Mood nook sp. z o.o. · effective 2026-08-11
Data Processing Agreement
The Art. 28 GDPR terms that apply when Mood nook sp. z o.o. processes personal data on your behalf, including subject matter, security measures, subprocessors and transfer safeguards.
1. Roles and scope
This Data Processing Agreement ("DPA") forms part of the Terms of Service between you (the "Controller") and Mood nook sp. z o.o. (the "Processor"). It applies whenever the Processor processes personal data contained in Customer Content on behalf of the Controller.
2. Subject matter and details of processing
| Item | Detail |
|---|---|
| Subject matter | Provision of the schema-driven content and structured data platform |
| Duration | The term of the subscription plus the deletion window in the Privacy Policy |
| Nature and purpose | Storage, structuring, retrieval, transmission, backup and deletion of Customer Content, and delivery of it through APIs configured by the Controller |
| Types of personal data | Determined by the Controller through the schemas it defines; typically identifiers, contact details, profile and editorial metadata |
| Categories of data subjects | Determined by the Controller; typically its employees, editors, customers and site visitors |
3. Processor obligations
- Process personal data only on documented instructions from the Controller, including the instructions embodied in the configuration of the Service, unless required otherwise by law.
- Ensure that personnel authorised to process personal data are bound by confidentiality.
- Implement the technical and organisational measures set out in Section 6 and on the Security page.
- Assist the Controller with data subject requests, data protection impact assessments and prior consultations, taking into account the nature of the processing.
- Notify the Controller without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting Customer Content.
- At the Controller's choice, delete or return personal data at the end of the provision of services, save where storage is required by law.
- Make available the information necessary to demonstrate compliance and allow audits once per year, or after a breach, on reasonable notice and under confidentiality; documented evidence and third-party reports may satisfy an audit request.
4. Controller obligations
- Ensure a lawful basis exists for the processing instructed, and that required notices and consents are in place.
- Configure roles, permission sets, field-level security and API token scopes so that access matches the intended purpose.
- Avoid placing special category data in fields not designed for it, and avoid placing production personal data in demo or preview environments.
5. Subprocessors
The Controller gives general authorisation for the Processor to engage the subprocessors listed on the Subprocessors page. The Processor imposes data protection obligations equivalent to this DPA on each subprocessor and remains fully liable for their performance. Changes are announced at least 30 days in advance; the Controller may object on reasonable data protection grounds and, if no alternative can be found, terminate the affected part of the Service without penalty.
6. Security measures (Art. 32)
- Encryption of data in transit (TLS 1.2+) and at rest.
- Tenant isolation enforced at the database level with row-level security and account-scoped queries, verified by automated cross-tenant regression tests.
- Role-based, attribute-based and relationship-based access control, with field-level projections and scoped API tokens.
- Secrets, passwords and API tokens stored only as salted hashes.
- Append-only audit logging of administrative and content mutations, with immutable version snapshots.
- Least-privilege access for personnel, multi-factor authentication and periodic access review.
- Backups with tested restore procedures, and separation of production, staging and development environments.
- Dependency and vulnerability scanning as part of the release process.
7. International transfers
Where processing takes place outside the European Economic Area, the parties rely on an adequacy decision or incorporate the Standard Contractual Clauses (Commission Implementing Decision 2021/914), Module Two (controller to processor), with the docking clause enabled, this DPA supplying the required annexes.
8. Liability and precedence
Liability under this DPA is subject to the limitations in the Terms of Service, to the extent permitted by law. In case of conflict between this DPA and the Terms in matters of personal data protection, this DPA prevails.