Data Processing Agreement
Version 2.6 · Effective July 2026 · Mango Technologies Ltd. · DIFC Licensed CL5222
Supersedes v2.5 (July 2026).
This Data Processing Agreement governs how Mango Technologies Ltd. (DIFC Licensed CL5222) processes personal data on behalf of its users, and how sub-processors process that data under instruction from maivis.
This agreement applies to maivis users: the individuals and families who use the platform directly.
maivis is free of charge, and maivis does not process transactions. No user pays for maivis today, and no payment method is collected. maivis reads financial data and organizes it: it does not and cannot initiate, authorize, schedule, or execute a payment, transfer, deposit, withdrawal, or trade, and it holds no client money or asset custody. Bank connections are retrieval-only (account identifiers, balances, transaction history). The processing governed by this agreement is therefore read and analysis of financial records, never the execution of a financial transaction.
Controller: Mango Technologies Ltd., DIFC Innovation Hub, Gate Avenue, Dubai, UAE. License CL5222.
Data Protection Officer: dpo@maiviswealth.com
To request a signed DPA: privacy@maiviswealth.com
1. Scope and Definitions
This agreement covers all personal data processed by Mango Technologies Ltd. in the operation of the maivis platform at maiviswealth.com. Personal data means any information relating to an identified or identifiable natural person, as defined under the DIFC Data Protection Law 2020.
- Data Controller:
- Mango Technologies Ltd. determines the purposes and means of processing.
- Data Processor:
- A third-party service provider that processes personal data under instruction from Mango Technologies Ltd.
- Data Subject:
- An individual whose personal data is processed, including maivis users, family members, and subscribers.
2. Data Controller
Mango Technologies Ltd.
DIFC Innovation Hub, Gate Avenue, Dubai, UAE
DIFC Licensed CL5222
Privacy contact: privacy@maiviswealth.com
Data Protection Officer: dpo@maiviswealth.com
3. Sub-Processors
The following sub-processors process personal data under instruction from Mango Technologies Ltd. Mango Technologies maintains a current sub-processor list and provides 30 days notice of material changes.
3.1 Changes to This List, and Your Options
We publish the current list here and at maiviswealth.com/subprocessors, with the date of the last change. Before we add or replace a sub-processor that will process your personal data, we give at least 30 days notice by email to your registered address and by in-app notification. If you object to a new sub-processor, you may delete your account and request erasure of your data before the change takes effect, at no cost and with no obligation. Because maivis is free of charge, there is no subscription for you to terminate and nothing to refund.
3.2 Assurance and Audit
Our primary means of assurance is independent third-party certification and audit reporting rather than our own inspection. On written request to legal@maiviswealth.com we will provide the current certification and audit reports we hold or can obtain for the sub-processors above, and a description of our own technical and organizational measures as set out in Section 7. See Section 7.1 for what maivis itself is and is not certified to, stated plainly.
3.3 Breach Notification From a Sub-Processor
We are subject to a 72-hour regulator notification obligation, so we cannot rely on a processor that would tell us late. We require every sub-processor, as a condition of processing personal data for maivis, to notify us of a personal data breach without undue delay and in time for us to meet that 72-hour obligation. Where a processor's own terms set a shorter period, the shorter period applies. Our obligations to you on a breach are in Privacy Policy Section 11 and are unaffected by where the breach originated.
3.4 The Instrument the Transfers Rely On
For every Google service listed below, including Cloud SQL, Cloud Run, Cloud Storage, Cloud KMS, Firebase Authentication, Firebase Analytics, Cloud Functions, and the Gemini Enterprise Agent Platform, the transfer instrument is the Google Cloud Data Processing Addendum as published by Google at cloud.google.com/terms/data-processing-addendum, in the version in force for our Google Cloud organization, which incorporates the EU Standard Contractual Clauses and the UK Addendum. For every other sub-processor the instrument is stated in that processor's entry below. If you need the executed documents for a diligence or compliance review, contact legal@maiviswealth.com.
3.5 Banking Aggregation: What Is Actually Live
Only one banking rail carries real member data today. Lean Technologies provides read-only account, balance, and transaction retrieval for UAE accounts and is a live sub-processor. Plaid is integrated but runs in sandbox mode in production, which means it processes no real member banking data: no member's live account is connected through it, and no personal data reaches it.
