Data Processing Addendum
Last Updated: 28 September 2026
Contact: info@myntriq.io
This DPA is entered into between:
- Data Processor: Myntriq Pte Ltd (UEN 202537571M), Singapore ("Myntriq")
- Data Controller: The customer organisation that has accepted MyntriqOS Terms of Service ("Customer")
Recitals
This Data Processing Addendum ("DPA") supplements the MyntriqOS Terms of Service ("Agreement") entered into between Myntriq and the Customer. It governs the processing of Personal Data by Myntriq on behalf of the Customer in connection with the MyntriqOS platform.
The parties agree that:
- The Customer is the Data Controller with respect to Personal Data processed through MyntriqOS
- Myntriq is the Data Processor acting on the Customer's behalf
- This DPA reflects the obligations of a Data Processor under Singapore's Personal Data Protection Act 2012 (PDPA) and, where applicable, the EU General Data Protection Regulation (GDPR)
1. Definitions
"Personal Data" means any information relating to an identified or identifiable natural person that the Customer provides to, or that is collected by, MyntriqOS in the course of the Customer's use of the platform.
"Processing" means any operation performed on Personal Data, including collection, storage, use, disclosure, or deletion.
"Data Subject" means any natural person whose Personal Data is processed through MyntriqOS on behalf of the Customer.
"Subprocessor" means any third-party service provider engaged by Myntriq to process Personal Data in connection with MyntriqOS.
"Security Incident" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data.
Capitalised terms not defined here have the meanings given in the Agreement.
2. Scope of Processing
2.1 Subject matter
Myntriq processes Personal Data to provide the MyntriqOS platform services to the Customer, including:
- Platform access and authentication
- AI agent operation and inference routing
- Conversation and knowledge base storage
- Governance and audit logging
- Platform analytics and support
2.2 Duration
Processing continues for the duration of the Agreement and for the period required to delete or return Personal Data following termination.
2.3 Nature and purpose
The nature and purpose of processing is to enable the Customer to operate AI agents, manage business workflows, and access business intelligence through MyntriqOS, as described in the Agreement.
2.4 Categories of Personal Data
The categories of Personal Data processed depend on what the Customer chooses to input into MyntriqOS. Common categories include:
- Contact information (names, email addresses, phone numbers) of the Customer's users and their business contacts
- Business information (company names, roles, deal information) entered through CRM, HR, and other business modules
- Content submitted in conversations and knowledge base documents
- Any other information the Customer or its users enter into the platform
2.5 Categories of Data Subjects
Data Subjects may include:
- The Customer's employees, contractors, and authorised platform users
- The Customer's business contacts, leads, customers, and partners whose information is entered into the platform
3. Myntriq's Obligations as Data Processor
3.1 Processing on documented instructions
Myntriq will process Personal Data only on the Customer's documented instructions, as set out in this DPA and the Agreement. If Myntriq is required by applicable law to process Personal Data for other purposes, Myntriq will inform the Customer before doing so (unless prohibited from doing so by law).
3.2 Confidentiality
Myntriq will ensure that all personnel authorised to process Personal Data are subject to appropriate confidentiality obligations.
3.3 Security
Myntriq will implement and maintain appropriate technical and organisational measures to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures are described in the Myntriq Security Overview, which forms part of this DPA by reference.
3.4 Subprocessors
Myntriq engages the Subprocessors listed in the current Subprocessor List to process Personal Data on its behalf. The Subprocessor List forms part of this DPA by reference and records, for every AI model provider, the jurisdiction where inference is processed, whether the provider may use customer content to train its models, and a dated retention snapshot. Myntriq will:
- Ensure that its contracts with Subprocessors impose data protection obligations no less protective than those in this DPA, with the single transitional exception disclosed in the Subprocessor List (the Moonshot AI route, for which the qualifying terms and the migration in progress are recorded there)
- Notify the Customer of any planned addition or replacement of Subprocessors at least 14 days before the change takes effect
- Remain liable to the Customer for the acts and omissions of its Subprocessors to the same extent Myntriq would be liable if performing the processing directly
The Customer consents to Myntriq's use of the Subprocessors listed in the current Subprocessor List, as updated in accordance with this clause. If the Customer objects to a new Subprocessor, the Customer must notify Myntriq in writing within 14 days of the notification. Where an objection cannot be resolved, the Customer may terminate the affected services.
3.5 Data Subject Rights
Myntriq will, to the extent technically feasible, assist the Customer in responding to requests from Data Subjects to exercise their rights under applicable data protection law, including rights of access, rectification, erasure, restriction, portability, and objection. Where Myntriq receives a request directly from a Data Subject, Myntriq will redirect the Data Subject to the Customer.
3.6 Security Assistance
Myntriq will assist the Customer in meeting its data protection obligations with respect to security, breach notification, data protection impact assessments, and prior consultation with supervisory authorities, taking into account the nature of processing and the information available to Myntriq.
3.7 Deletion or Return
Upon termination of the Agreement, or upon the Customer's written request, Myntriq will:
- Delete all Personal Data processed on behalf of the Customer within 30 days, and
- Provide written confirmation of deletion to the Customer
Where deletion is not technically feasible within this period (for example, for data included in encrypted backups), Myntriq will confirm the timeline for deletion of backup data and will not use that data for any other purpose.
The Customer may alternatively request that Myntriq return Personal Data in a portable format before deletion.
3.8 Audit Rights
Myntriq will provide the Customer with all information reasonably necessary to demonstrate compliance with this DPA. The Customer may, on 30 days' written notice and at the Customer's cost, conduct an audit of Myntriq's data processing activities, limited to information and facilities relevant to the processing of the Customer's Personal Data. Audits may be conducted no more than once per calendar year except where a Security Incident has occurred.
4. Customer's Obligations
The Customer is responsible for:
- Ensuring it has a lawful basis for processing the Personal Data it submits to MyntriqOS
- Ensuring that Data Subjects are informed of the processing of their Personal Data through MyntriqOS, as required by applicable law
- Ensuring that its use of MyntriqOS complies with applicable laws, regulations, and industry standards
- Providing accurate and complete instructions to Myntriq regarding the processing of Personal Data
- Promptly notifying Myntriq of any changes to its instructions that may affect Myntriq's ability to process Personal Data in compliance with applicable law
- Applying data minimisation when submitting Personal Data to AI agents — prompts should contain only the information necessary for the task, anonymised or pseudonymised where possible
5. Security Incident Notification
If Myntriq becomes aware of a Security Incident affecting Personal Data processed on behalf of the Customer, Myntriq will:
- Notify the Customer within 72 hours of becoming aware of the incident
- Provide the nature of the Security Incident
- Provide the categories and approximate number of Data Subjects affected
- Provide the categories and approximate volume of Personal Data affected
- Provide the likely consequences of the incident
- Provide the measures taken or proposed to address the incident
Myntriq will cooperate with the Customer in responding to the incident and in making any required notifications to supervisory authorities or Data Subjects.
6. Cross-Border Data Transfers
MyntriqOS's platform application compute and primary data store are hosted in Singapore. AI model inference requests are transferred to and processed by the Subprocessor model providers named in the Subprocessor List, in the jurisdictions disclosed there — which include the United States and, for one transitional route (Moonshot AI), mainland China. The Subprocessor List is the authoritative record of which providers process Personal Data and in which jurisdictions, and it forms part of this DPA by reference.
Where Personal Data is transferred outside Singapore, Myntriq will ensure that appropriate safeguards are in place, consistent with the transfer limitation obligation under the PDPA and, where applicable, Chapter V of the GDPR. The safeguards in place differ by provider and are recorded here accurately:
- OpenAI, Anthropic, Google, and OpenRouter — each processes inference under a data processing addendum that incorporates Standard Contractual Clauses (EU instruments) covering transfers of EU/EEA Personal Data.
- Alibaba Cloud (DashScope international) — a Data Processing Addendum is incorporated into the Alibaba Cloud Membership Agreement; Standard Contractual Clauses are available from this provider on request. Customers whose processing involves EU/EEA Personal Data should contact Myntriq so that the appropriate transfer instrument is put in place before such data is routed through this provider.
- Moonshot AI — no data processing addendum or Standard Contractual Clauses are currently published by this provider, and the transitional route described in the Subprocessor List currently operates under platform terms that permit customer content to be used for model improvement, with no opt-out. While that transitional qualifier is in effect, Myntriq limits this route to lower-sensitivity workloads, and the Customer should not submit Personal Data of EU/EEA Data Subjects to workloads routed through this provider. Myntriq is transitioning this route to Moonshot AI's international platform and a written agreement restricting content use; the limitation is removed when that written restriction is in force.
For all inference routes, Myntriq additionally relies on data minimisation: prompts should contain only the information necessary for the task, and Personal Data should be anonymised or pseudonymised where possible.
7. Term and Termination
This DPA remains in force for the duration of the Agreement and continues to apply to any Personal Data retained by Myntriq following termination until that data is deleted in accordance with Clause 3.7.
8. Governing Law
This DPA is governed by the laws of Singapore. Any disputes arising in connection with this DPA will be subject to the exclusive jurisdiction of the courts of Singapore, unless the parties agree otherwise in writing.
9. Order of Precedence
In the event of a conflict between this DPA and the Agreement, this DPA will take precedence with respect to matters relating to the processing of Personal Data.
10. Contact
For questions about this DPA or to exercise rights under it, contact:
Myntriq Pte Ltd
Data Protection
info@myntriq.io
MyntriqOS Privacy Policy
Last Updated: 28 September 2026
Applies to: MyntriqOS platform (distinct from the Myntriq website privacy policy at /legal/privacy)
Company: Myntriq Pte Ltd (UEN 202537571M), Singapore
Contact: info@myntriq.io
Introduction
This Privacy Policy describes how Myntriq Pte Ltd ("Myntriq", "we", "us", "our") collects, processes, and protects information when you or your organisation uses the MyntriqOS platform.
This policy applies to the MyntriqOS platform — the authenticated dashboard, AI agents, governance tools, and APIs available to registered customers. It is separate from the website privacy policy that applies to visitors of www.myntriq.io.
By using MyntriqOS, you accept this policy on behalf of yourself and your organisation.
1. Two Types of Data Controller
It is important to understand who controls different categories of data in MyntriqOS:
Myntriq as Data Controller — for data Myntriq collects to operate its business: account information, billing, authentication credentials, platform usage analytics, and platform communications.
Customer as Data Controller, Myntriq as Data Processor — for data the customer enters into MyntriqOS: customer content (conversations, knowledge base documents, business data, agent configurations, and any personal data of the customer's own users or third parties that the customer uploads or processes through the platform). For this data, the customer is the Data Controller and Myntriq processes it only to provide the platform services. The Data Processing Addendum governs this relationship.
