Data Processing Agreement

Version 1.1 — September 17, 2026

This Data Processing Agreement (“DPA”) forms part of the Terms of Service or another agreement that expressly incorporates it (“Agreement”) between Mythos Software, LLC (“Mythos”) and the customer identified in that Agreement or the accepting account (“Customer”). It applies when Mythos processes personal data on Customer’s behalf to provide the agreed services (“Customer Personal Data”).

The DPA takes effect with the applicable Agreement. It does not make every customer a controller, convert every supplier into a subprocessor, or replace the Privacy Policy for processing where Mythos determines its own purposes. Contact privacy@mythos.new for a copy suitable for your procurement process or additional required transfer documentation.

1. Roles and instructions

Customer is the controller, or a processor authorized by its controller, of Customer Personal Data. Mythos acts as Customer’s processor or subprocessor, respectively. Each party complies with the data-protection laws applicable to its role.

Mythos processes Customer Personal Data only on documented instructions: the Agreement, this DPA, Customer’s authorized product settings and requests, and other instructions we accept in writing. If law requires other processing, we will inform Customer before processing unless that law prohibits notice. We will tell Customer if we believe an instruction infringes applicable data-protection law.

Customer is responsible for the lawfulness of its instructions, notices and rights to provide the data, and for consent where required. Customer controls the data it places in project content, connected services and published applications. Do not submit special-category data or criminal-offence data unless we have separately agreed appropriate processing and safeguards.

2. Purpose and duration

Processing is limited to providing and securing the services described in Annex A. Mythos does not use Customer Personal Data for unrelated advertising, sell it, or use it to train a general-purpose model for its own purposes.

Processing continues for the Agreement and any limited period needed to carry out return, deletion, security reconciliation or legally required retention. A retained record remains protected and is used only for its permitted purpose.

3. Confidentiality and security

People authorized to process Customer Personal Data must be bound by confidentiality duties and receive access appropriate to their responsibilities. Mythos maintains technical and organizational measures appropriate to the nature and risks of the processing, including the measures in Annex B. We may improve these measures without materially reducing protection.

No internet service can guarantee that every incident will be prevented. A product feature or provider certification is not a separate certification of Mythos.

4. Subprocessors

Customer generally authorizes the service providers identified for the applicable processing in the Subprocessors register. Mythos will bind a subprocessor to data-protection obligations appropriate to its work and at least as protective as required by applicable law and this DPA, and remains responsible for its performance of those obligations.

We will provide at least 30 days’ advance notice of a new subprocessor that will process Customer Personal Data, unless an urgent change is needed to maintain security or service and applicable law permits shorter notice. Customer may object before the stated effective date on reasonable data-protection grounds by contacting privacy@mythos.new. We will seek a reasonable solution. If no solution is available, Customer may stop the affected processing or terminate the affected service without a future-service penalty; we will address unused prepaid affected service under the Agreement and applicable law.

A connection Customer independently authorizes to its own external account is not automatically a Mythos subprocessor. Its role depends on the particular data flow and contractual relationship.

5. Requests, incidents and cooperation

Taking account of the nature of processing and available information, Mythos will assist Customer with applicable access, correction, deletion, restriction, portability and objection requests. We will not respond on Customer’s behalf without instructions, except where legally required. We may direct a requester to Customer and notify Customer of a request concerning its data.

Mythos will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. We will provide available information about the incident, affected data, likely consequences, mitigation and a contact point, and supply further information as it becomes available. Notification is not an admission of liability. Customer remains responsible for its own notifications to individuals and authorities unless law allocates that responsibility otherwise.

We will provide reasonable assistance with legally required security assessments, data-protection impact assessments and prior consultation, proportionate to the processing and information available to us.

6. Return and deletion

During the service, Customer may use the available export, project-source and deletion controls, and request assistance for data outside self-service export. On termination or Customer’s valid instruction, Mythos will return or delete Customer Personal Data at Customer’s choice, subject to applicable law.

Deletion can require reconciliation of an in-progress external operation or Customer action in a separately owned provider account. Mythos will identify an unresolved state rather than report it as complete. Completed deletion removes live content from the relevant systems; isolated backups expire under their applicable retention schedule and are protected from ordinary use. If restoration is necessary for recovery, applicable deletion instructions are reapplied.

Where law requires retention, we limit the data and processing to that requirement. Minimal security and execution records processed by Mythos for its own legally permitted purposes are separately described in the Privacy Policy; this is not permission to retain the original Customer content indefinitely.

7. Demonstrating compliance

Mythos will make available information reasonably needed to demonstrate compliance with this DPA and allow and contribute to audits required by applicable law, including inspections by Customer or its authorized independent auditor. The parties will reasonably coordinate scope, timing, confidentiality and security, without preventing legally required oversight or urgent investigation. An audit must protect other customers’ information and service availability.

Routine questions should first be sent to privacy@mythos.new so we can provide the relevant documentation and identify any additional inspection needed. We do not promise an independent certification or report that we have not obtained.

