Data Processing Agreement
Last updated: 2026-07-20
1. Introduction and Scope
This Data Processing Agreement (“DPA”) supplements the Mintgrove Terms of Service (the “Agreement”) between Mintgrove LLC (“Mintgrove,” “we,” “us,” or “our”) and the App Company that has agreed to the Agreement (“App Company,” “you,” or “Customer”). This DPA applies where Mintgrove processes personal data on your behalf in the course of providing the Mintgrove platform.
This DPA is incorporated into and forms part of the Agreement. In the event of a conflict between this DPA and the Agreement regarding the processing of personal data, this DPA controls.
Roles.For personal data of your Buyers' individual employees who are assigned seat licenses (“Seat Holders”), Mintgrove processes that data as a processor, acting only on your documented instructions. You (the App Company) act as controllerof your end-user/customer data. Buyer organizations act as their own independent controllers of their own organization's data. Mintgrove does not determine the purposes or means of processing Seat Holder or Buyer personal data beyond what is necessary to provide the platform — see Section 4 (Processor Obligations). Separately, and outside the scope of this DPA, Mintgrove acts as an independent controller of your (the App Company's) own account, billing, and contact data in connection with Mintgrove's Platform Fee and Revenue Share billing relationship with you — see Privacy Policy Section 2. This role structure is consistent with Section 10 of the Terms of Service.
2. Definitions
Capitalized terms not defined in this DPA have the meanings given in the Agreement or the Privacy Policy. In addition:
“Personal Data” means any information relating to an identified or identifiable natural person that Mintgrove processes on your behalf under this DPA.
“Processing” means any operation performed on Personal Data, including collection, storage, use, disclosure, and deletion.
“Data Protection Laws” means all applicable laws relating to the processing of Personal Data, including the EU GDPR, UK GDPR, and equivalent US state laws, as applicable.
“Sub-processor”means any third party engaged by Mintgrove to process Personal Data on Mintgrove's behalf in order to provide the platform.
3. Subject Matter, Duration, and Purpose of Processing
Subject matter:Mintgrove's processing of Personal Data in connection with providing enterprise access management infrastructure — seat license issuance, entitlement sync, access grant/revoke, billing, and related account operations.
Duration: For the term of the Agreement, plus the wind-down and data-export period described in Section 9 (Return and Deletion of Data) and Section 12 of the Terms of Service.
Nature and purpose: Operating the seat/entitlement lifecycle (assignment, activation, deactivation, revocation), syncing access grants to your configured in-app access provider (e.g., Adapty), processing seat license transactions through your Connected Billing Account, sending renewal reminders white-labeled as your identity, and maintaining audit history of the above.
4. Processor Obligations
Where Mintgrove processes Personal Data on your behalf as a processor, Mintgrove will:
- Process Personal Data only on your documented instructions (which include the instructions embedded in your platform configuration — e.g., pricing tiers, integration settings — and the ordinary operation of the platform as described in the Agreement), unless required to do otherwise by law, in which case Mintgrove will inform you before processing (unless legally prohibited from doing so). If Mintgrove reasonably believes an instruction infringes Data Protection Laws, Mintgrove will immediately inform you, and may suspend performance of that instruction pending your confirmation or revision of it.
- Ensure that personnel authorized to process Personal Data are subject to confidentiality obligations (see Agreement Section 9).
- Implement the technical and organizational measures described in Section 6 and Annex II below.
- Not engage a Sub-processor without providing notice as described in Section 7.
- Assist you, taking into account the nature of processing, in responding to data subject requests and in meeting your own obligations under Data Protection Laws (security, breach notification, and data protection impact assessments), to the extent Mintgrove has the relevant information and the request relates to data processed via the platform.
