Data Processing Agreement
The Article 28 GDPR agreement that forms part of the Cloud Service Terms: how we process personal data on the Customer’s behalf.
Last updated: 20 August 2026
01Parties, integration and precedence
1.1. This Data Processing Agreement (the "DPA") is entered into between:
a) Nevergetold, Lda., legal person no. 510 372 945, with registered office at Rua Dr. Gomes Leal 3A, Torres Vedras, Portugal, commercially designated Modular Digital, privacy contact hello@modulardigital.pt (the "Processor", "Nevergetold" or "ModuHelp"); and
b) the legal person or sole trader identified in the registration, in the proposal or in the account (the "Customer" or "Controller", also designated "Tenant" in the ModuHelp Terms of Service).
1.2. The DPA forms part of the agreement relating to ModuHelp (the "Main Agreement") and takes effect on the date on which the Customer accepts it electronically or by signature. The person who accepts it on behalf of the Customer represents that they hold sufficient powers to bind the Customer.
1.3. In online contracting, the electronic confirmation identifies the Customer, the service, the version of the DPA and the date and time of acceptance, and allows the accepted text to be retained or downloaded.
1.4. In the event of conflict, this DPA prevails over the Main Agreement only as regards the processing of Personal Data on behalf of the Customer. The Standard Contractual Clauses (SCCs) applicable to an international transfer prevail over this DPA to the extent of the conflict.
02Definitions and roles of the Parties
2.1. The terms "personal data", "processing", "controller", "processor", "sub-processor", "data subject", "personal data breach" and "supervisory authority" have the meaning set out in Regulation (EU) 2016/679 ("GDPR").
2.2. "Customer Data" means the personal data processed in ModuHelp on behalf of the Customer and described in Annex I, including the data of the End Customers who contact the Customer through the service.
2.3. The Customer determines the purposes and essential means of the processing of Customer Data and acts as controller. Nevergetold processes it on behalf of and according to the documented instructions of the Customer, in its capacity as processor.
2.4. If the Customer processes data on behalf of another controller, it represents that it is authorised to engage Nevergetold as sub-processor and to transmit that controller's instructions. References to the Customer cover that capacity, where applicable.
2.5. Nevergetold acts as an independent controller in respect of the data necessary to manage its commercial relationship, account authentication and security, subscription billing, collection, fraud prevention, proof of contracting and legal compliance. Such processing is governed by the Privacy Policy and not by this DPA.
03Subject matter, scope and duration
3.1. This DPA governs the ongoing processing of Customer Data necessary for the hosting, operation, maintenance, security, support and provision of ModuHelp, including the artificial intelligence features, as detailed in Annex I.
3.2. The processing is not merely occasional: it takes place in an automated and continuous manner during the term of the Main Agreement and during the period of export, return, limited retention and deletion provided for in clause 16 and in Annex IV.
3.3. The DPA terminates when Nevergetold has deleted or returned all Customer Data, without prejudice to the obligations that must survive by law or by their nature.
04Description and limits of the processing
4.1. The subject matter, nature, purposes, operations, frequency, categories of data subjects and categories of data are set out in Annex I, which forms part of this DPA.
4.2. ModuHelp is not intended, by default, for the processing of special categories of data under Article 9 of the GDPR, data relating to convictions or offences, full payment card numbers, third-party passwords or other data subject to undocumented sector-specific requirements.
4.3. Support requests, messages, free-text responses, attachments and knowledge base content are defined and submitted by the Customer and its End Customers. The Customer must not configure channels, forms or flows intended to collect special categories of data without first informing Nevergetold, documenting the instruction, demonstrating the basis and the applicable safeguards, and obtaining confirmation that the service and the agreed measures are adequate.
4.4. It is the Customer's responsibility to apply minimisation, to avoid requesting unnecessary data from End Customers, to moderate the content it includes in the knowledge base used by the AI Features, and to configure proportionate retention periods.
05Documented instructions
5.1. Nevergetold processes Customer Data only on documented instructions, including this DPA, the Main Agreement, the configurations and actions of authorised users within the product, and written requests sent through an authenticated channel.
