GDPR Art. 28 · Effective 2026-05-20

Data Processing Agreement

This Data Processing Agreement ("DPA") is concluded between Codelabs Studio S.L., a Spanish limited company ("Codelabs", the "Processor"), and the entity subscribing to MemoryFirst (the "Customer", the "Controller"). It governs the processing of Personal Data by Codelabs on behalf of Customer through the MemoryFirst service. This DPA is incorporated by reference into the Terms of Service.

1. Definitions

Capitalised terms have the meanings given in the GDPR (Regulation (EU) 2016/679). "Workspace Data" means Personal Data submitted by Customer to the Service for Processing. "Subprocessor" means a third party engaged by Codelabs to Process Workspace Data on behalf of Customer.

2. Roles & scope

Customer is the Controller of Workspace Data. Codelabs is the Processor and acts only on documented instructions from Customer. Codelabs is the Controller for its own account, billing and security-log data, as described in the Privacy Policy.

3. Subject matter, nature and purpose

  • Subject matter: Processing of Workspace Data to operate the Service.
  • Nature: Storage, chunking, embedding, retrieval, transmission to AI subprocessors when requested by Customer.
  • Purpose: Provide AI-assisted memory and reasoning over Customer's sources.
  • Duration: The term of the Customer's subscription, plus a maximum 30-day deletion window thereafter.
  • Categories of data subjects: Determined by Customer (employees, customers, suppliers, prospects, etc.).
  • Categories of data: Determined by Customer. Customer warrants it has a valid lawful basis under Art. 6 GDPR (and Art. 9 if special categories are involved).

4. Codelabs obligations

  • Process Workspace Data only on documented Customer instructions.
  • Ensure persons authorised to process Workspace Data are bound by confidentiality.
  • Implement appropriate technical and organisational measures (TOMs) listed in Annex II.
  • Assist Customer in responding to data subject requests within 7 business days.
  • Notify Customer of any Personal Data Breach without undue delay and in any event within 72 hours of becoming aware.
  • Make available all information necessary to demonstrate compliance and allow for audits as set out in section 9.
  • Delete or return Workspace Data within 30 days of termination, save where retention is legally required.

5. Customer obligations

  • Provide instructions in writing (the Service configuration is deemed Customer's instructions).
  • Ensure a valid lawful basis for any Personal Data submitted.
  • Inform data subjects of the processing where required by law.
  • Configure access controls and least-privilege correctly within the Service.

6. Subprocessors

Customer provides a general authorisation for Codelabs to engage Subprocessors. Codelabs will:

  • Impose data-protection obligations on Subprocessors no less protective than this DPA.
  • Maintain the current Subprocessor list below; notify Customer at least 30 days before any addition or replacement.
  • Remain liable to Customer for the acts and omissions of its Subprocessors.

Annex I · Subprocessor list (live)

SubprocessorPurposeLocationTransfer mechanism
Hetzner Online GmbHCloud infrastructure (compute, storage, networking)Falkenstein, Germany (EU)Intra-EEA: no transfer mechanism required
Cloudflare, Inc.DNS, CDN, WAF, edge securityUSA (with EU edge routing where available)EU SCCs (Module 3) + supplementary measures
Stripe Payments Europe Ltd.Subscription billing and payment processingIreland (EU)Intra-EEA: no transfer mechanism required
Anthropic PBCLLM inference (Claude family) routed via gatewayUSA (EU regions where available)EU SCCs + Anthropic zero data-retention API addendum
OpenAI Ireland Ltd.Optional LLM inference (GPT family) when selected by CustomerIreland (EU)Intra-EEA + OpenAI Data Processing Addendum
Google Ireland Ltd.Optional LLM inference (Gemini) + OAuth identity for Workspace integrationsIreland (EU)Intra-EEA + Google Cloud DPA
Mistral AI SASOptional LLM inference (Mistral models)Paris, France (EU)Intra-EEA: no transfer mechanism required
Resend, Inc.Transactional email deliveryUSAEU SCCs (Module 2)

7. International transfers

Workspace Data is hosted in Germany by default. Transfers to Subprocessors outside the EEA rely on EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) and the supplementary measures listed in Annex II. Customers on the Enterprise tier may pin processing to EU-only Subprocessors.

8. Security · Annex II (TOMs)

  • TLS 1.3 in transit, AES-256-GCM at rest, per-workspace key derivation.
  • Per-client data isolation at the database level.
  • API keys hashed with bcrypt (cost 12); secrets stored in Vaultwarden.
  • Least-privilege staff access; production access via audited SSH bastion only.
  • Encrypted daily backups with 30-day retention and point-in-time recovery.
  • Vulnerability scanning on CI; dependency pinning and automated SCA.
  • Annual third-party penetration test (planned FY 2026).
  • Incident-response playbook with 72-hour breach-notification commitment.
  • Pseudonymisation of telemetry and aggregation of usage data within 90 days.

9. Audit rights

Codelabs makes available, on Customer's written request, the information necessary to demonstrate compliance with this DPA. Customer may conduct an audit no more than once per calendar year with at least 30 days' prior written notice; audits must respect Codelabs' security policies and confidentiality obligations to other customers. Once available, a SOC 2 Type II report or equivalent third-party attestation will satisfy this obligation.

10. Breach notification

Codelabs notifies Customer of a Personal Data Breach affecting Workspace Data without undue delay and in any event within 72 hours of becoming aware. The notification will describe the nature of the breach, categories and approximate number of data subjects affected, likely consequences, and measures taken or proposed.

11. Liability

The liability provisions of the Terms of Service. apply to this DPA. Nothing in this DPA excludes or limits either party's liability under Articles 82 GDPR for damages suffered by data subjects.

12. Term & deletion

This DPA remains in effect for as long as Codelabs Processes Workspace Data. Upon termination of the subscription, Customer may export Workspace Data within 30 days; after that period, Codelabs permanently deletes Workspace Data from all live systems and (within 60 additional days) from backups.

13. Signing the DPA

Subscribing to a paid plan and accepting the Terms of Service constitutes acceptance of this DPA. Enterprise customers may request a counter-signed copy by writing to dpa@memoryfirst.ai; we return signed copies within 5 business days.