Snapshot 44965
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Legal Morphed Data Processing Agreement Last updated: May 2026 This standalone Data Processing Agreement (the “Agreement”) governs the Processing of Customer Data by Morphed Proprietary Limited (“Morphed”) on behalf of the Customer in connection with the Services. It forms part of, and is incorporated into, the Services Agreement between the parties. Draft for legal review — May 2026. 1. Definitions and Interpretation In this Agreement, unless the context otherwise requires, the following terms shall have the meanings set out below and cognate terms shall be construed accordingly: “Agreement” means this Data Processing Agreement (including any schedules hereto). “Controller” means the natural or legal person which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data, as defined in the GDPR and UK GDPR, and includes a “responsible party” as defined in section 1 of POPIA. “Customer” means the party identified as the customer or partner in the Services Agreement. “Customer Data” means Personal Data relating to the Customer and any Personal Data that is disclosed and/or submitted by the Customer or any Group Company to Morphed or otherwise collected and Processed by or for the Customer or any Group Company by Morphed in the course of providing the Services. “Data Protection Laws” means: (a) the General Data Protection Regulation (EU) 2016/679 (“GDPR”) (together with laws implementing or supplementing the GDPR in EU Member States, in each case as amended from time to time); (b) the GDPR as transposed into the national law of the United Kingdom by virtue of section 3 of the European Union (Withdrawal) Act 2018 (“UK GDPR”), and where the UK GDPR applies to the Processing of Personal Data under this Agreement, references to the GDPR and to provisions of the GDPR shall be construed as references to the UK GDPR and to the corresponding provisions of the UK GDPR, and references to EU or Member State law shall be construed as references to UK law; (c) the Protection of Personal Information Act 4 of 2013 (“POPIA”), as amended or replaced from time to time, and the regulations promulgated in terms of section 112(2) of POPIA; and (d) all other applicable laws, rules, regulations, and regulatory guidance relating to data protection and privacy in each jurisdiction where the Services are delivered. “Data Subject” has the meaning given to it in the GDPR, and for the purposes of POPIA includes both natural persons and juristic persons as contemplated in section 1 of POPIA. “Group Company” means any of the Customer’s subsidiaries, associates, and affiliated companies. “Information Regulator” means the supervisory authority in South Africa established in terms of POPIA. “Personal Data” has the meaning given to it in the GDPR and UK GDPR, and includes “personal information” as defined in section 1 of POPIA. “Personal Data Breach” has the meaning given to it in the GDPR, and includes a security compromise as contemplated under POPIA, being where there are reasonable grounds to believe that the Personal Data of a Data Subject has been accessed or acquired by any unauthorised person. “Process” (and “Processing”) has the meaning given to it in the GDPR, and includes any operation or activity concerning Personal Data as described in section 1 of POPIA, including the collection, receipt, recording, organisation, collation, storage, updating or modification, retrieval, alteration, consultation, use, dissemination, transmission, distribution, merging, linking, restriction, degradation, erasure, or destruction of Personal Data. “Processor” has the meaning given to it in the GDPR and UK GDPR, and includes an “operator” as defined in section 1 of POPIA. “Services” means the services described in the Services Agreement. “Services Agreement” means the agreement between the Customer and Morphed pursuant to which Morphed provides the Services, including any applicable subscription, order form, partner agreement, or the Website and Service Terms and Conditions (www.morphed.io). “Special Personal Information” means Personal Data concerning religious or philosophical beliefs, race or ethnic origin, trade union membership, political persuasion, health or sex life, biometric information, and criminal behaviour, to the extent that such information relates to the alleged commission by a Data Subject of an offence or any proceedings in respect of an offence committed by the Data Subject or the disposal of such proceedings, and includes “special categories of personal data” as defined in Article 9 of the GDPR. “Supervisory Authority” has the meaning given to it in the GDPR and UK GDPR, and includes the Information Regulator. In this Agreement (unless the context otherwise requires): (a) words importing persons shall include firms, companies, and bodies corporate and vice versa; (b) words importing the singular shall include the plural and vice versa; (c) words importing any one gender shall include each other gender; (d) construction of this Agreement shall ignore the headings and front matter (which are for reference only); (e) references to a numbered clause or schedule are references to the clauses and schedules of this Agreement so numbered; (f) any reference to a legislative provision shall be deemed to include any subsequent re-enactment or amending provision; and (g) capitalised terms used but not defined in this Agreement shall have the meanings ascribed to them in the Data Protection Laws or the Services Agreement, as the context requires. 