Version 1.0 · Last updated: August 13, 2026
This Data Processing Addendum ("DPA") is part of the My Molecule Terms of Service between Molecule Work LLC ("we," "us") and the business accepting them ("you"). It governs the personal information about your clients that you collect, enter, or manage through the platform ("Client Data"). It applies automatically — no separate signature is needed — and its current version is always published at this page.
For Client Data, you are the controller (or "business" under California law) and we act as your processor and service provider: we process Client Data only to provide the platform to you and as this DPA allows. For our own account, billing, and platform-operations data — and for the cross-business consumer profile described in our Privacy Policy — we act in our own capacity.
With respect to Client Data, we will not:
We certify that we understand these restrictions and will comply with them. If we determine we can no longer meet our obligations under applicable privacy law, we will notify you, and you may take reasonable steps to stop and remediate unauthorized use of Client Data.
We limit access to Client Data to personnel and systems that need it to operate the platform, and we protect it with the measures described in the Privacy Policy's security section, including encryption in transit, encryption at rest with managed keys, per-business data isolation, role-based access controls, and a tamper-evident audit log of sensitive administrative actions.
You authorize us to use the subprocessors listed at mymolecule.ai/subprocessors to provide the platform. Each subprocessor is bound by written terms no less protective of Client Data than this DPA. When we add or replace a subprocessor, we will update that page and notify you (by email or in the product) before the new subprocessor processes Client Data; if you object on reasonable data-protection grounds and we cannot offer an alternative, you may terminate the affected services.
The platform includes a privacy-request system supporting access, deletion, correction, portability, opt-out, and limit-use requests from your clients, with identity verification and status tracking. When your client makes a request to you, you can open and fulfill it there; deletion requests scrub the client's identifying details from the affected records while preserving the non-identifying transaction history your business records may require. We provide reasonable further assistance where the platform tooling does not cover a request.
If we determine that a security breach has affected Client Data, we will notify you without undue delay, give you the information we have about what happened and what data was involved, and cooperate with your notification obligations under the breach laws that apply to you.
If you close your account, we will, at your written request, delete Client Data by scrubbing identifying details and deactivating the records, except where retention is required for legal, audit, or financial-record purposes (in which case the data remains protected by this DPA until deleted). On request, we will provide an export of your business records.
We will respond in writing to your reasonable questions about our processing of Client Data, including the security measures above — enough for you to meet your own obligations to assess your processors. Contact [email protected].
We may update this DPA as the platform and the law evolve; the version and date above change when we do, and material changes are notified the same way as changes to the Terms. Because this DPA is part of the Terms, your recorded acceptance of the Terms (shown in your account's legal settings) covers the DPA version those Terms incorporate.