Self-Serve Data Processing Agreement
Data processing terms for self-serve customers using MangoApps under the Terms of Service. Last updated July 7, 2026.
Last updated: July 7, 2026.
This Self-Serve Data Processing Agreement ("DPA") forms part of the MangoApps Terms of Service ("Terms") between MangoApps, Inc. ("MangoApps") and the customer using the Service under the Terms ("Customer"). This DPA applies when MangoApps processes Personal Data in Customer Data on Customer's behalf as a processor, service provider, or similar role under applicable Data Protection Laws.
No signature is required for this DPA to be effective for self-serve use. If Customer has a separate written agreement, enterprise data processing agreement, business associate agreement, order form, or other negotiated contract with MangoApps, that written agreement controls to the extent of any conflict. Customers that require countersigned terms, custom security commitments, HIPAA terms, regulated-data terms, custom data residency, on-site audits, or negotiated transfer terms must use MangoApps' enterprise contracting process.
1. Definitions
"Data Protection Laws" means privacy, data-protection, and data-security laws applicable to MangoApps' processing of Personal Data under the Terms, including where applicable the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and U.S. state privacy laws including the California Consumer Privacy Act as amended ("CCPA").
"Personal Data" means Customer Data relating to an identified or identifiable natural person that is protected as personal data, personal information, or a similar term under Data Protection Laws. "Controller," "Processor," "Data Subject," "Personal Data Breach," "Processing," and "Supervisory Authority" have the meanings given in applicable Data Protection Laws. "Subprocessor" means a third party engaged by MangoApps to process Personal Data on Customer's behalf. "SCCs" means the standard contractual clauses approved by European Commission Implementing Decision (EU) 2021/914.
2. Roles and Scope
For Personal Data in Customer Data, Customer is the Controller or a Processor acting on behalf of a third-party Controller, and MangoApps is a Processor or service provider. Each party will comply with the Data Protection Laws applicable to it. Customer is responsible for the accuracy, quality, legality, source, collection, retention, and use of Personal Data; for having all required notices, consents, authorizations, and lawful bases; and for ensuring that Customer's instructions to MangoApps comply with Data Protection Laws.
This DPA applies only to Personal Data in Customer Data processed by MangoApps on Customer's behalf through the Service. It does not apply to Account Data or other data for which MangoApps determines the purposes and means of processing, which is governed by the MangoApps Privacy Policy.
3. Customer Instructions
MangoApps will process Personal Data only on Customer's documented instructions unless required to do otherwise by applicable law. Customer's documented instructions consist of the Terms, this DPA, Customer's use and configuration of the Service, support requests, account settings, and other written instructions MangoApps accepts. MangoApps may refuse, suspend, or delay an instruction if MangoApps reasonably believes the instruction violates law, violates the Terms, creates security or operational risk, requires custom services not included in Customer's self-serve plan, or is outside the scope of the Service.
Customer instructs MangoApps to process Personal Data to provide, secure, support, maintain, troubleshoot, analyze, and improve the Service; prevent abuse and fraud; comply with law; process integrations and AI features enabled by Customer; create aggregated or de-identified data; and otherwise perform MangoApps' obligations and exercise MangoApps' rights under the Terms and this DPA.
4. Regulated Data and Customer Responsibilities
Self-serve plans are not designed for payment cardholder data, protected health information subject to HIPAA, children's data subject to COPPA or similar child-privacy laws, biometric identifiers or biometric information, government classified information, export-controlled technical data, or other data subject to sector-specific legal obligations beyond ordinary business personal data. Customer must not submit that data to the Service unless MangoApps has expressly approved the use in a separate written agreement or plan-specific addendum. MangoApps is not responsible for regulated data submitted in violation of this section.
Customer is responsible for all employee, worker, candidate, applicant, contractor, union, works-council, monitoring, consent, notice, retention, and workplace-law obligations arising from Customer's use of the Service. Customer is also responsible for responding to Data Subjects except as expressly stated in this DPA.
5. Confidentiality
MangoApps will ensure that persons authorized to process Personal Data are subject to contractual or statutory confidentiality obligations and process Personal Data only as needed to provide the Service or as otherwise permitted by the Terms and this DPA.
6. Security
MangoApps implements and maintains commercially reasonable technical and organizational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, as described in Annex 2. MangoApps may update these measures from time to time, provided updates do not materially reduce the overall protection of Personal Data in the Service.
Self-serve plans do not include custom security controls, dedicated environments, custom data residency, private cloud, SSO/SAML, SCIM, extended audit-log retention, security questionnaires, on-site assessments, penetration testing by Customer, or custom compliance documentation unless MangoApps expressly includes them in the applicable plan or a separate written agreement.
