Draft — not yet in force. These terms take effect when the operating legal entity is registered and this page carries its name and an effective date. Nothing here is presented as an executed agreement.
Data Processing Addendum
Effective date: to be set at entity registration. This DPA forms part of the Terms of Service between the Morna operating entity (registration pending) (“Processor”, “Morna”) and the customer (“Controller”, “you”) and applies where Morna processes personal data on your behalf. If it conflicts with the Terms, this DPA governs for data protection.
1. Definitions
“Data Protection Law” means the laws applicable to the processing, including the EU and UK GDPR and applicable US state privacy laws. “Controller”, “Processor”, “Data Subject”, “Personal Data”, “Processing”, and “Sub-processor” have the meanings given in Data Protection Law.
2. Roles and instructions
For the business data you bring and the personal data of your customers that the service reads, you are the Controller and Morna is the Processor. We process Personal Data only on your documented instructions — configuring and using the service is your instruction — and as needed to comply with law, in which case we will inform you unless prohibited. We will tell you if, in our opinion, an instruction infringes Data Protection Law.
3. Scope and purpose
We process Personal Data only to provide the service: reading your connected sources, drafting work, and — on your approval — acting through your connected tools. We do not process it for any other purpose and never for our own marketing. The details of processing are in the Annex.
Excluded categories. Protected health information (PHI) and other special-category data are out of scope. We are not a HIPAA business associate and do not sign BAAs today. Regulated practices must keep clinical content out of the workspace (see the Privacy Policy); the product enforces draft-only outbound and a no-clinical-content rule for regulated workspaces.
4. Confidentiality
We ensure that personnel authorized to process Personal Data are bound by confidentiality and access it only on a need-to-know basis.
5. Security measures
We maintain technical and organizational measures appropriate to the risk, including: tenant isolation via row-level security enforced at the database and re-checked in the API; encryption of credentials at rest and data in transit; a least-privilege request-path role; an append-only, hash-chained decision log; the irreversible “floor” that no automation can cross without a human approval; access controls and logging; and secure development and change management. A fuller description is available on request.
6. Sub-processors
You authorize us to engage Sub-processors to provide the service (for example hosting, database, language-model proxy, and email delivery). We impose data-protection obligations on each Sub-processor no less protective than this DPA and remain responsible for their performance. A current list is available on request; we will give reasonable notice of intended changes and a chance to object on reasonable data-protection grounds.
7. International transfers
Where processing involves transferring Personal Data across borders, we rely on a lawful transfer mechanism, such as the Standard Contractual Clauses, which are incorporated by reference where they apply. [State your primary hosting region and confirm the mechanism with counsel.]
8. Assistance to the Controller
Taking into account the nature of processing, we assist you, insofar as possible and at your reasonable cost for non-routine effort, with: responding to Data Subject requests (much of which is self-serve in-product — access, export, and deletion); data protection impact assessments and prior consultations; and your obligations to secure the data.
9. Data-subject requests
If we receive a request directly from one of your Data Subjects, we will not respond except on your instruction or as legally required, and we will forward it to you without undue delay.
10. Personal-data breach
We will notify you without undue delay after becoming aware of a Personal Data breach affecting your data, with the information reasonably available to help you meet your own notification duties, and we will take reasonable steps to mitigate and remediate.
11. Audit
We will make available the information reasonably necessary to demonstrate compliance with this DPA and, on reasonable prior notice and subject to confidentiality, allow for audits no more than once a year (or after a material breach) — satisfiable through up-to-date documentation or a third-party report where available.
12. Deletion and return
On erasure or termination we delete your Personal Data (credentials, workspace state, and durable records), subject to backup rotation and any legal retention duty. Erasure is self-serve and total. On request before deletion, we will help you export Your Content.
13. Liability
Each party’s liability under this DPA is subject to the limitations and exclusions in the Terms of Service.
Annex · Details of processing
- Subject matter: provision of the Morna service.
- Duration: the term of your account, plus deletion per §12.
- Nature and purpose: reading connected sources, drafting back-office and growth work, and executing approved actions through connected tools.
- Types of Personal Data: business contact and account data; the contents of connected sources you enable (for example emails, invoices, transactions, calendar entries); operational and approval records. PHI and special-category data are excluded.
- Categories of Data Subjects: you and your personnel; your customers, contacts, and counterparties whose data appears in your connected sources.
- Controller / Processor: you / the Morna operating entity (registration pending).
Contact
Data protection: [privacy@yourdomain] / [dpo@yourdomain]. The Morna operating entity (registration pending), registered address: pending.