Data Processing Agreement
Mindcapita · v1.0 · 2 September 2026 · Article 28 GDPR · Forms part of the Terms of Service
When you measure with Mindcapita, you remain the controller of your employees' data and we are your processor. This agreement sets out what we may do with that data, which sub-processors we use, how it is protected, and what happens to it when the contract ends.
1. Subject matter and duration
1.1 This agreement is concluded between the customer (the "Controller") and Dreaverr Digital Solutions LLP, 1103 - 11871 Horseshoe Way, Richmond, British Columbia, Canada V7A 5H5 (the "Processor"), which operates the Mindcapita platform. It supplements the Terms of Service and applies whenever the Processor processes personal data on behalf of the Controller.
1.2 The subject matter of the processing is the provision of the Mindcapita platform as described in the Terms of Service.
1.3 This agreement runs for as long as the main contract runs. Obligations that by their nature outlast the contract, in particular sections 6 and 12, survive its end.
2. Scope, nature and purpose
2.1 The Processor processes personal data exclusively to provide the platform: inviting participants, conducting AI interviews, evaluating conversations and questionnaires, producing aggregated results and making them available, and administering accounts and seats.
2.2 The processing takes place in an automated manner. Annex I describes it in detail.
2.3 The Processor does not use the data for its own purposes. Aggregated data from which no person can be identified is not personal data and may be used to operate, secure and improve the platform.
3. Types of data and categories of data subjects
The types of personal data and the categories of data subjects are set out in Annex I. Where the Controller enters further data of its own accord, the Controller is responsible for whether it may lawfully do so.
4. Rights and obligations of the controller
4.1 The Controller is responsible for the lawfulness of the processing, in particular for the legal basis on which its employees take part, for the information duties towards them, and for involving employee representation where required.
4.2 The Controller is entitled to issue instructions about the processing at any time. Instructions are given in text form to contact@mindcapita.com.
4.3 The Controller confirms that it will not use the platform for decisions about individual employees, and that it will not attempt to re-identify individual participants.
5. Processing on instructions only
5.1 The Processor processes personal data only on the documented instructions of the Controller, unless required to do otherwise by Union or Member State law. In that case the Processor informs the Controller of that legal requirement before processing, unless the law prohibits such information.
5.2 The configuration the Controller makes in the platform, and the use of the platform as intended, constitute instructions.
5.3 The Processor informs the Controller without undue delay if, in its opinion, an instruction infringes data protection law. The Processor may suspend the execution of such an instruction until the Controller confirms it.
5.4 The Processor does not transfer personal data to a third country except as set out in Annex III or on the Controller's instructions. The Processor itself is established in Canada; where the Controller is established in the EU or the UK, the processing by the Processor is itself a transfer to a third country and is covered by the transfer mechanism stated in Annex III.
6. Confidentiality
6.1 The Processor obliges every person authorised to process the data to confidentiality, unless they are already under a statutory duty of confidentiality. The obligation survives the end of their engagement.
6.2 Access to production data is limited to those persons who need it to provide the service, to maintain it or to remedy faults.
7. Security of processing
7.1 The Processor implements the technical and organisational measures required by Article 32 GDPR. The measures in place are described in Annex II.
7.2 The measures are subject to technical progress. The Processor may adapt them provided the level of protection is not reduced.
7.3 Beyond Article 32, the platform enforces a minimum group size before any result is shown, and never exposes individual conversation content to the Controller. These are product properties, not merely policies.
8. Sub-processors
8.1 The Controller grants general authorisation for the engagement of sub-processors. Those currently engaged are listed in Annex III.
8.2 The Processor informs the Controller in text form at least four weeks before adding or replacing a sub-processor. The Controller may object on reasonable data protection grounds within that period. If the parties cannot resolve the objection, the Controller may terminate the main contract with effect from the date the change takes effect.
8.3 The Processor imposes on each sub-processor obligations equivalent to those in this agreement and remains liable for their performance.
9. Assistance with data subject rights
9.1 Taking into account the nature of the processing, the Processor assists the Controller with appropriate technical and organisational measures in responding to requests from data subjects under Articles 15 to 22 GDPR.
9.2 Where a data subject approaches the Processor directly, the Processor forwards the request to the Controller without undue delay and does not answer it itself.
9.3 Because results are aggregated and individual responses are not accessible to the Controller, the Processor supports the identification of the relevant records where a request concerns conversation data.
10. Assistance with Articles 32 to 36
The Processor assists the Controller in complying with its obligations under Articles 32 to 36 GDPR, in particular with the security of processing, breach notification and data protection impact assessments, taking into account the nature of the processing and the information available to the Processor.
