Data Processing Agreement
Last updated: July 8, 2026
This Data Processing Agreement (“DPA”) is an addendum to the Master Service Agreement or Terms of Service (the “Agreement”) between Manta Finance LLC (“Processor”) and the Customer (“Controller”).
1. Definitions
- "Data Protection Laws" means all applicable worldwide legislation relating to data protection and privacy which applies to the respective party in the role of processing Personal Data under the Agreement, including without limitation the European General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA).
- "Personal Data" means any information relating to an identified or identifiable natural person that is processed by the Processor on behalf of the Controller in the course of providing the Services.
- "Subprocessor" means any third party engaged by the Processor to process Personal Data on behalf of the Controller.
2. Processing of Personal Data
2.1. Roles of the Parties
The parties acknowledge and agree that with regard to the Processing of Personal Data, Customer is the Controller and Manta Finance is the Processor.
2.2. Customer's Instructions
Processor shall process Personal Data only on documented instructions from Controller, unless required to do so by applicable law. The Agreement and this DPA constitute Controller's complete and final documented instructions.
2.3. Nature and Purpose of Processing
Processor will process Personal Data solely for the purpose of providing the financial intelligence SaaS platform as described in the Agreement, including ingesting, normalizing, and modeling financial, sales, and inventory data.
3. Confidentiality and Security
3.1. Confidentiality
Processor shall ensure that its personnel authorized to process the Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
3.2. Security Measures
Processor shall implement and maintain appropriate technical and organizational measures designed to protect the Personal Data against unauthorized or unlawful processing and against accidental loss, destruction, damage, alteration, or disclosure. These measures include, but are not limited to, encryption of data in transit and at rest, role-based access controls, and regular security testing.
4. Subprocessors
4.1. Authorization
Controller generally authorizes Processor to engage Subprocessors to process Personal Data. Processor shall maintain an up-to-date list of its Subprocessors and make it available to Controller upon request.
4.2. Subprocessor Obligations
Processor shall enter into a written agreement with each Subprocessor imposing data protection terms that require the Subprocessor to protect the Personal Data to the standard required by Data Protection Laws and this DPA. Processor remains liable for the acts and omissions of its Subprocessors.
5. Data Subject Rights
Processor shall, to the extent legally permitted, promptly notify Controller if Processor receives a request from a Data Subject to exercise their rights under Data Protection Laws (e.g., access, rectification, deletion). Processor shall not respond to such request without Controller's prior written consent, except to confirm that the request relates to Controller. Processor shall provide reasonable assistance to Controller to enable Controller to respond to such requests.
6. Personal Data Breach
6.1. Notification
Processor shall notify Controller without undue delay (and in any event within 48 hours) after becoming aware of a Personal Data Breach affecting Controller's Personal Data.
6.2. Assistance
Processor shall provide reasonable assistance to Controller in investigating the breach and fulfilling any data breach notification obligations under Data Protection Laws.
7. Return or Deletion of Data
Upon termination or expiration of the Agreement, Processor shall (at Controller's election) delete or return to Controller all Personal Data in its possession or control, save to the extent that Processor is required by applicable law to retain some or all of the Personal Data.
8. Audits
Upon Controller's written request at reasonable intervals, Processor shall make available to Controller information reasonably necessary to demonstrate compliance with this DPA, which may include providing summaries of third-party security audit reports (e.g., SOC 2 Type II report).