This Data Processing Addendum (this "DPA") is incorporated into the morningmate Terms of Service (the "Terms") pursuant to Article 7(4) of the Terms and applies where the Company processes personal data on behalf of the Customer pursuant to Article 6(2)(b) of the Terms. When the Customer agrees to the Terms or uses the Service, this DPA is also deemed to have been entered into without a separate signature. Capitalized terms not defined in this DPA have the meanings given to them in the Terms.
Article 1 (Purpose and Scope)
1. The purpose of this DPA is to set out the rights and obligations of the parties required by Applicable Data Protection Law where the Company processes Customer Personal Data in the course of providing the Service.
2. This DPA does not apply to personal data that the Company processes as a controller for its own purposes (Article 6(2)(a) of the Terms). The processing of such personal data is governed by the Company's Privacy Policy.
3. In the event of any conflict between this DPA and the Terms with respect to the processing of personal data, this DPA prevails; and in the event of any conflict between this DPA and a transfer mechanism incorporated under Article 14, such as the standard contractual clauses, that transfer mechanism prevails.
Article 2 (Definitions)
The following terms used in this DPA have the meanings set out below.
1. "Applicable Data Protection Law" means the laws and regulations relating to the protection of personal data that apply to the processing of Customer Personal Data, including, to the extent applicable, the EU General Data Protection Regulation (Regulation (EU) 2016/679) ("GDPR"), the UK GDPR and the Data Protection Act 2018 (together, the "UK Data Protection Law"), the Swiss Federal Act on Data Protection ("FADP"), the California Consumer Privacy Act (as amended) ("CCPA") and other U.S. state privacy laws, Japan's Act on the Protection of Personal Information ("APPI"), and the Personal Information Protection Act of the Republic of Korea.
2. "Customer Personal Data" means personal data contained in data that the Customer, Members or Guests enter, store or upload into the Service, or that is generated through the Service, and that the Company processes on behalf of the Customer.
3. "Processing", "data subject", "controller", "processor" and "supervisory authority" have the meanings given to them in Applicable Data Protection Law. Where the CCPA applies, "processor" includes "service provider" and "Customer" includes "business".
4. "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss or alteration of, or unauthorized disclosure of or access to, Customer Personal Data processed by the Company or a sub-processor.
5. "Sub-processor" means any third party engaged by the Company to process Customer Personal Data, including the Company's affiliates.
6. "EU SCCs" means the standard contractual clauses set out in European Commission Implementing Decision (EU) 2021/914.
7. "UK Addendum" means the International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner's Office (ICO) (version B1.0 and any successor version).
8. "Restricted Transfer" means an international transfer (including an onward transfer) that is not permitted under Applicable Data Protection Law without a lawful transfer basis such as an adequacy decision.
Article 3 (Roles of the Parties)
1. The Customer is the controller of Customer Personal Data, and the Company is a processor that processes Customer Personal Data on behalf of the Customer. The entity that processes Customer Personal Data as the processor under this DPA and as the data importer under Article 14 is the Provider, Madrascheck Inc.; the Operator, MADRAS CHECK GLOBAL, does not process Customer Personal Data. Where the Customer uses the Service as a processor on behalf of a third party, the Company acts as a sub-processor with respect to that third party, and the Customer warrants that it has obtained the necessary authorization from that third party.
2. The Customer is responsible for obtaining the lawful basis for processing, notices and consents required under Applicable Data Protection Law for the collection and processing of Customer Personal Data, and warrants that its processing instructions to the Company comply with Applicable Data Protection Law.
3. Where the APPI applies, the Company, as a person entrusted by the Customer with the handling of personal data, is subject to the Customer's supervision in accordance with this DPA.
Article 4 (Processing Instructions)
1. The Company will process Customer Personal Data only on the documented instructions of the Customer. The Terms, this DPA and the instructions given by the Customer through the features and settings of the Service constitute the Customer's complete documented instructions. Any additional or modified instructions must be agreed by both parties in writing.
2. Notwithstanding paragraph 1, where the Company is required to process Customer Personal Data under Applicable Law, the Company will inform the Customer of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.
3. The Company will inform the Customer without delay if it considers that an instruction of the Customer infringes Applicable Data Protection Law.
4. The Company will not use Customer Personal Data to train artificial intelligence models (Article 33(1) of the Terms). Any use for the purpose of improving service quality under Article 33(3) of the Terms takes place only to the extent that the Customer or a Member has provided feedback on AI outputs or has expressly permitted such use, and the Company will process such data only to the minimum extent necessary to achieve that purpose.