We will not enable a banking provider to process real member data before an executed data-processing agreement with an appropriate transfer mechanism is in place for that provider, and we will update this section when Plaid or any other provider moves out of sandbox. If you want to know which providers are live at the moment you read this, ask legal@maiviswealth.com and we will tell you.
Google Cloud Platform(Google LLC)
Stripe, Inc.(Stripe, Inc.)
Lean Technologies(Lean Technologies (UAE))
India open banking(India open banking (coming soon))
Plaid, Inc.(Plaid, Inc. (US / UK / Canada))
PostHog(PostHog, Inc. (PostHog Cloud EU))
Anthropic Claude (via Google Cloud Gemini Enterprise Agent Platform Model Garden)(Google LLC (Google Cloud Model Garden))
Gemini Enterprise Agent Platform (Gemini Flash)(Google LLC)
Google Search Grounding(Google LLC (via Gemini Enterprise Agent Platform))
Mango Intelligence(Mango Technologies Ltd. (internal analytics affiliate, mango-intelligence-492117))
4. Data Subject Categories
maivis processes data belonging to: registered users (adults, age 18+); and family members added by the account administrator. maivis does not knowingly process data relating to children under 18.
5. Data Retention
Financial data: seven years (UAE Commercial Transactions Law). Identity and active account data, where no deletion request is made: account lifetime plus up to three years after the account becomes inactive. Deleted account data: a deletion request opens a 30-day grace period (cancellable during that window), after which data is permanently purged except for a category subject to a named statutory minimum; a deletion request governs, and the three-year period does not apply to data a member has asked us to delete. Authentication logs: 90 days rolling. Encrypted vault documents: retained until explicit deletion request. Banking access tokens: purged within 24 hours of disconnection. Canadian members (FINTRAC): financial transaction records retained five years. Breach records (PIPEDA): retained 24 months. Pseudonymized event analytics: no longer than the retention window configured with the analytics provider, and in any case no longer than 14 months for event-level records. Aggregate, non-identifying counts: retained indefinitely. Where a statutory minimum is longer than the 30-day purge, that minimum governs for that category of data alone, and we tell the member which category and why. Privacy Policy Section 9 carries the same list. Users may request deletion at any time: privacy@maiviswealth.com. Deletion is actioned within 30 days under Article 19 of DIFC Data Protection Law 2020.
6. International Transfers
Personal data is transferred internationally only where a lawful transfer mechanism exists. Mechanisms in use: EU Standard Contractual Clauses (EU SCCs 2021), UK International Data Transfer Agreement (IDTA), DIFC Standard Contractual Clauses, and adequacy decisions where applicable.
Stored personal data resides in a single region, Google Cloud me-central1 (Doha, Qatar), for all members regardless of residence, with backups and Cloud KMS keys in that same region. We do not operate a storage region matched to each member's country of residence, and we do not claim to. The mechanisms above are what govern the transfer from a member's own jurisdiction to that region. AI inference is a separate activity from storage and is described in Section 3.
7. Security Measures
AES-256-GCM encryption, or an algorithm of equivalent or greater strength, for all data at rest and in transit. Client-side encryption for the Document Vault: documents are encrypted on the user's device before upload and maivis stores only ciphertext. Key material is generated inside Google Cloud KMS, is held within that service, and cannot be exported from it. Keys provisioned for new families use the Cloud KMS software protection level. Some keys provisioned earlier use a higher protection level. maivis makes no representation as to the protection level of any particular key. A plaintext key transits the server in-memory only during an authorized access and is never persisted to disk or logs. An authorized access includes both a member viewing or downloading a document and server-side processing of that document to power document search, asset matching, and AI-driven intelligence: in those cases maivis decrypts the document in server memory. maivis is therefore able to read document content while your family's key is enabled, and does so for those purposes. Direct identifiers are stripped before any document content reaches an AI model. FIDO2 biometric authentication for user access. GCP Virtual Private Cloud (VPC) isolation. Cloud KMS key management with customer-managed encryption keys (CMEK). DIFC DP Law 2020 breach notification obligations apply.
7.1 What maivis Is and Is Not Certified To
The infrastructure maivis runs on is Google Cloud, and Google's certifications for that infrastructure, including ISO/IEC 27001, ISO/IEC 27017, ISO/IEC 27018 and SOC 1, 2 and 3, apply to that layer. We rely on them and can provide the current reports on request.
