This Data Processing Agreement (under Art. 28 GDPR) governs the processing of personal data by MonMyIP (the "Processor") on behalf of the Customer (the "Controller") in connection with the Service.
1. Roles
The Customer is the controller of the data processed within scans/reports; MonMyIP acts as processor on the Customer's documented instructions.
2. Subject matter and duration
Processing covers the data necessary to provide the Service and lasts for the term of the agreement plus any legally required retention period.
3. Scope and purpose
Data is processed solely to provide the Service (security analysis, reconnaissance, reporting) per the Controller's instructions.
4. Sub-processors
The Customer authorizes the use of sub-processors (infrastructure providers, country-specific payment processors, AI model providers in a redacted-data mode). A list is available on request; we notify of material changes with a right to object.
5. Security measures (Art. 32)
We apply encryption in transit and at rest, access control, environment separation, and an immutable hash-chained audit trail.
6. International transfers
Transfers outside the EEA rely on Standard Contractual Clauses (SCCs) or another valid mechanism; the platform flags transfers that require assessment.
7. Data-subject rights
We assist the Controller in handling data-subject requests (access, rectification, erasure) within a reasonable time.
8. Personal-data breaches
We notify the Controller without undue delay of any personal-data breach.
9. Deletion/return of data
On termination of the Service, data is deleted or returned to the Controller, except where retention is legally required.
10. Audit
On reasonable request we make available the information necessary to demonstrate compliance with this Agreement.
This document is a template and is subject to final legal review.