Data Processing Agreement
Last updated: 21 July 2026.
This Data Processing Agreement ("DPA") forms part of the agreement between Code Energy, Inc. and the Customer for the use of the Motiro service (the "Agreement" — the Terms of Service and any order form or subscription). It governs processing of personal data that Code Energy carries out on the Customer's behalf. Where the Agreement and this DPA conflict on data protection, this DPA prevails.
Between:
Code Energy, Inc., a Delaware corporation, 304 S Jones Blvd #401, Las Vegas, NV 89107, United States, notice email hi@motiro.com ("Processor" or "Code Energy"); and
the Customer identified in the Agreement — the organization that operates teams and surveys on Motiro ("Controller" or "Customer"). The verified Motiro account accepting the Agreement is the Customer's notice contact unless the Customer gives Code Energy another contact.
Effective date: the effective date of the Agreement. The person who creates or uses a Motiro organization as an authorized manager accepts this DPA electronically for the Customer through the Terms of Service and represents that they have authority to do so. Motiro's organization, account, and creation records identify the Customer, accepting account, and acceptance date.
This DPA is entered into to satisfy Article 28(3) of Regulation (EU) 2016/679 ("GDPR") and, where applicable, the Swiss Federal Act on Data Protection ("FADP") and the UK GDPR.
1. Roles of the parties
For personal data of the Customer's team members that is processed because the Customer surveys them — identification details, survey answers, message delivery records — the Customer is the controller and Code Energy is the processor, acting only on the Customer's documented instructions.
Code Energy is an independent controller, not a processor, for the personal data of account holders (its direct account relationship, private personality assessments, billing, and security) and of website visitors. That processing is governed by the Motiro Privacy Policy, not this DPA.
Nothing in this DPA makes the parties joint controllers.
2. Subject matter, duration, nature, and purpose (Art. 28(3))
- Subject matter: Code Energy's processing of Customer personal data to provide the Motiro team-motivation survey and analysis service.
- Nature: hosting and storage; delivery of survey invitations and reminders by email, WhatsApp, and SMS; computation of aggregated team metrics and scores; AI-assisted generation of aggregated insights and guidance; disclosure through a connected application when an authorized Customer user selects and approves its access; and the operations, security, and support activities needed to run the service.
- Purpose: performing the Agreement — enabling the Customer to survey its teams and read aggregated results. Code Energy does not process Customer personal data for any independent purpose.
- Duration: for the term of the Agreement, plus the limited post-termination period in §10 (deletion or return).
Details required by the Annexes are set out in Annex 1 (processing details), Annex 2 (technical and organizational measures), and Annex 3 (subprocessors).
3. Categories of data and data subjects (Art. 28(3))
Data subjects: the Customer's team members and invitees (employees, volunteers, students, or equivalent), and the Customer's managers and administrators.
Categories of personal data:
- Identification: name, email address, phone number, profile picture, preferred language.
- Survey answers, including optional demographic answers (age range, gender) where the survey collects them.
- Message delivery records: which invitations and notifications were sent, on which channel, and their delivery status.
Special categories (Art. 9): the service is not designed to process special categories of personal data. The Customer must not submit, and must not instruct Code Energy to process, special-category data through free-text or survey fields except as expressly agreed in writing. Optional demographic data can be sensitive in context but are not, as designed, used to infer an Article 9 category. They receive the additional access, aggregation, and deletion safeguards described in Annex 2.
4. Controller instructions (Art. 28(3)(a))
Code Energy processes Customer personal data only on the Customer's documented instructions, including for international transfers, unless required otherwise by EU or member-state law (in which case Code Energy informs the Customer of that requirement before processing, unless the law forbids it). The Agreement, this DPA, the product's configuration options, and the Customer's use of the service through its account together constitute the Customer's complete documented instructions. Code Energy informs the Customer without undue delay if, in its opinion, an instruction infringes the GDPR or other applicable data protection law.
The Customer warrants that it has a lawful basis to collect the contact details it enters and to invite those data subjects to surveys, and that its instructions comply with applicable law.
If the Customer invites a child, the Customer must determine and document an appropriate lawful basis, provide privacy information the child can understand, and obtain authorization from a holder of parental responsibility where the applicable law and chosen basis require it. Code Energy does not obtain consent on the Customer's behalf and does not treat a child's participation as consent to the Customer's processing. A child can answer an organization-issued survey without creating a Motiro account.