Article 5 (Details of Processing)
The subject matter and duration of the processing, the nature and purpose of the processing, the types of personal data and the categories of data subjects are as set out in Annex 1.
Article 6 (Confidentiality)
The Company will ensure that its employees and other personnel authorized to process Customer Personal Data are subject to appropriate obligations of confidentiality, and will grant access only to the minimum number of personnel necessary to perform their duties.
Article 7 (Security Measures)
1. Taking into account the nature, scope, context and purposes of the processing and the risks to the rights of data subjects, the Company will implement appropriate technical and organizational security measures as required by Applicable Data Protection Law, including Article 32 of the GDPR. Details of those measures are set out in Annex 2.
2. The Company may update its security measures in line with technological developments, provided that such updates do not reduce the overall level of protection of Customer Personal Data.
Article 8 (Sub-processors)
1. The Customer grants the Company a general authorization to engage sub-processors. The sub-processors as at the date this DPA is entered into are as listed in Annex 3 (Article 7(5) of the Terms).
2. Where the Company adds or replaces a sub-processor, the Company will update Annex 3 at least 30 days before the change takes effect and will notify the Customer by email to the Customer's registered email address or by notice within the Service.
3. The Customer may object in writing on reasonable data protection grounds within 30 days of receiving the notice under paragraph 2. In that case, the parties will consult in good faith, and if the Company is unable to offer a reasonable alternative, the Customer may terminate the Agreement solely with respect to the part of the Service for which the use of that sub-processor is unavoidable. The Company will then refund, on a pro rata basis, the fees already paid for the remaining period in respect of the terminated part.
4. The Company will enter into a written contract with each sub-processor imposing data protection obligations substantially equivalent to those set out in this DPA, and will remain liable to the Customer for the performance of the sub-processor's obligations.
Article 9 (Assistance with Data Subject Rights)
1. Taking into account the nature of the processing, the Company will assist the Customer, through features of the Service or other appropriate technical and organizational measures, in responding to requests from data subjects to exercise their rights, such as the rights of access, rectification, erasure, restriction of processing, data portability and objection.
2. If the Company receives a request relating to Customer Personal Data directly from a data subject, the Company will forward the request to the Customer and will not respond to it directly without the Customer's instructions, except to inform the data subject that the request has been forwarded to the Customer.
Article 10 (Notification of Personal Data Breaches)
1. The Company will notify the Customer of a Personal Data Breach without undue delay, and in any event within 48 hours after becoming aware of it.
2. The notification under paragraph 1 will include the following information to the extent known, and any information that cannot be provided at the same time will be provided in phases without delay as it becomes available:
(a) the nature of the breach, including the categories and approximate number of data subjects and personal data records concerned;
(b) the Company's point of contact;
(c) the likely consequences of the breach; and
(d) the measures taken or to be taken by the Company to address the breach and mitigate its adverse effects.
3. The Company will investigate the cause of the breach, take reasonable steps to mitigate the harm, and provide the information the Customer needs to comply with its obligations to notify supervisory authorities and data subjects. No notification or cooperation by the Company will be construed as an acknowledgment by the Company of any fault or liability.
Article 11 (Assistance with Impact Assessments and Prior Consultation)
Taking into account the nature of the processing and the information available to the Company, the Company will provide reasonable information necessary for the data protection impact assessments (DPIAs) and prior consultations with supervisory authorities that the Customer carries out under Applicable Data Protection Law.
Article 12 (Return and Deletion of Customer Personal Data)
1. Upon termination of the Agreement, the Customer may download Customer Personal Data during the period set out in Article 18(4) of the Terms (including, for EEA customers, Article 18(6) of the Terms).
2. The Company will delete Customer Personal Data from its production systems within 30 days after the expiry of the period referred to in paragraph 1, and will delete Customer Personal Data stored in backups in accordance with its regular backup cycle and in any event within 90 days thereafter. However, where Applicable Law requires retention, the Company will retain such data for the required period, will not process it for any other purpose, and will continue to apply the protections under this DPA.
3. At the Customer's request, the Company will confirm in writing (including by electronic means) that deletion has been completed.
Article 13 (Information and Audits)
1. At the Customer's request, the Company will make available the information necessary to demonstrate compliance with this DPA and Article 28 of the GDPR. Where the Company holds independent third-party security certifications or audit reports, the Company may meet this obligation by providing a copy or summary of them, subject to confidentiality.
