Legal
Data Processing Addendum
Last updated: 2026-09-08
This summary describes how Momentum AI sp. z o.o.(“Processor”) processes personal data on behalf of a customer (“Controller”) under Article 28 GDPR, in connection with Momentum Terminal. A countersigned DPA incorporating the EU Standard Contractual Clauses is available on request as part of the order form. Contact hello@momentumterminal.pl.
1. Roles
For data a customer uploads or generates (accounts, lists, notes), the customer is the Controller and Momentum Terminal is the Processor. Separately, Momentum Terminal acts as an independent Controller for the public-registry and company-officer data it compiles (see the Article 14 notice and the Legitimate Interest Assessment).
2. Subject-matter & duration
Processing lasts for the term of the subscription plus any legally required retention. Subject-matter: provision of the Service. Nature/purpose: hosting, authentication, search, and support. Data subjects: the Controller’s authorized users. Categories: account identifiers, usage, and any content the Controller chooses to store.
3. Processor obligations
- Process only on documented instructions from the Controller.
- Ensure persons authorized to process are bound by confidentiality.
- Implement appropriate technical and organizational measures (Art. 32).
- Assist with data-subject requests and with Arts. 32–36 obligations.
- Delete or return personal data at the end of the service, subject to legal retention.
- Make available information needed to demonstrate compliance and allow audits.
4. Security measures
Encryption in transit (TLS); access controls and least-privilege roles; append-only, hash-chained audit logging of sensitive actions; revocable sessions and optional MFA. The application and its database run on a server in Frankfurt am Main, Germany (EEA), with nightly and weekly database backups. Measures are kept current and described on request.
5. International transfers
Some sub-processors below process data in the United States: the AI providers (Anthropic, OpenAI) on their default endpoints, the transactional email provider, the team messaging service and, once billing is live, the payment processor’s US parent. Transfers rest on the EU-US Data Privacy Framework where the provider is certified under it, and otherwise on the EU Standard Contractual Clauses incorporated in that provider’s data processing agreement (linked in the table below). The AI providers receive the user’s own query text and company-level figures; register-person records are not sent to them (see the privacy notice, Part I §5).
6. Sub-processors
The Controller authorizes the sub-processors below. Providers marked “configured, not active” are integrated but process no data until the corresponding feature launches; they are listed for transparency. We give prior notice of changes and an opportunity to object.
| Sub-processor | Status | Purpose | Region |
|---|---|---|---|
| Anthropic | Active | Large language model (Claude) behind the AI features: chat, question answering, and query interpretation | United States (default API endpoint today); EU routing planned |
| OpenAI | Active | Text embeddings for semantic search and screening (query understanding) | United States (default API endpoint today) |
| Active | OAuth sign-in (identity provider) - only for users who choose to sign in with Google | Per Google account terms (global provider) | |
| Discord | Active | The team's internal notification channel: new access requests and accounts, problem reports sent from the product's "Report a problem" door, and data requests sent from the Financials tab | United States |
| Hostinger | Active | Infrastructure hosting for the database server | Frankfurt am Main, Germany (EEA); verified 2026-09-08 against the server's public address |
| Resend | Active | Transactional email: sign-in links, email verification, account and billing notices, team invites, data-request verification | United States, certified under the EU-US Data Privacy Framework; our sending domain uses its EU region (Ireland) for dispatch, while account data and email logs are stored in the United States |
| Upstash | Configured, not active | Redis for rate limiting. Not active: not provisioned; no data is stored there today | Region selected at provisioning |
| Stripe | Configured, not active | Payment processing and subscription billing: checkout, card storage, renewals, the billing portal. Activates with the billing launch (September 2026); until then no payment can be made | Stripe Payments Europe Ltd (Ireland) contracts with EU merchants; US parent under the EU-US Data Privacy Framework |
| Sentry | Configured, not active | Error monitoring for the app (browser, server and edge). Wired in code with personal data capture switched off (sendDefaultPii false); inert until a DSN is set, which production does not do today | United States company with an EU data region option; region chosen at activation |
7. Breach notification
We notify the Controller without undue delay after becoming aware of a personal-data breach affecting their data, with the information needed for the Controller’s own obligations.
8. Contact
Data protection enquiries: hello@momentumterminal.pl.
See also the Data Processing Addendum, Privacy and Data requests.