Skip to content

Legal

Data Processing Agreement

Effective date

1. Application

This Data Processing Agreement ("DPA") forms part of the agreement between MBI and a business Customer where MBI processes Personal Data on behalf of Customer in connection with the Service.

This DPA applies automatically when:

  1. Customer is a Controller or Processor subject to Applicable Data Protection Law; and
  2. MBI processes Customer Personal Data as a Processor or Subprocessor.

If Customer is itself a Processor, references to "Controller" include the relevant upstream controller where required, and Customer represents that it is authorized to appoint MBI as a Subprocessor.

If this DPA conflicts with the Terms on matters concerning processing of Customer Personal Data, this DPA prevails.

2. Definitions

Applicable Data Protection Law means privacy and data-protection law applicable to the processing under the agreement, including the GDPR and applicable national legislation implementing or supplementing it.

Customer Personal Data means Personal Data contained in Customer Content that MBI processes on Customer's behalf.

Controller, Processor, Subprocessor, Data Subject, Personal Data, Processing, Personal Data Breach, and Supervisory Authority have the meanings given in Applicable Data Protection Law.

GDPR means Regulation (EU) 2016/679.

Service has the meaning given in the Terms.

3. Roles

For Customer Personal Data:

  • Customer acts as Controller or Processor, as applicable; and
  • MBI acts as Processor or Subprocessor.

Each party is responsible for its own compliance with Applicable Data Protection Law.

Customer determines the purposes of processing Customer Personal Data and is responsible for:

  • establishing a lawful basis;
  • providing required notices;
  • obtaining required consents;
  • configuring the Service lawfully;
  • ensuring its instructions are lawful; and
  • responding to Data Subjects except to the extent MBI must assist under this DPA.

MBI determines the purposes and means of processing account, billing, security, and other data for which MBI acts independently as Controller. Such processing is governed by the Privacy Policy and is outside the processor relationship established by this DPA.

4. Customer instructions

MBI will process Customer Personal Data only:

  1. on documented instructions from Customer;
  2. as necessary to provide, secure, support, and maintain the Service; or
  3. where required by applicable law.

The agreement, Customer's use and configuration of the Service, API requests, source selections, prompts, and other documented directions constitute Customer's instructions.

If MBI is required by law to process Customer Personal Data other than on Customer's instructions, MBI will inform Customer before processing unless the law prohibits that notice.

If MBI reasonably believes an instruction infringes Applicable Data Protection Law, MBI may suspend the affected processing and inform Customer.

5. Nature and purpose of processing

MBI may process Customer Personal Data to provide configured market and business intelligence functions, including:

  • retrieving information from Customer-selected or Customer-configured sources;
  • ingesting and storing source material;
  • searching and indexing;
  • extracting entities and facts;
  • classifying and tagging information;
  • comparing information over time;
  • generating summaries, reports, alerts, and recommendations;
  • performing AI inference;
  • creating embeddings or similar machine-readable representations where used by the Service;
  • providing APIs and integrations;
  • troubleshooting and support;
  • maintaining security;
  • preventing abuse; and
  • performing backup, continuity, and recovery operations.

The processing continues for the duration of the Service relationship and any limited post-termination period required for deletion, backup rotation, legal obligations, or Customer-requested return of data.

6. Categories of Data Subjects

Customer Personal Data may relate to:

  • Customer employees, contractors, administrators, and users;
  • employees, executives, founders, directors, or representatives of monitored organizations;
  • authors, analysts, journalists, speakers, experts, or public business figures appearing in monitored material;
  • business contacts;
  • customers or prospects identified in Customer-provided data;
  • individuals appearing in Customer-selected public sources; and
  • other individuals whose Personal Data Customer lawfully submits to the Service.

The Service is not intended for systematic processing of children's data or special-category Personal Data.

7. Types of Personal Data

Depending on Customer configuration, Customer Personal Data may include:

  • names;
  • business contact details;
  • employer, role, title, and professional history;
  • public statements and professional publications;
  • public social or business profile information;
  • professional opinions and business-related activity;
  • source URLs and excerpts;
  • identifiers supplied by Customer;
  • Customer notes;
  • prompts;
  • user instructions;
  • account-related identifiers relevant to Customer Content; and
  • technical metadata associated with the processing.

Customer must not instruct MBI to process special-category Personal Data or other highly sensitive regulated data unless separately agreed in writing.

8. Confidentiality

MBI ensures that personnel authorized to process Customer Personal Data are subject to appropriate confidentiality obligations.

Access is limited to personnel and providers who require access to perform authorized functions.

9. Security measures

MBI implements and maintains technical and organizational measures appropriate to the risk, nature, scope, context, and purposes of processing.

These include, as appropriate:

Access control

  • role-based or function-based access controls;
  • least-privilege access;
  • controlled administrative access;
  • authentication controls; and
  • periodic review or removal of unnecessary access.

Data protection

  • encrypted network transport using current secure protocols;
  • encryption of stored data where appropriate;
  • logical separation of customer data;
  • controlled secrets and credential handling; and
  • safeguards against accidental disclosure.