2. Where the information under paragraph 1 does not reasonably enable the Customer to verify compliance, or where a supervisory authority so requires, the Customer may, on at least 30 days' prior written notice and no more than once per year, conduct an audit itself or through an independent auditor appointed by the Customer and reasonably agreed to by the Company. Audits will be conducted during the Company's normal business hours in a manner that does not unreasonably interfere with its operations, and the Customer will bear the costs. However, if the audit reveals a material breach of the Company's obligations, the Company will bear the reasonable costs of the audit.
3. The auditor may not access information relating to the Company's other customers, trade secrets or information that cannot be disclosed for security reasons, and is bound by confidentiality obligations with respect to information obtained in the course of the audit.
Article 14 (International Transfers)
1. The Company stores Customer Personal Data in the data center region referred to in Article 7(1) of the Terms, and may transfer Customer Personal Data to the countries listed in Annex 1 and Annex 3 for the purposes of service provision, backup, incident response, customer support and processing for the AI Services.
2. Where a transfer basis recognized under Applicable Data Protection Law exists for the destination country, such as an adequacy decision (including the EU adequacy decision for the Republic of Korea and the UK–Korea data bridge), the transfer is made on that basis.
3. Restricted Transfers from the EEA. For Restricted Transfers of Customer Personal Data subject to the GDPR, the EU SCCs are incorporated into this DPA by reference and are deemed completed as follows:
(a) Module Two (controller to processor) applies where the Customer is a controller, and Module Three (processor to processor) applies where the Customer is a processor; the Customer is the data exporter and the Company is the data importer;
(b) Clause 7 (docking clause) applies;
(c) Option 2 (general written authorization) applies to Clause 9(a), and the time period for notice is as set out in Article 8(2) of this DPA;
(d) the optional wording in Clause 11 does not apply;
(e) the competent supervisory authority under Clause 13 is as set out in Part C of Annex 1;
(f) the governing law under Clause 17 is the law of Ireland, and the courts under Clause 18(b) are the courts of Ireland; and
(g) Annex I of the EU SCCs is completed by Annex 1 to this DPA, and Annex II of the EU SCCs is completed by Annex 2 to this DPA. As general written authorization applies under item (c), information on sub-processors is provided through Annex 3.
4. Restricted Transfers from the United Kingdom. For Restricted Transfers of Customer Personal Data subject to the UK GDPR, the EU SCCs as completed under paragraph 3 apply together with the UK Addendum. The UK Addendum is deemed completed as follows:
(a) Table 1 (Parties) is completed with the information in Part A of Annex 1; Table 2 (Selected SCCs, Modules and Selected Clauses) is completed by paragraph 3 of this Article; and Table 3 (Appendix Information) is completed with the information in Annexes 1 to 3;
(b) in Table 4, both the data importer and the data exporter are selected as the parties that may end the UK Addendum in accordance with Section 19 of the UK Addendum; and
(c) the Mandatory Clauses in Part 2 of the UK Addendum means the Mandatory Clauses of the Approved Addendum, being the template Addendum B1.0 issued by the UK Information Commissioner's Office (ICO) and laid before Parliament in accordance with s119A of the Data Protection Act 2018 on February 2, 2022, as revised under Section 18 of those Mandatory Clauses, and are incorporated into this DPA by reference.
5. Restricted Transfers from Switzerland. For Restricted Transfers of Customer Personal Data subject to the FADP, the EU SCCs as completed under paragraph 3 apply with the following adaptations:
(a) the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner (FDPIC);
(b) the term "Member State" in the EU SCCs is to be interpreted as including Switzerland, so that data subjects habitually resident in Switzerland are able to exercise their rights in Switzerland; and
(c) references to the GDPR are to be read as references to the corresponding provisions of the FADP.
6. Transfers from Japan. Where Customer Personal Data subject to the APPI is transferred to a country outside Japan, the Company will establish a system (equivalent measures) that conforms to the standards prescribed in Article 28(1) of the APPI and its Enforcement Rules, will implement such measures on a continuous basis, and, at the Customer's request, will provide information on the status of their implementation and on the personal data protection regime of the destination country.
7. For Restricted Transfers, the Company will assess the laws and practices of the destination country and, where necessary, apply supplementary measures such as encryption. If a transfer mechanism is invalidated or superseded, the parties will cooperate to put in place an alternative mechanism recognized under Applicable Data Protection Law.
