Data Processing Agreement

Last updated: June 21, 2026

This DPA forms part of the Terms or another agreement between the customer and Dragan Atanasov, NIP PL6762491554, REGON 362195598, at Rakowicka 10b/4, 31-511 Kraków, Lesser Poland Voivodeship, Poland. It applies where Mosaicora processes personal data in Customer Content on the customer’s behalf.

1. Scope and roles

The customer is the controller or a processor acting for another controller. Mosaicora is the processor or subprocessor. Terms such as personal data, processing, controller, processor, and data subject have the meanings given in the GDPR. This DPA becomes binding when the customer accepts the Terms, purchases the Service, or signs an order that incorporates it.

2. Documented instructions

Mosaicora processes personal data only to provide, secure, maintain, and support the Service, follow the customer’s documented configuration and lawful requests, and meet applicable law. The agreement, this DPA, account settings, and lawful support requests are the customer’s documented instructions.

If we believe an instruction violates data protection law, we will inform the customer unless prohibited and may suspend the affected processing until resolved.

3. Customer responsibilities

The customer is responsible for the lawfulness, accuracy, and quality of Customer Content, required notices and consents, appropriate Service configuration, and lawful instructions. Special-category or highly sensitive data must not be submitted unless expressly agreed in writing and protected by suitable safeguards.

4. Confidentiality

Personnel authorized to process Customer personal data are bound by confidentiality and receive access only where needed for their role.

5. Security

Taking into account the state of the art, cost, context, and risk, Mosaicora maintains appropriate technical and organizational measures, including the measures in Annex II.

6. Subprocessors

The customer gives general authorization for the subprocessors on our Subprocessor List. We bind subprocessors to materially equivalent data-protection obligations and remain responsible for their performance to the extent required by law.

We provide notice of material additions or replacements. A customer may object on reasonable data-protection grounds within 14 days. The parties will seek a reasonable alternative. If none is available, the customer may stop or terminate the affected Service.

7. International transfers

Mosaicora will not make a restricted transfer without a lawful mechanism. Depending on the destination and provider, safeguards may include an adequacy decision, the EU-US Data Privacy Framework, the Standard Contractual Clauses completed in Annex III, the UK Addendum, or Swiss-law adaptations.

8. Assistance and data-subject requests

Taking into account the nature of processing and information available, Mosaicora will reasonably assist with data-subject requests, security obligations, impact assessments, and regulator consultations. Requests should be sent to hello@mosaicora.io. If we receive a request concerning Customer personal data, we direct it to the customer unless law requires us to respond.

9. Personal data breaches

We notify the customer without undue delay after becoming aware of a confirmed personal data breach affecting Customer personal data. As information becomes available, notice describes the nature, likely consequences, affected data and people, mitigation, and a contact point. Notice is not an admission of fault or liability.

10. Return and deletion

The customer may email hello@mosaicora.io for export assistance, account closure, or deletion. After a verified request or termination, Mosaicora deletes or anonymizes active Customer personal data within 30 days and removes residual copies through normal backup rotation, unless law requires retention. Retained data remains protected and is not used for other purposes.

11. Information and audits

We provide information reasonably necessary to demonstrate compliance. If insufficient, the customer may request an audit once annually or after a confirmed breach, with reasonable notice. Audits must protect other customers, confidentiality, and security, avoid unreasonable disruption, and be at the customer’s cost unless they reveal our material breach.

Annex I - Processing details

Subject matter and duration
Processing Customer Content for the subscription term and deletion period.
Nature and purpose
Retrieving webpages and metadata, receiving, hosting, transforming, rendering, caching, storing, delivering, securing, troubleshooting, and deleting Customer Content.
Data subjects
Customer users, personnel, website visitors, customers, prospects, content authors, and other people included in source pages or Customer Content.
Personal data
Names, professional details, usernames, profile images, contact details, public webpage content, metadata, images, URLs, IP addresses, and technical identifiers. Sensitive data is not intended for processing.

Annex II - Security measures

  • encrypted transport and provider-managed encryption at rest where applicable
  • role-based access, least privilege, credential controls, and restricted production access
  • logging, monitoring, abuse prevention, and security maintenance
  • backups, recovery procedures, and availability controls
  • data minimization, support verification, and deletion procedures
  • incident review and continuous improvement of safeguards.

Annex III - Transfer terms

For a restricted EEA transfer, the 2021 EU Standard Contractual Clauses are incorporated as follows: Module Two applies when the customer is controller and Mosaicora is processor. Module Three applies when both parties act as processors. Clause 7 applies. For Clause 9, Option 2 general authorization applies with the notice process in Section 6. The optional Clause 11 language does not apply. Polish law governs Clause 17 and the courts of Kraków, Poland apply under Clause 18. The competent authority is determined under Clause 13, including UODO where applicable. Annexes I and II of this DPA complete the SCC annexes.

Restricted UK transfers use the then-current UK International Data Transfer Addendum with the EU SCC selections above. Swiss transfers use those clauses with references to the GDPR interpreted to include the Swiss Federal Act on Data Protection, the Swiss authority recognized as competent where required, and Swiss law protecting Swiss data subjects.

If this DPA conflicts with the SCCs or mandatory data protection law, those higher protections control. Otherwise, the governing-law and liability provisions of the main agreement apply.