Terms of Service
Last updated: May 27, 2026
Table of Contents
- 1. Agreement to Terms
- 2. Eligibility and Accounts
- 3. The Services
- 4. License
- 5. Use Restrictions
- 6. AI Processing
- 7. User Content
- 8. Cloud Publishing
- 9. Payment and Subscriptions
- 10. Updates and Beta Features
- 11. Proprietary Rights
- 12. Feedback
- 13. Privacy
- 14. Termination
- 15. Disclaimers
- 16. Limitation of Liability
- 17. Indemnification
- 18. Export Compliance
- 19. Governing Law and Dispute Resolution
- 20. Changes to Terms
- 21. Contact
1. Agreement to Terms
By accessing or using the Modus web application or any services offered at https://www.getmodus.com (collectively, the "Services"), you agree to be bound by these Terms of Service ("Terms"). If you do not agree, you may not use the Services.
2. Eligibility and Accounts
You must be at least 16 years old and capable of forming a binding contract to create an account. Account registration can be completed using email or OAuth authentication (including Google and other supported providers). You are responsible for keeping your login credentials secure and for all activities that occur under your account.
3. The Services
Modus is an agentic workforce for data teams, allowing you to create automations of any data work. Features include:
- Automated data processing and analysis workflows
- AI-powered data agents that perform complex data tasks
- Collaboration with teammates through shared links
- Leverage AI models from OpenAI, Anthropic, and other providers for natural-language query generation, summarization, and recommendations
4. License
Subject to these Terms, Modus grants you a limited, non-exclusive, non-transferable, revocable license to access and use the web application solely for your internal business or personal purposes.
5. Use Restrictions
You may not:
- Reverse engineer, decompile, or disassemble the software except as permitted by law
- Circumvent technical limitations or security features
- Use the Services to develop or train competing AI or analytics products
- Upload or publish unlawful or infringing content
- Violate applicable export, privacy, or data-protection laws
6. AI Processing
Modus automatically submits relevant portions of your data to third-party AI providers to power core features. Paid, no-data-retention endpoints are used. You acknowledge and agree that:
- AI outputs may contain errors. You must validate results before relying on them.
- You cannot disable core AI processing or AI metadata reporting.
- You will not input content that you are prohibited from sharing with third parties.
7. User Content
"User Content" means data, files, prompts, and any output you create with the Services. Except for the limited rights granted to Modus to operate the Services, you retain all ownership in User Content. You represent that you have all rights necessary to submit the User Content and to grant Modus the rights described in these Terms.
8. Cloud Storage
By using the Services, you acknowledge that your data is hosted on AWS servers, primarily located in the United States, though the specific region may vary. You are solely responsible for ensuring that your content does not contain confidential or regulated information beyond what you're authorized to share. Deletion from cloud storage will be completed within 30 days of your verified deletion request.
9. Payment and Subscriptions
Modus does not currently offer automatic payment processing. Pricing and payment arrangements are handled separately. Any fees agreed upon are non-refundable except where required by law.
10. Updates and Beta Features
Modus may provide automatic updates or new features. Beta or preview features are offered "as is" and may be changed or discontinued at any time without notice.
11. Proprietary Rights
Modus and its licensors own all intellectual property rights in the Services. All trademarks, logos, and product names are the property of their respective owners.
12. Feedback
If you provide ideas, suggestions, or feedback, you grant Modus a perpetual, irrevocable, royalty-free license to use that feedback for any purpose without compensation.
13. Privacy
Our Privacy Policy explains how we collect, use, and safeguard personal data and is incorporated by reference. By using the Services, you consent to our data practices.
14. Termination
You may stop using the Services at any time. Modus may suspend or terminate your access if you breach these Terms or if required by law. Sections 6, 7, 9, 11, 12, 15-19 survive termination.
Surviving Sections After Termination:
- AI Processing (Section 6)
- User Content (Section 7)
- Payment and Subscriptions (Section 9)
- Proprietary Rights (Section 11)
- Feedback (Section 12)
- Disclaimers (Section 15)
- Limitation of Liability (Section 16)
- Indemnification (Section 17)
- Export Compliance (Section 18)
- Governing Law and Dispute Resolution (Section 19)
15. Disclaimers
The Services are provided "as is" and "as available." Modus disclaims all warranties, express or implied, including merchantability, fitness for a particular purpose, and non-infringement. Modus does not warrant that the Services will be error-free, uninterrupted, or secure, or that AI outputs will be accurate.