When a Customer user connects an application through OAuth, each approved permission and request under that permission is a Customer instruction to disclose the covered data to that application. The Customer is responsible for authorizing which of its users may give that instruction, selecting the recipient, and establishing any legal basis and transfer safeguard required for the recipient. Code Energy shows the requested permissions before authorization, limits responses to approved permissions, and provides revocation. Individual survey responses are never available through a connected application.
5. Confidentiality (Art. 28(3)(b))
Code Energy ensures that persons authorized to process Customer personal data are bound by an appropriate duty of confidentiality (contractual or statutory) and are granted access only on a need-to-know basis. Per-bounded-context access isolation limits internal access to the data each function requires.
6. Security (Art. 28(3)(c), Art. 32)
Code Energy implements and maintains the technical and organizational measures in Annex 2, appropriate to the risk. The Customer acknowledges those measures provide an appropriate level of security given the nature of the data and the state of the art. Code Energy may update the measures provided the level of protection is not materially reduced.
7. Subprocessors (Art. 28(2), (3)(d), (4))
The Customer gives general written authorization for Code Energy to engage subprocessors. The subprocessors engaged as of the effective date are listed in Annex 3, each processing Customer personal data solely to deliver its function and bound by a written contract imposing data protection obligations no less protective than this DPA.
Change notification. Code Energy maintains the current subprocessor list at https://motiro.com/privacy-policy and will give the Customer at least 30 days' advance notice of any intended addition or replacement of a subprocessor, by updating that page and notifying affected Customer account administrators by email. The Customer may object on reasonable data protection grounds within the notice period; the parties will work in good faith to resolve the objection, and if they cannot, the Customer may terminate the affected part of the service.
Code Energy remains fully liable to the Customer for its subprocessors' performance of their data protection obligations.
An application that a Customer user independently chooses and authorizes is a Customer-designated recipient, not a Code Energy subprocessor. Code Energy does not appoint that application to provide the Motiro service and does not control the recipient's later processing. The Customer must review its terms, location, retention, and AI-training choices before authorizing it.
8. Assistance with data subject rights (Art. 28(3)(e))
Taking account of the nature of the processing, Code Energy assists the Customer by appropriate technical and organizational measures to respond to data subject requests to exercise their rights (access, rectification, erasure, restriction, portability, objection).
Much of this assistance is built into the product and available to the Customer and to data subjects with accounts directly, without a manual request:
- Access and portability: self-service export of the personal data associated with the requester's account, as a machine-readable file (Account -> Your data), OTP-gated.
- Erasure: self-service, immediate account deletion (Account -> Delete account), OTP-gated. Completed survey answers are de-identified rather than deleted, so de-identified team results do not change; suppressions are retained as a do-not-contact record.
- Rectification: account holders edit their own name and contact details in the product.
For requests Code Energy receives directly from a data subject about Customer data, Code Energy will not respond substantively but will, without undue delay, forward the request to the Customer. For requests the built-in tooling does not cover, Code Energy assists the Customer and responds within one month.
9. Assistance with Controller obligations (Art. 28(3)(f), Art. 32–36)
Code Energy assists the Customer, taking into account the nature of processing and the information available to it, in ensuring compliance with the Customer's obligations regarding security (Art. 32), personal data breach notification and communication (Art. 33–34), data protection impact assessments (Art. 35), and prior consultation (Art. 36).
Breach notification to the Controller. Code Energy notifies the Customer without undue delay after becoming aware of a personal data breach affecting Customer personal data, and in any event in time to let the Customer meet its own Art. 33 deadline. The notice describes, to the extent known, the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed. Code Energy provides further information as it becomes available. Code Energy's notice is not an acknowledgment of fault.
10. Deletion or return at end of processing (Art. 28(3)(g))
On termination of the Agreement, and at the Customer's choice, Code Energy deletes or returns all Customer personal data and deletes existing copies, unless retention is required by applicable law.
Deletion is carried out by the product's erasure machinery: identifiers are removed rather than whole records where a record carries counts, scores, or audit value, so de-identified and aggregate data may be retained under the access and statistical safeguards in Annex 2. When the Customer's organization is deleted, its tree — circles, teams, surveys, ballots, journeys, roles, and subscription — is destroyed. Financial records are retained as described in §11 and Annex 1.
Backups. Backups are retained under Code Energy's documented retention schedule. Person and organization deletions are recorded as HMAC-hashed references in a separate append-only ledger. If a database backup is restored, the service remains offline while the ledger is matched against the restored data and completed deletions are re-applied. The ledger and its matching HMAC secret are themselves protected as disaster-recovery assets. The hashes remain pseudonymous personal data because Code Energy holds the matching key; they contain no raw identifier and are used only for deletion continuity, concurrency control, and compliance evidence.
