Data Processing Agreement
Draft, pending legal review. This agreement was written by us and no lawyer has read it yet. It is offered in good faith and describes what we actually do, but if your own adviser needs changes before you can rely on it, write to privacy@momentumminds.net and we will talk. We will publish a reviewed version and tell customers when we do.
Version 1 draft — 8 August 2026.
Parties and how this is entered into
This agreement is between you, the Findkeep account holder ("the Controller"), and Momentum Minds LLC, a New Mexico (USA) limited liability company doing business as Findkeep.io ("the Processor"). It applies from the moment you accept the Terms of Service and forms part of them. If you need a countersigned copy for your own records, ask and we will sign one.
It exists because of Art. 28(3) of the GDPR, which requires a contract between a controller and a processor covering a specific list of things. The headings below follow that list, so your adviser can check it off.
What is being processed (Art. 28(3), opening)
- Subject matter. Providing the Findkeep lead-generation CRM to the Controller.
- Duration. For as long as the Controller has an account, plus the backup window described under "Deletion" below.
- Nature and purpose. Storing, organising, displaying, searching and exporting business contact records the Controller has gathered or imported, so that the Controller can contact those businesses.
- Type of personal data. Trading name, business telephone number, business address, town, business type, Google Maps link and Google place identifier, whether the business has a website, and whatever the Controller records against the record: pipeline stage, notes, call outcomes, follow-up dates. The Controller decides what goes in the notes field and is responsible for keeping it proportionate.
- Categories of data subject. Businesses and the people behind them — in practice, principally sole traders and other one-person businesses, who are natural persons, together with named contacts the Controller records.
- No special categories. The Service is not designed to hold data revealing health, beliefs, political opinions, trade-union membership, sex life, biometrics, or criminal offences, and the Controller agrees not to put such data into it.
Personal data the Processor holds about the Controller's own users — their email addresses, passwords and billing — is not covered by this agreement. For that data the Processor is itself a controller, and the Privacy Policy governs it.
1. Documented instructions (Art. 28(3)(a))
The Processor processes the personal data covered by this agreement only on the Controller's documented instructions, including on transfers to a third country. The instructions are: the Terms of Service, this agreement, and the Controller's own use of the product's features. The Processor will not use the data for its own purposes, will not sell or share it, and will not use it to train any model.
If the Processor is required by law to process the data otherwise, it will tell the Controller before doing so unless that law prohibits it. If the Processor believes an instruction infringes data-protection law, it will say so.
2. Confidentiality (Art. 28(3)(b))
Everyone authorised to process the data is bound to confidentiality. Momentum Minds LLC is at present a one-person company, so in practice that means its owner; anyone else engaged in future will be under a written confidentiality obligation before being given access. Access to the production database is limited to what administration of the Service requires, and customer records are not read except to fix a fault the customer has reported or to investigate abuse.
3. Security (Art. 28(3)(c) and Art. 32)
The Processor implements appropriate technical and organisational measures. What that means concretely, including the gaps, is in the security annex at the foot of this page.
4. Sub-processors (Art. 28(3)(d) and Art. 28(2))
The Controller gives general written authorisation for the Processor to engage sub-processors. The current list, with what each one does and where, is at /subprocessors.html and forms part of this agreement.
Before a new sub-processor starts processing, the Processor will give at least 30 days' notice by email to account owners. The Controller may object on reasonable data-protection grounds within that period; if the objection cannot be resolved, the Controller may terminate the affected part of the Service and receive a pro-rata refund of anything paid for the unused period.
The Processor engages each sub-processor under written data-protection terms and undertakes to impose obligations no less protective than these. It is in the process of confirming each provider's current published data processing agreement, and the sub-processor page records the status of each one; this clause is an undertaking about what the Processor will do, not a statement that every check has already been completed. The Processor remains fully liable to the Controller for its sub-processors' performance.
5. Assisting with data subject rights (Art. 28(3)(e))
The product is the first line of assistance: the Controller can search, correct, export and delete any record from the dashboard without asking anyone, which covers access, rectification, erasure and portability directly. Two exports are built in — the lead list as CSV, and the whole account as a machine-readable JSON file — and both remain available when a subscription has lapsed and when an account is on hold. Where that is not enough, the Processor will help by appropriate technical and organisational measures, taking into account the nature of the processing.
If a data subject contacts the Processor about data in the Controller's workspace — the public data request page is the route for that — the Processor will not answer on the Controller's behalf. It will forward the request without undue delay and ask the Controller to respond within the statutory time limit. The Controller agrees to act on such a request and to tell the Processor what it did.
If the Controller has not acted within 14 days of the Processor forwarding a request, the Controller instructs the Processor to act on it in the Controller's workspace — deletion, correction or suppression, as the request requires — and to tell the data subject that it has been done. The same applies where the account has been closed or the subscription has lapsed. That is a standing instruction forming part of the Controller's documented instructions under clause 1; the Controller accepts it in the acceptable-use section of the Terms of Service, and it exists because the data subject is entitled to an answer inside a month and cannot tell whose inbox the request is waiting in. Without it the Processor would have no authority to act at all, and the public data request page would be promising something this agreement forbids. An objection to direct marketing under Art. 21(2) is absolute and the Controller must act on it.