2. Information Myntriq Collects
2.1 Account and Organisation Information
When a customer organisation is onboarded to MyntriqOS, Myntriq collects:
- Organisation name and unique identifier
- Administrator email address and profile information
- User email addresses and profile information for each added user
- Role assignments (admin, member, viewer)
- Organisation settings and preferences
This information is collected to create and manage the customer's platform account and is processed under Myntriq's legitimate interest in providing the contracted service.
2.2 Authentication Data
Myntriq uses a managed cloud authentication service to manage authentication. When users sign in, Myntriq collects:
- Authentication method (single sign-on via Google OAuth 2.0, Microsoft Entra ID, or SAML 2.0; or email/password)
- Session identifiers (stored as httpOnly cookies; not accessible to JavaScript)
- Sign-in timestamps and authentication history
- Device and browser information for session management
Authentication data is retained for the duration of the account plus 12 months following account termination, except where longer retention is required by law.
2.3 Platform Usage Data
Myntriq collects platform usage data to operate the service, enforce usage limits, generate billing data, and improve platform performance. This includes:
- Feature interactions (pages visited, features used, agents configured)
- AI model usage metrics: model invoked, token counts, estimated cost, outcome
- API request logs: endpoint, timestamp, response time, status code
- Error and diagnostic logs
Usage data is associated with the organisation and user identifier, not retained as individually profiled records.
2.4 Customer Content
Customer content is data that the customer and its users enter into MyntriqOS. This includes:
- Conversations: Messages and responses exchanged with AI agents
- Prompts: Instructions and context submitted to AI models
- Knowledge base documents: Files, text, and data uploaded to train or inform agents
- Business data: Data entered into business modules (CRM contacts, HR records, financial figures, campaign data) where applicable modules are in use
- Agent configurations: Instructions, personas, and workflow settings defined for AI agents
Customer content is processed by Myntriq solely to provide the platform services. Myntriq does not use customer content to train its own AI models. Myntriq does not sell, share, or use customer content for purposes outside the contracted service.
2.5 Audit Log Data
MyntriqOS maintains an audit log of all actions taken by users and agents within the platform. Audit log entries contain:
- User or agent identifier
- Timestamp
- Action type and description
- Outcome (success/failure)
- AI model used and cost (for agent actions)
Audit logs are available to organisation administrators through the Governance Dashboard. They are retained for a minimum of 24 months.
3. How Myntriq Uses Information
Myntriq uses the information described above for the following purposes:
| Purpose | Data Used | Legal Basis |
|---|
| Providing and operating MyntriqOS | Account data, authentication data, customer content, usage data | Contract performance |
| Authentication and session management | Authentication data | Contract performance |
| Billing and subscription management | Usage data, account data | Contract performance |
| Platform support and troubleshooting | Usage data, error logs, customer content (where shared with support) | Contract performance / Legitimate interest |
| Security monitoring and incident detection | Usage data, authentication data, audit logs | Legitimate interest |
| Platform improvement (aggregate/anonymised) | Anonymised usage metrics | Legitimate interest |
| Legal compliance | As required by applicable law | Legal obligation |
Myntriq does not use customer content for advertising, model training, or any purpose outside the contracted service.
4. AI Model Processing
MyntriqOS routes AI inference requests through third-party model providers. When a user or agent submits a prompt, that prompt — together with any context from the conversation history or knowledge base — is sent to the selected AI model provider for processing.
All model inference requests are routed through Myntriq's managed model routing service. Customers do not interact with model providers directly.
What model providers receive: The prompt text, system instructions, and conversation context required to generate a response. Model providers do not receive account identifiers, billing information, or other platform metadata.
Model training: Myntriq does not use customer prompts or responses to train its own AI models. The model providers named in the Subprocessor List are contractually barred from using customer content to train their models, with one named transitional exception: the Moonshot AI route currently operates under platform terms that permit customer content to be used for model improvement, with no opt-out. Myntriq is transitioning this route to Moonshot AI's international platform and a written agreement restricting content use; while that transition is in effect, Myntriq limits this route to lower-sensitivity workloads. The current training posture and a dated retention snapshot for every model provider are recorded in the Subprocessor List.
Cross-border transfers: AI inference requests are processed in the jurisdictions disclosed in the Subprocessor List — which include the United States and, transitionally, mainland China — not in any single country. Customers who submit personal data of Singapore residents or EU/EEA individuals as part of prompts should be aware of these transfers and should apply appropriate safeguards (such as pseudonymisation or data minimisation) when submitting personal data to AI agents.
5. Subprocessors
6. Data Retention
Myntriq retains platform data in accordance with the following schedule:
| Data Category | Retention Period |
|---|
| Account and organisation data | Duration of account + 12 months |
| User profiles | Duration of account + 12 months |
| Conversation history | Duration of account + 12 months |
| Knowledge base documents | Duration of account; deleted within 30 days of account termination |
| Audit logs | 24 months minimum |
| AI usage metrics | 24 months |
| Authentication session tokens | Session-scoped; cleared on sign-out |
| Error and diagnostic logs | 90 days |
Retention by third-party model providers is outside this schedule; each provider's retention posture, as reviewed on the date shown, is recorded in the Subprocessor List.
Following account termination, Myntriq will delete or anonymise customer data within 30 days, unless longer retention is required by law or by the terms of the Data Processing Addendum.
Customers may request early deletion of specific data categories by contacting info@myntriq.io.
7. Security
Myntriq implements technical and organisational security measures appropriate to the risks associated with processing customer data. These are described in detail in the Myntriq Security Overview.
Key controls include:
- AES-256 encryption at rest for all customer data in the database
- TLS encryption in transit for all connections
- Row-level security (RLS) enforcing strict tenant isolation at the database layer
- Secrets management via a managed cloud secrets service
- Role-based access control within organisations
- Immutable audit logging of all user and agent actions
In the event of a personal data breach affecting customer data, Myntriq will notify affected customers in accordance with the incident response process described in the Security Overview.
8. International Data Transfers
MyntriqOS's platform application compute and primary data store are hosted in Singapore. AI model inference requests are processed by the third-party providers named in the Subprocessor List, in the jurisdictions disclosed there — which include the United States and, for one transitional route, mainland China. Myntriq does not claim that customer data never leaves any particular country; it claims that every provider that processes it is named in the Subprocessor List, together with the jurisdiction and data handling posture that apply.
Where customer data — including personal data of Singapore residents — is transferred outside Singapore for AI model processing, Myntriq relies on:
- Contractual data protection commitments in each provider's terms or data processing addendum, as recorded per provider in the Subprocessor List and described in the Data Processing Addendum
- Data minimisation: prompts should contain only the information necessary for the task; personal data should be anonymised or pseudonymised where possible
Customers in regulated sectors or with jurisdiction-specific processing requirements should contact info@myntriq.io to discuss what the current architecture supports.
9. Customer Rights
Customers (as Data Controllers for their own data) may exercise the following rights with respect to data Myntriq holds about the customer organisation and its users:
Access — request a copy of the personal data Myntriq holds about the organisation's users.
Correction — request correction of inaccurate personal data.
Deletion — request deletion of personal data. Myntriq will comply within 30 days except where retention is required by law or legitimate business interest.
Data portability — request export of conversation history, knowledge base content, and agent configurations in a portable format (where technically feasible).
Objection — object to processing based on Myntriq's legitimate interest.
To exercise any of these rights, contact info@myntriq.io. Myntriq will respond within 30 days.
Rights of individual users within a customer organisation: individual users who wish to exercise data subject rights should contact their organisation's administrator in the first instance, as the customer is the Data Controller for user data entered into the platform.
10. Children's Data
MyntriqOS is a business platform intended for use by organisations and their employees. It is not directed at individuals under 18 years of age. Myntriq does not knowingly collect personal data from minors.
If a customer uploads or processes personal data of minors through MyntriqOS, the customer is responsible for ensuring they have the appropriate legal basis and parental or guardian consent to do so.
11. Changes to This Policy
Myntriq may update this Privacy Policy from time to time. Material changes will be communicated to customers through the platform or by email at least 14 days before taking effect, in accordance with the Trust Document Versioning Standard.
The effective date at the top of this document will reflect the date of the most recent update.
12. Contact
For privacy enquiries, data subject rights requests, or to report a data protection concern, contact:
Myntriq Pte Ltd
Data Protection
info@myntriq.io
Singapore
Myntriq's Data Protection Officer can be reached at info@myntriq.io marked "Attn: Data Protection".
Data Retention Policy
Last Updated: 28 September 2026
Company: Myntriq Pte Ltd (UEN 202537571M), Singapore
Contact: info@myntriq.io
Overview
This policy describes how long Myntriq retains different categories of data collected through the MyntriqOS platform and the Myntriq website. It should be read alongside the MyntriqOS Privacy Policy, the website Privacy Policy, and the Data Processing Addendum.
Data is retained for as long as necessary to provide the contracted services, to meet legal and regulatory obligations, and to resolve disputes. When the retention period expires, data is deleted or anonymised in accordance with the schedule below.
Retention Schedule
Platform Data (MyntriqOS)
| Data Category | Retention Period | Deletion Method | Notes |
|---|
| Organisation account data | Duration of account + 12 months | Permanent deletion | Deleted within 30 days of account termination request |
| User profiles and accounts | Duration of account + 12 months | Permanent deletion | Includes name, email, role, and authentication identifiers |
| Conversation history | Duration of account + 12 months | Permanent deletion | All messages and agent responses |
| AI agent prompts | Duration of account + 12 months | Permanent deletion | Included in conversation history |
| Knowledge base documents (uploaded files) | Duration of account | Permanent deletion | Deleted within 30 days of account termination |
| Knowledge base metadata | Duration of account + 12 months | Permanent deletion | Includes document titles, tags, and index references |
| Agent configurations | Duration of account + 12 months | Permanent deletion | Includes agent instructions, personas, and workflow settings |
| Business module data (CRM, HR, Finance, etc.) | Duration of account + 12 months | Permanent deletion | Data entered by the customer into business modules |
| Audit logs | 24 months minimum | Permanent deletion after retention period | Required for governance and compliance evidence |
| AI usage metrics | 24 months | Permanent deletion after retention period | Used for billing, cost visibility, and governance reporting |
| Authentication session tokens | Session-scoped | Cleared on sign-out | No persistent storage beyond the active session |
| Authentication history | 12 months | Permanent deletion | Sign-in timestamps and authentication events |
| Error and diagnostic logs | 90 days | Permanent deletion | Application-level error and debugging logs |
| API request logs | 90 days | Permanent deletion | Endpoint, timestamp, response code; no payload content |
Website Data (www.myntriq.io)
| Data Category | Retention Period | Deletion Method | Notes |
|---|
| Contact form submissions | 24 months | Permanent deletion or anonymisation | Includes name, email, company, message content |
| Demo request submissions | 24 months | Permanent deletion or anonymisation | Includes name, email, company, interest area |
| Email delivery logs (Resend) | Per Resend's retention schedule | Subject to Resend's data handling terms | Standard transactional email logs |
| Analytics data (if implemented) | 24 months | Aggregated or deleted | If analytics tools are implemented |
Provider-Side Retention (AI Model Subprocessors)
This policy governs data held by Myntriq. Prompts, outputs, and audio sent to third-party AI model providers for inference are additionally subject to those providers' own retention policies, which sit outside this schedule. The current retention posture of each model subprocessor — including how long prompts and completions are kept and for what purpose — is recorded, with dated review snapshots, in the Myntriq Subprocessor List. The clause-level evidence is maintained in `docs/trust/MODEL_PROVIDER_DATA_POLICY_REVIEW_2026-09.md`.