16. Limitation of Liability
To the maximum extent permitted by law, Modus will not be liable for indirect, incidental, special, consequential, or punitive damages, or for loss of profits, data, or goodwill, even if advised of the possibility. Modus's total liability arising out of or relating to the Services is limited to the amount you paid to Modus in the 12 months preceding the claim.
17. Indemnification
You agree to indemnify and hold harmless Modus and its officers, directors, employees, and agents from any claims, damages, or expenses arising from your use of the Services or violation of these Terms.
18. Export Compliance
You may not use or export the Services in violation of applicable export laws and regulations.
19. Governing Law and Dispute Resolution
These Terms are governed by the laws of the State of Delaware without regard to conflict-of-law rules. Any dispute that cannot be resolved informally will be submitted to the exclusive jurisdiction of the competent courts in Delaware. The United Nations Convention on Contracts for the International Sale of Goods does not apply.
| Legal Aspect | Details |
|---|---|
| Governing Law | Laws of the State of Delaware |
| Jurisdiction | Courts in Delaware |
| Conflict of Laws | Rules do not apply |
| UN Convention | Does not apply to these Terms |
20. Changes to Terms
We may modify these Terms. Material changes will be posted in-app or on https://www.getmodus.com and will become effective 14 days after notice. Your continued use of the Services after the effective date constitutes acceptance of the revised Terms.
21. Contact
Modus Legal Team
Email: contact@getmodus.com
If you have questions about these Terms, please contact us at the address above.
Privacy Policy
Last updated: July 28, 2026
Table of Contents
- 1. Who We Are
- 2. Scope
- 3. Information We Collect
- 4. How We Use Information
- 5. AI Processing Details
- 6. How We Share Information
- 7. Data Location & International Transfers
- 8. Security
- 9. Retention
- 10. Your Rights
- 10A. Additional Information for Individuals in the United States
- 10B. Health Information (HIPAA)
- 11. "Do Not Track" Disclosures
- 12. Children
- 13. Changes to This Policy
- 14. Contact Us
1. Who We Are
Modus Technologies Inc. and Modus Artificial Intelligence Ltd. ("Modus," "we," "our," or "us") offer an agentic workforce for data teams, allowing you to create automations of any data work. This Privacy Policy explains how we collect, use, disclose, and safeguard personal information when you use our website (https://www.getmodus.com) and the Modus web application (together, the "Services").
2. Scope
This Policy applies to any person who visits our website or uses the Modus web application. When we process personal data on your behalf (for the performance of a contract), the Data Processing Agreement (DPA) shall apply, not this Privacy Policy.
3. Information We Collect
| Category | What We Collect | Purpose | Legal Basis (e.g. EU/UK) |
|---|---|---|---|
| Account Data | Name, email address, authentication identifier (OAuth or email-based) | Account creation, authentication | Contract performance with you |
| Usage Metrics, Cookies and similar technologies | IP address, time and date of access, type of device and browser used, language used, pages visited, feature interactions, error events, volumes of usage (via Datadog) | Facilitate a feature specifically requested, product analytics, debugging, service improvement, inform and serve personalized ads more relevant to user interests | If essential — Legitimate interest in providing you with the functionality of the Service If non-essential — consent |
| Contacting us with an inquiry through our email and our online contact form, booking a demo | Full name, work email, company, job title, company size, and text message | Reply, schedule demos and follow up | Legitimate interest in responding to your inquiry or demo request and our business development |
| AI Interaction Metadata | Structural metadata about prompts and responses (never raw content) | Model quality improvement, troubleshooting | Legitimate interest in developing and enhancing our business and the Service |
| User-Uploaded Content | Datasets, notebooks, dashboards, reports you choose to import or publish | Core functionality | Contract performance with you |
| Integration Data | Data imported through database integrations (e.g., BigQuery, Snowflake, PostgreSQL, MySQL, Clickhouse, Oracle, Databricks, SQLite, CSV files), including table schemas, query results, and metadata | Core functionality, data analysis | Contract performance with you |