5.2. Nevergetold does not sell Customer Data, does not use it for behavioural advertising, and does not determine new purposes of its own that are incompatible with the instructions. In particular, it does not use Customer Data to train artificial intelligence models. The processing by the AI sub-processor is governed by that sub-processor's terms, identified in Annex III-A.
5.3. If a rule of Union or Member State law requires Nevergetold to process Customer Data without instruction, Nevergetold informs the Customer of that requirement in advance, unless legally prohibited on important grounds of public interest.
5.4. If it considers that an instruction infringes the GDPR or other applicable rule, Nevergetold informs the Customer without delay and may suspend the execution of the affected instruction until it is confirmed, amended, or its lawfulness is demonstrated.
5.5. Changes to scope, purpose, type of data or categories of data subjects that exceed Annex I require written instruction and, where they materially alter the risk or the cost, the prior agreement of the Parties.
06Customer obligations
6.1. The Customer warrants that the instructions, the collection and the processing of Customer Data are lawful and transparent and that it has a legal basis for each purpose, including support to End Customers, the communications it sends through the service, the retention, the attachments and the knowledge base content.
6.2. It is the Customer's responsibility, in particular, to:
a) provide End Customers with the information required by Articles 13 and 14 of the GDPR;
b) respond to data subjects and determine the merits of their requests;
c) ensure accuracy, minimisation and limitation of retention;
d) manage the users, permissions, devices and credentials of its organisation;
e) assess whether the service, including the AI Features and any automatic sending of responses, is adequate to its legal and sector-specific obligations;
f) obtain the authorisations, consents or other safeguards required for special categories, images or documents; and
g) not instruct Nevergetold to infringe the law or the rights of third parties.
6.3. The Customer keeps up to date a contact authorised to receive data protection and incident communications.
07Authorised persons and confidentiality
7.1. Nevergetold limits access to Customer Data to the persons who need it to operate, protect or support the service, in accordance with the principle of least privilege.
7.2. Such persons are subject to a legal duty or written commitment of confidentiality, receive adequate instructions and maintain the obligation after their role ceases.
7.3. Support access to an organisation's data is limited to what is necessary, authorised, logged where technically applicable and ended after the intervention.
08Security of processing
8.1. Nevergetold applies and maintains the technical and organisational measures of Annex II to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of the processing.
8.2. The measures aim at confidentiality, integrity, availability and resilience, the restoration of access in a timely manner following an incident, and the regular assessment of their effectiveness, in accordance with Article 32 of the GDPR.
8.3. Nevergetold may replace a measure with another that offers materially equivalent or superior protection, without reducing the overall level of security. Changes that materially reduce that level are communicated to the Customer.
8.4. No measure eliminates all risks. The Customer applies the measures under its control, including strong passwords, account limitation, review of permissions, secure devices and correct use of the features.
09Sub-processors
9.1. The Customer grants general authorisation to Nevergetold to engage the sub-processors identified in Annex III, exclusively to the extent necessary for the provision of the service.
9.2. Nevergetold concludes with each sub-processor a written agreement imposing data protection obligations no less protective than those applicable to the sub-contracted function, and remains liable to the Customer for that sub-processor's obligations, in accordance with Article 28(4) of the GDPR.
9.3. Nevergetold maintains an up-to-date list and informs the Customer, through the account contact, at least 15 days in advance of any intended addition or replacement, save in cases of urgency justified by security, continuity or legal requirement.
9.4. The Customer may object within that period, on concrete and reasonable data protection grounds. The Parties seek in good faith an alternative. If no reasonable solution exists, Nevergetold may withhold the affected functionality or either Party may terminate the part of the service that requires the new sub-processor, without prejudice to the mandatory rights and the economic conditions of the Main Agreement.
9.5. The authorisation does not cover third-party services that the Customer contracts and activates directly, as set out in Annex III-B.
10Location within the European Union
10.1. Nevergetold configures the primary location of the infrastructure in accordance with Annex III: application and database in a European Union region, cache only in European Union regions, R2 files with EU jurisdiction, Sentry monitoring (when enabled) in Frankfurt, and AI processing (Mistral) within the European Union.
