Parties and scope
You are the controller of your brand data, and we are your processor.
This Data Processing Agreement (DPA) is between you, the customer, as controller, and mentionedin.ai (KvK 70562431, VAT NL002399377B14, The Hague, the Netherlands) as processor. It forms part of the Terms of Service at /terms/ and applies whenever we process personal data on your behalf. If this DPA and the Terms conflict on data protection, this DPA wins.
You accept this DPA by accepting the Terms. No separate signature is needed. Email [email protected] for a countersigned copy.
What we commit to
The processor duties from Article 28(3) of the GDPR, in plain terms.
- Instructions: we process personal data only on your documented instructions, which are the Terms, this DPA and how you configure your account. If an instruction appears to break data protection law, we tell you.
- Confidentiality: everyone who can access the personal data is bound to confidentiality.
- Security: we apply the measures in Annex II and keep them up to date.
- Records: we keep a record of the processing we carry out for you.
Sub-processors
A general authorisation, with 14 days notice and a right to object.
You authorise us to use the sub-processors listed in Annex III. We bind each of them to data protection obligations at least as strict as these and stay responsible to you for their work. Before a new sub-processor processes customer data, we email you at least 14 days in advance. You may object by email to [email protected]. If we cannot resolve the objection, you may terminate the affected service without penalty.
Assistance to you
Help with data subject requests, DPIAs and audits.
- Data subject requests: we help you answer requests for access, rectification, erasure and the other GDPR rights, and forward any request we receive directly.
- DPIAs: we give you the information you reasonably need for a data protection impact assessment.
- Audits: we make available, on request, the information needed to show we meet these obligations. Email [email protected].
Personal data breaches
We tell you without undue delay.
If we become aware of a personal data breach affecting your data, we notify you without undue delay, with what we know about its nature, the data and people affected, the likely consequences and the measures taken, and we help you meet your own notification duties.
At the end of the service
Your data is deleted, or returned first if you ask.
When you delete your account, we delete the personal data we process for you within 30 days, unless the law requires us to keep some of it. If you want a copy first, ask before deleting the account and we return it to you.
Annex I. Details of the processing
What is processed, for whom, and for how long.
| Item | Details |
|---|---|
| Subject matter | Providing mentionedin.ai, the AI visibility tool |
| Duration | For the life of the customer's account, then deleted within 30 days of account deletion |
| Nature and purpose | Storing brand profiles and prompts, asking AI engines those prompts, storing and scoring the answers, grading public web pages, and producing reports |
| Data categories | Contact details of the customer's users; names of people that appear in brand data, prompts or AI answers |
| Data subjects | The customer's users, and people named in the customer's brand data or in AI answers |
Annex II. Security measures
The measures that apply to every account.
- Hosting in the EU, in Germany.
- All data in transit is protected with TLS.
- Passwords are stored as hashes.
- Access control with least privilege: only the people and systems that need access have it.
- Card data is handled by Stripe and never stored by us.
Annex III. Sub-processors
The current list lives on its own page and is kept up to date.
The authorised sub-processors, with their country, purpose and the data they handle, are listed at /subprocessors/. That list is Annex III of this DPA.