11. Personal data breaches
11.1 The Processor notifies the Controller without undue delay, and at the latest within 24 hours, after becoming aware of a personal data breach concerning data processed on the Controller's behalf.
11.2 The notification describes the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences and the measures taken or proposed.
11.3 The Processor takes appropriate remedial measures without undue delay and documents the incident.
12. Deletion and return
12.1 After the end of the main contract, the Processor deletes the personal data processed on the Controller's behalf, or returns it, at the Controller's choice.
12.2 The Controller can export its results through the platform for 30 days after the contract ends. Deletion follows after that period.
12.3 Data whose retention is required by Union or Member State law is retained for the period prescribed and is blocked from further processing.
12.4 Backups are deleted within the ordinary backup cycle of at most 30 days.
13. Evidence and audits
13.1 The Processor makes available to the Controller the information necessary to demonstrate compliance with Article 28 GDPR.
13.2 The Controller may audit compliance, itself or through an auditor bound to confidentiality and not a competitor of the Processor. Audits take place during business hours, with reasonable notice of at least four weeks, and without disproportionate disruption of operations.
13.3 The Processor may satisfy the obligation by presenting current certifications or audit reports where these cover the relevant processing.
14. Liability and final provisions
14.1 Liability is governed by Article 82 GDPR and by the liability provisions of the Terms of Service.
14.2 Should individual provisions be invalid, the validity of the remainder is unaffected.
14.3 In case of conflict between this agreement and the Terms of Service, this agreement prevails in matters of data protection.
Annex I: Processing details
Categories of data subjects:the Controller's employees invited to take part; the Controller's administrative users of the platform.
Types of personal data, participants:email address; team or department; personal invitation token; consent timestamps, including a separate consent for the optional camera channel; participation status and timestamps; conversation transcript; questionnaire responses; the values derived from these; a short content summary of previous conversations; short anonymous phrases naming what would make the person's work easier, reported only in aggregate; where the camera channel is enabled, one coarse aggregated value per conversation.
Types of personal data, administrative users: name, email address, password hash, role, activity timestamps.
Types of personal data, employee directory: first name, last name, email address and the attributes the Controller maintains, such as department.
Nature and purpose: automated processing to conduct interviews, evaluate them and produce aggregated results, as described in section 2.
Special categories of data: the platform is not designed to process special categories under Article 9 GDPR. Participants speak freely, so a participant may mention such information of their own accord. The evaluation does not target it, and the Controller never sees conversation content.
Duration: for the duration of the main contract, subject to section 12.
Annex II: Technical and organisational measures
Access control: access to the platform requires an account with a verified email address; passwords are stored only as salted hashes (bcrypt); roles limit what each user may see and do; platform administration is restricted to a defined list of accounts.
Separation: data is separated by organisation; every query is scoped to the organisation of the requesting account.
Confidentiality of content: conversation transcripts and individual responses are inaccessible to every customer role by design; results below the minimum group size are suppressed by the system.
Transmission: all traffic is encrypted in transit (TLS). Interview audio is transmitted to the model provider only for the duration of the conversation.
Device-side processing:the optional camera analysis runs in the participant's browser; no image or video leaves the device.
Input control: security-relevant actions are logged with a timestamp; invitation tokens are single-purpose and expire.
Availability: the database is backed up daily, backups are kept for 30 days, and restores are tested at least once a year.
Encryption at rest: the database and its backups are encrypted at rest by the infrastructure provider.
Review: these measures are reviewed at least once a year, and whenever the processing changes materially.
Annex III: Approved sub-processors
Cloud infrastructure provider - hosting of the application and the database. The provider currently engaged, its processing location and the transfer basis are stated in the sub-processor list we keep current and supply on request to contact@mindcapita.com. Changes are notified under section 8.2.
OpenAI- conducting the AI interview and evaluating responses. Conversation content is transmitted. Location: United States. Transfer basis: the EU standard contractual clauses agreed in OpenAI's data processing addendum. Content sent through the API is not used to train their models.
Resend- delivery of transactional email. Recipient address and message content are transmitted. Location: United States. Transfer basis: the EU standard contractual clauses agreed in the provider's data processing addendum.
Paddle - payment processing as merchant of record for self-service subscriptions. Note: for the payment transaction itself Paddle acts as an independent controller, not as our sub-processor.
Version 1.0, 2 September 2026. Dreaverr Digital Solutions LLP, represented by Robinson Guerra. Contact: contact@mindcapita.com.