| Technical Data | Device type, OS version, app version, IP-derived region | Security, fraud prevention, analytics | Legitimate interest in developing and enhancing our business and the Service, defending and enforcing against violations and breaches that are harmful to our business |
4. How We Use Information
- Provide, operate, and maintain the Services
- Authenticate users and secure accounts
- Diagnose and fix bugs or performance issues
- Improve and develop new features (excluding the use of Google Workspace data or personal data to train or develop AI/ML models)
- Send service-related notices (e.g., critical updates)
- Comply with legal obligations
5. AI Processing Details
| Question | Answer |
|---|---|
| Third-party providers | Anthropic, OpenAI, and Google; all via paid, no-data-retention endpoints |
| Data sent | Text you explicitly run through AI features, project structure, and relevant code or schema snippets |
| PII transmission | Sensitive data is detected and protected through built-in DSPM and DLP controls (redaction, masking, flagging, blocking) before reaching the AI context window. |
| Vendor training | Vendors are contractually opted-out of training on your content |
| Our own training | We do not use Google Workspace data (including Google Drive content) or personal data to train or develop AI/ML models. Any model training is limited to aggregated, de-identified, non-personal statistics, and never uses raw user content. |
| Opt-out | Core AI processing and AI metadata reporting cannot be disabled because they underpin Modus's functionality |
7. Data Location & International Transfers
Your data is hosted in the cloud on servers primarily located in the United States (AWS), though the specific region may vary. Data may be transferred internationally for AI processing and analytics. We rely on Standard Contractual Clauses (SCCs) or other recognized safeguards for such transfers. California residents should note that their data may be transferred outside of California and the United States for processing.
8. Security
Modus maintains a SOC 2 Type II report (covering Security, Availability, and Confidentiality, including HIPAA Security Rule mapping) audited by Kost Forer Gabbay & Kasierer (EY Israel). Modus is also certified to ISO/IEC 27001:2022 (Certificate No. 1127587, issued by SII-QCD, ANAB accredited and IQNET recognized; valid through May 2029). Reports and certificates are available to customers under NDA via security@getmodus.com.
- TLS encryption for all in-transit data leaving your device
- Encryption-at-rest for any cloud-stored secrets and published content
- Secrets (e.g., API keys, passwords) stored in OS-level secure keychains
- Access to production systems limited to a small, vetted Modus team on a least-privilege basis
- Continuous monitoring and automated alerts via Datadog
9. Retention
- Cloud-hosted data: retained until you request deletion
- Tenant deletion: completed within 30 days of your verified deletion request
- Account records and logs: retained until you request deletion, then erased as part of tenant deletion process
- Backup copies: may persist in encrypted backups for up to 7 days before permanent deletion
10. Your Rights (Including EU/UK Rights)
Modus is the data controller of the personal information collected in accordance with this Policy, and the data processor for the information collected in the performance of a contract, as further explained in the DPA.
Name: Modus Technologies Inc.
Registered Agent Address: Cogency Global Inc. at 850 New Burton Road, Suite 201, Dover DE 19904, 800-483-1140.
Name: Modus Artificial Intelligence Ltd.
Address: Ahad Ha'am 54 Tel Aviv, 6520216, Israel
Modus EU GDPR Representative
Name: Prighter EU Rep GmbH
Address: Schellinggasse 3/10, 1010 Vienna Austria
Privacy Request Link: https://app.prighter.com/dsrtool/new/dsr_eu/18019768846
Modus UK GDPR Representative
Name: Prighter Ltd
Address: 20 Mortlake Mortlake High Street, London, SW14 8JN United Kingdom
Privacy Request Link: https://app.prighter.com/dsrtool/new/dsr_uk/18019768846
You have the right to review the personal information we collect and use about you and the right to request correction of your personal information. To exercise these rights, please contact us at contact@getmodus.com.
If you are an EU or UK data subject, or under applicable jurisdiction with similar rights as granted under the GDPR, you have the:
- Right to Access and receive a copy of your personal information that we process.
- Right to Rectify inaccurate personal information we have concerning you and to have incomplete personal information completed.
- Right to easily and at any time withdraw your consent, such as to the use of non-essential cookies. The withdrawal of consent will not affect the lawfulness of processing based on consent before its withdrawal.
