Legal

Data Processing Addendum

Last updated: 2026-09-08

This summary describes how Momentum AI sp. z o.o.(“Processor”) processes personal data on behalf of a customer (“Controller”) under Article 28 GDPR, in connection with Momentum Terminal. A countersigned DPA incorporating the EU Standard Contractual Clauses is available on request as part of the order form. Contact hello@momentumterminal.pl.

1. Roles

For data a customer uploads or generates (accounts, lists, notes), the customer is the Controller and Momentum Terminal is the Processor. Separately, Momentum Terminal acts as an independent Controller for the public-registry and company-officer data it compiles (see the Article 14 notice and the Legitimate Interest Assessment).

2. Subject-matter & duration

Processing lasts for the term of the subscription plus any legally required retention. Subject-matter: provision of the Service. Nature/purpose: hosting, authentication, search, and support. Data subjects: the Controller’s authorized users. Categories: account identifiers, usage, and any content the Controller chooses to store.

3. Processor obligations

  • Process only on documented instructions from the Controller.
  • Ensure persons authorized to process are bound by confidentiality.
  • Implement appropriate technical and organizational measures (Art. 32).
  • Assist with data-subject requests and with Arts. 32–36 obligations.
  • Delete or return personal data at the end of the service, subject to legal retention.
  • Make available information needed to demonstrate compliance and allow audits.

4. Security measures

Encryption in transit (TLS); access controls and least-privilege roles; append-only, hash-chained audit logging of sensitive actions; revocable sessions and optional MFA. The application and its database run on a server in Frankfurt am Main, Germany (EEA), with nightly and weekly database backups. Measures are kept current and described on request.

5. International transfers

Some sub-processors below process data in the United States: the AI providers (Anthropic, OpenAI) on their default endpoints, the transactional email provider, the team messaging service and, once billing is live, the payment processor’s US parent. Transfers rest on the EU-US Data Privacy Framework where the provider is certified under it, and otherwise on the EU Standard Contractual Clauses incorporated in that provider’s data processing agreement (linked in the table below). The AI providers receive the user’s own query text and company-level figures; register-person records are not sent to them (see the privacy notice, Part I §5).

6. Sub-processors

The Controller authorizes the sub-processors below. Providers marked “configured, not active” are integrated but process no data until the corresponding feature launches; they are listed for transparency. We give prior notice of changes and an opportunity to object.

Sub-processorStatusPurposeRegion
AnthropicActiveLarge language model (Claude) behind the AI features: chat, question answering, and query interpretationUnited States (default API endpoint today); EU routing planned
OpenAIActiveText embeddings for semantic search and screening (query understanding)United States (default API endpoint today)
GoogleActiveOAuth sign-in (identity provider) - only for users who choose to sign in with GooglePer Google account terms (global provider)
DiscordActiveThe team's internal notification channel: new access requests and accounts, problem reports sent from the product's "Report a problem" door, and data requests sent from the Financials tabUnited States
HostingerActiveInfrastructure hosting for the database serverFrankfurt am Main, Germany (EEA); verified 2026-09-08 against the server's public address
ResendActiveTransactional email: sign-in links, email verification, account and billing notices, team invites, data-request verificationUnited States, certified under the EU-US Data Privacy Framework; our sending domain uses its EU region (Ireland) for dispatch, while account data and email logs are stored in the United States
UpstashConfigured, not activeRedis for rate limiting. Not active: not provisioned; no data is stored there todayRegion selected at provisioning
StripeConfigured, not activePayment processing and subscription billing: checkout, card storage, renewals, the billing portal. Activates with the billing launch (September 2026); until then no payment can be madeStripe Payments Europe Ltd (Ireland) contracts with EU merchants; US parent under the EU-US Data Privacy Framework
SentryConfigured, not activeError monitoring for the app (browser, server and edge). Wired in code with personal data capture switched off (sendDefaultPii false); inert until a DSN is set, which production does not do todayUnited States company with an EU data region option; region chosen at activation

7. Breach notification

We notify the Controller without undue delay after becoming aware of a personal-data breach affecting their data, with the information needed for the Controller’s own obligations.

8. Contact

Data protection enquiries: hello@momentumterminal.pl.

See also the Data Processing Addendum, Privacy and Data requests.