Data Processing Agreement (DPA)
Personal data processing agreement under Article 28 GDPR for the Munwyn Council service.
Personal data processing agreement
concluded under Article 28 of Regulation (EU) 2016/679 of the European Parliament and of the Council (the “GDPR”).
1. Parties
Processor: Ladislav Votroubek, a sole trader under Czech trade law, Company ID (IČO) 88930653, registered office Vršovická 796/37, 101 00 Prague 10, Czech Republic, not registered in the Commercial Register, operator of the Munwyn service (the “processor” or “provider”).
Controller: the customer — the company or sole trader that has subscribed to the Munwyn Council service (the “controller” or “customer”). The controller’s identity follows from the order or from the billing details entered at purchase.
This agreement is an integral part of the agreement on the provision of the Munwyn Council service (the “main agreement”) and is concluded at the moment the service is subscribed to. Written form is preserved by electronic acceptance; on request the provider will send a copy for signing.
2. Subject matter and duration
The subject matter of this agreement is the processing of personal data by the processor on behalf of the controller to the extent necessary to provide the Munwyn Council service. The agreement lasts for the duration of the main agreement and thereafter for the period necessary to return and erase the data under Section 10 of this agreement.
3. Nature and purpose of the processing
The nature of the processing is the storage, structuring, retrieval, analysis and display of content created by the controller’s users within the company spaces of the Munwyn Council service, including automated AI analysis (for example challenge sessions, contradiction detection, the graveyard of initiatives). The purpose of the processing is exclusively the operation of the Munwyn Council service for the controller; the processor does not use the data for its own purposes or for training AI models.
4. Categories of data subjects and categories of personal data
4.1 Categories of data subjects
- employees and collaborators of the customer to whom the customer has granted access to the company spaces.
4.2 Categories of personal data
- identification and contact data of users (name, email address, account identifier),
- the content of company thoughts and comments, including metadata (time of creation, author, connections),
- technical records necessary for operation and security (audit log, access records).
Users’ private thoughts (the “My Mind” space) are not part of the company spaces, the controller has no access to them and they are not covered by this agreement; in relation to them the provider acts towards the user under its own terms of service.
5. Controller’s instructions
The processor processes personal data only on documented instructions from the controller, including instructions concerning transfers to third countries. The main agreement, this agreement and the settings the controller makes in the service administration are considered documented instructions. If the processor considers that an instruction infringes the GDPR or other legal provisions, it shall inform the controller without undue delay.
6. Confidentiality
The processor shall ensure that persons authorised to process the personal data have committed themselves to confidentiality, unless they are under an appropriate statutory obligation of confidentiality. The confidentiality obligation survives the termination of this agreement.
7. Security
The processor shall implement and maintain technical and organisational measures under Article 32 GDPR appropriate to the risk of the processing. The current description of the measures (encryption, backups, access control, data location in the EU) is published on the Trust & security page (TOMs), which forms an annex to this agreement. A material reduction of the security level is considered an amendment of the agreement.
8. Subprocessors
The controller grants the processor a general authorisation to engage subprocessors. The current list of subprocessors is published on the Trust & security page.
- The processor shall notify the controller of intended changes (addition or replacement of a subprocessor) by email at least 30 days in advance; the controller has the right to object to the change. If no agreement is reached, the controller may terminate the main agreement as of the effective date of the change.
- The processor shall impose on each subprocessor, by contract, the same data protection obligations as arise from this agreement; the processor remains fully liable to the controller for the performance of the subprocessors’ obligations.
- Transfers of personal data to third countries (in particular to the USA for AI inference and transactional email) are based on Standard Contractual Clauses (SCC) under Article 46(2)(c) GDPR, or another valid transfer mechanism.
9. Assistance to the controller
Taking into account the nature of the processing, the processor:
- assists the controller by appropriate technical and organisational measures in fulfilling its obligation to respond to requests of data subjects under Chapter III GDPR (in particular the export and erasure of a user’s data),
- assists the controller in ensuring compliance with the obligations under Articles 32 to 36 GDPR (security, notification of personal data breaches to the supervisory authority and to data subjects, data protection impact assessments and prior consultation), taking into account the information available to it,
- notifies the controller of a personal data breach without undue delay, and at the latest within 72 hours of becoming aware of it; where the controller has subscribed to Council Pro or above, the deadline is 24 hours.
10. Erasure and return of data after the end of the service
After the end of the provision of the service, the processor shall, at the choice of the controller, return the personal data (an export in a machine-readable format) and subsequently delete all existing copies within 30 days, unless Union or Member State law requires further storage. On request, the processor shall confirm the erasure.
11. Audits
The processor shall make available to the controller all information necessary to demonstrate compliance with Article 28 GDPR and shall allow for and contribute to audits, including inspections, conducted by the controller or an auditor mandated by the controller. An audit may take place at most once a year, upon notice of at least 30 days, during normal business hours and in a manner that does not unreasonably disrupt the operation of the service; the costs of the audit are borne by the controller. The powers of supervisory authorities remain unaffected.
12. Liability
The parties’ liability for damage caused by processing is governed by Article 82 GDPR. Limitations of liability agreed in the main agreement also apply to this agreement to the extent permitted by law; they do not apply to damage caused intentionally or by gross negligence.
13. Final provisions
- This agreement is governed by the law of the Czech Republic; directly applicable provisions of the GDPR remain unaffected.
- In the event of a conflict between this agreement and the main agreement, this agreement prevails in matters of personal data protection.
- If any provision is invalid, the remaining provisions remain unaffected.
- Contact for data protection matters: .
DPA version: 1.0 · Effective date: 1 September 2026 · Last updated: 23 August 2026