Legal
Data Processing Addendum
Last updated September 25, 2026
This Data Processing Addendum (including all Schedules attached hereto, the “DPA”) is incorporated into, and is subject to the terms and conditions of, the underlying customer agreement or terms of service (“Agreement”) between Reliable AI, Inc., a Delaware corporation (“Mubit”) and the entity identified as the customer in the Agreement or the relevant order form entered into with Mubit (“Customer”). This DPA applies to the extent Mubit’s Processing of Customer Personal Data is subject to the Data Protection Laws. This DPA shall be effective for the term of the Agreement.
-
Definitions
- “Controller” means the entity which determines the purposes and means of the Processing of Personal Data. The term “Controller” includes a “business” as defined under the CCPA.
- “Customer Content” means data, information and other materials submitted by or on behalf of Customer to the Service, including inputs to and outputs from the Service’s AI Tools.
- “Customer Personal Data” means the Personal Data described under Schedule 1 to this DPA.
- “Data Protection Laws” means all applicable laws and regulations, including laws and regulations of: (i) the European Union, the European Economic Area and their member states, Switzerland and the United Kingdom; (ii) the United States (including, but not limited to the California Consumer Privacy Act as amended by the California Privacy Rights Act (collectively, the “CCPA”) and other applicable state privacy laws); and (iii) any other jurisdiction in which the parties operate, in each case, applicable to the Processing of Personal Data under the Agreement and this DPA.
- “Data Subjects” means the individuals identified in Schedule 1 to this DPA.
- “EU SCCs” means the Standard Contractual Clauses approved with Commission Implementing Decision (EU) 2021/914 of June 4, 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council, as amended, supplemented, updated or replaced from time to time.
- “GDPR” means the General Data Protection Regulation (EU) 2016/679 together with any national implementing laws in any member state of the EEA (“EU GDPR”) and the EU GDPR as incorporated into the laws of the United Kingdom (“UK GDPR”).
- “Personal Data” and “Processing” will each have the meaning given to them in the Data Protection Laws. The term “Personal Data” includes “personal information,” “personally identifiable information,” and equivalent terms as such terms may be defined by the Data Protection Laws.
- “Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of or access to Customer Personal Data.
- “Processor” means the entity which Processes Personal Data on behalf of the Controller. The term “Processor” includes a “service provider” as that term is defined under the CCPA.
- “Sell” has the meaning given in the Data Protection Laws.
- “Service” means the services provided by Mubit to Customer pursuant to the Agreement.
- “Share” has the meaning given in the CCPA.
- “Sub-Processor” means another Processor engaged by a Processor to carry out Processing on behalf of a Controller.
- “UK Addendum” means the International Data Transfer Addendum to the EU SCCs, issued by the UK Information Commissioner for parties making restricted transfers, which entered into force on 21 March 2022 (collectively, with the EU SCCs, the “SCCs”).
Capitalized terms not otherwise defined herein shall have the meaning given to them in the Agreement.
-
Processing of Customer Personal Data
- Customer is a Controller of Customer Personal Data and Mubit is a Processor of Customer Personal Data. If Customer is itself acting as a Processor for Customer Personal Data on behalf of a Controller of such data, Mubit will Process such data as a Sub-Processor to Customer. The details of Mubit’s Processing of Customer Personal Data are described in Schedule 1 to this DPA.
- Mubit will only Process Customer Personal Data as a Processor on behalf of and in accordance with Customer’s prior written instructions, including any instructions provided through Customer’s use of the Service. Customer hereby instructs Mubit to Process Customer Personal Data to the extent necessary to provide the Service as set forth in the Agreement and this DPA. Mubit Processes Customer Personal Data only to provide the Service under Customer’s documented instructions, unless otherwise required by applicable law. Mubit shall not use Customer Content or Customer Personal Data for model training or product improvement unless Customer expressly agrees in writing and this DPA permits that Processing. Mubit may use aggregated or de-identified information to improve its products and services only where the information does not identify, and cannot reasonably be used to identify, Customer or any individual. Creating that information from Customer Personal Data remains subject to Customer’s documented instructions and this DPA. Mubit shall not (1) retain, use, or disclose Customer Personal Data other than as needed to provide the Service under Customer’s documented instructions and this DPA, or as required by Data Protection Laws; (2) retain, use, or disclose Customer Personal Data outside of the direct business relationship between Customer and Mubit, including by combining Customer Personal Data with Personal Data Mubit receives from third parties, other than Customer, except as permitted by the Data Protection Laws; or (3) Sell or Share Customer Personal Data. Upon notice to Mubit, Customer may take reasonable and appropriate steps to remediate Mubit’s use of Customer Personal Data in violation of this DPA.
