Data Processing Agreement

Version 1.0

Effective Date: April 1, 2026 — Review Cycle: Annual

ⓘ This DPA applies to MHLE Enterprise and Institutional customers. It governs how MHLE processes Customer Data on behalf of the institution, including sub-processor disclosures, data location, breach notification, deletion timelines, and audit rights. Referenced from Terms of Service §9.2.

1. Definitions

The following capitalized terms have the meanings set out below. Where applicable, terms align with definitions under the GDPR (EU 2016/679) and applicable U.S. state privacy laws (including CCPA/CPRA).

TermDefinition
AgreementThe Master Subscription Agreement or Enterprise Order Form between Customer and MHLE, to which this DPA is incorporated by reference.
Customer DataAll Personal Data submitted to, stored in, or processed through the MHLE platform by or on behalf of the Customer, including end-user research notes, documents, uploaded media, and derived analytical outputs.
Data ControllerThe Customer — the natural or legal person who determines the purposes and means of processing Personal Data submitted to MHLE.
Data ProcessorMHLE — which processes Personal Data on behalf of and under the documented instructions of the Data Controller.
Personal DataAny information relating to an identified or identifiable natural person, as defined under applicable privacy law.
ProcessingAny operation performed on Personal Data, including collection, storage, analysis, retrieval, disclosure, and deletion.
Sub-processorAny third-party data processor engaged by MHLE to process Customer Data in connection with the delivery of the MHLE platform services.
Security Incident / Data BreachAny confirmed, unauthorized access to, acquisition of, or disclosure of Customer Data that poses a material risk to the rights of data subjects.
Standard Contractual Clauses (SCCs)The European Commission's standard contractual clauses for international transfers of Personal Data (Commission Implementing Decision (EU) 2021/914).
GDPRThe General Data Protection Regulation (EU) 2016/679 and, where applicable, its UK equivalent (UK GDPR).
CCPA/CPRAThe California Consumer Privacy Act (Cal. Civ. Code § 1798.100 et seq.) as amended by the California Privacy Rights Act.

2. Scope and Role of the Parties

2.1 Relationship

The Customer acts as the Data Controller and MHLE acts as the Data Processor with respect to all Personal Data processed through the MHLE platform under the Agreement.

2.2 Instructions

MHLE shall process Customer Data only:

  • On the documented instructions of the Customer as set forth in this DPA and the Agreement.
  • As necessary to provide and maintain the MHLE platform services.
  • As required by applicable law (in which case MHLE shall notify the Customer of such legal requirement before processing, unless prohibited by law).

MHLE shall promptly inform the Customer if, in MHLE's reasonable opinion, an instruction violates applicable data protection law.

2.3 Compliance Obligations

Each party is responsible for compliance with its respective obligations under applicable data protection law. Customer warrants that it has a lawful basis for sharing Customer Data with MHLE and that it has provided all required notices and obtained all required consents from data subjects.

3. Categories of Data Processed

CategoryDescription
Account & Identity DataName, email address, institutional affiliation, account credentials (hashed).
Research & Intellectual ContentNotes, documents, PDFs, audio recordings, images, and related metadata submitted by users.
Usage & Behavioral DataFeature interaction logs, session metadata, analysis request history.
AI-Generated OutputsAnalytical outputs, knowledge graph data, synthesis papers, and learning artifacts generated from Customer Data.
Payment DataHandled entirely by Stripe; MHLE retains only non-sensitive billing identifiers (no PAN or CVV).

4. Sub-processors

4.1 Authorized Sub-processors

MHLE hereby discloses the following authorized Sub-processors engaged in the delivery of the MHLE platform services. Each Sub-processor is bound by contractual data protection obligations no less protective than those in this DPA.

