S\P
ProductSolutionsUse casesPricingResourcesDocumentation
Sign inGet started
← Back to Legal & Provenance Hub

Data Processing Addendum (DPA)

Last updated: January 2025

Controller and processor roles for enterprise, research, and global compliance.

TL;DR

  • •Customer is the Controller; Modern Ancients is the Processor
  • •We process data only for provenance workflows, not advertising or training
  • •Immutable provenance records cannot be deleted once created
  • •We assist with data subject rights where technically feasible
  • •Designed for GDPR, CCPA, VCDPA, LGPD, PIPEDA compliance

1. Definitions

"Controller" - The entity that determines the purposes and means of processing personal data. Typically: You.

"Processor" - Modern Ancients LLC, acting on your instruction.

"Personal Data" - Any information relating to an identified or identifiable individual.

"Provenance Metadata" - System-generated metadata (cryptographic hashes, manifests, lineage logs, timestamps) that may include processing of identifiers but is not editable or deletable once archived.

"Immutable Records" - Data written into cryptographic or decentralized storage (e.g., IPFS, OpenTimestamps) that cannot be altered or erased.

2. Roles and Scope

The parties agree:

  • Customer is the Controller
  • Modern Ancients is the Processor

Modern Ancients processes personal data solely to provide provenance workflows, maintain platform integrity, secure artifacts and metadata, execute hashing/timestamping/proof generation, and monitor for abuse, fraud, or system compromise.

We do not process personal data for advertising, profiling, or model training.

3. Processor Obligations

Modern Ancients shall:

  • Process data only on Customer's documented instructions - including account provisioning, artifact ingestion, provenance computation, archival workflows, audit checks, and data export
  • Maintain confidentiality - All personal data is confidential. Employees and contractors are bound by strict confidentiality agreements
  • Implement appropriate technical & organizational measures - encryption in transit and at rest, cryptographic hashing, access controls, workspace isolation, rate limiting, tamper-evident logs, secure provenance workflow execution
  • Assist with data subject rights - access, correction, deletion (except immutable proofs), portability, objections, consent withdrawals
  • Notify of data breaches - We will notify Customer without undue delay if any breach affects their data
  • Maintain records of processing activities - In line with GDPR Article 30 and similar global requirements

4. Customer Obligations

Customer shall ensure personal data provided is lawful, refrain from uploading harmful or illegal material, not attempt to circumvent provenance systems, ensure rights requests are legitimate and verified, and understand and communicate the nature of immutable proof storage.

Customer is responsible for data legality and data governance in their own environment.

5. Subprocessors

Modern Ancients may engage subprocessors strictly for storage, authentication, payments, email delivery, timestamping, hashing or compute, network security, and infrastructure provisioning.

Core categories commonly include: authentication and database hosting (e.g., Supabase), payment processing (e.g., Stripe), transactional email (e.g., Resend), cloud infrastructure, and—when Customer enables them—decentralized archival/timestamp networks (e.g., IPFS, OpenTimestamps). Identity providers chosen by end users (e.g., Google, GitHub, Apple, Facebook) process authentication data under their own terms.

All subprocessors are bound by confidentiality, data protection agreements, and equivalent security controls. A current list is available upon request at legal@modernancients.com.

6. International Transfers

We may process or store data in the United States or other jurisdictions. If data is transferred cross-border, safeguards are applied (SCCs, equivalent mechanisms).

Sovereign Zones & jurisdictional restrictions—if enabled—limit where proofs and metadata may propagate. Immutable proofs archived in public networks (e.g., OTS) may be globally retrievable by design; Customer acknowledges the technical nature of decentralized timestamping systems.

7. Immutable Provenance Records

Certain outputs of SOVEREIGN\\PROVENANCE cannot be deleted, including:

  • cryptographic hashes
  • manifests
  • lineage logs
  • timestamp receipts
  • distributed ledger entries
  • IPFS objects
  • OTS commitments

Customer acknowledges that immutable data cannot be erased once written, this is a required feature of provenance, Modern Ancients cannot reverse this process, and immutable data is excluded from erasure rights.

We will, however, delete corresponding personal content stored in non-immutable systems, remove non-essential personal identifiers where possible, and pseudonymize identifiers associated with immutable records whenever supported.

8. Data Subject Rights

Modern Ancients will support Customer in fulfilling rights under applicable law, including access, correction, deletion (where possible), data portability, objection, and restriction of processing.

Immutable data (as defined above) is excluded from deletion and modification rights.

9. Data Breach Notification

If a security breach affecting Customer data occurs, we notify Customer without undue delay, provide details of scope/impact/mitigation, and cooperate with remediation and regulatory obligations.

10. Audit and Compliance

Customer may request a summary of our security policies, a list of subprocessors, a review of technical controls, and standardized audit reports (SOC, ISO, etc.) when available.

Customer may not demand access to systems that would compromise other users or provenance infrastructure.

11. Return or Deletion of Data

Upon termination, Customer account data is deleted, non-immutable storage is purged, but immutable records persist by design. Customer may export data prior to termination.

Immutable records remain part of the global historical provenance chain.

12. Liability

Both parties limit liability to the maximum allowed by applicable law, except for data misuse, intentional misconduct, and breaches of confidentiality.

13. Term and Survival

This DPA remains in effect as long as Customer uses the Service. Sections related to confidentiality, security, and immutable records survive termination.

Related Documents

  • Privacy Policy
  • Immutable Data Policy
  • Data Retention & Deletion Policy

Contact

Questions or Support: weare@modernancients.com

← Back to Legal & Provenance Hub
SOVEREIGN\PROVENANCE

Proof of origin for the age of intelligent creation. A Modern Ancients technology platform.

Follow product updates via Build Notes and investor surfaces.

  • Protocol
  • Investors

Product

  • Capabilities
  • Mirror console
  • Workflow templates
  • Pricing
  • Protocol
  • Specification
  • Policy packs

Solutions

  • Creators
  • AI labs
  • Institutions
  • Cities

Resources

  • Case studies
  • Mission
  • Genesis
  • How we use SP

Developers

  • Documentation
  • API overview

Community

  • Ecosystem
  • Federated Venture Alliance

Company

  • Investors
  • Contact
  • Security

© 2026 Modern Ancients LLC. SOVEREIGN\PROVENANCE is a Modern Ancients technology.

  • Journey Consultant Access
  • Privacy
  • Terms
  • Legal Hub