Mind Lab Toolkit (MinT)
Support

DATA PROCESSING ADDENDUM

MinT — Mind Lab Toolkit

This Data Processing Addendum (this “DPA”) forms part of, and is subject to, the MinT Terms of Service or other written master agreement (the “Agreement”) entered into between MINDAI PTE. LTD. (“Mindai”) and the customer identified below (“Customer”). This DPA governs Mindai’s Processing of Personal Data on behalf of Customer in connection with the MinT Service.

Background. MinT comprises two independent components: (a) the MinT Training Platform — a reinforcement-learning model training infrastructure platform (a “parameter platform”) whose primary output consists of model parameters (model weights, checkpoints, and related training artifacts) produced from Customer-supplied training data and configurations; with respect to the Training Platform, Mindai does not directly generate or deliver content to end users or Data Subjects on Customer’s behalf; and (b) the MinT Model Gateway — through which Mindai provides Customer with API access to the Macaron model series and to third-party open-source models (such as DeepSeek, GLM) deployed by Mindai, whose outputs may include text, image, code, and other generative content. The Parties acknowledge that Customer remains solely responsible for (i) the lawfulness of any training data Customer submits to the Service and of any Inputs Customer submits through the Model Gateway API, (ii) the characteristics, uses, and outputs of any model trained using the Service or invoked through the Model Gateway, and (iii) any interaction with Data Subjects that may result from Customer’s deployment or use of such models, or from Customer’s downstream use of Model Gateway Outputs. Mindai’s role under this DPA is limited accordingly.

Effective Date: [DATE]

Customer Legal Name: [CUSTOMER LEGAL NAME]

Customer Address: [CUSTOMER ADDRESS]

Customer Authorized Representative: [NAME / TITLE]

Mindai: MINDAI PTE. LTD., a company incorporated in Singapore, Company No. 202322737E, with registered address at 152 Beach Road, #11-05, Gateway East, Singapore 189721.

In the event of any conflict between this DPA and the Agreement with respect to the Processing of Personal Data, this DPA prevails. All capitalized terms not defined in this DPA have the meanings given in the Agreement.

1. Definitions

1.1 “Applicable Data Protection Laws” means all laws and regulations applicable to the Processing of Personal Data under this DPA, including, where applicable, (a) the EU General Data Protection Regulation 2016/679 and the UK GDPR (collectively, “GDPR”); (b) the Personal Information Protection Law of the People’s Republic of China (“PIPL”) and related implementing rules; (c) the Personal Data Protection Act 2012 of Singapore (“PDPA”); and (d) any other data protection or privacy laws that apply to a Party’s activities under the Agreement.

1.2 “Customer Data” has the meaning given in the Agreement, including without limitation training data, model weights, checkpoints and other training outputs uploaded through the Training Platform, as well as Inputs submitted through the Model Gateway API and Outputs generated therefrom, and including any Personal Data contained therein.

1.3 “Data Subject” means the identified or identifiable natural person to whom Personal Data relates.

1.4 “Personal Data” means any information relating to a Data Subject that is Processed by Mindai on behalf of Customer, as more fully described in Schedule A.

1.5 “Process / Processing” means any operation or set of operations performed on Personal Data, whether or not by automated means, including collection, storage, access, use, transmission, and deletion.

1.6 “Controller,” “Processor,” “Personal Data Breach,” and “Supervisory Authority” have the meanings given under GDPR; “Personal Information Processor” (个人信息处理者) and “Entrusted Party” (受托人) have the meanings given under PIPL; equivalent terms under other Applicable Data Protection Laws are construed accordingly.

1.7 “Sub-processor” means any third party engaged by Mindai to Process Personal Data in connection with the Service.

1.8 “Security Whitepaper” means the MinT Security and Compliance Whitepaper, as updated from time to time.

1.9 “Subprocessor List” means the list of approved Sub-processors referenced in Schedule C, as updated from time to time.

2. Roles of the Parties

2.1 The Parties acknowledge and agree that, with regard to the Processing of Personal Data under this DPA: (a) Customer is the Controller (or Personal Information Processor under PIPL) of Personal Data; and (b) Mindai is the Processor (or Entrusted Party under PIPL) acting on behalf of Customer.

