MuninMunin
Sign inStart free

Data Processing Agreement — Munin Cloud

Last updated: 2026-08-31

This Data Processing Agreement ("DPA") governs our processing of personal data contained in Customer Data when your organisation uses Munin Cloud at app.getmunin.com, api.getmunin.com, and mcp.getmunin.com (the "Service").

It is entered into between:

This DPA forms part of, and is incorporated by reference into, the Terms of Service. You do not need to sign it separately for it to apply — accepting the Terms accepts this DPA. If your procurement process requires a countersigned copy, email privacy@getmunin.com and we will execute one; we sign DPAs with any customer who processes personal data through Munin Cloud, regardless of plan.

This DPA implements Article 28 of Regulation (EU) 2016/679 ("GDPR"), as incorporated into Norwegian law by the Personal Data Act (personopplysningsloven). It follows the structure of the standard contractual clauses adopted by the European Commission under Article 28(7) GDPR in Implementing Decision (EU) 2021/915.

1. Order of precedence

In the event of a conflict, the following order applies, most authoritative first: (1) this DPA, (2) the Terms of Service, (3) the Privacy Policy. This DPA prevails over the Terms only in respect of the processing of personal data contained in Customer Data.

2. Definitions

"Controller", "processor", "sub-processor", "data subject", "personal data", "processing", "personal data breach", and "supervisory authority" have the meanings given in the GDPR.

"Customer Data" has the meaning given in Section 5 of the Terms of Service. "Customer Personal Data" means the personal data contained within Customer Data.

3. Roles of the parties

You are the controller of Customer Personal Data and we are your processor. Where you are yourself a processor acting for a third-party controller (for example, as an agency or a reseller's customer), we are a sub-processor and you warrant that you have the authority of that controller to appoint us on these terms.

This DPA does not cover the data for which we are an independent controller — account credentials, billing information, support correspondence, security and abuse logs, and aggregated anonymised service metrics. That processing is described in Sections 1 and 2 of the Privacy Policy and is not carried out on your instructions.

Where we derive aggregated or anonymised data from Customer Data, we will do so only in a form that no longer identifies any data subject and cannot reasonably be used to re-identify one, we will not attempt to re-identify it, and we will bind any recipient to the same obligation.

4. Subject matter and duration

The subject matter, nature and purpose of the processing, the categories of data subjects, and the types of personal data are set out in Annex I.

This DPA takes effect when you accept the Terms of Service and continues for as long as we process Customer Personal Data on your behalf. Sections 12 (deletion and return), 14 (audits), and 19 (liability) survive termination.

5. Processing on documented instructions

We will process Customer Personal Data only on your documented instructions, including with regard to transfers to a third country, unless required to do so by Union or Member State law to which we are subject — in which case we will inform you of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.

Your documented instructions consist of:

Purpose limitation. We will process Customer Personal Data only for the purposes set out in Annex I, unless you instruct us otherwise.

We will immediately inform you if, in our opinion, an instruction infringes the GDPR or other Union or Member State data-protection law. We may suspend performance of an instruction that we reasonably believe to be unlawful until it is withdrawn, amended, or confirmed; if you insist on compliance with such an instruction, we may terminate the Service under Section 16.

Actions performed by AI agents authorised under your organisation — whether connected by you via OAuth 2.1 or acting under delegated tokens you minted server-side — are your instructions for the purposes of this Section. This includes agents acting on content that reached them through an inbound channel; see Section 11.

We will not sell Customer Personal Data, use it to train AI models, or use it for our own purposes. We do not read or analyse the content of Customer Data except where strictly necessary to provide a feature you have enabled (for example, generating embeddings for kb_search) or to investigate a confirmed abuse or security report.

6. Confidentiality

We ensure that persons authorised to process Customer Personal Data are bound by an appropriate statutory or contractual obligation of confidentiality, and that access is granted only to the extent strictly necessary to implement, manage, and monitor the Service.

7. Security of processing

We implement appropriate technical and organisational measures under Article 32 GDPR. The measures in force at the effective date are described in Annex II, and we will implement at least those measures. We may update them over time provided the level of security is not materially reduced.

