Data Processing Addendum
Last Updated: 19 June 2026
This DPA is entered into between:
- Data Processor: Myntriq Pte Ltd (UEN 202537571M), Singapore ("Myntriq")
- Data Controller: The customer organisation that has accepted MyntriqOS Terms of Service ("Customer")
Recitals
This Data Processing Addendum ("DPA") supplements the MyntriqOS Terms of Service ("Agreement") entered into between Myntriq and the Customer. It governs the processing of Personal Data by Myntriq on behalf of the Customer in connection with the MyntriqOS platform.
The parties agree that:
- The Customer is the Data Controller with respect to Personal Data processed through MyntriqOS
- Myntriq is the Data Processor acting on the Customer's behalf
- This DPA reflects the obligations of a Data Processor under Singapore's Personal Data Protection Act 2012 (PDPA) and, where applicable, the EU General Data Protection Regulation (GDPR)
1. Definitions
"Personal Data" means any information relating to an identified or identifiable natural person that the Customer provides to, or that is collected by, MyntriqOS in the course of the Customer's use of the platform.
"Processing" means any operation performed on Personal Data, including collection, storage, use, disclosure, or deletion.
"Data Subject" means any natural person whose Personal Data is processed through MyntriqOS on behalf of the Customer.
"Subprocessor" means any third-party service provider engaged by Myntriq to process Personal Data in connection with MyntriqOS.
"Security Incident" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data.
Capitalised terms not defined here have the meanings given in the Agreement.
2. Scope of Processing
2.1 Subject matter
Myntriq processes Personal Data to provide the MyntriqOS platform services to the Customer, including:
- Platform access and authentication
- AI agent operation and inference routing
- Conversation and knowledge base storage
- Governance and audit logging
- Platform analytics and support
2.2 Duration
Processing continues for the duration of the Agreement and for the period required to delete or return Personal Data following termination.
2.3 Nature and purpose
The nature and purpose of processing is to enable the Customer to operate AI agents, manage business workflows, and access business intelligence through MyntriqOS, as described in the Agreement.
2.4 Categories of Personal Data
The categories of Personal Data processed depend on what the Customer chooses to input into MyntriqOS. Common categories include:
- Contact information (names, email addresses, phone numbers) of the Customer's users and their business contacts
- Business information (company names, roles, deal information) entered through CRM, HR, and other business modules
- Content submitted in conversations and knowledge base documents
- Any other information the Customer or its users enter into the platform
2.5 Categories of Data Subjects
Data Subjects may include:
- The Customer's employees, contractors, and authorised platform users
- The Customer's business contacts, leads, customers, and partners whose information is entered into the platform
3. Myntriq's Obligations as Data Processor
3.1 Processing on documented instructions
Myntriq will process Personal Data only on the Customer's documented instructions, as set out in this DPA and the Agreement. If Myntriq is required by applicable law to process Personal Data for other purposes, Myntriq will inform the Customer before doing so (unless prohibited from doing so by law).
3.2 Confidentiality
Myntriq will ensure that all personnel authorised to process Personal Data are subject to appropriate confidentiality obligations.
3.3 Security
Myntriq will implement and maintain appropriate technical and organisational measures to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures are described in the Myntriq Security Overview, which forms part of this DPA by reference.
3.4 Subprocessors
Myntriq engages the subprocessors listed in the current Myntriq Subprocessor List to process Personal Data on its behalf. Myntriq will:
- Ensure that its contracts with subprocessors impose data protection obligations no less protective than those in this DPA
- Notify the Customer of any planned addition or replacement of subprocessors at least 14 days before the change takes effect
- Remain liable to the Customer for the acts and omissions of its subprocessors to the same extent Myntriq would be liable if performing the processing directly
The Customer consents to Myntriq's use of the subprocessors listed in the current Subprocessor List, as updated in accordance with this clause. If the Customer objects to a new subprocessor, the Customer must notify Myntriq in writing within 14 days of the notification. Where an objection cannot be resolved, the Customer may terminate the affected services.