2.2 Nothing in this DPA relieves Customer of its own direct responsibilities and obligations as a Controller under Applicable Data Protection Laws, including obtaining lawful bases and providing required notices to Data Subjects.

3. Scope and Details of Processing

3.1 Subject Matter and Duration. Mindai shall Process Personal Data solely to provide the Service to Customer under the Agreement, for the duration of the Agreement and for such additional period as is required by law or permitted in accordance with Section 12 below.

3.2 Nature and Purpose; Categories; Instructions. The nature and purpose of the Processing, the categories of Personal Data, and the categories of Data Subjects are set out in Schedule A.

3.3 Customer Instructions. Mindai shall Process Personal Data only on documented instructions from Customer, including with regard to transfers, unless otherwise required by applicable law. The Agreement, this DPA, and Customer’s use of the Service in accordance with its documentation constitute Customer’s documented instructions. Mindai shall inform Customer if, in its opinion, an instruction violates Applicable Data Protection Laws.

3.4 Limitation on Use (No-Training Commitment). Mindai shall not Sell or Share Personal Data (as those terms are defined under applicable law). Mindai shall not use Customer Data, training data submitted by Customer, or Customer Model Outputs (as defined below) to train, fine-tune, evaluate, benchmark, or otherwise improve Mindai’s own artificial-intelligence models or any third party’s artificial-intelligence models, except: (a) for aggregated and de-identified operational statistics that do not identify Customer or any Data Subject; or (b) where Customer has provided prior, separate, express, and revocable written consent, which Customer may withdraw at any time with prospective effect. For the avoidance of doubt, model parameters, weights, checkpoints, and other training artifacts produced using the Service on behalf of Customer (“Customer Model Outputs”) constitute Customer Data under the Agreement. Mindai shall not retain, access, reuse, or derive independent commercial value from Customer Model Outputs beyond what is strictly necessary to provide, secure, and bill the Service, and shall return or delete Customer Model Outputs in accordance with Section 12.

3.5 Deployment Modes and Scope of Processing. The scope of Mindai’s Processing depends on the deployment mode selected by Customer: (a) Cloud deployment — Mindai hosts the Service on cloud infrastructure (as further described in the Subprocessor List) and acts as Processor / Entrusted Party in respect of Customer Data stored in or transiting through the Service; (b) Private or On-Premises deployment — the Service is installed within Customer’s environment or a cloud tenancy controlled by Customer, Mindai does not have routine access to Customer Data or training data, and Customer acts as the sole Controller and Processor of such data. In case (b), Mindai’s limited collection of identity, license, configuration, usage telemetry, and support data necessary to license, bill, and support the Service constitutes Processing for Mindai’s own business purposes; with respect to such data, Mindai acts as an independent Controller (independent Personal Information Processor under PIPL) and Processes it solely in accordance with the Privacy Policy and Applicable Data Protection Laws. Mindai shall retain such data only for as long as necessary for the stated purposes and in any event no longer than twenty-four (24) months after the end of the applicable support, licensing, or billing relationship, unless a longer period is required by applicable law.

3.6 Return or Deletion of API Content. Inputs submitted through the Model Gateway API and Outputs generated therefrom (“API Content”) are treated as Customer Data. Mindai will delete all API Content from its systems within thirty (30) days after termination of the Agreement, unless: (i) Mindai is legally required to retain it; or (ii) you have agreed otherwise in writing.

4. Confidentiality

4.1 Mindai shall ensure that personnel authorized to Process Personal Data are bound by written confidentiality obligations or are subject to appropriate statutory obligations of confidentiality.

4.2 Access to Personal Data is limited to personnel with a legitimate need to access it in order to provide the Service and fulfill Mindai’s obligations under the Agreement and this DPA.

5. Security Measures

5.1 Mindai shall implement and maintain appropriate technical and organizational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data (a “Personal Data Breach”), taking into account the state of the art, the cost of implementation, the nature, scope, context and purposes of Processing, and the risk to Data Subjects.

5.2 A summary of Mindai’s current technical and organizational measures is set out in Schedule B and further described in the Security Whitepaper. Mindai may update such measures from time to time, provided that the overall level of security is not diminished.

