Data Processing Addendum

Mocono Technologies Ltd | Version 3.0 | Effective 18 May 2026

This Data Processing Addendum ("DPA") forms part of, and is incorporated into, the Mocono Publisher Terms and Conditions of Service (the "Agreement") between Mocono Technologies Ltd ("Mocono", "Processor") and the publisher identified in the Order (the "Publisher", "Controller"). It records the parties' obligations under Article 28 of the UK GDPR in respect of Personal Data processed by Mocono on the Publisher's behalf. Capitalised terms not defined here have the meanings given in the Agreement.

1. Definitions

1.1 In this DPA:

  • "Data Protection Laws" the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003 and, where applicable to the processing, Regulation (EU) 2016/679, each as amended or replaced.
  • "Personal Data" personal data, as defined in Data Protection Laws, which Mocono processes on behalf of the Publisher under the Agreement, as further described in Annex 1.
  • "Restricted Transfer" a transfer of Personal Data to a country or territory outside the United Kingdom which is not the subject of UK adequacy regulations.
  • "Sub-Processor" any third party engaged by Mocono to process Personal Data on the Publisher's behalf.
  • "Transfer Mechanism" the International Data Transfer Agreement, the UK Addendum to the EU Standard Contractual Clauses, or any other mechanism permitted under Data Protection Laws for a Restricted Transfer.

1.2 The terms "controller", "processor", "data subject", "processing", "personal data breach" and "supervisory authority" have the meanings given in the UK GDPR.

2. Roles and Scope

2.1 Roles: The Publisher is the controller and Mocono is the processor in respect of the Personal Data described in Annex 1. Each party shall comply with its own obligations under Data Protection Laws.

2.2 Independent Controller Data: This DPA does not apply to data in respect of which Mocono acts as an independent controller, including Account contact data, billing data, support correspondence and Usage Data. Mocono processes that data in accordance with its own privacy policy.

2.3 Not a Joint Controllership: Nothing in this DPA is intended to create, and the parties do not intend to create, a joint controllership under Article 26 of the UK GDPR.

2.4 Duration: This DPA applies from the Start Date and continues for so long as Mocono processes Personal Data on the Publisher's behalf.

3. Publisher's Obligations and Warranties

3.1 Lawfulness: The Publisher warrants that it has, and will maintain throughout the Term, a valid lawful basis under Article 6 of the UK GDPR (and, where relevant, a condition under Article 9) for all processing carried out by Mocono on its behalf, and that it has provided all privacy information required by Articles 13 and 14 to the relevant data subjects.

3.2 Consents: Where consent is required, including under PECR in respect of cookies, similar technologies or electronic marketing, the Publisher is responsible for obtaining, recording and maintaining evidence of that consent, and for honouring its withdrawal.

3.3 Lawful Instructions: The Publisher warrants that its instructions to Mocono, including its configuration of the Platform, will not cause Mocono to breach Data Protection Laws, and that it is entitled to transfer the Personal Data to Mocono for processing.

3.4 Accuracy and Minimisation: The Publisher is responsible for the accuracy, quality, legality and relevance of the Personal Data it uploads, imports or generates in the Platform, and for ensuring that no more Personal Data is provided to Mocono than is necessary.

3.5 Storage Limitation: The Publisher determines the retention period for Personal Data in its Account. The Publisher acknowledges that the fee structure under clause 5 of the Agreement is calculated by reference to database capacity, that this does not relieve it of its obligations under the storage limitation principle, and that the decision to retain or delete inactive records is the Publisher's alone as controller. Mocono is under no obligation to identify, flag or delete Personal Data which the Publisher no longer requires.

3.6 Special Category Data: The Publisher shall not upload special category personal data or criminal offence data to the Platform without Mocono's prior written agreement and the completion of any additional measures Mocono reasonably requires.

3.7 Indemnity: The Publisher shall indemnify Mocono on demand against all claims, fines, penalties, losses, costs and expenses arising from any breach of this clause 3, from any unlawful instruction, or from the Publisher's own breach of Data Protection Laws.