- Right to be Forgotten. Under certain circumstances, such as when you object to our processing of your personal information based on our legitimate interest and there are no overriding legitimate grounds for the processing, you have the right to ask us to erase your personal information. However, notwithstanding such request, we may still process your personal information if it is necessary to comply with our legal obligations, or for the establishment, exercise, or defense of legal claims. If you wish to exercise any of these rights, please contact us through the channels listed in this Privacy Policy.
- Right to Data Portability, that is, to receive the personal information that you provided to us, in a structured, commonly used, and machine-readable format. You have the right to transmit this data to another person or entity. Where technically feasible, you have the right to have your personal information transmitted directly from us to the person or entity you designate.
- Right to Object to our processing of your personal information based on our legitimate interest. However, we may override the objection if we demonstrate compelling legitimate grounds, or if we need to process such personal information for the establishment, exercise, or defense of legal claims.
- Right to Restrict us from processing your personal information (except for storing it): (a) if you contest the accuracy of the personal information (in which case the restriction applies only for a period enabling us to determine the accuracy of the personal information); (b) if the processing is unlawful and you prefer to restrict the processing of the personal information rather than requiring the deletion of such data by us; (c) if we no longer need the personal information for the purposes outlined in this Privacy Policy, but you require the personal information to establish, exercise or defend legal claims; or (d) if you object to our processing based on our legitimate interest (in which case the restriction applies only for the period enabling us to determine whether our legitimate grounds for processing override yours).
How to exercise:
- Trust Center: We provide you with an easy way to submit to us privacy related request like a request to access or erase your personal data. If you want to make use of your data subject rights, please access the above privacy request links or visit our Trust Center: https://app.prighter.com/portal/modus.
- Account data: email contact@getmodus.com from your registered address.
- In-app data: use the data management tools within the application settings.
When you contact us, we reserve the right to ask for reasonable evidence to verify your identity before we provide you with information. Where we are not able to provide you with information that you have asked for, we will explain the reason.
We will respond to requests within 30 days (45 days for individuals in the United States). Deletion from cloud storage requires a manual tenant deletion process, which will be completed within 30 days.
Subject to applicable law, you have the right to lodge a complaint with your local data protection authority. If you are in the EU, then according to Article 77 of the GDPR, you can lodge a complaint to the supervisory authority, in the Member State of your residence, place of work or place of alleged infringement of the GDPR. For a list of supervisory authorities in the EU, click here.
If you are in the UK, you can lodge a complaint to the Information Commissioner's Office (ICO) pursuant to the instructions provided here. You can also lodge a complaint to Modus, as a Controller, for the personal information described in this Privacy Policy, by filling an electronic complain form at the following link https://app.prighter.com/dsrtool/new/dsr_uk/18019768846.
10A. Additional Information for Individuals in the United States
If you are an individual residing in the United States, we provide you with the following information pursuant to state privacy laws, such as the California Consumer Privacy Act of 2018, as amended (CCPA) and the Texas Data Privacy and Security Act (TDPSA).
Categories of Personal Information We Collect
We collect the following categories of personal information, as described in Section 3 above:
- Identifiers (name, email address, OAuth identifier). Source of Information: The consumers themselves.
- Internet or network activity (usage metrics, browsing history on our site). Source of Information: The consumers' device.
- Professional or employment-related information (if included in datasets you upload). Source of Information: The consumers themselves.
- Inferences drawn from the above to create user profiles. Source of Information: The consumers themselves.
How We Use Personal Information & Business Purposes
We use personal information for the business and commercial purposes described in Section 4 of this Privacy Policy, and for the following business purposes:
- Providing you with the functionality of our Service to you.
- Maintaining or servicing accounts, providing customer service.
- Detecting security incidents and protecting against malicious, deceptive, fraudulent, or illegal activity.
- Undertaking activities to verify or maintain the quality of the Service and to improve, upgrade or enhance the Service.
- Debugging to identify and repair errors.
Disclosures to third parties
We do not sell your personal information and have not done so in the past 12 months. We do not share your personal information for cross-context behavioral advertising.
The list below explains with whom we disclosed your personal information for a business purpose in the preceding 12 months. Other than this, we have not disclosed your personal information for a business purpose in the preceding 12 months:
- Our service providers, who will use it only as necessary to assist us in the internal operations of our business and the Service, and not for their own promotional purposes. In general, we share personal information with service providers (subprocessors listed in Section 6) who perform services on our behalf.
