Data Processing Agreement

Draft, pending legal review. This agreement was written by us and no lawyer has read it yet. It is offered in good faith and describes what we actually do, but if your own adviser needs changes before you can rely on it, write to privacy@momentumminds.net and we will talk. We will publish a reviewed version and tell customers when we do.

Version 1 draft — 8 August 2026.

Parties and how this is entered into

This agreement is between you, the Findkeep account holder ("the Controller"), and Momentum Minds LLC, a New Mexico (USA) limited liability company doing business as Findkeep.io ("the Processor"). It applies from the moment you accept the Terms of Service and forms part of them. If you need a countersigned copy for your own records, ask and we will sign one.

It exists because of Art. 28(3) of the GDPR, which requires a contract between a controller and a processor covering a specific list of things. The headings below follow that list, so your adviser can check it off.

What is being processed (Art. 28(3), opening)

Personal data the Processor holds about the Controller's own users — their email addresses, passwords and billing — is not covered by this agreement. For that data the Processor is itself a controller, and the Privacy Policy governs it.

1. Documented instructions (Art. 28(3)(a))

The Processor processes the personal data covered by this agreement only on the Controller's documented instructions, including on transfers to a third country. The instructions are: the Terms of Service, this agreement, and the Controller's own use of the product's features. The Processor will not use the data for its own purposes, will not sell or share it, and will not use it to train any model.

If the Processor is required by law to process the data otherwise, it will tell the Controller before doing so unless that law prohibits it. If the Processor believes an instruction infringes data-protection law, it will say so.

2. Confidentiality (Art. 28(3)(b))

Everyone authorised to process the data is bound to confidentiality. Momentum Minds LLC is at present a one-person company, so in practice that means its owner; anyone else engaged in future will be under a written confidentiality obligation before being given access. Access to the production database is limited to what administration of the Service requires, and customer records are not read except to fix a fault the customer has reported or to investigate abuse.

3. Security (Art. 28(3)(c) and Art. 32)

The Processor implements appropriate technical and organisational measures. What that means concretely, including the gaps, is in the security annex at the foot of this page.

4. Sub-processors (Art. 28(3)(d) and Art. 28(2))

The Controller gives general written authorisation for the Processor to engage sub-processors. The current list, with what each one does and where, is at /subprocessors.html and forms part of this agreement.

Before a new sub-processor starts processing, the Processor will give at least 30 days' notice by email to account owners. The Controller may object on reasonable data-protection grounds within that period; if the objection cannot be resolved, the Controller may terminate the affected part of the Service and receive a pro-rata refund of anything paid for the unused period.

The Processor engages each sub-processor under written data-protection terms and undertakes to impose obligations no less protective than these. It is in the process of confirming each provider's current published data processing agreement, and the sub-processor page records the status of each one; this clause is an undertaking about what the Processor will do, not a statement that every check has already been completed. The Processor remains fully liable to the Controller for its sub-processors' performance.

5. Assisting with data subject rights (Art. 28(3)(e))

The product is the first line of assistance: the Controller can search, correct, export and delete any record from the dashboard without asking anyone, which covers access, rectification, erasure and portability directly. Two exports are built in — the lead list as CSV, and the whole account as a machine-readable JSON file — and both remain available when a subscription has lapsed and when an account is on hold. Where that is not enough, the Processor will help by appropriate technical and organisational measures, taking into account the nature of the processing.

If a data subject contacts the Processor about data in the Controller's workspace — the public data request page is the route for that — the Processor will not answer on the Controller's behalf. It will forward the request without undue delay and ask the Controller to respond within the statutory time limit. The Controller agrees to act on such a request and to tell the Processor what it did.

If the Controller has not acted within 14 days of the Processor forwarding a request, the Controller instructs the Processor to act on it in the Controller's workspace — deletion, correction or suppression, as the request requires — and to tell the data subject that it has been done. The same applies where the account has been closed or the subscription has lapsed. That is a standing instruction forming part of the Controller's documented instructions under clause 1; the Controller accepts it in the acceptable-use section of the Terms of Service, and it exists because the data subject is entitled to an answer inside a month and cannot tell whose inbox the request is waiting in. Without it the Processor would have no authority to act at all, and the public data request page would be promising something this agreement forbids. An objection to direct marketing under Art. 21(2) is absolute and the Controller must act on it.

6. Assistance with security, breaches and impact assessments (Art. 28(3)(f))

The Processor will assist the Controller in meeting its obligations under Arts. 32 to 36, taking into account the nature of the processing and the information available to it.

On becoming aware of a personal data breach affecting the Controller's data, the Processor will notify the Controller without undue delay and in any event within 48 hours, at the email address on the account, and will describe what happened, what data was involved, what it is doing about it and what the Controller may need to do. The Processor does not notify the supervisory authority on the Controller's behalf; that remains the Controller's decision and duty.

7. Deletion or return at the end (Art. 28(3)(g))

On the Controller's choice, the Processor will delete or return the personal data at the end of the Service. In practice:

8. Information and audits (Art. 28(3)(h))

The Processor will make available to the Controller all information necessary to demonstrate compliance with this agreement, and will allow and contribute to audits and inspections by the Controller or an auditor it mandates.

Realistically: the Processor is a one-person company with no SOC 2 report and no ISO certificate, and pretending otherwise in a contract would be worse than saying it here. What it will do is answer a security questionnaire in writing, describe its architecture and its measures, and give evidence about a specific control on request. An on-site audit of a shared hosting provider is not something it can grant, and remote access to production is not something it will grant; a documentary audit plus written answers is the form of audit available. Audits are limited to once a year unless a breach or a supervisory authority requires otherwise, and the Controller bears its own costs.

International transfers

The Processor is established in the United States and processes there. Where the Controller is in the EU or the EEA, the parties agree that the European Commission's Standard Contractual Clauses of 4 June 2021, Module Two (controller to processor), are incorporated into this agreement and apply to the transfer, with the details in this agreement completing their annexes: the description of processing above fills Annex I.B, the sub-processor page fills Annex III, and the security annex below fills Annex II. The supervisory authority is the one competent for the Controller's own establishment. The Processor has no Art. 27 representative in the EU yet; appointing one is in progress.

Liability and precedence

The liability provisions of the Terms of Service apply to this agreement. Where this agreement and the Terms conflict on the processing of personal data, this agreement prevails; where the Standard Contractual Clauses conflict with either, the Clauses prevail.

Annex: security measures

The measures in place today, stated plainly enough to be checked:

And what is not in place, because a security annex that lists only the good news is not worth reading:

← Privacy Policy · Sub-processors · Back to Findkeep