1. Parties, scope and definitions
This Data Processing Agreement (DPA) is between the business identified as the Customer in the signed order (Controller) and MONASTYRSKYI AI, organisation number 937 724 594, trading as MONAFORGE (Processor). It applies when the Processor handles personal data on the Controller's behalf to provide the ordered service.
Applicable Data Protection Law means the UK GDPR, Data Protection Act 2018, Privacy and Electronic Communications Regulations 2003 where relevant, applicable provisions of the Data (Use and Access) Act 2025, the EU/EEA GDPR where it applies, and other binding data-protection law applicable to the processing. Controller, processor, personal data, processing, data subject and personal data breach have their statutory meanings.
2. Roles and documented instructions
- The Controller decides why and how its caller and lead data is used and is responsible for lawful basis, transparency, accuracy, minimisation and its own retention policy.
- The Processor processes that data only on documented instructions in the signed agreement, order form, this DPA or another written instruction that can be retained, unless applicable law requires otherwise.
- The Processor will tell the Controller if it reasonably believes an instruction violates Applicable Data Protection Law, unless prohibited from doing so.
- Each party remains an independent controller for personal information used for its own business administration, billing, security, fraud prevention and legal compliance.
3. Confidentiality and security
The Processor will restrict access to authorised people who need it to deliver or protect the service. Those people are bound by contractual, professional or statutory confidentiality duties.
Taking account of risk, cost and available technology, the Processor will maintain appropriate measures including:
- multi-factor authentication where supported, unique credentials and least-privilege administrative access;
- provider-managed encryption in transit and at rest where offered by the relevant platform;
- logical separation of customer accounts and controlled lead-delivery destinations;
- fixed, minimised intake questions and instructions not to collect passwords, payment credentials or unnecessary sensitive data;
- testing of disclosure, routing and lead delivery before live use;
- access removal, incident handling, provider review and recorded deletion processes; and
- security and application logs restricted to service, abuse prevention and incident investigation.
4. Sub-processors
The Controller gives general written authorisation for sub-processors necessary to supply the ordered service. The Processor will impose data-protection obligations required by law and remains responsible for its sub-processors' performance of those obligations.
The actual order-specific register must identify the configured core CRM/Voice AI platform, telephony route, AI provider, hosting, email and workflow providers. The current service may use HighLevel/LeadConnector and providers in its published stack; Google Workspace may be used for email handover. Vercel, Vercel AI Gateway and Make are used for MONAFORGE's public website but are not used for a customer's live call data unless the signed order expressly includes that route.
Where practicable, the Processor will give reasonable advance notice of a material new sub-processor. The Controller may object within 14 days on reasonable data-protection grounds. The parties will seek an alternative; if none is reasonably available, either party may terminate the affected service without a termination penalty, while accrued charges remain payable.
5. International transfers
The Controller authorises processing in Norway and the locations used by approved order-specific sub-processors. UK-to-Norway transfers may rely on the UK's adequacy recognition for the EEA. A restricted onward transfer must use a lawful mechanism, such as an applicable adequacy regulation, the UK International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses or another approved safeguard, together with any assessment required by law.
The Processor will provide reasonable information about the applicable transfer route on request.
6. Data-subject requests
If the Processor receives a request concerning Controller personal data, it will notify the Controller promptly and will not answer substantively except on documented instructions or as required by law. Taking account of the processing, the Processor will provide reasonable assistance with requests for access, correction, deletion, restriction, portability and objection.
7. Personal data breaches
The Processor will notify the Controller without undue delay after becoming aware of a confirmed personal data breach affecting Controller personal data and, where practicable, within 24 hours. Available information may be provided in stages and will cover the nature of the incident, affected records and people, likely consequences, containment and contact point.
The Processor will take reasonable containment, investigation and remediation steps and assist with legally required notifications. The Controller remains responsible for deciding whether and when to notify the ICO, another authority or affected people.
8. Compliance assistance
Taking account of the nature of processing and information available, the Processor will reasonably assist with security duties, breach response, data-protection impact assessments and prior consultation with a supervisory authority. Material work beyond ordinary service may be charged at a pre-agreed reasonable rate unless caused by the Processor's breach.
9. Return and deletion
At the end of service, and subject to a written request made within 30 days, the Processor will provide an available export or delete Controller personal data, then delete remaining copies unless law requires retention. Protected backups may remain beyond primary deletion but must be put beyond ordinary use and deleted on the provider's backup cycle. The signed order may set shorter operational retention periods.
10. Information and audits
The Processor will provide information reasonably necessary to demonstrate compliance with applicable processor duties. The Controller may conduct one reasonable audit per 12 months on at least 20 business days' notice, during normal business hours, subject to confidentiality and without accessing another customer's information. Additional audits are permitted following a material breach or regulator request. The Controller pays reasonable audit costs unless a material Processor breach is found.
11. Liability, precedence and law
Liability under this DPA is subject to the signed Service Agreement to the extent permitted by law. This DPA prevails over the Service Agreement for personal-data processing; a mandatory transfer instrument prevails for the relevant restricted transfer.
Unless the signed order states otherwise, this DPA is governed by Norwegian law and the Norwegian courts have non-exclusive jurisdiction.
Annex 1 - Processing details
| Subject matter | Inbound AI answering and agreed lead-intake, transcription or recording if enabled, summarisation, routing and support. |
|---|---|
| Duration | The setup and subscription period, followed by the order-specific deletion and backup period. |
| Nature and purpose | Receive, collect, transcribe, structure, store, retrieve, transmit and delete enquiry data so the Controller can respond to potential customers. |
| Data subjects | People contacting the Controller and the Controller's authorised users and contacts. |
| Personal data | Name, phone number, voice, postcode or address, job description, urgency, availability, transcript, recording if enabled, call metadata, lead status and technical metadata. |
| Special-category data | Not intended. The configured agent should discourage and minimise health, biometric, criminal and other sensitive information. |
| Frequency | Recurring during live use of the ordered inbound service. |
Annex 2 - Order-specific items
Before launch, the signed order must record:
- the exact service, phone route, AI model/provider and approved sub-processors;
- the intake questions, recipients, customer privacy notice and AI/recording disclosure;
- whether audio recording or transcription is enabled and each retention period;
- the customer's authorised instructions, acceptance tests and support contacts; and
- any additional international-transfer terms or sector-specific restrictions.
To request a signature-ready DPA and order schedule, email vlad@monaforge.com.