1. Parties, scope, and priority
This Data Processing Addendum (DPA) is between Decennium Platforms Limited (Decennium) and the Customer identified by the Moduly workspace, Order Form, or other agreement that incorporates it (Customer). It applies when Decennium processes Customer Personal Data on Customer's behalf to provide Moduly. Customer Personal Data means personal data contained in Customer Material or otherwise processed only on Customer's documented instructions.
Customer Personal Data does not include account administration, contracting, billing, tax, fraud-prevention, service-security, support-relationship, product-improvement, or legal-compliance data that Decennium determines how and why to process as controller, even where the same service also contains Customer Personal Data. That Service Data is governed by the Privacy Policy rather than this DPA, unless applicable law assigns a different role.
This DPA forms part of the Terms of Service or signed agreement (Agreement). If they conflict about processing Customer Personal Data, this DPA controls. Mandatory data-protection law and unmodified mandatory transfer clauses control over both. Capitalised terms not defined here have the meanings in the Agreement or applicable data-protection law.
2. Roles and documented instructions
Customer may be a controller or a processor, and Decennium acts correspondingly as processor or subprocessor for Customer Personal Data (or as the equivalent service provider or contractor under applicable law). Customer instructs Decennium to process that data only to host and organise Customer Material; carry out Customer's configured generation, review, storage, export, and publication actions; protect that data; comply with the Agreement; and follow additional lawful, documented instructions agreed by the parties.
Decennium will not process Customer Personal Data for another purpose unless required by applicable law. Where legally permitted, Decennium will notify Customer before doing so. Decennium will promptly tell Customer if, in our reasonable opinion, an instruction infringes applicable data-protection law, and may pause the affected processing.
3. Processing details
The subject matter, nature, purpose, and duration of processing are:
- Subject matter and purpose: hosting Customer Material and providing Brand Brain, content generation and editing, claim review, team approval, storage, export, and Customer-directed connector publishing.
- Nature of processing: collection, recording, organisation, structuring, storage, retrieval, consultation, use, model inference, transformation, review, disclosure to authorised subprocessors or Customer-selected recipients, restriction, export, and deletion.
- Duration: the subscription or other Agreement term plus the documented retrieval, backup, security, dispute, and deletion periods in the Privacy Policy, unless law or a written instruction requires a different period.
- Data subjects: Customer's authorised users, personnel, contractors, business contacts, campaign reviewers, endorsers, creators, prospects or customers whose data Customer lawfully submits, and people appearing in Customer-provided media.
- Personal data: identity and contact data that Customer submits; workspace, role, approval, and Customer-content audit data; brand, campaign, prompt, evidence, draft, media, and publication data; connector identifiers; and device or network data only where it forms part of Customer Material or is needed to secure that processing on Customer's behalf.
- Sensitive data: not intended for routine use. Customer must not submit special-category, health, child, precise-location, payment-card, authentication-secret, or similarly sensitive data unless a feature expressly supports it and the parties document the necessary safeguards and lawful basis.
4. Customer obligations
Customer is responsible for lawful instructions, the accuracy and minimisation of Customer Personal Data, required notices and consents, configuring roles and retention, and ensuring that its use of generated or published material complies with law. Where Customer is a controller, it is responsible for responding to data subjects. Where Customer is a processor, it warrants that the relevant controller has authorised its instructions and remains responsible for forwarding requests and enabling that controller to meet its obligations.
Customer will not direct Decennium to process data in violation of law, this DPA, the Acceptable Use Policy, or third-party rights. Customer must use the Service's security features, protect credentials, and notify Decennium promptly of a suspected compromise or unlawful upload.
5. Confidentiality and security
Decennium ensures that people authorised to process Customer Personal Data are bound by confidentiality and access it only as needed for their duties. We maintain proportionate technical and organisational measures designed to protect confidentiality, integrity, availability, and resilience.
Verified application-level measures currently include tenant- and role-scoped server authorisation; restricted browser access to Moduly data; TLS encryption in transit; protected secrets; and append-only approval and publication records. Production identity and access management, provider-managed encryption at rest, backup, recovery, monitoring, incident-response, and deletion controls must be separately verified before this DPA is activated. No measure makes a service absolutely secure.
6. Subprocessors
Customer gives general written authorisation for the subprocessors on the current Subprocessor List. Decennium will impose data-protection obligations that provide materially equivalent protection for the processing they perform and remains responsible to Customer for each subprocessor's performance to the same extent as if Decennium performed that processing itself.
We will give at least 30 days' advance notice of a new subprocessor that will process Customer Personal Data, unless an urgent security or legal need makes that impracticable. Customer may object on reasonable data-protection grounds during the notice period. The parties will work in good faith on a commercially reasonable alternative; if none is available, Customer may stop the affected feature or terminate the affected Service and receive any refund mandatory law or the Agreement requires.
7. Data-subject and compliance assistance
Taking account of the nature of processing, Decennium will provide reasonable technical and organisational assistance for Customer to respond to lawful requests for access, correction, deletion, restriction, portability, objection, or other applicable rights. If a person contacts us about Customer-controlled data, we will normally direct the request to Customer unless law requires otherwise.
Considering the information available to us, we will reasonably assist Customer with security, breach notification, data-protection impact assessments, prior consultation, and evidence needed to demonstrate compliance. Assistance outside standard product functions or caused by Customer's non-compliance may be charged at an agreed reasonable rate where law permits.
8. Personal-data incidents
Decennium will notify Customer without undue delay after becoming aware of a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Customer Personal Data. Where practicable, we target notification within 48 hours after becoming aware. We may send an initial notice before every fact is confirmed and update it in phases.
Notification will include available information about the nature and likely consequences, affected data and people, mitigation taken or proposed, and a contact point. Information may be supplied in phases. Notice is not an admission of fault. Where Customer is controller, it remains responsible for legally required notifications, with our reasonable assistance. Where Customer is processor, it remains responsible for promptly informing and assisting the relevant controller in accordance with its instructions and applicable law.
9. Return, deletion, and retention
During an active account, Customer can use available export functions. Account deletion removes the requesting user's Moduly identity and memberships but does not delete shared organisation content controlled by other authorised members. On verified organisation closure or termination, Decennium will delete or return Customer Personal Data in accordance with Customer's lawful choice, the Privacy Policy, and documented product procedures, unless applicable law requires retention.
Customer Personal Data may remain in rotating backups until normal expiry and in restricted security, approval, claim-review, usage, publication, privacy-request, or legal records for the periods stated in the Privacy Policy only where needed to carry out Customer's documented instructions, secure the Service, demonstrate compliance, satisfy law, preserve a documented legal hold, or resolve a live dispute. Retained Customer Personal Data remains protected, is not used for an unrelated purpose, and is deleted when that basis ends. Controller-side Service Data follows the separate schedule in the Privacy Policy.
10. Information and audits
Decennium will make available information reasonably necessary to demonstrate compliance with this DPA, which may include security descriptions, independent reports if available, policies, and written responses. Customer must protect confidential security information.
If the supplied information is insufficient, Customer may request one audit per twelve-month period, or an additional audit after a confirmed incident or regulator request. Audits require reasonable notice, must minimise disruption and exposure of other customers' data, and may use an agreed independent auditor. Customer bears its costs unless the audit finds a material Decennium breach.
11. International transfers
Customer authorises processing in the countries identified in the Subprocessor List, subject to applicable transfer rules. The parties will use a valid transfer mechanism and supplementary measures where required.
For a restricted transfer of Customer Personal Data from the EEA or otherwise subject to EU GDPR to Decennium in a country without an applicable adequacy decision, the parties will complete and enter the European Commission Standard Contractual Clauses issued under Decision (EU) 2021/914 before that transfer relies on them. Module Two applies when Customer is controller and Module Three applies when Customer is processor. The Customer acceptance record or Order Form must complete the exporter details, role, signature date, transfer description, competent supervisory authority, technical measures, and subprocessor schedule; Sections 1, 3, 5, 6, and 13 and the Subprocessor List provide the corresponding baseline. Docking is permitted; Irish law governs Clause 17 and Irish courts are selected under Clause 18 where that selection is valid.
For a restricted transfer under UK data-protection law, the parties will complete the ICO International Data Transfer Addendum to the EU SCCs, including its mandatory clauses and Tables 1 to 4, before that transfer relies on it. Customer is exporter and Decennium is importer unless the completed schedule states the legally correct roles. The exporter remains responsible for any required transfer risk assessment or data-protection test, with reasonable information from Decennium. Neither this paragraph nor an incomplete workspace profile represents that a customer-specific transfer instrument has already been executed.
12. Hong Kong, Taiwan, and US state terms
For Hong Kong personal data, Decennium will process as Customer's data processor or subprocessor, as applicable, under contractual controls supporting the Data Protection Principles, including purpose limitation, data minimisation, security, processor oversight, and deletion when no longer needed.
For Taiwan personal data, each party will comply with duties applicable to its role under the Personal Data Protection Act, including lawful collection and use, notice, security, rights handling, and cessation or deletion where required.
For personal information subject to the CCPA or similar US state law, Decennium acts as Customer's service provider or contractor for the specific business purposes in Section 3. Decennium will not sell or share that personal information; use it for cross-context behavioural advertising; retain, use, or disclose it outside the direct business relationship or specified purposes except as law permits; combine it with unrelated personal information except as permitted; or attempt to re-identify deidentified data. Decennium will provide the same level of privacy protection required by applicable law, allow reasonable monitoring, notify Customer if we can no longer comply, and permit Customer to take reasonable steps to stop and remediate unauthorised use.
13. Liability, termination, and contact
The Agreement's liability limits apply to this DPA to the maximum extent permitted by law, but do not limit a data subject's rights or liability that mandatory law does not allow the parties to limit. Termination of this DPA does not affect provisions intended to protect retained data or mandatory transfer clauses.
Processor: Decennium Platforms Limited, incorporated in Hong Kong SAR. Business contact address: Entrepreneurship Centre, Level 5, Core F, Cyberport 3, 100 Cyberport Road, Hong Kong. Privacy contact: privacy@decennium.app. Customer details and authorised contact are the verified workspace, Order Form, or signature record.