3.5 Data Subject Rights
Myntriq will, to the extent technically feasible, assist the Customer in responding to requests from Data Subjects to exercise their rights under applicable data protection law, including rights of access, rectification, erasure, restriction, portability, and objection. Where Myntriq receives a request directly from a Data Subject, Myntriq will redirect the Data Subject to the Customer.
3.6 Security Assistance
Myntriq will assist the Customer in meeting its data protection obligations with respect to security, breach notification, data protection impact assessments, and prior consultation with supervisory authorities, taking into account the nature of processing and the information available to Myntriq.
3.7 Deletion or Return
Upon termination of the Agreement, or upon the Customer's written request, Myntriq will:
- Delete all Personal Data processed on behalf of the Customer within 30 days, and
- Provide written confirmation of deletion to the Customer
Where deletion is not technically feasible within this period (for example, for data included in encrypted backups), Myntriq will confirm the timeline for deletion of backup data and will not use that data for any other purpose.
The Customer may alternatively request that Myntriq return Personal Data in a portable format before deletion.
3.8 Audit Rights
Myntriq will provide the Customer with all information reasonably necessary to demonstrate compliance with this DPA. The Customer may, on 30 days' written notice and at the Customer's cost, conduct an audit of Myntriq's data processing activities, limited to information and facilities relevant to the processing of the Customer's Personal Data. Audits may be conducted no more than once per calendar year except where a Security Incident has occurred.
4. Customer's Obligations
The Customer is responsible for:
- Ensuring it has a lawful basis for processing the Personal Data it submits to MyntriqOS
- Ensuring that Data Subjects are informed of the processing of their Personal Data through MyntriqOS, as required by applicable law
- Ensuring that its use of MyntriqOS complies with applicable laws, regulations, and industry standards
- Providing accurate and complete instructions to Myntriq regarding the processing of Personal Data
- Promptly notifying Myntriq of any changes to its instructions that may affect Myntriq's ability to process Personal Data in compliance with applicable law
5. Security Incident Notification
If Myntriq becomes aware of a Security Incident affecting Personal Data processed on behalf of the Customer, Myntriq will:
- Notify the Customer within 72 hours of becoming aware of the incident
- Provide the following information (or as much as is available at the time of notification):
- The nature of the Security Incident
- The categories and approximate number of Data Subjects affected
- The categories and approximate volume of Personal Data affected
- The likely consequences of the incident
- The measures taken or proposed to address the incident
Myntriq will cooperate with the Customer in responding to the incident and in making any required notifications to supervisory authorities or Data Subjects.
6. Cross-Border Data Transfers
MyntriqOS processes Personal Data primarily in Singapore. AI model inference requests may be transferred to and processed by subprocessors in the United States (OpenAI, Anthropic, OpenRouter).
Where Personal Data is transferred outside Singapore, Myntriq will ensure that appropriate safeguards are in place, which may include:
- Contractual clauses with subprocessors incorporating data protection obligations
- Reliance on the data transfer frameworks applicable in the relevant jurisdiction
For EU/EEA Personal Data, transfers to subprocessors in third countries (including the United States) are governed by the Standard Contractual Clauses incorporated into Myntriq's agreements with those subprocessors.
7. Term and Termination
This DPA remains in force for the duration of the Agreement and continues to apply to any Personal Data retained by Myntriq following termination until that data is deleted in accordance with Clause 3.7.
8. Governing Law
This DPA is governed by the laws of Singapore. Any disputes arising in connection with this DPA will be subject to the exclusive jurisdiction of the courts of Singapore, unless the parties agree otherwise in writing.
9. Order of Precedence
In the event of a conflict between this DPA and the Agreement, this DPA will take precedence with respect to matters relating to the processing of Personal Data.
10. Contact
For questions about this DPA or to exercise rights under it, contact:
Myntriq Pte Ltd
Data Protection
hello@myntriq.io
*This DPA is effective from 19 June 2026. Customers who entered into the Agreement before this date are deemed to have accepted this DPA as of the date they continue to use MyntriqOS.*