Early Deletion
Customers may request early deletion of their organisation's data at any time by contacting info@myntriq.io. Myntriq will:
- Confirm receipt of the request within 2 business days
- Complete deletion of the requested data within 30 days
- Provide written confirmation of deletion
Early deletion requests apply to data in active storage. Data that has been included in encrypted database backups will be excluded from those backups as they are cycled within the normal backup retention window (typically within 30 days).
Myntriq will not retain data beyond the end of the retention period for any purpose other than compliance with a legal obligation, defence of a legal claim, or resolution of a regulatory matter.
Deletion on Account Termination
When a customer's account is terminated — whether initiated by the customer or by Myntriq — the following applies:
1. Active data (database records, uploaded files, agent configurations, conversation history) will be deleted within 30 days of termination
2. Audit logs and usage metrics will be retained for the full 24-month retention period from the date each record was created, and then deleted
3. Backup data will be excluded from backups as the backup rotation schedule progresses
Customers who wish to export their data before account termination may request a data export by contacting info@myntriq.io. Exports are provided in a portable format where technically feasible.
Backups
Myntriq uses automated database backup services provided by the managed cloud database service. Backup retention is managed by the backup configuration and is typically 30 days for point-in-time recovery.
Backup data is encrypted and subject to the same access controls as live data. Backups are not used as an alternative data source once active data has been deleted — when deletion of a customer's data is requested, the data will be excluded from future backups as the rotation schedule progresses.
Legal Holds
If Myntriq is required to preserve data beyond its normal retention period in connection with a legal proceeding, regulatory investigation, or court order, Myntriq will apply a legal hold to the relevant data. A legal hold suspends the normal deletion schedule for the affected data only and is removed when the legal or regulatory matter concludes.
Customers whose data is subject to a legal hold will be notified where Myntriq is permitted to do so.
Review
This policy is reviewed annually and updated to reflect changes in data handling practices, regulatory requirements, or Myntriq's platform capabilities.
For questions about data retention or to submit a deletion request, contact info@myntriq.io.
Myntriq Subprocessor List
Last Updated: 28 September 2026
Contact: info@myntriq.io
Overview
Myntriq uses the following third-party service providers (subprocessors) to deliver MyntriqOS. Each subprocessor has been selected based on its security standards, data handling practices, and its ability to support Myntriq's obligations to customers under Singapore's Personal Data Protection Act 2012 (PDPA) and, where applicable, the EU General Data Protection Regulation (GDPR).
This list is the authoritative, versioned register of subprocessors. For every AI model provider it records the jurisdiction where inference is processed, whether the provider may use customer data to train its models, and the provider's retention posture as reviewed on the date shown — provider policies change, and the review date is part of the record. The clause-level evidence behind the AI model entries is maintained in the repository (`docs/trust/MODEL_PROVIDER_DATA_POLICY_REVIEW_2026-09.md`).
This list is maintained as a live page and is updated when subprocessors are added, removed, or change their data handling arrangements. Customers subscribed to the Data Processing Addendum (DPA) will be notified of material changes to this list with at least 14 days' notice before the change takes effect.
A note on geography. MyntriqOS's application compute and primary data store are hosted in Singapore. Model inference is processed by the third-party providers named below, in the jurisdictions disclosed below — which include the United States and, for one transitional route, mainland China. Myntriq does not claim that customer data never leaves any particular country; we claim that every provider that touches it is named here, contractually barred from training on it (with one named transitional exception), and accountable to the retention posture recorded here.
Infrastructure Subprocessors
Google Cloud Platform
| Field | Detail |
|---|
| Purpose | Cloud compute (Cloud Run), secrets management (Secret Manager), container registry (Artifact Registry), and supporting infrastructure |
| Data categories | Application code and container images; encrypted runtime secrets; application logs; system configuration |
| Processing location | Singapore (`asia-southeast1`) |
| Parent company | Google LLC, United States |
| DPA available | Yes — Google Cloud Data Processing Addendum |
| Security certifications | ISO/IEC 27001, ISO/IEC 27017, ISO/IEC 27018, SOC 1, SOC 2, SOC 3 |
| Notes | Primary compute and infrastructure provider. Google Cloud does not access customer data except as required to deliver contracted services. Distinct from Google's AI inference service, listed separately below. |
Supabase
| Field | Detail |
|---|
| Purpose | Database (PostgreSQL), authentication, file storage, and row-level security enforcement |
| Data categories | Customer organisation data; user accounts and profiles; conversation history; agent configurations; knowledge base metadata; uploaded document references; audit logs; AI usage metrics |
| Processing location | Singapore (`ap-southeast-1`) |
| Parent company | Supabase Inc., United States |
| DPA available | Yes — available from Supabase on request |
| Security certifications | SOC 2 Type II |
| Notes | Supabase is the primary data store for MyntriqOS. Row-level security policies enforce strict tenant isolation — one customer's data cannot be accessed by another. Supabase does not use customer data for any purpose other than providing the database service. |
AI Model Subprocessors
Every provider in this section processes customer content (prompts, documents, conversation messages, and where noted, audio) to produce model output. Two facts are recorded per provider: whether it may use that content to train its models, and how long it retains it — reviewed 27 September 2026 against each provider's own current terms.
OpenAI
| Field | Detail |
|---|
| Purpose | AI model inference (`gpt-4o`, `gpt-4o-mini`, `gpt-5.6-terra`) and audio transcription (`whisper-1`) |
| Data categories | Prompts and conversation messages; knowledge base query text; audio recordings submitted for transcription (meetings) |
| Processing location | Global (OpenAI does not commit to a processing location on the standard API; storage-only residency in some regions on request) |
| Parent company | OpenAI OpCo, LLC, United States |
| DPA available | Yes — OpenAI Data Processing Addendum |
| Training | No. Contractual — OpenAI does not use API customer content to develop or improve its models (Services Agreement §4.2, effective 1 January 2026; policy unchanged since 1 March 2023) |
| Retention (reviewed 27 Sep 2026) | Chat endpoints: prompts and completions retained up to 30 days for abuse monitoring, with possible human review. `whisper-1` transcription: no retention. Zero-data-retention arrangements exist but require OpenAI approval. |
Anthropic
| Field | Detail |
|---|
| Purpose | AI model inference (`claude-opus-4-8`, `claude-sonnet-4-6`, `claude-sonnet-5`, `claude-opus-5`, `claude-fable-5`) |
| Data categories | Prompts and conversation messages; knowledge base query text |
| Processing location | United States or global (Anthropic offers "global" or US-only inference; no Singapore/Asia-Pacific option exists) |
| Parent company | Anthropic, PBC, United States |
| DPA available | Yes — Anthropic Data Processing Addendum, incorporated into its Commercial Terms |
| Training | No. Contractual — Anthropic may not train models on customer content from its commercial services (Commercial Terms §B) |
| Retention (reviewed 27 Sep 2026) | Default: inputs/outputs deleted within 30 days. Content flagged by automated trust-and-safety systems may be retained up to 2 years (this carve-out applies even under zero-retention arrangements). `claude-fable-5` is a designated Covered Model: 30-day retention is mandatory on every platform, effective 9 June 2026. |
Google (Gemini API)
| Field | Detail |
|---|
| Purpose | AI model inference (`gemini-3.7-flash`) |
| Data categories | Prompts and conversation messages; knowledge base query text |
| Processing location | Global — Google's terms permit processing in any country where Google or its agents maintain facilities; no residency commitment exists on this API |
| Parent company | Google LLC, United States |
| DPA available | Yes — Google Cloud Data Processing Addendum applies to paid-tier API use |
| Training | No, on the paid tier — Google does not use paid-tier API prompts or responses to improve its products. (Google's free tier does use submitted content; Myntriq's access is via a billed Cloud project.) |
| Retention (reviewed 27 Sep 2026) | Prompts and responses logged for up to 55 days for abuse prevention, with possible human review. Zero-data-retention is not offered on this API (Google directs that requirement to its Vertex AI platform). |
Alibaba Cloud (DashScope / Model Studio, international)
| Field | Detail |
|---|
| Purpose | AI model inference (`qwen3.8`, `qwen3.8-instant`) via the international endpoint `dashscope-intl.aliyuncs.com` |
| Data categories | Prompts and conversation messages; knowledge base query text |
| Processing location | Singapore region service operated by Alibaba Cloud's international entity; the provider's terms permit processing in countries where Alibaba Cloud, its affiliates, or subcontractors maintain facilities |
| Contracting entity | Alibaba Cloud (Singapore) Private Limited — Singapore law |
| DPA available | Yes — a Data Processing Addendum is incorporated into the Alibaba Cloud Membership Agreement |
| Training | No. Contractual — Alibaba Cloud does not use customer content to develop or improve Model Studio models unless the customer separately consents (Product Terms §4.48.1(e), v3.8.0, 28 August 2026) |
| Retention (reviewed 27 Sep 2026) | Model Studio states that it stores data generated from model calls; no retention period is published. Zero-data-retention is not offered on public terms. |
| Notes | Myntriq has no arrangement with, and sends no traffic to, Alibaba Cloud's mainland-China platform. A planned migration to self-hosted Qwen models on Myntriq infrastructure will remove this route from the data path (see Changes to This List). |
Moonshot AI (Kimi)
| Field | Detail |
|---|
| Purpose | AI model inference (`kimi-k3`) |
| Data categories | Prompts and conversation messages; knowledge base query text |
| Processing location | Mainland China — current route uses the `api.moonshot.cn` platform operated by Beijing Moonshot AI Co., Ltd. |
| Contracting entity | Beijing Moonshot AI Co., Ltd. — PRC law (transition to the Singapore entity in progress, below) |
| DPA available | None published |
| Training — transitional qualifier (27 September 2026) | Yes — currently permitted. The platform terms under which this route operates today permit customer content to be used for model improvement, with no opt-out. Myntriq is transitioning this route to Moonshot AI's international platform (Moonshot AI PTE. LTD., Singapore) and a written agreement restricting content use. This qualifier will be removed when that written restriction is in force. While it is in effect, Myntriq limits this route to lower-sensitivity workloads. |
| Retention (reviewed 27 Sep 2026) | No retention schedule is published; the provider's terms require certain records to be retained under Chinese cybersecurity law. |
OpenRouter
| Field | Detail |
|---|
| Purpose | AI model inference routing for `qwen3.7-plus`, `glm-5.2` (Zhipu), and `llama3.3` / `llama3.2` (Meta) |
| Data categories | Prompts and conversation messages; knowledge base query text |
| Processing location | United States (Google Cloud); no Singapore routing option exists |
| Parent company | OpenRouter Inc., United States |
| DPA available | Yes — OpenRouter Data Processing Agreement (26 August 2026) |
| Training | No, by OpenRouter — OpenRouter does not use inputs or outputs for model training. Downstream model providers are selected with training-permitted providers excluded and zero-retention endpoints preferred; the effective provider chain is disclosed in the Model Governance Policy. |
| Retention (reviewed 27 Sep 2026) | Prompts and completions are not stored by default; request metadata (token counts, latency, model, cost) is retained. |
First-party inference (not a subprocessor)
Myntriq's embedding model (`bge-m3`) runs on Myntriq's own infrastructure inside its own Google Cloud project. No customer data leaves Myntriq's environment for embedding workloads, and no third party processes it. Self-hosted Qwen inference is planned on the same pattern; when it enters service, the corresponding hosted route (Alibaba Cloud, above) will be removed from this list.
