Abstract gradient background in NinthMoon's brand colors

    Data Processing Addendum (DPA)

    Version: v1.0Effective Date: Jun 25, 2026

    This DPA applies ONLY where a business or partner organization (“Customer”) engages NinthMoon to process personal data on the Customer’s behalf. It does NOT govern NinthMoon’s direct relationship with individual consumer users as for that, NinthMoon is the controller and the Privacy Policy applies.

    1. Scope and Roles

    This DPA supplements the agreement between the Customer and NinthMoon AI LLC (“NinthMoon”). Where NinthMoon processes personal data on behalf of the Customer, the Customer is the controller and NinthMoon is the processor. This DPA applies to processing subject to the GDPR, UK GDPR, and other applicable data-protection laws.

    2. Definitions

    “Personal Data,” “Processing,” “Controller,” “Processor,” “Sub-processor,” “Data Subject,” and “Personal Data Breach” have the meanings given in the GDPR.

    3. Processing Obligations

    NinthMoon will:

    • (a) process personal data only on the Customer’s documented instructions;
    • (b) ensure personnel are bound by confidentiality;
    • (c) implement appropriate technical and organizational security measures (Article 32);
    • (d) assist the Customer with data-subject requests and with its obligations under Articles 32–36;
    • (e) (i) delete or return personal data at the end of the services, except where retention is legally required (ii) Upon receipt of a verified deletion request from a Data Subject or the Customer, NinthMoon shall not only purge the data from its own active production environments but shall also, within thirty (30) days, issue a mandatory downstream deletion directive to all Sub-processors who have processed such data. NinthMoon shall maintain a record of these deletion confirmations to provide to the Customer upon reasonable request. ; and
    • (f) make available information necessary to demonstrate compliance and allow audits under reasonable conditions and NDA.

    Legal Infringement Notification Mandate: NinthMoon shall immediately inform the Customer if, in its professional opinion, any documented processing instruction received from the Customer infringes the GDPR, UK GDPR, or other global data protection regulations.

    Audit Framework and Technical Scope: In satisfying its audit obligations under Section 3(f), the parties agree that audits shall be conducted no more than once per calendar year, upon at least thirty (30) days’ written notice, and strictly at the Customer’s sole expense. To protect NinthMoon’s multi-tenant cloud environment and proprietary configurations, the Customer shall first review NinthMoon’s third-party independent security attestations. A physical or remote inspection of NinthMoon’s active production code or cloud databases shall only be triggered if such documentation fails to verify compliance with Article 32 obligations, and must be executed in a manner that completely isolates other data subjects’ profiles from view.

    4. Sub-processors

    The Customer authorizes NinthMoon to engage sub-processors, including:

    • OpenAI — AI processing for Nimo (API business terms; no model training on the data);
    • Google Cloud Platform (Firebase) — hosting, database, storage, authentication, and messaging;
    • Google Cloud Natural Language — sentiment analysis for wellbeing/safety;
    • Google Speech-to-Text / Text-to-Speech — voice features.

    A current list is maintained in our Sub-processor List. NinthMoon will impose data-protection obligations on each sub-processor equivalent to those in this DPA, give notice of intended changes, and remain responsible for their performance.

    NinthMoon shall notify the Customer via email or an in-app administrative dashboard at least thirty (30) days prior to authorizing any new technical sub-processor to access personal data. The Customer possesses a period of fourteen (14) calendar days from the date of such notice to object to the appointment on reasonable, documented data protection grounds. Upon receipt of a valid objection, NinthMoon will work in good faith to provide an alternative configuration or route the Customer’s data streams clear of the disputed provider. If NinthMoon cannot provide a commercially viable alternative within thirty (30) days, either party may terminate the underlying service agreement without penalty upon written notice.

    5. International Transfers

    Where personal data is transferred outside the EEA/UK or another adequate jurisdiction, the parties will rely on the EU Standard Contractual Clauses, the UK Addendum, or another valid transfer mechanism.

    6. Personal Data Breach

    NinthMoon shall notify the Customer in writing within thirty-six (36) hours of confirming any Personal Data Breach affecting the Customer’s managed data segments. This notification shall, at a minimum, describe the nature of the security incident, the specific categories of data subjects and records compromised, the estimated technical impact on the Services, and the immediate mitigation measures implemented by NinthMoon’s Incident Response Team. NinthMoon shall provide reasonable downstream assistance to support the Customer’s statutory reporting obligations to relevant Supervisory Authorities and affected individuals.

    7. Liability and Term

    This DPA is governed by the governing law of the underlying agreement. It survives termination to the extent necessary. In case of conflict regarding personal-data protection, this DPA prevails over the underlying agreement.

    For the avoidance of doubt, NinthMoon’s total aggregate liability arising out of or related to this DPA, whether in contract, tort, or under any other theory of liability, shall be subject to the limitations and exclusions of liability set forth in the Underlying Agreement. In the absence of a specific liability cap in the Underlying Agreement, NinthMoon’s liability under this DPA shall not exceed the greater of: (i) the total fees paid by Customer to NinthMoon in the twelve (12) months preceding the incident giving rise to the claim; or (ii) $100. In no event shall NinthMoon be liable for any indirect, consequential, or punitive damages.

    8. Contact

    Data Protection / Privacy contact: legal@ninthmoon.ai
    NinthMoon AI LLC, 8 The Green, Ste A, Dover, DE 19901

    Schedule 1: Details of Processing Activities

    1. Subject Matter of Processing: The provision of an interactive, AI-driven emotional wellness companion interface (Nimo) and associated peer-support community or journaling features to the Customer’s authorized personnel or end-user demographic.

    2. Duration of Processing: The term of the underlying service agreement plus the standard fourteen (14) day data-erasure grace period utilized upon account termination or contract expiration.

    3. Nature and Purpose of Processing: Document storage, secure hosting, text-to-speech voice translation, natural language processing sentiment analysis for crisis detection, and conversational generative AI response compilation to deliver requested wellness insights.

    4. Categories of Data Subjects: Employees, members, authorized end users, or program participants authorized by the Customer to access the platform.

    5. Types of Personal Data Processed:

    • Account Identifiers: Names, corporate or personal email addresses, device push tokens, and authorization IDs.
    • Special Category Data (Health and Reproductive Logs): Voluntarily inputted reproductive milestones, fertility tracking entries, pregnancy tracking durations, pregnancy loss logs, or emotional wellness states.
    • Conversational Metadata: Interactive text logs submitted via chat prompts to Nimo, personal journaling records, and transient audio voice recording bytes.
    • System-Generated Inferences: Algorithmic sentiment tracking scores, user engagement logs, and consolidated long-term personal “memory” profiles.
    Soft, calming gradient background in NinthMoon's brand colors

    Your privacy matters to us.

    Transparent policies.

    HIPAA-conscious design.

    We never sell your data.

    Built on trust, designed with care.

    Download on the App StoreGet it on Google Play

    Download NinthMoon today 💛