- Third party cookie providers, for the same purposes indicated in the chart above.
- Competent authorities, legal counsels, and advisors if you abused your rights to use the Service or violated any applicable law in the course of doing business with us.
- Judicial, governmental, or regulatory authority if they require us to disclose your information.
- Target entity of the merger or acquisition, legal counsels, and advisors if the operation of the Service or our business is organized within a different framework, or through another legal structure or entity.
Your rights if you reside in the United States
- Right to know: the categories of personal information we have collected about you, the categories of sources from which the personal information is collected, our business or commercial purpose is for collecting personal information, the categories of third parties with whom we share personal information, if any, the specific pieces of personal information we have collected about you.
- Right to delete personal data provided by or obtained about you: Subject to certain exceptions set out below, on receipt of a verifiable request from you, we will:
- Delete your personal information from our records; and
- Direct any service providers to delete your personal information from their records.
- Complete the transaction for which the personal information was collected, fulfill the terms of a written warranty or product recall conducted in accordance with federal law, provide a good or service requested by you, or reasonably anticipated within the context of our ongoing business relationship with you, or otherwise perform a contract between you and us.
- Help to ensure security and integrity to the extent the use of the consumer's personal information is reasonably necessary and proportionate for those purposes.
- Debug to identify and repair errors that impair existing intended functionality.
- Exercise free speech, ensure the right of another consumer to exercise his or her right of free speech, or exercise another right provided for by law.
- Comply with the applicable state privacy law.
- Engage in public or peer-reviewed scientific, historical, or statistical research that conforms or adheres to all other applicable ethics and privacy laws, when our deletion of the information is likely to render impossible or seriously impair the ability to complete such research, provided we have obtained your informed consent.
- Enable solely internal uses that are reasonably aligned with your expectations based on your relationship with us and compatible with the context in which you provided the information.
- Comply with an existing legal obligation.
- Right to Non-Discrimination: We will not discriminate against you for exercising any of your US rights, including by denying goods or services, charging different prices, or providing a different level of quality.
- Right to correct inaccurate personal information, taking into account the nature of the data and the purposes for processing the data: If we receive a verifiable request from you to correct your information and we determine the accuracy of the corrected information you provide, we will correct inaccurate personal information that we maintain about you. In determining the accuracy of the personal information that is the subject of your request to correct, we will consider the totality of the circumstances relating to the contested personal information. We also may require that you provide documentation if we believe it is necessary to rebut our own documentation that the personal information is accurate. We may deny your request to correct in the following cases:
- We have a good-faith, reasonable, and documented belief that your request to correct is fraudulent or abusive.
- We determine that the contested personal information is more likely than not accurate based on the totality of the circumstances.
- Conflict with federal or state law.
- Other exception of the state privacy laws.
- Inadequacy in the required documentation
- Compliance proves impossible or involves disproportionate effort.
- Protection against discrimination for exercising these rights: You have the right not to be discriminated against by us because you exercised any of your rights under state privacy laws.
- Right to Opt-Out of Sale: We do not sell personal information to third parties. If our practices change, we will update this Policy and provide an opt-out mechanism.
- Right to Limit Use of Sensitive Personal Information: While we do not intentionally collect sensitive personal information, if you believe we have such information, you may request that we limit its use.
Data Retention
We retain personal information as described in Section 9 of this Privacy Policy. California residents can request deletion at any time, subject to legal exceptions.
How to Exercise Your US Rights
To exercise your US rights, you may:
- Email us at: contact@getmodus.com
- Registered Agent Address: Cogency Global Inc. at 850 New Burton Road, Suite 201, Dover DE 19904, 800-483-1140.
- Use the data management tools in your account settings
You will need to verify your identity before we can fulfill your request, by using a two or three points of data verification process, depending on the type of information you require and the nature of your request. We will respond within 45 days of receipt of your request. If we require more time, we will inform you of the reason and extension period in writing.
Authorized Agents
You may designate an authorized agent to make a request on your behalf. To do so, you need to provide the authorized agent with written permission to do so, and the agent will need to submit to us proof that they have been authorized by you. We will also require that you verify your own identity, as explained above.
Shine the Light Law
California Civil Code Section 1798.83 permits California residents to request certain information about disclosure of personal information to third parties for direct marketing purposes. We do not share personal information with third parties for their direct marketing purposes.