Communication Subprocessors
Resend
| Field | Detail |
|---|
| Purpose | Transactional email delivery (contact form notifications, demo request notifications) |
| Data categories | Name, email address, company name, and message content submitted through contact and demo request forms on the Myntriq website |
| Processing location | United States |
| Parent company | Resend Inc., United States |
| DPA available | Contact Resend directly for DPA terms |
| Notes | Resend is used solely for delivering form submission notifications to Myntriq's internal team. Form data is not stored by Resend beyond standard email delivery logs. |
Meta (WhatsApp Cloud API)
| Field | Detail |
|---|
| Purpose | WhatsApp Business messaging channel — live in production for agent communication |
| Data categories | Message content and sender/recipient identifiers (phone numbers, display names) passed through the WhatsApp channel |
| Processing location | United States and Meta's global infrastructure, per Meta's data terms |
| Parent company | Meta Platforms, Inc., United States |
| DPA available | Meta's Data Processing Terms apply to WhatsApp Business Platform use |
| Notes | Active since the WhatsApp Cloud channel launched. Message content transits Meta's platform as the channel operator; Myntriq does not use Twilio or Infobip for WhatsApp. |
Changes to This List
Myntriq will update this page when subprocessors are added, removed, or materially change their data handling arrangements.
Customers operating under a signed Data Processing Addendum are entitled to object to the addition of a new subprocessor within 14 days of notice. If a customer objects and Myntriq cannot reasonably accommodate the objection, the customer may terminate the affected services.
Known upcoming changes, recorded here as they complete:
- Moonshot AI route transition — move from `api.moonshot.cn` to Moonshot AI's international (Singapore-entity) platform with a written restriction on content use; the transitional qualifier above is removed when that restriction is in force.
- Self-hosted Qwen — Qwen inference moves onto Myntriq's own infrastructure; the hosted Alibaba Cloud route is then removed from this list, after which Qwen workloads leave Myntriq's environment for no third party.
To be notified of changes to this list, or to request a copy of a subprocessor's DPA, contact info@myntriq.io.
Myntriq Security Overview
Last Updated: 28 September 2026
Contact: security-office@myntriq.io
Company: Myntriq Pte Ltd (UEN 202537571M), Singapore
Our Approach
Security at Myntriq is not an afterthought. It is a constraint that shapes every architecture decision — from how we isolate customer data to how we manage AI model access to how we deploy code.
This document describes the technical and organisational controls Myntriq has in place. We write it for the buyers, security reviewers, and procurement teams who need an honest account of how we operate — not a marketing document.
Infrastructure Security
Cloud Provider
MyntriqOS platform infrastructure — application compute and the primary data store — is hosted on cloud infrastructure certified to ISO/IEC 27001 and SOC 2. As a matter of security policy, Myntriq does not name its infrastructure provider, cloud services, or region topology in public-facing documents. The Subprocessor List is the authoritative, named register of the subprocessors that deliver the service.
AI model inference is a separate data path. Inference requests leave the platform and are processed by the third-party model providers named in the Subprocessor List, in the jurisdictions disclosed there — which include the United States and, for one transitional route, mainland China. The Data Locations and Jurisdictions section below explains this split, and the Subprocessor List is the authoritative annex for it.
We do not operate physical servers. All infrastructure is managed cloud-native.
Compute
Application workloads run on serverless, fully containerised cloud compute. There are no persistent virtual machines. Each request is handled by an ephemeral container instance that is created on demand and destroyed when idle. This architecture eliminates entire categories of infrastructure vulnerability (unpatched VMs, stale base images left running, persistent SSH access).
Container images are stored in a private container registry. No image is publicly accessible.
Database
Customer data is stored in a managed cloud database, hosted in Singapore. All data is encrypted at rest using AES-256 and encrypted in transit using TLS 1.2 minimum.
The database layer is hosted on infrastructure certified to SOC 2 Type II.
Secrets Management
All application secrets — database credentials, API keys, service-role keys — are stored in a managed cloud secrets service. They are never committed to source code, never logged, and never passed as plaintext environment variables in container build arguments.
Secrets are mounted to application services at runtime and are not visible in build artefacts.
Transport Security
All connections to MyntriqOS — from users' browsers to the application, from the application to the database, from the application to AI model providers — are encrypted in transit using TLS. The minimum supported TLS version is 1.2.
Application Security
Tenant Isolation
MyntriqOS is a multi-tenant platform. Each customer (tenant) is assigned a unique organisation identifier at onboarding. Row-level security (RLS) policies are enforced at the database layer, ensuring that all queries — including those issued by the application server — are scoped to the authenticated user's organisation.
A tenant cannot access another tenant's data, even if they share the same database instance. This is enforced by the database engine, not just the application layer — removing the risk that an application bug could accidentally expose cross-tenant data.
Authentication
User authentication is provided by the platform's managed cloud authentication service, which supports:
- Single sign-on via Google OAuth 2.0, Microsoft Entra ID, or SAML 2.0 — the sign-in methods for production environments
- Email and password — available for environments where SSO is not configured
Session tokens are stored as httpOnly cookies — they are not accessible to JavaScript and are therefore not vulnerable to XSS-based session theft. Sessions expire on sign-out and have a configurable idle timeout.
Role-Based Access Control (RBAC)
Within each organisation, users are assigned one of three roles:
| Role | Permissions |
|---|
| Admin | Full access to all features, settings, user management, and governance controls |
| Member | Access to assigned modules and conversations; cannot manage users or settings |
| Viewer | Read-only access to dashboards and reports; cannot interact with agents or access sensitive data |
Role assignments are managed by organisation administrators. Role changes take effect immediately.
Audit Logging
Every action taken in MyntriqOS is recorded in an immutable audit log:
- User authentication events (sign-in, sign-out, failed attempts)
- Agent actions (model invocations, outputs, approvals, rejections)
- Administrative actions (user management, settings changes, agent configuration)
- AI usage metrics (model used, token count, estimated cost, outcome)
Audit logs are available to organisation administrators through the Governance Dashboard. They are retained for a minimum of 24 months in accordance with the Data Retention Policy.
Input Validation and Output Handling
All user-facing inputs are validated server-side. The API layer validates type, length, and format before processing. Inputs are never interpolated into SQL queries without parameterisation.
AI model outputs are treated as untrusted content and are rendered in controlled UI contexts that prevent execution of injected scripts.
AI Model Security
Model Routing
All AI inference in MyntriqOS is routed through Myntriq's managed model routing service — a proxy layer that sits between the MyntriqOS application and the third-party model providers named in the Subprocessor List (Anthropic, OpenAI, Google, Alibaba Cloud, Moonshot AI, and OpenRouter). One model — the bge-m3 embedding model — runs on Myntriq's own infrastructure and involves no third-party processing.
Customers do not interact directly with model provider APIs. Model provider API keys are held exclusively by Myntriq and are stored in the managed cloud secrets service. They are never exposed to customers or users.
The model routing service enforces authentication: only authenticated MyntriqOS application services can submit inference requests.
The full model slate, per-provider routing details, and the controls over which models are available to each organisation are described in the Model Governance Policy.
Training Data
Myntriq does not use customer conversation data, prompts, or uploaded documents to train its own AI models.
With one transitional exception, the third-party model providers named in the Subprocessor List do not use data submitted through MyntriqOS to train their models, under the terms of their commercial API agreements as reviewed on 27 September 2026. The exception is the Moonshot AI route (kimi-k3): the platform terms under which this route operates today permit customer content to be used for model improvement, with no opt-out. Myntriq is transitioning this route to Moonshot AI's international platform (Moonshot AI PTE. LTD., Singapore) under a written agreement restricting content use; this qualifier will be removed when that written restriction is in force. While it is in effect, Myntriq limits this route to lower-sensitivity workloads.
Per-provider training postures and dated retention snapshots are recorded in the Subprocessor List. Customers may select specific models for specific agents where that option is available. The choice of model affects which third-party provider's infrastructure processes the associated prompts.
Data Protection
Data at Rest
All customer data stored in the platform database is encrypted at rest using AES-256.
Data in Transit
All data in transit is encrypted using TLS. This applies to all connections: user browser to application, application to database, application to AI model providers, and all internal service-to-service calls.
Data Locations and Jurisdictions
Platform application compute and the primary data store are hosted in Singapore.
AI model inference is processed by the third-party providers named in the Subprocessor List, in the jurisdictions disclosed there. Those jurisdictions include the United States and, for one transitional route (Moonshot AI, kimi-k3), mainland China; some providers do not commit to a processing location at all. The Subprocessor List records, for each provider, the processing location, the contracting entity and governing law, whether customer content may be used for training, and a retention snapshot as reviewed on 27 September 2026.
Myntriq does not claim that customer data never leaves any particular country. Customers submitting personal data of Singapore residents or EU/EEA individuals as part of AI prompts should review the Subprocessor List and can restrict which models are available to their organisation through the model permissions described in the Model Governance Policy.
Vulnerability Management
Myntriq follows a structured approach to identifying and addressing security vulnerabilities:
- Dependency updates: Application dependencies are monitored for known vulnerabilities. Critical vulnerabilities are patched within 48 hours. High-severity vulnerabilities are addressed within 7 days.
- Container base images: Production container images are rebuilt regularly to pick up base image security patches.
- Code review: All changes to production systems go through peer review before deployment. Security-relevant changes (authentication, data access, API routes) receive additional scrutiny.
- Access controls: Access to production infrastructure is restricted to authorised personnel. Production access is audited.