Application and infrastructure security

  • secure development practices;
  • dependency and vulnerability management;
  • security updates and patching;
  • logging and monitoring;
  • protection against common web and application attacks; and
  • controlled production access.

Resilience

  • backup processes;
  • recovery procedures;
  • continuity measures; and
  • monitoring of critical systems and dependencies.

Organizational measures

  • confidentiality obligations;
  • access limited by job need;
  • incident-response procedures;
  • security awareness;
  • vendor due diligence; and
  • documented processes for handling personal data.

MBI may update these measures as technology and risk change, provided the overall level of protection is not materially reduced.

10. EU hosting and data transfers

Persistent Customer Personal Data and primary application data are hosted in the European Union.

Customer authorizes MBI to use Subprocessors that may process or access Customer Personal Data outside the European Economic Area where required to provide the Service.

Where a transfer is subject to GDPR Chapter V, MBI will ensure that an appropriate transfer mechanism is in place. Depending on the destination and provider, this may include:

  • an adequacy decision;
  • the European Commission's Standard Contractual Clauses;
  • another transfer mechanism permitted by Applicable Data Protection Law; and
  • supplementary measures where required.

Where MBI enters into the European Commission's Standard Contractual Clauses with a Subprocessor, MBI will use the module applicable to the parties' roles.

11. AI providers

Customer gives MBI general authorization to use one or more AI and machine-learning providers as Subprocessors where necessary to provide the Service.

AI providers may include Anthropic, OpenAI, and other providers selected by MBI.

MBI may route different requests, features, or workloads to different providers and may add, replace, or remove providers based on capability, availability, security, performance, cost, geography, or other operational requirements.

Customer is not entitled to a provider-specific implementation unless separately agreed.

Where an AI provider processes Customer Personal Data:

  • it must be included in the current Subprocessor Register;
  • MBI will impose data-protection obligations required by Applicable Data Protection Law;
  • MBI will use an appropriate international transfer mechanism where required; and
  • MBI remains responsible to Customer for the Subprocessor's data-protection obligations to the extent required by Applicable Data Protection Law.

MBI does not authorize use of Customer Personal Data to train general-purpose AI models unless Customer expressly agrees to that use.

12. General authorization of Subprocessors

Customer provides general written authorization for MBI to engage and replace Subprocessors.

MBI maintains a current Subprocessor Register identifying Subprocessors that process Customer Personal Data, their processing purpose, and relevant processing region.

MBI may change Subprocessors without seeking separate Customer approval.

Where GDPR Article 28 or another applicable rule requires notice of an intended addition or replacement, MBI will provide notice to an account administrator by email or in-product administrative notification at least 10 calendar days before the new Subprocessor begins processing Customer Personal Data.

Customer may object during that period only on reasonable, documented data-protection grounds.

If the parties cannot resolve an objection in good faith, MBI may:

  1. avoid using the Subprocessor for Customer where reasonably possible;
  2. offer an alternative configuration where reasonably available;
  3. discontinue the affected feature; or
  4. permit Customer to terminate the affected Service without penalty for the unused prepaid portion.

For an emergency change required to maintain security, prevent material Service disruption, comply with law, or replace a provider that has unexpectedly ceased service, MBI may engage a replacement before the notice period expires and will provide notice as soon as reasonably practicable.

MBI will impose on each Subprocessor data-protection obligations that provide materially equivalent protection for the processing entrusted to that Subprocessor, as required by Applicable Data Protection Law.

13. Data Subject requests

Taking into account the nature of the processing, MBI will provide reasonable assistance to Customer through appropriate technical and organizational measures to enable Customer to respond to requests from Data Subjects.

If MBI receives a request directly concerning Customer Personal Data, MBI will not independently respond to the substance of the request unless authorized by Customer or required by law.

MBI may direct the Data Subject to Customer and will notify Customer where reasonably possible.

14. Personal Data Breaches

MBI will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.

The notice will include information reasonably available to MBI, which may include:

  • the nature of the breach;
  • affected categories of data and Data Subjects;
  • known or likely consequences;
  • containment or remediation measures; and
  • information reasonably required for Customer's regulatory assessment.

Information may be provided in phases as the investigation develops.

MBI's notification does not constitute an admission of fault or liability.

Customer remains responsible for determining whether notification to a Supervisory Authority or Data Subject is required, except where Applicable Data Protection Law directly imposes a separate obligation on MBI.

15. DPIAs and regulatory consultations

Taking into account the nature of processing and information available to MBI, MBI will provide reasonable assistance with:

  • data protection impact assessments; and
  • prior consultation with a Supervisory Authority,

where the requested assistance relates specifically to MBI's processing of Customer Personal Data.

MBI may charge reasonable fees for substantial assistance beyond standard documentation where the work is caused by Customer-specific requirements rather than MBI's non-compliance.

16. Information and audits

MBI will make available information reasonably necessary to demonstrate compliance with the processor obligations applicable under this DPA.

Customer should first use MBI's available security, privacy, compliance, and audit documentation.

