1. Scope
This Data Processing Addendum (“DPA”) applies where a myMulti customer uses the services to process personal data for which the customer determines the purposes and means and MULTI PLATFORMS, Corp. acts as processor or service provider.
2. Roles and instructions
The customer is the controller/business and MULTI PLATFORMS, Corp. is the processor/service provider for Customer Personal Data. myMulti processes Customer Personal Data only on documented instructions, including those contained in the customer’s configuration, use of the service, order form and this DPA, unless law requires otherwise.
3. Confidentiality
Personnel authorized to process Customer Personal Data are subject to appropriate confidentiality obligations.
4. Security
myMulti maintains technical and organizational measures appropriate to the risk, including access controls, authentication, encrypted transport, logging, vulnerability and incident-management practices, and measures designed to maintain availability and recoverability.
5. Subprocessors
The customer authorizes use of subprocessors necessary to provide the service. myMulti remains responsible for imposing data-protection obligations on subprocessors appropriate to the services they perform. The current register is at Subprocessors.
6. Data-subject requests
Taking into account the nature of processing, myMulti will provide reasonable assistance to customers responding to valid data-subject requests where the customer cannot reasonably fulfill the request using service functionality.
7. Personal-data breaches
myMulti will notify the customer without undue delay after becoming aware of a breach of Customer Personal Data requiring notification under applicable data-protection law and will provide information reasonably available to support the customer’s legal obligations.
8. DPIAs and regulatory assistance
Taking into account the nature of processing and information available to myMulti, we will provide reasonable assistance with data-protection impact assessments and regulator consultations where required by law.
9. Return and deletion
At the end of the service, myMulti will delete or return Customer Personal Data as provided by the service and agreement, unless applicable law requires retention. Residual backup copies may remain for a limited period subject to continued protection.
10. Audit and information
myMulti will make available information reasonably necessary to demonstrate compliance with applicable processor obligations. Audits must be proportionate, protect other customers and system security, and normally rely first on available security documentation or third-party reports.
11. International transfers
Where restricted transfers of Customer Personal Data occur, the parties will use an applicable lawful mechanism. If required, the applicable European Commission Standard Contractual Clauses are incorporated by reference to the extent necessary, using the module matching the parties’ roles, together with any required local addendum.
12. Processing details
| Subject matter | Providing myMulti business, AI, automation and integration services selected by the customer. |
|---|---|
| Duration | For the term of the service plus limited deletion/backup periods. |
| Nature | Collection, storage, organization, retrieval, analysis, generation, transmission, integration, logging, deletion and other processing necessary to provide configured features. |
| Data subjects | Customer personnel, the customer’s clients/prospects, contacts, counterparties and other persons whose data the customer lawfully submits. |
| Data types | Contact details, messages, requests, booking/transaction context, account identifiers, business relationship data, instructions, AI input/output and connected-service metadata. |
| Sensitive data | Not intended unless specifically supported, contractually authorized and lawfully configured. Customers should avoid submitting unnecessary sensitive data. |