The English version is legally governing; Arabic translation coming soon.
Data Processing Addendum (DPA)
Version 1.0 — August 11, 2026 — published for customer review; executed as part of each customer’s signed agreement. This addendum reflects our standard processing terms and is subject to counsel review in the customer’s jurisdiction before signature.
1. Roles and scope
For personal data submitted to a Customer Instance (“Service Data” — including student profiles, enrollment records, activity events, and conversation content), the customer is the controller and Molab LLC is the processor. Much of this data relates to minors; the customer is responsible for the lawful basis, notices, and any parental consents its own service requires, and Molab designs the service so each customer’s data stays architecturally isolated.
2. Instructions
Molab processes Service Data only: (a) to provide, secure, and support the Customer Instance; (b) as documented in the agreement and this DPA; and (c) per the customer’s other documented instructions. Molab does not use Service Data for advertising, profiling for its own purposes, or training models.
3. Confidentiality and personnel
Access to Service Data is limited to personnel who need it to deliver the service and who are bound by confidentiality obligations.
4. Security measures
- One dedicated, isolated instance per customer: separate application, database, and storage; no shared database and no cross-customer access path.
- Hosting in EU data centers; TLS encryption in transit on all connections.
- Server-side HMAC verification of end-user identity.
- Scheduled database backups, with restore procedures tested before go-live.
- Secrets management separated from code; least-privilege operational access.
5. Sub-processors
The current list is published at /legal/subprocessors. The customer consents to those sub-processors and will be notified of intended additions or replacements at least 30 days before they take effect, with the right to object on reasonable data-protection grounds.
6. Assistance
Taking into account the nature of the processing, Molab will reasonably assist the customer with data-subject requests (access, correction, deletion, export) and with the customer’s security and impact-assessment obligations.
7. Personal data breach
Molab will notify the customer without undue delay after becoming aware of a personal data breach affecting Service Data, and will provide information reasonably required for the customer’s own notification obligations as it becomes available.
8. International transfers
Service Data is hosted in the EU. Where a transfer of Service Data to a country without an adequacy finding is necessary (including operational access), the parties will rely on appropriate safeguards such as the EU Standard Contractual Clauses, incorporated into the signed agreement as needed.
9. Return and deletion
On termination or expiry, Molab will make Service Data available for export in a commonly used format and, after the customer confirms export (or after 30 days), delete Service Data from the instance and subsequently from backups in the ordinary backup cycle.
10. Audit
Molab will make available information reasonably necessary to demonstrate compliance with this DPA, and will allow audits as agreed in the signed agreement, no more than annually absent a supervisory-authority requirement or a material incident.