11. Audit and information rights (Art. 28(3)(h))
Code Energy makes available to the Customer the information necessary to demonstrate compliance with Art. 28 and allows for and contributes to audits, including inspections, conducted by the Customer or an auditor it mandates.
To satisfy this in practice, Code Energy will first make available its then- current security documentation and this DPA's Annexes on request. Where that is insufficient, the Customer may conduct an audit no more than once per year (and after a breach affecting its data), on reasonable prior written notice, at the Customer's expense, during business hours, without unreasonable disruption, and subject to confidentiality. An independent certification or audit report may satisfy the request where it provides equivalent evidence, but does not remove a statutory audit right.
Records retained after deletion. Financial and billing records (org billing data; on Stripe's side, invoices and card display brand/last-four only) survive deletion as an accounting and audit trail; person references in Code Energy's own ledger rows are scrubbed on erasure.
12. International transfers (Chapter V)
The primary application and database are stored on DigitalOcean infrastructure in Amsterdam, the Netherlands. Certain subprocessors (Annex 3) process personal data outside the EEA, including in the United States and Australia. An operator-held disaster-recovery copy is an additional Code Energy processing location in Brazil. Its current status, required safeguards, and the European Commission's Brazil adequacy decision are recorded in Code Energy's transfer assessment, available on request.
For the Customer-to-Code Energy restricted transfer, the parties incorporate the EU Standard Contractual Clauses in Commission Implementing Decision (EU) 2021/914, Module Two (controller to processor). The Agreement and Annex 1 supply the parties and processing details for the corresponding SCC annexes. Electronic acceptance of the Agreement constitutes signature of Annex 1; each party must keep its legal name, address, contact, and authority details accurate in the Agreement or an agreed order form. For Code Energy's onward transfers, Module Three (processor to processor) applies where required. Clause 7 (docking) applies; Clause 9 Option 2 (general authorization) applies with the 30-day notice in §7.
For each US subprocessor, Code Energy relies on the provider's certification under the EU-US Data Privacy Framework, including the UK Extension and Swiss-US framework where that provider is certified for the relevant data, or on the SCC module recorded in Annex 3 when DPF does not apply. No DPF claim is made for Code Energy itself, Anthropic, or an Australian recipient.
For Switzerland the SCCs apply with the FADP amendments and the Swiss FDPIC as supervisory authority; for the UK the SCCs apply together with the UK International Data Transfer Addendum. Code Energy carries out and documents transfer impact assessments and applies supplementary measures (encryption in transit and at rest, access control, provider-specific minimization, and post-restore erasure reconciliation) as needed. The current assessment, certification sources, locations, and verification status are available on request.
13. General
- Liability for this DPA is governed by the liability provisions of the Agreement.
- Governing law and jurisdiction follow the Agreement, without prejudice to the mandatory application of GDPR/FADP and any data subject's rights under the law of their residence.
- Term: this DPA lasts as long as Code Energy processes Customer personal data.
- Order of precedence: this DPA over the rest of the Agreement on data protection; the SCCs over this DPA on the matters they govern.
Annex 1 — Details of processing
| Item | Detail |
|---|---|
| Data exporter | The Customer (controller), identified by its Motiro organization name, the legal name and registered or principal address in its order form, billing profile, public register, or written notice to Code Energy, and the verified account contact that accepts the Agreement. The Customer must notify Code Energy if those details change. |
| Data importer | Code Energy, Inc. (processor), a Delaware corporation, 304 S Jones Blvd #401, Las Vegas, NV 89107, United States; privacy and notice contact: hi@motiro.com. |
| Subject matter | Provision of the Motiro survey and analysis service. |
| Duration | Term of the Agreement plus the §10 wind-down period. |
| Nature and purpose | Hosting, message delivery, aggregated metric computation, AI-assisted insight generation, operations, security, and support — solely to perform the Agreement (§2). |
| Data subjects | The Customer's team members, invitees, managers, and administrators. |
| Categories of data | Identification (name, email, phone, avatar, language); survey answers incl. optional demographics (age, gender); message delivery records. |
| Special categories | None instructed (§3). |
| Frequency | Continuous, for the term. |
| Retention | Personal data: for the life of the account / the Customer's use of the service. Message-log contact details: stripped after 12 months. Successfully delivered internal-event payloads: cleared immediately; an event abandoned after bounded retries: up to 30 days for operator redrive. De-identified survey data: retained for statistical and research purposes under the Annex 2 safeguards. Backups: per the documented retention schedule, with erasure re-applied on restore (§10). Billing/financial records: retained as an audit trail (§11). |
| Competent supervisory authority | The authority determined under SCC Clause 13 from the Customer's establishment and the transfer; the Customer records it in the Agreement or countersignature. For Swiss data, the FDPIC. |
Annex 2 — Technical and organizational measures (Art. 32)
Measures in place, appropriate to the risk:
- Encryption in transit: TLS for all client and provider connections.