8. Sub-processors

You give us general written authorisation to engage sub-processors. The sub-processors authorised at the effective date are listed in Annex III.

We will notify account admins by email at least 30 days before adding or replacing a sub-processor, and will provide the information you need to decide whether to object. You may object on reasonable data-protection grounds within 30 days of that notice by writing to privacy@getmunin.com. We will work with you in good faith to address the objection; if we cannot, you may terminate the affected part of the Service without penalty before the change takes effect, and we will delete Customer Data in accordance with Section 12.

We engage each sub-processor under a written contract imposing, in substance, the same data-protection obligations as those in this DPA. We remain fully responsible to you for each sub-processor's performance, and we will notify you of any failure by a sub-processor to fulfil its obligations. On request we will provide you with a copy of the relevant sub-processor agreement and any subsequent amendments, redacted to the extent necessary to protect business secrets, other confidential information, or personal data.

Where a sub-processor's terms allow it, we will agree a third-party beneficiary clause under which, if we have factually disappeared, ceased to exist in law, or become insolvent, you may terminate the sub-processor contract directly and instruct the sub-processor to erase or return Customer Personal Data. Where a sub-processor contracts only on standard terms that do not permit this, we will tell you so on request.

The third-party providers you contract with directly and configure on your tenant with your own credentials — SMS, voice, custom SMTP/IMAP, and custom LLM or embedding endpoints — are not our sub-processors. They act under your contract, they are your processors, and you are responsible for the data-processing agreement and disclosures with them. We handle that data only in transit between your end-users and the provider you have chosen. See Section 4a of the Privacy Policy.

9. International transfers

All processing carried out by us and by our sub-processors takes place within the EU/EEA. Apps AS is established in Norway, an EEA state to which Union data-protection law applies, so processing by us is not a transfer to a third country.

We will not transfer Customer Personal Data outside the EEA without either an adequacy decision or appropriate safeguards under Chapter V GDPR, and any such transfer will be made only on your documented instructions or to satisfy a specific requirement of Union or Member State law to which we are subject. Where safeguards are required, the parties agree that the Standard Contractual Clauses adopted by the European Commission in Implementing Decision (EU) 2021/914 apply, Module Two (controller to processor) or Module Three (processor to processor) as appropriate, and that such a transfer would be notified as a sub-processor change under Section 8.

Transfers arising from the third-party providers you contract with directly under Section 8 are governed by your agreement with that provider, not by this DPA.

10. Government and law-enforcement access requests

If we receive a legally binding request from a public authority — including a law-enforcement or national-security authority — for disclosure of Customer Personal Data, we will:

We will keep a record of such requests and make it available to you on request, to the extent permitted by law. We do not grant any public authority direct, unfettered access to Customer Personal Data, and we have not created any means of access to our systems for that purpose.

11. Assistance to the Controller

Taking into account the nature of the processing and the information available to us, we will assist you by appropriate technical and organisational measures with:

For assistance materially exceeding what the Service provides self-service, we may charge a reasonable fee, notified in advance.

Prompt injection. Inbound channel content — email bodies, chat-widget messages, voice and SMS transcripts — may contain attempts to manipulate connected AI agents into processing personal data in ways you did not intend. We apply defences (sanitisation, constrained tool surfaces, scoped delegated tokens, audit logging) but cannot guarantee absolute prevention. Designing agent instructions, validating outputs before any consequential action, and supervising agent behaviour remain your responsibility as controller. We will work with you in good faith to investigate any incident.

12. Deletion and return of data

At the end of the provision of the Service, and at any time on your written request, we will at your choice either delete all Customer Personal Data and certify to you that we have done so, or return it to you and delete existing copies. If you give us no instruction, we will delete. You may also export Customer Data yourself at any time via the export endpoints or the dashboard.

Deletion timelines:

A request for return must reach us within 30 days of termination, so that it does not collide with the deletion window above. We do not preserve data beyond the deletion window solely on request.

