Data Processing Addendum
Terms for engagements where Mirai processes personal data on a customer's documented instructions.
Published 8 September 2026. Version 2026-09-08-1.
Contract template. A signed processing schedule and applicable transfer terms are required before relying on this addendum. This page is not evidence of a completed DPA or certification.
1. Scope and roles
This addendum applies only to personal data Mirai processes as a processor for the customer as controller, or as a subprocessor where the customer has authority from its controller. The processing schedule must identify those roles. Where Mirai determines its own purposes for account administration, billing, fraud prevention or rights records, its controller obligations are separate and described in the Privacy Policy.
The schedule must identify the subject matter, duration, nature and purposes of processing, categories of individuals, data types, permitted operations and the customer's rights and obligations. No sensitive-category data, biometric identification, children's data or new processing purpose is authorized merely by signing this template; any such scope requires specific agreement and an appropriate lawful basis.
2. Documented instructions
Mirai will process covered data only on the customer's documented instructions, including instructions concerning international transfers, unless applicable law requires otherwise. Where legally permitted, Mirai will notify the customer of that legal requirement before processing. Mirai will inform the customer if it considers an instruction to infringe applicable data protection law and may pause the affected processing pending clarification.
The customer is responsible for its lawful basis, required notices and authority to provide the data and instructions. A processing instruction does not replace a person's likeness consent or an IP owner's licence. Covered data may not be used for independent model training under this addendum.
3. Confidentiality and security
Mirai will ensure that persons authorized to process covered data are bound by confidentiality obligations or an appropriate statutory duty. It will implement technical and organizational measures appropriate to the risk and agreed in the security schedule, considering the state of the art, implementation costs and the nature, scope, context and purposes of processing.
Before signing, the schedule must describe the actual access controls, authentication, encryption, separation of customer data, logging, incident response, backup and recovery arrangements, and how their effectiveness is assessed. A public security summary is not a substitute for that schedule. Material changes must not reduce the agreed protection without written agreement.
4. Subprocessors
The signed schedule must list each authorized subprocessor, its function and processing locations. Mirai will obtain the customer's prior specific or general written authorization before engaging subprocessors. Under general authorization, Mirai will give at least 30 days' prior notice of an intended addition or replacement so the customer can raise a reasoned data-protection objection.
Mirai will impose written data-protection obligations providing equivalent protection for the delegated processing and remains responsible to the customer for the subprocessor's performance of those obligations. If an objection cannot be resolved, the parties must stop or terminate the affected processing under their agreed commercial terms rather than silently route data to the disputed provider.
5. International transfers
The processing schedule must identify restricted transfers and the applicable lawful mechanism. Where required, the parties must execute the appropriate EU Standard Contractual Clauses, UK Addendum or other valid instrument, complete its annexes, and assess supplementary safeguards before the transfer. Those instruments prevail over conflicting commercial terms.
No transfer mechanism, regional hosting promise or government-access assurance is established merely by listing a provider on the website. Onward transfers must meet the same applicable requirements.
6. Individuals' rights and assistance
Taking account of the nature of processing, Mirai will assist the customer through appropriate technical and organizational measures, insofar as possible, with access, correction, erasure, restriction, objection and portability requests. Requests received directly concerning covered processor data will be forwarded to the customer without undue delay; Mirai will not substantively respond without instructions unless legally required.
Taking account of the nature of processing and information available, Mirai will assist the customer with security obligations, breach notifications, impact assessments and prior regulatory consultation. The commercial schedule may allocate reasonable assistance costs but cannot remove mandatory duties.
7. Personal data breaches
Mirai will notify the customer without undue delay after becoming aware of a personal data breach affecting covered data. Notice will include available information about the incident, affected data and individuals, likely consequences, mitigation and a contact point. Incomplete information may be supplied in stages without undue delay.
Mirai will take reasonable steps to contain and investigate the incident, preserve relevant evidence and cooperate with the customer's response. The customer remains responsible for its controller notifications. Notification is not an admission of liability.
8. Return, deletion and audit
At the customer's choice, Mirai will return or delete covered personal data after the processing services end, and delete existing copies unless applicable law requires retention. The schedule must set the return format and deletion timetable, including backups. Retained data remains protected, restricted to the required purpose, and subject to deletion when that requirement ends.
Mirai will make available information necessary to demonstrate compliance and allow and contribute to audits, including inspections, by the customer or its mandated auditor. Proportionate notice, confidentiality and security arrangements may apply, but must not prevent an effective audit or regulator access. Nothing here relieves either party of direct statutory duties or limits an individual's rights under applicable law.