Data Processing Agreement — Munin Cloud
Last updated: 2026-08-31
This Data Processing Agreement ("DPA") governs our processing of personal data contained in Customer Data when your organisation uses Munin Cloud at app.getmunin.com, api.getmunin.com, and mcp.getmunin.com (the "Service").
It is entered into between:
- Apps AS, org. no. 922 222 045, Vulkan 16, 0178 Oslo, Norway ("Processor", "we", "us", "Munin"), and
- the organisation that accepted our Terms of Service ("Controller", "Customer", "you").
This DPA forms part of, and is incorporated by reference into, the Terms of Service. You do not need to sign it separately for it to apply — accepting the Terms accepts this DPA. If your procurement process requires a countersigned copy, email privacy@getmunin.com and we will execute one; we sign DPAs with any customer who processes personal data through Munin Cloud, regardless of plan.
This DPA implements Article 28 of Regulation (EU) 2016/679 ("GDPR"), as incorporated into Norwegian law by the Personal Data Act (personopplysningsloven). It follows the structure of the standard contractual clauses adopted by the European Commission under Article 28(7) GDPR in Implementing Decision (EU) 2021/915.
1. Order of precedence
In the event of a conflict, the following order applies, most authoritative first: (1) this DPA, (2) the Terms of Service, (3) the Privacy Policy. This DPA prevails over the Terms only in respect of the processing of personal data contained in Customer Data.
2. Definitions
"Controller", "processor", "sub-processor", "data subject", "personal data", "processing", "personal data breach", and "supervisory authority" have the meanings given in the GDPR.
"Customer Data" has the meaning given in Section 5 of the Terms of Service. "Customer Personal Data" means the personal data contained within Customer Data.
3. Roles of the parties
You are the controller of Customer Personal Data and we are your processor. Where you are yourself a processor acting for a third-party controller (for example, as an agency or a reseller's customer), we are a sub-processor and you warrant that you have the authority of that controller to appoint us on these terms.
This DPA does not cover the data for which we are an independent controller — account credentials, billing information, support correspondence, security and abuse logs, and aggregated anonymised service metrics. That processing is described in Sections 1 and 2 of the Privacy Policy and is not carried out on your instructions.
Where we derive aggregated or anonymised data from Customer Data, we will do so only in a form that no longer identifies any data subject and cannot reasonably be used to re-identify one, we will not attempt to re-identify it, and we will bind any recipient to the same obligation.
4. Subject matter and duration
The subject matter, nature and purpose of the processing, the categories of data subjects, and the types of personal data are set out in Annex I.
This DPA takes effect when you accept the Terms of Service and continues for as long as we process Customer Personal Data on your behalf. Sections 12 (deletion and return), 14 (audits), and 19 (liability) survive termination.
5. Processing on documented instructions
We will process Customer Personal Data only on your documented instructions, including with regard to transfers to a third country, unless required to do so by Union or Member State law to which we are subject — in which case we will inform you of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.
Your documented instructions consist of:
- this DPA and the Terms of Service;
- the configuration you set in the dashboard, via the REST API, or via MCP tools;
- the operations performed by users, API keys, connected admin agents, and end-user delegated tokens authorised under your organisation;
- any written instruction you subsequently send to privacy@getmunin.com and we accept in writing.
Purpose limitation. We will process Customer Personal Data only for the purposes set out in Annex I, unless you instruct us otherwise.
We will immediately inform you if, in our opinion, an instruction infringes the GDPR or other Union or Member State data-protection law. We may suspend performance of an instruction that we reasonably believe to be unlawful until it is withdrawn, amended, or confirmed; if you insist on compliance with such an instruction, we may terminate the Service under Section 16.
Actions performed by AI agents authorised under your organisation — whether connected by you via OAuth 2.1 or acting under delegated tokens you minted server-side — are your instructions for the purposes of this Section. This includes agents acting on content that reached them through an inbound channel; see Section 11.
We will not sell Customer Personal Data, use it to train AI models, or use it for our own purposes. We do not read or analyse the content of Customer Data except where strictly necessary to provide a feature you have enabled (for example, generating embeddings for kb_search) or to investigate a confirmed abuse or security report.
6. Confidentiality
We ensure that persons authorised to process Customer Personal Data are bound by an appropriate statutory or contractual obligation of confidentiality, and that access is granted only to the extent strictly necessary to implement, manage, and monitor the Service.
7. Security of processing
We implement appropriate technical and organisational measures under Article 32 GDPR. The measures in force at the effective date are described in Annex II, and we will implement at least those measures. We may update them over time provided the level of security is not materially reduced.
8. Sub-processors
You give us general written authorisation to engage sub-processors. The sub-processors authorised at the effective date are listed in Annex III.
We will notify account admins by email at least 30 days before adding or replacing a sub-processor, and will provide the information you need to decide whether to object. You may object on reasonable data-protection grounds within 30 days of that notice by writing to privacy@getmunin.com. We will work with you in good faith to address the objection; if we cannot, you may terminate the affected part of the Service without penalty before the change takes effect, and we will delete Customer Data in accordance with Section 12.
We engage each sub-processor under a written contract imposing, in substance, the same data-protection obligations as those in this DPA. We remain fully responsible to you for each sub-processor's performance, and we will notify you of any failure by a sub-processor to fulfil its obligations. On request we will provide you with a copy of the relevant sub-processor agreement and any subsequent amendments, redacted to the extent necessary to protect business secrets, other confidential information, or personal data.
Where a sub-processor's terms allow it, we will agree a third-party beneficiary clause under which, if we have factually disappeared, ceased to exist in law, or become insolvent, you may terminate the sub-processor contract directly and instruct the sub-processor to erase or return Customer Personal Data. Where a sub-processor contracts only on standard terms that do not permit this, we will tell you so on request.
The third-party providers you contract with directly and configure on your tenant with your own credentials — SMS, voice, custom SMTP/IMAP, and custom LLM or embedding endpoints — are not our sub-processors. They act under your contract, they are your processors, and you are responsible for the data-processing agreement and disclosures with them. We handle that data only in transit between your end-users and the provider you have chosen. See Section 4a of the Privacy Policy.
9. International transfers
All processing carried out by us and by our sub-processors takes place within the EU/EEA. Apps AS is established in Norway, an EEA state to which Union data-protection law applies, so processing by us is not a transfer to a third country.
We will not transfer Customer Personal Data outside the EEA without either an adequacy decision or appropriate safeguards under Chapter V GDPR, and any such transfer will be made only on your documented instructions or to satisfy a specific requirement of Union or Member State law to which we are subject. Where safeguards are required, the parties agree that the Standard Contractual Clauses adopted by the European Commission in Implementing Decision (EU) 2021/914 apply, Module Two (controller to processor) or Module Three (processor to processor) as appropriate, and that such a transfer would be notified as a sub-processor change under Section 8.
Transfers arising from the third-party providers you contract with directly under Section 8 are governed by your agreement with that provider, not by this DPA.
10. Government and law-enforcement access requests
If we receive a legally binding request from a public authority — including a law-enforcement or national-security authority — for disclosure of Customer Personal Data, we will:
- notify you of the request before disclosing anything, so that you can seek protective relief, unless we are legally prohibited from doing so;
- where notification is prohibited, use reasonable efforts to obtain a waiver of the prohibition and provide as much information as we lawfully can, as soon as we lawfully can;
- challenge the request where we have reasonable grounds to consider it unlawful, overbroad, or inconsistent with the GDPR, including by pursuing available appeals;
- disclose only the minimum amount of data lawfully required, based on a reasonable interpretation of the request.
We will keep a record of such requests and make it available to you on request, to the extent permitted by law. We do not grant any public authority direct, unfettered access to Customer Personal Data, and we have not created any means of access to our systems for that purpose.
11. Assistance to the Controller
Taking into account the nature of the processing and the information available to us, we will assist you by appropriate technical and organisational measures with:
- Data subject rights (Art. 12–23). The Service provides self-service access, export (
/v1/export/*and the dashboard), correction, and deletion for Customer Data, which is ordinarily sufficient for you to answer a request yourself. If a data subject contacts us directly about Customer Personal Data, we will promptly inform you and will not respond substantively unless you authorise us to. Where you cannot fulfil a request through the Service, we will assist on request and in accordance with your instructions. - Security (Art. 32). By maintaining the measures in Annex II and providing the information you reasonably need to assess them.
- Breach notification (Art. 33–34). As set out in Section 13.
- Data protection impact assessments and prior consultation (Art. 35–36). By providing the information about the Service reasonably necessary for your assessment.
- Accuracy. By informing you without delay if we become aware that Customer Personal Data we are processing is inaccurate or has become outdated.