Sub-processorPurposeData LocationTrains on Customer Data
OpenAI, L.L.C. Core multi-perspective analysis (GPT-4o), embedding generation, wicked problem simulations United States No — API Terms prohibit use of Customer Data for model training.
Anthropic, PBC Learning artifact generation (Claude 3.5 Sonnet) United States No — API usage data is not used for model training per Anthropic's API usage policy.
Google LLC Multimedia processing, transcription, image analysis, epistemology tagging (Gemini) United States No — Google Cloud DPA prohibits use of Customer Data for model training.
Perplexity AI, Inc. Internet-grounded fact verification (Weekly Pulse feature) United States No — API queries are processed transiently and not retained for training.
Stripe, Inc. Payment processing and subscription management United States N/A — Payment data only; no research or personal content.
Mailjet (Sinch) Transactional email delivery, onboarding sequences EU / United States N/A — Email metadata only.
Replit / Cloud Infrastructure Application hosting, database hosting, compute infrastructure United States N/A — Infrastructure provider only.

4.2 No Use of Customer Data for Model Training

MHLE confirms, and each AI Sub-processor listed above contractually warrants, that Customer Data transmitted via API is not used to train, fine-tune, or improve any AI model by any Sub-processor. This applies to all content submitted by users — including research notes, documents, queries, and analytical outputs. MHLE does not independently train models on Customer Data.

4.3 Sub-processor Change Notification

MHLE shall provide Enterprise Customers with a minimum of 30 days' written notice before adding or replacing any Sub-processor that will have access to Customer Data. Enterprise Customers may object to a new Sub-processor in writing within the notice period. If MHLE cannot accommodate the objection, Customer may terminate the affected services without penalty pursuant to the termination provisions of the Agreement.

5. Data Location and Transfers

5.1 Primary Data Location

All Customer Data at rest — including the PostgreSQL database, uploaded files, and AI-generated outputs — is stored in United States-based infrastructure (US-East region). MHLE does not transfer Customer Data to servers outside the United States without Customer consent, except as necessary for the transient API processing described in Section 4.1.

5.2 International Transfers

Where Customer Data originates from the EEA or United Kingdom and is transferred to MHLE's U.S.-based infrastructure, such transfers are governed by:

  • Standard Contractual Clauses (SCCs): Module 2 (Controller-to-Processor) as issued by the European Commission (2021/914), incorporated herein by reference.
  • UK Addendum: The International Data Transfer Addendum issued by the UK ICO, for UK-originating data.

Customers subject to GDPR may request SCC documentation by contacting privacy@mhle.app.

6. Security Measures

MHLE implements and maintains the following technical and organizational security measures to protect Customer Data:

DomainMeasure
AuthenticationJWT-based session authentication; bcrypt password hashing; MFA available for Enterprise accounts.
Encryption in TransitTLS 1.2+ enforced on all network communications.
Encryption at RestDatabase-level encryption for all Customer Data at rest.
Access ControlsRole-based access control (RBAC); principle of least privilege for all internal personnel.
Audit LoggingComprehensive audit log of all data access, modification, and deletion events.
Vulnerability ManagementDependency scanning and SAST on every production deployment; regular penetration testing.
Infrastructure SecurityProduction environment isolated from development/staging; security headers enforced on all HTTP responses.

7. Data Breach Notification

7.1 MHLE Obligations

In the event MHLE becomes aware of a confirmed Security Incident affecting Customer Data, MHLE shall:

  1. Notify the Customer's registered Data Protection contact without undue delay, and in any event within 72 hours of MHLE confirming that a Security Incident has occurred.
  2. Provide in the initial notification (to the extent known): a description of the nature of the incident, the categories and approximate volume of data affected, likely consequences, and measures taken or proposed.
  3. Cooperate with the Customer in investigating the incident and fulfilling any regulatory notification obligations.
  4. Update the Customer as additional information becomes available.

7.2 Notification Method

  • Primary: Email to the Customer's registered Data Protection/Privacy contact or account administrator.
  • Secondary: In-app notification banner (if platform access is not itself affected).
  • Tertiary: Phone call to the named Enterprise support contact, if the incident is P1-severity and the Customer has a designated Emergency Contact on file.