6. Sub-processors

6.1 General Authorization. Customer provides a general authorization for Mindai to engage Sub-processors to assist in providing the Service, subject to the requirements of this Section 6.

6.2 Current List. The current list of approved Sub-processors is maintained as the Subprocessor List, available to Customer and referenced in Schedule C.

6.3 Notice of Changes. Mindai shall notify Customer of any intended addition or replacement of Sub-processors by updating the Subprocessor List and providing notice through the Service console, customer portal, or email at least thirty (30) days before the change takes effect, unless a shorter period is required to address a security, legal, or operational issue.

6.4 Objection. Customer may object to a new Sub-processor on reasonable data-protection grounds by providing written notice within fifteen (15) days of Mindai’s notice. The Parties shall work in good faith to resolve the objection. If no resolution can be reached, Customer’s sole remedy is to terminate the portion of the Service that cannot be provided without the new Sub-processor, with a pro-rata refund of any prepaid fees for that portion.

6.5 Flow-down. Mindai shall enter into a written agreement with each Sub-processor imposing data-protection obligations substantially equivalent to those set out in this DPA. Mindai remains liable to Customer for the acts and omissions of its Sub-processors as if they were Mindai’s own.

7. International and Cross-Border Data Transfers

7.1 Customer Choice of Region. Mindai offers Service deployments in multiple regions. Customer selects the deployment region when provisioning the Service. Absent a specific selection, Mindai will apply its default regional deployment and identify it to Customer in writing upon request.

7.2 Transfer Mechanisms. Where the Processing involves a transfer of Personal Data across jurisdictions, the Parties shall cooperate in good faith to apply the transfer mechanism required by Applicable Data Protection Laws, which may include, as applicable: (a) the PRC Standard Contract for Outbound Transfer of Personal Information, security assessment filing, or PIPL-compliant certification; (b) the EU Standard Contractual Clauses and/or UK International Data Transfer Agreement; and (c) any equivalent mechanism under PDPA or other applicable law.

7.3 SCC Incorporation. If and to the extent that Personal Data transferred under this DPA is subject to GDPR, the Parties shall be deemed to have entered into the EU Standard Contractual Clauses (Module Two, controller-to-processor) as approved by European Commission Implementing Decision (EU) 2021/914, with Customer as data exporter and Mindai as data importer. Optional clauses are selected as set out in Schedule A. In the event of any conflict between this DPA and the SCCs with respect to a transfer subject to GDPR, the SCCs prevail.

7.4 China Cross-Border. Where Personal Data is subject to PIPL and is transferred outside mainland China, Customer shall, as the Personal Information Processor, ensure that a valid transfer mechanism is in place (including, where applicable, the standard contract, security assessment, or certification under PIPL). Mindai shall provide reasonable assistance and required information to support Customer’s filing or assessment.

8. Data Subject Rights

8.1 Taking into account the nature of the Processing, Mindai shall provide reasonable assistance, by appropriate technical and organizational measures and insofar as possible, to enable Customer to fulfill its obligations to respond to requests from Data Subjects exercising their rights under Applicable Data Protection Laws, including rights of access, rectification, erasure, restriction, objection, portability, and withdrawal of consent.

8.2 If Mindai receives a request directly from a Data Subject relating to Personal Data Processed on behalf of Customer, Mindai shall, without undue delay, inform the Data Subject to address the request to Customer and shall not respond substantively to the request unless authorized by Customer or required by applicable law.

9. Data Protection Impact Assessment and Consultation

9.1 Mindai shall provide reasonable assistance to Customer in carrying out any data protection impact assessment (“DPIA”), personal information protection impact assessment (PIPIA) required under PIPL, or prior consultation with a Supervisory Authority, in each case where required by Applicable Data Protection Laws and taking into account the nature of the Processing and the information available to Mindai.

10. Personal Data Breach Notification

10.1 Mindai shall notify Customer without undue delay, and in any event no later than seventy-two (72) hours after confirming the occurrence of a Personal Data Breach affecting Customer Personal Data.