10.2. Nevergetold does not deliberately add a storage or replica region outside the European Union without updating the applicable information and complying with clause 11.
10.3. The primary location within the European Union does not, in itself, exclude remote access, support, security, network routing or processing by entities and sub-processors located outside the EEA. The list in Annex III identifies those known situations.
10.4. Transactional email is subject to the specific conditions of the provider. As long as there is no contractual guarantee of exclusive residency within the European Union, Nevergetold does not present Postmark as a service of exclusively European residency and applies the safeguards of clause 11.
11International transfers
11.1. Any transfer or making available of Customer Data to a country outside the EEA occurs only where it is necessary for the provision of the service and a valid mechanism exists under Chapter V of the GDPR.
11.2. Nevergetold uses, as applicable and in the order legally available:
a) an adequacy decision of the European Commission;
b) the EU-US Data Privacy Framework, while valid and applicable to the recipient; or
c) the Standard Contractual Clauses approved by Implementing Decision (EU) 2021/914, as a rule Module 3 between processor and sub-processor, accompanied by the necessary supplementary measures.
11.3. Nevergetold assesses, with the support of the providers, the relevant legislation and practices of the third country, the nature of the data and the contractual, technical and organisational measures. Where it is not possible to ensure a level of protection that is essentially equivalent, it does not initiate the transfer or suspends it.
11.4. To the extent legally permitted, Nevergetold and its sub-processors assess requests from authorities, challenge those that are manifestly unlawful or disproportionate, limit disclosure to what is strictly required, and publish or make available aggregated information where possible.
11.5. Nevergetold makes available to the Customer, upon reasonable request and subject to confidentiality, information on the applicable mechanism and a copy of the relevant safeguards, and may redact commercial or security information that is not necessary to demonstrate compliance.
12Data subject rights
12.1. Taking into account the nature of the processing, Nevergetold assists the Customer, through appropriate technical and organisational measures, to respond to requests for access, rectification, erasure, restriction, portability, objection and other applicable rights.
12.2. If it receives directly a request relating to Customer Data, Nevergetold does not decide on its merits and forwards it to the Customer without undue delay, unless subject to a legal obligation to the contrary.
12.3. The Customer first uses the normal features for consultation, correction, export and deletion. Extraordinary assistance or assistance arising from the Customer's configuration may be subject to a quote, provided that this does not limit Nevergetold's legal obligations.
13Compliance assistance
13.1. Taking into account the nature of the processing and the information available, Nevergetold provides reasonable assistance to the Customer in complying with Articles 32 to 36 of the GDPR, including security, data breaches, impact assessments and prior consultations.
13.2. Nevergetold provides, upon reasonable request, information on the service, the security measures and the sub-processors that is necessary for the Customer's assessment. The Customer remains responsible for its impact assessment and for the decisions incumbent on it, including as regards the use of the AI Features.
14Personal data breaches
14.1. Nevergetold notifies the Customer without undue delay after confirming a personal data breach affecting Customer Data processed on its behalf.
14.2. The notification includes, to the extent the information is available:
a) the nature of the breach;
b) the categories and approximate number of data subjects and records affected;
c) the likely consequences;
d) the measures adopted or proposed to contain, investigate and mitigate; and
e) a point of contact for follow-up.
14.3. If it is not possible to provide all the information simultaneously, it is provided in phases without further undue delay. The notification does not constitute an acknowledgement of fault or liability.
14.4. It is the Customer's responsibility to assess and make the notifications to the supervisory authority and to data subjects, except where the law imposes a direct obligation on Nevergetold.
15Demonstration of compliance and audits
15.1. Nevergetold maintains the records required by Article 30(2) of the GDPR and makes available to the Customer the information necessary to demonstrate compliance with Article 28.
15.2. Wherever appropriate, Nevergetold may satisfy the request by means of certifications, independent audit reports, security questionnaires, test summaries and provider documentation.
15.3. If such information is insufficient, the Customer may carry out an audit or inspection, by itself or by an independent, non-competing auditor, at most once a year and subject to 30 days' written notice. These limits do not apply following a material incident, a requirement of an authority or a well-founded suspicion of non-compliance.