10B. Health Information (HIPAA)
Where Modus processes Protected Health Information (PHI) on behalf of customers under a Business Associate Agreement (BAA), such data is handled in accordance with the HIPAA Privacy and Security Rules. Modus does not collect PHI directly from individuals. PHI processing is governed by the terms of the applicable BAA.
For questions about how Modus handles PHI, contact privacy@getmodus.com.
11. "Do Not Track" Disclosures
We do not monitor or respond to Do Not Track browser requests. Please ensure to change any settings of your browser and/or our Service, whenever you wish cookies to cease.
12. Children
Modus is not directed to children under 16, and we do not knowingly collect data from minors. If you believe a minor has provided personal data, please contact us and we will delete it.
13. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be announced in-app or via email at least 14 days before they take effect. Continued use of the Services after the effective date constitutes acceptance of the revised Policy.
14. Contact Us
Modus Privacy Team
Email: contact@getmodus.com.
For any questions about this Policy or our privacy practices, please contact us using the information above.
Data Processing Agreement
Effective date: May 27, 2026
Table of Contents
- 1. Definitions
- 2. Subject Matter and Duration
- 3. Purpose and Nature of Processing
- 4. Categories of Data and Data Subjects
- 5. Obligations of Controller
- 6. Obligations of Processor
- 7. International Transfers
- 8. Audits
- 9. Liability and Indemnity
- 10. Precedence
- 11. Governing Law
- Annex I – Details of Processing
- Annex II – Technical and Organisational Security Measures
- Annex III – Approved Sub-processors
1. Definitions
| Term | Definition |
|---|---|
| Applicable Data Protection Law | All laws and regulations regarding the protection of Personal Data that apply to the Processing under this Agreement, including the EU and UK GDPR. |
| Personal Data | Any information relating to an identified or identifiable natural person that is Processed by Modus on behalf of Customer. |
| Processing, Processor, and Controller | Have the meanings set out in Applicable Data Protection Law. |
| Standard Contractual Clauses | The clauses adopted by the European Commission Implementing Decision 2021/914 and, where relevant, the UK Addendum. |
| Services | The Modus web application and any related cloud features provided to Customer. |
2. Subject Matter and Duration
- 2.1 This Agreement governs Modus's Processing of Personal Data on behalf of Customer in the course of providing the Services.
- 2.2 This Agreement remains in force for the term of the underlying Services agreement and until all Personal Data has been deleted or returned to Customer.
3. Purpose and Nature of Processing
Modus Processes Personal Data solely to provide, secure, and improve the Services, including:
- Web-based analytics platform functions
- Cloud storage and publication of notebooks, dashboards, and reports
- Error monitoring, usage analytics, and product development
- Automated AI-powered analysis using third-party model providers (see Annex III)
4. Categories of Data and Data Subjects
| Item | Description |
|---|---|
| Data Subjects | Customer's employees, contractors, end users, and any individuals whose data appears in datasets Customer imports |
| Categories of Personal Data | Names, email addresses, authentication identifiers (OAuth or email-based), usage metrics (pseudonymous), technical device data, any Personal Data included by Customer in uploaded datasets or published reports |
| Special Categories | Not intended – Customer must not intentionally submit special-category data without a lawful basis |
Full details appear in Annex I.
5. Obligations of Controller
Customer will:
- a. ensure it has a valid legal basis for all Processing carried out under this Agreement,
- b. provide any required notices to data subjects,
- c. not instruct Modus to Process Personal Data in violation of Applicable Data Protection Law.
6. Obligations of Processor
Modus shall:
- 6.1 Process only on documented instructions – including those set out in the Agreement, unless otherwise required by EU or Member State law.
- 6.2 Confidentiality – ensure all personnel authorised to Process Personal Data are subject to confidentiality obligations.
- 6.3 Security – implement the technical and organisational measures in Annex II and maintain them throughout the term.
- 6.4 Sub-processors – engage only the sub-processors listed in Annex III and notify Customer of any intended additions or replacements, giving Customer an opportunity to object on reasonable grounds.
- 6.5 Data Subject Rights – taking into account the nature of the Processing, assist Customer by appropriate technical and organisational measures to respond to requests for exercising data-subject rights.
