Legal
Effective: April 2026 · Incorporated into the Terms of Service
This Data Processing Agreement ("DPA") governs the processing of personal data by Mnemexa ("Processor") on behalf of the customer ("Controller") in connection with the Mnemexa API platform and services.
Mnemexa acts as a data processor when processing personal data that you, as the data controller, submit via the API. We process this data solely on your instructions and in accordance with applicable data protection law, including the GDPR and, where applicable, UK GDPR and other regional laws.
In this DPA, the following terms have the meaning given to them under applicable data protection law:
You are the data controller for all personal data you submit to the Mnemexa API. You are responsible for ensuring you have a lawful basis for processing, providing required notices to data subjects, and complying with your own data protection obligations under applicable law.
Mnemexa processes personal data only on your documented instructions, as set out in this DPA and the Terms of Service. We will not process personal data for any purpose other than providing the services, unless required by applicable law.
| Item | Details |
|---|---|
| Subject matter | Provision of the Mnemexa memory API platform |
| Duration | For the term of the customer's subscription |
| Nature of processing | Storage, retrieval, deduplication, importance scoring, and categorisation of memory entries |
| Purpose | Enabling AI agents to store and retrieve contextual memory on behalf of the Controller |
| Types of personal data | Any personal data contained in API payloads submitted by the Controller |
| Categories of data subjects | Customers, users, employees, or any individuals whose data the Controller submits via the API |
Mnemexa undertakes to:
The Controller provides general authorisation for Mnemexa to engage sub-processors. Mnemexa will inform the Controller of any intended changes to sub-processors, giving the Controller the opportunity to object. Current sub-processors include:
| Sub-processor | Purpose | Location |
|---|---|---|
| Cloud infrastructure provider | Hosting, compute, and database services | EU / US |
| OpenAI | LLM processing for importance scoring, deduplication, and reasoning features | US |
| Paddle | Payment processing and billing | UK / US |
All sub-processors are bound by data processing terms offering an equivalent level of protection to this DPA.
Where personal data is transferred outside the European Economic Area (EEA) or UK, Mnemexa will ensure the transfer is subject to appropriate safeguards, including Standard Contractual Clauses (Module 2: Controller to Processor) as adopted by the European Commission, or equivalent mechanisms recognised under applicable law.
For enterprise customers requiring executed SCCs, contact privacy@mnemexa.com.
Mnemexa implements the following technical and organisational measures:
Full technical details are available at mnemexa.com/security.
In the event of a personal data breach affecting your data, Mnemexa will notify you without undue delay and in any event within 72 hours of becoming aware of the breach, to the extent this is feasible. Notification will include:
To report a potential security incident: security@mnemexa.com
Upon termination or expiry of the services, Mnemexa will, at the Controller's election:
Billing records are retained for up to 7 years for legal and tax compliance. Anonymised usage metrics may be retained indefinitely.
Mnemexa will provide all information necessary to demonstrate compliance with this DPA and allow for audits conducted by the Controller or a mandated auditor, subject to reasonable notice (minimum 30 days) and agreement on scope and confidentiality. Mnemexa may satisfy audit obligations by providing up-to-date third-party audit reports or certifications where available.
Each party's liability under this DPA is subject to the limitations and exclusions set out in the Mnemexa Terms of Service. Nothing in this DPA limits either party's liability for death or personal injury caused by negligence, or for fraud or fraudulent misrepresentation.
For all data protection enquiries, DPA execution requests, and data subject rights requests: