Skip to main content
Last updated: July 24, 2026 This Data Processing Agreement is a draft framework for B2B customers. It should be reviewed and finalised with counsel before being used as a signed contract.

Parties and Roles

For tenant-scoped MemoryOS usage, the customer is usually the controller or business for customer-submitted personal data, and MemoryOS is usually the processor or service provider. The exact role may depend on the product flow, Memory Passport use, contract, and applicable law.

Subject Matter

MemoryOS processes data to provide AI memory storage, extraction, retrieval, provenance, conflict handling, Memory Passport controls, dashboards, SDKs, and operational support.

Categories of Data

Data may include end-user identifiers chosen by the customer, conversation or event content, structured memories, source metadata, service writer metadata, event references, evidence references, Memory Passport grants, corrections, revocations, connections, operational logs, request IDs, usage, and error data.

Instructions

MemoryOS processes customer data according to the customer agreement, API instructions, dashboard actions, documented product behavior, and applicable law.

Confidentiality

MemoryOS personnel and contractors with access to customer data should be bound by confidentiality obligations appropriate to their role.

Security Measures

MemoryOS maintains technical and organisational measures designed to protect customer data, including authentication, access controls, encrypted transport, auditability, secret handling, and operational monitoring.

Subprocessors

MemoryOS may use subprocessors for hosting, databases, queues, authentication, email, observability, LLM processing, embeddings, billing, and support. Customers may request current subprocessor information at support@memoryo.dev.

Data Subject Requests

MemoryOS will provide reasonable assistance for access, correction, deletion, restriction, portability, and objection requests where required and technically feasible.

Deletion and Return

On termination or verified deletion request, MemoryOS will delete or return customer data according to the agreement, product capabilities, and legal retention requirements.

Security Incidents

MemoryOS will notify affected customers of confirmed security incidents involving customer data as required by law or written agreement.

International Transfers

Where cross-border transfer rules apply, the parties should use appropriate safeguards in their written agreement.

Audits

Enterprise customers may request security and processing information reasonably needed to assess MemoryOS controls, subject to confidentiality and operational limits.

Reference

European Commission controller and processor guidance: https://commission.europa.eu/law/law-topic/data-protection/rules-business-and-organisations/obligations/controllerprocessor/what-data-controller-or-data-processor_en