MontrusLegal

Data Processing Agreement

Montrus Technologies LLC Version 1.5 — 19 September 2026


This Data Processing Agreement ("DPA") forms part of the agreement between Montrus Technologies LLC ("Montrus", "Processor") and the organisation subscribing to Montrus ("Customer", "Controller") for the provision of the Montrus platform (the "Services").

It applies where Montrus processes personal data on the Customer's behalf and the GDPR, UK GDPR or a comparable law applies.

Where this DPA conflicts with the main agreement, this DPA governs the processing of personal data.


1. Definitions

Terms not defined here have the meaning given in the GDPR. "Data Protection Law" means the EU GDPR, the UK GDPR and the UK Data Protection Act 2018, and any other data protection or privacy law applicable to the processing.


2. Roles

2.1 For the personal data of the Customer's workers processed through the Services, the Customer is the Controller and Montrus is the Processor.

2.2 For its own business data — the Customer's account, its billing records, its administrators' contact details, and security and service logs — Montrus is an independent Controller and its Privacy Policy applies.

2.3 An important distinction, stated plainly. Montrus allows an individual to hold a personal account which is separate from any workplace account. For that personal account — including the individual's capability passport, their personal Mentor conversations, their wellbeing conversations and their private career exploration — Montrus is the Controller and the Customer has no rights over it and no visibility of it. The Customer only ever sees an individual's personal passport if that individual explicitly grants access, which they may revoke at any time. The Customer must not instruct Montrus to disclose it, and Montrus will not.


3. Subject matter, duration, nature and purpose

Subject matter. Processing of personal data of the Customer's workers in order to provide the Services.

Duration. For as long as the main agreement is in force, plus the period in section 12.

Nature and purpose. Hosting, storage, and processing to: assess capability; generate and schedule development plans; provide AI-assisted coaching, interview practice and content; calculate capability levels, readiness and talent signals; support succession and internal mobility; provide reporting to the Customer; host and moderate a private community space for the Customer's workers where the Customer enables it; and support hiring where the Customer uses those features.

Categories of data subject and of personal data are set out in Annex I.


4. Processing instructions

4.1 Montrus will process personal data only on the Customer's documented instructions, including on transfers, unless required otherwise by law — in which case Montrus will inform the Customer first unless that law forbids it.

4.2 The main agreement, this DPA, and the Customer's use of the Services' configuration options together constitute the Customer's complete documented instructions.

4.3 Montrus will tell the Customer if, in its opinion, an instruction infringes Data Protection Law.

4.4 Montrus does not use Customer personal data to train artificial intelligence models, and does not permit its AI subprocessors to do so. Montrus does not sell personal data.

4.5 The community space. Where the Customer enables the community space, its workers can post to a room private to that organisation. Montrus processes that content on the Customer's instruction and does not make it available to the Customer — not to its administrators, not to HR, and not to a worker's manager. That is deliberate rather than a limitation: a space the employer can read is not one in which people will say what they cannot yet do, which is what the space is for. Montrus screens every post before it is published and reviews any post a worker reports. The Customer may switch the space off at any time, which stops new posts; switching it off does not give the Customer access to posts already made.


5. Confidentiality

Montrus will ensure that everyone authorised to process the personal data is bound by an appropriate duty of confidentiality, and will limit access to those who need it to provide the Services or to comply with law.


6. Security

Montrus will implement appropriate technical and organisational measures as required by Article 32 GDPR. The measures in place are described in Annex II.

Montrus may update these measures provided the level of protection is not reduced.


7. Subprocessors

7.1 The Customer gives Montrus general written authorisation to engage subprocessors. The subprocessors in use on the date of this DPA are listed in Annex III.

7.2 Montrus will impose data protection obligations on each subprocessor that are no less protective than those in this DPA, and remains fully liable to the Customer for their performance.

7.3 Montrus will give the Customer at least 30 days' notice before adding or replacing a subprocessor. The Customer may object on reasonable data protection grounds within that period. If the parties cannot resolve the objection, the Customer may terminate the affected Services without penalty for the remainder of the term.

