This DPA forms part of the agreement between you (“Controller”) and NeuroBazar Inc. (“Processor”) for the Midcore Service.
This Data Processing Agreement (“DPA”) is entered into between the entity agreeing to these terms (“Controller” or “Customer”) and NeuroBazar Inc., a Delaware corporation (“Processor” or “NeuroBazar”), and supplements the Midcore Terms of Service (“Agreement”). This DPA governs the processing of personal data by NeuroBazar on behalf of the Controller in connection with the Midcore Service.
For the purposes of this DPA:
This DPA applies to the processing of personal data by NeuroBazar in the course of providing the Midcore Service to the Customer. The scope of processing includes:
| Subject Matter | Provision of AI-powered software development tools |
| Duration | For the term of the Agreement, plus the period needed to delete or return personal data |
| Nature & Purpose | AI code completion, chat, agent execution, codebase indexing, analytics |
| Data Categories | Account data (name, email), usage data, code snippets, project metadata, IP addresses |
| Data Subjects | Customer employees, contractors, and authorized end users of the Service |
NeuroBazar shall:
NeuroBazar will assist the Controller in fulfilling its obligations to respond to data subject requests under Data Protection Laws, including requests for access, rectification, erasure, restriction, portability, and objection.
If NeuroBazar receives a request directly from a data subject, NeuroBazar will promptly notify the Controller (unless prohibited by law) and will not respond to the request directly unless authorized to do so by the Controller or required by applicable law.
NeuroBazar will implement technical measures to enable the Controller to fulfill data subject requests, including data export functionality, account deletion capabilities, and processing restriction mechanisms.
The Controller provides general authorization for NeuroBazar to engage sub-processors. NeuroBazar will notify the Controller of any intended changes to sub-processors at least 30 days in advance, giving the Controller the opportunity to object.
NeuroBazar imposes data protection obligations on each sub-processor no less protective than those in this DPA. NeuroBazar remains fully liable for the acts and omissions of its sub-processors.
| Sub-Processor | Purpose | Location |
|---|---|---|
| Amazon Web Services (AWS) | Cloud infrastructure, data storage, compute | United States / EU |
| Google Cloud Platform (GCP) | Cloud infrastructure, AI model hosting | United States / EU |
| Anthropic | AI model inference (Claude) | United States |
| OpenAI | AI model inference (GPT) | United States |
| Google DeepMind | AI model inference (Gemini) | United States / EU |
| Stripe | Payment processing | United States |
| Resend | Transactional email delivery | United States |
| PostHog (self-hosted) | Product analytics (anonymized) | Customer-controlled |
To the extent that processing involves the transfer of personal data outside the European Economic Area (EEA), United Kingdom, or Switzerland to a country not recognized as providing an adequate level of data protection, NeuroBazar will ensure appropriate safeguards are in place:
For US-based processing, NeuroBazar relies on the EU-US Data Privacy Framework where applicable, supplemented by SCCs as a fallback mechanism.
NeuroBazar implements and maintains the following technical and organizational measures:
AES-256 at rest, TLS 1.3 in transit, per-session key derivation
RBAC with least privilege, MFA enforced, quarterly access reviews
VPC isolation, WAF, DDoS protection, intrusion detection
Process only data necessary for the Service; obfuscation in Privacy Mode
Documented IR plan, 24/7 on-call, post-incident review process
Multi-region redundancy, automated backups, tested disaster recovery
Background checks, annual security training, confidentiality agreements
Security assessments for all sub-processors, contractual safeguards
For a comprehensive overview of our security practices, see our Security page.
In the event of a personal data breach, NeuroBazar will:
Notifications will include: nature of the breach, categories and approximate number of data subjects affected, likely consequences, measures taken or proposed to address the breach, and contact point for further information.
NeuroBazar will make available to the Controller all information necessary to demonstrate compliance with this DPA. The Controller (or its appointed auditor) may conduct audits, subject to the following conditions:
This DPA takes effect when the Controller agrees to the Midcore Terms of Service and remains in effect for the duration of the Agreement.
Upon termination of the Agreement, NeuroBazar will, at the Controller's choice:
NeuroBazar may retain personal data to the extent required by applicable law, provided that NeuroBazar ensures the confidentiality of such data and processes it only for the purpose required by law.
Each party's liability under this DPA is subject to the limitations of liability set forth in the Agreement, except that:
For questions about this DPA or to exercise any rights hereunder, contact:
To request a signed copy of this DPA or the Standard Contractual Clauses, email legal@midcore.dev.
See also: Privacy Policy · Terms of Service · Security