For assistance materially exceeding what the Service provides self-service, we may charge a reasonable fee, notified in advance.
Prompt injection. Inbound channel content — email bodies, chat-widget messages, voice and SMS transcripts — may contain attempts to manipulate connected AI agents into processing personal data in ways you did not intend. We apply defences (sanitisation, constrained tool surfaces, scoped delegated tokens, audit logging) but cannot guarantee absolute prevention. Designing agent instructions, validating outputs before any consequential action, and supervising agent behaviour remain your responsibility as controller. We will work with you in good faith to investigate any incident.
12. Deletion and return of data
At the end of the provision of the Service, and at any time on your written request, we will at your choice either delete all Customer Personal Data and certify to you that we have done so, or return it to you and delete existing copies. If you give us no instruction, we will delete. You may also export Customer Data yourself at any time via the export endpoints or the dashboard.
Deletion timelines:
| Stage | Timeline |
|---|---|
| Live systems (application database, object storage) | Within 30 days of termination or request |
| Backup snapshots | Rolled off within a further 35 days |
| Audit log entries | Purged automatically 90 days after creation |
A request for return must reach us within 30 days of termination, so that it does not collide with the deletion window above. We do not preserve data beyond the deletion window solely on request.
We may retain Customer Personal Data where Union or Member State law requires it, for as long as that requirement applies. Until data is deleted or returned, and for any period we are required to retain it, it remains subject to this DPA.
13. Personal data breach
We will notify you without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data. Notification goes to the email addresses of your organisation admins.
Our notification will describe, to the extent then known: the nature of the breach and the categories and approximate number of data subjects and records affected; the likely consequences; the measures taken or proposed; and a contact point for further information. Where the information is not all available at once, we will provide it in phases without further undue delay.
We will also assist you in notifying the supervisory authority and, where required, the affected data subjects. Notifying the authority and the data subjects remains your responsibility as controller. Notifying you is not an acknowledgement of fault or liability.
Unsuccessful attempts that do not compromise the security of Customer Personal Data are not personal data breaches and are not notifiable under this Section — for example blocked port scans, failed login attempts, denial-of-service attempts that do not result in access, and rejected network connections.
Vulnerability disclosures should be sent to security@getmunin.com; we acknowledge within 72 hours and give a remediation timeline within 7 days for confirmed issues.
14. Audits and information
We will make available to you all information necessary to demonstrate compliance with Article 28 GDPR, will deal promptly and adequately with your enquiries about our processing, and will allow for and contribute to audits, including inspections, conducted by you or an auditor mandated by you.
In the first instance we will satisfy audit requests by providing our security documentation, our current sub-processor list, and written answers to a reasonable security questionnaire. Where that is insufficient to demonstrate compliance, you may conduct an audit subject to the following: no more than once per twelve-month period — unless required by a supervisory authority, following a personal data breach affecting your data, or where there are reasonable indications of non-compliance with this DPA; at least 30 days' written notice; during business hours; without unreasonably disrupting the Service; conducted under an obligation of confidentiality; not extending to the data, systems, or personnel of other customers; and at your cost, save where the audit reveals a material breach of this DPA.
Where an audit relates to a sub-processor's facilities, we will use reasonable efforts to obtain the equivalent right or to provide the sub-processor's own third-party audit reports.
Both parties will make the information referred to in this Section, including the results of any audit, available to a competent supervisory authority on request.
15. Records of processing
We maintain a record of the categories of processing carried out on your behalf under Article 30(2) GDPR, and will make the relevant extract available to you or to a supervisory authority on request.
16. Non-compliance, suspension and termination
We will promptly inform you if we become unable to comply with this DPA, for whatever reason. If we are in breach of our obligations under this DPA, you may instruct us to suspend the processing of Customer Personal Data until we comply or the Service is terminated.
You are entitled to terminate the Service insofar as it concerns the processing of Customer Personal Data if: (a) you have suspended processing under the paragraph above and compliance is not restored within a reasonable time and in any event within one month of suspension; (b) we are in substantial or persistent breach of this DPA or of our obligations under the GDPR; or (c) we fail to comply with a binding decision of a competent court or supervisory authority regarding those obligations.
We are entitled to terminate the Service insofar as it concerns the processing of Customer Personal Data where, having informed you under Section 5 that an instruction infringes applicable law, you insist on compliance with that instruction.
Section 12 applies on any termination under this Section.
17. Other data protection laws
Where the processing is subject to a law other than the GDPR, the following apply in addition to the rest of this DPA.
United Kingdom. References to the GDPR are read as references to the UK GDPR and the Data Protection Act 2018, references to a supervisory authority as references to the Information Commissioner, and any transfer requiring safeguards is made under the ICO's International Data Transfer Addendum to the EU Standard Contractual Clauses.
Switzerland. References to the GDPR are read as references to the Swiss Federal Act on Data Protection, references to a supervisory authority as references to the Federal Data Protection and Information Commissioner, and "personal data" includes data relating to legal entities to the extent that Act protects it.
California and other US state privacy laws. We act as a "service provider" (or "processor", as those laws term it) and you as the "business" (or "controller"). We process Customer Personal Data solely to provide the Service under the Terms and this DPA, which is the business purpose. We will not sell or share it, retain, use, or disclose it for any purpose other than performing the Service, or outside the direct business relationship with you, and we will not combine it with personal information from another source except as those laws permit. We will notify you if we determine we can no longer meet these obligations. Your rights under Section 14 include the steps needed to confirm our use of Customer Personal Data is consistent with these obligations.
18. Data protection contact
Our contact point for all matters under this DPA is privacy@getmunin.com, Apps AS, Vulkan 16, 0178 Oslo, Norway. We have not appointed a data protection officer, as none of the conditions in Article 37(1) GDPR applies; we will appoint one and update this DPA if that changes.
Apps AS is established in the EEA and therefore does not require a representative under Article 27 GDPR.
19. Liability
Each party's liability under this DPA is subject to the exclusions and the aggregate cap in Section 12 of the Terms of Service. Nothing in this DPA limits either party's liability to a data subject or a supervisory authority under Article 82 GDPR, or any other liability that cannot be limited under applicable law.
20. Changes to this DPA
We may update this DPA to reflect changes in law, in the Service, or in our sub-processors. Material changes will be notified to account admins at least 30 days before they take effect, and the "Last updated" date above will change. If you reject a material change you may terminate the Service before the effective date, and Section 12 applies.
21. Governing law and venue
This DPA is governed by the laws of Norway, without regard to its conflict-of-laws rules. Disputes will be brought before the ordinary courts of Oslo, Norway. This does not affect any mandatory right of a data subject or supervisory authority under the GDPR.
Annex I — Details of processing
Subject matter. Provision of the Munin Cloud hosted platform — Knowledge Base, Conversations, CRM, CMS, analytics, and the MCP and REST interfaces to them.
Nature and purpose. Hosting, storage, retrieval, structuring, transmission, indexing (including vector-embedding generation for hybrid search), backup, and deletion of Customer Data, together with the transmission of messages through the channels you configure, in each case in order to provide the Service to you.
Duration. For the term of the Terms of Service, plus the deletion windows in Section 12.
Frequency. Continuous, for as long as the Service is in use.
Categories of data subjects
- Your personnel: users, organisation members, invitees, and administrators.
- Your end-users and customers: people who contact you through a chat widget, email, SMS, or voice channel, and people recorded as end-user records.
- Your contacts and prospects: individuals recorded in the CRM as contacts, or associated with companies, deals, and activities.
- Any individual whose personal data you choose to include in knowledge-base articles, CMS entries, assets, or files you upload.
Categories of personal data
- Identity and contact data: name, email address, phone number, job title, company affiliation, postal address where you record one.
- Account and access data: organisation membership, role, session and OAuth tokens, hashes of API keys, delegated end-user tokens.
- Communications content: chat-widget messages, email bodies and headers, SMS content, voice call audio and transcripts where those channels are enabled, message attachments.
- Commercial data: deals, pipeline stages, activities, notes, consent flags, segment membership.
- Content you author: knowledge-base documents, CMS entries and assets, and any personal data they contain.
- Usage and technical data attributable to an individual: audit-log entries (tool name, arguments, result code, actor, organisation), analytics page-view and search events, request timestamps, IP address, user agent.
Special categories of data. The Service is not designed for the processing of special categories of personal data under Article 9 GDPR, or personal data relating to criminal convictions and offences under Article 10, and you must not configure it to process such data as a deliberate purpose. You control what enters the Service. We recognise that incidental special-category data can reach a support inbox unbidden; the measures in Annex II — tenancy isolation, least-privilege access, encryption, and audit logging — apply to it in the same way as to all other Customer Personal Data. If your use case involves such data as a matter of course, contact privacy@getmunin.com before submitting it so that additional restrictions and safeguards can be agreed in writing.
