Legal

Data Processing Agreement

Last updated: 31 July 2026

This Data Processing Agreement (“DPA”) forms part of the agreement between the customer using Mind Weave (“Customer”) and Traciq Innovation LLC (“Traciq”) for the Mind Weave services (the “Services”). It applies when Traciq processes Customer Personal Data on Customer’s behalf. If there is a conflict, this DPA controls for that processing.

1. Definitions

Applicable Data Protection Law
means laws applicable to the processing of Customer Personal Data, including the GDPR, UK GDPR, and applicable national privacy or data-protection laws.
Customer Personal Data
means personal data contained in content or information submitted to the Services by or for Customer and processed by Traciq on Customer’s behalf.
Controller, Processor, Data Subject, Personal Data, Processing, and Supervisory Authority
have the meanings given to them by Applicable Data Protection Law.
Personal Data Breach
means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Customer Personal Data.
Subprocessor
means a third party appointed by Traciq to process Customer Personal Data on Customer’s behalf.

2. Roles and instructions

Customer is the Controller and Traciq is the Processor of Customer Personal Data, except where Customer acts as a Processor for another Controller, in which case Traciq acts as Customer’s Subprocessor. Customer instructs Traciq to process Customer Personal Data to provide, secure, maintain, support, and improve the Services; comply with the agreement and Customer’s documented use of the Services; and follow other lawful written instructions agreed by the parties.

Traciq will process Customer Personal Data only on documented instructions unless law requires otherwise. Where permitted, Traciq will inform Customer before legally required processing. Traciq will promptly notify Customer if, in its opinion, an instruction violates Applicable Data Protection Law.

3. Customer responsibilities

Customer will:

  • Provide lawful instructions and comply with its obligations as Controller.
  • Ensure it has all notices, permissions, and legal bases needed for Traciq to process Customer Personal Data.
  • Use the Services and share-link features in accordance with law and appropriate security practices.
  • Limit Customer Personal Data to what is relevant and proportionate for its use of the Services.
  • Respond to Data Subject requests and regulator inquiries for which it is responsible.

4. Confidentiality and personnel

Traciq will ensure that personnel authorised to process Customer Personal Data are subject to appropriate confidentiality obligations and receive access only as necessary for their responsibilities. Traciq remains responsible for its personnel’s compliance with this DPA.

5. Security

Taking into account the state of the art, implementation costs, and the nature, scope, context, and purposes of processing, Traciq will maintain appropriate technical and organisational measures designed to protect Customer Personal Data. These measures include, as appropriate:

  • Encryption of data in transit and security controls provided by our hosting infrastructure.
  • Access controls, secure session handling, and least-privilege access practices.
  • Logging, monitoring, vulnerability management, and incident-response procedures.
  • Resilience, recovery, and periodic review of safeguards appropriate to the Services.

Customer is responsible for securely configuring its use of the Services, controlling account and share-link access, and evaluating whether the Services are appropriate for the data it submits.

6. Personal Data Breaches

Traciq will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data. The notice will include information reasonably available to help Customer meet its notification obligations. Traciq will take reasonable steps to contain, investigate, and mitigate the incident. Notification is not an acknowledgement of fault or liability.

7. Data Subject and compliance assistance

Taking into account the nature of processing, Traciq will provide reasonable assistance to Customer with Data Subject requests. If Traciq receives a request concerning Customer Personal Data directly, it will forward the request to Customer unless prohibited by law and will not respond on Customer’s behalf without authorisation.

Traciq will also provide reasonable assistance with security, regulatory notifications, data-protection impact assessments, and consultations with Supervisory Authorities, taking into account the information available to Traciq and the nature of processing.

8. Subprocessors

Customer gives Traciq general authorisation to appoint Subprocessors. Traciq will impose data-protection obligations materially consistent with this DPA and remain responsible for their performance. Current categories and providers include:

ProviderPurpose
Cloudflare, Inc.Application hosting, database, delivery, security, and infrastructure services.
Google LLCOptional account authentication and identity information.
Stripe, Inc.Subscription checkout, billing management, and payment records.

Customer may object to a new Subprocessor on reasonable data-protection grounds by contacting Traciq within 15 days after notice. The parties will work in good faith on a reasonable solution. If none is available, Customer may discontinue the affected feature.

9. International transfers

Traciq will ensure that international transfers of Customer Personal Data use a lawful transfer mechanism where required, which may include an adequacy decision, the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, or another recognised safeguard. The parties will execute additional transfer documents reasonably necessary to comply with Applicable Data Protection Law.

10. Return and deletion

During the term, Customer may delete cloud maps through the Services. On termination or written request, Traciq will delete or return Customer Personal Data within a reasonable period, unless retention is required by law. Data retained in backups will remain protected and be deleted in accordance with applicable backup cycles. Traciq may retain information that has been irreversibly anonymised.

11. Information and audits

Traciq will make information reasonably necessary to demonstrate compliance with this DPA available on written request. No more than once per year, unless required by a regulator or following a confirmed Personal Data Breach, Customer may request an audit. Audits must be conducted during normal business hours, with reasonable notice, under confidentiality, without disrupting operations or exposing another customer’s information. Customer is responsible for its audit costs.

12. Processing details

Subject matter
Operation of a local-first and cloud-enabled mind-mapping workspace, including account, sync, sharing, and subscription features.
Duration
For the term of the Services and the limited period needed for deletion, backups, or legal retention.
Nature and purpose
Collection, storage, organisation, retrieval, transmission, display, deletion, security, support, and other processing needed to provide the Services on Customer’s instructions.
Data Subjects
Customer’s users, personnel, collaborators, contacts, and individuals whose personal data Customer includes in maps or related content.
Personal Data
Names, email addresses, profile data, account identifiers, map content, notes, uploaded images, links, collaboration and sharing data, and technical or usage data included in Customer content.
Sensitive data
The Services are not designed for special-category or highly sensitive personal data. Customer must not submit such data unless lawful, necessary, and subject to appropriate safeguards.
Frequency
Continuous or occasional, depending on Customer’s use of cloud-enabled features.

13. Term and contact

This DPA remains effective while Traciq processes Customer Personal Data. Liability and governing-law terms in the main agreement apply to this DPA unless Applicable Data Protection Law requires otherwise. Requests for a signed copy or questions about this DPA may be sent to inquiry@mindweave.work.