7.4 The Customer should note that the Services depend on AI subprocessors (Annex III) to function at all. An objection to those subprocessors cannot be resolved by removing them, and the practical remedy is termination under 7.3.


8. Assisting with data subject rights

8.1 The Services provide the Customer with the means to access, correct and delete personal data of its workers directly through its administrative interface. Individuals with a personal account can additionally export and erase their own personal data themselves.

8.2 Where an individual exercises a right that the Customer cannot fulfil through the Services, Montrus will provide reasonable assistance, taking into account the nature of the processing.

8.3 If Montrus receives a request directly from one of the Customer's workers about workplace data, it will not respond substantively, and will refer the individual to the Customer and notify the Customer without undue delay. A worker's question to Montrus support about workplace data is handled the same way: it is not answered substantively, and it is referred to the Customer. Where the Customer has published workplace documents in the Services, a worker's workplace question is answered from those documents only; otherwise the worker is referred to the HR contact the Customer named or, at the worker's choice, the question is sent to the Customer's administrators.

8.4 Limits the Customer should be aware of. Certain records are retained after a worker's access is removed, because deleting them would remove protection or destroy evidence:

  • security and administrative audit logs, which record who viewed sensitive information and who changed what;
  • hiring records, which document the Customer's own hiring decisions and are the Customer's data to keep or delete;
  • the workplace record itself, which is retained under the Customer's control until the Customer instructs deletion.

8.5 Community space content. Because the Customer cannot read the community space, it cannot fulfil a request about that content through the Services. Each worker can export their own posts themselves from their own account, which is how this right is met in practice. Where the Customer must respond to a request it cannot meet that way, clause 8.2 applies.

8.6 Support requests. The Customer's administrators and workers can contact Montrus support from within the Services. What a worker sends to Montrus support is not disclosed to the Customer, except as clause 8.3 requires. Montrus holds support correspondence as its own record of dealing with the person who wrote it, and keeps it for the periods published in the Montrus Privacy Policy.


9. Automated decision-making

The Services generate automated outputs about individuals, including capability levels, a capability index, talent signals, succession readiness, internal candidate match scores and interview scores.

The Customer remains responsible for how those outputs are used, for any decision that produces legal or similarly significant effects, for meeting the requirements of Article 22 GDPR including human review, and for informing its workers that these outputs exist.

Montrus will provide, on request, an explanation of how a given output is produced.

Local employment law. In several jurisdictions, profiling workers carries obligations beyond the GDPR — works council consultation and co-determination in Germany, for example, or equivalent employee representative requirements elsewhere. Those obligations attach to the Customer as the employer, apply regardless of the governing law of this Agreement, and cannot be discharged by it. The Customer is responsible for identifying and meeting them before deploying the Services to its workers.

Switching the talent signal off. The capability index is generated for all workplace users. The talent signal — flagging individuals against that index — is off by default. It is switched on and off by the Customer's own administrator, in the organisation's settings, and switching it off also clears any flags already set. Montrus will make the change on request, but the Customer does not need to ask: it is the Customer's own control.


10. Personal data breach

Montrus will notify the Customer without undue delay, and in any event within 48 hours, of becoming aware of a personal data breach affecting the Customer's personal data, and will provide the information reasonably available to enable the Customer to meet its own obligations, with updates as the investigation proceeds.

Notification will be sent to the Customer's designated administrative contact. Montrus will not notify the Customer's data subjects or a supervisory authority on the Customer's behalf unless instructed to.

The Customer may report a suspected breach through Help → Contact support in the Services. Montrus treats such a report as urgent on any day of the week, not only in business hours.


11. Data protection impact assessments

Montrus will provide reasonable assistance with data protection impact assessments and prior consultations under Articles 35 and 36 GDPR, taking into account the nature of the processing and the information available to it.


12. Deletion and return

On termination or expiry of the main agreement, Montrus will, at the Customer's choice, delete or return the Customer's personal data, and delete existing copies, within 60 days — unless law requires it to be retained, in which case Montrus will tell the Customer what is retained and why.

