Muster.

legal

Data Processing Agreement

Draft. This document is pending legal review and may change before it takes effect. Questions? Contact us.

Effective Date: [DATE] · Version: 1.0 (draft)


This Data Processing Agreement, including all schedules attached to it (the "DPA"), is incorporated into and forms part of the Muster Terms of Service or the Muster Master Subscription Agreement (MSA), as applicable (the "Agreement"), entered into between the Customer and [MUSTER LEGAL ENTITY NAME] ("Muster"). Capitalized terms used but not defined in this DPA have the meanings given in the Agreement. If this DPA conflicts with the Agreement, this DPA prevails.

1. Definitions

The terms "controller," "processor," "data subject," "process," and "supervisory authority," and their derivatives and analogous terms, have the meanings set out in applicable Data Protection Laws.

2. Rights and Obligations

2.1. Purpose. For the purposes of this DPA, Customer acts as the data controller and Muster acts as the data processor with respect to the Personal Data processed under the Agreement. Processing of Personal Data occurs only on the Customer's instructions and for no other purpose, and only for the duration of Customer's use of the Products and Services as set out in the Agreement, after which the Personal Data will be deleted in accordance with the process set out in the Agreement.

2.2. Processing Instructions. The parties agree that the Agreement and this DPA constitute the Customer's instructions for the processing of Personal Data. Each Party will comply with its respective obligations under the Data Protection Laws. Muster will assist Customer in complying with Customer's obligations under the Data Protection Laws. Muster's security commitments and Security Incident obligations with respect to Personal Data are specified in the Agreement, as is the process for deleting Customer Data, including Personal Data.

2.3. Audit. As required by Data Protection Law, Muster will keep a written record of its processing activities with respect to Personal Data. Upon reasonable prior notice, Muster will make available to Customer all information necessary to demonstrate compliance with this DPA, and will allow and contribute to audits (including on-site inspections) by Customer or an independent auditor mandated by Customer to verify Muster's compliance with its obligations under this DPA. Such audits are at Customer's expense, subject to appropriate confidentiality, conducted no more than once annually (unless a data breach or suspected material non-compliance has occurred), and carried out in a manner that minimizes disruption to Muster's business. In lieu of, or prior to, an on-site audit, Muster may first provide current [ISO 27001 certificates, SOC 2 attestation reports — REPLACE WITH MUSTER'S ACTUAL ATTESTATIONS], summary audit reports, or other relevant documentation to address the information requests, and Customer agrees to review these materials in good faith before requesting any further audit.

2.4. Security. Muster will establish and maintain appropriate administrative, technical, and physical safeguards and controls (the Technical and Organizational Measures) to: (i) ensure the ongoing confidentiality, integrity, availability, and resilience of the Products and Services and Customer Content; (ii) restore the availability of and access to Customer Content in a timely manner in the event of a physical or technical incident; and (iii) maintain a process for regularly testing, assessing, and evaluating the effectiveness of the technical and organizational measures for ensuring the security of processing through the Products and Services.

2.5. Confidentiality. Personal Data received by Muster under this DPA will be used only for the purposes of the Agreement, and Muster will not reproduce, disseminate, or disclose it to any person except its employees and authorized representatives (such as temporary staff, consultants, and contractors) who need to know it for the purposes of the Agreement and are bound by confidentiality obligations at least as restrictive as this Section. Muster will treat received Personal Data with the same degree of care it applies to its own information of similar sensitivity, and never less than reasonable care. The obligations in this Section survive for three (3) years following expiration or termination of the Agreement; Personal Data retained in backup media remains subject to this Section until deleted.

2.6. Permitted Disclosure. Muster may disclose received Personal Data: (i) as approved in writing and signed by Customer; (ii) as necessary to comply with any law or valid order of a court or other governmental body; or (iii) as necessary to establish the rights of Muster — provided that, in the case of (ii) and (iii), Muster promptly notifies Customer of the details of the required disclosure and provides all assistance reasonably required to enable steps to prevent the disclosure or to ensure it occurs subject to an appropriate obligation of confidence.

