When a DPA is needed
A Data Processing Addendum sets out the conditions under which Minds processes personal data on your organization’s behalf. Your organization may be the controller or may itself act as a processor for another organization. Establish the applicable roles and have the required agreement in place before submitting data that requires it.
A dedicated instance is a deployment boundary. It does not replace the need to document who controls the data, who can access it, and which platform or external services also process it.
Define the processing
The processing schedule should describe the actual use of Minds, including hosted instance services, Helm, agents, integrations, support access, and relevant platform administration. The agreement should distinguish customer content from information we process for our own account administration.
- The subject matter, purpose, nature, and duration of processing.
- Categories of people and personal data involved, including whether sensitive categories are permitted.
- The customer’s instructions, authorized users, agents, tools, and model providers.
- Hosting arrangement, processing regions, transfer paths, and applicable safeguards.
- Retention, export, deletion, backup handling, and procedures at the end of the service.
Set out each party’s responsibilities
The signed terms should address processing only on documented instructions; confidentiality; appropriate security measures; how additional processors are engaged; assistance with individual rights, incidents, and impact assessments; deletion or return of data; and information needed to demonstrate compliance.
Your team remains responsible for the lawfulness of its instructions, the information it submits, notices to the people affected, and the access it gives to users and agents. Minds’ obligations must be defined in the executed agreement and the service configuration it covers.
Review the actual controls
Review identity and permissions, instance isolation, encryption configuration, network boundaries, key custody, logging, backup and recovery, deletion, and incident communications for the deployment you will use. Engine capabilities and marketing examples are not evidence that every control is enabled in a particular instance.
If your review requires an audit report, certificate, penetration-test summary, recovery objective, or specific access policy, request that evidence before contracting. We do not substitute an unverified badge or product claim for an assessment.
Providers and international transfers
The signed schedule must identify the providers and processing locations relevant to your service, together with the notice and objection process for changes. Customer-selected model providers or tools may involve separate customer arrangements; document those paths as well.
Where personal data crosses a border and a transfer mechanism is required, the parties must identify and complete the applicable safeguards. EU controller–processor clauses and international transfer clauses serve different purposes. This page does not claim automatic coverage by either.
Request an agreement
Email legal@minds.sh with your organization’s legal name, contracting contact, intended Minds deployment, data categories, locations, and any regulatory or procurement requirements. If you already have an Order, include its reference. Request the processing schedule, security details, applicable provider list, and transfer terms together.
Do not attach production datasets or credentials. Use a description of the workload so we can scope the agreement without receiving the personal information it is intended to protect.
Which document applies
An executed DPA and the Order identify the parties, scope, and binding commitments. If there is a conflict, the precedence provisions in those signed documents and the Terms apply. A request email, website visit, or generic policy page is not a countersigned DPA.
Let’s make it clear.
For privacy requests, contact privacy@minds.sh. For agreements and processing questions, contact legal@minds.sh. Include your organization and the document you are asking about. Never email passwords, API keys, or sensitive customer content.