Routine backups are overwritten on their normal cycle; data in backups remains protected by this DPA until it is.

The Customer may export its data through the Services before termination and should do so, as deletion is irreversible.


13. Audit

Montrus will make available the information necessary to demonstrate compliance with Article 28 GDPR, and will allow and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates.

The parties agree that: audits will be at most once per year unless a supervisory authority or a personal data breach requires otherwise; the Customer will give at least 30 days' notice; audits will happen in business hours, without unreasonable disruption; and the auditor will be bound by confidentiality and must not be a Montrus competitor.

Montrus does not currently hold a SOC 2 or ISO 27001 certification. Where it obtains one, the report may be provided in place of an on-site audit.


14. International transfers

Montrus processes personal data in the United States and its subprocessors may process it in other countries.

Where personal data is transferred out of the EEA, the UK or Switzerland, the transfer is made under the European Commission's Standard Contractual Clauses (Decision 2021/914), Module Two (controller to processor) or Module Three (processor to processor) as applicable, together with the UK International Data Transfer Addendum where UK data is transferred, and the Swiss addendum where Swiss data is transferred.

Those clauses are incorporated into this DPA by reference and take precedence over it in the event of conflict. For the purposes of the clauses:

  • the Customer is the data exporter and Montrus the data importer;
  • the docking clause (Clause 7) applies;
  • Option 2 of Clause 9(a) applies, with the 30-day notice period in section 7.3;
  • the optional redress clause in Clause 11 does not apply;
  • the governing law under Clause 17 is the law of the Republic of Ireland, and the forum under Clause 18(b) is the courts of Ireland — or, for UK transfers, the law and courts of England and Wales;
  • Annexes I, II and III to this DPA populate Annexes I, II and III of the clauses.

Montrus does not currently offer a choice of processing region. A Customer with a legal or policy requirement for data residency in a specific country should raise it before contracting.


15. Liability

Each party's liability under this DPA is subject to the limitations and exclusions of liability in the main agreement.


16. Term

This DPA takes effect when the main agreement does and continues until all Customer personal data has been deleted or returned under section 12.



Annex I — Description of the processing

A. Categories of data subject

  • The Customer's employees, contractors and workers who use the Services.
  • The Customer's administrators and HR personnel.
  • External job candidates, where the Customer uses the hiring screening features.

B. Categories of personal data

CategoryDetail
Identity and contactName, work email address, profile photo (optional)
EmploymentJob title, position, department, reporting line, account status
CapabilityAssessment answers and scores, capability levels, the evidence behind each level, capability index, talent signal
DevelopmentPlans, sessions, completion, learning activity, written reflections
AI interactionMentor conversation text, memory notes derived from it, interview practice answers and scores
Feedback and performancePeer feedback, goals, performance reviews, where the Customer uses those features
CommunityPosts a worker writes in the Customer's private community space, and reports they make about another post. Not available to the Customer — see clause 4.5
UsageSign-in events, engagement, streaks, experience points
TechnicalDevice and browser information, and a one-way fingerprint of the network address used for abuse prevention
Candidate dataFor external candidates: name, email, interview transcript, generated score and report
Workplace documentsThe text of documents the Customer publishes in the Services to answer its workers' questions, and the questions its workers choose to send to the Customer's administrators

Special category data. The Services are not intended to process special category data on the Customer's behalf, and the Customer must not instruct or configure them to. Wellbeing conversations, which may touch health, occur only in an individual's personal account under Montrus's own controllership, are excluded by design from every Customer-facing surface, and are outside the scope of this DPA.

C. Frequency

Continuous, for the duration of the agreement.

D. Retention

For the duration of the agreement and then as set out in section 12. Montrus does not currently apply automatic time-based deletion within the term; data is retained until the Customer or the individual deletes it. Correspondence with Montrus support is Montrus's own record, kept for the periods published in the Montrus Privacy Policy.


Annex II — Technical and organisational measures

These are the measures actually in place. Montrus does not claim a certification it does not hold.