Mango Technologies Ltd. does not itself hold ISO/IEC 27001, SOC 2, or any equivalent organizational certification, and nothing in this agreement should be read as claiming one. Independent penetration testing of the maivis application is planned and has not yet been completed. We will state here when either position changes, and we will not describe a control as in force before it is.
7.2 Data Flow Summary
| Data category | Goes to | Region | Transfer mechanism |
|---|---|---|---|
| Identity, account and financial records; backups | Google Cloud SQL | me-central1 (Doha) | GCP Data Processing Addendum (EU SCCs + UK Addendum) |
| Encrypted vault documents (ciphertext) and wrapped keys | Google Cloud Storage and Cloud KMS | me-central1 (Doha) | GCP Data Processing Addendum |
| Authentication credentials | Firebase Authentication | Google infrastructure | GCP Data Processing Addendum |
| Pseudonymized financial values only; no direct identifiers | Gemini Enterprise Agent Platform, and Claude via Model Garden | Google global compute (US/EU), Zero Data Retention | GCP Data Processing Addendum |
| Generic market queries; no family data | Google Search Grounding | Google global compute | GCP Data Processing Addendum |
| Hashed family identifier, event type, timestamp; no names, emails or financial values | Mango Intelligence (same corporate group) | BigQuery, US multi-region | GCP Data Processing Addendum; intra-group |
| Product-usage events and masked session replay | PostHog Cloud EU | EU | PostHog DPA; EU processing, no transfer out |
| Read-only bank account, balance and transaction retrieval | Lean Technologies | UAE | DIFC SCCs; see Section 3.5 |
This table summarizes the Section 3 entries. Where the two differ, Section 3 governs, because it is the source this summary is drawn from.
7A. Liability and Changes in Law
7A.1 Liability
This agreement does not create a separate liability cap. Liability arising in connection with this agreement is governed by Section 10 of the Terms of Service, including its carve-outs for death, personal injury, fraud, and any liability that cannot be excluded under mandatory law. Nothing here limits any right or remedy you have under applicable data-protection law, including a right to compensation, which exists independently of any contractual limit.
7A.2 Changes in Law or Supervisory Guidance
Where applicable data-protection law or binding supervisory guidance changes in a way that affects this agreement, including the adoption of a new version of the Standard Contractual Clauses, the finalisation of rules under the DPDP Act 2023, or new guidance from the DIFC Commissioner of Data Protection, we will make the changes needed to stay compliant and will update this document to state what changed and when. Any such change is notified as set out in Privacy Policy Section 19.
8. Self-Hosted Services
The following tools are self-hosted on maivis's own Google Cloud Platform infrastructure. No personal data is transmitted to external third parties for these services. No separate DPA is required as Mango Technologies Ltd. acts as both data controller and processor.
- Native AI Chat (SSE): in-app chat widget and customer communication via native server-sent events implementation on Cloud Run within maivis VPC. Powered by Gemini Flash (via Gemini Enterprise Agent Platform), Claude Sonnet (via Google Cloud Model Garden), and Google Search Grounding (market queries) via PII gateway. No conversation data leaves maivis GCP infrastructure.
- Cloud Scheduler + Cloud Functions: serverless workflow automation for email notifications and internal processes. GCP-native, no additional infrastructure.
8A. Document Version Cross-Reference
These four documents are intended to be read together and to agree with each other. As at the date of this version, the set in force is:
| Document | Version | Where |
|---|---|---|
| Terms of Service | v2.11 (July 2026) | maiviswealth.com/legal/terms-of-service |
| Privacy Policy | v2.12 (July 2026) | maiviswealth.com/legal/privacy-policy |
| Data Processing Agreement | v2.6 (July 2026) | this page |
| Cookie Policy | v2.6 (July 2026) | maiviswealth.com/legal/cookie-policy |
Where any of these documents conflict on a matter of data protection, this agreement and the Privacy Policy govern. Where they conflict on a contractual term, the Terms of Service govern. If you find a genuine inconsistency between them, tell us at legal@maiviswealth.com and we will correct it and record the correction at maiviswealth.com/corrections.
9. Contact and DPA Requests
- Privacy enquiries:
- privacy@maiviswealth.com
- Data Protection Officer:
- dpo@maiviswealth.com
- Signed DPA requests:
- privacy@maiviswealth.com with subject line "DPA Request"
Mango Technologies Ltd. will respond to DPA requests within 10 business days.
Data Processing Agreement v2.6 · July 2026.
See also: Privacy Policy | Terms of Service | Cookie Policy