16.3 SCC Prevails on International Transfers. Where applicable SCCs or other transfer mechanisms have been incorporated pursuant to Section 9, the applicable SCC clauses prevail over any conflicting provision of this DPA or the Terms of Service to the extent required for the SCCs to be lawful and effective.
16.4 Order Form Prevails. Where an Order Form expressly modifies any provision of this DPA, the Order Form prevails for the applicable Customer relationship.
17. Governing Law
17.1 Governing Law. This DPA is governed by the laws of the Hong Kong Special Administrative Region, consistent with Section 14.1 of the Terms of Service, except to the extent that mandatory provisions of EU, UK, or Turkish data protection law apply by their own terms.
17.2 Dispute Resolution. Disputes arising under this DPA will be resolved in accordance with Section 14 of the Terms of Service (Governing Law and Dispute Resolution), except that either party may seek injunctive relief before any court of competent jurisdiction in respect of imminent or actual Personal Data Breaches or other urgent data protection matters.
17.3 Supervisory Authorities. Nothing in this DPA limits either party's right or obligation to communicate with or lodge complaints with relevant data protection supervisory authorities, including the Hong Kong Office of the Privacy Commissioner for Personal Data (PCPD), the European Data Protection Board (EDPB), the UK Information Commissioner's Office (ICO), or the Turkish Personal Data Protection Authority (KVKK).
Annex I: Description of Processing Activities
Parties
- Data exporter (Controller): The Customer as identified in the applicable Order Form.
- Data importer (Processor): Mission Growth Limited, Unit 2A, 17/F, Glenealy Tower, No.1 Glenealy, Central, Hong Kong S.A.R. Contact: contact@missiongrowth.io.
Nature and Purpose of Processing. Vendor processes Personal Data to provide the Service to Customer, including: hosting and storage of Customer Data, AI inference operations to generate AI-Generated Outputs, analytics and reporting features, automated workflow execution, and platform technical operations (logging, backup, monitoring).
Duration of Processing. Processing continues for the duration of the Master Agreement plus the 30-day data export window and 90-day backup deletion cycle following termination.
Categories of Data Subjects. Customer's employees and Authorized Users; Customer's end customers, clients, and marketing contacts included in Customer Data; any other natural persons whose Personal Data Customer chooses to include in the Service.
Categories of Personal Data. Account and identity data (names, email addresses, job titles); usage and log data (session identifiers, interaction logs, audit trails); Customer-uploaded content (which may contain any categories of Personal Data at Customer's discretion); AI inputs and outputs; integration data from third-party platforms connected by Customer.
Special Categories of Personal Data. None intended. Customer must not submit special categories of Personal Data (GDPR Article 9) without prior written agreement with Vendor.
Processing Operations. Storage (database persistence), transmission (API communication between service components), AI inference (processing inputs through AI models), analytics (aggregation and report generation), workflow automation (executing Customer-configured automations), backup (automated system backups), and logging (structured application logs for security and debugging).
Retention. Personal Data is retained for the duration of the Master Agreement. Following termination: Customer Data is deleted or exported within 30 days at Customer's election; backup systems are purged on a 90-day cycle; log data is retained for up to 12 months for security monitoring purposes and then deleted.
Annex II: Technical and Organizational Measures
The technical and organizational measures (TOMs) implemented by Vendor are described in full in Section 14 of this DPA. This Annex II incorporates Section 14 by reference and serves as the formal Annex II for the purposes of the EU Standard Contractual Clauses incorporated in Section 9 of this DPA.
Key measures summary:
- Encryption at rest (AES-256 via Supabase) and in transit (TLS 1.3)
- Row-Level Security for multi-tenant data isolation at the database layer
- JWT authentication with bcrypt hashing; MFA for Vendor staff
- Infrastructure hosted on Hetzner (ISO 27001) and Supabase (SOC 2 Type II) with SOC 2 Type II certified Sub-processors for AI and CDN
- Structured logging with anomaly detection; no Personal Data in full-content logs
- Critical vulnerability patching within 72 hours
- Documented incident response procedure with 72-hour Personal Data Breach notification
- Contractual security obligations imposed on all Sub-processors
These measures will be reviewed and updated by Vendor at least annually and following any significant change in the risk profile of the processing.
Annex III: Approved Sub-processors
The current list of approved Sub-processors is maintained at missiongrowth.io/legal/subprocessors and is updated in accordance with Section 8.3 of this DPA (30 days' prior notice of new Sub-processors).
This Annex III incorporates the Sub-processor list by reference. Customers who have subscribed to Sub-processor change notifications will receive email notification at the address registered in their account when the list is updated.
For questions about specific Sub-processors or transfer mechanisms, contact contact@missiongrowth.io.
Legal notice
This document is a current-state version of our legal terms, prepared with research from leading B2B SaaS templates and Hong Kong / EU / Türkiye regulatory sources. It is undergoing review by Hong Kong-licensed counsel and Turkish counsel where applicable. Please contact contact@missiongrowth.io with any questions or to request the latest counsel-reviewed version.