Article 15 (Government Access Requests)
1. If the Company receives a request from a public authority for disclosure of or access to Customer Personal Data, the Company will notify the Customer without delay, unless prohibited by Applicable Law.
2. The Company will review the legality of the request, pursue available legal avenues to challenge it where there are reasonable grounds to do so, and, if it complies with the request, will disclose only the minimum information necessary within the scope of the request.
3. At the Customer's request and to the extent permitted by Applicable Law, the Company will provide general information on requests from public authorities, such as the number of requests received.
Article 16 (Special Provisions on U.S. State Privacy Laws)
Where the CCPA or other U.S. state privacy laws apply, the Company, as a service provider or processor, will comply with the following:
(a) the Company will not sell Customer Personal Data or share it for cross-context behavioral advertising;
(b) the Company will not retain, use or disclose Customer Personal Data for any purpose other than the business purposes set out in the Terms, or outside the direct business relationship with the Customer;
(c) the Company will not combine Customer Personal Data with personal data received from other sources, except as permitted by Applicable Law;
(d) the Company will provide the level of privacy protection required by Applicable Law and will notify the Customer if it determines that it can no longer meet this obligation; and
(e) the Company acknowledges the Customer's right to take reasonable and appropriate steps to stop and remediate unauthorized use.
The Company certifies that it understands the restrictions in this Article and will comply with them.
Article 17 (Special Provisions on AI Services)
1. Third-party AI providers that process Customer Personal Data when the AI Services are used are sub-processors under this DPA and are listed in Annex 3.
2. The Company will ensure, through contracts, the relevant provider's terms or settings, that third-party AI providers do not use Customer Personal Data to train artificial intelligence models (Article 33(4) of the Terms), and will use reasonable efforts to ensure that the providers' data retention periods do not exceed what is necessary to provide the Service.
Article 18 (Liability)
Each party's liability under this DPA is subject to the limitations of liability in Article 27 of the Terms. However, this does not apply to the extent that a transfer mechanism incorporated under Article 14 or Applicable Data Protection Law does not permit the limitation of liability toward data subjects.
Article 19 (Term, Governing Law and Miscellaneous)
1. This DPA remains in effect for as long as the Company processes Customer Personal Data and continues to apply after termination of the Agreement for as long as the Company retains Customer Personal Data.
2. The governing law and dispute resolution for this DPA are governed by Article 32 of the Terms. However, a transfer mechanism incorporated under Article 14 is governed by the governing law and jurisdiction specified in that mechanism.
3. The Company may amend this DPA to the extent necessary as a result of amendments to Applicable Data Protection Law, decisions of supervisory authorities or changes to transfer mechanisms, and will give advance notice of any amendment that is unfavorable to the Customer in accordance with Article 3 of the Terms.
4. At the Customer's request, the Company will provide a signed copy of this DPA (Article 7(4) of the Terms). The signed copy will have the same content as this DPA, and whether or not it is signed does not affect the validity of this DPA.
5. This DPA is prepared in Korean and English, and Article 42 of the Terms applies mutatis mutandis to its interpretation.
