Skip to content

Trust Centre

Data Processing Agreement

What this page is

A summary of the structure, so a reviewer can see what the agreement covers before asking for it. It is not the agreement. The executable document is provided on request to sales@mindhyve.ai — send the questionnaire with it and you will get both back together.

⚠ It also names no regulatory framework. The sibling product sites state alignment to specific instruments; this page does not, because asserting an alignment nobody here has verified for this vertical would be the same defect as publishing a certification badge. What the DPA is aligned to is a question for counsel, and the open list says so.

Roles and scope

The customer is the controller of the personal data in its own book; Eve-Finance, LLC processes it on the customer’s instructions in order to provide EliAI. Scope is the data a customer puts into its own tenant: the underlying matters, the treatment records, the liens and filings, the counterparty correspondence, and the derived valuation artifacts.

The marketing site is out of scope entirely — it is a static export with no database, and the only thing it collects is what you choose to send us through the contact form or by email.

The clauses that matter most here

  • Purpose limitation. Processing is for providing the service and nothing else. There is no training and no fine-tuning in this product, so customer data cannot be absorbed into a model — see AI disclosures.
  • Confidentiality and access. Named roles, multi-factor authentication, server-side authorisation on every request, and tenant isolation enforced by database policy rather than by a query convention.
  • Subprocessors. One, and it is named. Notice before a new one reaches a production path, on the period the agreement specifies.
  • Security measures. The architectural controls in the security page, referenced rather than restated — a DPA that paraphrases them acquires a second version to drift.
  • Assistance with data-subject requests. Erasure is destruction of a per-subject key and the certificate enumerates what was destroyed and what deliberately survives. See data handling.
  • Breach notification. On the timeline the agreement and applicable law require, with what happened, what data was involved, what we have done, and what remains open. See incident response.
  • Return and deletion on termination. Handled per the agreement; export available before access ends.
  • Audit and assistance. Negotiated with the agreement, including penetration-test arrangements.

Sensitive data reached through a matter

A medical receivable exists because an individual was injured and treated, so this platform touches clinical records about people who are not the customer. That is the single most important thing for a reviewer to raise, and it is open: what contractual framework governs it for this vertical has not been settled. Raise it and you will get a straight answer about what exists rather than a paragraph implying it is handled.

How to get the document

Email sales@mindhyve.ai with “DPA” in the subject. A person answers it, and the reply will tell you which of the above is executed, which is negotiable, and which is still with counsel.

SecurityData handlingSubprocessorsAvailabilityIncident responseComplianceAI disclosures