---
title: "Data Processing Agreement (DPA) | Minds"
canonical_url: "https://getminds.ai/legal/dpa"
last_updated: 2026-08-25
meta:
  description: "Last Updated: August 25, 2026"
  "og:description": "Last Updated: August 25, 2026"
  "og:title": "Data Processing Agreement (DPA) | Minds"
  "twitter:description": "Last Updated: August 25, 2026"
  "twitter:title": "Data Processing Agreement (DPA) | Minds"
---

Minds

August 25, 2026·Minds Team # **Data Processing Agreement (DPA)** Last Updated: August 25, 2026**Last Updated: August 25, 2026** This Data Processing Agreement ("DPA") pursuant to Art. 28 GDPR forms part of the Agreement between Art of X UG (haftungsbeschränkt) ("Processor", "we", "us") and the Customer ("Controller", "you") for the use of our services (the "Main Agreement"). Where the Customer’s contracting entity is Minds AI Labs, Inc. (see Section 1 of the Terms of Service), Minds AI Labs, Inc. is the Processor under this DPA and Art of X UG (haftungsbeschränkt) acts as its Sub-processor for the development, hosting, operation, and support of the platform, on terms back-to-back with this DPA. ## 1. Definitions - **Personal Data**: Any information relating to an identified or identifiable natural person (Art. 4(1) GDPR). - **Processing**: Any operation performed on Personal Data, including collection, storage, use, and deletion (Art. 4(2) GDPR). - **Sub-processor**: Any third party engaged by the Processor to process Personal Data. - **GDPR**: Regulation (EU) 2016/679 (General Data Protection Regulation). - **Data Breach**: A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data (Art. 4(12) GDPR). ## 2. Scope and Duration of Processing 2.1 This DPA applies to all Processing of Personal Data by the Processor on behalf of the Controller in connection with the services. 2.2 The Processor shall process Personal Data only for the purposes of providing the services as described in the Main Agreement and in accordance with the Controller's documented instructions. 2.3 The duration of the Processing corresponds to the term of the Main Agreement, unless further obligations arise from the provisions of this DPA. ## 3. Data Processing Details | Category | Description |
| --- | --- | | **Subject Matter** | Provision of the AI-powered platform "Minds", including AI assistants, synthetic panels, Audience-grounded simulations, API/MCP access, browser-extension and widget workflows, integrations, voice/messaging features, and related services | | **Duration** | For the term of the Main Agreement | | **Nature and Purpose** | Hosting, authentication, storage, retrieval, analysis, simulation, and generation of outputs from Controller-provided data; operation of optional integrations such as Google Calendar, public API/MCP access, source extraction, messaging/voice, and billing. Controller data is not used to train, fine-tune, or improve general-purpose, foundation, generalized, shared, or third-party models or generalized datasets. If the Controller expressly instructs Minds to create or adapt a private Controller-specific model or voice clone, the selected data is processed only for that private feature and authorized workspace, not for another customer or any generalized, shared, or third-party model. AI sub-processors may process Controller data only to provide the requested service and must be subject to applicable no-generalized-training, confidentiality, retention, and deletion controls. | | **Types of Personal Data** | Contact data (name, email), access credentials, usage data, content data provided by the Controller (text, images, audio, files, URLs), prompts and outputs, embeddings, API keys, OAuth tokens, calendar event/attendee metadata, phone/message/call metadata and audio where enabled, technical data (IP address, browser, device), payment data (via Stripe), audit and security logs | | **Categories of Data Subjects** | Controller's employees and agents, end users invited by the Controller, individuals whose data is entered into the platform by the Controller, and individuals referenced in submitted content, calendar events, messages, or public sources | ## 4. Instruction Rights 4.1 The Processor shall process Personal Data only on the basis of documented instructions from the Controller, including the instructions set out in this DPA and the Main Agreement, unless required to do so by Union or Member State law to which the Processor is subject. In such a case, the Processor shall inform the Controller of that legal requirement before Processing, unless that law prohibits such information. 