15.4. The audit must respect the confidentiality, security and rights of other customers, take place at reasonable times, be limited to the processing concerned, and avoid disproportionate disruption. The Customer bears its costs, unless the audit reveals material non-compliance attributable to Nevergetold.
15.5. Nevergetold informs the Customer if, in its view, an audit instruction infringes the law, the confidentiality of third parties or security, and proposes an alternative means of demonstration.
16Return, export and deletion
16.1. During the Agreement, the Customer may use the available features to export Customer Data in the supported formats and must prepare its recovery before termination.
16.2. Following termination, Nevergetold allows recovery during the period indicated in Annex IV. At the end of that period, it deletes or anonymises the data from the active systems, unless the Customer has requested earlier deletion or a rule requires retention.
16.3. Backups are deleted by overwriting in the normal cycle indicated in Annex IV. Until such deletion they remain isolated, protected and are not reused for any other purpose, save for restoration necessary following an incident.
16.4. If a rule requires certain Customer Data to be retained, Nevergetold informs the Customer where permitted, isolates it from further processing and retains it only for the legal period.
16.5. Upon request, Nevergetold confirms in writing the completion of the deletion, except for backups still within the documented cycle and data whose retention is legally required.
17Liability and termination for non-compliance
17.1. The liability of the Parties is governed by the GDPR, by the applicable law and by the Main Agreement, without limitation of the rights of data subjects or of liability that cannot be limited by agreement.
17.2. If Nevergetold is unable to comply with this DPA, it informs the Customer and adopts reasonable measures to remedy the non-compliance. If the non-compliance is material and is not remedied within a reasonable period, the Customer may suspend the affected processing or terminate the corresponding component of the service.
17.3. Termination does not prejudice the obligations of confidentiality, assistance, return, deletion and demonstration of compliance that must survive.
18Communications and final provisions
18.1. Data protection communications are sent to the contacts maintained in the Customer's account and, for Nevergetold, to hello@modulardigital.pt, without prejudice to any specific channel communicated during the incident.
18.2. The Customer keeps its contacts up to date. A change of contact does not constitute a material amendment of this DPA.
18.3. This DPA is governed by Portuguese law, without prejudice to the direct application of the GDPR, the powers of the supervisory authorities and the rules of the SCCs.
18.4. If a provision is invalid, it is limited or replaced to the extent necessary, with the remaining provisions remaining in force.
19Annex I: Description of the processing
Subject matter: Ongoing hosting and operation of ModuHelp on behalf of the Customer, for the management of and response to the support requests of the Customer's End Customers, with the aid of artificial intelligence features.
Nature and operations: Receipt of support requests by email forwarded to the assigned address, through the widget embeddable on the Customer's website and through a shareable contact page; creation, organisation and threading of tickets and messages; management of a shared inbox; classification and drafting of proposed responses by language models; sending of responses, including automatic sending where the Customer enables it; maintenance of a knowledge base; recording; structuring; retention; consultation; search (including vector search); export; restriction; deletion; support and security.
Purposes: To centralise and respond to the support requests of the Customer's End Customers; to classify and prioritise requests; to draft and, when enabled, send responses; to maintain a support history; to make available exports and reports; to prevent abuse; to provide support and to maintain the service.
Frequency: Continuous and determined by the use of the Customer and its data subjects. The transmission of content to the AI sub-processor occurs when a classification or drafting of a response is initiated or configured.
Duration: Term of the Main Agreement, recovery period and limited backup cycles of Annex IV.
Data subjects: End Customers who contact the Customer through the service (by email, widget or shareable page); persons mentioned in the content of the requests, messages, attachments or knowledge base; administrative users (agents) of the Customer.
Identification and contact: Name, email address, and other identifiers or contacts that the End Customer provides or that the Customer configures.
Support content: Subject and body of the messages, ticket history, status and priority, free-text responses, internal notes, attachments and uploaded files, and knowledge base content defined by the Customer.
