Data Processing Addendum
Last updated: 8 May 2026
This Addendum forms part of the Terms of Service between you (Customer, acting as Controller) and Mentionhub OÜ (Mentionhub, acting as Processor) when Mentionhub processes Personal Data on your behalf. Mentionhub OÜ is registered in Tallinn, Estonia (registry code 17503260, registered office Narva mnt 5, 10117 Tallinn).
1. Subject and duration
We process Personal Data only to provide the brand-monitoring service described in our Terms, for the duration of your subscription plus 30 days for backup purposes.
2. Nature of processing
Indexing, storage, aggregation, and sentiment analysis of public news articles and social posts mentioning the brand keywords you configure.
3. Sub-processors
We use the sub-processors listed in our Privacy Policy (Vercel, Supabase, Clerk, Stripe). We will give 30 days' notice via email before adding a new sub-processor; you may object by terminating your subscription.
4. Security
- Data encrypted at rest (AES-256, Supabase) and in transit (TLS 1.2+).
- Row-level security enforced; service-role keys are server-only.
- Access to production data limited to two named operators.
- Backups retained 30 days, then deleted.
- Vulnerability monitoring on all dependencies via npm audit.
5. Data subject rights
We will assist you in responding to data-subject requests (access, deletion, rectification, portability) within 7 business days of your notice to privacy@mentionhub.ai.
6. Breach notification
We will notify you of any confirmed Personal Data breach within 72 hours of becoming aware of it, with such information as is reasonably available at the time.
7. International transfers
Where Personal Data is transferred outside the EEA, we rely on the EU Standard Contractual Clauses (Module 2: Controller-to-Processor) which are deemed incorporated here by reference.
8. Termination
On termination of services we will delete or return all Personal Data within 30 days, except where retention is required by law.