Momiji Data Processing Addendum
How Momiji handles the personal information a customer entrusts to it, with the subprocessor register and the security measures as schedules.
Draft for review, not yet in force
This document is a draft awaiting counsel review. It does not bind Momiji or any customer, and no version of it has been published with an effective date. It is posted so that a customer, an investor or a reviewer can read the terms we intend to operate under. Tell us where they are wrong: hello@mymomiji.com.
Version 1.0, draft of September 9, 2026. Not yet in force until published with an effective date after counsel review.
This Addendum forms part of the Momiji Subscription Agreement between Momiji AI Inc. ("Momiji") and the Customer. It describes how Momiji handles Personal Information that the Customer entrusts to it. Where this Addendum and the Agreement conflict on the handling of Personal Information, this Addendum wins.
1. Roles
1.1 The Customer is the organization that collects Personal Information about its employees, contractors and other individuals and determines why and how it is used. In the language of Quebec's private-sector privacy law, the Customer is the person carrying on an enterprise and Momiji is a service provider acting on its behalf. Under PIPEDA and the Alberta and British Columbia statutes, the Customer remains accountable for the information and Momiji processes it on the Customer's instructions.
1.2 Momiji processes Personal Information only to provide the Service, on the Customer's documented instructions, which are: the Agreement, this Addendum, the configuration the Customer's administrators set in the product, and the actions Users take in it.
1.3 Momiji will inform the Customer if it believes an instruction contravenes privacy law, and may suspend that instruction until resolved.
2. What is processed
Schedule 1 lists the categories of individuals, the categories of Personal Information, the purposes and the duration. The Customer will not enter Personal Information that the Service is not designed to hold, in particular Social Insurance Numbers outside the year-end slip generation step and banking details outside the Vault feature, which is off by default.
3. Momiji's obligations
3.1 Confidentiality. Momiji personnel with access to Personal Information are bound by written confidentiality obligations and receive privacy and security training. Access is limited to what a role needs and is logged.
3.2 Security. Momiji maintains the measures in Schedule 3 and will not reduce their overall level during the term.
3.3 Subprocessors. Momiji uses the subprocessors in Schedule 2. Momiji will give the Customer at least 30 days notice by email to the owner before adding or replacing a subprocessor. The Customer may object in writing on reasonable, documented privacy or security grounds within that period. If the objection cannot be resolved, the Customer may terminate the affected Module with a pro-rated refund of prepaid fees. Momiji remains responsible for its subprocessors as for itself, and binds each to obligations no less protective than this Addendum.
3.4 Location. Primary storage and compute are in Canada (Montreal, Quebec). Document backups are held in Cloudflare's eastern North America region. The model provider, product analytics and error reporting operate in the United States. Schedule 2 states the location for each subprocessor. Momiji will support the Customer's privacy impact assessment for transfers outside Quebec or Canada by supplying the information in this Addendum and answering reasonable written questions.
3.5 Assistance. Momiji will assist the Customer, at no charge for reasonable requests, in responding to individuals' requests to access, correct or delete their information, by providing the tools in the product and, where the product cannot do it, by manual action within 15 business days.
3.6 Breach notification. Momiji will notify the Customer's owner and administrators without undue delay, and no later than 72 hours after confirming a breach of security safeguards involving the Customer's Personal Information. The notice will describe the nature of the breach, the categories and approximate number of individuals and records affected, the likely consequences, the measures taken or proposed, and a contact for follow-up, and will be updated as facts become known. The Customer decides whether and how to notify individuals, the Office of the Privacy Commissioner of Canada, the Commission d'accès à l'information du Québec or any other authority; Momiji will supply what the Customer needs to do so.
3.7 Records. Momiji keeps a record of processing activities and of breaches of security safeguards for at least 24 months, as PIPEDA requires, and makes it available to the Customer on request.
3.8 Deletion and return. On termination, the Customer may export its data for 60 days. Momiji deletes Personal Information from live systems within 90 days after the term ends, and from backups on their normal rotation, except records the Customer is required by law to keep, which Momiji retains only as long as the Customer instructs or the law requires, and then deletes or returns. Momiji certifies deletion in writing on request.
3.9 Audit. Momiji will answer the Customer's reasonable written security questionnaire once per year at no charge, and provide any independent assurance report it holds under confidentiality. Where a report does not cover a question, the Customer may audit, on 30 days notice, once per year, during business hours, without disrupting the Service, at the Customer's cost, through an independent auditor bound to confidentiality. Findings are shared with Momiji first.
3.10 Government requests. If a public authority demands the Customer's Personal Information, Momiji will, unless the law forbids it, notify the Customer promptly and disclose only what the law compels.
4. The Customer's obligations
4.1 The Customer warrants that it has the authority and, where required, the consent to collect the Personal Information it enters and to have it processed as this Addendum describes, including transfer to the named subprocessors.
