Legal

Data Processing Addendum

Draft — pending counsel review. This document is provided to establish the contractual baseline and is not yet a substitute for legal advice. Last updated 2026-06-22.

This summary describes how Momentum AI sp. z o.o.(“Processor”) processes personal data on behalf of a customer (“Controller”) under Article 28 GDPR, in connection with Momentum Terminal. A countersigned DPA incorporating the EU Standard Contractual Clauses is available on request as part of the order form. Contact hello@momentumterminal.pl.

1. Roles

For data a customer uploads or generates (accounts, lists, notes), the customer is the Controller and Momentum Terminal is the Processor. Separately, Momentum Terminal acts as an independent Controller for the public-registry and company-officer data it compiles (see the Article 14 notice and the Legitimate Interest Assessment).

2. Subject-matter & duration

Processing lasts for the term of the subscription plus any legally required retention. Subject-matter: provision of the Service. Nature/purpose: hosting, authentication, search, and support. Data subjects: the Controller’s authorized users. Categories: account identifiers, usage, and any content the Controller chooses to store.

3. Processor obligations

  • Process only on documented instructions from the Controller.
  • Ensure persons authorized to process are bound by confidentiality.
  • Implement appropriate technical and organizational measures (Art. 32).
  • Assist with data-subject requests and with Arts. 32–36 obligations.
  • Delete or return personal data at the end of the service, subject to legal retention.
  • Make available information needed to demonstrate compliance and allow audits.

4. Security measures

Encryption in transit (TLS); access controls and least-privilege roles; tamper-evident audit logging of sensitive actions; revocable sessions and optional MFA. The database is hosted with an EU-based hosting provider; managed, region-pinned infrastructure is planned before commercial launch. Measures are kept current and described on request.

5. International transfers

The AI sub-processors (Anthropic, OpenAI) currently process content on their default United States endpoints; EU routing for the language model is planned. The intended transfer basis is the EU Standard Contractual Clauses with supplementary measures. (This transfer basis is being formalized. Counsel review required before reliance.)

6. Sub-processors

The Controller authorizes the sub-processors below. Providers marked “configured, not active” are integrated but process no data until the corresponding feature launches; they are listed for transparency. We give prior notice of changes and an opportunity to object.

Sub-processorStatusPurposeRegion
AnthropicActiveLarge language model (Claude) behind the AI features: chat, question answering, and query interpretationUnited States (default API endpoint today); EU routing planned
OpenAIActiveText embeddings for semantic search and screening (query understanding)United States (default API endpoint today)
GoogleActiveOAuth sign-in (identity provider) - only for users who choose to sign in with GooglePer Google account terms (global provider)
HostingerActiveInfrastructure hosting for the database serverEU-based provider; datacenter region of the specific server pending verification
ResendConfigured, not activeTransactional email (sign-in links, email verification, team invites, data-request verification). Not active: no email is sent todayUnited States
UpstashConfigured, not activeRedis for rate limiting. Not active: not provisioned; no data is stored there todayRegion selected at provisioning
StripeConfigured, not activePayment processing and subscription billing. Activates when billing launches; no payment can be made todayUS headquarters; Irish EU entity for EU customers

7. Breach notification

We notify the Controller without undue delay after becoming aware of a personal-data breach affecting their data, with the information needed for the Controller’s own obligations.

8. Contact

Data protection enquiries: hello@momentumterminal.pl.

See also Data Processing Addendum · Privacy · Data requests.