Data generated by AI: Classifications, suggestions and proposed responses produced by the AI Features from the content above and from the Customer's knowledge base.
Technical and security data: IP address, date and time, session/device identifiers, browser, authentication logs, audit events, errors, telemetry and metadata necessary for security and operation.
Special categories: Not provided for by default. They may be introduced by End Customers or by the Customer in free text or attachments; they are admitted only under clause 4.
20Annex II: Technical and organisational measures
1. Architecture and segregation. Multi-tenant SaaS instance with identification and logical scoping of the Customer in application operations, authorisation controls and tests intended to prevent cross-organisation access, including in the matching of messages to tickets.
2. Transmission and storage. TLS on external connections and to databases/services that support it; private storage; encryption at rest provided by the providers; credentials and integration secrets encrypted at the application level.
3. Identity and access. Individualised accounts, password hashing, session management, role-based permissions, least privilege, revocation of access and separation between platform administration and Customer users.
4. Secrets. Production keys and credentials outside the source code, in variables protected by the hosting provider; rotation in case of suspected exposure; prohibition of secrets in repositories and logs.
5. Files. Private R2 bucket, access through the application or temporary/authorised mechanisms, validation of permissions by organisation and EU jurisdiction configured.
6. Public surface and minimisation. The embeddable widget and the shareable page operate without analytics, advertising or profiling cookies and without cross-site tracking, with short-lived tokens associated with the page and the moment, without prejudice to the technical information strictly necessary for the anti-bot verification; the Redis cache is limited to strictly necessary technical data and is not used as a primary store, a deliberate content queue or a repository of End Customer content; limitation of the data sent to email, monitoring, AI and payments.
7. AI Features. The content transmitted to the AI sub-processor is limited to what is necessary to classify or draft responses; Customer Data is not used for model training; the Customer may require human approval and disable the automatic sending of responses at any time.
8. Logging and monitoring. Technical and security logs adequate for detection and investigation, with exclusion or masking of passwords, tokens, keys and unnecessary content.
9. Development and changes. Version control, review of changes, adequate separation of environments, testing before production, controlled migrations and the possibility of rollback proportionate to the risk.
10. Vulnerabilities. Updating of the system, framework and dependencies, analysis of alerts, correction prioritised by risk and security testing proportionate to the exposure.
11. Availability and recovery. Separate web and worker components; managed database; Supabase backups/PITR in accordance with the contracted plan; own versioning, retention and recovery policy for R2; periodic restore tests.
12. Incidents. Process of identification, containment, preservation of evidence, assessment, communication, recovery and lessons learned, with defined responsible persons and contacts.
13. Providers. Assessment of DPA, location, sub-processors, security, transfers and relevant changes before contracting and during the relationship.
14. Personnel continuity. Confidentiality commitments, training appropriate to the role and timely removal of access when a person changes role or ceases to collaborate.
15. Rights, portability and erasure. Consultation, export and deletion functions delimited by Customer, an exit procedure and controlled erasure according to Annex IV.
16. Review. Periodic assessment of the effectiveness of the measures and updating following a material change, incident or relevant change of risk.
21Annex III-A: Sub-processors
DigitalOcean, LLC, App Platform. Function and data: Execution of the application, worker, network and infrastructure logs; may process the Customer Data necessary for operation. Location: Frankfurt, Germany (EU). Observations: Global/US entity; provider's DPA; DPF/SCCs where applicable; there may be international support or access.
Supabase, Inc., PostgreSQL and vector search. Function and data: Primary database, sessions, queues, locks, operational state and vector search indexes of the knowledge base. Location: Project in an EU region, preferably Frankfurt, Germany. Observations: Global/US entity; provider's DPA; the selected region defines the primary storage, without excluding authorised international sub-processors/access.
Cloudflare, Inc., R2 and network. Function and data: Private files and attachments; DNS, CDN, TLS, custom domains and anti-bot verification (Turnstile) in the embeddable widget and on the shareable contact page, collecting the client-side signals necessary for that verification, namely IP address and User-Agent, that verification being carried out by us in our capacity as controller and not on behalf of the Tenant, and listed here for transparency. Location: R2 with EU jurisdiction; globally distributed edge network. Observations: The jurisdiction restriction must be enabled and evidenced; edge traffic and support may involve other countries; provider's DPA/transfer mechanism.