7. Subprocessors
Customer provides general written authorization for MangoApps to engage Subprocessors to provide the Service. MangoApps' current subprocessor list is published at /gdpr-subprocessors. MangoApps will impose data-protection obligations on each Subprocessor that are no less protective in substance than those in this DPA and will remain responsible for each Subprocessor's performance of those obligations.
MangoApps may update the subprocessor list from time to time. Customer is responsible for reviewing the list and may object to a new Subprocessor on reasonable data-protection grounds by emailing legal@mangoapps.com within fifteen (15) days after the list is updated or Customer receives notice where notice is required by law. If the parties cannot resolve the objection in a commercially reasonable manner, MangoApps may either not use the Subprocessor for Customer's affected Service or allow Customer to terminate the affected portion of the Service. Termination of the affected portion and, if required by law, a pro-rata refund of unused prepaid fees for that affected portion is Customer's sole remedy for a Subprocessor objection.
8. Data Subject Requests
Taking into account the nature of the Service, MangoApps will make available such self-service and export functionality as is then included in the Service to assist Customer in responding to Data Subject requests. This functionality is limited, may be intermittent, and varies by plan, feature, region, and data type, and it may not cover all Personal Data or all types of request; MangoApps does not guarantee that any particular Personal Data can be accessed, exported, corrected, or deleted through self-service functionality. If a Data Subject contacts MangoApps directly regarding Personal Data processed on Customer's behalf, MangoApps may redirect the request to Customer and need not respond substantively unless required by law. Assistance beyond available self-service functionality and standard support may be conditioned on Customer paying MangoApps' reasonable fees and expenses.
9. Personal Data Breach
MangoApps will notify Customer without undue delay and in any event within seventy-two (72) hours after MangoApps becomes aware of a confirmed Personal Data Breach affecting Personal Data processed by MangoApps on Customer's behalf. Notice will include information reasonably available to MangoApps about the nature of the breach, affected Personal Data, likely consequences, measures taken or proposed, and a contact point, in each case to the extent known and required by applicable law. MangoApps will take reasonable steps to contain and remediate the breach and reasonably cooperate with Customer's legally required investigation.
MangoApps' notification of or response to a Personal Data Breach is not an acknowledgment of fault or liability. Customer is responsible for determining whether notice to Data Subjects, regulators, employees, customers, or others is required and for providing any such notices unless applicable law requires MangoApps to do so.
10. Deletion and Return
During the subscription term and for sixty (60) days after cancellation or termination of a self-serve subscription, Network Administrators may, to the extent export functionality is then available in the Service for the relevant data, export available Customer Data, unless the account was terminated for legal, security, abuse, or similar cause, or unless law requires a different period. Export functionality is limited, may be intermittent, and varies by plan, feature, region, and data type, and may not cover all Customer Data; Customer is responsible for maintaining its own backups and for exporting any data it needs before the end of this period. After that period, MangoApps may delete or disable access to Personal Data from production systems. Backup copies containing Personal Data are deleted or overwritten on MangoApps' ordinary backup lifecycle, generally within ninety (90) days after production deletion, unless law or security needs require longer retention.
MangoApps has no obligation under this self-serve DPA to provide custom exports, migration services, offline archives, officer deletion certificates, or support-assisted extraction except where required by applicable law or expressly included in Customer's plan.
11. Assistance; Costs
Taking into account the nature of processing and information available to MangoApps, MangoApps will provide reasonable assistance required by Data Protection Laws for security, breach response, data protection impact assessments, prior consultations, and Data Subject requests. Assistance beyond self-service functionality and standard support is provided at Customer's reasonable, documented expense and subject to MangoApps' security, confidentiality, and operational requirements.
12. Audits and Information Rights
MangoApps will make information reasonably necessary to demonstrate compliance with this DPA available through the Service, public trust pages, standard support materials, or other documentation MangoApps elects to provide. Self-serve plans do not include custom audit reports, on-site audits, personnel interviews, vulnerability scans, penetration tests, security questionnaires, or custom evidence packages.
Where Data Protection Laws grant Customer a mandatory audit right that cannot be satisfied by documentation MangoApps makes available, Customer may request a remote records-based audit no more than once per twelve (12) months, on at least thirty (30) days' written notice, through an independent auditor that is not a MangoApps competitor. Any audit must occur during normal business hours, be limited to MangoApps' processing of Personal Data for Customer, avoid disruption, protect MangoApps' and other customers' confidential information, comply with MangoApps security policies, and be at Customer's expense. MangoApps may object to audit scope, methods, personnel, or timing that creates security, confidentiality, operational, legal, or competitive risk.