If additional verification is reasonably required, Customer may conduct an audit or appoint an independent auditor, subject to the following:

  • no more than once in any 12-month period unless required by a Supervisory Authority or following a material Personal Data Breach;
  • at least 30 days' written notice where practicable;
  • reasonable scope limited to processing relevant to Customer;
  • no access to other customers' data or confidential systems unrelated to the audit;
  • compliance with reasonable security and confidentiality requirements;
  • audits during normal business hours; and
  • Customer bears its own and MBI's reasonable audit-related costs unless the audit identifies a material breach of this DPA by MBI.

MBI may satisfy an audit request through current third-party audit reports or certifications where those materials reasonably address the request.

17. Return and deletion

Upon termination of the Service, MBI will delete or return Customer Personal Data in accordance with Customer's documented instruction, unless applicable law requires continued retention.

MBI may retain:

  • limited records required by law;
  • security or audit records that must be preserved;
  • data necessary to establish or defend legal claims; and
  • backup copies until overwritten through normal backup rotation.

Retained data remains protected under this DPA and will not be used for unrelated purposes.

If MBI receives a legally binding request from a public authority for Customer Personal Data, MBI will, where legally permitted:

  • review the request for validity;
  • limit disclosure to what is legally required;
  • challenge disproportionate or unlawful requests where reasonably appropriate; and
  • notify Customer before disclosure or as soon as permitted.

If a Subprocessor is subject to law that may materially interfere with its ability to comply with required data-protection safeguards, MBI will take reasonable steps required under Applicable Data Protection Law, which may include assessing the transfer, applying supplementary measures, changing the processing, or replacing the provider.

20. Liability

Liability arising under this DPA is subject to the liability provisions of the Terms or applicable order, except to the extent Applicable Data Protection Law prohibits such limitation.

Nothing in this DPA limits rights or remedies of Data Subjects or Supervisory Authorities that cannot lawfully be limited by contract.

21. Term and termination

This DPA remains in force for as long as MBI processes Customer Personal Data on Customer's behalf.

Obligations that by their nature continue after termination, including confidentiality, deletion, audit evidence relating to the processing period, and transfer safeguards, remain applicable for as long as relevant.

22. Governing law

Unless mandatory Applicable Data Protection Law requires otherwise, this DPA is governed by the governing-law and dispute provisions in the Terms.

---

DPA Annex A: Processing details

Item Description
Subject matter Processing Customer Personal Data to provide the MBI Service
Duration Subscription term plus limited deletion, backup, legal, and recovery periods
Nature Retrieval, hosting, storage, indexing, search, extraction, classification, comparison, AI inference, summarization, reporting, alerts, transmission, support, security, backup, and deletion
Purpose Provide Customer-configured market and business intelligence functionality
Data Subjects Customer users and personnel; business contacts; people appearing in monitored business sources; individuals contained in Customer Content
Personal Data Professional identifiers, business contact details, roles, public professional information, source content, prompts, notes, URLs, account-related content, and technical metadata
Special-category data Not intended or permitted unless separately agreed in writing
Controller instructions Agreement, Service configuration, Customer prompts, API requests, selected sources, integrations, and other documented directions

DPA Annex B: Technical and organizational measures

MBI's baseline security controls include, as appropriate to the Service:

  1. authentication and access controls;
  2. least-privilege production access;
  3. encrypted transport;
  4. encryption of stored data where appropriate;
  5. logical customer-data separation;
  6. logging and monitoring;
  7. vulnerability and dependency management;
  8. secure software-development practices;
  9. backups and recovery procedures;
  10. incident-response processes;
  11. confidentiality obligations;
  12. vendor and Subprocessor diligence;
  13. controlled secrets and credential management;
  14. data minimization and deletion processes; and
  15. periodic review of security measures based on risk and system changes.

DPA Annex C: Subprocessor Register

The current Subprocessor Register is maintained by MBI as part of the Service's legal/compliance information.

The register must identify each Subprocessor that processes Customer Personal Data and include:

  • legal provider name;
  • processing purpose;
  • relevant product or service;
  • processing region or country information sufficient for transfer assessment; and
  • whether an international transfer mechanism is required.

The register may include AI providers such as Anthropic and OpenAI, together with other infrastructure, authentication, communication, security, support, and operational providers actually used in production.

The register is dynamic. Addition or replacement of a Subprocessor does not require amendment of this DPA. Notice is handled under Section 12 where required by Applicable Data Protection Law.

---

Current Subprocessor Register

The register required by Annex C, as at 10 August 2026. It reflects the providers in production that process Customer Personal Data. Adding or replacing a Subprocessor does not amend the DPA; notice is handled under Section 12.

SubprocessorPurposeWhere it appliesRegionTransfer mechanism
Anthropic PBCAI inference for research, analysis and report writingThe research pipeline that produces your briefsUnited StatesStandard Contractual Clauses
Hetzner Online GmbHApplication hosting, database and encrypted backupsAll persistent Customer Content and application dataEuropean UnionNot required
Mailjet (Sinch)Transactional and report email deliveryReport delivery to the recipients you nameEuropean UnionNot required
Stripe Payments Europe, Ltd.Payment processing and invoicingCheckout and subscription billingEuropean Union, with group processing outside itStandard Contractual Clauses