Remind Data Processing Addendum
Version: August 15, 2026
This Data Processing Addendum (“DPA”) forms part of the agreement between Moonbear Ventures LLC (“Processor” or “Moonbear”) and the customer using Remind (“Controller” or “Customer”) and applies when Moonbear processes Customer Personal Data on the Customer’s behalf.
This draft must be reviewed for Moonbear’s jurisdiction, international-transfer position and insurance before it is offered contractually.
1. Definitions
“Applicable Data Protection Law” means laws applicable to the processing of Customer Personal Data, including the GDPR and UK GDPR where applicable.
“Customer Personal Data” means personal data contained in Customer Content or otherwise processed by Moonbear on Customer’s behalf through Remind.
“Data Subject”, “Personal Data”, “Personal Data Breach”, “Process”, “Processor” and “Subprocessor” have the meanings given by Applicable Data Protection Law.
“Service” means Remind and its related Microsoft Teams, administration, support and delivery services.
2. Roles and instructions
Customer is the Controller and Moonbear is the Processor of Customer Personal Data. Customer determines the purposes and essential means of processing and is responsible for its instructions, notices, legal bases and configuration of Microsoft 365 permissions.
Moonbear will process Customer Personal Data only on Customer’s documented instructions, including this DPA, the agreement, configuration and authorized support requests, unless law requires other processing. If legally permitted, Moonbear will inform Customer before processing required by law.
Moonbear will promptly inform Customer if it believes an instruction infringes Applicable Data Protection Law.
3. Processing details
The subject matter, duration, nature, purpose, data types and data-subject categories are described in Schedule 1.
4. Confidentiality
Moonbear will ensure that persons authorized to process Customer Personal Data are bound by confidentiality obligations and receive access only as needed to provide and secure the Service.
5. Security
Moonbear will implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure or access. Current measures are described in Schedule 2 and at https://teamsreminder.app/security.
Customer is responsible for configuring Teams permissions, controlling its users and administrators, selecting appropriate reminder audiences, and avoiding unsupported sensitive data.
6. Subprocessors
Customer grants general written authorization for the subprocessors listed at https://teamsreminder.app/subprocessors.
Moonbear will:
- enter into a written agreement imposing materially equivalent data-protection obligations on each Subprocessor;
- remain responsible for the Subprocessor’s performance of those obligations;
- provide at least 30 days’ advance notice before a new Subprocessor begins processing Customer Personal Data, except for an urgent replacement needed to maintain security or continuity; and
- provide a reasonable opportunity for Customer to object on documented data-protection grounds.
If Customer objects to a new Subprocessor on reasonable and documented data-protection grounds, the parties will work in good faith to resolve the objection. Moonbear may, where reasonably available, use an alternative provider or configuration that avoids the new Subprocessor, but Moonbear is not required to materially redesign the Service or incur unreasonable cost.
If Moonbear cannot reasonably resolve the objection, Customer may terminate the affected Service by providing written notice before the new Subprocessor begins processing Customer Personal Data. If the Subprocessor was introduced urgently to protect the security, availability or continuity of the Service, Customer may terminate within 30 days after receiving notice.
Termination under this Section will not incur an early-termination fee. For a subscription purchased directly from Moonbear, Moonbear will refund any prepaid fees covering the unused period after termination. For a subscription purchased through Microsoft Teams, AppSource or Azure Marketplace, cancellation and any refund will be processed under the applicable Microsoft marketplace procedure, and Moonbear will provide reasonable assistance. Moonbear will not be required to issue a duplicate refund for amounts refunded or credited by Microsoft.
Customer remains responsible for fees accrued before the effective date of termination. Termination and any applicable prorated refund are Customer’s exclusive remedies for an unresolved objection to a new Subprocessor.
7. Data-subject requests
Taking into account the nature of processing, Moonbear will provide reasonable assistance for Customer to respond to verified requests to exercise data-protection rights. If Moonbear receives a request concerning Customer-controlled data, it will not respond substantively except on Customer’s documented instruction or as required by law, and will redirect or forward the request where feasible.
8. Compliance assistance
Taking into account the nature of processing and information available to it, Moonbear will reasonably assist Customer with:
- security of processing;
- Personal Data Breach notifications;
- data-protection impact assessments; and
- consultations with supervisory authorities.