- Mubit will immediately inform Customer if, in its opinion, an instruction from Customer infringes the Data Protection Laws. If applicable laws preclude Mubit from complying with Customer’s instructions, Mubit will inform Customer of its inability to comply with the instructions, to the extent permitted by law.
- Each of Customer and Mubit will comply with their respective obligations under the Data Protection Laws. Mubit shall notify Customer if it determines that it cannot meet its obligations under the Data Protection Laws. Customer has the right to take reasonable steps to ensure that Mubit uses Customer Personal Data in a manner consistent with Customer’s obligations under Data Protection Laws by exercising Customer’s audit rights in Section 10 of this DPA.
-
Cross-Border Transfers of Personal Data
- With respect to Customer Personal Data originating from the European Economic Area (“EEA”), the United Kingdom (the “UK”) or Switzerland that is transferred from Customer to Mubit, the parties agree to comply with the general clauses and with “Module Two” (Controller to Processor) and “Module Three” (Processor to Processor) of the EU SCCs, as applicable, which are incorporated herein by reference, with Customer as the “data exporter” and Mubit as the “data importer.”
-
For purposes of the EU SCCs the parties agree that:
- The optional docking clause 7 of the EU SCCs will not apply.
- In clause 9 of the EU SCCs, option 2 will apply and the time period for prior notice of Sub-Processor changes will be as set forth in Section 5.2 of this DPA.
- The optional language in clause 11 of the EU SCCs will not apply.
- In clause 17 of the EU SCCs, option 1 applies and the EU SCCs shall be governed by the laws of Ireland.
- In clause 18(b) of the EU SCCs, the parties agree to submit to the jurisdiction of the courts of Ireland.
- In Annex I, Section A (List of Parties) of the EU SCCs, (i) the Customer is the data exporter and Mubit is the data importer and their identity and contact details and, where applicable, information about their respective data protection officer and/or representative in the EEA are those set forth in this DPA or as otherwise communicated by each party to the other party; (ii) Customer is a Controller (under “Module Two” of the EU SCCs) or Processor (under “Module Three” of the EU SCCs), and Mubit is a Processor; (iii) the activities relevant to the data transferred under the EU SCCs relate to the provision of the Service pursuant to the Agreement; and (iv) entering into this DPA shall be treated as each party’s signature of Annex I, Section A, as of the effective date of this DPA.
- In Annex I, Section B (Description of Transfer) of the EU SCCs: (i) Schedule 1 to this DPA describes Mubit’s Processing of Customer Personal Data; (ii) the frequency of the transfer is continuous (for as long as Customer uses the Service); (iii) Customer Personal Data will be retained in accordance with Clause 8.5 of the EU SCCs and this DPA; (iv) Mubit uses the Sub-Processors described in Section 5.2 of this DPA to support the provision of the Service.
- In Annex I, Section C (Competent Supervisory Authority) of the EU SCCs, the competent supervisory authority identified in accordance with Clause 13 of the EU SCCs is the competent supervisory authority communicated by Customer to Mubit.
- In Annex II of the EU SCCs, data importer has implemented and will maintain appropriate technical and organizational measures to protect the security, confidentiality and integrity of Customer Personal Data as described on Schedule 2.
- If the transfer of Customer Personal Data is subject to the Swiss Federal Act on Data Protection (“FADP”), the parties agree to rely on the EU SCCs with the following modifications: (i) the Federal Data Protection and Information Commissioner (FDPIC) will be the competent supervisory authority under Clause 13 of the EU SCCs; (ii) the parties agree to abide by the GDPR standard in relation to all Processing of Customer Personal Data that is governed by the FADP; (iii) the term “Member State” in the EU SCCs will not prevent Data Subjects who habitually reside in Switzerland from initiating legal proceedings in Switzerland in accordance with Clause 18(c) of the EU SCCs; and (iv) references to the ‘GDPR’ in the EU SCCs will be understood as references to the FADP.