Effective Date: November 1, 2026
Privacy Contact: support@morningmate.com
Annex 1. Details of Processing (Annex I of the EU SCCs)
A. Parties
Category | Details |
|---|---|
Data exporter | The Customer that uses the Service having agreed to the Terms (name, address, contact person and contact details are as registered by the Customer in the Service) Role: controller (processor where the Customer processes on behalf of a third party) Signature and date: deemed signed when the Customer agrees to the Terms |
Data importer | Madrascheck Inc. (Republic of Korea) Address: 14F, 220 Yeongsin-ro, Yeongdeungpo-gu, Seoul, Republic of Korea Contact person's name, position and contact details: Chief Privacy Officer, support@morningmate.com Activities: development of the Service, operation of the hosting environment, maintenance, security and technical support Role: processor Signature and date: deemed signed on the effective date of the Terms |
B. Description of Processing and Transfer
Item | Details |
|---|---|
Categories of data subjects | The Customer's Members (employees, Administrators, etc.), Guests invited by the Customer, and third parties whose data is contained in data entered into the Service by the Customer, such as the Customer's business partners |
Categories of personal data | Name, email address, telephone number, affiliation, job title and Organization Chart information, profile photo, account identifiers, posts, comments, messages, Wiki Documents, Files and their metadata, schedule information, AI Services inputs and outputs, and access logs generated in the course of using the Service (IP address, device information, date and time of access) |
Sensitive data | The Company does not intend to process sensitive data (special categories of personal data). If the Customer enters such data, the Customer must ensure that it has a basis for processing under Applicable Data Protection Law, and the Company will apply the security measures in Annex 2 to such data in the same way. |
Frequency of the transfer | Continuous for the duration of use of the Service |
Nature of the processing | Collection, storage, hosting, backup, replication, search and indexing, display, transmission, preview conversion, summarization, search and generation through the AI Services, viewing for customer support purposes, and deletion |
Purpose of the processing | Provision, maintenance, security and customer support of the Service under the Terms (including Wiki, Projects, Tasks, Calendar, Drive, Teams and Repattern AI) |
Retention period | The term of the Agreement and the return and deletion period under Article 12 of this DPA |
Transfers to sub-processors | Transfers are made to the sub-processors listed in Annex 3 within the scope of the processing purposes and durations specified for each. |
C. Competent Supervisory Authority
EEA: where the data exporter is established in an EU Member State, the supervisory authority of the Member State responsible for ensuring compliance by the data exporter with the GDPR as regards the data transfer; where the data exporter is not established in an EU Member State but falls within the territorial scope of application of the GDPR in accordance with Article 3(2) and has appointed a representative pursuant to Article 27(1) of the GDPR, the supervisory authority of the Member State in which the representative is established; where the data exporter is not established in an EU Member State but falls within the territorial scope of application of the GDPR in accordance with Article 3(2) without however having to appoint a representative pursuant to Article 27(2) of the GDPR, the supervisory authority of one of the Member States in which the data subjects whose personal data is transferred under this DPA are located. United Kingdom: the Information Commissioner's Office (ICO). Switzerland: the Federal Data Protection and Information Commissioner (FDPIC).
Annex 2. Technical and Organizational Security Measures (Annex II of the EU SCCs)
Area | Measures |
|---|---|
Encryption | Data in transit is encrypted using TLS 1.2 or higher, and data at rest is encrypted using the managed encryption features of the cloud infrastructure. |
Access control | Role-based access control and the principle of least privilege are applied, and multi-factor authentication (MFA) is required for access to production systems. Access rights are revoked without delay upon departure or change of role, and are reviewed periodically. |
Customer-side controls | Features are provided that allow Workspace Administrators to configure Member permissions, external sharing and Guest access. |
Logging and monitoring | Records of access to and key operations on production systems are retained and monitored to detect abnormal access. |
Availability and recovery | Data is backed up regularly, and recovery procedures are maintained for use in the event of an outage. |
Vulnerability management | Security patches are applied in a timely manner, and vulnerability assessments are carried out regularly. |
Secure development | Security-conscious development procedures, such as code review, are maintained, and production and development environments are separated. |
Incident response | Personal Data Breach response procedures are established and maintained, and the Customer is notified in accordance with Article 10 of this DPA. |
Personnel security | Personnel with access to Customer Personal Data are subject to confidentiality obligations and receive regular security and data protection training. |
Physical security | Physical security of data centers is governed by the security framework of the cloud infrastructure provider (AWS). |
Sub-processor management | The security level of each sub-processor is reviewed before engagement, and data protection obligations substantially equivalent to those in this DPA are imposed by contract. |
Data minimization and deletion | Only the data necessary for processing by the AI Services is transmitted, and data is deleted in accordance with Article 12 of this DPA. |
Annex 3. Sub-processors
The sub-processors that process Customer Personal Data as at the date this DPA is entered into are listed below. Subsequent changes are as reflected in this Annex 3 as updated by the Company.
Sub-processor | Contracting entity, address and contact details | Purpose of processing | Processing location |
|---|---|---|---|
Amazon Web Services | Amazon Web Services, Inc., 410 Terry Avenue North, Seattle, WA 98109, USA | Service hosting, data storage and backup | United States and Japan |
OpenAI | OpenAI, L.L.C., 1455 3rd Street, San Francisco, CA 94158, USA / privacy@openai.com | AI Services processing | United States |
Anthropic | Anthropic, PBC, 548 Market Street, PMB 90375, San Francisco, CA 94104, USA / privacy@anthropic.com | AI Services processing | United States |
Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA | AI Services processing | United States | |
Perplexity | Perplexity AI, Inc., San Francisco, CA, USA | AI Services processing (search-based responses) | United States |