4. Mocono's Processing Obligations

4.1 Documented Instructions: Mocono shall process Personal Data only on the Publisher's documented instructions, including in relation to Restricted Transfers, unless required to do otherwise by law, in which case Mocono shall inform the Publisher of that requirement before processing unless the law prohibits it. The Agreement, this DPA, the Publisher's configuration of the Platform and the Publisher's use of the Platform's functionality together constitute the Publisher's complete documented instructions.

4.2 Instructions Outside Scope: If Mocono considers that an instruction infringes Data Protection Laws, it shall inform the Publisher. Mocono may suspend performance of the affected instruction until it is withdrawn, amended or confirmed. Any instruction which falls outside the scope of the Services as described in the Agreement, or which requires Mocono to change how the Platform operates, may be declined or may be carried out subject to a separate written agreement on scope and charges.

4.3 Confidentiality: Mocono shall ensure that persons authorised to process the Personal Data are subject to an appropriate duty of confidentiality, whether contractual or statutory, and receive appropriate data protection training.

4.4 Security: Mocono shall implement and maintain the technical and organisational measures set out in Annex 2, being measures appropriate to the risk in accordance with Article 32 of the UK GDPR. Mocono may update those measures from time to time provided the overall level of security is not materially reduced.

4.5 Accountability: Mocono shall maintain records of its processing activities as required by Article 30(2) and shall make available to the Publisher, on reasonable request, the information necessary to demonstrate compliance with Article 28, subject to clause 8.

5. Sub-Processors

5.1 General Authorisation: The Publisher grants Mocono general written authorisation to appoint Sub-Processors. The Sub-Processors engaged at the date of this DPA are listed in Annex 3, and a current list is maintained on the Platform.

5.2 Changes: Mocono shall give the Publisher not less than fourteen (14) days' notice, by email or via the Platform, of any intended addition or replacement of a Sub-Processor. It is the Publisher's responsibility to ensure it receives such notices at a monitored address.

5.3 Objection: The Publisher may object to a change on reasonable and substantiated data protection grounds by written notice within ten (10) days of the notice. The parties shall discuss the objection in good faith. If no resolution is reached within thirty (30) days, either party may terminate the affected Services on notice under clause 6 of the Agreement. Failure to object within the period constitutes approval.

5.4 Flow-Down and Liability: Mocono shall impose on each Sub-Processor data protection obligations which are, in substance, no less protective than those in this DPA, and remains liable to the Publisher for the performance of each Sub-Processor's obligations, subject always to clause 11.

6. International Transfers

6.1 Hosting Location: The Platform and its primary data stores are hosted in the United Kingdom, as described in Annex 1.

6.2 Restricted Transfers: Where Mocono makes a Restricted Transfer, it shall put in place an appropriate Transfer Mechanism, and shall carry out and document a transfer risk assessment where required. The Publisher instructs Mocono to make such transfers and, where the relevant Transfer Mechanism requires the controller to be a party, authorises Mocono to enter into it as agent for and on behalf of the Publisher.

6.3 Details: Mocono shall provide details of the Transfer Mechanism applicable to any particular Sub-Processor on reasonable written request.

7. Data Subject Requests

7.1 Self-Service: The Platform provides functionality enabling the Publisher to access, correct, export, restrict and delete Personal Data in its Account. The parties agree that this functionality constitutes the primary means by which Mocono assists the Publisher with data subject requests.

7.2 Requests Received by Mocono: If Mocono receives a request from a data subject relating to Personal Data processed on the Publisher's behalf, it shall not respond to the substance of the request except to acknowledge it and direct the data subject to the Publisher, and shall notify the Publisher without undue delay, save where responding is required by law.

7.3 Additional Assistance: Mocono shall provide reasonable further assistance, taking into account the nature of the processing and the information available to it. Where such assistance goes beyond the functionality described in clause 7.1, and is not required to be provided free of charge under Data Protection Laws, it is chargeable at Mocono's then-current day rates.

8. Audit and Information

8.1 Documentation First: Mocono shall make available to the Publisher, on request, its most recent security documentation, including any third party certification, penetration test summary and completed security questionnaire. The parties agree that the Publisher's audit rights under Article 28(3)(h) shall in the first instance be satisfied by the provision of that documentation.