- Notify you without undue delay, and in any event within 72 hours of becoming aware, of a Personal Data breach affecting data processed under this DPA. To the extent known at the time of notice, the notification will describe: the nature of the breach, including where possible the categories and approximate number of data subjects and records concerned; the name and contact details of a point of contact for further information; the likely consequences of the breach; and the measures taken or proposed to address it and mitigate its effects. Where information is not available within 72 hours, Mintgrove will provide it in phased updates without undue further delay as it becomes available, and will cooperate with you in good faith on your own downstream notification obligations (including your own 72-hour Article 33 clock, where applicable).
- Maintain records of processing activities carried out on your behalf sufficient to support your own Article 30(2) recordkeeping obligations, and make a summary of those records available to you on request.
- Make available to you the information reasonably necessary to demonstrate compliance with this Section 4, and allow for and contribute to audits as described in Section 8.
- At your written request, and subject to Section 9, delete or return Personal Data at the end of the provision of services, except where retention is required by law.
5. Categories of Data Subjects and Personal Data
Categories of data subjects:Your Buyer organizations' administrators, and individual Seat Holders assigned a seat license through your app.
Categories of Personal Data:consistent with the data inventory in the Privacy Policy (Sections 3–4) and covering, at minimum:
- Buyer organization admin contact details (name, email)
- Seat Holder email address and name (where provided)
- Seat assignment status and access grant/revoke history
- Transaction data (purchase amounts, dates, payment status)
- Magic-link authentication events (email address, timestamp)
- Invite links / access codes (time-limited, redacted once expired)
- Audit and webhook delivery logs referencing the above
- SSO/SCIM mapping metadata (Enterprise accounts only, where applicable)
Mintgrove does not process special categories of Personal Data (Art. 9 GDPR) and you agree not to submit special category data to the platform.
6. Security Measures
Mintgrove implements the technical and organizational measures (“TOMs”) set out in Annex II to Exhibit A of this DPA. Annex II is version-controlled: it reflects the measures in place as of the “Last updated” date of this DPA, changes to it are tracked, and it supersedes any general reference to security practices described elsewhere (including the Privacy Policy). Where Mintgrove obtains a third-party security certification (e.g., SOC 2) in the future, that certification will supplement, and where applicable be referenced from, Annex II.
7. Sub-processors
You provide general authorization for Mintgrove to engage the following Sub-processors, each of which processes Personal Data only to the extent necessary to provide its function to Mintgrove and is bound by data protection obligations no less protective than this DPA:
| Sub-processor | Function |
|---|---|
| Supabase | Database, authentication infrastructure |
| Vercel | Application hosting |
| Stripe | Payment/checkout and transaction metadata processed via your Connected Billing Account, for purposes of operating seat license transactions on your behalf (subprocessor role only — see note below) |
| Resend | Transactional email delivery |
| Adapty | In-app access/entitlement sync (only where you have connected this integration) |
Stripe — two distinct relationships.Stripe appears in this table solely in its capacity as a data processor/subprocessor for the checkout and transaction metadata Mintgrove handles on your behalf as part of operating the seat-license transaction flow through your Connected Billing Account. This is separate from, and does not extend to, (a) your own independent relationship with Stripe as the merchant of record for your Buyer transactions (Terms of Service Section 5), where you are Stripe's customer and Stripe's Connect terms govern directly between you and Stripe — Mintgrove is not a party to and does not assume audit, flow-down, or other subprocessor-type obligations with respect to that relationship; or (b) Mintgrove's own use of Stripe Billing to charge you the Platform Fee and Revenue Share, which is a Mintgrove-as-controller relationship outside the scope of this DPA (see Privacy Policy Section 5). This split mirrors Privacy Policy Sections 5 and 6.
Klaviyo.Klaviyo is not a Mintgrove Sub-processor and does not appear in this table. Where an App Company connects or uses Klaviyo, Klaviyo is the App Company's own vendor, engaged and instructed directly by the App Company, and Mintgrove has no processing relationship with Klaviyo on your behalf. This is consistent with Privacy Policy Section 5.
