Legal
Data processing addendum
For customers whose use of Mongeflow involves personal data subject to the GDPR or comparable laws, our data processing addendum (DPA) governs how we process that data on your behalf.
Last updated: 2 August 2026
What the DPA covers
The DPA describes: the subject matter and duration of processing; the nature and purpose of processing; the types of personal data and categories of data subjects; each party's obligations as controller and processor; confidentiality commitments for personnel; security measures; subprocessor use and objection rights; international transfer mechanisms; assistance with data subject requests; breach notification; and deletion or return of customer data at termination.
Customer data commitments
Customer decision data and uploaded files are processed only to provide the service, on documented instructions. Customer content is not used to train AI models. Organization isolation is enforced at the database layer.
Subprocessors
The current subprocessor list is published on the subprocessors page. The DPA includes advance notice of material subprocessor changes and a right to object.
How to execute a DPA
Contact LEXINTELI LLC via the contact page with your organization name and the email of the signatory. We will send the current addendum for signature. Enterprise agreements may incorporate the DPA directly.