Encryption. All data in transit is encrypted with TLS. All data at rest in the production database is encrypted by the database provider.

Access control. Access is governed by a role-based permission model enforced on the server on every request, not merely hidden in the interface. Permissions are checked by named capability against a central registry rather than by scattered role comparisons. Organisation scoping is enforced in the database query itself, so one Customer's data cannot be returned to another.

Least privilege. Managers see only their own reporting line. Administrative and platform roles are scoped to what each role requires, and the most sensitive operations are restricted to a single founder-level account.

Audit logging. Access to sensitive information — succession, talent review, compensation, linked passports, hiring, integrity records — is recorded with the actor, the subject, the resource and the time. Administrative changes at platform level are recorded with enough detail to be reversed.

Authentication. Sign-in, password storage and session management are delegated to a specialist provider (Clerk). Montrus never receives or stores passwords. Support impersonation is restricted to demonstration accounts, is time-boxed, is recorded, and displays a persistent banner to the person using it.

Segregation. Personal and workplace identities are architecturally separate. Personal conversations, wellbeing sessions and private career exploration are excluded from Customer-facing surfaces by construction rather than by filtering.

Input validation. All API request bodies are schema-validated. Identity is always taken from the authenticated session and never from a request body.

Abuse and cost control. Per-user daily AI budgets, per-user and per-visitor rate limits, and seat caps.

AI output control. AI-generated assessment questions, narratives and hiring reports are checked by a second model before display. Output that fails verification is regenerated or withheld rather than shown. Every AI prompt carries anti-fabrication and plain-language rules, enforced by an automated test that fails the build if a rule is removed.

Secure development. Type-checked codebase, an automated test suite of over 1,100 tests run before every deployment, no secrets in source control, and reversible database migrations.

Backups. Continuous backup and point-in-time recovery provided by the database platform.

Sub-processor management. As set out in section 7.

Known gaps, stated honestly. Montrus does not currently hold SOC 2 Type II or ISO 27001 certification, does not offer a choice of processing region, and does not apply automatic time-based deletion within the term of an agreement. A Customer for whom any of these is a requirement should raise it before contracting.


Annex III — Subprocessors

SubprocessorPurposeLocation
Vercel Inc.Application hosting and deliveryUnited States
Neon Inc.Managed databaseUnited States
Clerk Inc.Authentication, session management, password storageUnited States
Anthropic PBCPrimary AI model provider — Mentor, assessment generation, verificationUnited States
OpenAI, L.L.C.Fallback AI provider; text embeddings for duplicate detectionUnited States
ElevenLabs Inc.Text-to-speech for the Mentor's voiceUnited States
HeyGen / LiveAvatarReal-time avatar video for live Mentor sessionsUnited States
Resend Inc.Transactional email deliveryUnited States
Stripe, Inc.Payment processing for individual subscriptionsUnited States
jsDelivr and Google Cloud StorageDeliver the on-device face-reading library and model, only where an individual has opted in to engagement sensing. No personal data is transmitted to them.Global CDN / United States

Anthropic and OpenAI process data under their commercial API terms, which provide that customer content is not used to train their models and is retained only briefly for abuse monitoring.

HeyGen / LiveAvatar receives only the audio of the Mentor speaking. It does not receive the individual's camera or microphone.

The current list is maintained at montrus.ai/legal/subprocessors. Customers may subscribe to change notifications by writing to muhammad-abdou@outlook.com.


Signature

This DPA is accepted by the Customer on entering into the main agreement, or may be signed:

Customer Name: ______________________ Title: ______________________ Signature: __________________ Date: ______________________

Montrus Technologies LLC Name: ______________________ Title: ______________________ Signature: __________________ Date: ______________________


Questions: muhammad-abdou@outlook.com Montrus Technologies LLC · 30 N Gould St, STE R, Sheridan, WY 82801, United States

Data Processing Agreement · Version 1.5 · 19 September 2026

Every change we publish is listed on the legal index. We do not change these documents quietly.