-
With respect to transfers from Customer to Mubit of Customer Personal Data
originating from the UK, the parties agree that the UK Addendum will
complement the EU SCCs to the extent required under Data Protection Law.
The UK Addendum is incorporated herein by reference. The parties agree that
the UK Addendum is completed as follows:
-
For the purpose of Part 1 of the UK Addendum:
- Table 1 (Parties): the start date is the effective date of the Agreement, the exporter is the Customer and the importer is Mubit, the table is deemed to be completed with the information set out in Section 3.2 of this DPA, and by signing this DPA, parties are deemed to have signed the UK Addendum.
- Table 2 (Selected SCCs, Modules and Selected Clauses): the “Approved EU SCCs” which the UK Addendum is appended to are the EU SCCs incorporated into this DPA and completed as set out in Section 3.2 of this DPA.
- Table 3 (Appendix Information): the information requested in Annex 1 is provided in Sections 3.2.6 and 3.2.7 of this DPA; the security measures requested in Annex 2 are described in Schedule 2 to this DPA; the list of Sub-Processors is available as described in Section 5.2 of this DPA.
- Table 4: both the data importer and the data exporter may end the UK Addendum as set out in section 19 of the UK Addendum.
- The competent supervisory authority for data transfers in connection with the UK Addendum will be the Information Commissioner’s Office.
-
For the purpose of Part 1 of the UK Addendum:
-
Confidentiality and Security
- Mubit will require Mubit’s personnel who access Customer Personal Data to commit to protect the confidentiality of Customer Personal Data.
- Mubit will implement commercially reasonable technical and organizational measures, as further described in Schedule 2 to this DPA, that are designed to protect against accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data.
- To the extent required by Data Protection Laws, Mubit will provide Customer with reasonable assistance as necessary for the fulfilment of Customer’s obligations under Data Protection Laws to maintain the security of Customer Personal Data.
-
Sub-Processing
- Customer hereby authorizes Mubit to appoint (and permit each Sub-Processor appointed in accordance with this Section 5 to appoint) Sub-Processors in accordance with this Section 5.
- The Sub-Processors appointed by Mubit as at the date of this DPA are set out at Schedule 3 (“Sub-Processors List”). Mubit will inform Customer of any intended changes concerning the addition or replacement of any appointed Sub-Processors (a “New Sub-Processor”) at least ten (10) days in advance, along with reasonably detailed information about such New Sub-Processor by sending an email notification.
- Customer will have an opportunity to object in writing to the appointment of a New Sub-Processor within ten (10) business days after receipt of notice of a New Sub-Processor in accordance with Section 5.2, provided that such objection must be on reasonable, substantial grounds, directly related to such New Sub-Processor’s ability to comply with substantially similar obligations to those set out in this DPA. If Customer does not so object, the engagement of the New Sub-Processor shall be deemed accepted by Customer. If Customer notifies Mubit in writing of any objections to the proposed appointment, the parties agree to discuss commercially reasonable alternative solutions in good faith. If the parties cannot reach a resolution within thirty (30) business days from the date of Mubit’s receipt of Customer’s written objection, the parties may terminate the Agreement and this DPA.
- Mubit will enter into an agreement with each Sub-Processor that imposes on the Sub-Processor, in substance, the same obligations that apply to Mubit under this DPA. Where any of its Sub-Processors fails to fulfil its data protection obligations, Mubit will be liable to Customer for the performance of its Sub-Processors’ obligations.
-
Data Subject Rights
Customer is responsible for responding to any Data Subject requests relating to Customer Personal Data (“Requests”). If Mubit receives any Requests during the term of the Agreement, Mubit will advise the Data Subject to submit the request directly to Customer. Mubit will provide Customer with reasonable assistance to permit Customer to respond to Requests.