6. Assistance with security, breaches and impact assessments (Art. 28(3)(f))
The Processor will assist the Controller in meeting its obligations under Arts. 32 to 36, taking into account the nature of the processing and the information available to it.
On becoming aware of a personal data breach affecting the Controller's data, the Processor will notify the Controller without undue delay and in any event within 48 hours, at the email address on the account, and will describe what happened, what data was involved, what it is doing about it and what the Controller may need to do. The Processor does not notify the supervisory authority on the Controller's behalf; that remains the Controller's decision and duty.
7. Deletion or return at the end (Art. 28(3)(g))
On the Controller's choice, the Processor will delete or return the personal data at the end of the Service. In practice:
- Export first. Both exports — the lead CSV and the whole-account JSON file — are built in and available at any time, so the Controller can take a copy before deleting anything.
- The account owner deleting the account from Settings hard-deletes the leads, their history, jobs, usage records, invites and event feed from the live database in a single transaction. A member deleting their own login does something different and much smaller — it removes that person and leaves the workspace standing — so it is not the act that ends the processing under this agreement.
- Backups. Nightly snapshots are kept for 14 nights, so deleted data persists in backup copies for up to 14 more nights before the last copy holding it is destroyed. Backups are used only for disaster recovery, and a deletion made after a snapshot was taken is re-applied if that snapshot is ever restored.
- Where law requires the Processor to retain something, it will retain only that and keep protecting it.
8. Information and audits (Art. 28(3)(h))
The Processor will make available to the Controller all information necessary to demonstrate compliance with this agreement, and will allow and contribute to audits and inspections by the Controller or an auditor it mandates.
Realistically: the Processor is a one-person company with no SOC 2 report and no ISO certificate, and pretending otherwise in a contract would be worse than saying it here. What it will do is answer a security questionnaire in writing, describe its architecture and its measures, and give evidence about a specific control on request. An on-site audit of a shared hosting provider is not something it can grant, and remote access to production is not something it will grant; a documentary audit plus written answers is the form of audit available. Audits are limited to once a year unless a breach or a supervisory authority requires otherwise, and the Controller bears its own costs.
International transfers
The Processor is established in the United States and processes there. Where the Controller is in the EU or the EEA, the parties agree that the European Commission's Standard Contractual Clauses of 4 June 2021, Module Two (controller to processor), are incorporated into this agreement and apply to the transfer, with the details in this agreement completing their annexes: the description of processing above fills Annex I.B, the sub-processor page fills Annex III, and the security annex below fills Annex II. The supervisory authority is the one competent for the Controller's own establishment. The Processor has no Art. 27 representative in the EU yet; appointing one is in progress.
Liability and precedence
The liability provisions of the Terms of Service apply to this agreement. Where this agreement and the Terms conflict on the processing of personal data, this agreement prevails; where the Standard Contractual Clauses conflict with either, the Clauses prevail.
Annex: security measures
The measures in place today, stated plainly enough to be checked:
- All traffic over HTTPS. Passwords hashed with Argon2 and never stored in any recoverable form.
- Session cookie is HttpOnly, Secure and SameSite=Lax; sessions can be revoked account-wide by the customer or by us, and are invalidated automatically by a password change.
- A Content-Security-Policy without
unsafe-inlinefor scripts, a CSRF header check on every state-changing request except the Stripe payment webhook, which is verified by Stripe's own signature instead, and a limit on the size of a request body. - Rate limiting on authentication, with email addresses and IP addresses stored only as keyed hashes.
- Tenant isolation: every query is scoped to the account, so one customer's workspace is not reachable from another's session.
- Any Google API key a customer supplies is encrypted at rest.
- Nightly database backups, taken with SQLite's own snapshot command so a backup cannot catch a half-written transaction, compressed, and rotated after 14 nights.
- Data minimisation in the search itself. Findkeep asks the Google Places API for seven fields and no others: the place identifier, the display name, the formatted address, the national and international phone numbers, the website address and the Google Maps link. The town and the trade on a lead are your own search terms, not something Google is asked for.
And what is not in place, because a security annex that lists only the good news is not worth reading:
- The database file is not separately encrypted at rest beyond the host's own disk encryption, and neither are the backup files.
- There is no third-party security certification, no penetration test report, and no formal incident-response retainer.
- The Service runs on a single server shared with other applications operated by the same owner; there is no high-availability setup.
- There is no 24/7 monitoring rota. Alerts reach one person.
- The restore has not been rehearsed. Backups are taken every night and we can see that the files exist and are the right size, but no scheduled drill restores one into a scratch database and confirms it opens. An untested backup is a hope rather than a control, and this is the gap on this list we would fix first. A drill is on the launch checklist.
- The nightly snapshot is currently kept on the same server as the database it was taken from. The script supports an off-site copy and it is not configured, which means a failure that destroys the disk destroys the backups with it.