Legal & compliance

Data Processing Addendum

This DPA is available for business customers that use Montesque to process personal data on their behalf.

Effective August 26, 2026

1. Application

This Data Processing Addendum (“DPA”) forms part of a written agreement between Montesque and a customer only when that agreement incorporates this DPA. The customer is the controller or processor of Customer Personal Data, and Montesque is its processor or subprocessor, as applicable. Capitalized terms not defined here have the meaning given in the applicable agreement or Data Protection Laws.

2. Processing details

  • Subject matter and purpose: providing, securing, supporting, and maintaining the Montesque service.
  • Duration: the agreement term plus the limited deletion period described below.
  • Data subjects: customer-authorized users and people whose information they submit.
  • Data types: account identifiers, optional profile attributes, prompts, conversations, saved items, preferences, and technical/security data.
  • Processing: collection, storage, organization, retrieval, transmission to approved subprocessors, generation of requested output, security monitoring, export, and deletion.

3. Customer instructions and responsibilities

Montesque will process Customer Personal Data only on documented instructions from the customer, including instructions expressed through use of the service, unless law requires otherwise. The customer is responsible for lawful instructions, notices, permissions, data minimization, account configuration, and responding to data-subject requests for which it is the controller.

4. Confidentiality and security

Montesque will ensure people authorized to process Customer Personal Data are bound by confidentiality obligations and will maintain appropriate technical and organizational safeguards. These include access controls, encrypted transport, managed authentication, input validation, rate limiting, security headers, dependency monitoring, data export and deletion controls, and incident-response procedures appropriate to the risk.

5. Subprocessors

The customer authorizes Montesque to use subprocessors needed to provide the service. Current categories and providers include Supabase for authentication and data infrastructure; Google Gemini for AI processing; hosting and network providers; and Geocodio, Congress.gov, and news-data providers when requested features use them. Montesque remains responsible for subprocessors to the extent required by Data Protection Laws.

Material subprocessor changes will be communicated through the service or an agreed business contact channel. A customer may object on reasonable data-protection grounds within 15 days of notice.

6. Assistance and incidents

Taking into account the nature of processing, Montesque will reasonably assist with data-subject requests, security obligations, impact assessments, regulator consultations, and demonstrations of compliance. Montesque will notify the customer without undue delay after confirming a breach of Customer Personal Data and provide available information needed for the customer's response.

7. Return, deletion, and audits

During the agreement, self-service tools allow export and deletion. After termination, Montesque will delete or return Customer Personal Data on request unless retention is legally required. Limited encrypted backups may persist until overwritten under normal retention cycles. On reasonable written request, Montesque will provide information necessary to demonstrate compliance and support proportionate audits subject to confidentiality, security, and non-disruption requirements.

8. International transfers

If Customer Personal Data protected by the EEA, UK, or Swiss data-protection laws is transferred to a country without an adequacy decision, the applicable approved standard contractual clauses are incorporated by reference with the customer as data exporter and Montesque as data importer. The parties will apply supplementary measures where required.

9. Order of precedence and execution

If this DPA conflicts with the applicable service agreement on personal-data processing, this DPA controls. Liability is governed by that agreement. Customers that require an executed copy or negotiated compliance terms should use our private contact channel before deploying Montesque for regulated or enterprise processing.