4.2 Instructions may be given in writing or in text form (including email). Oral instructions shall be confirmed in text form without undue delay. 4.3 The Processor shall immediately inform the Controller if, in the Processor's opinion, an instruction infringes data protection law (Art. 28(3) sentence 3 GDPR). The Processor shall be entitled to suspend the execution of the relevant instruction until it is confirmed or amended by the Controller. ## 5. Processor Obligations The Processor shall: 5.1 Process Personal Data only within the scope of the Controller's instructions and not for its own purposes. 5.2 Ensure that persons authorized to process Personal Data have committed to confidentiality or are under an appropriate statutory obligation of confidentiality (Art. 28(3)(b) GDPR). 5.3 Implement and maintain appropriate technical and organizational measures (TOMs) pursuant to Art. 32 GDPR throughout the duration of this DPA. The current TOMs are described in **Appendix 1 – Technical and Organizational Measures (TOM)** of this DPA and available at https://getminds.ai/legal/tom. 5.4 Immediately inform the Controller if the Processor becomes aware of any violations of the GDPR or other data protection regulations in connection with the Processing. 5.5 Designate a Data Protection Officer where required by law. The current Data Protection Officer is: Prof. Dr. Norman Uhlmann, h3ko Innovations GmbH, Pappelallee 64, 16359 Biesenthal, Germany. Email: [privacy@getminds.ai](https://getminds.ai/mailto:privacy@getminds.ai) 5.6 Not use, and not permit any Sub-processor to use, Personal Data processed on the Controller's behalf to train, fine-tune, or improve a general-purpose, foundation, generalized, shared, or third-party model or generalized dataset. A private Controller-specific model may be created or adapted only on the Controller's documented instruction and only for the Controller's authorized use. ## 6. Data Subject Rights 6.1 The Processor shall assist the Controller by appropriate technical and organizational measures, insofar as possible, in fulfilling the Controller's obligations to respond to requests for exercising the data subjects' rights laid down in Chapter III of the GDPR (access, rectification, erasure, restriction of processing, data portability, objection). 6.2 If a data subject contacts the Processor directly with a request, the Processor shall forward the request to the Controller without undue delay. ## 7. Assistance with Data Protection Obligations 7.1 The Processor shall assist the Controller, taking into account the nature of the Processing and the information available to the Processor, in ensuring compliance with the obligations pursuant to Articles 32 to 36 GDPR, in particular: - ensuring the security of Processing (Art. 32 GDPR); - notifying Personal Data breaches to the supervisory authority (Art. 33 GDPR) and to data subjects (Art. 34 GDPR); - carrying out Data Protection Impact Assessments (Art. 35 GDPR); - prior consultation with the supervisory authority (Art. 36 GDPR). 7.2 The Processor shall assist the Controller with requests and investigations by data protection supervisory authorities relating to the commissioned Processing. ## 8. Sub-processors 8.1 The Controller hereby grants the Processor general written authorization to engage Sub-processors pursuant to Art. 28(2) GDPR, subject to the requirements of this section. 8.2 The current Sub-processors at the time of conclusion of this DPA are listed at https://getminds.ai/legal/subprocessors. 8.3 The Processor shall notify the Controller of any intended addition or replacement of Sub-processors at least **14 days** before the planned change, giving the Controller the opportunity to object. 8.4 If the Controller raises objections within the notice period, the parties shall endeavor to reach an amicable solution. If this is not possible, the Controller shall have the right to terminate the Main Agreement with immediate effect. 8.5 The Processor shall contractually ensure that Sub-processors are bound by data protection obligations no less protective than those set out in this DPA (Art. 28(4) GDPR). The Processor shall be liable for the acts and omissions of its Sub-processors as for its own acts and omissions. ## 9. International Transfers 9.1 Processing of Personal Data in a third country or by an international organization shall only take place where the specific conditions of Articles 44 et seq. GDPR are met. 9.2 For Sub-processors located in the United States, transfers are carried out on the basis of: - The EU-US Data Privacy Framework (DPF), where the Sub-processor is certified - Standard Contractual Clauses (SCCs) pursuant to Commission Implementing Decision (EU) 2021/914 9.3 For Sub-processors in the United Kingdom, the European Commission's adequacy decision (Decision 2021/1772) applies. 