8.2 On-Site Audit: Where that documentation does not reasonably satisfy the Publisher's obligations, the Publisher may audit Mocono's compliance with this DPA, subject to the following: the audit may take place no more than once in any twelve (12) month period (save where required by a supervisory authority or following a personal data breach affecting the Publisher's Personal Data); it requires not less than thirty (30) days' prior written notice; it must take place during business hours and with minimum disruption; the auditor must not be a competitor of Mocono and must sign a confidentiality undertaking; and the Publisher shall bear its own and Mocono's reasonable costs.

8.3 Limits: No audit shall extend to Personal Data of, or information relating to, Mocono's other customers, to Mocono's source code, or to any information which is legally privileged or subject to a confidentiality obligation owed to a third party.

9. Personal Data Breach

9.1 Notification: Mocono shall notify the Publisher without undue delay after becoming aware of a personal data breach affecting the Personal Data, and shall provide, to the extent known and as it becomes available, a description of the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed.

9.2 Cooperation: Mocono shall take reasonable steps to contain and remediate the breach and shall provide reasonable assistance to the Publisher in meeting its obligations under Articles 33 and 34. Assistance beyond the provision of information within Mocono's control is chargeable at Mocono's then-current day rates, save where the breach was caused by Mocono's own breach of this DPA.

9.3 Notifications and Statements: The Publisher is responsible for determining whether a breach requires notification to a supervisory authority or to data subjects, and for making that notification. The Publisher shall not name Mocono in any public statement or regulatory notification without Mocono's prior written approval, such approval not to be unreasonably withheld or delayed where the disclosure is required by law.

9.4 No Admission: Mocono's notification of, or response to, a personal data breach is not an acknowledgement of fault or liability.

10. Return and Deletion

10.1 Export at Any Time: The Publisher may at any time during the Term export the whole of the Personal Data held in its Account in CSV format, without charge and without Mocono's approval, in accordance with clause 6.7 of the Agreement. That right is not conditional on the Account being in good standing and is not withdrawn on suspension or notice of termination.

10.2 On Termination: The Publisher elects, by continuing to use the Services, that Mocono shall delete the Personal Data on termination. Mocono shall keep the export function available for thirty (30) days following the effective date of termination, after which it may delete the Personal Data from its live systems. If the Publisher requires return in another format, it must request this in writing before termination takes effect, and such return is chargeable at Mocono's then-current day rates.

10.3 Backups and Retained Copies: Personal Data deleted from live systems may persist in encrypted backups until overwritten in the ordinary course of Mocono's backup cycle, during which time it remains subject to this DPA and is not actively processed. Mocono may retain Personal Data to the extent required by law, and may retain aggregated and anonymised data indefinitely.

10.4 Confirmation: Mocono shall confirm deletion in writing on request.

11. Liability

11.1 Cap: The liability of each party arising out of or in connection with this DPA is subject to the exclusions and limitations set out in clause 12 of the Agreement. For the avoidance of doubt, the liability caps in clause 12 of the Agreement apply in aggregate across the Agreement and this DPA taken together, and not to each separately.

11.2 Article 82: Nothing in this DPA limits any liability which cannot be limited under Data Protection Laws, including a data subject's rights under Article 82 of the UK GDPR.

11.3 Contribution: Where one party has paid compensation for damage for which both parties are responsible, it may claim back from the other that part of the compensation corresponding to the other's share of responsibility.

12. General

12.1 Precedence: In the event of conflict between this DPA and the Agreement, this DPA prevails in respect of the processing of Personal Data only. In the event of conflict between this DPA and a Transfer Mechanism, the Transfer Mechanism prevails.

12.2 Variation: Mocono may amend this DPA where necessary to reflect a change in Data Protection Laws, guidance from a supervisory authority, a decision of a competent court, or a change to its Sub-Processors or security measures, on notice to the Publisher. Any other amendment requires the written agreement of both parties.