2. Roles 2.1 The parties acknowledge and agree that, for the purposes of the Data Protection Laws, the Customer shall be the Controller (responsible party under POPIA) and Morphed shall be the Processor (operator under POPIA), in respect of any Customer Data Processed by Morphed during the course of performing the Services. Morphed acts as an independent Controller for its own account administration, billing, security, compliance, product improvement (using anonymised or aggregated data only), and support operations, and the Customer acknowledges that this Agreement does not apply to such independent Controller processing. 2.2 Morphed shall only Process the Customer Data in accordance with the Customer’s documented instructions (which may be specific instructions or instructions of a general nature as set out in this Agreement, the Services Agreement, or as otherwise notified by the Customer to Morphed from time to time), and for the purposes determined and communicated in writing by the Customer, unless required by applicable law to which Morphed is subject, in which case Morphed shall (to the extent permitted by law) inform the Customer of that legal requirement before Processing. 2.3 To the extent that the Customer Processes Personal Data about Morphed or any employees of Morphed for the purpose of the Services Agreement, Morphed hereby consents to the Customer Processing such Personal Data and undertakes that there is a justification in law for Morphed to disclose the Personal Data of its employees to the Customer for the purpose of the Services Agreement. 2.4 Morphed shall implement appropriate technical and organisational measures to protect Customer Data against unauthorised or unlawful Processing and against accidental loss, destruction, damage, alteration, or disclosure. Such measures shall be appropriate to the harm which might result from such unauthorised or unlawful Processing or accidental loss, destruction, or damage, and to the nature of the Customer Data to be protected, taking into account the state of the art and the costs of implementation. 2.5 Morphed shall take all reasonable steps to ensure the reliability of any employee, agent, or contractor who may have access to the Customer Data, ensuring in each case that access is strictly limited to those individuals who need to access the Customer Data as strictly necessary for the purposes of the Services, and ensuring that all such individuals: (a) are informed of the confidential nature of the Customer Data and are aware of Morphed’s obligations under this Agreement; (b) have undertaken appropriate training in relation to the Data Protection Laws (including POPIA); (c) are subject to binding obligations of confidentiality by virtue of their contract or office; and (d) are subject to user authentication and log-on processes when accessing the Customer Data. 3. Data Processing Terms — Operating Boundary Morphed prepares operational work, humans approve, Morphed executes safe approved fixes, and Morphed verifies recovery. Write-capable connector actions require explicit approval and audit logging before execution. 4. AI Routing Customer credentials, OAuth tokens, bearer tokens, and API keys are never sent to model providers. Model calls use the minimum context required for the approved task. OpenAI and Anthropic API data is not used for model training under the applicable provider terms. EU routing is used where enabled for the customer or partner deployment profile. Where EU-only routing is unavailable, Morphed minimises, pseudonymises or summarises data where the use case allows it. 5. Sub-processors 5.1 The Customer provides a general authorisation for Morphed to engage sub-processors in connection with the Services. Morphed’s current sub-processor register is maintained at www.morphed.io/sub-processors. Morphed shall give the Customer not less than 14 days’ prior written notice before adding or replacing a sub-processor (unless a signed addendum sets a different Customer-specific notice period). If the Customer objects to a new sub-processor on reasonable grounds relating to data protection within such notice period, the parties shall discuss the Customer’s concerns in good faith. If the parties are unable to resolve the objection within 14 days, the Customer may, as its sole and exclusive remedy, terminate this Agreement (and the affected Services only) on written notice to Morphed, and Morphed shall have no liability to the Customer in respect of such termination. 