Modalius ← Back to home

Data Processing Agreement

Version 1.1 · Effective date: July 23, 2026 · Replaces version 1.0 (June 1, 2026)

This Data Processing Agreement ("DPA") forms part of, and is subject to, the Terms of Service or other written agreement (the "Agreement") between Modalius, LLC ("Modalius", "we", "us", or "Processor") and the customer that has entered into the Agreement ("Customer", "you", or "Controller") for the use of Modalius Partner Connect (the "Service"). This DPA governs the Processing of Personal Data that Modalius performs on behalf of Customer in connection with the Service. If there is a conflict between this DPA and the Agreement with respect to the Processing of Personal Data, this DPA controls.

1. Definitions

Applicable Data Protection Laws
All laws and regulations applicable to the Processing of Personal Data under the Agreement.
Personal Data
Information relating to an identified or identifiable individual that is contained in Customer Data and Processed by Modalius on Customer's behalf under the Agreement.
Customer Data
Data that Customer (or its users or trading partners) submits to, or that is generated by Customer's use of, the Service.
Processing
Any operation performed on Personal Data, such as collection, storage, use, transmission, or deletion.
Controller / Processor
The party that determines the purposes and means of Processing (Customer), and the party that Processes Personal Data on the Controller's behalf (Modalius), respectively.
Data Subject
The individual to whom Personal Data relates.
Subprocessor
A third party engaged by Modalius to Process Personal Data in connection with the Service.
Personal Data Breach
A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data.

2. Roles and Scope

As between the parties, Customer is the Controller of Personal Data and Modalius is the Processor. Modalius will Process Personal Data only to provide and support the Service and only in accordance with this DPA and Customer's documented instructions. The Agreement, this DPA, and Customer's configuration and use of the Service constitute Customer's documented instructions. The subject matter, duration, nature, and purpose of the Processing, and the types of Personal Data and categories of Data Subjects, are described in Appendix A.

3. Processing Instructions

Modalius will Process Personal Data only on Customer's documented instructions, including with regard to transfers, unless required to do otherwise by applicable law (in which case Modalius will, where permitted, inform Customer of that requirement before Processing). Modalius will not Process Personal Data for its own purposes and will not sell Personal Data. Modalius will promptly inform Customer if, in its opinion, an instruction infringes Applicable Data Protection Laws.

4. Confidentiality

Modalius will ensure that personnel authorized to Process Personal Data are bound by appropriate confidentiality obligations and access Personal Data only on a need-to-know basis to perform their duties.

5. Security

Modalius will implement and maintain appropriate technical and organizational measures designed to protect Personal Data against a Personal Data Breach, taking into account the nature of the Processing and the risks involved. A description of these measures is set out in Appendix B. Customer is responsible for securing its own credentials and for configuring the Service appropriately for its data.

6. Subprocessors

Customer provides general authorization for Modalius to engage Subprocessors to support the Service. A current list of Subprocessors is set out in Appendix C. Modalius will impose data-protection obligations on each Subprocessor that are substantially the same as those in this DPA and remains responsible for each Subprocessor's performance.

Notice of changes. Modalius will give Customer at least 30 days' notice before adding or replacing a Subprocessor, by email to Customer's designated administrative contact and by updating Appendix C. Customer may subscribe to these notices by emailing contact@modalius.com with the subject "Subprocessor Notices". Where an urgent replacement is required to maintain the security or continuity of the Service, Modalius will give notice as soon as reasonably practicable.

Objection. Customer may object to a new Subprocessor on reasonable data-protection grounds by giving written notice within 30 days of Modalius's notice. The parties will work in good faith to resolve the objection, which may include Modalius making the affected functionality available without that Subprocessor. If the objection is not resolved within 30 days, Customer may terminate the affected part of the Service without penalty, and Modalius will refund any prepaid fees covering the terminated portion of the then-current term.

7. Data Subject Requests

Taking into account the nature of the Processing, Modalius will provide reasonable assistance to enable Customer to respond to requests from Data Subjects to exercise their rights under Applicable Data Protection Laws. If Modalius receives such a request directly, it will, where lawful, advise the Data Subject to submit the request to Customer and will not respond on Customer's behalf except on Customer's instructions.

