Data Processing Addendum
For when you need it in writing that we handle your clients' data on your behalf and don't own any of it. It applies automatically — there's nothing to sign.
Not yet reviewed by a lawyer. This describes exactly what the software does and how it handles data, which is accurate. It has not been through legal review in Michigan. We would rather tell you that than let you assume otherwise.
When this applies
This addendum forms part of the Terms of Service and applies automatically to every customer. You do not need to request it or return a signed copy. If your own client requires a countersigned version, write to privacy@mogulxos.com and we will sign one.
The roles
You are the controller of the personal data you put into your workspace about your clients. Mogul to Mogul Consulting, LLC is your processor. We process that data only to provide the product to you, and only on your documented instructions — your use of the product is those instructions.
We are a separate controller for your own account data: your name, email, billing status and security records. That is covered by the Privacy Policy.
If we ever receive an instruction we believe breaks data protection law, we will tell you rather than carry it out.
What we process, and for whom
Subject matter: providing a CRM, client portal and project management product.
Duration: for as long as your account is open, and no longer.
Categories of data subject: your clients, and the individuals at your clients who use their portal.
Categories of personal data: name, email address, phone number, company, timezone, portal password hash, IP address, browser user agent, message content including full email bodies, form and intake responses, uploaded file contents, meeting bookings, invoices and payment records, and relationship-health scores derived from the above.
We do not ask for and do not intend to process special-category data. If your work involves it — health, biometric, or similar — you should satisfy yourself that this product is appropriate before putting it here, and write to privacy@mogulxos.com so we can talk about it.
Confidentiality and security
Everyone with access to personal data is bound by confidentiality. We maintain technical and organisational measures appropriate to the risk, described in the Security section of the Privacy Policy — including database-enforced tenant isolation, argon2id password hashing, hashed session tokens, encryption in transit, and access controls that give no employee a screen showing your clients.
Sub-processors
You authorise the sub-processors listed on the sub-processors page. Each is bound by written terms no less protective than these, and we remain responsible for what they do.
We will give you at least 30 days' notice before adding a new one. If you object on reasonable data-protection grounds, tell us within those 30 days and we will either not use them for your data or let you terminate and refund the unused part of what you have paid.
Helping you meet your obligations
- Data subject requests. Access, correction, export and erasure are all self-serve inside the product, so you can answer a request from your own client immediately and without us. If one comes to us directly, we will forward it to you rather than act on it.
- Breach notification. If we become aware of a personal data breach affecting your data we will notify you without undue delay and within 72 hours, with the detail you need to make your own notifications.
- Impact assessments. We will give you reasonable help with a DPIA or with a prior consultation, taking into account what we know about how the product works.
- Audit. We will make available the information needed to demonstrate compliance with this addendum, and answer reasonable written questions from you or your client.
Return and deletion
At any time during the agreement you can export everything in one file, and delete everything permanently, both from inside the product. On termination, deleting the account destroys all personal data immediately; if you do not delete it yourself we will erase it on written request. Encrypted backups age out within 30 days.
International transfers
Data is processed in the United States. Where personal data is transferred out of the UK, EEA or Switzerland, the transfer is made under the European Commission's Standard Contractual Clauses (and the UK Addendum where applicable), which are incorporated into this addendum by reference.
California
For the purposes of the CCPA as amended, we are a service provider. We do not sell or share personal information, we do not retain, use or disclose it for any purpose other than performing the services, and we do not combine it with information from other sources except as the CCPA permits.
Getting in touch
Anything on this page: privacy@mogulxos.com. Anything else: support@mogulxos.com.
Mogul to Mogul Consulting, LLC, Michigan, United States.