8. International transfers

The locations and provider boundaries are described in the Subprocessors register. Where an EEA transfer of Customer Personal Data to Mythos requires safeguards under Chapter V GDPR and no applicable adequacy decision covers it, the European Commission’s Standard Contractual Clauses in Decision (EU) 2021/914 (“SCCs”) are incorporated: Module Two applies to controller-to-processor transfers, and Module Three to processor-to-processor transfers.

For the applicable module: Clause 7 applies; Clause 9 uses general written authorization with the notice period in section 4; the optional wording in Clause 11 is not used; Clause 17 is governed by Irish law; the courts in Clause 18 are the courts of Ireland. Annex A below supplies the parties and processing description; Annex B supplies the security measures; the Subprocessors register identifies authorized recipients. The competent supervisory authority is determined under Clause 13. Customer supplies any information necessary to complete these details and, for Module Three, confirms its controller’s authorization.

For a restricted transfer governed by UK data-protection law, the parties incorporate the ICO’s International Data Transfer Addendum, version B1.0, in force 21 March 2022, including its mandatory clauses as lawfully revised. Table 1 uses the parties and contacts in Annex A and the DPA effective date; Table 2 uses the SCC modules and choices above; Table 3 uses Annexes A and B and the Subprocessors register. For Table 4, both exporter and importer may exercise the termination option when the approved addendum changes. Required customer identity, registration and contact information must be completed before the restricted transfer.

For transfers governed by Swiss data-protection law, references to GDPR are read as references to the Swiss Federal Act on Data Protection to the extent that law governs the transfer. The Swiss Federal Data Protection and Information Commissioner is the competent authority for that processing. For Swiss-only transfers, Clause 17 uses Swiss law and Clause 18 uses Swiss courts. Data subjects may enforce their rights at their habitual residence in Switzerland. Where GDPR also applies, its separate supervisory authority, Irish governing law and Irish court provisions above remain applicable to the GDPR transfer; these adaptations do not diminish GDPR protections.

The parties must assess the actual transfer and implement any required supplementary measures. Neither these clauses nor an EU hosting location alone establishes that every transfer is lawful. Contact privacy@mythos.new to complete customer-specific documentation.

Mandatory transfer clauses prevail over conflicting terms, including dispute and liability provisions. Otherwise this DPA controls over the Agreement concerning its subject matter.

Annex A — Parties and processing

Customer / data exporter: the customer identified in the accepting account or signed Agreement; its account or designated privacy contact; acting as controller or authorized processor. Its acceptance of the Agreement includes this DPA where applicable.

Mythos / data importer: Mythos Software, LLC, 2810 North Church Street, STE 90672, Wilmington, DE 19802, United States; privacy@mythos.new; acting as processor or subprocessor. Its acceptance of the Agreement includes this DPA.

ItemDescription
SubjectsCustomer’s authorized users, collaborators, contacts and people whose data Customer lawfully includes in content; visitors to Customer’s published sites where built-in analytics is enabled and collection is permitted.
DataIdentifiers and contact details included by Customer; prompts, messages, files, code and attachments; selected connected-service inputs and results; bounded visitor session/event identifiers and traffic attributes. Credentials are handled only for the authorized connection and are excluded from portable user exports.
ActivitiesReceiving, storing, organizing, retrieving, transmitting for authorized inference or connector actions, generating output, hosting requested content, collecting permitted traffic events, exporting, securing and deleting.
FrequencyOngoing or on demand while Customer uses the relevant feature. Visitor analytics only for an eligible published site with permitted collection.
PurposesProviding the selected development, collaboration, integration, hosting and analytics features according to Customer’s instructions.
RetentionProject/account content follows the relevant deletion boundary; analytics events become eligible for the scheduled bounded deletion sweep after 90 days; successful connector-result payloads become unavailable for replay after 30 days from completion and are erased through bounded maintenance or expired-result reads. Confirmed connection, project and account cleanup also erases the response payloads covered by that cleanup. Minimal identifiers, digests and outcome receipts may remain to prevent duplicate external actions. Unresolved external operations retain the evidence needed to reconcile their outcome. See Privacy for the distinction between live data, backups and minimal separate legal/security records.
Sensitive dataNot specifically requested or supported under this DPA; requires a separate agreement before submission.
Other service accountsCustomer-owned external services remain governed by Customer’s provider relationship; authorized Mythos processing of selected data remains within these instructions.

Annex B — Technical and organizational measures

  • Authenticated access and workspace/project authorization boundaries; restricted operator access according to responsibilities.
  • Encrypted transport for service communications and provider-managed protections for data at rest; encrypted stored connector credentials.
  • Separation of tenant data and controls around generated-code execution, preview artifacts and publishing.
  • Bounded, authorized external operations with durable identities to prevent accidental duplicate execution; reconciliation of uncertain outcomes.
  • Redaction of common secrets and sensitive content from error telemetry; no enabled session replay in the Mythos application.
  • Account/project deletion workflows, export controls, documented retention and handling of incomplete external cleanup.
  • Incident assessment, privacy-request handling, vendor review and change procedures described in Mythos’s operational documentation.

These measures describe the applicable control categories. They do not promise that all Customer data remains exclusively in one country, that every provider has zero retention, or that Mythos has an independent security certification.