DRAFT OUTLINE · v1 · needs legal review before signature.
Data Processing Addendum — outline
1. Roles
The Customer (organization) is the controller; Miirae Core is the processor, processing personal data only on the Customer's documented instructions.
2. Subject matter & duration
Processing of enrolled members' submitted content and derived CCI reports for the duration of the service agreement.
3. Nature & purpose
Generating individual capability reports and an anonymized team aggregate; storage, access control, and audit logging.
4. Categories of data & subjects
Enrolled members (data subjects); account identifiers, submitted text/documents, derived scores. No special-category data is requested; members should avoid submitting it.
5. Sub-processors
Hosting, email, and LLM providers, engaged under equivalent obligations. A list is maintained and changes notified. Details to be completed.
6. Security measures
Hashed passwords, access controls, audit logging of named report access, encryption in transit. Full technical & organizational measures to be documented.
7. Data subject rights & assistance
Miirae Core assists the Customer in fulfilling access, export, and erasure requests, including self-service export/erasure tooling.
8. International transfers
SCCs / transfer mechanism to be specified based on hosting region.
9. Return & deletion
On termination, member data is deleted or returned at the Customer's choice, subject to legal retention requirements.