Myntriq does not currently operate a public bug bounty programme. To report a suspected security vulnerability, email security-office@myntriq.io with the subject line "Security Vulnerability Report". We will acknowledge receipt within 24 hours and aim to respond with an initial assessment within 72 hours.
Backup and Recovery
Database Backups
Automated database backups are performed by the managed database service. Backup frequency and retention are determined by the service plan tier. Point-in-time recovery (PITR) is available.
Recovery Objective
Myntriq targets the following recovery objectives, subject to infrastructure provider capabilities:
- Recovery Point Objective (RPO): 24 hours (last successful backup)
- Recovery Time Objective (RTO): 4 hours for critical platform services
These are targets, not guaranteed SLAs, and are subject to the nature and severity of any incident.
Incident Response
Myntriq maintains an incident response process for security incidents including data breaches, service disruptions, and unauthorised access.
Breach notification timeline:
In the event of a personal data breach affecting customer data, Myntriq will:
- Notify affected customers within 72 hours of becoming aware that a breach has occurred, where it is feasible to do so
- Notify the Personal Data Protection Commission (PDPC) within the timeframe required under Singapore's mandatory breach notification rules — 3 calendar days for significant breaches (defined as those that affect 500 or more individuals, or that involve sensitive personal data)
- Provide a written incident report describing the nature of the breach, the data categories and approximate volume affected, the likely consequences, and the measures taken or proposed to address it
To report a suspected incident or security concern, contact security-office@myntriq.io.
Certifications and Compliance
Current status (28 September 2026):
Myntriq is an early-stage company. We do not currently hold third-party security certifications such as SOC 2 Type II or ISO/IEC 27001 in our own name. We rely on the certifications of our infrastructure providers — cloud infrastructure certified to ISO/IEC 27001 and SOC 2, with the database layer certified to SOC 2 Type II — for the underlying infrastructure layer. Customers in regulated sectors who require a SOC 2 report before procurement should contact security-office@myntriq.io to discuss their requirements.
Singapore PDPA:
Myntriq's data handling practices are designed to be consistent with Singapore's Personal Data Protection Act 2012 (PDPA) and its associated guidelines. Our Privacy Policy, Data Processing Addendum, and Data Retention Policy describe how we collect, use, and protect personal data.
Contact
For security enquiries, vulnerability reports, or questions about Myntriq's security posture, contact security-office@myntriq.io.
For data protection enquiries, contact our Data Protection Officer at info@myntriq.io, marked "Attn: Data Protection".
Cookie Policy
Last Updated: 28 September 2026
Company: Myntriq Pte Ltd (UEN 202537571M), Singapore
Contact: info@myntriq.io
What Are Cookies?
Cookies are small text files placed on your device when you visit a website or use a web application. They are widely used to make websites and applications function, to remember your preferences, and — in some implementations — to track behaviour across sessions for analytics or advertising purposes.
How Myntriq Uses Cookies
Myntriq uses a limited set of cookies. We do not use cookies for advertising, cross-site tracking, or third-party profiling.
Essential Cookies
These cookies are required for the MyntriqOS platform to function. They cannot be disabled.
| Cookie | Purpose | Duration |
|---|
| `sb-[ref]-auth-token` | Authentication session token. Stores your encrypted session so you remain logged in while using MyntriqOS. | Session (cleared on sign-out) |
| `sb-[ref]-auth-token.0` / `.1` | Session token chunks (used when the token exceeds single-cookie size limits). | Session (cleared on sign-out) |
These cookies contain no personally identifiable information in their readable form. They store an encrypted session reference that Myntriq's servers use to verify your identity on each request. They are httpOnly cookies — they cannot be accessed by browser JavaScript, which prevents them from being stolen by cross-site scripting attacks.
Functional Cookies
Functional cookies store preferences that improve your experience but are not strictly necessary for the platform to operate.
| Cookie | Purpose | Duration |
|---|
| Preference cookies (if implemented) | May store UI preferences such as sidebar state, selected themes, or language settings. | 1 year or until cleared |
*Note: Functional cookies will be listed here as they are implemented. If this table has no entries, no functional cookies are currently in use.*
Analytics Cookies
Myntriq does not currently use analytics cookies on `www.myntriq.io` or within the MyntriqOS platform. If analytics tools are introduced in the future, this policy will be updated and, where required by applicable law, consent will be obtained before analytics cookies are set.
Cookies Set by Third Parties
MyntriqOS does not load third-party advertising networks, social media widgets, or third-party analytics scripts that would set their own cookies in your browser.
When you use AI agents within MyntriqOS, your prompts — and, for meeting transcription, audio — are transmitted server-side to the AI model providers named in the Myntriq Subprocessor List (OpenAI, Anthropic, Google, Alibaba Cloud, Moonshot AI, and OpenRouter) via Myntriq's server-side model routing service. These transmissions occur server-to-server and do not result in cookies being set in your browser by those providers.
Your Cookie Choices
Essential cookies
Essential cookies cannot be disabled without preventing the MyntriqOS platform from functioning. If you do not wish to use essential cookies, you should not use MyntriqOS.
Browser controls
You can control and delete cookies through your browser settings. The following links explain how to manage cookies in the most common browsers:
- Google Chrome: Settings → Privacy and security → Cookies and other site data
- Safari: Preferences → Privacy → Manage Website Data
- Mozilla Firefox: Settings → Privacy & Security → Cookies and Site Data
- Microsoft Edge: Settings → Cookies and site permissions → Cookies and site data
Clearing authentication cookies will sign you out of MyntriqOS. You will need to sign in again on your next visit.
Do Not Track
Some browsers can send a "Do Not Track" signal. MyntriqOS does not currently respond to Do Not Track signals because we do not perform the type of cross-site tracking that this signal is designed to prevent.
Contact
For questions about our use of cookies, contact info@myntriq.io.
Myntriq AI Usage Policy
Last Updated: 28 September 2026
Contact: info@myntriq.io
Applies to: MyntriqOS platform and all services delivered under it
Company: Myntriq Pte Ltd (UEN 202537571M), Singapore
1. Purpose
This AI Usage Policy describes how MyntriqOS uses artificial intelligence and automated agents on behalf of customers, what obligations customers have when deploying AI agents through the platform, and the limitations that apply to AI-generated outputs.
This policy is part of Myntriq's commitment to Trusted AI Adoption — the principle that AI should be transparent, accountable, and in the control of the business owner who is responsible for the outcomes it produces.
By using MyntriqOS, customers accept the terms of this policy. This policy should be read alongside the MyntriqOS Terms of Service, Privacy Policy, and Data Processing Addendum.
2. How MyntriqOS Uses AI
MyntriqOS uses large language models (LLMs) and AI agents to provide its platform capabilities. These include:
- Digital Workforce agents — AI agents that perform business functions such as lead qualification, content drafting, query handling, financial summarisation, HR task routing, and operational workflow management on behalf of the customer
- Executive Intelligence — an AI capability that synthesises information from across business functions and responds to natural language questions about business performance
- Knowledge retrieval — AI-assisted search and retrieval across the customer's uploaded documents and business knowledge base
- Workflow orchestration — AI-assisted routing, escalation, and task management across connected business functions
MyntriqOS routes AI inference requests through a multi-model infrastructure that includes commercial AI providers and open-weight models. The providers in use, the jurisdictions in which they process inference, and their data handling postures are recorded in the Subprocessor List; how models are evaluated and admitted to the platform is described in the Model Governance Policy. Customers may configure model preferences where that option is provided.
3. Human Oversight
MyntriqOS is designed with human oversight as the default operating principle.
Autonomy levels
Every AI agent in MyntriqOS operates at an autonomy level set by the customer's administrator:
| Level | Behaviour |
|---|
| Level 1 — Draft | Agent produces output for human review. No external action is taken without explicit human approval. |
| Level 2 — Approve | Agent queues actions for approval before execution. Actions are held until an authorised user approves or rejects them. |
| Level 3 — Act and Notify | Agent acts and simultaneously notifies the relevant user. The action has occurred; the notification provides awareness and the opportunity to reverse where supported. |
| Level 4 — Autonomous | Agent acts without notification for defined low-stakes task categories. Restricted to task types explicitly configured by the administrator. |
The default autonomy level for all agents at deployment is Level 2 (Approve). Administrators may increase the autonomy level for specific agents and task types after reviewing agent behaviour and establishing confidence in its performance.
Myntriq recommends that customers begin at Level 1 or Level 2 and increase autonomy incrementally based on demonstrated agent accuracy.
Approval queue
Actions awaiting approval are held in the Governance Dashboard approval queue. Administrators and authorised users can review, approve, reject, or modify queued actions before they are executed.
Audit log
Every action taken by every agent — regardless of autonomy level — is recorded in the audit log with the agent identifier, timestamp, action type, outcome, and associated cost. The audit log is available to administrators through the Governance Dashboard and is retained in accordance with the Data Retention Policy.
4. Limitations of AI-Generated Outputs
Customers must understand and accept that AI-generated outputs are subject to the following limitations:
Accuracy — AI models may produce outputs that are factually incorrect, incomplete, out of date, or based on incorrect assumptions. Outputs should not be treated as authoritative without human review.
Consistency — AI models may produce different outputs for similar inputs. Outputs may vary based on model version, context window, and underlying model behaviour. Myntriq does not guarantee consistency of output across sessions or time periods.
Context — AI agents can only work with the information they have access to. If relevant information has not been uploaded to the knowledge base, provided in the conversation, or stored in the business data layer, the agent will not have access to it. Agents do not have access to information outside the MyntriqOS platform.
Hallucination — AI models may generate plausible-sounding but incorrect information, including fabricated facts, invented references, or inaccurate summaries. All AI-generated content that will be used in customer communications, financial decisions, legal processes, or regulated activities must be reviewed by a human before use.
Bias — AI models reflect patterns in their training data, which may include biases that affect outputs in ways that are not always visible. Customers should be aware of this risk, particularly when using AI outputs in HR, marketing, or customer-facing contexts.
5. Customer Responsibilities
Customers are responsible for:
Reviewing AI outputs before acting on them. Particularly for customer communications, financial decisions, legal documents, compliance-related content, or any output that will be acted on by the business or shared externally.
Configuring autonomy levels appropriately. Customers determine the autonomy level at which each agent operates. Myntriq provides default settings, but the customer's administrator is responsible for reviewing and configuring those settings to reflect the customer's risk appetite and governance requirements.
Maintaining the knowledge base. AI agent quality depends on the quality of the information provided. Customers are responsible for ensuring their knowledge base is accurate, current, and relevant to the tasks agents are expected to perform.
Training users. Customers are responsible for ensuring that users who interact with AI agents understand the limitations of AI-generated outputs and are equipped to review and override agent recommendations where appropriate.
Compliance with applicable law. Customers are responsible for ensuring that their use of MyntriqOS complies with all applicable laws, regulations, and industry standards in their jurisdiction. Myntriq provides a platform — compliance responsibility remains with the customer.