5.2 With respect to each sub-processor, Morphed shall, before the sub-processor first Processes the Customer Data: (a) carry out adequate due diligence on each sub-processor to ensure that it is capable of providing the level of protection for the Customer Data as is required by this Agreement, including sufficient guarantees to implement appropriate technical and organisational measures in such a manner that Processing will meet the requirements of the Data Protection Laws; (b) ensure that the contract between Morphed and each sub-processor includes terms which are substantially the same as those set out in this Agreement, and upon reasonable request, provide a summary of such terms to the Customer for its review; (c) insofar as that contract involves the transfer of Customer Data outside of South Africa, ensure that there is an appropriate justification under POPIA (including section 72 thereof) for the transfer; and (d) remain liable to the Customer for the Processing of Customer Data performed by its sub-processors to the extent required by Article 28(4) of the GDPR and section 21 of POPIA, subject to the limitations set out in this Agreement. Current Sub-processor Register The following vendors may process Customer Data on Morphed’s behalf depending on the deployment profile and enabled features. Customer-enabled external systems remain subject to the Customer’s own vendor agreements. Sub-processor Purpose Region Transfer mechanism Supabase Postgres database, authentication, file storage, and pgvector retrieval where enabled Frankfurt, Germany or EU region selected for the customer environment EU hosted, no international transfer for primary storage Render Backend application hosting for Morphed API and worker services Frankfurt, Germany for the EU deployment profile EU hosted for EU profile, SCCs where applicable Vercel Frontend hosting, static assets, and edge delivery EU primary region with global edge delivery SCCs and EU-US Data Privacy Framework where applicable OpenAI OpenAI EU data residency ↗ LLM inference for governed agent reasoning and document generation where selected EU routing where enabled, including Amazon Bedrock EU geo inference for the BEE workspace; otherwise United States with minimised payloads SCCs, EU-US Data Privacy Framework, and no training use for API data Amazon Web Services Bedrock AWS Bedrock EU geo inference ↗ Claude and OpenAI model inference for the BEE workspace where the Bedrock route is enabled EU geo inference profile, starting from Frankfurt EU geo inference route under AWS terms, with no training use of customer data Anthropic Claude model provider behind Amazon Bedrock for the BEE EU route, or direct inference where selected BEE route uses Amazon Bedrock EU geo inference; United States for direct inference unless an approved EU path is selected AWS Bedrock EU route for BEE; SCCs and EU-US Data Privacy Framework where direct Resend Transactional email for alerts, approvals, notifications, and system communications European Union EU hosted, no international transfer for primary email processing 6. International Transfers Where Personal Data is transferred outside the EEA, the United Kingdom, or South Africa, Morphed relies on the European Commission Standard Contractual Clauses (or the UK International Data Transfer Addendum, as applicable), an adequacy decision, or another lawful transfer mechanism recognised under the Data Protection Laws. For transfers outside South Africa, Morphed shall ensure that: (a) the recipient is subject to a law which provides an adequate level of protection for the Processing of Personal Data similar to POPIA; or (b) the recipient has entered into a binding agreement containing terms which are substantially similar to the data protection obligations in this Agreement. To the extent that a transfer of Special Personal Information or other Personal Data requires prior authorisation from the Information Regulator under POPIA, Morphed shall ensure that such prior authorisation is obtained prior to the transfer. The Customer hereby authorises such transfers, provided that Morphed maintains appropriate supplementary measures including encryption in transit and at rest, access controls, data minimisation, audit logging, and vendor due diligence. The Customer acknowledges that certain sub-processors engaged by Morphed may be located outside the EEA, the United Kingdom, and South Africa, and that the Customer’s general authorisation of sub-processors under clause 5 of this Agreement includes authorisation for such transfers. 