Notice and objection.Mintgrove will provide notice of any new Sub-processor, or any change to an existing Sub-processor's function, by updating this list and notifying you by email or in-platform notice at least 30 days before the change takes effect (this 30-day notice period applies uniformly, without a separate “material change” carve-out). During that notice period, you may object on reasonable data-protection grounds by contacting privacy@mintgrove.co. If you object, Mintgrove will discuss the objection with you in good faith; if the parties are unable to reach a resolution, you may terminate the affected service(s) (or, where the new Sub-processor is not reasonably severable from the platform, the Agreement) without penalty, effective on written notice, with respect to the data processing at issue.
Mintgrove intends to stand up a public subprocessor list page (with change history and an email subscription option) referenced from this Section; until that page is live, this table and the notice mechanism above remain the governing record.
8. Audit Rights
Mintgrove's compliance with this DPA can be demonstrated, and audited, through a layered process:
- Documentation and self-assessment (ordinary course). On request, no more than once per year absent cause, Mintgrove will make available its current documentation regarding the measures in Section 6/Annex II, a completed security questionnaire, and (when available) any third-party security certification or audit report Mintgrove holds (e.g., SOC 2).
- Inspection (on cause).Where (a) required by a supervisory authority with jurisdiction over your processing, (b) requested following a confirmed Personal Data breach affecting your data, or (c) the documentation provided under (1) is not reasonably sufficient to demonstrate compliance, you (or an independent, mutually agreed third-party auditor bound by confidentiality) may audit and inspect Mintgrove's relevant processing operations and records, on at least 30 days' written notice, during normal business hours, no more than once per year absent further cause, at your cost, and subject to reasonable confidentiality and security restrictions to protect Mintgrove's other customers' data and systems.
Mintgrove will cooperate in good faith with audits and inspections conducted under this Section and will revisit this Section — including expanding the certifications referenced in (1) — as its security program matures.
9. Return and Deletion of Data
This section governs the export/deletion obligation referenced in Terms of Service Section 12 (“Offboarding process”).
Upon termination or expiry of the Agreement, and following your written request made during the wind-down period described in Terms of Service Section 12:
- Format and delivery:Mintgrove will make available an export of your App Company's account data (App Company records, Buyer org records, seat assignment history, transaction history, and audit logs relating to the above) in a standard machine-readable format (CSV or JSON). The export will be delivered via a time-limited, authenticated download link (not email attachment) to reduce transmission risk.
- Timing: The export will be made available within 15 business days of your request.
- Data minimization:The export will include only data associated with your own App Company account — not data belonging to other App Companies, and not full payment card data (which Mintgrove does not store; see Privacy Policy Section 3).
- Deletion after export: Following delivery of the export (or 30 days after the wind-down period ends, whichever is earlier, if no export is requested), Mintgrove will delete or anonymize Personal Data associated with your account, except where retention is required by law or for legitimate audit purposes consistent with the retention periods in Privacy Policy Section 7.
- Confirmation: Mintgrove will confirm deletion in writing upon request.
10. International Data Transfers
Where Personal Data is transferred outside the region in which it originated (e.g., from the EEA/UK to the United States), the transfer is governed by the Standard Contractual Clauses referenced in Privacy Policy Section 6 and set out in Exhibit A to this DPA (incorporating, by reference, the European Commission's Standard Contractual Clauses for the transfer of personal data to third countries under Regulation (EU) 2016/679, adopted 4 June 2021 (Commission Implementing Decision (EU) 2021/914), Module Two: Controller to Processor, and, for transfers subject to UK GDPR, the UK Information Commissioner's International Data Transfer Addendum to those Clauses). For App Companies established in the EEA or UK, Exhibit A is auto-incorporated at the point of clickwrap acceptance, rather than requiring a separate signature step. Exhibit A completes the Annexes required by the Clauses and is accompanied by a lightweight transfer impact assessment. Mintgrove does not rely on the EU-U.S. Data Privacy Framework or its UK/Swiss extensions as a transfer mechanism. In the event of a conflict between this DPA and Exhibit A regarding the transfer of Personal Data, Exhibit A controls.