Assistance beyond functionality and information generally included with the Service may be subject to reasonable fees agreed in advance, unless the assistance is required because Moonbear breached this DPA.
9. Personal Data Breaches
Moonbear will notify Customer without undue delay after becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data. The notice will include available information concerning the nature of the incident, affected data and subjects, likely consequences, mitigation and a contact for follow-up. Moonbear may provide information in phases as the investigation progresses.
Notification is not an admission of fault or liability. Customer is responsible for determining whether notice to individuals or authorities is required unless law assigns that duty to Moonbear.
10. Return and deletion
During the agreement, Customer may access or delete data through available Service functionality. On termination or a verified written instruction, Moonbear will delete or return Customer Personal Data, at Customer’s choice where technically feasible, unless law requires retention.
Production data will be deleted within 30 days and backup copies will expire through protected rotation within 90 days. Until deletion, retained data remains protected and is not used for another purpose. Billing and legal records controlled independently by Moonbear are governed by the Privacy Policy rather than this section.
11. Demonstrating compliance and audits
Moonbear will make available information reasonably necessary to demonstrate compliance with this DPA, including relevant policies, summaries, certifications and responses to security questionnaires.
No more than once annually, unless required by a regulator or following a material incident, Customer may request an audit by an independent qualified auditor bound by confidentiality. Audits must avoid access to other customers’ information and unreasonable disruption. Customer bears reasonable audit costs unless the audit identifies a material breach by Moonbear.
12. International transfers
Moonbear will not transfer Customer Personal Data to a country outside the country or region in which it is initially processed except in accordance with Applicable Data Protection Law and the Customer’s documented instructions, including the instructions contained in this DPA.
12.1 EEA transfers
Where Customer Personal Data protected by the EEA GDPR is transferred to Moonbear in a country that is not covered by an applicable adequacy decision, the parties incorporate the European Commission Standard Contractual Clauses adopted under Commission Implementing Decision (EU) 2021/914 (“EU SCCs”).
For such transfers:
- Customer is the “data exporter” and Moonbear is the “data importer”;
- Module 2 (Controller to Processor) applies;
- the optional docking clause in Clause 7 is included;
- Option 2, general written authorization, applies under Clause 9(a);
- the notice period for changes to subprocessors is 30 days;
- the optional independent dispute-resolution language in Clause 11(a) is not included;
- the laws of the Netherlands govern the EU SCCs under Clause 17;
- the courts of the Netherlands have jurisdiction under Clause 18;
- the competent supervisory authority is determined under Clause 13 based on the Customer’s establishment, representative or affected data subjects; and
- Schedules 1, 2 and 3 of this DPA provide the information required by Annexes I, II and III of the EU SCCs.
If Customer is acting as a processor rather than a controller, the parties will apply the SCC module appropriate to their actual roles.
12.2 UK transfers
Where Customer Personal Data protected by the UK GDPR is subject to a restricted transfer, the parties incorporate the then-current International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner. Customer is the exporter and Moonbear is the importer. The selections and information specified above and in Schedules 1, 2 and 3 also apply to the UK Addendum where relevant.
12.3 Transfer assessments and supplementary measures
Each party will perform the responsibilities applicable to it concerning international-transfer assessments. Moonbear will provide information reasonably necessary for Customer to complete a transfer-impact or transfer-risk assessment.
Moonbear will implement supplementary technical, contractual or organizational measures where reasonably necessary to provide the level of protection required by Applicable Data Protection Law. These measures may include encryption in transit and at rest, access restrictions, logging, data minimization and procedures for reviewing legally binding government requests.
If the transfer mechanism used by the parties becomes invalid or is no longer legally sufficient, the parties will cooperate in good faith to implement another lawful mechanism. Moonbear may suspend an affected transfer if no lawful mechanism is reasonably available.
12.4 Changes to processing locations
Customer authorizes Moonbear to process Customer Personal Data in the countries and regions identified in this DPA and on Moonbear’s Subprocessor page.
Moonbear will provide at least 30 days’ advance notice before changing the country in which the primary production database or Customer Content is hosted. The notice will identify the new location, relevant service providers and the international-transfer mechanism that will apply.
Customer may object to the change on reasonable and documented data-protection grounds. The objection and any resulting termination will be handled under Section 6 of this DPA.