2.7. Liability. Muster's liability under this DPA is subject to the limitations and exclusions of liability set forth in the Agreement. Nothing in this DPA increases or expands Muster's liability beyond what the Agreement provides.

3. Subprocessors

3.1. Customer grants Muster general authorization to engage third parties to process Personal Data ("Subprocessors"). Muster will maintain an up-to-date list of Subprocessors at [SUBPROCESSOR LIST URL].

3.2. Muster will provide Customer at least fourteen (14) days' prior written notice of its intent to add or replace a Subprocessor. If Customer does not object in writing within fourteen (14) days of receiving the notice, Customer is deemed to have consented to the change. If Customer objects within the 14-day period and Muster does not agree with the objection, Customer may terminate the Agreement by providing written notice to Muster.

3.3. Muster will ensure each Subprocessor is appointed under a written contract imposing materially the same obligations with respect to Personal Data as this DPA, and will remain responsible for each Subprocessor's compliance with those obligations.

4. Data Requests

4.1. Taking into account the nature of the processing, Muster will provide reasonable assistance to Customer in responding to requests from data subjects under the Data Protection Laws.

4.2. If Muster becomes subject to a request from a public authority to disclose Personal Data, Muster will review the legality of the request before acceding to it. To the extent permitted by law, Muster will promptly notify Customer in writing of any such request. Muster will comply with such requests only if and to the extent it is lawfully compelled to do so, and will disclose only the minimum amount of Personal Data required.

5. GDPR

5.1. This Section applies only to the extent Personal Data contains personal information subject to the GDPR or UK GDPR, and applies in addition to the other requirements of the Agreement and this DPA. The parties agree that Muster may process Personal Data as part of providing the Services pursuant to the Agreement. Muster will inform Customer if it becomes aware that Customer's instructions infringe the GDPR or UK GDPR (as applicable), but has no obligation to actively monitor Customer's compliance.

6. International Data Transfers

6.1. Customer acknowledges and agrees that Muster may transfer, access, and process Personal Data on a global basis as necessary to provide the Services in accordance with the Agreement. Muster will make any such transfers in compliance with the Data Protection Laws.

6.2. The parties agree that the terms of the EU SCCs, Module Two (Controller to Processor), apply to any Restricted Transfer under the GDPR from Customer (as data exporter) to Muster (as data importer).

6.3. The parties agree that the terms of the UK SCCs apply to any Restricted Transfer under the UK GDPR from Customer (as data exporter) to Muster (as data importer).

6.4. To the extent Muster makes an onward transfer that is a Restricted Transfer, it will take such measures as necessary to ensure the transfer complies with the Data Protection Laws.

6.5. For the purposes of the EU SCCs: the chosen Member State for Clause 17 (governing law) is [MEMBER STATE — source uses Belgium] (unless EU data protection law requires the country of Customer's establishment), and the supervisory authority of [MEMBER STATE] shall act as the competent authority unless the SCCs require otherwise. Schedule 1 of this DPA is deemed Annex I of the EU SCCs (Modules 2 and 3, as applicable) and the UK Addendum, and Schedule 2 of this DPA is deemed Annex II (Technical and Organisational Measures) of the EU SCCs.

7. CCPA

7.1. This Section applies only to the extent Personal Data contains personal information subject to the CCPA, and applies in addition to the other requirements of the Agreement and this DPA.

7.2. Customer may, upon prior written notice to Muster, take reasonable and appropriate steps to stop and remediate any unauthorized use of Personal Data by Muster.

7.3. Muster processes Personal Data subject to the CCPA for or on behalf of Customer for the business purposes specified in the Agreement. Muster will not retain, use, or disclose Personal Data for any purpose other than performing the Services under the Agreement pursuant to the business relationship of the parties, or as otherwise permitted for Service Providers under the CCPA.