8. Assistance

Taking into account the nature of the Processing and the information available to it, Modalius will provide reasonable assistance to Customer with respect to security, Personal Data Breach notifications, data protection impact assessments, and consultations with supervisory authorities, to the extent these obligations apply to Customer.

9. Personal Data Breach Notification

Modalius will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer's Personal Data and will provide Customer with information reasonably available to it to assist Customer in meeting any obligations to notify supervisory authorities or affected Data Subjects.

10. Return and Deletion of Personal Data

Retention during normal operation. Personal Data is retained for limited periods while the Agreement is in force: soft-deleted records can be restored for 7 days; EDI files are retained for a default of 730 days (configurable per account, subject to Customer's subscription); external connection activity logs are retained for at least 45 days; processing, operational, and product usage logs are retained for up to 90 days; and generated report files are retained for 7 days. Backups are overwritten on a rolling basis in the ordinary course.

On termination. For 30 days after termination or expiry of the Agreement, Customer may request return of Personal Data. Modalius will provide it in a commercially reasonable machine-readable format (file content in its original form, together with associated metadata as structured export), delivered through the application or through a secure transfer method agreed by the parties, at no charge for a single standard export. After that 30-day window, or earlier at Customer's written instruction, Modalius will delete Personal Data and instruct its Subprocessors to do the same, except where retention is required by law, is subject to a legal hold, or is held in backups that are overwritten on the rolling schedule described above. Personal Data held in backups remains subject to the confidentiality and security obligations of this DPA until overwritten.

11. Audits

Modalius will make available to Customer information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by Customer or an auditor mandated by Customer. Audits are subject to at least 30 days' prior written notice, confidentiality obligations, and reasonable limits on scope and duration, must be conducted during normal business hours, must not interfere with Modalius's operations or the security of other customers' data, and are limited to once in any twelve-month period unless required by a supervisory authority or following a Personal Data Breach affecting Customer's Personal Data. Each party bears its own costs, except that Customer bears Modalius's reasonable costs for audits beyond the annual allowance. Modalius may satisfy this obligation by providing relevant third-party reports, certifications, or summaries where available.

12. International Transfers

The Service is hosted on secure cloud infrastructure located in the United States. Where Personal Data is transferred from the European Economic Area, the United Kingdom, or Switzerland to a country that has not received an adequacy decision, the parties agree that the European Commission's Standard Contractual Clauses (Module Two, controller to processor) are incorporated into this DPA by reference and apply to that transfer, with Customer as data exporter and Modalius as data importer, and with the UK International Data Transfer Addendum applying to transfers subject to UK law. The information required to complete the annexes to those clauses is set out in Appendices A, B, and C. Where the Standard Contractual Clauses conflict with this DPA, the Standard Contractual Clauses control for the transfer they govern.

13. United States State Privacy Laws

Where Customer is a "business" and Modalius is a "service provider" (or the equivalent terms) under the California Consumer Privacy Act as amended by the California Privacy Rights Act, or under comparable state privacy laws, Modalius certifies that it understands and will comply with the following restrictions with respect to Personal Data it Processes on Customer's behalf:

Aggregated or de-identified information derived from the operation of the Service, as described in the Agreement, is not Personal Data for the purposes of this section, and Modalius will not attempt to re-identify it.

14. Liability and Governing Law

Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Agreement. This DPA is governed by the laws of the State of Georgia, without regard to its conflict-of-law rules, consistent with the Agreement.

15. Term

This DPA takes effect on the effective date above and remains in effect for as long as Modalius Processes Personal Data on Customer's behalf under the Agreement. Provisions that by their nature should survive termination will survive.

Appendix A: Details of Processing

Subject matter and duration

The provision of the Modalius Partner Connect Service to Customer for the duration of the Agreement.

Frequency of Processing

Continuous, for the duration of the Agreement.

Nature and purpose of Processing

Hosting, receiving, validating, processing, mapping, transforming, transmitting, and delivering electronic data interchange (EDI) and related documents across SFTP, FTPS, AS2, HTTP/API, email, and direct upload, including delivery to trading partners and to third-party intermediaries that Customer configures; managing Customer accounts, authentication, permissions, partner relationships, routing rules, and connection credentials; providing customer support; generating notifications, reports, dashboards, and usage analytics; and metering usage for billing, all for the purpose of providing, securing, and supporting the Service.