-
Personal Data Breaches
Upon becoming aware of a Personal Data Breach affecting Customer Personal Data, Mubit will (i) promptly take measures designed to remediate the Personal Data Breach, and (ii) notify Customer without undue delay. Customer is solely responsible for complying with Personal Data Breach notification requirements applicable to Customer. Customer may request that Mubit reasonably assist Customer’s efforts to notify Personal Data Breaches to the competent data protection authorities and/or affected Data Subjects, if Customer is required to do so under the Data Protection Laws. Mubit’s notice of or response to a Personal Data Breach under this Section 7 will not be an acknowledgement or admission by Mubit of any fault or liability with respect to the Personal Data Breach.
-
Data Protection Impact Assessment; Prior Consultation
Customer may request reasonable assistance from Mubit in connection with conducting data protection impact assessments and consultation with data protection authorities if Customer is required to engage in such activities under applicable Data Protection Laws and the data protection impact assessment or consultation relate to the Processing by Mubit of Customer Personal Data.
-
Deletion of Customer Personal Data
Customer instructs Mubit to delete Customer Personal Data within ninety (90) days of the termination of the Agreement and delete existing copies unless applicable law requires otherwise. The parties agree that the certification of deletion described in the SCCs, if applicable, shall be provided only upon Customer’s written request. Notwithstanding the foregoing, Mubit may retain Customer Personal Data to the extent and for the period required by applicable laws provided that Mubit maintains the confidentiality of all such Customer Personal Data and Processes such Customer Personal Data only as necessary for the purpose(s) specified in the applicable laws requiring its storage.
-
Audits
- Customer may audit Mubit’s compliance with its obligations under this DPA up to once per year. In addition, Customer may perform more frequent audits (including inspections) in the event: (1) Mubit suffers a Personal Data Breach affecting Customer Personal Data; (2) Customer has genuine, documented concerns regarding Mubit’s compliance with this DPA or the Data Protection Laws; or (3) where required by the Data Protection Laws, including where mandated by regulatory or governmental authorities with jurisdiction over Customer Personal Data. Mubit will contribute to such audits by providing Customer or Customer’s regulatory or governmental authority with the information and assistance reasonably necessary to conduct the audit.
- To request an audit, Customer must submit a detailed proposed audit plan to legal@mubit.ai at least one month in advance of the proposed audit start date. The proposed audit plan must describe the proposed scope, duration, start date of the audit, and the identity of any third party Customer intends to appoint to perform the audit. Mubit will review the proposed audit plan and provide Customer with any concerns or questions (for example, Mubit may object to the third party auditor as described in Section 10.3, provide an Audit Report as described in Section 10.4, or identify any requests for information that could compromise Mubit confidentiality obligations or security, privacy, employment or other relevant policies). The parties will negotiate in good faith to agree on a final audit plan at least two weeks in advance of the proposed audit start date. Nothing in this Section 10 shall require Mubit to breach any duties of confidentiality.
- Mubit may object to third party auditors that are, in Mubit’s reasonable opinion, not suitably qualified or independent, a competitor of Mubit, or otherwise manifestly unsuitable. Customer will appoint another auditor or conduct the audit itself if the parties cannot resolve Mubit’s auditor objection after negotiating in good faith.
- If the requested audit scope is addressed in an SSAE 18/ISAE 3402 Type 2, ISO, NIST or similar audit report performed by a qualified third party auditor on Mubit’s systems that Process Customer Personal Data (“Audit Reports”) within twelve (12) months of Customer’s audit request and Mubit confirms there are no known material changes in the controls audited, Customer agrees to accept the Audit Report in lieu of requesting an audit of the controls covered by the Audit Report.
- The audit must be conducted at a mutually agreeable time during regular business hours at the applicable facility, subject to the agreed final audit plan and Mubit’s health and safety or other relevant policies. The audit may not unreasonably interfere with Mubit business activities.
- Any audits are at Customer’s expense and Customer will promptly disclose to Mubit any perceived non-compliance or security concerns discovered during the audit, together with all relevant details.
- The parties agree that the audits described in the SCCs, if applicable, shall be performed in accordance with this Section 10.