7.3 Customer Responsibilities

The Customer is solely responsible for determining whether the Security Incident triggers any regulatory notification obligation (e.g., GDPR Article 33/34, CCPA) and for making such notifications to regulators and data subjects as required by law.

8. Deletion and Return of Customer Data

8.1 Deletion on Termination or Request

Upon termination or expiration of the Agreement, or upon Customer's written request, MHLE shall:

  1. Cease all processing of Customer Data within 5 business days.
  2. Delete all Customer Data (including backups and derived data) from MHLE systems within 30 calendar days of the termination date or deletion request.
  3. Provide a Certificate of Deletion upon Customer's written request, confirming that all Customer Data has been permanently deleted. Certificates will be issued within 10 business days of request.

8.2 Retention for Legal Obligations

MHLE may retain Customer Data beyond the 30-day deletion period solely where required by applicable law (e.g., financial records required by tax law). In such cases, MHLE shall notify the Customer and restrict processing of such data to the minimum necessary.

8.3 Data Export

Prior to account termination, Enterprise Customers may request a full data export in a machine-readable format (JSON/CSV). Export requests must be made at least 15 business days before the scheduled termination date.

9. Data Subject Rights

MHLE shall, to the extent technically feasible, assist the Customer in responding to data subject rights requests (access, rectification, erasure, portability, restriction, objection) that the Customer receives under applicable privacy law. Such assistance is provided within the bounds of MHLE's technical capabilities and shall not require MHLE to act outside the Customer's documented instructions.

9A. U.S. Student Privacy — FERPA and Georgia SDPAT

9A.1 FERPA Applicability

Where Customer is a U.S. educational institution subject to FERPA (20 U.S.C. § 1232g), MHLE acts as a "school official" with a legitimate educational interest as defined under 34 C.F.R. § 99.31(a)(1). MHLE processes education records solely as directed by the institution and does not re-disclose such records except as permitted by FERPA.

9A.2 Student Data Transparency Notice

MHLE publishes a public Student Data Transparency Notice that describes the categories of student data collected, the purposes for which it is processed, how long it is retained, and the rights available to students and their families.

Transparency Notice URL: /docs/legal/student-data-transparency

9A.3 Student Data Correction Requests

Students enrolled through an institutional account may submit FERPA correction requests directly within the MHLE platform. Institutions retain responsibility for reviewing and resolving correction requests within the 45-day period required by FERPA.

10. Audit Rights

10.1 Annual Security Questionnaire

Enterprise Customers have the right to request, once per calendar year, a completed response to a standardized enterprise security questionnaire. Custom questionnaire responses may be provided at MHLE's discretion, subject to a reasonable processing timeline.

10.2 Third-Party Audit Reports

Upon request, MHLE will provide Enterprise Customers with copies of available third-party security assessment reports (e.g., penetration test executive summaries, SOC 2 Type II reports if obtained) under a mutual non-disclosure agreement.

10.3 On-Site Audit

Enterprise Customers may request an on-site or virtual audit of MHLE's data processing activities no more than once per year, subject to: (a) minimum 30 days' advance written notice; (b) execution of a mutual NDA; (c) agreement on scope to avoid disruption; and (d) the Customer bearing reasonable costs of the audit.

11. Conflict, Precedence, and Term

In the event of any conflict between this DPA and the Agreement, this DPA shall take precedence with respect to the subject matter of data protection. In the event of any conflict between this DPA and any SCCs incorporated herein, the SCCs shall take precedence.

This DPA is effective for the duration of the Agreement and survives termination to the extent necessary to govern the deletion obligations in Section 8 and any ongoing legal retention obligations.

Contact

Document Version 1.0 — Effective April 1, 2026 — © 2026 MHLE (Cognitive Engine, Inc.). This document is confidential and intended solely for MHLE Enterprise customers.