A clear agreement for your data. Minds, Inc. Updated 14 September 2026 The information your team needs to scope a Data Processing Addendum for Minds and its dedicated Akasha instances. This page explains the DPA process. It is not a signed addendum, does not execute international transfer clauses, and does not replace an agreement with your organization. 1. When a DPA is needed A Data Processing Addendum sets out the conditions under which Minds processes personal data on your organization’s behalf. Your organization may be the controller or may itself act as a processor for another organization. Establish the applicable roles and have the required agreement in place before submitting data that requires it. A dedicated instance is a deployment boundary. It does not replace the need to document who controls the data, who can access it, and which platform or external services also process it. 2. Define the processing The processing schedule should describe the actual use of Minds, including hosted instance services, Helm, agents, integrations, support access, and relevant platform administration. The agreement should distinguish customer content from information we process for our own account administration. - The subject matter, purpose, nature, and duration of processing. - Categories of people and personal data involved, including whether sensitive categories are permitted. - The customer’s instructions, authorized users, agents, tools, and model providers. - Hosting arrangement, processing regions, transfer paths, and applicable safeguards. - Retention, export, deletion, backup handling, and procedures at the end of the service. 3. Set out each party’s responsibilities The signed terms should address processing only on documented instructions; confidentiality; appropriate security measures; how additional processors are engaged; assistance with individual rights, incidents, and impact assessments; deletion or return of data; and information needed to demonstrate compliance. Your team remains responsible for the lawfulness of its instructions, the information it submits, notices to the people affected, and the access it gives to users and agents. Minds’ obligations must be defined in the executed agreement and the service configuration it covers. 4. Review the actual controls Review identity and permissions, instance isolation, encryption configuration, network boundaries, key custody, logging, backup and recovery, deletion, and incident communications for the deployment you will use. Engine capabilities and marketing examples are not evidence that every control is enabled in a particular instance. If your review requires an audit report, certificate, penetration-test summary, recovery objective, or specific access policy, request that evidence before contracting. We do not substitute an unverified badge or product claim for an assessment. 5. Providers and international transfers The signed schedule must identify the providers and processing locations relevant to your service, together with the notice and objection process for changes. Customer-selected model providers or tools may involve separate customer arrangements; document those paths as well. Where personal data crosses a border and a transfer mechanism is required, the parties must identify and complete the applicable safeguards. EU controller–processor clauses and international transfer clauses serve different purposes. This page does not claim automatic coverage by either. 6. Request an agreement Email legal@minds.sh with your organization’s legal name, contracting contact, intended Minds deployment, data categories, locations, and any regulatory or procurement requirements. If you already have an Order, include its reference. Request the processing schedule, security details, applicable provider list, and transfer terms together. Do not attach production datasets or credentials. Use a description of the workload so we can scope the agreement without receiving the personal information it is intended to protect. 7. Which document applies An executed DPA and the Order identify the parties, scope, and binding commitments. If there is a conflict, the precedence provisions in those signed documents and the Terms apply. A request email, website visit, or generic policy page is not a countersigned DPA.