7.4. Muster will not sell Personal Data within the meaning of the CCPA. To the extent the CCPA applies, the parties acknowledge that Customer's transfer of Personal Data to Muster is not a "sale," and Muster provides no monetary or other valuable consideration to Customer in exchange for the Personal Data.

7.5. To the extent any Personal Data is deidentified by Muster or Customer, Muster will take reasonable measures to ensure the deidentified data cannot be associated with a consumer or household, and will not attempt to reidentify it.

7.6. Muster certifies that it understands the obligations and restrictions in this Section 7 and will comply with them.

8. General

8.1. Governing Law. Unless otherwise required, the parties agree that the Agreement is governed by and construed under the laws of [GOVERNING LAW JURISDICTION], without regard to conflict-of-law rules and excluding the United Nations Convention on Contracts for the International Sale of Goods. The parties irrevocably submit to the exclusive jurisdiction of the courts of competent jurisdiction in [VENUE], and will first attempt to settle any dispute amicably in good-faith negotiations before seeking enforcement from a court.

8.2. Updates. Muster may modify this DPA as required as a result of: (a) changes in Data Protection Laws; (b) a merger, acquisition, corporate reorganization, or similar event; or (c) the release of new features, functions, products, or services, or material changes to existing Services. Muster may make such modifications by posting a revised version at [DPA URL] or by otherwise notifying Customer. The modified DPA becomes effective upon posting, and Customer's continued use of the Services after the effective date constitutes agreement to be bound by the modified DPA.


Schedule 1: Data Processing Details

ItemDetails
Categories of data subjectsDevelopers, security engineers, and other employees of Customer who are users of Muster's services or otherwise contribute to Customer's codebases or manage Customer's assets.
Categories of personal dataFirst and last name, employer, title, and position; email addresses; user IDs on source code repositories and other services integrated with Muster by Customer's users; connection and/or localization data. [CONFIRM: add asset/DNS/cloud account identifiers if these can identify individuals.]
Sensitive data transferredNone.
Frequency of the transferOngoing.
Nature of the processingProcessing of certain personal data by the processor on behalf of the controller in relation to providing the controller's users access to the processor's platform for the purposes of analyzing software projects and other designated assets submitted to the platform.
Purpose(s) of the data transferProviding the Services pursuant to the Agreement.
Retention period (or criteria)As set forth in the Agreement.
Transfers to (sub-)processorsSee [SUBPROCESSOR LIST URL] for details.

Schedule 2: Technical and Organizational Measures to Protect the Personal Data

Muster may update or modify its Technical and Organizational Measures from time to time, provided such updates do not materially reduce the protection provided for Personal Data.

Accountability and certification — [internal governance protocols; external certifications maintained, if any (e.g., SOC 2, ISO/IEC 27001)]

Infrastructure security — [production database authentication; encryption key access restrictions; access control procedures for adding/modifying/removing users; production database, firewall, OS, and network access restrictions; access revocation on termination; unique authentication and SSH keys; MFA for remote access; encrypted remote access; intrusion detection; log management; network segmentation; firewall reviews; hardening standards]

Organizational security — [asset disposal; portable media encryption; anti-malware; employee background checks; code of conduct and confidentiality agreements for employees and contractors; performance evaluations; password policy; MDM; visitor procedures]

Product security — [encryption at rest; control self-assessments; annual penetration testing with remediation SLAs; encryption in transit; vulnerability management and system monitoring policies]

Internal security procedures — [BC/DR plans established and tested annually; cybersecurity insurance; configuration management; SDLC; whistleblower policy; board oversight of security and privacy risk; backup processes; communication of system changes to customers; defined security roles and responsibilities; annual policy reviews; external support system; quarterly access reviews; documented access requests; incident response plan tested annually; incident response policies; physical access processes; annual data center access reviews; annual risk assessments; risk management program; vendor management program with annual reviews]

Data and privacy — [data retention and disposal procedures; customer data purged upon leaving the service; data classification policy]