9.4 The Processor monitors the status of applicable adequacy decisions and transfer mechanisms and shall inform the Controller if changes require an adjustment to the transfer basis. 9.5 If the Processor or any of its Sub-processors receives a governmental order for the disclosure of Personal Data (including orders under the US CLOUD Act, FISA, or comparable legislation), the Processor shall inform the Controller without undue delay, to the extent legally permitted. The Processor shall review the legality of the order and pursue reasonable legal remedies before disclosing any Personal Data. ## 10. Personal Data Breach Notification 10.1 The Processor shall notify the Controller without undue delay, and in any event within **24 hours**, upon becoming aware of a Personal Data breach. 10.2 The notification shall include at a minimum: - a description of the nature of the breach, including where possible the categories and approximate number of data subjects and data records concerned; - the name and contact details of the Data Protection Officer or other point of contact; - a description of the likely consequences of the breach; - a description of the measures taken or proposed to address the breach and to mitigate its effects. 10.3 The Processor shall assist the Controller in fulfilling the notification obligations pursuant to Articles 33 and 34 GDPR. 10.4 Where a Material AI Incident under the Main Agreement also concerns Personal Data, the Processor shall provide reasonable assistance with investigation, containment, remediation, and legally required notices. The Personal Data breach duties and deadlines in this Section remain controlling. ## 11. Audit Rights 11.1 The Processor shall make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Art. 28 GDPR. 11.2 Audits shall ordinarily begin with remote review of available policies, questionnaires, summaries, logs, or independent reports. The Controller may conduct one audit in any rolling 12-month period on at least 14 days' written notice during normal business hours, without unreasonable disruption. 11.3 An additional audit, shorter notice, or proportionate remote or on-site inspection is permitted where reasonably necessary following a Personal Data breach affecting the Controller, a material substantiated compliance concern, or a binding request from a supervisory authority. On-site access is permitted only where documentary evidence is insufficient for the relevant purpose. 11.4 Appointed third-party auditors must be independent, appropriately qualified, and bound by confidentiality obligations. An audit must not expose another customer's data, privileged material, trade secrets beyond what is necessary, or source code unless specifically required by law or a supervisory authority. The parties shall agree reasonable scope, timing, and security procedures in advance. 11.5 The Controller bears its audit costs. The Processor bears its reasonable internal costs for one ordinary annual audit, but may charge reasonable costs for additional audits unless they identify a material breach by the Processor or are required because of such a breach. ## 12. Deletion and Return of Personal Data 12.1 Upon termination of the Main Agreement, the Processor shall delete Personal Data from active systems within **30 days**, unless the Controller requests its return in a common, machine-readable format. Residual copies in protected backups shall be isolated from ordinary use and deleted or overwritten through the backup cycle within a further period of up to **30 days**. 12.2 Deletion shall be carried out in accordance with the current state of the art and shall be confirmed to the Controller in writing upon request. 12.3 Where retention is required under Union or Member State law, the Processor shall inform the Controller of the retention obligation and the data concerned. ## 13. Liability 13.1 The parties' liability shall be governed by Art. 82 GDPR. 13.2 The Processor shall be liable to the Controller for damages attributable to Processing that does not comply with the GDPR or the Controller's instructions. 13.3 The Processor shall be liable for the acts and omissions of its Sub-processors as for its own acts and omissions. 