Skip to content
Skip to main content
maivis

Data Processing Agreement

Version 2.6 · Effective July 2026 · Mango Technologies Ltd. · DIFC Licensed CL5222
Supersedes v2.5 (July 2026).

This Data Processing Agreement governs how Mango Technologies Ltd. (DIFC Licensed CL5222) processes personal data on behalf of its users, and how sub-processors process that data under instruction from maivis.

This agreement applies to maivis users: the individuals and families who use the platform directly.

maivis is free of charge, and maivis does not process transactions. No user pays for maivis today, and no payment method is collected. maivis reads financial data and organizes it: it does not and cannot initiate, authorize, schedule, or execute a payment, transfer, deposit, withdrawal, or trade, and it holds no client money or asset custody. Bank connections are retrieval-only (account identifiers, balances, transaction history). The processing governed by this agreement is therefore read and analysis of financial records, never the execution of a financial transaction.

Controller: Mango Technologies Ltd., DIFC Innovation Hub, Gate Avenue, Dubai, UAE. License CL5222.

Data Protection Officer: dpo@maiviswealth.com

To request a signed DPA: privacy@maiviswealth.com

1. Scope and Definitions

This agreement covers all personal data processed by Mango Technologies Ltd. in the operation of the maivis platform at maiviswealth.com. Personal data means any information relating to an identified or identifiable natural person, as defined under the DIFC Data Protection Law 2020.

Data Controller:
Mango Technologies Ltd. determines the purposes and means of processing.
Data Processor:
A third-party service provider that processes personal data under instruction from Mango Technologies Ltd.
Data Subject:
An individual whose personal data is processed, including maivis users, family members, and subscribers.

2. Data Controller

Mango Technologies Ltd.

DIFC Innovation Hub, Gate Avenue, Dubai, UAE

DIFC Licensed CL5222

Privacy contact: privacy@maiviswealth.com

Data Protection Officer: dpo@maiviswealth.com

3. Sub-Processors

The following sub-processors process personal data under instruction from Mango Technologies Ltd. Mango Technologies maintains a current sub-processor list and provides 30 days notice of material changes.

3.1 Changes to This List, and Your Options

We publish the current list here and at maiviswealth.com/subprocessors, with the date of the last change. Before we add or replace a sub-processor that will process your personal data, we give at least 30 days notice by email to your registered address and by in-app notification. If you object to a new sub-processor, you may delete your account and request erasure of your data before the change takes effect, at no cost and with no obligation. Because maivis is free of charge, there is no subscription for you to terminate and nothing to refund.

3.2 Assurance and Audit

Our primary means of assurance is independent third-party certification and audit reporting rather than our own inspection. On written request to legal@maiviswealth.com we will provide the current certification and audit reports we hold or can obtain for the sub-processors above, and a description of our own technical and organizational measures as set out in Section 7. See Section 7.1 for what maivis itself is and is not certified to, stated plainly.

3.3 Breach Notification From a Sub-Processor

We are subject to a 72-hour regulator notification obligation, so we cannot rely on a processor that would tell us late. We require every sub-processor, as a condition of processing personal data for maivis, to notify us of a personal data breach without undue delay and in time for us to meet that 72-hour obligation. Where a processor's own terms set a shorter period, the shorter period applies. Our obligations to you on a breach are in Privacy Policy Section 11 and are unaffected by where the breach originated.

3.4 The Instrument the Transfers Rely On

For every Google service listed below, including Cloud SQL, Cloud Run, Cloud Storage, Cloud KMS, Firebase Authentication, Firebase Analytics, Cloud Functions, and the Gemini Enterprise Agent Platform, the transfer instrument is the Google Cloud Data Processing Addendum as published by Google at cloud.google.com/terms/data-processing-addendum, in the version in force for our Google Cloud organization, which incorporates the EU Standard Contractual Clauses and the UK Addendum. For every other sub-processor the instrument is stated in that processor's entry below. If you need the executed documents for a diligence or compliance review, contact legal@maiviswealth.com.

3.5 Banking Aggregation: What Is Actually Live

Only one banking rail carries real member data today. Lean Technologies provides read-only account, balance, and transaction retrieval for UAE accounts and is a live sub-processor. Plaid is integrated but runs in sandbox mode in production, which means it processes no real member banking data: no member's live account is connected through it, and no personal data reaches it.