10.2 The notification shall include, to the extent then known and to the extent reasonably available: (a) a description of the nature of the Personal Data Breach, including the categories and approximate number of Data Subjects and records concerned; (b) the likely consequences; (c) the measures taken or proposed to address and mitigate the Personal Data Breach; and (d) the contact point for further information.

10.3 Mindai shall cooperate with Customer’s reasonable requests for information and shall take reasonable steps to preserve evidence and contain the impact of the Personal Data Breach. Customer is responsible for determining whether to notify Data Subjects, regulators, or other third parties.

11. Audits and Information Rights

11.1 Information Provision. Mindai shall make available to Customer, upon reasonable written request and no more than once per twelve-month period (absent a Personal Data Breach or regulatory requirement), information reasonably necessary to demonstrate compliance with this DPA, including current certifications, summary audit reports (such as ISO 27001 and SOC 2 reports, if and when obtained), penetration testing summaries, and relevant policies.

11.2 On-Site Audit. Where the information described in Section 11.1 is insufficient to demonstrate compliance with this DPA and Applicable Data Protection Laws (including Article 28(3)(h) GDPR), Customer may, upon at least thirty (30) days’ prior written notice and subject to reasonable confidentiality and security protocols, conduct or cause to be conducted (by a mutually acceptable, independent auditor bound by confidentiality) an on-site audit of Mindai’s relevant facilities and records, limited to what is reasonably necessary to verify compliance.

11.3 Costs and Scope. Audits shall be conducted during normal business hours, shall not unreasonably interfere with Mindai’s operations, and shall not extend to other customers’ data or to sensitive security information beyond what is strictly necessary. Customer bears its own costs and Mindai’s reasonable expenses where audits exceed once per year or are triggered by circumstances within Customer’s control.

12. Return or Deletion of Personal Data

12.1 Upon termination or expiration of the Agreement, and subject to Customer’s election, Mindai shall, within a reasonable time period (and in any event within the data-portability and deletion windows set out in the Agreement and Privacy Policy), either (a) return to Customer all Personal Data Processed on Customer’s behalf; or (b) delete such Personal Data, except to the extent retention is required by applicable law or for the resolution of actual or threatened legal claims.

12.2 Where retention is required, Mindai shall continue to ensure the confidentiality and security of such Personal Data and Process it only for the purpose(s) requiring retention. Upon request, Mindai shall provide written confirmation that it has complied with this Section 12.

13. Liability

13.1 Each Party’s liability arising out of or related to this DPA shall be subject to the limitations and exclusions of liability set out in the Agreement. For the avoidance of doubt, this DPA does not increase a Party’s liability cap beyond what is set out in the Agreement, except to the extent required by mandatory Applicable Data Protection Laws.

14. Customer Regulatory Compliance and Assistance

14.1 Customer Responsibility. The Customer shall be solely responsible for fulfilling any regulatory filing, listing, security assessment, content moderation, user protection or similar obligations applicable to its deployment of training outputs under applicable laws, including without limitation regimes governing generative artificial intelligence services, deep synthesis services and algorithmic recommendation services in any applicable jurisdiction.

14.2 Mindai Assistance. Upon Customer’s reasonable written request, Mindai shall provide compliance materials within the scope set out in the MinT Security and Compliance Whitepaper to support the Customer in completing such regulatory filings or listings, including: (a) Training-Platform-side materials (e.g., descriptions of training data processing, compute resources, and security measures); and (b) Model-Gateway-side materials (e.g., basic information about the Macaron model series, the deployment and compliance status of third-party open-source models, and API-level safety and content-moderation measures), with the scope of materials being matched to the specific regulatory obligation the Customer is seeking to fulfil.

14.3 Limits of Assistance. Mindai’s assistance under this Article 14 is limited to information at the Training-Platform infrastructure level and the Model-Gateway service level as operated by Mindai. Mindai makes no representation or warranty regarding the outcome of any regulatory filing by Customer or the compliance status of Customer’s downstream application. Any regulatory action against the Customer arising from Customer’s own application compliance, or from Customer’s configuration, deployment, or use of any model trained on the Training Platform or invoked through the Model Gateway, shall not affect Mindai’s scope of liability under the Main Agreement or this DPA.

