Legal
Data Processing Addendum
Written for the person in your organization who has to sign something before you can use us.
Draft — awaiting legal review
This document has not yet been reviewed by counsel and should not be relied upon. It is published so the structure can be checked, not as a binding agreement.
Last updated: 4 August 2026
This addendum describes how Codas Labs, LLC processes personal data on your behalf when you use MeshTale. Where you are subject to the UK or EU General Data Protection Regulation, you are the controller and we are the processor.
1. What we process, and why
We process the content you connect or upload, and the account information of the people you invite, for one purpose only: providing the service to you. We do not use your content to train models, and we do not sell it.
- Categories of data subject: your staff, and any individual referenced in content you choose to bring in
- Categories of data: names, email addresses, and whatever appears inside the content you connect
- Duration: for as long as your account is active, plus the deletion window in section 6
2. Your instructions
We process personal data only on your documented instructions, of which your use of the service is the primary one. If we believe an instruction breaches data protection law, we will tell you.
3. Confidentiality
Anyone with access to your data is bound by confidentiality obligations. Access is limited to those who need it to run or support the service.
4. Security
The technical measures in place today are described plainly on our security page, including a section stating what we do not yet claim. We would rather you read that than a list of adjectives here.
Open: a formal description of organizational measures, and any independent assessment, are not yet in place. We hold no compliance certification and will not imply otherwise.
5. Subprocessors
Our current subprocessors are listed on the subprocessors page, along with what each one does.
We will give you at least thirty (30) days’ notice before adding or replacing a subprocessor. During that period you may object on reasonable data protection grounds. If we cannot resolve your objection, you may terminate the affected part of the service without penalty for the remainder of your term.
Each subprocessor is bound by written terms imposing data protection obligations no less protective than those in this addendum. We remain responsible to you for their performance.
6. Deletion and return
On termination you may export your data. After the export window we delete it from active systems, and backups age out on their normal cycle.
Open: we are not putting a number of hours on deletion in this document until the automated enforcement behind it is running. Stating a timeline we cannot yet meet would be worse than stating none.
7. Assisting you
We will help you respond to requests from individuals exercising their rights, and with impact assessments and consultations, to the extent the information sits with us.
8. Incidents
If we become aware of a breach affecting your personal data, we will notify you without undue delay and share what we know, what we are doing, and what we recommend.
9. International transfers
Codas Labs, LLC is established in North Carolina, United States. Where you are in the United Kingdom or the European Economic Area, using MeshTale involves transferring personal data to the United States and to the countries in which our subprocessors operate.
9.1 Transfer mechanism
For transfers from the EEA, the European Commission’s Standard Contractual Clauses (Decision 2021/914) are incorporated into this addendum by reference, using Module Two where you are a controller and we are your processor, and Module Three where you are yourself a processor acting for your own customer. Where the clauses offer options, the following apply:
- Clause 7 (docking): included, so further parties may join
- Clause 9 (subprocessors): Option 2, general written authorization, with the thirty-day notice period set out in section 5
- Clause 11 (redress): the optional independent dispute resolution body is not selected
- Clause 17 (governing law) and Clause 18 (forum): Ireland
- Annexes: Annex I is populated by section 1 of this addendum and the subprocessors page; Annex II by our security page
For transfers from the United Kingdom, the UK International Data Transfer Addendum to those clauses (version B1.0, issued under section 119A of the Data Protection Act 2018) applies, with the clauses above as the approved transfer mechanism. For transfers from Switzerland, references to EU law are read as references to the Swiss Federal Act on Data Protection, and the Swiss Federal Data Protection and Information Commissioner is the competent authority.
9.2 Transfer risk
We will assist you with any transfer impact assessment you are required to carry out, and will tell you if we receive a government or law enforcement request for your data, unless we are legally prohibited from doing so. Where prohibited, we will challenge the prohibition where there is a reasonable basis to do so.
9.3 Processing locations
Open: the specific processing region for each subprocessor is being confirmed and will be published as a column on the subprocessors page. Until it is, treat processing as taking place in the United States and in the regions those providers operate globally.
9.4 Local representation
Open: where required under Article 27 of the UK and EU GDPR, a representative in each of those territories will be appointed and named here. This has not yet been put in place.
10. Audit
We will make available the information reasonably needed to demonstrate compliance with this addendum, and will respond to reasonable questions in writing.
Signing this
If you need a countersigned copy, contact us. While the draft banner is on this page it is a structure for review, not an executed agreement.