11. Liability
Each party's liability arising out of or related to this DPA is subject to the limitations of liability set out in Section 14 of the Terms of Service.
12. Term
This DPA takes effect on the date you agree to the Agreement and remains in effect for as long as Mintgrove processes Personal Data on your behalf, including during the wind-down period described in Section 9 above.
13. General
This DPA is governed by the same governing law as the Terms of Service (Section 16). If any provision of this DPA is found invalid or unenforceable, the remaining provisions continue in full force.
Exhibit A — Standard Contractual Clauses
This Exhibit A forms part of the DPA and implements Section 10 above.
Incorporation.The Parties agree that the Standard Contractual Clauses referenced in Section 10 (Module Two: Controller to Processor, together with the UK International Data Transfer Addendum where applicable) are incorporated into this DPA in their entirety, in the exact form published by the European Commission and the UK Information Commissioner's Office respectively, and are completed by the Parties as set out in the Annexes below.
Note to counsel: attach the full, unmodified text of the Clauses (as officially published) as an appended exhibit or referenced link rather than retyping them — the Clauses cannot be modified and transcription risk in a binding legal instrument should be avoided. The Annexes below are drafted to drop directly into that attached text.
Annex I.A — List of Parties
- Data exporter: The App Company, as identified in the Agreement (name, address, and contact details as provided at Mintgrove account signup).
- Data importer: Mintgrove LLC, 790 Newark Rd, Island Pond, VT 05846, privacy@mintgrove.co.
Annex I.B — Description of Transfer
Categories of data subjects, categories of Personal Data, and the nature, purpose, and duration of processing are as set out in DPA Sections 3 and 5 above.
Annex I.C — Competent Supervisory Authority
The supervisory authority of the EU member state in which the data exporter's EU representative is established (or, absent an EU representative, the supervisory authority of the EU member state in which the data subjects whose Personal Data is transferred are principally located); for UK transfers, the UK Information Commissioner's Office.
Annex II — Technical and Organizational Measures
Mintgrove implements the following technical and organizational measures. This Annex is version-controlled as of the “Last updated” date of this DPA; material changes will be reflected in a dated revision.
- Encryption in transit: All data in transit between clients, the Mintgrove platform, and sub-processors is encrypted using TLS.
- Encryption at rest: Data at rest, including stored integration credentials, is encrypted at rest.
- Access control and multi-tenancy isolation: Row-level security policies scope data access by organization/account; access to production data is further restricted by role-based access controls (RBAC) limiting personnel access to what is necessary for their role.
- Logging and monitoring: Personally identifiable information is masked in application logs and internal tooling; access to production systems and data is logged.
- Vendor management: Sub-processors are engaged only where bound to data protection obligations no less protective than this DPA, per Section 7.
- Incident response: Mintgrove maintains an internal process for identifying, triaging, and responding to security incidents, feeding the breach-notification commitments in Section 4.
- Backup and recovery: Production data is backed up on a recurring basis to support recovery in the event of data loss.
- Secure development: New features are reviewed for security considerations before release.
This Annex reflects current practice at Mintgrove's prototype/early-stage of operation. As Mintgrove's security program matures (including any future formal certification such as SOC 2), this Annex will be revised and the revision dated accordingly; changes are governed by Section 7's sub-processor/DPA-update notice process where they affect App Company rights, and otherwise take effect prospectively on posting of a dated revision.
Annex III — List of Sub-processors
As set out in DPA Section 7 (Sub-processors) above.
This document cross-references Terms of Service Sections 5, 12, 14, and Privacy Policy Sections 2, 5, 6, and 7 — if those change, this document needs a consistency pass.