-
Liability
- Each party’s liability towards the other party under or in connection with this DPA will be limited in accordance with the provisions of the Agreement.
- Customer acknowledges that Mubit is reliant on Customer for direction as to the extent to which Mubit is entitled to Process Customer Personal Data on behalf of Customer in performance of the Service. Consequently, Mubit will not be liable under the Agreement for any claim brought by a Data Subject arising from (i) any action or omission by Mubit in compliance with Customer’s instructions or (ii) from Customer’s failure to comply with its obligations under the Data Protection Laws.
-
General Provisions
With regard to the subject matter of this DPA, in the event of inconsistencies between the provisions of this DPA and the Agreement, the provisions of this DPA shall prevail. In the event of inconsistencies between the DPA and the SCCs, the SCCs will prevail.
This DPA is entered into and executed by Customer and Mubit through their acceptance of, and as part of, the Agreement.
Schedule 1 — Details of Processing
Categories of Data Subjects
This DPA applies to the Processing of Customer Personal Data relating to:
- Customer’s employees, contractors, and other authorized users of the Service (“Product Users”).
- Individuals whose Personal Data is Processed in connection with the Service, including individuals with whom Customer’s AI agents interact, as determined by Customer (“Other Data Subjects”).
Types of Personal Data
The extent of the Customer Personal Data Processed by Mubit is determined and controlled by the Customer in its sole discretion and includes:
- Names, email addresses, and any other Personal Data that may be transmitted through the Service by Product Users.
- Personal Data pertaining to Other Data Subjects transmitted through the Service, as determined by Customer.
Customer Content may contain personal data, including special-category data, if Customer is authorized to provide it and the parties have agreed in writing that the Service and applicable safeguards support that processing. Customer must not submit PHI unless Mubit has approved the use in writing and the parties have entered into a Business Associate Agreement. PHI means Protected Health Information.
Subject-Matter and Nature of the Processing
The subject-matter of Processing of Customer Personal Data by Mubit is the provision of the Service to the Customer. Customer Personal Data will be subject to those Processing activities which Mubit needs to perform in order to provide the Service pursuant to the Agreement.
Purpose of the Processing
Customer Personal Data will be Processed by Mubit for purposes of providing the Service under Customer’s documented instructions as set out in the Agreement and Section 2 of this DPA. Mubit will not use Customer Content or Customer Personal Data for model training or product improvement unless Customer expressly agrees in writing and this DPA permits it.
Duration of the Processing
Customer Personal Data will be Processed for the duration of the Agreement, subject to Section 9 of the DPA.
Schedule 2 — Security Measures
- Security Program. Mubit shall maintain commercially reasonable administrative, technical and physical safeguards that comply with applicable laws and are designed to protect the security, integrity, accessibility and confidentiality of any computer systems or services owned, leased or otherwise used by Mubit to use, access or connect to Customer’s systems or process Customer Personal Data. Mubit’s safeguards shall be designed to (i) protect against any anticipated threats or hazards to the security or integrity of the Customer Personal Data; and (ii) protect against unauthorized access to or use of the Customer Personal Data that could result in harm to Customer. Mubit shall reasonably and promptly cooperate with any Customer questionnaires or inquiries regarding the security of the Mubit Platform.
- Privacy Compliance. To the extent Mubit receives, has access to or processes personal information of Customer or its affiliates, agents, employees, representatives, customers or other third parties that is subject to applicable laws governing the collection, use, disclosure, security, processing and transfer of such information, Mubit will (i) comply with such laws strictly as a service provider and data processor hereunder, and (ii) maintain policies and procedures to meet or exceed the requirements of such laws. Mubit shall provide reasonable assistance to Customer as may be required for compliance with such laws, including where necessary, the execution of additional data processing and/or data transfer terms regarding such information.
- Personnel and Subcontractors. All Mubit employees and subcontractor employees who access or process Customer Personal Data (collectively “Personnel”) shall be subject to: (i) reasonable pre-employment screening; (ii) security and privacy training; and (iii) discipline for violations of information security or privacy requirements. If Mubit subcontracts any rights or obligations under the Agreement to a third party (each, a “Subcontractor”), Mubit will enter into written non-disclosure and data security agreements with such Subcontractor(s) that impose confidentiality and security obligations no less restrictive than those imposed on Mubit under the Agreement, and only engage Subcontractors that Mubit reasonably expects are suitable and capable of securing Customer Personal Data in accordance with the Agreement.