6. Prohibited Uses
The following uses of MyntriqOS are not permitted under any circumstances:
Generating harmful content — using MyntriqOS to generate content that is defamatory, discriminatory, threatening, harassing, fraudulent, deceptive, or that incites violence or illegal activity.
Disinformation and synthetic identity — generating false information designed to deceive, manipulate public opinion, impersonate individuals or organisations, or create synthetic identity documents.
Circumventing human oversight in high-stakes decisions — using MyntriqOS to make autonomous decisions in contexts where human review is required by law or regulation, including credit decisions, employment decisions, medical diagnoses, legal proceedings, and similar high-stakes determinations.
Processing personal data of children without appropriate consent — using MyntriqOS to collect, store, or process personal data of individuals under 18 years of age without appropriate legal basis and parental or guardian consent where required.
Extracting model internals — attempting to extract training data, model weights, system prompts, or internal configurations from AI models through MyntriqOS, or using the platform to probe, reverse-engineer, or circumvent the safety measures of underlying AI models.
Surveillance without consent — using MyntriqOS to monitor, profile, or collect data about individuals without their knowledge or consent.
Automated harm — deploying agents to generate spam, conduct phishing campaigns, distribute malware, or conduct any automated activity designed to cause harm to individuals, organisations, or infrastructure.
Violating third-party rights — generating content that infringes intellectual property rights, uses third-party trademarks without authorisation, or violates the privacy rights of individuals.
Violation of this section may result in immediate suspension of service, termination of the customer's agreement, and referral to relevant authorities where required by law.
7. High-Risk Use Cases
Certain use cases require additional care and explicit human review regardless of the autonomy level configured:
- Any AI output used in a legal document, contract, or regulatory submission
- Any AI output used to make or support a decision that materially affects an individual's employment, compensation, or terms of engagement
- Any AI output used in communications with regulators, auditors, or government authorities
- Any AI output used in medical, clinical, or patient-care contexts
- Any AI output used in financial advice or investment recommendations
- Any AI output used as evidence in a legal or arbitration proceeding
In all high-risk use cases, a human must review and explicitly take responsibility for the output before it is acted upon. The MyntriqOS audit log should be retained as evidence of review.
8. Regulatory Responsibility
MyntriqOS is a platform. Customers are responsible for ensuring their use of the platform complies with all applicable regulations in their jurisdiction and industry.
This includes but is not limited to:
- Singapore's Personal Data Protection Act 2012 (PDPA) and its associated guidelines
- Singapore's Monetary Authority of Singapore (MAS) guidelines on technology risk management, where applicable
- EU General Data Protection Regulation (GDPR), where the customer processes personal data of EU/EEA individuals
- Industry-specific regulations applicable to healthcare, financial services, legal services, and other regulated sectors
Myntriq does not provide legal, compliance, or regulatory advice. Customers operating in regulated industries should seek independent advice on their obligations before deploying AI agents in regulated workflows.
9. Third-Party AI Models
MyntriqOS routes AI inference through the third-party model providers named in the Subprocessor List: OpenAI, Anthropic, Google, Alibaba Cloud (DashScope international), Moonshot AI (Kimi), and OpenRouter. Each provider processes inference in the jurisdictions disclosed in the Subprocessor List — which include the United States and, for one transitional route (Moonshot AI), mainland China. Myntriq's embedding model runs on Myntriq's own infrastructure and involves no third party. Each provider maintains its own usage policies and data handling terms.
When customer data — including prompts, conversation content, and knowledge base queries — is processed by a third-party model provider, it is processed in accordance with that provider's terms of service and data processing agreements.
Myntriq maintains Data Processing Agreements with third-party model providers where such agreements are offered and applies controls over data routing. The Subprocessor List is the current, versioned register of model providers: it records, per provider, the processing jurisdiction, whether the provider may use customer content to train its models, and a dated snapshot of its retention posture. It should be read alongside the Model Governance Policy.
Customers should note that:
- Myntriq does not use customer data to train its own AI models
- Every provider named in the Subprocessor List is contractually barred from using data submitted through the MyntriqOS API to train its models, with one named transitional exception: Moonshot AI (Kimi). The platform terms under which the Moonshot route operates today permit customer content to be used for model improvement, with no opt-out. Myntriq is transitioning this route to Moonshot AI's international platform and a written agreement restricting content use; while this qualifier is in effect, Myntriq limits the route to lower-sensitivity workloads. The qualifier will be removed from the Subprocessor List and from this policy when the written restriction is in force.
- Each provider's retention of submitted content is governed by that provider's own published policies; the Subprocessor List records dated snapshots of each provider's training and retention posture as reviewed.
- Customers may select specific models for specific agents where model selection is supported; this may affect which third-party provider processes the associated data
10. Generative AI Limitations
All customers using generative AI capabilities within MyntriqOS should understand the following:
Outputs are not advice. AI-generated content — including financial summaries, HR recommendations, marketing copy, and executive briefings — is not professional advice. It should be treated as a starting point for human review, not a final decision.
Outputs may become outdated. AI models have knowledge cut-off dates and do not have real-time awareness of events unless connected to live data sources. Time-sensitive outputs must be verified against current information.
Confidence is not accuracy. AI models may express outputs with apparent confidence regardless of their accuracy. A confident-sounding output is not necessarily a correct one. Critical outputs must be reviewed against primary sources.
Outputs are not attributable to individuals. AI-generated content is not the opinion, recommendation, or professional judgement of any individual at Myntriq. Responsibility for using AI-generated outputs rests with the customer.
11. Updates to This Policy
Myntriq may update this AI Usage Policy from time to time to reflect changes in platform capabilities, underlying model providers, regulatory requirements, or industry standards.
The effective date at the top of this document will be updated when changes are made. Customers will be notified of material changes through the platform or by email. Continued use of MyntriqOS after notification of a material change constitutes acceptance of the updated policy.
For questions about this policy, contact info@myntriq.io.
Model Governance Policy
Last Updated: 28 September 2026
Contact: info@myntriq.io
Company: Myntriq Pte Ltd (UEN 202537571M), Singapore
Purpose
This policy describes how Myntriq selects, routes, evaluates, and governs the AI models available through MyntriqOS. It is intended for customers, procurement teams, and technical reviewers who need to understand how model decisions are made and what controls exist over AI model behaviour on the platform.
This policy names the models and explains the governance. The per-provider facts that change over time — the jurisdiction where inference is processed, whether the provider may use customer content to train its models, and the provider's retention posture as reviewed on a stated date — are recorded in the Myntriq Subprocessor List, which is the authoritative annex to this policy. The clause-level evidence behind those entries is maintained in Myntriq's model provider data-policy review (September 2026).
1. Model Architecture
MyntriqOS uses a multi-model architecture. Rather than being tied to a single AI provider, MyntriqOS routes inference requests through a managed model routing layer that can serve multiple models from multiple providers.
This architecture provides:
- Provider independence — if a single provider experiences an outage or changes its terms, the platform continues to operate through alternative models
- Model choice — customers can select models that match their requirements for capability, cost, or data handling
- Future flexibility — new models can be added to the routing layer as they become available, without requiring customers to change how they interact with the platform
All model inference is handled server-side through Myntriq's managed model routing service. Customers and users interact with a unified platform interface — they do not interact directly with model provider APIs.
One model runs on Myntriq's own infrastructure rather than a third-party provider: the bge-m3 embedding model, which supports knowledge base retrieval. Self-hosted inference is the pattern Myntriq is extending to further models over time (see Section 4).
2. Supported Models
The following models are currently available through MyntriqOS:
| Model | Provider | Access route | Primary role |
|---|
| claude-opus-4-8 | Anthropic | Direct API | Advanced reasoning, long-form content, structured outputs |
| claude-sonnet-4-6 | Anthropic | Direct API | General agent tasks |
| claude-sonnet-5 | Anthropic | Direct API | General agent tasks |
| claude-opus-5 | Anthropic | Direct API | Advanced reasoning and executive intelligence tasks |
| claude-fable-5 | Anthropic | Direct API | Advanced reasoning; designated Covered Model under Anthropic's terms (mandatory 30-day retention — see Subprocessor List) |
| gpt-4o | OpenAI | Direct API | Advanced reasoning, long-form content, structured outputs |
| gpt-4o-mini | OpenAI | Direct API | Cost-efficient routine tasks |
| gpt-5.6-terra | OpenAI | Direct API | Advanced reasoning and agent tasks |
| whisper-1 | OpenAI | Direct API | Audio transcription for recorded meetings |
| gemini-3.7-flash | Google | Direct API (paid tier) | Cost-efficient general tasks |
| qwen3.8 | Alibaba Cloud | Direct API, DashScope international endpoint | General agent tasks |
| qwen3.8-instant | Alibaba Cloud | Direct API, DashScope international endpoint | Cost-efficient tier for long inputs (reasoning mode disabled) |
| kimi-k3 | Moonshot AI | Direct API — transitional route, see Section 3 | General agent tasks; limited to lower-sensitivity workloads while the transitional qualifier in Section 3 is in effect |
| qwen3.7-plus | Alibaba (via OpenRouter) | OpenRouter | Open-weight general tasks |
| glm-5.2 | Zhipu (via OpenRouter) | OpenRouter | Open-weight general tasks |
| llama3.3 | Meta (via OpenRouter) | OpenRouter | Open-source, strong general reasoning |
| llama3.2 | Meta (via OpenRouter) | OpenRouter | Temporary compatibility alias that serves the same Llama 3.3 model for historical conversations |
| bge-m3 | First-party | Myntriq's own infrastructure | Embeddings for knowledge base retrieval; no third party processes this data |
For every provider named above, the jurisdiction where inference is processed, whether customer content may be used to train the provider's models, and the provider's retention posture as reviewed on 27 September 2026 are recorded in the Subprocessor List. This policy cross-references that annex rather than restating those details, because provider terms change and the annex carries dated snapshots.
3. Model Selection Principles
Myntriq evaluates models against the following criteria before making them available on the platform:
Capability — The model must be capable of performing the tasks for which it will be used in MyntriqOS (reasoning, instruction following, structured output generation, content creation). Capability is assessed through internal testing against MyntriqOS use cases.
Safety and alignment — The model must have demonstrated reasonable alignment with safe and responsible AI practices, including resistance to generating harmful content and responsiveness to safety instructions.
Data handling — The model provider must offer clear terms around how data submitted through their API is used. Myntriq requires that the provider's terms confirm customer content is not used to train the provider's models. As of 27 September 2026 this requirement is met by every provider on the platform with one transitional exception: the Moonshot AI route (kimi-k3) operates today under platform terms that permit customer content to be used for model improvement, with no opt-out. Myntriq is transitioning this route to Moonshot AI's international platform (Moonshot AI PTE. LTD., Singapore) under a written agreement restricting content use; this exception will be removed when that written restriction is in force. While it is in effect, Myntriq limits this route to lower-sensitivity workloads.