13.4 As between the parties, the limitations and caps in Section 13 of the Main Agreement apply, including any higher cap stated there for contractual data-protection, confidentiality, or information-security obligations. No contractual limitation affects a data subject's rights under Article 82 GDPR or any liability that cannot lawfully be limited. ## 14. Amendments to this DPA 14.1 The Processor may amend this DPA with at least 30 days' notice before the amendment takes effect, where such amendment is necessary due to changes in law, regulatory orders, technical developments, or changes to the processing activities. 14.2 The Controller shall be notified of amendments by email to the address associated with their account. The amended version shall be published at https://getminds.ai/legal/dpa. 14.3 If the Controller does not object to the amendments within 30 days of receipt of the notification, the amendments shall be deemed accepted. The Processor shall draw attention to this legal consequence in the amendment notification. 14.4 If the Controller objects, the parties shall endeavor to reach an amicable solution. If this is not possible, the Controller shall have the right to terminate the Main Agreement with immediate effect. ## 15. Final Provisions 15.1 This DPA shall be governed by the laws of the Federal Republic of Germany. 15.2 The exclusive place of jurisdiction for all disputes arising from or in connection with this DPA shall be Berlin, to the extent legally permissible. 15.3 Amendments and supplements to this DPA must be made in text form, unless otherwise provided in Section 14. 15.4 Should any provision of this DPA be or become invalid, the validity of the remaining provisions shall not be affected. 15.5 In the event of conflicts between this DPA and the Main Agreement, this DPA shall prevail with respect to the protection of Personal Data. ---**Art of X UG (haftungsbeschränkt)** Köpenicker Straße 145, 10997 Berlin, Germany Managing Directors: Friedrich von Borries and Alexander Doudkin For questions regarding this DPA, contact: [privacy@getminds.ai](https://getminds.ai/mailto:privacy@getminds.ai) --- ## 16. United States State Privacy Laws 16.1 This Section applies where the Customer's contracting entity is Minds AI Labs, Inc. and the processing of personal information is subject to the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA"), or to the Virginia, Colorado, Connecticut, Texas, Oregon, Montana or an equivalent state privacy statute (each a "US State Privacy Law"). 16.2 For the CCPA the Customer is the business and Minds is a service provider. For every other US State Privacy Law the Customer is the controller and Minds is a processor. 16.3 Minds does not sell and does not share personal information, as those terms are defined in the CCPA, and does not disclose it for cross-context behavioural or targeted advertising. Minds receives no valuable consideration for personal information. 16.4 Minds does not retain, use or disclose personal information for any purpose other than the business purposes identified in Section 16.4a, and not outside the direct business relationship with the Customer, except where a US State Privacy Law expressly permits. 16.4a The business purposes for which the Customer discloses personal information to Minds are, specifically: (a) hosting the Customer's tenant and storing personal information the Customer or its authorized users submit to the platform; (b) authenticating and managing the Customer's authorized users and administering their access rights and roles; (c) executing the synthetic audience research, panel simulation, segmentation and analysis operations the Customer initiates in the platform, including transmitting content the Customer submits to the model and inference providers on the sub-processor list solely to return a result to the Customer; (d) providing technical support and incident response in response to a request or an alert relating to the Customer's tenant, including access by named support personnel to the Customer's tenant to diagnose and correct a fault; (e) maintaining the security and integrity of the platform and the Customer's tenant, including monitoring for, investigating and remediating unauthorized access, abuse and fraud; (f) creating and maintaining backups of the Customer's tenant and restoring it after a failure; (g) detecting and repairing errors that impair intended functionality, and testing and verifying that fixes work; (h) calculating usage against the Customer's plan allowances for the purpose of billing the Customer; and (i) retaining personal information as required by law and deleting or returning it at the end of the subscription term. This Section is intended to satisfy 11 CCR § 7051(a)(1), which requires business purposes to be identified specifically rather than in generic terms. 