15. General

15.1 Order of Precedence. In the event of any conflict between this DPA and the Agreement with respect to the Processing of Personal Data, this DPA prevails. In the event of any conflict between this DPA and the EU Standard Contractual Clauses (with respect to a transfer subject to GDPR), the SCCs prevail.

15.2 Updates. Mindai may update this DPA from time to time to reflect changes in Applicable Data Protection Laws, new transfer mechanisms, or operational improvements, provided that no update shall materially diminish the protections afforded to Personal Data under this DPA without Customer’s consent.

15.3 Governing Law and Dispute Resolution. This DPA is governed by, and construed in accordance with, the governing law and dispute resolution provisions of the Agreement, except where overridden by mandatory provisions of Applicable Data Protection Laws.

15.4 Severability. If any provision of this DPA is held to be invalid or unenforceable, the remaining provisions continue in full force and effect.

15.5 Counterparts; Electronic Signature. This DPA may be executed in counterparts, including by electronic signature, each of which is deemed an original and all of which together constitute one instrument.

Signature Block

IN WITNESS WHEREOF, the Parties have caused this DPA to be executed by their duly authorized representatives as of the Effective Date first written above.

For MINDAI PTE. LTD.:

Signature: __________________________________

Name: [NAME]

Title: [TITLE]

Date: __________________________________

For [CUSTOMER LEGAL NAME]:

Signature: __________________________________

Name: [NAME]

Title: [TITLE]

Date: __________________________________

Schedule A — Details of Processing

A.1 Subject Matter and Duration

Subject matter: Processing of Personal Data to enable Customer’s use of the MinT reinforcement-learning training platform, including provisioning, operation, support, security, and billing of the Service.

Duration: For the term of the Agreement, plus any retention period required by applicable law or permitted under Section 12.

A.2 Nature and Purpose

Nature: Hosting, storing, transmitting, computing, and logging Personal Data contained in Customer Data submitted to the Service, for the purpose of providing the Service.

Purpose: Delivery of the MinT Service as described in the Agreement; security and abuse prevention; billing and reporting; provision of support.

A.3 Categories of Data Subjects

  • Customer’s authorized users (employees, contractors, developers) of the Service.

  • Data subjects whose Personal Data is contained in training datasets, evaluation data, prompts, or outputs submitted by Customer to the Service.

A.4 Categories of Personal Data

  • Account / identity data: name, business email, job role, organization, authentication credentials.

  • Usage telemetry: API request metadata (timestamps, endpoints, response status codes, request sizes), GPU-hour consumption, training job identifiers, console interactions.

  • Billing data: billing entity, tax identifiers, invoice addresses, payment method tokens (full card data not stored by Mindai).

  • Support communications: ticket content, screenshots, logs voluntarily submitted.

  • Customer Model Outputs: model weight files, training checkpoints, and intermediate training artifacts produced on behalf of Customer, to the extent that any Personal Data may be inferable from such artifacts (treated as Customer Data under Section 3.4).

  • Any Personal Data contained in Customer Data that Customer chooses to submit to the Service (which may include additional categories depending on Customer’s use case).

A.5 Special Categories (Sensitive Personal Information)

The Service is not intended for the Processing of special categories of personal data or sensitive personal information unless Customer has established a valid legal basis and confirms appropriate safeguards. Customer shall not submit such data except where specifically agreed in writing with Mindai.

A.6 Frequency of Transfer

Continuous, on demand, during the term of the Agreement.

A.7 Cross-Border Transfer Mechanisms

The following cross-border transfer mechanism applies by default, with additional mechanisms triggered where the underlying Processing falls within the scope of a specific regime:

  • Default (PIPL / PDPA framework): Where Personal Data is subject to PIPL and is transferred outside mainland China, Customer shall, as the Personal Information Processor, ensure that a valid PIPL cross-border mechanism is in place (the PRC Standard Contract for Outbound Transfer of Personal Information, a security assessment filing, or PIPL-compliant certification, as applicable). Where PDPA applies, Parties shall comply with its transfer limitation requirements and rely on contractually-imposed equivalent protection.

