DPA

Data Processing Addendum

The baseline processing terms Memrov uses for business customers and partners that process personal data through Memrov.

Last updated May 25, 2026

Plain-English summary
  • For consumer accounts, the Privacy Policy controls the direct user relationship.
  • For business customers, a signed agreement or order form may incorporate this DPA.
  • The DPA describes roles, instructions, security, subprocessors, deletion, assistance, and incident notice.
Roles

Where a business customer determines the purpose and means of processing personal data through Memrov, that customer is the controller or business and Memrov acts as processor or service provider. Where Memrov operates direct consumer accounts, Memrov may act as controller for those account operations.

Processing instructions
  • Memrov processes personal data to provide the contracted services, follow product settings, comply with documented instructions, secure the service, and meet legal obligations.
  • Business customers are responsible for having a lawful basis, notices, consents, and rights workflows for data they send to Memrov.
Security

Memrov maintains administrative, technical, and organizational measures designed to protect personal data, including access controls, managed cloud infrastructure, encryption where available, audit logging, scoped credentials, and deletion workflows.

Subprocessors
  • Memrov may use subprocessors listed on the Subprocessor List to provide the service.
  • Memrov remains responsible for subprocessor performance under the applicable agreement.
  • Business customers may receive notice and objection rights as described in their signed agreement.
Assistance and rights

Memrov will provide reasonable assistance for data subject requests, security reviews, impact assessments, deletion, export, and incident response where required by the applicable agreement and law.

Return and deletion

At termination or on valid request, Memrov will delete or return personal data according to the product deletion workflow, agreement, and legal retention requirements.

International transfers

If transfer safeguards are required, the parties will use legally recognized transfer mechanisms, such as standard contractual clauses or other approved safeguards, as applicable.

Incident notice

Memrov will notify affected customers of a confirmed personal data breach without undue delay and provide information reasonably available to support investigation and required notices.

Contact
Send legal, privacy, billing, SMS, security, and account requests to Memrov.

Memrov, Inc.

admin@memrov.com

Registered agent

Legalinc Corporate Services Inc.

131 Continental Dr

Suite 305

Newark, DE 19713

United States