7. Security Measures Morphed shall implement and maintain reasonable, appropriate technical and organisational measures to preserve the integrity and confidentiality of the Customer Data and to prevent any unauthorised Processing, access, use, corruption, or loss of the Customer Data, including but not limited to the measures set out below. Morphed shall conduct regular assessments to identify all reasonably foreseeable internal and external risks to the Customer Data in Morphed’s possession or control, and shall update and align safeguards with the risks identified. Encryption at rest and in transit. Encrypted storage of OAuth tokens, bearer tokens, and connector credentials. Tenant isolation and portal scoped access controls. Approval gates and idempotency keys for write-capable connector actions. Audit logs for agent activity, connector calls, approvals, and writes. Role based access controls, least privilege access, and personnel confidentiality obligations. 8. Assistance, Breach Notice, and Deletion 8.1 Morphed shall provide reasonable cooperation to the Customer to enable the Customer to respond to requests from Data Subjects exercising their rights under the Data Protection Laws (including rights of access, correction, deletion, and objection under both the GDPR and POPIA), to the extent that the Customer is unable to respond to such requests using the functionality of the Service. To the extent that such assistance requires effort beyond the provision of standard Service functionality, Morphed may charge the Customer its then-current reasonable professional fees for time spent on such assistance. Such cooperation shall include, where reasonably requested by the Customer: (a) the provision of all data requested by the Customer within any reasonable timescale specified by the Customer, including full details and copies of any complaint, communication, or request and any Customer Data Morphed holds in relation to a Data Subject; (b) providing such assistance as is reasonably requested to enable the Customer to comply with the relevant request within the timescales prescribed by the Data Protection Laws; and (c) implementing any additional technical and organisational measures as may be reasonably required by the Customer to allow the Customer to respond effectively to relevant complaints, communications, or requests. 8.2 Morphed shall notify the Customer without undue delay (and in any event within 72 hours) after becoming aware of a Personal Data Breach affecting Customer Data Processed under this Agreement. Such notification shall include, to the extent reasonably available to Morphed at the time: (a) a description of the nature of the Personal Data Breach, the categories and approximate number of Data Subjects affected, and the categories and approximate number of Personal Data records concerned; (b) the name and contact details of Morphed’s data protection officer or other relevant contact from whom more information may be obtained; (c) a description of the likely consequences of the Personal Data Breach; and (d) a description of the measures taken or proposed to be taken to address the Personal Data Breach. Morphed shall provide reasonable co-operation and assistance to the Customer in relation to the investigation, mitigation, and remediation of any such breach. 8.3 In the event of a Personal Data Breach, Morphed shall not inform any third party without first obtaining the Customer’s prior written consent, unless notification is required by applicable law, in which case Morphed shall (to the extent permitted by such law) inform the Customer of that legal requirement, provide a copy of the proposed notification, and consider any comments made by the Customer before making notification of the Personal Data Breach. 8.4 Morphed shall make available to the Customer on request all information reasonably necessary to demonstrate Morphed’s compliance with its obligations under Article 28 of the GDPR and this Agreement, and shall allow for and contribute to audits, including inspections, conducted by an independent third-party auditor appointed by the Customer (not a competitor of Morphed), subject to the following conditions: (a) the Customer shall give Morphed not less than 30 business days’ prior written notice of any proposed audit; (b) audits shall be conducted during normal business hours and shall not unreasonably disrupt Morphed’s operations; (c) the Customer shall not be entitled to more than one audit in any 12-month period, except where an additional audit is required by a Supervisory Authority (including the Information Regulator) or is reasonably necessary following a Personal Data Breach; (d) the auditor shall enter into a confidentiality agreement with Morphed on terms reasonably acceptable to Morphed before commencing the audit; (e) the audit scope shall be limited to Morphed’s compliance with its obligations under this Agreement; and (f) all costs and expenses of the audit (including Morphed’s internal costs of facilitating the audit) shall be borne by the Customer. Morphed shall immediately inform the Customer if, in its opinion, an instruction pursuant to this clause infringes the Data Protection Laws. 8.5 Without prejudice to the foregoing, Morphed may elect to satisfy any audit request by providing the Customer with a copy of a recent SOC 2 Type II report, ISO 27001 certificate, or equivalent third-party certification or audit report covering the systems and processes relevant to the Processing. The Customer agrees that provision of such report shall satisfy the Customer’s audit rights under this clause for the period covered by the report, save where the Customer can demonstrate on reasonable grounds that such report is insufficient to address a specific, identified concern. 