Sub-processor processing. Where a sub-processor in Annex III processes personal data, the subject matter and duration are as stated in Annex III for that sub-processor.
Annex II — Technical and organisational measures
These are the measures in force at the effective date. They may be updated provided the level of security is not materially reduced.
Access control and tenancy isolation
- Postgres row-level security enforces the tenancy boundary on every read and write. Service-role queries bypass RLS only on narrow infrastructure paths, and those paths are audited.
- End-user delegated tokens are short-lived and scoped to a single end-user record; the tools they reach see only that end-user's own contact and conversations, enforced by RLS rather than by client-side filtering.
- OAuth 2.1 with PKCE for admin agent authorisation. Connected agents receive a constrained tool surface rather than direct database access.
- Least-privilege access for our personnel, limited to those who need it to provide, secure, or support the Service.
Encryption and pseudonymisation
- TLS in transit on all connections; HSTS enforced on app.getmunin.com.
- Recoverable secrets — SMTP and IMAP passwords, third-party provider keys — are encrypted at rest in Postgres using pgcrypto
pgp_sym_encrypt, keyed by an instance-wide key held in Scaleway Secret Manager. - API keys are stored only as salted hashes; plaintext is displayed once at mint time and never retrievable afterwards.
- Backups encrypted at rest.
Integrity, availability and resilience
- Managed Postgres with automated backups; 35-day rolling snapshot retention.
- Disaster-recovery procedures documented and tested at least annually.
- Application infrastructure defined as code and reproducible from source.
Logging and accountability
- Audit log of tool calls and administrative actions, retained 90 days, recording tool name, arguments, result code, actor, and organisation.
- Operational request logs retained 30 days.
- Error tracking with PII attachment disabled; dashboard session replay captures interaction shape only, with all text masked and media blocked.
Governance
- Confidentiality obligations for all personnel with access to Customer Personal Data.
- Published vulnerability disclosure policy: security@getmunin.com, acknowledgement within 72 hours, remediation timeline within 7 days for confirmed issues.
- Sub-processors assessed before engagement and bound to equivalent obligations.
- Prompt-injection defences on inbound channel content: sanitisation, constrained tool surfaces, scoped delegated tokens, and audit logging.
Assistance measures. The measures by which we assist you under Section 11 are: the self-service export, correction, and deletion functions of the Service; the audit log; the information in this Annex; and written responses from privacy@getmunin.com.
Annex III — Authorised sub-processors
Current at the "Last updated" date above. Changes are notified under Section 8. The authoritative list is maintained in Section 4 of the Privacy Policy.
| Sub-processor | Purpose | Data processed | Location |
|---|---|---|---|
| Scaleway SAS (France) | Hosting (Postgres with pgvector, application containers, object storage, backups); transactional email; embedding generation for Knowledge Base and CMS hybrid search via Scaleway Generative APIs | All Customer Personal Data. Text sent to Scaleway Generative APIs for vector generation is transient, is not retained by the provider, and is not used for model training | EU — Netherlands (application, storage), France (embeddings, email) |
| Functional Software, Inc. (Sentry) | Error and exception tracking; performance and profiling traces (10 % sampled); dashboard session replay captured only on error, with text masked and media blocked | Stack traces, exception messages, URL paths, browser and runtime version, request correlation IDs, IP address. Default PII attachment is disabled; we do not pass account identity or Customer Data into events | EU — Germany (Sentry EU region) |
Sub-processor processing lasts for as long as that sub-processor is engaged to provide the Service, and Customer Personal Data held by a sub-processor is deleted in accordance with Section 12.
Google LLC and GitHub, Inc. are not sub-processors. Where a user chooses to sign in with Google or GitHub, that provider acts as an independent controller of the authentication event and returns the user's email address and display name to us. See Section 4b of the Privacy Policy.
Annex IV — Execution
This DPA is accepted by acceptance of the Terms of Service and requires no signature to be effective. A countersigned PDF is available on request from privacy@getmunin.com; state your legal entity name, registered address, and the email address of the signatory.
Apps AS Org. no. 922 222 045 Vulkan 16, 0178 Oslo, Norway privacy@getmunin.com