Reliability — The model must be reliably available through a hosted API or proxy service, or run on Myntriq's own infrastructure. Myntriq does not offer models that require customer-managed hosting.
Commercial viability — The model must be available at a cost level that is consistent with the platform's pricing structure and the expected usage patterns of MyntriqOS customers.
4. Open-Source and Open-Weight Models
MyntriqOS includes support for open-source and open-weight AI models — currently Llama 3.3 (Meta), GLM-5.2 (Zhipu), and Qwen 3.7 Plus (Alibaba), all reached through OpenRouter, plus the self-hosted bge-m3 embedding model. Open-source model inclusion reflects several important values:
Independence from proprietary models. Open-source models are not controlled by a single commercial entity. This reduces the risk that changes to a proprietary model provider's terms, pricing, or capabilities create a problem for customers without alternatives.
Cost efficiency. Open-source models are generally available at lower per-token costs, making them suitable for high-volume, lower-complexity tasks (routine query handling, summarisation, content drafting).
Transparency. For customers in certain regulated sectors or with specific procurement requirements, open-source models may be preferred because the model architecture is publicly documented.
Myntriq currently routes hosted open-source and open-weight inference through OpenRouter, which provides hosted inference without requiring Myntriq or its customers to manage model infrastructure. OpenRouter itself does not use inputs or outputs for model training and does not store prompts or completions by default. OpenRouter passes each request to a downstream hosting provider; Myntriq configures its OpenRouter routes to exclude downstream providers that permit training on customer content and to prefer zero-retention endpoints. Inference through OpenRouter is processed in the United States, and no Singapore routing option exists — the full details are recorded in the Subprocessor List.
One OpenRouter route, qwen3.7-plus, terminates at an Alibaba-hosted endpoint. Whether the terminating platform is Alibaba's international or mainland-China platform could not be confirmed from the provider's documentation as of 27 September 2026; this is recorded in Myntriq's provider policy review. Customers who require certainty on this point can disable the route for their organisation through model permissions (Section 5) or contact Myntriq.
The bge-m3 embedding model runs on Myntriq's own infrastructure inside its own cloud environment. No customer data leaves Myntriq's environment for embedding workloads, and no third party processes it. Self-hosted Qwen inference is planned on the same pattern; when it enters service, the corresponding hosted Alibaba Cloud route will be removed from the data path and from the Subprocessor List.
5. Model Permissions and Customer Control
Organisation-level model permissions
Each MyntriqOS customer organisation has a model permissions configuration that determines which models are available within that organisation. This allows:
- Customers to restrict agents to specific models that meet their internal data handling or compliance requirements
- Customers to enable or disable specific models for their users — including disabling any route whose processing jurisdiction or training posture does not meet the organisation's requirements
- Administrators to configure model permissions through the platform settings
Default model permissions are configured during environment setup and can be adjusted by organisation administrators.
Agent-level model selection
Where agent-level model selection is supported, administrators can configure specific agents to use specific models. This allows a customer to run different agents on different models — for example, using a more capable model for executive intelligence tasks and a cost-efficient model for routine query handling.
User model selection
In standard deployments, users interact with agents — they do not select models directly. Model selection is an administrative function. This ensures that model governance decisions are made at the organisation level, not by individual users.
6. Governance Controls
Audit logging
Every AI model invocation through MyntriqOS is recorded in the audit log with:
- The model used
- The agent identifier
- The user identifier
- Timestamp
- Token usage (input and output)
- Estimated cost
- Outcome
This provides administrators with complete visibility over which models are being used, by whom, for what, and at what cost.
Cost visibility
The Governance Dashboard provides cost visibility at the organisation, agent, and user level. Cost data is derived from token usage metrics and the current pricing of each model. This allows organisations to monitor AI spend and to make informed decisions about model selection and usage policies.
Usage limits
Myntriq reserves the right to apply usage limits at the organisation or user level to prevent abuse or to manage platform capacity. Where usage limits are applied, affected customers will be notified.
7. Adding New Models
Myntriq evaluates new models on an ongoing basis. The criteria in Section 3 apply to all new model additions.
When a new model is added to MyntriqOS:
- The Subprocessor List is updated to include the model provider if not already listed, with its processing jurisdiction, training posture, and a dated retention snapshot
- The MyntriqOS Privacy Policy and this Model Governance Policy are updated to reflect the new model
- Customers are notified through the platform or by email at least 14 days before the model becomes available in production
- New models are initially added to the available models list but not activated by default in existing organisations — administrators must opt in
8. Removing or Deprecating Models
If a model is removed from MyntriqOS — due to provider changes, performance issues, security concerns, or strategic reasons — affected customers will be notified with reasonable notice (minimum 14 days where feasible) and provided guidance on migrating agents to alternative models.
9. Model Limitations
Customers should be aware that:
- All AI models, regardless of provider, may produce incorrect, incomplete, or biased outputs
- Model capabilities change over time as providers update their models — Myntriq cannot guarantee that a specific model version will be available indefinitely
- Model behaviour may vary based on the prompt, context, and system instructions provided
- No model is certified for use in regulated decision-making without human review
The AI Usage Policy contains further guidance on the limitations of AI-generated outputs and the customer's responsibility for reviewing them.
10. Contact
For questions about model governance, model availability, or to request information about specific model data handling terms, contact info@myntriq.io.
Responsible AI Statement
Last Updated: 28 September 2026
Company: Myntriq Pte Ltd (UEN 202537571M), Singapore
Why We Wrote This
There are a lot of companies now publishing AI principles. Most of them say the same things: AI should be fair, transparent, accountable. These are the right words. They are also easy to write and difficult to honour.
We are writing this document because we think the responsibility question for AI has a specific answer in our context — and that answer is worth stating clearly, not abstractly.
Myntriq builds an AI operating system for small and medium-sized businesses across Southeast Asia. Our customers are not large enterprises with AI governance teams. They are the founders, operations managers, and department heads of companies that are trying to do more with less. When they deploy AI agents through MyntriqOS, the AI is acting on their behalf — in their name, in their business. That changes what accountability means, and it changes what we have to do to earn their trust.
The Accountability Question
When an AI agent in MyntriqOS drafts a customer email, qualifies a lead, or summarises the week's financials — who is responsible for what it says and does?
The answer is the customer. Always.
Not Myntriq. Not the AI model provider. The business owner who deployed the agent, configured it, and chose to act on its output.
This is not a liability disclaimer — it is the correct answer. The AI is operating in the customer's business, with the customer's data, on behalf of the customer's organisation. Responsibility follows control. And because responsibility follows control, control must be genuinely available.
This is why MyntriqOS is built the way it is:
- Every agent operates at an autonomy level the customer sets
- Every action is recorded in an audit log the customer can inspect
- Every output can be reviewed before it is acted on
- Agents can be paused, reconfigured, or overridden at any time
We are not trying to build AI that removes humans from the loop. We are trying to build AI that makes it worthwhile for humans to stay in the loop — because the AI is doing the work they would otherwise have had to do themselves.
What We Build For
Transparency over black boxes. If a MyntriqOS agent takes an action, the customer can see what it did, when, why, and at what cost. This is not optional — it is a core platform requirement. We will not ship agent capabilities that cannot be audited.
Human oversight as the default. When we configure agent autonomy levels, the default is always "ask before acting". Increasing autonomy is something the customer chooses, based on demonstrated performance, not something we push.
Model independence. We support multiple AI models from different providers — commercial and open-weight — because no single model has a monopoly on being right. If a model changes, degrades, or is found to have systematic biases in a particular context, our customers are not locked in. They switch the model; they do not rebuild the business logic. The current slate, its providers, and its jurisdictions are recorded in the Subprocessor List and Model Governance Policy.
Data belonging to the customer. Customer content — conversations, documents, business data — belongs to the customer. We do not use it to train our own models. We do not sell it. We do not aggregate it to improve our product at the customer's expense. We process it to provide the service they have paid for.
What We Do Not Do
We do not allow AI agents to make autonomous decisions in contexts where human review is required — credit decisions, employment decisions, medical diagnoses, legal proceedings. These are areas where the consequences of error fall on individuals, not on the business. Our AI Usage Policy is explicit about this, and our platform configuration enforces it.
We do not deploy agents at autonomy levels that bypass the controls the customer has set. If a customer has configured an agent to ask for approval before sending emails, that configuration is enforced. We do not override it.
We do not generate content designed to deceive. We do not build tools for disinformation, synthetic identity, surveillance without consent, or any purpose whose value depends on the target not knowing it is happening.
We do not claim our AI is infallible. AI models make mistakes. They hallucinate facts, miss context, and reflect biases from their training data. Knowing this is not a reason to avoid using AI — it is a reason to use it with appropriate review, especially for consequential outputs. Our platform is designed on this assumption: not that the AI is always right, but that the human reviewing the AI's output can catch the cases where it is not.
How We Handle AI Errors
AI models make mistakes. MyntriqOS is designed with this as a given.
Agents are configured to flag uncertainty — rather than proceed confidently when they do not have enough information. When an agent is not confident, it should ask, not invent.
The Governance Dashboard gives administrators visibility over agent outputs before they are acted on, at the autonomy levels the customer has set.
Customers can roll back agent actions in supported workflows. Where rollback is not technically feasible, the audit log provides a clear record of what happened for the purposes of manual correction.
We maintain a channel for reporting agent errors and responsible AI concerns: info@myntriq.io. Reports are reviewed and, where they reveal systemic issues with platform behaviour, are fed back into our engineering process.
How We Think About AI and Employment
This question comes up, and it deserves a direct answer.
MyntriqOS is designed for businesses that cannot afford to hire specialists. A 40-person distribution company does not have a dedicated marketing analyst, a sales development team, and a finance data analyst. MyntriqOS gives that company capabilities that would otherwise require those hires — not to replace existing employees, but to fill roles that were never filled.
For our typical customer, the relevant question is not "will this replace someone's job?" It is "will this give us the capabilities we need to compete?" We think the answer to that second question is yes. We also think that businesses that are better equipped and more organised create better conditions for the people who work in them.
We are aware that the broader AI employment picture is more complicated than this. We do not pretend otherwise. But we build for the customers we serve, in the context they operate in — and in that context, AI that works correctly is a tool for expanding what is possible, not reducing who is needed.
Our Commitments Going Forward
This document reflects where we are in September 2026. Our platform is live and early — we are not a research lab, we are building a product, and product decisions involve trade-offs.
