1. Roles
The client is the controller of the personal data contained in the content it sends for moderation. Moderators is the processor. The parties are identified in the order and in the company details shown at the bottom of this page.
2. Subject matter and duration
We process client content and related personal data to moderate it according to the client's policy, for the duration of the subscription or order and the agreed retention period after it.
3. Categories of data and data subjects
Data subjects are the client's users and other people who appear in user content. Data includes user identifiers, profile data, text, messages, images, video, audio, reports, appeals and moderation decisions. Content may contain special categories of data, which we process only as needed to apply the client's policy.
4. Instructions
We process personal data only on the client's documented instructions, including the policy, thresholds and escalation rules, unless the law requires otherwise. We tell the client if we believe an instruction breaks data protection law.
5. Confidentiality
Everyone authorised to process the data, including moderators, is bound by confidentiality obligations and sees only the queues assigned to them.
6. Security
We apply technical and organisational measures appropriate to the risk, including encryption in transit and at rest, role based access, multi factor authentication, an audit log of access and decisions, and restrictions on copying and downloading content. Measures are described on our security page.
7. Subprocessors
The client authorises the use of subprocessors in these categories: hosting providers in the EU or the US, AI model providers for content scoring, an email delivery provider, and identity verification providers for moderators. We impose the same data protection obligations on each subprocessor, keep a current list available to clients on request, and inform clients of changes in advance so they can object.
8. International transfers
Where data is transferred outside the European Economic Area, we use an adequacy decision or the standard contractual clauses adopted by the European Commission, with supplementary measures where required. Clients choosing EU data residency have content stored in the EU.
9. Assistance to the client
We help the client respond to data subject requests, carry out data protection impact assessments and meet its security obligations, taking into account the nature of the processing.
10. Personal data breaches
We notify the client without undue delay after becoming aware of a personal data breach affecting client data, with the information the client needs to meet its own notification duties.
11. Deletion and return
At the end of the service, we delete or return client data according to the client's choice and the retention settings, unless the law requires us to keep it.
12. Audits
We make available the information needed to demonstrate compliance with this agreement and allow audits by the client or an auditor it appoints, with reasonable notice and confidentiality.
13. Child safety and legal requests
Where content suggests that a child is at risk or that a crime threatening life or safety has been committed, we follow the escalation path agreed with the client and any reporting duty imposed by law.
Contact
Questions about this agreement or requests for a signed copy go to support@moderators.net.