Types of Personal Data

  • Account and user information: names, business email addresses, organization and business unit affiliation, permissions and group membership, notification preferences, terms acceptance records, and login and activity timestamps;
  • Authentication data: hashed passwords, multi-factor authentication secrets and recovery codes, one-time codes transmitted by email, and session tokens;
  • Technical and usage data: IP addresses and request metadata, session identifiers, device, browser, screen, language and time zone information, product usage telemetry (features used and interactions), and application error detail, associated with the user and organization;
  • Support data: the content of support requests and attachments, and correspondence with Modalius support;
  • Routing and connection data: email addresses and domains used to identify expected senders for inbound email receiving, and identifiers used to route documents;
  • Personal Data contained in Customer Data or transaction documents: for example contact names, telephone numbers, and addresses associated with orders, shipments, or deliveries.

Customer is responsible for not submitting special categories of personal data (such as health, biometric, or payment card data) through the Service unless the parties have agreed in writing to support it. The Service is not designed for such data.

Categories of Data Subjects

  • Customer's authorized users and administrators;
  • Customer's personnel who contact Modalius support;
  • Contacts at Customer's trading partners and third-party intermediaries whose details appear in connection or routing configuration;
  • Individuals identified within Customer's transaction data (for example, shipping, receiving, or delivery contacts, and drivers).

Appendix B: Technical and Organizational Measures

Modalius maintains measures that include, as applicable:

Encryption and key management

  • Encryption of Personal Data in transit (TLS) and at rest;
  • Managed secrets storage for connection credentials and certificates, with supported credential rotation including a grace period during cutover;
  • Support for encrypted and signed transport protocols including SFTP, FTPS, and AS2.

Access control

  • Role-based access controls and least-privilege access, with permissions administered by Customer for its own users;
  • Multi-factor authentication for sensitive operations, which a Customer administrator may require for all users in the organization;
  • Separation of customer data by organization, enforced in the application layer;
  • Support access control: authorized Modalius personnel may access a Customer account, including by temporarily operating the Service as one of Customer's users, only to provide requested support, investigate a suspected security or integrity issue, diagnose a fault, or comply with law. Such access is restricted to personnel who need it, is recorded in an audit log, and cannot be used to issue support-portal credentials on Customer's behalf.

Infrastructure and network security

  • Network isolation and segmentation between environments, with production databases not reachable from the public internet;
  • Separate accounts and boundaries for production, quality assurance, and management workloads;
  • Continuous configuration recording and automated security posture monitoring against recognized benchmarks, including the CIS Amazon Web Services Foundations Benchmark and the AWS Foundational Security Best Practices standard.

Monitoring, logging, and incident response

  • Centralized logging, monitoring, alerting, and activity auditing across the platform;
  • Documented procedures for detecting, escalating, and responding to security events, including notification of Customer as set out in section 9.

Resilience and data lifecycle

  • Regular backups and tested restoration procedures;
  • Data retention and deletion controls, including configurable file lifetimes, a soft-delete reversal window, and scheduled expiry of logs;
  • Automated recovery of interrupted processing and delivery workflows.

Product and personnel security

  • A secure development lifecycle including peer code review before changes reach production, separate pre-production environments, and automated deployment pipelines with the ability to roll back;
  • Automated security findings from the monitoring described above triaged and remediated according to severity;
  • Written confidentiality obligations for personnel with access to Personal Data;
  • Prompt revocation of access on role change or departure.

Appendix C: Subprocessors

Modalius engages the following Subprocessors to support the Service, as of the effective date of this DPA. Customer may subscribe to change notices as described in section 6.

Subprocessor Purpose Personal Data involved Location
Amazon Web Services, Inc. Hosting, storage, databases, queuing, secrets management, managed file transfer, and outbound transactional and notification email All categories in Appendix A United States
Microsoft Corporation Hosted mailboxes used to receive inbound documents by email, where Customer enables email receiving; internal operational alerting Inbound message content and attachments, sender addresses, and operational metadata United States
Zendesk, Inc. Customer support portal, support identities, and support request management Account and user information, support data United States
Google LLC Usage analytics for the application and the Modalius website Technical and usage data United States

Trading partners, brokers, value added networks, and other recipients that Customer configures in the Service are not Subprocessors. They receive Customer Data as independent recipients at Customer's direction, and Customer is responsible for its relationships with them.

Contact

Questions about this DPA may be sent to contact@modalius.com.