Data Processing Agreement
This Data Processing Agreement ("DPA") is concluded between Codelabs Studio S.L., a Spanish limited company ("Codelabs", the "Processor"), and the entity subscribing to MemoryFirst (the "Customer", the "Controller"). It governs the processing of Personal Data by Codelabs on behalf of Customer through the MemoryFirst service. This DPA is incorporated by reference into the Terms of Service.
1. Definitions
Capitalised terms have the meanings given in the GDPR (Regulation (EU) 2016/679). "Workspace Data" means Personal Data submitted by Customer to the Service for Processing. "Subprocessor" means a third party engaged by Codelabs to Process Workspace Data on behalf of Customer.
2. Roles & scope
Customer is the Controller of Workspace Data. Codelabs is the Processor and acts only on documented instructions from Customer. Codelabs is the Controller for its own account, billing and security-log data, as described in the Privacy Policy.
3. Subject matter, nature and purpose
- Subject matter: Processing of Workspace Data to operate the Service.
- Nature: Storage, chunking, embedding, retrieval, transmission to AI subprocessors when requested by Customer.
- Purpose: Provide AI-assisted memory and reasoning over Customer's sources.
- Duration: The term of the Customer's subscription, plus a maximum 30-day deletion window thereafter.
- Categories of data subjects: Determined by Customer (employees, customers, suppliers, prospects, etc.).
- Categories of data: Determined by Customer. Customer warrants it has a valid lawful basis under Art. 6 GDPR (and Art. 9 if special categories are involved).
4. Codelabs obligations
- Process Workspace Data only on documented Customer instructions.
- Ensure persons authorised to process Workspace Data are bound by confidentiality.
- Implement appropriate technical and organisational measures (TOMs) listed in Annex II.
- Assist Customer in responding to data subject requests within 7 business days.
- Notify Customer of any Personal Data Breach without undue delay and in any event within 72 hours of becoming aware.
- Make available all information necessary to demonstrate compliance and allow for audits as set out in section 9.
- Delete or return Workspace Data within 30 days of termination, save where retention is legally required.
5. Customer obligations
- Provide instructions in writing (the Service configuration is deemed Customer's instructions).
- Ensure a valid lawful basis for any Personal Data submitted.
- Inform data subjects of the processing where required by law.
- Configure access controls and least-privilege correctly within the Service.
6. Subprocessors
Customer provides a general authorisation for Codelabs to engage Subprocessors. Codelabs will:
- Impose data-protection obligations on Subprocessors no less protective than this DPA.
- Maintain the current Subprocessor list below; notify Customer at least 30 days before any addition or replacement.
- Remain liable to Customer for the acts and omissions of its Subprocessors.
Annex I · Subprocessor list (live)
| Subprocessor | Purpose | Location | Transfer mechanism |
|---|---|---|---|
| Hetzner Online GmbH | Cloud infrastructure (compute, storage, networking) | Falkenstein, Germany (EU) | Intra-EEA: no transfer mechanism required |
| Cloudflare, Inc. | DNS, CDN, WAF, edge security | USA (with EU edge routing where available) | EU SCCs (Module 3) + supplementary measures |
| Stripe Payments Europe Ltd. | Subscription billing and payment processing | Ireland (EU) | Intra-EEA: no transfer mechanism required |
| Anthropic PBC | LLM inference (Claude family) routed via gateway | USA (EU regions where available) | EU SCCs + Anthropic zero data-retention API addendum |
| OpenAI Ireland Ltd. | Optional LLM inference (GPT family) when selected by Customer | Ireland (EU) | Intra-EEA + OpenAI Data Processing Addendum |
| Google Ireland Ltd. | Optional LLM inference (Gemini) + OAuth identity for Workspace integrations | Ireland (EU) | Intra-EEA + Google Cloud DPA |
| Mistral AI SAS | Optional LLM inference (Mistral models) | Paris, France (EU) | Intra-EEA: no transfer mechanism required |
| Resend, Inc. | Transactional email delivery | USA | EU SCCs (Module 2) |
7. International transfers
Workspace Data is hosted in Germany by default. Transfers to Subprocessors outside the EEA rely on EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) and the supplementary measures listed in Annex II. Customers on the Enterprise tier may pin processing to EU-only Subprocessors.
8. Security · Annex II (TOMs)
- TLS 1.3 in transit, AES-256-GCM at rest, per-workspace key derivation.
- Per-client data isolation at the database level.
- API keys hashed with bcrypt (cost 12); secrets stored in Vaultwarden.
- Least-privilege staff access; production access via audited SSH bastion only.
- Encrypted daily backups with 30-day retention and point-in-time recovery.
- Vulnerability scanning on CI; dependency pinning and automated SCA.
- Annual third-party penetration test (planned FY 2026).
- Incident-response playbook with 72-hour breach-notification commitment.
- Pseudonymisation of telemetry and aggregation of usage data within 90 days.
9. Audit rights
Codelabs makes available, on Customer's written request, the information necessary to demonstrate compliance with this DPA. Customer may conduct an audit no more than once per calendar year with at least 30 days' prior written notice; audits must respect Codelabs' security policies and confidentiality obligations to other customers. Once available, a SOC 2 Type II report or equivalent third-party attestation will satisfy this obligation.
10. Breach notification
Codelabs notifies Customer of a Personal Data Breach affecting Workspace Data without undue delay and in any event within 72 hours of becoming aware. The notification will describe the nature of the breach, categories and approximate number of data subjects affected, likely consequences, and measures taken or proposed.
11. Liability
The liability provisions of the Terms of Service. apply to this DPA. Nothing in this DPA excludes or limits either party's liability under Articles 82 GDPR for damages suffered by data subjects.
12. Term & deletion
This DPA remains in effect for as long as Codelabs Processes Workspace Data. Upon termination of the subscription, Customer may export Workspace Data within 30 days; after that period, Codelabs permanently deletes Workspace Data from all live systems and (within 60 additional days) from backups.
13. Signing the DPA
Subscribing to a paid plan and accepting the Terms of Service constitutes acceptance of this DPA. Enterprise customers may request a counter-signed copy by writing to dpa@memoryfirst.ai; we return signed copies within 5 business days.