MockingBird AI

Data Processing Agreement

Last updated: December 28, 2024

📋 For Business Customers

This Data Processing Agreement (DPA) governs how MockingBird AI processes personal data on behalf of business customers in compliance with GDPR and other data protection laws.

Request Signed DPA

1. Introduction

This Data Processing Agreement (DPA) forms part of the agreement between MockingBird AI Inc. (Processor, we, us) and the business entity using our Services (Controller, you) where we process personal data on your behalf.

This DPA reflects the parties' agreement regarding the processing of personal data in accordance with the requirements of Data Protection Laws, including the EU General Data Protection Regulation (GDPR), the UK GDPR, and the California Consumer Privacy Act (CCPA).

2. Definitions

  • Personal Data means any information relating to an identified or identifiable natural person.
  • Processing means any operation performed on Personal Data, including collection, storage, use, and deletion.
  • Data Protection Laws means all applicable laws relating to the processing of Personal Data, including GDPR, UK GDPR, and CCPA.
  • Sub-processor means any third party engaged by MockingBird to process Personal Data.
  • Data Subject means the individual whose Personal Data is processed.

3. Scope of Processing

3.1 Subject Matter

The subject matter of processing is the provision of AI-powered design and image generation services as described in our Terms of Service.

3.2 Nature and Purpose

Personal Data is processed for the following purposes:

  • Providing the Service and its features
  • Account management and authentication
  • Processing payments and subscriptions
  • Customer support and communications
  • Service analytics and improvement

3.3 Types of Personal Data

  • Account data (name, email, password hash)
  • Usage data (feature usage, access logs)
  • User-generated content (images, prompts)
  • Payment information (processed by Stripe)

3.4 Categories of Data Subjects

  • Employees and contractors of the Controller
  • End users of the Controller's products/services

4. Processor Obligations

MockingBird shall:

  • Process Personal Data only on documented instructions from the Controller
  • Ensure personnel processing data are bound by confidentiality obligations
  • Implement appropriate technical and organizational security measures
  • Assist the Controller in responding to Data Subject requests
  • Assist with data protection impact assessments where required
  • Delete or return Personal Data upon termination of the agreement
  • Make available information necessary to demonstrate compliance
  • Allow and contribute to audits and inspections

5. Sub-processors

5.1 Authorization

The Controller authorizes MockingBird to engage Sub-processors to process Personal Data. Current Sub-processors are listed below.

5.2 Sub-processor List

Sub-processorPurposeLocation
Amazon Web ServicesCloud infrastructureUS, EU
Google Cloud PlatformAI/ML processingUS, EU
SupabaseDatabase, AuthenticationUS
StripePayment processingUS
SendGrid / ResendEmail deliveryUS
IntercomCustomer supportUS

5.3 New Sub-processors

We will provide at least 30 days notice before engaging new Sub-processors. Controllers can object by contacting us within that period.

6. Security Measures

MockingBird implements the following security measures:

  • Encryption: TLS 1.3 in transit, AES-256 at rest
  • Access Control: Role-based access, MFA for employees
  • Network Security: Firewalls, intrusion detection, DDoS protection
  • Monitoring: 24/7 monitoring, security logging, anomaly detection
  • Physical Security: SOC 2 Type II certified data centers
  • Employee Training: Regular security awareness training
  • Incident Response: Documented procedures, 72-hour breach notification

7. Data Subject Rights

MockingBird will assist the Controller in responding to Data Subject requests, including access, rectification, erasure, restriction, portability, and objection requests. We will respond to requests within 30 days.

8. International Transfers

When Personal Data is transferred outside the EEA/UK, MockingBird ensures appropriate safeguards through:

  • EU-US Data Privacy Framework certification (where applicable)
  • Standard Contractual Clauses (SCCs)
  • Supplementary measures as required

9. Data Breach Notification

In the event of a Personal Data breach, MockingBird will notify the Controller without undue delay (within 72 hours of becoming aware) and provide:

  • Description of the nature of the breach
  • Categories and approximate number of Data Subjects affected
  • Likely consequences of the breach
  • Measures taken or proposed to address the breach

10. Audits

MockingBird will make available information necessary to demonstrate compliance with this DPA and allow for audits. We provide SOC 2 Type II reports upon request under NDA.

11. Term and Termination

This DPA is effective for the duration of the service agreement. Upon termination, MockingBird will delete or return all Personal Data within 30 days, unless retention is required by law.

12. Contact

For DPA-related inquiries: