Skip to main content
Last updated March 1, 2026

Data Processing Agreement

This DPA forms part of the agreement between you (“Controller”) and NeuroBazar Inc. (“Processor”) for the Midcore Service.

This Data Processing Agreement (“DPA”) is entered into between the entity agreeing to these terms (“Controller” or “Customer”) and NeuroBazar Inc., a Delaware corporation (“Processor” or “NeuroBazar”), and supplements the Midcore Terms of Service (“Agreement”). This DPA governs the processing of personal data by NeuroBazar on behalf of the Controller in connection with the Midcore Service.

1Definitions

For the purposes of this DPA:

Personal Data
Any information relating to an identified or identifiable natural person, as defined in Article 4(1) of the GDPR.
Processing
Any operation performed on personal data, including collection, recording, storage, retrieval, use, disclosure, erasure, or destruction.
Controller
The entity that determines the purposes and means of processing personal data — i.e., the Customer.
Processor
The entity that processes personal data on behalf of the Controller — i.e., NeuroBazar Inc.
Sub-Processor
A third party engaged by the Processor to process personal data on behalf of the Controller.
Data Subject
An identified or identifiable natural person whose personal data is processed.
Data Protection Laws
All applicable laws relating to data protection, including the GDPR (EU), UK GDPR, CCPA (California), and any successor legislation.
Standard Contractual Clauses (SCCs)
The contractual clauses adopted by the European Commission for international data transfers, as amended or replaced.

2Scope & Purpose

This DPA applies to the processing of personal data by NeuroBazar in the course of providing the Midcore Service to the Customer. The scope of processing includes:

Subject MatterProvision of AI-powered software development tools
DurationFor the term of the Agreement, plus the period needed to delete or return personal data
Nature & PurposeAI code completion, chat, agent execution, codebase indexing, analytics
Data CategoriesAccount data (name, email), usage data, code snippets, project metadata, IP addresses
Data SubjectsCustomer employees, contractors, and authorized end users of the Service

3Processor Obligations

NeuroBazar shall:

  • Process personal data only on documented instructions from the Controller, unless required by applicable law
  • Ensure that persons authorized to process personal data have committed themselves to confidentiality
  • Implement appropriate technical and organizational security measures as described in Section 7
  • Not engage another processor without prior specific or general written authorization of the Controller
  • Assist the Controller in responding to data subject requests, taking into account the nature of processing
  • Assist the Controller in ensuring compliance with GDPR Articles 32–36 (security, breach notification, DPIAs)
  • At the choice of the Controller, delete or return all personal data upon termination of the Agreement
  • Make available to the Controller all information necessary to demonstrate compliance with this DPA

4Data Subject Rights

NeuroBazar will assist the Controller in fulfilling its obligations to respond to data subject requests under Data Protection Laws, including requests for access, rectification, erasure, restriction, portability, and objection.

If NeuroBazar receives a request directly from a data subject, NeuroBazar will promptly notify the Controller (unless prohibited by law) and will not respond to the request directly unless authorized to do so by the Controller or required by applicable law.

NeuroBazar will implement technical measures to enable the Controller to fulfill data subject requests, including data export functionality, account deletion capabilities, and processing restriction mechanisms.

5Sub-Processors

The Controller provides general authorization for NeuroBazar to engage sub-processors. NeuroBazar will notify the Controller of any intended changes to sub-processors at least 30 days in advance, giving the Controller the opportunity to object.

NeuroBazar imposes data protection obligations on each sub-processor no less protective than those in this DPA. NeuroBazar remains fully liable for the acts and omissions of its sub-processors.