We will not enable a banking provider to process real member data before an executed data-processing agreement with an appropriate transfer mechanism is in place for that provider, and we will update this section when Plaid or any other provider moves out of sandbox. If you want to know which providers are live at the moment you read this, ask legal@maiviswealth.com and we will tell you.

Google Cloud Platform(Google LLC)

PurposeInfrastructure: Cloud SQL (database), Cloud Run (compute), Cloud KMS (encryption), Cloud Storage, Firebase Authentication, Firebase Analytics, Cloud Functions, Gemini Enterprise Agent Platform (Gemini models)
Data locationGoogle Cloud me-central1 (Doha, Qatar), a single region for all members regardless of residence.
Data categoriesAll user data including identity, financial, encrypted documents, authentication credentials
Transfer mechanismGCP Cloud Data Processing Addendum with EU Standard Contractual Clauses and UK IDTA
SecurityAES-256 at rest and in transit, CMEK via Google Cloud KMS, non-exportable key material

Stripe, Inc.(Stripe, Inc.)

PurposePayment processing infrastructure. maivis is currently free, with no active charges; this sub-processor relationship is retained for account records and in case a paid plan is introduced in the future
Data locationUnited States (Stripe infrastructure)
Data categoriesBilling name, email address, billing address, subscription metadata. Card data processed under Stripe's own PCI DSS controllership. maivis never receives raw card numbers.
Transfer mechanismStripe Data Processing Agreement with EU Standard Contractual Clauses and EU-US Data Privacy Framework
SecurityPCI DSS Level 1, 3D Secure 2, tokenized storage

Lean Technologies(Lean Technologies (UAE))

PurposeRead-only UAE bank account aggregation via CBUAE Open Finance Framework
Data locationUAE (Lean infrastructure, G42 UAE)
Data categoriesBank account identifiers, balances, transaction history, authentication certificates
Transfer mechanismManual DPA with DIFC Standard Contractual Clauses. Lean holds CBUAE Innovative Payment Authorisation.
SecurityADGM FSRA licensed, certificate-based API authentication

India open banking(India open banking (coming soon))

PurposeIndia open banking integration is not yet active. Indian assets can be added manually. Integration to be announced.
Data locationN/A (no integration currently active)
Data categoriesNone (no data shared until integration is launched)
Transfer mechanismN/A
SecurityN/A

Plaid, Inc.(Plaid, Inc. (US / UK / Canada))

PurposeRead-only banking aggregation via Plaid Link OAuth for US, UK, and Canadian accounts. NOT LIVE: the integration runs in sandbox mode in production and processes no real member banking data.
Data locationUnited States (Plaid infrastructure). No real member data sent today.
Data categoriesNone today. If enabled: bank account identifiers, balances, transaction history, encrypted authentication tokens.
Transfer mechanismPlaid Data Processing Addendum with EU SCCs, UK SCCs (IDTA), and DIFC SCCs for UAE transfers
SecurityBank-grade encryption, Plaid Link OAuth, Data Transparency Messaging

PostHog(PostHog, Inc. (PostHog Cloud EU))

PurposeProduct analytics: feature interaction events, screen views, funnel completion, heatmaps, and session replay on a small number of pre-login pages. Optional and consent-gated: nothing is collected until the member accepts analytics cookies.
Data locationEuropean Union (PostHog Cloud EU infrastructure)
Data categoriesPseudonymized product-usage events keyed by an anonymous PostHog identifier, plus device, browser, page and referrer metadata. Session replay masks all form inputs, so typed values are not captured. No names, emails, account numbers, government IDs, or financial values.
Transfer mechanismPostHog Data Processing Agreement with EU Standard Contractual Clauses. EU-resident processing; no onward transfer to a third country for this sub-processor.
SecurityEU-hosted, TLS in transit, input masking on session replay, consent-gated collection with Global Privacy Control and Do Not Track honored

Anthropic Claude (via Google Cloud Gemini Enterprise Agent Platform Model Garden)(Google LLC (Google Cloud Model Garden))

PurposeAI language model processing for complex analysis via Claude models for portfolio analysis, succession assessment, and financial insights. Accessed through Google Cloud Model Garden (IAM auth, no direct Anthropic API key)
Data locationGlobal (contractual Zero Data Retention via Gemini Enterprise Agent Platform; no data stored by Google or Anthropic)
Data categoriesPseudonymized financial data only: asset values, portfolio holdings, spending amounts, jurisdictions. Direct identifiers are removed, but the financial profile remains re-linkable to a family, so this is pseudonymized rather than anonymous. No PII (names, emails, account numbers, government IDs stripped by Privacy Gateway before transmission)
Transfer mechanismFully covered by GCP Cloud Data Processing Addendum. Claude models processed under contractual ZDR: data transits Google infrastructure for processing but is not stored or used for training. No direct Anthropic API. GCP IAM auth only. No separate Anthropic DPA required.
SecurityGoogle Cloud Model Garden IAM auth, contractual Zero Data Retention, PII gateway filtering pre-transmission, no training on customer data

Gemini Enterprise Agent Platform (Gemini Flash)(Google LLC)

PurposePrimary AI inference: intelligence generation, briefings, document extraction, scoring analysis (~93% of AI requests)
Data locationGlobal (US/EU datacenters via Gemini Enterprise Agent Platform, contractual Zero Data Retention)
Data categoriesPseudonymized financial data: asset values, portfolio holdings, spending amounts, jurisdictions, re-linkable to a family, hence pseudonymized not anonymous. No PII (stripped by Privacy Gateway)
Transfer mechanismCovered by GCP Cloud Data Processing Addendum. Contractual ZDR: data processed but not stored or used for training.
SecurityGCP IAM auth, contractual Zero Data Retention, PII gateway filtering pre-transmission

Google Search Grounding(Google LLC (via Gemini Enterprise Agent Platform))

PurposeReal-time market intelligence and asset validation for portfolio context
Data locationGCP / EEA (Google infrastructure)
Data categoriesGeneric market queries only: anonymized asset classes, market conditions, and aggregate allocation percentages (no PII, no family financial details)
Transfer mechanismCovered by GCP Cloud Data Processing Addendum (Gemini Enterprise Agent Platform ZDR). No separate DPA required.
SecurityQuery-level PII filtering, no personal data transmission, 100% GCP ZDR, generic market context only

Mango Intelligence(Mango Technologies Ltd. (internal analytics affiliate, mango-intelligence-492117))

PurposeInternal behavioral-analytics pipeline that receives aggregated product-engagement signals to improve the product
Data locationGCP BigQuery (US multi-region)
Data categoriesPseudonymized family IDs (hashed, but a re-linking key exists, so this is pseudonymized rather than anonymous), event types (e.g. session_started, asset_added, frs_band_change, upgrade_completed, subscription_started, chat_message_sent), is_demo flag, is_free_tier flag, event timestamps. No names, emails, financial values, or direct identifiers.
Transfer mechanismIntra-group transfer to a BigQuery project within the same Google Cloud organization, covered by the GCP Cloud Data Processing Addendum.
SecurityPII never enters the pipeline (only hashed identifiers and event metadata), GCP IAM access control, day-partitioned tables with a 365-day expiry.

4. Data Subject Categories

maivis processes data belonging to: registered users (adults, age 18+); and family members added by the account administrator. maivis does not knowingly process data relating to children under 18.

5. Data Retention

Financial data: seven years (UAE Commercial Transactions Law). Identity and active account data, where no deletion request is made: account lifetime plus up to three years after the account becomes inactive. Deleted account data: a deletion request opens a 30-day grace period (cancellable during that window), after which data is permanently purged except for a category subject to a named statutory minimum; a deletion request governs, and the three-year period does not apply to data a member has asked us to delete. Authentication logs: 90 days rolling. Encrypted vault documents: retained until explicit deletion request. Banking access tokens: purged within 24 hours of disconnection. Canadian members (FINTRAC): financial transaction records retained five years. Breach records (PIPEDA): retained 24 months. Pseudonymized event analytics: no longer than the retention window configured with the analytics provider, and in any case no longer than 14 months for event-level records. Aggregate, non-identifying counts: retained indefinitely. Where a statutory minimum is longer than the 30-day purge, that minimum governs for that category of data alone, and we tell the member which category and why. Privacy Policy Section 9 carries the same list. Users may request deletion at any time: privacy@maiviswealth.com. Deletion is actioned within 30 days under Article 19 of DIFC Data Protection Law 2020.