12.3 Severability and Survival: If any provision is held invalid, the remainder continues in full force. Clauses 3.7, 8, 9.3, 10, 11 and 12 survive termination.

Annex 1 — Details of the Processing

ItemDetail
ControllerThe Publisher identified in the Order
ProcessorMocono Technologies Ltd
Subject matterProvision of hosted paywalling and subscriber management services
DurationThe Term, plus the thirty (30) day export window under clause 10.2, plus any backup retention period under clause 10.3
Nature of the processingCollection, recording, organisation, structuring, storage, retrieval, consultation, use, transmission, alignment, restriction, erasure and destruction, by automated means
Purpose of the processingSubscriber registration and authentication; paywall and entitlement checks; subscription, membership and order management; billing and transaction records; transactional and marketing email delivery as instructed by the Publisher; reporting and analytics within the Account; customer support
Categories of data subjectsThe Publisher's subscribers, registrants, trialists, lapsed and former subscribers, prospective subscribers, and the Publisher's own personnel who hold Account logins
Types of Personal DataName; business and personal contact details including email address, telephone number and postal address; job title and employer; login credentials and authentication tokens; subscription, entitlement, order and renewal data; transaction and payment metadata (Mocono does not store full payment card numbers); marketing preferences and consent records; content consumption and engagement data; IP address, device and browser data; correspondence and support history
Special category dataNone, unless expressly agreed in writing under clause 3.6
Hosting locationUnited Kingdom — Microsoft Azure, UK South region
Frequency of transferContinuous, for the duration of the Term

Annex 2 — Technical and Organisational Measures

Mocono maintains the following measures, which it may update provided the overall level of security is not materially reduced.

A2.1 Encryption: Personal Data is encrypted in transit using TLS 1.2 or above, and encrypted at rest at the storage layer.

A2.2 Access control: Access to production systems is restricted on a least-privilege, role-based basis to named personnel who require it. Administrative access requires multi-factor authentication. Access is reviewed periodically and revoked promptly on change of role or departure.

A2.3 Tenant separation: Publisher Accounts are logically separated so that one Publisher cannot access another Publisher's data.

A2.4 Network security: Firewalling, network segregation, restricted administrative endpoints, and protection against common web application attacks.

A2.5 Logging and monitoring: Systems and access are logged and monitored, with alerting for anomalous activity. Logs are retained for a period appropriate to investigation and are protected against alteration.

A2.6 Resilience and backup: Regular encrypted backups, with restoration procedures tested periodically. Backups are held within the United Kingdom.

A2.7 Change management: Changes to production systems follow a documented process including review and the ability to roll back. Development and test environments do not use live Personal Data other than where necessary and appropriately protected.

A2.8 Vulnerability management: Dependencies and infrastructure are patched on a risk-prioritised basis. Vulnerability scanning is carried out periodically.

A2.9 Personnel: Personnel are subject to written confidentiality obligations, receive data protection and security awareness training, and are subject to pre-engagement checks appropriate to their role.

A2.10 Supplier management: Sub-Processors are subject to due diligence before engagement and to written data protection terms.

A2.11 Incident response: A documented personal data breach response procedure, including triage, containment, assessment and notification.

A2.12 Deletion: Documented procedures for the deletion of Personal Data on termination and for secure disposal of media.

Annex 3 — Approved Sub-Processors

Sub-ProcessorPurposeLocationTransfer mechanism
Microsoft AzureCloud hosting and storageUnited KingdomN/A — UK
StripePayment processingUnited States / IrelandUK Addendum to the EU Standard Contractual Clauses
PostmarkTransactional and bulk emailUnited StatesUK Addendum to the EU Standard Contractual Clauses
Help ScoutCustomer supportUnited StatesUK Addendum to the EU Standard Contractual Clauses
SentryApplication monitoringUnited StatesUK Addendum to the EU Standard Contractual Clauses
Veeam / Azure BackupBackup and disaster recoveryUnited KingdomN/A — UK

A current list of Sub-Processors is maintained on the Platform and may be updated in accordance with clause 5.

This DPA is entered into and becomes binding on acceptance of the Agreement.