Last updated: July, 2026

Modash Data Processing Agreement (DPA)

This Data Processing Agreement (“DPA”) forms part of the Modash Terms of Service (the “Agreement”) entered into between Modash OÜ (“Modash”, “Processor”) and the customer entity agreeing to the Agreement (“Customer”, “Controller”).

By entering into the Agreement, Customer agrees to this DPA.

This DPA applies only to the extent that Modash processes Personal Data on behalf of Customer as a Processor under applicable Data Protection Laws.

1. Definitions

“Data Protection Laws” means the GDPR, UK GDPR, and any applicable data protection legislation.

“Personal Data”, “Controller”, “Processor”, “Data Subject”, and “Personal Data Breach” have the meanings given in the GDPR.

“Subprocessor” means any third party engaged by Modash to process Personal Data on behalf of Customer.

2. Scope and Roles

Customer acts as Controller.
Modash acts as Processor.

This DPA does not apply to processing activities for which Modash acts as an independent Controller, including but not limited to processing of publicly available creator data as describedin Modash’s Privacy Policy.

Modash shall process Personal Data:

● Only on documented instructions from Customer (including as set forth in the Agreement);
● For the purpose of providing the Services;
● In accordance with Data Protection Laws.
● If Modash reasonably believes that an instruction from Customer infringes applicable Data Protection Laws, Modash shall inform Customer without undue delay and may suspend implementation of the relevant instruction until the instruction is confirmed, modified or withdrawn.

3. Nature of Processing

Nature and Purpose
Modash provides influencer discovery, campaign management, analytics, outreach, and related services.

Duration of Processing
Modash shall process Customer Personal Data for the duration of the Agreement and for such additional period as necessary to comply with Customer's documented instructions or applicable law. Upon termination of the Services, Customer Personal Data shall be returned or deleted in accordance with Section 10 of this DPA.

Categories of Data Subjects
May include Customer representatives, end users, influencers engaged by Customer, and campaign participants.

Categories of Personal Data
May include names, business contact information, account data, campaign data, communication data, and usage data submitted to or processed through the Services.

Modash does not intentionally process special category personal data on behalf of Customer.
Customer agrees not to upload or submit special category data unless explicitly agreed inwriting.

4. Security Measures

Modash implements appropriate technical and organizational measures designed to ensure alevel of security appropriate to the risk, including:

● Encryption of Personal Data in transit and at rest;
● Access controls based on least privilege principles;
● Strong authentication and identity management controls;
● Secure software development lifecycle practices;
● Regular vulnerability scanning and security testing;
● Backup and disaster recovery procedures;
● Incident response procedures with designated security personnel;
● Ongoing monitoring of system confidentiality, integrity, and availability.

Modash maintains and periodically reviews documented technical and organisational measures designed to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the risks to the rights and freedoms of natural persons.

Modash may update its technical and organisational measures from time to time, provided that such updates do not materially reduce the overall level of protection afforded to Customer Personal Data.

Personnel Confidentiality. Modash shall ensure that all personnel authorized to process Customer Personal Data are subject to appropriate confidentiality obligations, whether contractual or statutory. Such obligations shall survive the termination of the individual's employment, engagement, or other relationship with Modash.

5. Subprocessors

5.1. Customer hereby provides Modash with a general authorization to engage Subprocessors to process Customer Personal Data on its behalf in connection with the provision of the Services.

5.2. Modash shall maintain an up-to-date list of its authorized Subprocessors at Customer authorizes Modash to engage Subprocessors listed at:
modash.io/legal/subprocessors.5.3. Modash will provide reasonable advance notice of any intended addition or replacement of a Subprocessor by updating the above list or by other reasonable means, thereby giving Customer the opportunity to raise reasonable data protection concerns before the new Subprocessor begins processing Customer Personal Data.

5.4. Modash shall ensure that each Subprocessor is bound by written contractual obligations providing a level of protection for Customer Personal Data that is substantially equivalent to those set out in this DPA, to the extent applicable to the services performed by the Subprocessor.

5.5. Modash shall remain responsible for the performance of its Subprocessors' obligations to the extent required under applicable Data Protection Laws.

6. International Transfers

Where Customer Personal Data is transferred to a country outside the European Economic Area, the United Kingdom or any other jurisdiction requiring an appropriate transfer mechanism under applicable Data Protection Laws, Modash shall ensure that such transfer is subject to appropriate safeguards in accordance with applicable Data Protection Laws.

Such safeguards may include, where applicable, the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, adequacy decisions, or any other lawful transfer mechanism recognized under applicable Data Protection Laws, including any successor or replacement mechanism.

7. Assistance to Customer

Taking into account the nature of processing, Modash shall provide reasonable assistance to Customer to enable compliance with Data Protection Laws, including:

● Assistance with responding to Data Subject rights requests;
● Assistance with taking into account the nature of the processing and the information available to Modash, in ensuring compliance with Customer's obligations relating to data protection impact assessments and prior consultation with competent supervisory authorities where required under applicable Data Protection Laws;
● Assistance with supervisory authority consultations where applicable.

8. Personal Data Breaches

Modash will notify you without undue delay after becoming aware of a personal data breach involving Your Data. Such notification will include, to the extent reasonably available at the time, the nature of the breach, the categories of data affected, the likely consequences, the measures taken or proposed to address the breach, and any information reasonably required by Customer to comply with applicable Data Protection Laws. Where all relevant information is not available at the time of the initial notification, Modash may provide such information in phases as it becomes available.

9. Audit and Compliance

9.1. Upon reasonable written request, Modash shall make available to Customer all information reasonably necessary to demonstrate compliance with this DPA and applicable Data Protection Laws. Where available, Modash's current ISO 27001 certification, or other independent third-party audit reports or certifications may be used to satisfy such requests.

9.2. Where the information provided by Modash is reasonably insufficient to demonstrate compliance with this DPA or applicable Data Protection Laws, Customer may, itself or through an independent third-party auditor, conduct an audit of Modash's processing of Customer Personal Data under this DPA.

9.3. Any audit conducted under this Section shall:

● be conducted upon reasonable prior written notice;
● take place during normal business hours;
● not unreasonably interfere with Modash's business operations;
● be subject to appropriate confidentiality obligations; and
● be conducted by an independent auditor that is not a competitor of Modash.

9.4. Nothing in this Section limits the rights of a competent supervisory authority under applicable Data Protection Laws.

10. Return and Deletion of Data

Upon termination or expiration of the Services, Customer may request the return of Customer Personal Data within thirty (30) days. Following such period, or once Customer confirms that the data has been returned, Modash shall delete Customer Personal Data, unless applicable law requires continued retention.

Modash shall ensure that Customer Personal Data held by its authorized Subprocessors is also deleted or returned in accordance with this Section, unless applicable law requires continued retention.

Customer Personal Data contained in backup systems may be retained until overwritten in the ordinary course of business, provided that such data remains protected in accordance with this DPA and is not further processed except as required by applicable law.

11. Liability

Liability arising out of or in connection with this DPA shall be subject to the limitations and exclusions of liability set forth in the Agreement.

12. Governing Law

This DPA shall be governed by the governing law specified in the Agreement.