Data Processing Agreement
Plain-English overview of how personal data may be processed when MCModGen is used for business purposes.
Overview
This Data Processing Agreement describes the current MCModGen processing model for business use. A separately executed agreement may add customer-specific terms before public enterprise use.
In a typical DPA, the customer acts as the Controller and MCModGen (or its operator) acts as the Processor when processing personal data on the customer's behalf.
Scope & Purpose
- Applies to personal data processed in connection with MCModGen services
- Covers account management, service delivery, support, analytics, security monitoring, and AI-assisted generation workflows
- Covers the account holders, beta testers, and business users whose data is processed through the service
Processing Activities & Data Categories
- Account and authentication data
- Billing/payment-related records (if applicable)
- Usage and technical telemetry
- Prompt inputs, generated outputs, and generation logs
- Support and communication records
- Service configuration and operational data relevant to product usage
Sub-processors
MCModGen uses the providers below to operate the current production service. Provider legal names, regions, and processing roles will be confirmed in any separately executed customer agreement.
- OpenRouter (current default AI gateway) and any downstream model providers used through your configured AI pipeline (for example, providers selected via OpenRouter)
- Vercel for frontend hosting, deployment, and delivery infrastructure
- Google Cloud and Firebase for authentication, database, Cloud Run execution, private object storage, and secret management
- Google Analytics 4, only after visitor consent, for explicit pageview reporting with Enhanced Measurement and advertising features disabled
Each sub-processor should be bound by appropriate confidentiality, security, and data-processing obligations.
- Process data only on documented instructions
- Maintain confidentiality and appropriate safeguards
- Assist with compliance obligations where required
- Flow down equivalent protections to their own sub-processors when applicable
Security Measures
- Encryption in transit and at rest (where appropriate)
- Access controls and authentication protections
- Security monitoring, patching, and incident response procedures
- Operational policies, training, and periodic security reviews
Incident Response & Breach Notification
- Investigate and contain incidents quickly
- Notify affected customers/parties without undue delay, subject to legal and contractual requirements (for example, within 72 hours if your final policy or applicable law requires it)
- Provide updates on scope, impact, and mitigation efforts as information becomes available
- Document remediation steps and post-incident improvements
Data Subject Requests, Retention, and Audits
- Assist customers with data subject requests where applicable (access, correction, copies, etc.)
- Retain account, build, share, and billing records as needed to provide the service, meet legal and security obligations, and honor user deletion controls
- Set audit cooperation terms and reasonable audit conditions in any separately executed customer agreement
- Set data-location, transfer-safeguard, and governing-law terms in any separately executed customer agreement