Mentrast Logo
Mentrast
Revision: 2026.01

Data Processing Agreement

This Data Processing Agreement ("DPA") reflects the parties’ agreement with respect to the Processing of Personal Data by Mentrast on behalf of the Customer in connection with the Mentrast Subscription Services under the Mentrast Terms of Service.

1. Preamble

This DPA is an addendum to and forms part of the Master Services Agreement between Mentrast Inc. ("Processor") and the Customer ("Controller"). In the course of providing the Services to Customer pursuant to the Agreement, Processor may Process Personal Data on behalf of Customer. This DPA sets out the rights and obligations of the Parties in relation to such Processing.

2. Definitions

  • "CCPA" means the California Consumer Privacy Act of 2018.
  • "GDPR" means Regulation (EU) 2016/679 of the European Parliament and of the Council.
  • "Personal Data" means any information relating to an identified or identifiable natural person.
  • "Processing" means any operation performed on Personal Data, such as collection, recording, storage, adaptation, or destruction.
  • "Subprocessor" means any third party appointed by or on behalf of Processor to process Personal Data.

3. Processing Instructions

Processor shall process Personal Data only for the purposes described in the Agreement or as otherwise agreed within the scope of Customer's lawful instructions, except where otherwise required by applicable EU or Member State law. The subject matter, nature, purpose, and duration of the Processing are set out in Annex A.

4. Confidentiality

Processor ensures that persons authorized to process the Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. This obligation survives the termination of the Agreement.

5. Security of Processing (TOMs)

Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of Processing, Processor shall implement appropriate technical and organizational measures ("TOMs") to ensure a level of security appropriate to the risk.

EncryptionAES-256 for data at rest. TLS 1.3 for all data in transit.
Access ControlStrict Principle of Least Privilege (PoLP) and MFA enforcement.
PrivacySeparating your identity from your learning data where possible.
ResilienceDaily encrypted backups with quarterly restoration testing.

6. Subprocessing

Customer grants Processor general authorization to engage Subprocessors. Processor shall maintain an up-to-date list of Subprocessors in Annex C. Processor shall verify that Subprocessors implement sufficient guarantees to protect the Personal Data. Processor shall notify Customer of any intended changes concerning the addition or replacement of Subprocessors.

7. Data Subject Rights

Taking into account the nature of the Processing, Processor shall assist Customer by appropriate technical and organizational measures, insofar as this is possible, for the fulfillment of Customer's obligation to respond to requests for exercising the Data Subject's rights laid down in Chapter III of the GDPR (including right of access, rectification, erasure, and portability).

8. Personal Data Breach

Processor shall notify Customer without undue delay after becoming aware of a Personal Data Breach. Such notification shall include, at a minimum: (a) the nature of the breach; (b) the categories and approximate number of Data Subjects concerned; and (c) the likely consequences and measures taken to mitigate possible adverse effects.

9. International Transfers

Where Personal Data is transferred from the EEA/UK/Switzerland to a country outside these regions that is not recognized as providing an adequate level of protection, the transfer shall be governed by the Standard Contractual Clauses (SCCs).

10. Audit Rights

Processor shall make available to Customer all information necessary to demonstrate compliance with the obligations laid down in this DPA and allow for and contribute to audits, including inspections, conducted by Customer or an auditor mandated by Customer.

11. Liability

Each party's liability for any breach of this DPA shall be subject to the limitations and exclusions of liability set out in the Main Agreement, except where such limitation is prohibited by applicable Data Protection Laws.

Annex A: Details of Processing

Subject Matter

The provision of the Mentrast Learning Platform and learning maps.

Duration

The term of the Agreement plus the period from expiry of the Agreement until deletion of all Customer Data.

Categories of Data Subjects

Employees, contractors, and end-users authorized by the Customer to use the Service.

Annex B: Security Measures

Description of the technical and organizational measures implemented by the Processor:

  • Identity & Access Management: Implementation of SSO, MFA, and strong password policies.
  • Network Security: Use of firewalls, IDS/IPS, and separation of production and non-production environments.
  • Physical Security: Data centers (via AWS/Vercel) compliant with SOC 2 Type II and ISO 27001.
  • Incident Response: Maintained Incident Response Plan with defined RTO/RPO objectives.
  • Vulnerability Management: Regular container scanning, dependency auditing, and annual penetration testing.

Annex C: Authorized Subprocessors

Vercel Inc.Hosting & Edge Compute | Location: USA
Approved
Supabase Inc.Database & Auth | Location: AWS East (USA)
Approved
Stripe Inc.Payment Processing | Location: USA
Approved