4.2 The Customer is responsible for the accuracy of Personal Information, for the access rights it grants Users, for responding to individuals, and for the retention periods that apply to it as an employer.
4.3 The Customer has designated a person responsible for privacy compliance, as PIPEDA and Quebec law require, and will identify that person to Momiji on request.
5. Liability
Liability under this Addendum is subject to the limitations in the Agreement.
6. Term
This Addendum lasts as long as Momiji holds any Personal Information of the Customer.
Schedule 1: Processing details
Individuals. The Customer's employees, contractors and other workers; their managers and administrators; emergency contacts named by workers; dependants only where a leave or benefit record names them; visitors and applicants only if the Customer uses features that record them.
Personal Information. Identity and contact details; employment details (role, department, site, manager, start and end dates, employment type); compensation and pay history; statutory tax elections (TD1 and provincial equivalents); hours, schedules, punches and, where a site is geofenced, the location of a punch; leave requests, balances and reasons as entered by the worker; expense claims and receipts; performance goals, feedback, appraisals, plans and survey responses, held with the confidentiality rules the product enforces; training completions and knowledge-check results; Social Insurance Number, transiently, only at the moment a year-end slip is generated and only in the generated slip; bank details only if the Customer enables the Vault; audit trail of actions in the product; support conversations.
Purposes. Operating the Customer's people, time, expense, payroll, compliance and performance processes; producing statutory records, statements, remittance summaries and year-end slips; securing the Service; providing support; and producing Usage Data that identifies no one.
Duration. The term of the Agreement plus the export and deletion periods in section 3.8, and any longer period the Customer instructs for records it must keep by law.
Schedule 2: Subprocessors
| Subprocessor | Function | Location | Data reached |
|---|---|---|---|
| Supabase, Inc. | Database, authentication, file storage | Canada (Montreal) | All Customer Data |
| Vercel Inc. | Application hosting and scheduled jobs | Canada (Montreal) for compute; global edge for static assets | All Customer Data in transit and in memory during requests |
| Cloudflare, Inc. (R2) | Backup of stored documents | United States (eastern North America) | Documents, receipts, slips and training records |
| Anthropic, PBC | Document extraction during setup and expense capture; the help assistant | United States | Uploaded documents and receipts; help questions with excerpts of documents the asker may read; no model training on Customer Data |
| PostHog, Inc. | Product analytics in the mobile application and on the marketing site | United States | Pseudonymous identifiers and events; no Customer Data content |
| Functional Software, Inc. (Sentry) | Error reporting for the mobile application | United States | Scrubbed error reports; no Customer Data content |
| Expo (650 Industries, Inc.) | Mobile application updates and push notification relay | United States | Device push tokens; notification title and one sentence, never an amount |
| Apple Inc. and Google LLC | Push notification delivery to devices | United States and global | Notification title and one sentence |
| Stripe, Inc. | Subscription billing, when card billing is enabled | United States and Canada | Owner name, email and billing details; usage counts |
Momiji publishes the current list at mymomiji.com/privacy and updates it in the same change as any change to the product.
Schedule 3: Security measures
- Tenant isolation in the database. Row-level security is enabled on every table in the application schema; a query from one organization cannot return another organization's rows.
- Least privilege for sensitive columns. Salary and pay rate are revoked at the column level and released only through gated functions that check authority and record the access. There is no Social Insurance Number column; bank details exist only in the Vault feature, which is off by default and encrypted.
- Encryption. TLS in transit everywhere; encryption at rest for the database and object storage; a separately keyed encrypted queue on the mobile device for offline punches.
- Authentication. Passwords hashed by the platform; CAPTCHA and rate limiting on sign-in, setup and invitation; time-based one-time-password two-factor sign-in available to every User and required for owners and administrators by default; administrator reset of a User's second factor, audited.
- Audit log. Append-only, written by a privileged database function that verifies membership; no update or delete path from the application for any role.
- Immutable records. Committed payroll registers, compliance completions and issued slips cannot be edited; corrections are new records that reference the original. Every payroll figure carries the engine version and tax-table edition that produced it.
- Backups. Daily database backups by the platform; daily document backups to a second provider; restore testing on a schedule, with the drill recorded.
- Change control. All changes pass automated type checks, unit tests and a database test suite of several thousand assertions before deployment; database migrations are reviewed and applied by a named operator, never by automation.
- Personnel. Access to production is limited to named individuals with two-factor authentication on every provider console; contractors and automated agents have no production write access.
- Vulnerability management. Dependency monitoring, secret scanning, and an external penetration test on the roadmap dated in the assurance plan; findings are remediated by severity.
- Incident response. A written procedure covering detection, containment, customer notification under section 3.6, and post-incident review.
- Subprocessor diligence. Each subprocessor is assessed for security posture and bound by terms at least as protective as this Addendum.
Momiji AI Inc. · Privacy contact: hello@mymomiji.com · Registered office 2408 Guildstone Crescent, Oakville, Ontario L6M 3Y6