8.6 Morphed shall provide reasonable assistance to the Customer with data protection impact assessments and prior consultations with Supervisory Authorities pursuant to Articles 35 and 36 of the GDPR, and with any assessment, enquiry, notice, or investigation by the Information Regulator or any other Supervisory Authority under the Data Protection Laws in respect of the Customer Data or this Agreement, taking into account the nature of the Processing and information available to Morphed. Morphed may charge the Customer its then-current reasonable professional fees for time spent providing such assistance. 8.7 Upon termination or expiry of this Agreement or the Services Agreement (whichever is earlier), Morphed shall, at the Customer’s written election (to be communicated within 30 days of termination), either: (a) return a complete copy of all the Customer Data to the Customer by secure file transfer in such format as reasonably notified by the Customer to Morphed and securely wipe all other copies of the Customer Data; or (b) securely wipe all copies of the Customer Data Processed by Morphed or any sub-processor, and in each case promptly provide written certification to the Customer that it has complied fully with this clause. If the Customer does not make an election within such 30-day period, Morphed shall delete the Customer Data. Morphed may retain copies of Customer Data to the extent required by applicable law or regulation, or where necessary for the establishment, exercise, or defence of legal claims, provided that Morphed shall ensure the confidentiality of all such Customer Data and shall ensure that such retained data is only Processed as necessary for the purpose(s) specified in the applicable law requiring its storage and for no other purpose. 9. Customer Warranties and Indemnity 9.1 The Customer represents and warrants to Morphed that: (a) it is the Controller (responsible party) of the Customer Data and has the appropriate authority to enter into this Agreement and to instruct Morphed in relation to the Processing of the Customer Data; (b) it has provided all necessary information to, and obtained all necessary consents and legal bases from, Data Subjects to enable Morphed to Process the Customer Data as required to perform the Services, and that such Processing shall not cause Morphed to breach the Data Protection Laws; (c) the Customer’s instructions to Morphed shall at all times comply with the Data Protection Laws (including POPIA); and (d) it shall not, by act or omission, cause Morphed to breach the Data Protection Laws. 9.2 The Customer shall indemnify and hold harmless Morphed from and against all claims, damages, losses, liabilities, costs, and expenses (including reasonable legal fees) arising from or in connection with: (a) any breach by the Customer of its warranties under this clause 9; (b) any third-party claim (including Data Subject claims) arising from the Customer’s instructions or the Customer’s failure to comply with Data Protection Laws; or (c) any claim arising from the Customer’s failure to have a lawful basis for the Processing instructed. 10. Compliance with Law and Liability 10.1 Both parties shall comply with their respective obligations under the Data Protection Laws (including POPIA and the GDPR) which arise in connection with this Agreement. 10.2 The Customer acknowledges that Morphed is reliant on the Customer for direction as to the extent to which Morphed is entitled to use and Process the Customer Data. Consequently, Morphed shall not be liable for any claim brought by a Data Subject or Supervisory Authority arising from any action or omission by Morphed, to the extent that such action or omission resulted directly from Morphed performing the Services in accordance with the Customer’s documented instructions. 10.3 Without prejudice to the foregoing, Morphed shall inform the Customer if, in its opinion, an instruction infringes Data Protection Laws. Morphed shall not be required to carry out such instruction until the Customer, in writing, either: (a) issues an amended instruction which complies with Data Protection Laws; or (b) confirms that the original instruction complies with Data Protection Laws, in which case the Customer shall bear sole responsibility for any non-compliance resulting from the confirmed instruction. 