Data processing addendum

Last updated October 9, 2026

This data processing addendum (“DPA”) is part of the terms of service (the “Terms”) and applies automatically when we process Customer Personal Data for a customer. No signature is needed. Capitalized terms not defined here have the meanings in the Terms.

1. Parties

This DPA is between the customer that accepted the Terms (“Customer”) and Mise en AI, LLC, a Maryland limited liability company (“MISE EN AI”, “we”).

2. Definitions

  • “Data Protection Laws” means privacy and data protection laws that apply to the processing of Customer Personal Data under the Terms, such as United States state privacy laws.
  • “Customer Personal Data” means personal information within Customer Data that we process on Customer’s behalf.
  • “Subprocessor” means a third party we engage that processes Customer Personal Data to help provide the Service.
  • “Security Incident” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data in our or our Subprocessors’ systems.
  • “Controller”, “processor”, “business”, “service provider”, “personal information” and similar terms have the meanings given in the applicable Data Protection Laws.

3. Scope and details of processing

  • Subject matter and duration: providing the Service under the Terms, for as long as we process Customer Personal Data.
  • Nature and purpose: hosting, storing, analyzing, reading documents, calculating, transmitting to integrations Customer chooses, supporting and securing the Service.
  • Data subjects: Customer’s employees and workers, its vendors and their contacts, its catering and other customers, and other individuals whose information Customer provides.
  • Categories of data: names and contact details; job roles; time-clock records, hours, wage rates and labor costs; transaction and order information; vendor and invoice details; bank transaction descriptions; and other personal information in documents Customer uploads.
  • Sensitive data: the Service is not designed for sensitive categories of personal information, and Customer will not submit them except where a feature clearly asks for it.

This DPA does not cover information we process as an independent controller, such as user account, authentication, security and billing contact information, which our privacy policy covers.

4. Customer responsibilities

Customer is the controller (or business) for Customer Personal Data, or acts on behalf of the controller. Customer is responsible for having a lawful basis for the processing, for giving the notices and obtaining the consents Data Protection Laws require (including to its employees), for the accuracy of the data, and for its instructions to us complying with Data Protection Laws.

5. Our role

We process Customer Personal Data as Customer’s processor or service provider. We will not:

  • sell or share Customer Personal Data, as those terms are defined by law;
  • retain, use or disclose it for any purpose other than providing the Service and the other purposes the Terms and Data Protection Laws allow (such as security, debugging, and creating de-identified or aggregated information as described in the Terms);
  • retain, use or disclose it outside our direct business relationship with Customer, or combine it with personal information from other sources except as Data Protection Laws permit; or
  • use identifiable Customer Personal Data to train AI models.

We will comply with the obligations Data Protection Laws place on processors and service providers and tell Customer if we determine we can no longer meet them.

6. Documented instructions

The Terms, this DPA, and Customer’s use and configuration of the Service (including which integrations it connects and what it sends to them) are Customer’s documented instructions. We will process Customer Personal Data only on those instructions unless the law requires otherwise, in which case we will tell Customer first unless the law forbids it. We will tell Customer if we believe an instruction violates Data Protection Laws.

7. Confidentiality

We ensure that personnel and contractors authorized to process Customer Personal Data are bound by confidentiality obligations and access it only as needed to provide the Service, support Customer or meet legal obligations.

8. Security measures

We maintain administrative, technical and organizational measures designed to protect Customer Personal Data, appropriate to the risk, as summarized on our security page. We may update these measures as long as we don’t materially reduce the overall protection. Customer is responsible for its users’ access, roles and credentials, and for the security of systems it connects.

9. Subprocessors

Customer generally authorizes us to engage Subprocessors. The current list is on our subprocessors page. We will impose data protection obligations on each Subprocessor that are no less protective than this DPA in substance, to the extent applicable to the service it provides, and we remain responsible for their performance under this DPA. Third-party services Customer chooses to connect (such as its point-of-sale, accounting or bank connection) are not our Subprocessors; Customer directs the data they receive, and Customer’s relationship with them governs their processing.

10. Changes to subprocessors

We will update the subprocessors page before a new Subprocessor begins processing Customer Personal Data. Customer may ask to be notified of changes by email at williamsedgwick@miseenai.com. Customer may object on reasonable data protection grounds within 30 days of the update. We will discuss the objection in good faith; if we can’t reasonably accommodate it, Customer may cancel the affected Service as its sole remedy.

11. Assistance with privacy requests

Taking into account the nature of the processing, we will provide reasonable assistance to Customer in responding to requests from individuals exercising their rights, mainly through the Service’s features for viewing, correcting and exporting data, and otherwise on request. If we receive a request directly that relates to Customer Personal Data, we will refer the individual to Customer and won’t respond to it ourselves except to do so, unless the law requires. We will also provide reasonable information to help Customer with data protection assessments that Data Protection Laws require.

12. Security incidents

We will notify Customer without undue delay after we confirm a Security Incident, and in any event within the time Data Protection Laws require. The notice will describe what we know about the incident and the steps we are taking, and we will update Customer as we learn more. We will take reasonable steps to contain and remedy the incident and provide reasonable cooperation with Customer’s obligations to notify authorities or individuals. Notice is not an admission of fault. Unsuccessful attempts that don’t compromise security, such as failed sign-ins or blocked requests, are not Security Incidents.

13. Deletion and return

Customer can view and export much of its Customer Data through the Service. Canceling a subscription does not delete Customer Personal Data. When an organization owner asks us to delete the organization, or the Terms end and the notice period in the Terms has passed, we will delete Customer Personal Data from our active systems within a reasonable time, and, on request made before deletion, provide a copy in a commonly used format. Data in backups maintained by our infrastructure providers is deleted as those backups expire, and we may keep data the law requires us to keep, which remains protected under this DPA.

14. Audits and compliance information

On Customer’s reasonable written request, no more than once a year (or after a Security Incident), we will provide information reasonably necessary to demonstrate our compliance with this DPA, such as written answers to a security questionnaire and a description of our security measures. If Data Protection Laws require more, Customer may conduct an audit, or have an independent auditor bound by confidentiality do so, at Customer’s expense, on at least 30 days’ notice, during business hours, and in a way that does not disrupt our operations or compromise the security or confidentiality of other customers’ data. Information provided is our Confidential Information.

16. International transfers

The Service is hosted in the United States, and Customer Personal Data is processed there and wherever our Subprocessors operate. If Data Protection Laws require a transfer mechanism for Customer Personal Data leaving another country, the parties will cooperate in good faith to put an appropriate mechanism in place before such data is transferred.

17. Limitations

Each party’s liability arising out of or relating to this DPA is subject to the exclusions and limitations of liability in the Terms, and this DPA does not create any liability not provided for there. This DPA does not give rights to third parties, except where Data Protection Laws require.

18. Term and precedence

This DPA lasts as long as we process Customer Personal Data. If this DPA conflicts with the Terms about the processing of Customer Personal Data, this DPA controls. Otherwise the Terms control. We may update this DPA as described in the Terms for changes to the Terms, and will not make changes that materially reduce the protection of Customer Personal Data unless the law requires them.

19. Contact

Data protection questions: williamsedgwick@miseenai.com. Security incidents and reports: williamsedgwick@miseenai.com.