We may retain Customer Personal Data where Union or Member State law requires it, for as long as that requirement applies. Until data is deleted or returned, and for any period we are required to retain it, it remains subject to this DPA.

13. Personal data breach

We will notify you without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data. Notification goes to the email addresses of your organisation admins.

Our notification will describe, to the extent then known: the nature of the breach and the categories and approximate number of data subjects and records affected; the likely consequences; the measures taken or proposed; and a contact point for further information. Where the information is not all available at once, we will provide it in phases without further undue delay.

We will also assist you in notifying the supervisory authority and, where required, the affected data subjects. Notifying the authority and the data subjects remains your responsibility as controller. Notifying you is not an acknowledgement of fault or liability.

Unsuccessful attempts that do not compromise the security of Customer Personal Data are not personal data breaches and are not notifiable under this Section — for example blocked port scans, failed login attempts, denial-of-service attempts that do not result in access, and rejected network connections.

Vulnerability disclosures should be sent to security@getmunin.com; we acknowledge within 72 hours and give a remediation timeline within 7 days for confirmed issues.

14. Audits and information

We will make available to you all information necessary to demonstrate compliance with Article 28 GDPR, will deal promptly and adequately with your enquiries about our processing, and will allow for and contribute to audits, including inspections, conducted by you or an auditor mandated by you.

In the first instance we will satisfy audit requests by providing our security documentation, our current sub-processor list, and written answers to a reasonable security questionnaire. Where that is insufficient to demonstrate compliance, you may conduct an audit subject to the following: no more than once per twelve-month period — unless required by a supervisory authority, following a personal data breach affecting your data, or where there are reasonable indications of non-compliance with this DPA; at least 30 days' written notice; during business hours; without unreasonably disrupting the Service; conducted under an obligation of confidentiality; not extending to the data, systems, or personnel of other customers; and at your cost, save where the audit reveals a material breach of this DPA.

Where an audit relates to a sub-processor's facilities, we will use reasonable efforts to obtain the equivalent right or to provide the sub-processor's own third-party audit reports.

Both parties will make the information referred to in this Section, including the results of any audit, available to a competent supervisory authority on request.

15. Records of processing

We maintain a record of the categories of processing carried out on your behalf under Article 30(2) GDPR, and will make the relevant extract available to you or to a supervisory authority on request.

16. Non-compliance, suspension and termination

We will promptly inform you if we become unable to comply with this DPA, for whatever reason. If we are in breach of our obligations under this DPA, you may instruct us to suspend the processing of Customer Personal Data until we comply or the Service is terminated.

You are entitled to terminate the Service insofar as it concerns the processing of Customer Personal Data if: (a) you have suspended processing under the paragraph above and compliance is not restored within a reasonable time and in any event within one month of suspension; (b) we are in substantial or persistent breach of this DPA or of our obligations under the GDPR; or (c) we fail to comply with a binding decision of a competent court or supervisory authority regarding those obligations.

We are entitled to terminate the Service insofar as it concerns the processing of Customer Personal Data where, having informed you under Section 5 that an instruction infringes applicable law, you insist on compliance with that instruction.

Section 12 applies on any termination under this Section.

17. Other data protection laws

Where the processing is subject to a law other than the GDPR, the following apply in addition to the rest of this DPA.

United Kingdom. References to the GDPR are read as references to the UK GDPR and the Data Protection Act 2018, references to a supervisory authority as references to the Information Commissioner, and any transfer requiring safeguards is made under the ICO's International Data Transfer Addendum to the EU Standard Contractual Clauses.

Switzerland. References to the GDPR are read as references to the Swiss Federal Act on Data Protection, references to a supervisory authority as references to the Federal Data Protection and Information Commissioner, and "personal data" includes data relating to legal entities to the extent that Act protects it.

California and other US state privacy laws. We act as a "service provider" (or "processor", as those laws term it) and you as the "business" (or "controller"). We process Customer Personal Data solely to provide the Service under the Terms and this DPA, which is the business purpose. We will not sell or share it, retain, use, or disclose it for any purpose other than performing the Service, or outside the direct business relationship with you, and we will not combine it with personal information from another source except as those laws permit. We will notify you if we determine we can no longer meet these obligations. Your rights under Section 14 include the steps needed to confirm our use of Customer Personal Data is consistent with these obligations.