- Backups and deletion continuity: a separate append-only erasure ledger drives reconciliation before service resumes after a restore. DigitalOcean's daily crash-consistent Droplet images provide short-window host recovery. Code Energy's independent-local-copy procedure requires an encrypted removable volume, an application-consistent MongoDB archive, the newest ledger, and matching secrets before that copy qualifies as an active recovery control. Code Energy documents the current status, retention, test, and evidence requirements and makes a description available on request.
- Authentication: passwords hashed with bcrypt; JWT session tokens with server-side revocation (token-version check on every request); OTP re-authentication required for data export and account deletion, and OTP verification required for new contact details.
- Access control: internal access on a need-to-know basis; per-bounded- context data isolation limits each function to the data it requires; confidentiality obligations on authorized personnel.
- Connected applications: OAuth uses granular read permissions, displays each requested permission before authorization, and supports revocation. Survey permissions expose only aggregates, never individual ballots. A Customer-selected application receives only data requested under an active approved permission.
- Abuse and rate-limiting: request rate limiting; Cloudflare Turnstile on abuse-prone endpoints.
- Data minimization to AI subprocessor: only aggregated results, numeric answers, and manager-written notes are sent to Anthropic. Motiro does not add account-profile identifiers or individual survey answers, and instructs managers not to place identifying details in free text. The data is not used to train AI models.
- Anonymity protection: result visibility is gated by team-size anonymity thresholds; individual survey answers are never shown to managers; demographic filtering is floored by a minimum segment size; survey-answering pages are not tracked by analytics.
- Resilience and integrity: single-node replica set with multi-document transactions for consistent, atomic writes; a transactional event outbox durably completes cross-context reactions, clears payloads after successful delivery, and bounds failed-event retention.
- Verifiable erasure: durable leased jobs survive intermediate failures; a two-layer sweep (declared-collection plus schema-blind value scan) verifies that erasure leaves no residual identifier; the external erasure ledger prevents an older database restore from making a deletion disappear.
- Governance: structural CI gates keep the personal-data inventory current — a new data collection cannot ship without declaring its erasure/export disposition; the provider/transfer register is reviewed on provider changes; the personal-data breach path is documented; access and recovery controls are reviewed on their documented cadences.
- Log minimization and retention: application access logs record matched route templates rather than raw URLs, query strings, referrers, or user agents. Slow-query alert emails replace command values with type markers. Backend, frontend, and database container logs rotate after five 10 MiB files.
Annex 3 — Subprocessors
General authorization applies (§7). As of the effective date:
| Subprocessor | Purpose | Data processed | Location | Transfer mechanism |
|---|---|---|---|---|
| DigitalOcean, LLC | Application, database, and erasure-ledger hosting | All Customer personal data at rest | Amsterdam, Netherlands (ams3) |
EEA processing; DigitalOcean DPA governs support/onward access |
| Mailgun Technologies, Inc. / Sinch Email | Email delivery | Recipient email, rendered message, delivery/failure metadata | EU message region; limited global/US account and support processing | Sinch SCC Module Three; Sinch Email DPF where applicable |
| Meta Platforms / WhatsApp | WhatsApp delivery | Recipient phone, rendered message, delivery status, inbound opt-out | Global, including United States | DPF for certified US recipient; Meta SCC fallback |
| ClickSend Pty Ltd (ACN 165 918 525), a Sinch company | SMS delivery | Recipient phone, rendered message, delivery status, inbound opt-out | Australia and telecommunications-network locations | Sinch SCC Module Three and UK Addendum |
| Anthropic, PBC | AI-assisted analysis | Aggregated results, numeric answers, manager-written notes; no account-profile identifiers or individual survey answers added by Motiro; no model training by default | United States | Anthropic SCCs |
Stripe, Cloudflare Turnstile, and self-hosted Matomo process Code Energy controller data rather than Customer survey data under §1. They are disclosed, with roles, locations, and safeguards, in the public Privacy Policy and Code Energy's transfer assessment, available on request.