11. Limitation of Liability 11.1 To the maximum extent permitted by applicable law, Morphed’s total aggregate liability under or in connection with this Agreement (whether in contract, delict, statute, or otherwise) shall not exceed the total fees paid by the Customer to Morphed under the Services Agreement in the 12 months immediately preceding the event giving rise to the claim. 11.2 In no event shall Morphed be liable for any indirect, incidental, special, consequential, or punitive damages, including (without limitation) loss of profits, revenue, data, business, goodwill, or anticipated savings, howsoever arising and whether in contract, delict (tort), statute, or otherwise, even if Morphed has been advised of the possibility of such damages. 11.3 Nothing in this Agreement shall exclude or limit Morphed’s liability for: (a) death or personal injury caused by Morphed’s negligence; (b) fraud or fraudulent misrepresentation; (c) any administrative fines imposed directly on Morphed by a Supervisory Authority in respect of Morphed’s own breach of Data Protection Laws (and not arising from compliance with the Customer’s instructions); or (d) any other liability that cannot be excluded or limited under applicable law. 12. Termination 12.1 This Agreement shall commence on the date on which the Customer first accesses the Service and shall continue until termination of the Services Agreement or this Agreement in accordance with this clause 12. 12.2 Either party may terminate this Agreement immediately upon written notice if: (a) the other party commits a material breach of this Agreement and (where the breach is remediable) fails to remedy such breach within 30 days of receiving written notice requiring it to do so; or (b) the Services Agreement is terminated or expires. Any breach of this Agreement by either party shall constitute a material breach of the Services Agreement. 12.3 Morphed may suspend Processing under this Agreement immediately upon written notice if Morphed reasonably determines that continued Processing of Customer Data in accordance with the Customer’s instructions would place Morphed in breach of Data Protection Laws. 12.4 Termination of this Agreement for whatever reason shall not affect the accrued rights or obligations of either party. Clauses 9 (Customer Warranties and Indemnity), 10 (Compliance with Law and Liability), 11 (Limitation of Liability), and 14 (Governing Law and Jurisdiction) shall survive termination. Any obligation imposed on Morphed under this Agreement in relation to the Processing of Customer Data shall survive any termination or expiration of this Agreement to the extent necessary to give effect to such obligation. 13. General 13.1 This Agreement, together with the Services Agreement, constitutes the entire agreement between the parties in respect of the Processing of Customer Data and supersedes all prior agreements, representations, and understandings (whether oral or written) relating to such matters. 13.2 In the event of any conflict between the terms of this Agreement and those of the Services Agreement or any other agreement between the parties, the terms of this Agreement shall take precedence with regard to the parties’ data protection obligations for Customer Data. In all other respects, the Services Agreement shall prevail. 13.3 Nothing in this Agreement shall be construed as creating a partnership, joint venture, employment, or agency relationship between the parties. 13.4 A person who is not a party to this Agreement shall have no right to enforce any term of this Agreement. 13.5 If any provision of this Agreement is held by a competent authority to be invalid, unlawful, or unenforceable, such provision shall be either: (a) amended as necessary to ensure its validity and enforceability, while preserving the parties’ intentions as closely as possible; or, if this is not possible, (b) severed, and the remaining provisions shall continue in full force and effect. 13.6 No failure or delay by Morphed in exercising any right or remedy under this Agreement shall operate as a waiver of that right, nor shall any single or partial exercise preclude any further exercise of the same or any other right or remedy. 13.7 Morphed may assign or transfer this Agreement (or any of its rights or obligations hereunder) to any affiliate or successor entity without the Customer’s consent. The Customer may not assign this Agreement without Morphed’s prior written consent. 14. Governing Law and Jurisdiction This Agreement shall be governed by and construed in accordance with the laws of the Republic of South Africa. Subject to any dispute resolution mechanism in the Services Agreement, the parties submit to the exclusive jurisdiction of the High Court of South Africa, Gauteng Division, Johannesburg. Contact For DPA-related enquiries, signed SCCs, security reviews, or Article 30 extracts, contact: Email: [email protected]