Upstash, Inc., Redis. Function and data: Temporary technical cache and queues; not a primary database. Location: Primary region and any replicas only within the EU, preferably Frankfurt and/or Ireland. Observations: Do not enable a replica outside the EU. Global/US entity; DPA and SCCs/measures applicable to international access.
AC PM LLC / Postmark, transactional and inbound email. Function and data: Addresses, names, subject, content and metadata necessary for the receipt of forwarded support requests and for the sending of responses and notifications. Location: No public guarantee of exclusive residency within the EU. Observations: The provider's DPA provides for international processing/transfers and SCCs. Replace or obtain a specific guarantee if exclusive EU residency is a requirement.
Mistral AI SAS, language models. Function and data: Content of requests, messages and knowledge base transmitted for classification and drafting of proposed responses; results returned to the application. Location: European Union (France). Observations: Processing within the EU. Governed by Mistral's terms (Data Processing Addendum and Privacy Policy at legal.mistral.ai). Under those terms, data sent through the API is not used for training; automated moderation applies, except where zero data retention is enabled.
Functional Software, Inc. / Sentry, optional. Function and data: Errors, stack traces and technical metadata; personal data should be filtered/minimised. Location: Sentry organisation in the EU region, Frankfurt, Germany. Observations: Included in the list only if enabled. US entity; the EU region does not exclude international access; DPA/DPF/SCCs and filtering are mandatory.
22Annex III-B: Independent processing not qualifying as sub-processing of ModuHelp
Stripe (Nevergetold). Flow: Billing of the ModuHelp subscription to the customer organisation. Qualification: Independent processing by Nevergetold relating to the account/billing; outside the scope of this DPA and covered by the Privacy Policy and by Stripe's terms.
ModuHelp does not process End Customer payments nor integrate payment providers on behalf of the Customer. Should this change, the roles and Annex III must be revised before the alteration of the service.
23Annex IV: Retention, recovery and deletion
Active Customer Data (tickets, messages, attachments, knowledge base): During the Agreement and, following termination or a workspace deletion request, a recovery period of 30 days; thereafter, deletion/anonymisation from the active systems.
Database in backups/PITR: Automatic overwriting in the Supabase backup cycle, with a maximum limit of 7 days after deletion of the active system.
R2 files and attachments and versions: Active deletion at the end of the 30-day recovery period; no version retention is kept beyond that period.
Application, security and infrastructure logs: 14 days (daily rotation), reduced where not necessary for security, support or evidence.
Upstash cache/queues: Short technical expiry defined by the application; automatic deletion or by invalidation; never used as a store.
Content transmitted to the AI (Mistral): Not retained by Nevergetold beyond what is necessary for processing; retention by Mistral is governed by its terms (automated moderation for abuse prevention, except where zero data retention is enabled).
Transactional and inbound email: According to the retention configured/contracted with the provider, limited to what is necessary for delivery, support and evidence.
Data subject to legal retention: Only the elements required, isolated and for the applicable legal period.
The subscription billing data, commercial contacts and proof of acceptance processed by Nevergetold as an independent controller are subject to the Privacy Policy and to their own legal periods, not to this Annex.
24Annex V: Identification and electronic acceptance
Controller: Name, NIPC/registration number, registered office and country of the Customer.
Representative: Name, professional email, role and declaration of powers.
Processor: Nevergetold, Lda., NIPC 510 372 945, Rua Dr. Gomes Leal 3A, Torres Vedras, Portugal.
Service: ModuHelp and the plan/instance identified in the confirmation.
DPA version: Immutable identifier and effective date of the version presented.
Acceptance: Date and time, authenticated user, event of a non-pre-selected checkbox and submission; IP/user-agent only if necessary, proportionate and disclosed.
Associated documents: Version of the Terms of Service, subscribed plan and a link or downloadable copy of the accepted documents.
Customer contact: Address for privacy, incidents and sub-processor changes.