- 6.6 Data Protection Impact Assessments – provide reasonable assistance to Customer with DPIAs and prior consultations with supervisory authorities where required.
- 6.7 Breach Notification – notify Customer without undue delay after becoming aware of a Personal Data Breach and provide information necessary for Customer to comply with its legal obligations.
- 6.8 Return or Deletion – at termination, delete or return Personal Data at Customer's choice, except to the extent EU or Member State law requires retention.
7. International Transfers
- 7.1 Where Modus or its sub-processors transfer Personal Data outside the EEA or UK to a country that has not received an adequacy decision, such transfer shall be governed by the Standard Contractual Clauses incorporated by reference.
- 7.2 For transfers to the United States, Modus or the relevant sub-processor will rely on either the Data Privacy Framework certification or the SCCs.
8. Audits
Modus will make available all information necessary to demonstrate compliance with this Agreement and allow, at Customer's reasonable request and expense, audits by an independent third party bound to confidentiality. Audits may occur once per year and after any material Personal Data Breach.
9. Liability and Indemnity
Each party is liable for the damages it causes by any Processing that infringes Applicable Data Protection Law. Liability limitations in the main Services agreement apply to this Agreement to the maximum extent permitted by law.
10. Precedence
In the event of conflict, the provisions of the Standard Contractual Clauses prevail, followed by this Agreement, followed by the main Services agreement.
11. Governing Law
This Agreement is governed by the same law and jurisdiction as the main Services agreement, unless the SCCs require otherwise.
Annex I – Details of Processing
| Element | Description |
|---|---|
| Processor | Modus Technologies Inc., Delaware, and Modus Artificial Intelligence Ltd., Tel Aviv-Yafo, jointly "Modus". |
| Controller | The Customer entity that accepted the Modus Terms of Service |
| Purpose | Provide and improve the Modus Services, including AI-powered analytics, publishing features, account management, security, and support |
| Data Subjects | See Section 4 |
| Personal Data | See Section 4 |
| Duration | For the term of the Services plus deletion period |
| Frequency | Continuous and ad-hoc, depending on user interactions |
| Location of Processing | Cloud-based operations primarily in the United States (AWS, region may vary) and AI processing as listed in Annex III |
Annex II – Technical and Organisational Security Measures
Encryption
- TLS 1.2+ for all data in transit leaving the user's device
- AES-256 or stronger encryption for secrets stored in the cloud
Access Control
- Role based access with least-privilege principle
- Multi-factor authentication for privileged accounts
Physical Security
- Cloud infrastructure hosted in ISO 27001 and SOC 2 certified data centres operated by AWS.
Certifications and Attestations
Modus maintains the following independent attestations and certifications, with reports available to customers under NDA via security@getmodus.com:
- SOC 2 Type II report covering Security, Availability, and Confidentiality, including HIPAA Security Rule mapping. Auditor: Kost Forer Gabbay & Kasierer (EY Israel).
- ISO/IEC 27001:2022 certification. Certificate No. 1127587. Issued by SII-QCD (ANAB accredited, IQNET recognized).
System Security
- Separation of production and development environments
- Automated dependency vulnerability scanning
- Regular penetration testing
Monitoring and Logging
- Centralised logging with tamper protection
- Real-time alerting via Datadog for anomalous events
Business Continuity
- Encrypted backups of published content
- Disaster recovery plan tested at least annually
Personnel Security
- Background checks for employees with production access
- Mandatory security awareness training
Incident Response
- Documented procedure defining roles, escalation paths, and customer communication timelines
Annex III – Approved Sub-processors
Mandatory Sub-processors
| Sub-processor | Description |
|---|---|
| Amazon Web Services (AWS) | Cloud hosting and storage infrastructure |
| Google Cloud Platform (GCP) | Cloud infrastructure and services |
| ClickHouse | Database and analytics processing |
| Clerk | Authentication and user management |
| Datadog | Product analytics and monitoring |
| OpenRouter | AI model routing and inference platform |
Optional Sub-processors (Add-ons)
The following sub-processors are only utilized if you enable specific add-on features:
| Sub-processor | Description |
|---|---|
| Pipedream | Workflow automation and integrations |
| E2B | Code execution and sandboxing environment |
| Mem0 | Memory and context management for AI |
| Tavily | AI-powered web search and research |