Data processing addendum
Moira Connect Data Processing Addendum
This Data Processing Addendum (DPA) forms part of the agreement between Moira and Customer where Moira processes Customer Personal Data on Customer's documented instructions. It is designed to address the processor terms commonly required by Article 28 GDPR; it should be reviewed with counsel before use for a particular customer or regulated workload.
1. Scope and precedence
This DPA applies only when Moira is a processor and Customer is a controller or processor acting for another controller. If Moira determines the purposes and means of a processing activity for its own account administration, billing, security, or legal compliance, Moira acts as controller for that activity and this DPA does not change that role.
If this DPA conflicts with the agreement on the processing of Customer Personal Data, this DPA controls. A signed data-processing addendum or Order Form with expressly different data-processing terms prevails to the extent of the conflict.
2. Processing details
The subject matter is the provision, security, support, operation, and recovery of Moira Connect connection workflows. Processing lasts for the agreement term plus the return, deletion, and legally required retention period.
| Detail | Description |
|---|---|
| Nature | Collection, access, transmission, normalisation, storage, retrieval, support, security monitoring, deletion, and other operations necessary to provide the service. |
| Purpose | To operate Customer-authorised connections, projects, APIs, events, webhooks, account health, support, and recovery workflows. |
| Data subjects | Customer's authorised users, connected-account holders, contacts, correspondents, and other individuals whose data Customer causes the service to process. |
| Data categories | Identity, contact, account, message, event, configuration, provider, technical, and audit data, as determined by Customer's use of the service. |
3. Documented instructions
Moira processes Customer Personal Data only on Customer's documented instructions, including the agreement, configured service controls, and authorised support instructions, unless applicable law requires otherwise. If law requires processing beyond those instructions, Moira will inform Customer before processing unless that law prohibits notice.
Moira will inform Customer if an instruction appears to infringe applicable data-protection law, without being required to provide legal advice or independently determine Customer's compliance obligations.
4. Confidentiality and authorised personnel
Moira limits access to Customer Personal Data to personnel and authorised service providers who need it to provide or secure the service and who are bound by confidentiality obligations or an appropriate statutory duty of confidentiality.
5. Security measures
Moira implements technical and organisational measures appropriate to the risk, taking account of the state of the art, implementation cost, nature, scope, context, and purposes of processing. Measures are operated and improved through the service's access-control, credential, encryption, auditing, operational-monitoring, backup, and incident-management processes.
Customer is responsible for the security of its own applications, users, provider accounts, endpoints, recipient systems, and choices made through the service, including scoped-key handling, role assignment, webhook destinations, and retention settings.
6. Subprocessors
Customer gives general written authorisation for Moira to engage the subprocessors listed on the Subprocessor page for the stated purposes. Moira will impose written data-protection obligations on each subprocessor that are materially no less protective than those applicable to Moira for the delegated processing.
Before adding or replacing a material subprocessor for Customer Personal Data, Moira will update the Subprocessor page and, where Customer has a contractual notification right, provide notice through the agreed channel. Customer may object on reasonable data-protection grounds within 30 days; the parties will work in good faith on a solution, and Customer may terminate the affected service if none is reasonably available.
7. International transfers
Moira will not transfer Customer Personal Data to a country outside the EEA, United Kingdom, or Switzerland unless a lawful transfer mechanism applies. Where required, Moira and the relevant recipient will use the applicable EU Standard Contractual Clauses, UK Addendum, adequacy regulation, or another valid mechanism, together with supplementary measures where appropriate.
8. Assistance with individual rights
Taking account of the nature of the processing, Moira will provide reasonable assistance through technical and organisational measures available in the service to help Customer respond to requests to exercise rights under applicable data-protection law. If Moira receives a request directly, it will refer the requester to Customer where appropriate and will not respond except as instructed or legally required.
9. Assistance with compliance and incidents
Taking account of the nature of processing and information available to Moira, Moira will provide reasonable assistance with Customer's data-protection impact assessments, prior consultations, and security obligations. Moira will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data and will provide information reasonably available to help Customer meet its notification obligations.
10. Return and deletion
At the end of the service, Customer may use available export and deletion controls during the applicable access period. Moira will delete or return Customer Personal Data in accordance with the agreement and documented retention controls, unless applicable law requires continued storage. The mandatory seven-day delay before irreversible workspace erasure remains a protective operational control, not an extension of a service term.
11. Demonstrating compliance and audits
Moira will make information reasonably necessary to demonstrate compliance with this DPA available to Customer, subject to confidentiality, security, and third-party restrictions. If documentation does not reasonably address a material compliance concern, Customer may request an audit no more than once in a 12-month period with at least 30 days' written notice, during normal business hours, and at Customer's expense.
An audit must be scoped to avoid disruption, protect other customers and confidential information, and use an independent auditor bound by confidentiality. Customer and Moira will agree the scope before the audit. Moira may provide an independent assessment or equivalent evidence where it reasonably satisfies the request.
12. Controller obligations
Customer warrants that it has provided the notices, obtained the permissions, and established the lawful basis required for Customer Personal Data and each instruction. Customer remains responsible for its relationship with data subjects, provider platforms, and downstream recipients, including the content, timing, and lawfulness of communications sent through a connected account.
13. Contact and execution
For a copy to execute with an Order Form, a regulated-workload review, or a subprocessor objection, contact [email protected]. This web version records the operating terms of the DPA but does not replace a mutually executed document where Customer's procurement process requires one.