Before transferring Customer Personal Data to the new location, Moonbear will implement a legally valid transfer mechanism and any supplementary measures required by Applicable Data Protection Law.
13. Conflict and liability
If this DPA conflicts with the agreement concerning processing of Customer Personal Data, this DPA controls. Liability under this DPA is subject to the agreement’s liability provisions except where Applicable Data Protection Law prohibits that limitation.
Schedule 1 - Processing description
Subject matter: Hosting, scheduling, managing and delivering reminders through Microsoft Teams; account, subscription, support and security operations necessary to provide Remind.
Duration: The term of the customer agreement plus the deletion and backup-rotation periods in this DPA.
Nature and purpose: Collection from Customer and Microsoft Teams, storage, organization, retrieval, scheduling, transmission back to authorized Teams conversations/users, subscription provisioning, support, security monitoring, backup and deletion.
Categories of data subjects: Customer users, Microsoft 365 administrators, reminder creators, reminder recipients, persons mentioned in reminders or source-message previews, billing contacts and support contacts.
Types of personal data: Microsoft tenant/user/team/channel/chat/conversation identifiers; display names; team/channel names; reminder text and schedule; message-sender name and limited preview; routing information; delivery/status history; plan and seat data; marketplace subscription identifier and status; support communications; technical logs; billing contact and transaction data.
Sensitive data: Not intentionally required. Customer must not submit special-category data, protected health information, payment-card data, authentication secrets or other highly sensitive data unless expressly authorized in a written amendment.
Frequency: Continuous or event-driven according to Customer’s use of the Service.
Primary processing location: The production application services, PostgreSQL database, Redis queue, logs and backups are hosted in Microsoft Azure’s West Europe region in the Netherlands. Support communications are handled in Google Workspace (Gmail) and may be processed in other locations according to Moonbear’s Workspace configuration, its agreement with Google and the applicable transfer safeguards.
Schedule 2 - Technical and organizational measures
- TLS 1.2 or later for public application traffic.
- Encryption at rest for production databases, Redis persistence, storage and backups.
- Private networking for data services.
- Multifactor authentication for administrative systems.
- Least-privilege human and workload identities, quarterly access review and prompt revocation.
- Centralized secrets management and credential rotation.
- Application, authentication, queue, database and security logging with defined retention and alerts.
- Dependency/container vulnerability scanning, patching procedure and recorded releases.
- Backups, protected retention and periodic restore tests.
- Incident-response, breach-notification and business-continuity procedures.
- Subprocessor due diligence and written data-protection terms.
- Data-minimization, retention and secure-deletion procedures.
Schedule 3 - International-transfer and party details
Data exporter/controller: The Customer legal entity identified in the applicable Remind account registration, direct order form, Microsoft commercial marketplace subscription or other purchasing record. The Customer’s address and privacy contact are the details associated with that record.
Data importer/processor: Moonbear Ventures LLC, 1021 E LINCOLNWAY STE 6216, Cheyenne, Wyoming 82001, United States. Privacy contact: privacy@teamsreminder.app.
Applicable SCC module: Module 2 - Controller to Processor.
Competent supervisory authority: The supervisory authority of the EEA member state in which Customer is established. If Customer is not established in the EEA, the competent supervisory authority will be determined in accordance with Clause 13 of the EU SCCs.
Clause 7 - Docking clause: Included.
Clause 9(a) - Use of subprocessors: Option 2, general written authorization.
Subprocessor notice period: 30 days.
Optional language in Clause 11(a) - Independent dispute resolution: Excluded.
Clause 17 - Governing law: The laws of the Netherlands.
Clause 18 - Choice of forum and jurisdiction: The courts of the Netherlands.
Transfer description: As set out in Schedule 1.
Transfer frequency: Continuous or event-driven according to Customer’s use of Remind.
Retention: As set out in Section 10 of this DPA and the Remind Privacy Policy.
Subprocessors: The providers identified at https://teamsreminder.app/subprocessors.
Technical and organizational measures: As set out in Schedule 2.
UK transfers: For restricted transfers subject to the UK GDPR, the parties incorporate the then-current UK International Data Transfer Addendum to the EU SCCs. The party information, Module 2 selection, processing description and security measures stated in this DPA also apply to that Addendum where relevant.
