MCModGen · Legal · DPA

Data Processing Agreement

Plain-English overview of how personal data may be processed when MCModGen is used for business purposes.

Updated August 15, 20267 sections
§

Overview

This Data Processing Agreement describes the current MCModGen processing model for business use. A separately executed agreement may add customer-specific terms before public enterprise use.

In a typical DPA, the customer acts as the Controller and MCModGen (or its operator) acts as the Processor when processing personal data on the customer's behalf.

§

Scope & Purpose

  • Applies to personal data processed in connection with MCModGen services
  • Covers account management, service delivery, support, analytics, security monitoring, and AI-assisted generation workflows
  • Covers the account holders, beta testers, and business users whose data is processed through the service
§

Processing Activities & Data Categories

  • Account and authentication data
  • Billing/payment-related records (if applicable)
  • Usage and technical telemetry
  • Prompt inputs, generated outputs, and generation logs
  • Support and communication records
  • Service configuration and operational data relevant to product usage
§

Sub-processors

MCModGen uses the providers below to operate the current production service. Provider legal names, regions, and processing roles will be confirmed in any separately executed customer agreement.

  • OpenRouter (current default AI gateway) and any downstream model providers used through your configured AI pipeline (for example, providers selected via OpenRouter)
  • Vercel for frontend hosting, deployment, and delivery infrastructure
  • Google Cloud and Firebase for authentication, database, Cloud Run execution, private object storage, and secret management
  • Google Analytics 4, only after visitor consent, for explicit pageview reporting with Enhanced Measurement and advertising features disabled

Each sub-processor should be bound by appropriate confidentiality, security, and data-processing obligations.

  • Process data only on documented instructions
  • Maintain confidentiality and appropriate safeguards
  • Assist with compliance obligations where required
  • Flow down equivalent protections to their own sub-processors when applicable
§

Security Measures

  • Encryption in transit and at rest (where appropriate)
  • Access controls and authentication protections
  • Security monitoring, patching, and incident response procedures
  • Operational policies, training, and periodic security reviews
§

Incident Response & Breach Notification

  • Investigate and contain incidents quickly
  • Notify affected customers/parties without undue delay, subject to legal and contractual requirements (for example, within 72 hours if your final policy or applicable law requires it)
  • Provide updates on scope, impact, and mitigation efforts as information becomes available
  • Document remediation steps and post-incident improvements
§

Data Subject Requests, Retention, and Audits

  • Assist customers with data subject requests where applicable (access, correction, copies, etc.)
  • Retain account, build, share, and billing records as needed to provide the service, meet legal and security obligations, and honor user deletion controls
  • Set audit cooperation terms and reasonable audit conditions in any separately executed customer agreement
  • Set data-location, transfer-safeguard, and governing-law terms in any separately executed customer agreement
Continue reading