A one-page summary of our DPA, structured around five core security anchors for fast InfoSec and procurement review.
Last updated: August 2026 · Effective: August 2026
This summary is provided for convenience only and does not modify the executed DPA. In the event of any conflict, the signed DPA controls. Enterprise customers may request a fully executed DPA at legal@marketmindai.cloud.
Customer acts as the Data Controller; MarketMind AI acts as the Data Processor.
Customer API payloads, system prompts, vector embeddings, tenant metadata, and domain-specific inputs.
Delivered strictly to execute real-time model inference, vector similarity search, and continuous background agent workflows.
Explicit contractual guarantee that customer inputs/outputs are never used to train or fine-tune public or multi-tenant models.
Upstream LLM providers (e.g., Google Vertex AI) operate under zero prompt logging/retention terms (Zero Data Retention, ZDR).
All vector embeddings and persistent memory stores are logically segregated using tenant-isolated pgvector namespaces on Cloud SQL.
Data encrypted at rest via AES-256 and in transit via TLS 1.3 across all microservices and API gateways.
Role-Based Access Control (RBAC) backed by Google Cloud Secret Manager and strict IAM policies.
Cloud Audit Logs track all administrative infrastructure changes and automated service account actions.
Mandatory notification to Customer within 48 hours of a confirmed security incident or unauthorized data access.
Automated tooling and API endpoints to execute right-to-be-forgotten and data extraction requests within 30 days.
Permanent purging of all customer schemas, backups, and vector indexes within 30 days of contract termination.
| Sub-processor | Purpose | Location |
|---|---|---|
| Google Cloud Platform (GCP) | Hosting, Cloud Run, Cloud SQL (pgvector), Pub/Sub, Secret Manager | United States / Multi-Region |
| Google Vertex AI | Foundational LLM Inference & Embeddings | United States / Multi-Region |
| Google Cloud Identity / Firebase | End-user authentication, identity lifecycle, MFA | United States / Global |
| WorkOS, Inc. | Enterprise SSO (SAML/OIDC) & SCIM directory sync | United States |
| Cloudflare, Inc. | Edge WAF, DDoS mitigation, DNS routing, TLS termination | Global Distributed Network |
This copy-paste ready Subprocessor Clause explicitly addresses foundational LLM providers, Zero Data Retention (ZDR), and flow-down zero-training commitments required by enterprise InfoSec teams.
Customer provides general authorization for MarketMind AI to engage the third-party processors listed in Schedule A (Authorized Subprocessors) — including Google Cloud Platform (GCP) for core infrastructure and Google Vertex AI for foundational model inference — to process Customer Personal Data strictly as necessary to deliver the Service.
MarketMind AI warrants and represents that all contracts executed with third-party foundational model providers, inference APIs, and embedding infrastructure incorporate strict data protection covenants requiring that:
Customer Personal Data — including prompts, completions, system instructions, database schemas, and vector embeddings — shall not be used, stored, or accessed to train, fine-tune, align, or reinforce any public, multi-tenant, or third-party AI/ML models.
Inference requests routed to foundational model subprocessors operate under zero-day prompt logging and zero-retention parameters, ensuring payloads are discarded immediately upon completion of the API response.
Egress to model subprocessors maintains tenant segregation, preventing cross-customer retrieval or shared embedding index commingling.
Pursuant to Applicable Data Protection Laws (including GDPR Art. 28 and CCPA/CPRA), MarketMind AI shall execute formal Data Processing Agreements with each subprocessor imposing data protection obligations no less restrictive than those set forth in this DPA. Such agreements shall mandate AES-256 encryption at rest, TLS 1.3 encryption in transit, and continuous adherence to recognized security standards (e.g., SOC 2 Type II, ISO/IEC 27001).
MarketMind AI shall provide Customer with at least thirty (30) days' prior written notice before adding, replacing, or modifying any subprocessor touching Customer Personal Data. Customer may object to such changes on reasonable data protection or compliance grounds within fourteen (14) days of notice. If MarketMind AI cannot accommodate the objection, Customer may terminate the impacted Service without penalty and receive a pro-rata refund of prepaid fees.
MarketMind AI remains fully liable to Customer for the performance of each subprocessor's data protection obligations to the same extent MarketMind AI would be liable if performing the processing directly.
Sample Excerpt
| Subprocessor | Processing Activity | Location | Data Protection Terms |
|---|---|---|---|
| Google Cloud Platform (GCP) | Application hosting, Cloud Run, Cloud SQL (pgvector), Pub/Sub | United States / Multi-Region | GCP Enterprise DPA, AES-256 Encryption, SOC 2 Type II certified |
| Google Vertex AI | Foundational LLM inference & vector embeddings | United States / Multi-Region | Enterprise ZDR, Explicit No-Training Terms, EU/US SCCs |
Ready to execute a DPA or need the full agreement? Contact us at legal@marketmindai.cloud