16.5 Minds does not combine personal information with personal information it receives from or on behalf of another person, or collects from its own interaction with a consumer, except where the CCPA expressly permits. 16.6 Minds does not use personal information to train, fine-tune or improve any general-purpose, foundation, generalized, shared or third-party model or generalized dataset, and does not permit a sub-processor to do so. 16.7 **Minds certifies that it understands the restrictions in this Section and will comply with them.** 16.8 Minds imposes on each sub-processor, by written contract, obligations at least as protective as those in this Section, and remains liable for their performance. Where Minds AI Labs, Inc. is the contracting entity, Art of X UG (haftungsbeschränkt) acts as its sub-processor. 16.9 Minds assists the Customer in responding to verifiable consumer requests to know, access, correct, delete, opt out or limit the use of sensitive personal information, and forwards to the Customer any request a consumer makes directly to Minds. Minds does not use or disclose sensitive personal information beyond the purposes permitted by § 1798.121 CCPA. 16.10 Minds notifies the Customer promptly if it determines it can no longer meet its obligations under a US State Privacy Law, and the Customer may then take reasonable and appropriate steps to stop and remediate unauthorised use. 16.11 Where the same processing is subject both to this Section and to another provision of this DPA, both apply and the provision giving the greater protection to the individual prevails. ## Appendix 1: Technical and Organizational Measures (TOM)**Last Updated: August 25, 2026** Art of X UG (haftungsbeschränkt) ("Minds") implements the following technical and organizational measures pursuant to Art. 32 GDPR to ensure a level of security appropriate to the risk involved in the processing of personal data. --- ## 1. Access Control ### Physical Access Control Minds infrastructure is hosted exclusively with certified cloud providers: - **DigitalOcean** – Frankfurt, Germany data center (EU). Certifications: SOC 2 Type II, ISO 27001, ISO 27017, ISO 27018. - **Supabase** – Stockholm, Sweden data center (EU), hosted on AWS. Certifications: SOC 2 Type II. Physical security (biometric access controls, 24/7 surveillance, access logging) is fully managed by the cloud providers. The certifications listed above are provider certifications and do not represent that Minds itself currently holds a SOC 2 report or ISO certification. ### Logical Access Control - Role-based access control (RBAC) for all internal systems and administration interfaces. - Multi-factor authentication (MFA) required for all employee access to production systems. - Individual user accounts – no shared credentials. - Regular review and revocation of access rights following the principle of least privilege. - API keys and credentials are managed in encrypted secrets managers. - OAuth tokens, integration credentials, and API keys are scoped, encrypted at rest, and revocable. --- ## 2. Encryption ### Encryption in Transit - All data transmissions are secured via TLS 1.2 or higher. - HSTS (HTTP Strict Transport Security) is enabled for all public endpoints. - Internal service-to-service communication is also encrypted. ### Encryption at Rest - Databases (Supabase/PostgreSQL) use AES-256 encryption for data at rest. - File storage (DigitalOcean Spaces / Supabase Storage) uses server-side AES-256 encryption. - Backups are stored in encrypted form. --- ## 3. Data Separation (Tenant Isolation) - Strict logical separation of customer data at the database level through tenant isolation (Row-Level Security in PostgreSQL). - Each customer can only access their own data – enforced at both the database and API level. - Automated tests ensure no cross-tenant data leakage occurs. --- ## 4. Availability and Resilience ### Hosting Architecture - Application runs on DigitalOcean App Platform with automatic scaling and health checks. - Database on Supabase with high-availability configuration. ### Backup and Recovery - Protected database backups are created regularly and retained for up to 30 days according to the applicable backup cycle. - Point-in-Time Recovery (PITR) for the PostgreSQL database. - Regular testing of recovery procedures. - Recovery objectives are operational targets unless an Order Form expressly makes a specific target