Current Sub-Processors

Sub-ProcessorPurposeLocation
Amazon Web Services (AWS)Cloud infrastructure, data storage, computeUnited States / EU
Google Cloud Platform (GCP)Cloud infrastructure, AI model hostingUnited States / EU
AnthropicAI model inference (Claude)United States
OpenAIAI model inference (GPT)United States
Google DeepMindAI model inference (Gemini)United States / EU
StripePayment processingUnited States
ResendTransactional email deliveryUnited States
PostHog (self-hosted)Product analytics (anonymized)Customer-controlled

6International Data Transfers

To the extent that processing involves the transfer of personal data outside the European Economic Area (EEA), United Kingdom, or Switzerland to a country not recognized as providing an adequate level of data protection, NeuroBazar will ensure appropriate safeguards are in place:

  • Standard Contractual Clauses (SCCs) as adopted by the European Commission (Module Two: Controller to Processor)
  • UK International Data Transfer Addendum where applicable
  • Supplementary measures including encryption in transit and at rest, access controls, and data minimization
  • Data Transfer Impact Assessments conducted for each transfer destination

For US-based processing, NeuroBazar relies on the EU-US Data Privacy Framework where applicable, supplemented by SCCs as a fallback mechanism.

7Security Measures

NeuroBazar implements and maintains the following technical and organizational measures:

Encryption

AES-256 at rest, TLS 1.3 in transit, per-session key derivation

Access Control

RBAC with least privilege, MFA enforced, quarterly access reviews

Network Security

VPC isolation, WAF, DDoS protection, intrusion detection

Data Minimization

Process only data necessary for the Service; obfuscation in Privacy Mode

Incident Response

Documented IR plan, 24/7 on-call, post-incident review process

Business Continuity

Multi-region redundancy, automated backups, tested disaster recovery

Employee Security

Background checks, annual security training, confidentiality agreements

Vendor Management

Security assessments for all sub-processors, contractual safeguards

For a comprehensive overview of our security practices, see our Security page.

8Data Breach Notification

In the event of a personal data breach, NeuroBazar will:

  • Notify the Controller without undue delay and no later than 72 hours after becoming aware of the breach
  • Provide the Controller with sufficient information to meet any obligations to report or inform data subjects
  • Cooperate with the Controller and take reasonable steps to assist in the investigation, mitigation, and remediation of the breach
  • Document the breach including its facts, effects, and remedial actions taken

Breach Notification Contents

Notifications will include: nature of the breach, categories and approximate number of data subjects affected, likely consequences, measures taken or proposed to address the breach, and contact point for further information.

9Audit Rights

NeuroBazar will make available to the Controller all information necessary to demonstrate compliance with this DPA. The Controller (or its appointed auditor) may conduct audits, subject to the following conditions:

  • The Controller provides at least 30 days' written notice of any audit request
  • Audits are conducted during normal business hours and no more than once per calendar year
  • The auditor agrees to reasonable confidentiality obligations
  • The Controller bears the cost of any audit, unless the audit reveals material non-compliance by NeuroBazar
  • NeuroBazar may satisfy audit requests by providing SOC 2 Type II reports, penetration test results, or equivalent third-party certifications

10Term & Termination

This DPA takes effect when the Controller agrees to the Midcore Terms of Service and remains in effect for the duration of the Agreement.

Upon termination of the Agreement, NeuroBazar will, at the Controller's choice:

  • Return all personal data to the Controller in a structured, commonly used, and machine-readable format; or
  • Delete all personal data, including all existing copies, within 30 days of termination

NeuroBazar may retain personal data to the extent required by applicable law, provided that NeuroBazar ensures the confidentiality of such data and processes it only for the purpose required by law.

11Liability

Each party's liability under this DPA is subject to the limitations of liability set forth in the Agreement, except that:

  • Neither party excludes or limits its liability for damages arising from breaches of this DPA to the extent such limitation would be prohibited by Data Protection Laws
  • NeuroBazar shall be liable for damages caused by processing that does not comply with Data Protection Laws or this DPA
  • NeuroBazar shall be exempt from liability if it proves that it is not responsible for the event giving rise to the damage

12Contact

For questions about this DPA or to exercise any rights hereunder, contact:

NeuroBazar Inc.

Data Protection Contact: legal@midcore.dev

Product: Midcore

To request a signed copy of this DPA or the Standard Contractual Clauses, email legal@midcore.dev.

See also: Privacy Policy · Terms of Service · Security