Legal & Compliance
Data Processing Agreement
The data processing terms that apply when customers use MumuWorks to process personal data through the platform.
1. Scope and relationship to the service terms
This Data Processing Agreement, or DPA, forms part of the MumuWorks Terms of Service and applies when a customer uses MumuWorks to process personal data that is subject to applicable data protection law. If there is a conflict between this DPA and the general service terms on data protection matters, this DPA controls for those matters.
2. Definitions
For this DPA, "Customer" means the entity using MumuWorks. "MumuWorks" means the service provider operating the platform. "Controller," "Processor," "personal data," "data subject," and "processing" have the meanings given by applicable data protection law.
3. Roles of the parties
The Customer acts as controller or processor for the personal data it submits to MumuWorks. MumuWorks acts as processor, or subprocessor where applicable, and processes personal data on documented instructions from the Customer to provide the contracted services.
4. Processing details
MumuWorks processes personal data for hosting, storage, AI-assisted drafting, workflow automation, messaging, retrieval, analytics, support, and security operations as required to perform the service. The categories of data may include account details, customer contact data, conversation data, uploaded files, and operational metadata. The duration of processing continues for the term of the service and any limited retention periods described in the Privacy Policy or required by law.
5. Documented instructions and confidentiality
MumuWorks will process personal data only on documented instructions from the Customer unless required otherwise by law. Personnel authorized to process personal data are subject to confidentiality obligations and are expected to access data only where operationally necessary.
6. Security measures
MumuWorks implements reasonable administrative, technical, and organizational safeguards designed to protect personal data. Measures may include encryption in transit, access controls, logging, environment separation, backup practices, and security review procedures appropriate to the platform and risk profile.
7. Assistance with data subject rights
Taking into account the nature of processing, MumuWorks will provide reasonable assistance to help the Customer respond to verified requests for access, correction, export, restriction, objection, deletion, or account closure, to the extent that assistance is required by applicable law and is operationally possible within the service.
8. Subprocessors
The Customer authorizes MumuWorks to engage subprocessors that are necessary to deliver the service, including AI, messaging, hosting, storage, payment, and support providers. Current subprocessors are disclosed on the Subprocessor List. MumuWorks remains responsible for its subprocessors to the extent required by law and contract.
9. Security incident and breach notification
If MumuWorks becomes aware of a confirmed personal-data breach affecting Customer data, MumuWorks will notify the Customer without undue delay after confirmation and will provide information reasonably available to help the Customer assess impact and meet any reporting obligations.
10. International transfers
Customer data may be processed in jurisdictions where MumuWorks or its subprocessors operate. Where required, MumuWorks will use contractual or operational safeguards reasonably designed to support lawful transfers and protect personal data during cross-border processing.
11. Return and deletion
Upon termination of the service or a valid deletion instruction, MumuWorks will delete or return Customer personal data within a commercially reasonable period, except where retention is required by law or reasonably necessary for security, backup rotation, billing records, dispute resolution, or legal defense.