We commit to:
- Publishing updates to this statement when our approach or platform capabilities change materially
- Being honest about limitations, including our own certifications (which, as an early-stage company, are currently limited)
- Maintaining the AI Usage Policy, Model Governance Policy, and Subprocessor List as live, current documents — not set-and-forget legal text
- Responding to responsible AI concerns submitted to info@myntriq.io
We do not commit to perfection. We commit to transparency about where we are, seriousness about the responsibilities that come with building AI agents that act in business contexts, and a genuine belief that AI can be a tool for expanding capability without surrendering control.
MyntriqOS Terms of Service
Last Updated: 28 September 2026
Company: Myntriq Pte Ltd (UEN 202537571M), Singapore ("Myntriq")
Contact: info@myntriq.io
Introduction
These Terms of Service ("Terms") govern your organisation's access to and use of the MyntriqOS platform ("Platform"), including all features, APIs, and associated services provided by Myntriq Pte Ltd.
By activating a MyntriqOS account or using the Platform, you accept these Terms on behalf of your organisation. If you are accepting these Terms on behalf of an organisation, you represent that you have the authority to bind that organisation.
These Terms should be read alongside the MyntriqOS Privacy Policy, the Data Processing Addendum, and the AI Usage Policy — each of which forms part of the agreement between you and Myntriq.
1. Definitions
"Agreement" means these Terms together with any applicable order form, service schedule, or addendum accepted by the parties.
"Authorised Users" means the employees, contractors, or agents of the Customer who are permitted by the Customer to access the Platform.
"Customer" means the organisation that has accepted these Terms and holds a MyntriqOS subscription.
"Customer Content" means data, text, files, prompts, knowledge base documents, and other information that the Customer or its Authorised Users upload to or process through the Platform.
"Intellectual Property Rights" means patents, copyrights, trade marks, trade secrets, and all other proprietary rights.
"Platform" means the MyntriqOS software-as-a-service platform, including all AI agents, dashboards, APIs, governance tools, and related services provided by Myntriq.
"Services" means the Platform and any professional services provided by Myntriq under this Agreement.
"Subscription" means the Customer's authorised access to the Platform under the terms and pricing agreed in the applicable order form.
2. Access to the Platform
2.1 Grant of access
Subject to these Terms and payment of applicable subscription fees, Myntriq grants the Customer a non-exclusive, non-transferable right to access and use the Platform during the Subscription term, solely for the Customer's internal business purposes and in accordance with this Agreement.
2.2 Authorised Users
The Customer is responsible for managing access to the Platform. The Customer may permit Authorised Users to access the Platform subject to these Terms. The Customer is responsible for the acts and omissions of its Authorised Users as if they were the acts and omissions of the Customer.
2.3 Account credentials
The Customer is responsible for maintaining the confidentiality of account credentials and for all activity that occurs under the Customer's account. The Customer must notify Myntriq immediately upon becoming aware of any unauthorised access.
2.4 Technical requirements
Access to the Platform requires a compatible web browser and internet connection. Myntriq does not warrant that the Platform will be compatible with all browsers, devices, or operating systems.
3. Acceptable Use
3.1 Permitted use
The Customer may use the Platform for its internal business operations, including deploying AI agents, managing business workflows, and accessing business intelligence, in accordance with the AI Usage Policy and these Terms.
3.2 Prohibited use
The Customer must not:
- Use the Platform in a manner that violates applicable laws or regulations
- Use the Platform to process personal data without a lawful basis under applicable data protection law
- Attempt to gain unauthorised access to other customers' data, the Platform's underlying systems, or third-party AI model APIs
- Reverse engineer, decompile, or disassemble the Platform or any part of it
- Use the Platform in a way that interferes with its availability or performance for other customers
- Resell, sublicence, or otherwise make the Platform available to third parties without Myntriq's prior written consent
- Use the Platform for the prohibited use cases set out in the AI Usage Policy
4. Customer Content
4.1 Ownership
The Customer retains all Intellectual Property Rights in Customer Content. Myntriq claims no ownership in Customer Content.
4.2 Licence to process
By uploading Customer Content to the Platform, the Customer grants Myntriq a limited, non-exclusive licence to store, process, and transmit Customer Content solely for the purpose of providing the Platform services.
4.3 Customer responsibility
The Customer is solely responsible for the accuracy, legality, and appropriateness of Customer Content. Myntriq has no obligation to review, screen, or moderate Customer Content.
4.4 No training
Myntriq will not use Customer Content to train its own AI models.
5. Intellectual Property
5.1 Platform ownership
The Platform, including its software, design, architecture, documentation, and trademarks, is owned by Myntriq or its licensors. These Terms do not transfer any Intellectual Property Rights in the Platform to the Customer.
5.2 Feedback
If the Customer provides suggestions or feedback about the Platform, Myntriq may use that feedback without restriction or compensation to the Customer.
5.3 Platform improvements
Myntriq may use aggregated, anonymised, non-customer-identifiable data derived from Customer use of the Platform to improve the Platform and related services.
6. AI-Generated Content
MyntriqOS uses AI models to generate content, recommendations, summaries, and outputs ("AI Outputs") in response to Customer prompts and instructions.
6.1 No warranty
Myntriq makes no warranty as to the accuracy, completeness, or fitness for purpose of AI Outputs. AI Outputs may be incorrect, incomplete, or outdated.
6.2 Customer responsibility
The Customer is solely responsible for reviewing AI Outputs before acting on them. Myntriq is not liable for decisions made by the Customer based on AI Outputs without adequate human review.
6.3 High-risk decisions
AI Outputs must not be used as the sole basis for decisions that materially affect an individual's employment, compensation, credit, healthcare, or legal rights without human review. See the AI Usage Policy for high-risk use case guidance.
7. Subscription, Billing, and Payment
7.1 Subscription fees
Subscription fees are as set out in the applicable order form or pricing schedule. Fees are payable in advance for each subscription period.
7.2 Payment
Payment is due by the date specified in the applicable invoice. Myntriq reserves the right to suspend access to the Platform if payment is not received within 14 days of the due date.
7.3 Taxes
Subscription fees are exclusive of applicable taxes, including GST where applicable. The Customer is responsible for any taxes applicable to its subscription.
7.4 Price changes
Myntriq may change subscription pricing by giving 30 days' notice before the start of the next subscription period. If the Customer does not wish to continue at the new price, the Customer may terminate the subscription before the new period begins.
8. Term and Termination
8.1 Term
This Agreement commences on the date the Customer activates a MyntriqOS account and continues until terminated in accordance with this clause.
8.2 Termination by Customer
The Customer may terminate this Agreement at any time by providing 30 days' written notice to Myntriq. Subscription fees paid in advance are non-refundable unless otherwise agreed in writing.
8.3 Termination by Myntriq
Myntriq may terminate this Agreement immediately on written notice if:
- The Customer materially breaches this Agreement and fails to remedy the breach within 14 days of written notice
- The Customer becomes insolvent, enters administration, or ceases to operate
- The Customer uses the Platform for prohibited purposes under the AI Usage Policy or these Terms
- Myntriq is required to terminate the Agreement by applicable law
8.4 Suspension
Myntriq may suspend access to the Platform without terminating the Agreement where suspension is required to address a security incident, unpaid fees, or a breach of these Terms that is capable of remedy.
8.5 Effect of termination
On termination, the Customer's access to the Platform ceases immediately. Myntriq will delete Customer Content within 30 days of termination in accordance with the Data Retention Policy. The Customer may request a data export before the deletion period expires.
9. Warranties and Disclaimers
9.1 Myntriq warranties
Myntriq warrants that it will:
- Provide the Platform with reasonable care and skill
- Implement the security measures described in the Security Overview
- Use commercially reasonable efforts to keep the Platform available, excluding scheduled maintenance. No uptime service level is offered under this Agreement; any service level commitment would be set out in a separate written schedule agreed with the Customer.
9.2 Disclaimers
Except as expressly set out in this Agreement, the Platform is provided "as is". To the maximum extent permitted by applicable law, Myntriq disclaims all implied warranties, including warranties of merchantability, fitness for a particular purpose, and non-infringement.
Myntriq does not warrant that:
- The Platform will be free from errors or interruptions
- AI Outputs will be accurate, complete, or fit for any particular purpose
- The Platform will meet all of the Customer's requirements
10. Limitation of Liability
10.1 Exclusion of consequential loss
To the maximum extent permitted by applicable law, neither party is liable to the other for indirect, incidental, special, punitive, or consequential loss or damage, including loss of profits, loss of revenue, loss of business, loss of data, or reputational damage, arising from or in connection with this Agreement.
10.2 Cap on liability
Myntriq's total aggregate liability to the Customer under or in connection with this Agreement, whether arising in contract, tort (including negligence), breach of statutory duty, or otherwise, is limited to the greater of:
- The total subscription fees paid by the Customer to Myntriq in the 12 months preceding the event giving rise to the claim, or
- SGD 100
10.3 Exclusions from cap
The liability cap in Clause 10.2 does not apply to:
- Death or personal injury caused by Myntriq's negligence
- Fraud or fraudulent misrepresentation
- Any liability that cannot be excluded or limited by applicable law
10.4 Mutual indemnity
Each party will indemnify the other against third-party claims arising from its own breach of this Agreement.
11. Confidentiality
Each party will keep confidential all information received from the other party that is designated as confidential or that ought reasonably to be understood as confidential, and will not disclose such information to third parties without the disclosing party's prior written consent, except as required by law.
Confidentiality obligations survive termination of this Agreement for a period of 3 years.
12. Changes to This Agreement
Myntriq may update these Terms from time to time. Material changes will be communicated to the Customer at least 30 days before they take effect. Continued use of the Platform after that date constitutes acceptance of the updated Terms.
If the Customer does not accept material changes, the Customer may terminate the Agreement by providing written notice before the changes take effect.
13. Governing Law and Dispute Resolution
This Agreement is governed by the laws of Singapore. Any dispute arising in connection with this Agreement will be subject to the exclusive jurisdiction of the courts of Singapore.
The parties agree to attempt to resolve disputes in good faith through senior management discussions before commencing formal proceedings.
14. General
14.1 Entire agreement
This Agreement (including the Privacy Policy, Data Processing Addendum, and AI Usage Policy incorporated by reference) constitutes the entire agreement between the parties relating to its subject matter and supersedes all prior agreements, representations, and understandings.
14.2 Assignment
The Customer may not assign or transfer this Agreement without Myntriq's prior written consent. Myntriq may assign this Agreement to an affiliate or in connection with a merger, acquisition, or sale of all or substantially all of its assets.
14.3 Severability
If any provision of this Agreement is found to be invalid or unenforceable, it will be modified to the minimum extent necessary to make it enforceable, and the remaining provisions will continue in full force.
14.4 Waiver
Failure by either party to enforce any provision of this Agreement does not constitute a waiver of that provision or the right to enforce it in the future.
14.5 Notices
Notices under this Agreement may be given by email. Notices to Myntriq should be sent to info@myntriq.io. Notices to the Customer will be sent to the email address associated with the Customer's administrator account.