18. Data protection contact

Our contact point for all matters under this DPA is privacy@getmunin.com, Apps AS, Vulkan 16, 0178 Oslo, Norway. We have not appointed a data protection officer, as none of the conditions in Article 37(1) GDPR applies; we will appoint one and update this DPA if that changes.

Apps AS is established in the EEA and therefore does not require a representative under Article 27 GDPR.

19. Liability

Each party's liability under this DPA is subject to the exclusions and the aggregate cap in Section 12 of the Terms of Service. Nothing in this DPA limits either party's liability to a data subject or a supervisory authority under Article 82 GDPR, or any other liability that cannot be limited under applicable law.

20. Changes to this DPA

We may update this DPA to reflect changes in law, in the Service, or in our sub-processors. Material changes will be notified to account admins at least 30 days before they take effect, and the "Last updated" date above will change. If you reject a material change you may terminate the Service before the effective date, and Section 12 applies.

21. Governing law and venue

This DPA is governed by the laws of Norway, without regard to its conflict-of-laws rules. Disputes will be brought before the ordinary courts of Oslo, Norway. This does not affect any mandatory right of a data subject or supervisory authority under the GDPR.


Annex I — Details of processing

Subject matter. Provision of the Munin Cloud hosted platform — Knowledge Base, Conversations, CRM, CMS, analytics, and the MCP and REST interfaces to them.

Nature and purpose. Hosting, storage, retrieval, structuring, transmission, indexing (including vector-embedding generation for hybrid search), backup, and deletion of Customer Data, together with the transmission of messages through the channels you configure, in each case in order to provide the Service to you.

Duration. For the term of the Terms of Service, plus the deletion windows in Section 12.

Frequency. Continuous, for as long as the Service is in use.

Categories of data subjects

Categories of personal data

Special categories of data. The Service is not designed for the processing of special categories of personal data under Article 9 GDPR, or personal data relating to criminal convictions and offences under Article 10, and you must not configure it to process such data as a deliberate purpose. You control what enters the Service. We recognise that incidental special-category data can reach a support inbox unbidden; the measures in Annex II — tenancy isolation, least-privilege access, encryption, and audit logging — apply to it in the same way as to all other Customer Personal Data. If your use case involves such data as a matter of course, contact privacy@getmunin.com before submitting it so that additional restrictions and safeguards can be agreed in writing.

Sub-processor processing. Where a sub-processor in Annex III processes personal data, the subject matter and duration are as stated in Annex III for that sub-processor.

Annex II — Technical and organisational measures

These are the measures in force at the effective date. They may be updated provided the level of security is not materially reduced.

Access control and tenancy isolation

Encryption and pseudonymisation

Integrity, availability and resilience

Logging and accountability

Governance

Assistance measures. The measures by which we assist you under Section 11 are: the self-service export, correction, and deletion functions of the Service; the audit log; the information in this Annex; and written responses from privacy@getmunin.com.

Annex III — Authorised sub-processors

Current at the "Last updated" date above. Changes are notified under Section 8. The authoritative list is maintained in Section 4 of the Privacy Policy.

Sub-processor processing lasts for as long as that sub-processor is engaged to provide the Service, and Customer Personal Data held by a sub-processor is deleted in accordance with Section 12.

Google LLC and GitHub, Inc. are not sub-processors. Where a user chooses to sign in with Google or GitHub, that provider acts as an independent controller of the authentication event and returns the user's email address and display name to us. See Section 4b of the Privacy Policy.

Annex IV — Execution

This DPA is accepted by acceptance of the Terms of Service and requires no signature to be effective. A countersigned PDF is available on request from privacy@getmunin.com; state your legal entity name, registered address, and the email address of the signatory.

Apps AS Org. no. 922 222 045 Vulkan 16, 0178 Oslo, Norway privacy@getmunin.com