Trust Center

Data Processing Agreement

A one-page summary of our DPA, structured around five core security anchors for fast InfoSec and procurement review.

Last updated: August 2026 · Effective: August 2026

This summary is provided for convenience only and does not modify the executed DPA. In the event of any conflict, the signed DPA controls. Enterprise customers may request a fully executed DPA at legal@marketmindai.cloud.

1. Roles & Processing Scope

Legal Roles

Customer acts as the Data Controller; MarketMind AI acts as the Data Processor.

Data Categories

Customer API payloads, system prompts, vector embeddings, tenant metadata, and domain-specific inputs.

Processing Purpose

Delivered strictly to execute real-time model inference, vector similarity search, and continuous background agent workflows.

2. AI Privacy & Zero-Training Commitments

Zero Model Training

Explicit contractual guarantee that customer inputs/outputs are never used to train or fine-tune public or multi-tenant models.

Zero Data Retention at API Layer

Upstream LLM providers (e.g., Google Vertex AI) operate under zero prompt logging/retention terms (Zero Data Retention, ZDR).

Tenant Isolation

All vector embeddings and persistent memory stores are logically segregated using tenant-isolated pgvector namespaces on Cloud SQL.

3. Technical & Organizational Measures (TOMs)

Encryption Standards

Data encrypted at rest via AES-256 and in transit via TLS 1.3 across all microservices and API gateways.

Access Control

Role-Based Access Control (RBAC) backed by Google Cloud Secret Manager and strict IAM policies.

Logging & Observability

Cloud Audit Logs track all administrative infrastructure changes and automated service account actions.

4. Incident Management & Compliance SLA

Breach Notification

Mandatory notification to Customer within 48 hours of a confirmed security incident or unauthorized data access.

Data Subject Requests (DSR)

Automated tooling and API endpoints to execute right-to-be-forgotten and data extraction requests within 30 days.

Data Deletion Upon Termination

Permanent purging of all customer schemas, backups, and vector indexes within 30 days of contract termination.

5. Authorized Sub-Processors

Sub-processorPurposeLocation
Google Cloud Platform (GCP)Hosting, Cloud Run, Cloud SQL (pgvector), Pub/Sub, Secret ManagerUnited States / Multi-Region
Google Vertex AIFoundational LLM Inference & EmbeddingsUnited States / Multi-Region
Google Cloud Identity / FirebaseEnd-user authentication, identity lifecycle, MFAUnited States / Global
WorkOS, Inc.Enterprise SSO (SAML/OIDC) & SCIM directory syncUnited States
Cloudflare, Inc.Edge WAF, DDoS mitigation, DNS routing, TLS terminationGlobal Distributed Network

DPA Clause

Subprocessors and AI Model Infrastructure

This copy-paste ready Subprocessor Clause explicitly addresses foundational LLM providers, Zero Data Retention (ZDR), and flow-down zero-training commitments required by enterprise InfoSec teams.

X.1Authorization of Subprocessors

Customer provides general authorization for MarketMind AI to engage the third-party processors listed in Schedule A (Authorized Subprocessors) — including Google Cloud Platform (GCP) for core infrastructure and Google Vertex AI for foundational model inference — to process Customer Personal Data strictly as necessary to deliver the Service.

X.2Foundational Model & AI Infrastructure Guarantees

MarketMind AI warrants and represents that all contracts executed with third-party foundational model providers, inference APIs, and embedding infrastructure incorporate strict data protection covenants requiring that:

No Model Training

Customer Personal Data — including prompts, completions, system instructions, database schemas, and vector embeddings — shall not be used, stored, or accessed to train, fine-tune, align, or reinforce any public, multi-tenant, or third-party AI/ML models.

Zero Data Retention (ZDR)

Inference requests routed to foundational model subprocessors operate under zero-day prompt logging and zero-retention parameters, ensuring payloads are discarded immediately upon completion of the API response.

Logical & Runtime Isolation

Egress to model subprocessors maintains tenant segregation, preventing cross-customer retrieval or shared embedding index commingling.

X.3Contractual Flow-Down Obligations

Pursuant to Applicable Data Protection Laws (including GDPR Art. 28 and CCPA/CPRA), MarketMind AI shall execute formal Data Processing Agreements with each subprocessor imposing data protection obligations no less restrictive than those set forth in this DPA. Such agreements shall mandate AES-256 encryption at rest, TLS 1.3 encryption in transit, and continuous adherence to recognized security standards (e.g., SOC 2 Type II, ISO/IEC 27001).

X.4Notification of Subprocessor Changes & Objection Rights

MarketMind AI shall provide Customer with at least thirty (30) days' prior written notice before adding, replacing, or modifying any subprocessor touching Customer Personal Data. Customer may object to such changes on reasonable data protection or compliance grounds within fourteen (14) days of notice. If MarketMind AI cannot accommodate the objection, Customer may terminate the impacted Service without penalty and receive a pro-rata refund of prepaid fees.

X.5Primary Liability

MarketMind AI remains fully liable to Customer for the performance of each subprocessor's data protection obligations to the same extent MarketMind AI would be liable if performing the processing directly.

Schedule A: Authorized Subprocessors

Sample Excerpt

SubprocessorProcessing ActivityLocationData Protection Terms
Google Cloud Platform (GCP)Application hosting, Cloud Run, Cloud SQL (pgvector), Pub/SubUnited States / Multi-RegionGCP Enterprise DPA, AES-256 Encryption, SOC 2 Type II certified
Google Vertex AIFoundational LLM inference & vector embeddingsUnited States / Multi-RegionEnterprise ZDR, Explicit No-Training Terms, EU/US SCCs

Ready to execute a DPA or need the full agreement? Contact us at legal@marketmindai.cloud