Data Processing Agreement (DPA)

v1.0 · Last updated: 30 June 2026

This Data Processing Agreement (under Art. 28 GDPR) governs the processing of personal data by MonMyIP (the "Processor") on behalf of the Customer (the "Controller") in connection with the Service.

1. Roles

The Customer is the controller of the data processed within scans/reports; MonMyIP acts as processor on the Customer's documented instructions.

2. Subject matter and duration

Processing covers the data necessary to provide the Service and lasts for the term of the agreement plus any legally required retention period.

3. Scope and purpose

Data is processed solely to provide the Service (security analysis, reconnaissance, reporting) per the Controller's instructions.

4. Sub-processors

The Customer authorizes the use of sub-processors (infrastructure providers, country-specific payment processors, AI model providers in a redacted-data mode). A list is available on request; we notify of material changes with a right to object.

5. Security measures (Art. 32)

We apply encryption in transit and at rest, access control, environment separation, and an immutable hash-chained audit trail.

6. International transfers

Transfers outside the EEA rely on Standard Contractual Clauses (SCCs) or another valid mechanism; the platform flags transfers that require assessment.

7. Data-subject rights

We assist the Controller in handling data-subject requests (access, rectification, erasure) within a reasonable time.

8. Personal-data breaches

We notify the Controller without undue delay of any personal-data breach.

9. Deletion/return of data

On termination of the Service, data is deleted or returned to the Controller, except where retention is legally required.

10. Audit

On reasonable request we make available the information necessary to demonstrate compliance with this Agreement.

This document is a template and is subject to final legal review.