13. International Transfers
MangoApps may process Personal Data in the United States and other countries where MangoApps or its Subprocessors operate. Where MangoApps transfers Personal Data protected by the GDPR, UK GDPR, or Swiss data-protection law to a country that is not recognized as providing adequate protection, the parties incorporate the SCCs as follows: Module Two applies where Customer is a Controller and MangoApps is a Processor; Module Three applies where Customer is a Processor and MangoApps is a Subprocessor. The UK International Data Transfer Addendum and Swiss adaptations apply where required.
For the SCCs: Customer is the data exporter and MangoApps is the data importer; clause 9 uses the general authorization option with the notice and objection process in Section 7; clause 17 selects Irish law; clause 18 selects the courts of Ireland; Annexes 1 and 2 of this DPA serve as Annexes I and II; and the subprocessor list at /gdpr-subprocessors serves as Annex III. To the extent the SCCs conflict with this DPA, the SCCs control for the restricted transfer.
14. U.S. State Privacy Terms
Where U.S. state privacy laws apply and Customer is a business, controller, or similar party, MangoApps acts as Customer's service provider, processor, contractor, or similar role for Personal Data in Customer Data. MangoApps will not sell or share Personal Data, retain, use, or disclose Personal Data for cross-context behavioral advertising, or retain, use, or disclose Personal Data outside the direct business relationship with Customer except as permitted by applicable law, the Terms, and this DPA. MangoApps certifies that it understands and will comply with these restrictions and will notify Customer if MangoApps determines it can no longer meet them.
15. AI Processing
If Customer enables AI features, Customer instructs MangoApps to process Personal Data in AI inputs, outputs, retrieved context, logs, and related records as necessary to provide the AI features. MangoApps does not use Customer Data, AI inputs, or AI outputs to train, fine-tune, or improve generalized AI models and requires its AI Subprocessors to apply equivalent restrictions. This does not limit MangoApps' use of aggregated or de-identified data that does not identify Customer, Users, or any individual.
Customer is responsible for its use of AI features, including notices, lawful bases, human review, impact assessments, worker consultation, and restrictions on automated decision-making. Customer must not use AI features as the sole basis for decisions that produce legal, employment, hiring, promotion, compensation, scheduling, disciplinary, termination, housing, credit, education, healthcare, benefits, safety, or similarly significant effects on individuals.
16. Liability; Order of Precedence; Duration
Each party's liability arising out of or related to this DPA is subject to the exclusions and limitations of liability in the Terms, except to the extent Data Protection Laws or the SCCs prohibit that limitation. This DPA does not expand MangoApps' liability, warranties, service commitments, support obligations, audit obligations, security obligations, or refund obligations beyond those expressly stated in the Terms and this DPA.
If there is a conflict, the SCCs control for restricted transfers, this DPA controls over the Terms with respect to MangoApps' processing of Personal Data on Customer's behalf, and the Terms control for all other matters. This DPA remains in effect for as long as MangoApps processes Personal Data on Customer's behalf under the Terms.
Annex 1 - Details of Processing
Subject matter and duration: Processing of Personal Data in Customer Data to provide the Service for the subscription term and post-termination retention period described in the Terms and this DPA.
Nature and purpose: Hosting, storage, transmission, display, backup, authentication, administration, support, security, analytics, AI-enabled processing, integrations, export, and related processing needed to provide, secure, support, maintain, analyze, and improve the MangoApps employee platform according to Customer's configuration and instructions.
Categories of Data Subjects: Customer's employees, contractors, workers, candidates, applicants, administrators, guests, customers, contacts, and other individuals whose Personal Data Customer or Users submit to the Service.
Categories of Personal Data: Identification and contact data, employment and workforce data, scheduling and time data, HR records, communications, posts, files, forms, training records, recognition data, usage data, log data, AI inputs and outputs, integration data, and other Personal Data submitted by Customer or Users. Sensitive or regulated data is prohibited except as expressly permitted under Section 4.
Frequency: Continuous for the duration of Customer's use of the Service.
Annex 2 - Technical and Organizational Measures
MangoApps maintains commercially reasonable measures that may include encryption in transit and at rest; access controls; logical tenant isolation; role-based permissions; least-privilege administrative access; monitoring; logging; firewalls; vulnerability management; patching; backups; incident response procedures; personnel confidentiality obligations; security training; and physical and environmental controls provided by cloud infrastructure providers. Measures may vary by plan, deployment model, region, feature, and configuration.
Customer is responsible for configuring the Service appropriately, managing Users and permissions, enabling available security features, protecting credentials and devices, reviewing audit logs available in its plan, managing integrations, and maintaining Customer's own backups and compliance controls.