Legal

Data Processing Agreement

mentionedin.ai is an AI visibility tool, available worldwide from $99 a month. This Data Processing Agreement sets out how we process your brand data and results for you, as your processor under Article 28 of the GDPR.

Last updated September 30, 2026

Parties and scope

You are the controller of your brand data, and we are your processor.

This Data Processing Agreement (DPA) is between you, the customer, as controller, and mentionedin.ai (KvK 70562431, VAT NL002399377B14, The Hague, the Netherlands) as processor. It forms part of the Terms of Service at /terms/ and applies whenever we process personal data on your behalf. If this DPA and the Terms conflict on data protection, this DPA wins.

You accept this DPA by accepting the Terms. No separate signature is needed. Email [email protected] for a countersigned copy.

What we commit to

The processor duties from Article 28(3) of the GDPR, in plain terms.

  • Instructions: we process personal data only on your documented instructions, which are the Terms, this DPA and how you configure your account. If an instruction appears to break data protection law, we tell you.
  • Confidentiality: everyone who can access the personal data is bound to confidentiality.
  • Security: we apply the measures in Annex II and keep them up to date.
  • Records: we keep a record of the processing we carry out for you.

Sub-processors

A general authorisation, with 14 days notice and a right to object.

You authorise us to use the sub-processors listed in Annex III. We bind each of them to data protection obligations at least as strict as these and stay responsible to you for their work. Before a new sub-processor processes customer data, we email you at least 14 days in advance. You may object by email to [email protected]. If we cannot resolve the objection, you may terminate the affected service without penalty.

Assistance to you

Help with data subject requests, DPIAs and audits.

  • Data subject requests: we help you answer requests for access, rectification, erasure and the other GDPR rights, and forward any request we receive directly.
  • DPIAs: we give you the information you reasonably need for a data protection impact assessment.
  • Audits: we make available, on request, the information needed to show we meet these obligations. Email [email protected].

Personal data breaches

We tell you without undue delay.

If we become aware of a personal data breach affecting your data, we notify you without undue delay, with what we know about its nature, the data and people affected, the likely consequences and the measures taken, and we help you meet your own notification duties.

At the end of the service

Your data is deleted, or returned first if you ask.

When you delete your account, we delete the personal data we process for you within 30 days, unless the law requires us to keep some of it. If you want a copy first, ask before deleting the account and we return it to you.

Annex I. Details of the processing

What is processed, for whom, and for how long.

ItemDetails
Subject matterProviding mentionedin.ai, the AI visibility tool
DurationFor the life of the customer's account, then deleted within 30 days of account deletion
Nature and purposeStoring brand profiles and prompts, asking AI engines those prompts, storing and scoring the answers, grading public web pages, and producing reports
Data categoriesContact details of the customer's users; names of people that appear in brand data, prompts or AI answers
Data subjectsThe customer's users, and people named in the customer's brand data or in AI answers

Annex II. Security measures

The measures that apply to every account.

  • Hosting in the EU, in Germany.
  • All data in transit is protected with TLS.
  • Passwords are stored as hashes.
  • Access control with least privilege: only the people and systems that need access have it.
  • Card data is handled by Stripe and never stored by us.

Annex III. Sub-processors

The current list lives on its own page and is kept up to date.

The authorised sub-processors, with their country, purpose and the data they handle, are listed at /subprocessors/. That list is Annex III of this DPA.