contractually binding. --- ## 5. Incident Response - Documented incident response process for security incidents. - Notification of the Controller (customer) within **24 hours** of becoming aware of a personal data breach, in accordance with the Data Processing Agreement (DPA). - Logging and tracking of all security-relevant incidents. - Regular review and update of the incident response plan. --- ## 6. Confidentiality and Employee Obligations - All employees and contractors are bound by confidentiality agreements (NDAs). - Regular data protection training for all employees. - Obligation to maintain data secrecy in accordance with GDPR. - Access to personal data is granted only on a need-to-know basis. --- ## 7. Subprocessor Management - Careful selection of sub-processors based on data protection and security criteria. - Contractual obligation of all sub-processors to GDPR-compliant data processing. - Regular review of sub-processors. - Current list of sub-processors is available at [Subprocessors](https://getminds.ai/legal/subprocessors). - Advance notice to customers of any changes as per the DPA. --- ## 8. Logging and Monitoring - Centralized logging of system events and access. - Audit logs cover API/MCP access, OAuth and integration changes, calendar sync/webhook events, and security-relevant administrative actions. - **Langfuse** for monitoring and tracing AI model interactions (hosted in the EU). - **PostHog** for product analytics and optional session replay - persistent analytics/session replay only with analytics consent; limited cookieless diagnostics where lawful. - Monitoring of critical system metrics with automated alerts. - Regular review of logs for anomalies. --- ## 9. Data Minimization and Pseudonymization ### Data Minimization - Collection and processing of only those personal data that are necessary for the respective processing purpose. - Regular review of processed data categories for necessity. - Automatic deletion of data no longer needed in accordance with defined retention periods. ### Pseudonymization - Where technically feasible and appropriate, personal data is processed in pseudonymized form. - Internal processing primarily uses UUIDs rather than real names. - Analytical evaluations are performed on an aggregated or pseudonymized basis. --- ## 10. Regular Review and Assessment - Regular security assessments of infrastructure and applications. - Dependencies are regularly checked for known vulnerabilities (dependency scanning). - Review and update of these TOMs at least annually or upon significant changes to processing activities. - Continuous improvement of security measures based on current threat landscape. --- ## 11. Additional Measures ### Input Control - Logging of changes to personal data (audit trail). - Traceability of who entered, modified, or deleted which data and when. ### Transfer Control - Data transfers are exclusively encrypted. - No transfer of personal data to third countries without an adequate level of protection (adequacy decision or Standard Contractual Clauses). ### Processing Control - Processing of personal data exclusively in accordance with the Controller's instructions. - Contractual regulation of commissioned processing in the DPA. ---_These technical and organizational measures are reviewed regularly and updated as necessary to ensure a level of protection consistent with the current state of the art._## **Continue your procurement review** Use the buyer-facing checklist and evidence pages alongside these legal terms. [Minds](https://getminds.ai/)© 2026 Minds. Your target audience. AI-driven and grounded in transparent evidence. Build within minutes. [Minds on X (Twitter)](https://x.com/mindsai_co) [Minds on LinkedIn](https://www.linkedin.com/company/mindsaicompany/) [Minds on Instagram](https://www.instagram.com/getminds.ai/)Minds is part of [![ESOMAR Corporate 2026](https://getminds.ai/images/newsroom/logos/esomar-corporate-2026-v2.png)ESOMAR](https://esomar.org/) [![bayern design](https://getminds.ai/images/customer-logos/bayern-design.svg)bayern design](https://bayern-design.de/) [![CSSDA Best UX Design Award](https://getminds.ai/images/newsroom/logos/cssda-best-ux-award.png)CSSDA Best UX Design Award](https://www.cssdesignawards.com/) [![CSSDA Best Innovation Award](https://getminds.ai/images/newsroom/logos/cssda-best-innovation-award.png)CSSDA Best Innovation Award](https://www.cssdesignawards.com/) [![CSSDA Best UI Design Award](https://getminds.ai/images/newsroom/logos/cssda-best-ui-award.png)CSSDA Best UI Design Award](https://www.cssdesignawards.com/)