- Access Permissions. Mubit will implement strict access controls using role based permissions and use by default least access principles which restrict raw customer data to only the employees and other personnel that absolutely need access to perform their job. All personnel are required to use MFA with Authentication Apps and/or biometrics in order to access these elevated permissions. Password requirements are strict as well and enforced through an internal SSO service, e.g. Okta.
- Change Management. The code that is written at Mubit undergoes several code reviews and goes through unit and integration testing before it is deployed. Mubit will employ source code security auditing tools which prevent situations like private keys from being checked into the code base. GitHub is also utilized to identify packages that are out of date and that have vulnerabilities and to create pull requests to fix them.
- Data Encryption and Infrastructure. All Customer Personal Data is encrypted at rest (AES-256) and in transit (TLS 1.2+) across all backend services. The Mubit Platform will be protected behind private Virtual Private Clouds (VPCs) with NAT gateways that only allow web service API access. Mubit will maintain access-controlled logs for auditing and security monitoring, and monitor and alert on potential security incidents. Secrets necessary for Mubit’s systems’ regular functioning are securely kept within Google Cloud Secret Manager. Mubit production infrastructure is hosted on Google Cloud Platform (GCP) in the United States and European Union. Google Cloud manages physical security for that infrastructure. Mubit is SOC 2 Type I compliant.
- Vendor Management. Mubit will not use third party vendors to process Customer Personal Data that themselves do not meet strict SOC 2 security compliance. All vendors are reviewed in a centralized fashion in order to verify that they meet these requirements.
- Incident Response. Mubit will maintain a rigorously documented Incident Response Plan that serves as Mubit’s predefined procedure for handling potential security incidents. Any identified incidents including security incidents are root caused and resolved with the highest priority. Customers are always notified when an incident occurs and how it was resolved including the full documentation for that resolution. Mubit shall notify Customer within 72 hours of discovering any unauthorized access, use, disclosure or loss of Customer Personal Data (an “Incident”), in which case Mubit will reasonably cooperate with Customer to investigate the Incident, mitigate any potential harm caused by the Incident, comply with any legal or contractual obligations, and take appropriate measures to prevent a recurrence of such Incident.
- Asset Management. All computers issued by Mubit to its personnel are secured through MDM (Mobile Device Management). This gives Mubit the capability to lock any computer and wipe its data remotely if it is lost or stolen. The hard drives on all Mubit-managed laptops are encrypted at rest.
- Malware and Known Vulnerabilities. Mubit will take reasonable precautions to prevent transmission of a computer virus, malware, Trojan horse, worm, ransomware, or other malicious code (collectively, “Malware”) to Customer Personal Data. Mubit will maintain current industry standard endpoint protection and detection tools on Mubit systems and ensure those systems are maintained with up-to-date security patches, hotfixes, and other similar software or firmware changes. Mubit will notify Customer immediately if Malware is detected in a file or transmission sent to or received from Customer.
- Logical Separation. Mubit uses a multi-tenant architecture with strict logical isolation mechanisms in place. Each tenant’s data is logically segregated using unique identifiers and access controls within Mubit’s databases and storage systems. Access to data is strictly controlled using RBAC and tenant-scoped permissions. Every API request and database transaction is validated against a customer-specific identifier to ensure proper access controls. Internal services enforce tenant-specific restrictions to prevent unauthorized data access.
Schedule 3 — Sub-Processors
| Entity Name | Purpose of Processing | Location |
|---|---|---|
| Google Cloud Platform | Production cloud hosting and managed compute | United States and European Union regions |
| Clerk, Inc. | Authentication and organization/user identity management (names, emails, org membership) | US |
| Cloudflare, Inc. | Edge hosting / CDN for the console web applications | Global (US/EU edge) |
Mubit’s current list of Sub-Processors is made available to Customer, and Mubit will notify Customer of any intended changes in accordance with Section 5.2 of this DPA.