  • Conditional (GDPR / UK GDPR): The EU Standard Contractual Clauses (Module Two, controller-to-processor) approved by European Commission Implementing Decision (EU) 2021/914 and, where applicable, the UK International Data Transfer Agreement / Addendum, are triggered only in respect of Personal Data whose Processing falls within the territorial scope of GDPR or UK GDPR. For such transfers only, the following SCC optional clauses apply:

  • Clause 7 – Docking clause: Selected.

  • Clause 9 – Sub-processor authorization: Option 2 (general written authorization) with thirty (30) days’ notice.

  • Clause 11 – Redress / independent dispute resolution: Not selected (Data Subjects retain all statutory rights).

  • Clause 17 – Governing law: [to be selected by the Parties; absent agreement, the law of an EU Member State permitted under Clause 17, Option 1, nominated in writing by Mindai at the time the SCCs are triggered].

  • Clause 18 – Choice of forum: [to be selected by the Parties; absent agreement, the courts of the EU Member State whose law governs the SCCs under Clause 17].

Schedule B — Technical and Organizational Measures

The following is a summary of the technical and organizational measures implemented by Mindai. A more complete description is set out in the Security Whitepaper, which forms part of this Schedule B by reference.

B.1 Identity and Access Management

  • Role-based access control (RBAC) and principle of least privilege.

  • Multi-factor authentication (MFA) required for all administrative and privileged access.

  • Just-in-time (JIT) access provisioning and approval workflow for production systems.

  • Quarterly access reviews and automated offboarding on role change or departure.

B.2 Encryption

  • TLS 1.2 or higher for all data in transit.

  • AES-256 or equivalent for data at rest; KMS-based key management; support for customer-managed keys (CMK) in cloud deployments.

  • Secrets stored in dedicated secret-management systems with audit logging.

B.3 Network and Infrastructure Security

  • Virtual private cloud isolation, security groups, and network ACLs.

  • Web application firewall and DDoS protection at the edge.

  • Hardened operating-system baselines and automated patch management.

  • Vulnerability scanning and penetration testing on a defined cadence.

B.4 Segregation and Tenant Isolation

  • Logical tenant isolation with tenant-scoped identity, storage, and compute boundaries.

  • Separation of duties between development, staging, and production environments.

B.5 Monitoring, Logging, and Incident Response

  • Centralized logging of access, configuration, and security-relevant events; tamper-evident log retention.

  • 24/7 security monitoring with defined alerting and on-call response.

  • Documented incident-response plan with roles, communications, forensic preservation, and post-incident review.

B.6 Business Continuity and Resilience

  • Multi-availability-zone deployment for production components.

  • Regular encrypted backups with tested restore procedures and defined RTO/RPO targets.

  • Business continuity and disaster-recovery testing at least annually.

B.7 Personnel

  • Background checks for personnel with access to production systems, where legally permitted.

  • Mandatory security and privacy training at onboarding and annually thereafter.

  • Written confidentiality obligations for all personnel with access to Customer Data.

B.8 Supplier Management

  • Security and privacy due diligence for Sub-processors.

  • Written data-protection agreements imposing obligations substantially equivalent to those in this DPA.

  • Ongoing monitoring of Sub-processor performance and security posture.

B.9 Certifications and Frameworks

Mindai pursues alignment with MLPS 2.0 Level 3 (China), ISO/IEC 27001, SOC 2, and ISO/IEC 27701. Current status is described in the Security Whitepaper.

Schedule C — Approved Sub-processors

The list of approved Sub-processors is maintained as the Subprocessor List and is incorporated into this DPA by reference. The then-current Subprocessor List is available through the MinT customer portal and on request at contact@mindlab.ltd.

Categories of Sub-processors currently engaged include:

  • Cloud and infrastructure: Huawei Cloud, Alibaba Cloud, Volcengine (for Chinese regional deployments).

  • Payment processing: PCI-DSS-compliant payment service providers.

  • Email and transactional communications providers.

  • Customer support and ticketing tooling.

  • Monitoring, logging, and observability tooling.

Each Sub-processor’s name, role, region, and categories of Personal Data Processed are set out in the Subprocessor List.

On this page