6. International Transfers

Personal data is transferred internationally only where a lawful transfer mechanism exists. Mechanisms in use: EU Standard Contractual Clauses (EU SCCs 2021), UK International Data Transfer Agreement (IDTA), DIFC Standard Contractual Clauses, and adequacy decisions where applicable.

Stored personal data resides in a single region, Google Cloud me-central1 (Doha, Qatar), for all members regardless of residence, with backups and Cloud KMS keys in that same region. We do not operate a storage region matched to each member's country of residence, and we do not claim to. The mechanisms above are what govern the transfer from a member's own jurisdiction to that region. AI inference is a separate activity from storage and is described in Section 3.

7. Security Measures

AES-256-GCM encryption, or an algorithm of equivalent or greater strength, for all data at rest and in transit. Client-side encryption for the Document Vault: documents are encrypted on the user's device before upload and maivis stores only ciphertext. Key material is generated inside Google Cloud KMS, is held within that service, and cannot be exported from it. Keys provisioned for new families use the Cloud KMS software protection level. Some keys provisioned earlier use a higher protection level. maivis makes no representation as to the protection level of any particular key. A plaintext key transits the server in-memory only during an authorized access and is never persisted to disk or logs. An authorized access includes both a member viewing or downloading a document and server-side processing of that document to power document search, asset matching, and AI-driven intelligence: in those cases maivis decrypts the document in server memory. maivis is therefore able to read document content while your family's key is enabled, and does so for those purposes. Direct identifiers are stripped before any document content reaches an AI model. FIDO2 biometric authentication for user access. GCP Virtual Private Cloud (VPC) isolation. Cloud KMS key management with customer-managed encryption keys (CMEK). DIFC DP Law 2020 breach notification obligations apply.

7.1 What maivis Is and Is Not Certified To

The infrastructure maivis runs on is Google Cloud, and Google's certifications for that infrastructure, including ISO/IEC 27001, ISO/IEC 27017, ISO/IEC 27018 and SOC 1, 2 and 3, apply to that layer. We rely on them and can provide the current reports on request.

Mango Technologies Ltd. does not itself hold ISO/IEC 27001, SOC 2, or any equivalent organizational certification, and nothing in this agreement should be read as claiming one. Independent penetration testing of the maivis application is planned and has not yet been completed. We will state here when either position changes, and we will not describe a control as in force before it is.

7.2 Data Flow Summary

Data categoryGoes toRegionTransfer mechanism
Identity, account and financial records; backupsGoogle Cloud SQLme-central1 (Doha)GCP Data Processing Addendum (EU SCCs + UK Addendum)
Encrypted vault documents (ciphertext) and wrapped keysGoogle Cloud Storage and Cloud KMSme-central1 (Doha)GCP Data Processing Addendum
Authentication credentialsFirebase AuthenticationGoogle infrastructureGCP Data Processing Addendum
Pseudonymized financial values only; no direct identifiersGemini Enterprise Agent Platform, and Claude via Model GardenGoogle global compute (US/EU), Zero Data RetentionGCP Data Processing Addendum
Generic market queries; no family dataGoogle Search GroundingGoogle global computeGCP Data Processing Addendum
Hashed family identifier, event type, timestamp; no names, emails or financial valuesMango Intelligence (same corporate group)BigQuery, US multi-regionGCP Data Processing Addendum; intra-group
Product-usage events and masked session replayPostHog Cloud EUEUPostHog DPA; EU processing, no transfer out
Read-only bank account, balance and transaction retrievalLean TechnologiesUAEDIFC SCCs; see Section 3.5

This table summarizes the Section 3 entries. Where the two differ, Section 3 governs, because it is the source this summary is drawn from.

7A. Liability and Changes in Law

7A.1 Liability

This agreement does not create a separate liability cap. Liability arising in connection with this agreement is governed by Section 10 of the Terms of Service, including its carve-outs for death, personal injury, fraud, and any liability that cannot be excluded under mandatory law. Nothing here limits any right or remedy you have under applicable data-protection law, including a right to compensation, which exists independently of any contractual limit.

7A.2 Changes in Law or Supervisory Guidance

Where applicable data-protection law or binding supervisory guidance changes in a way that affects this agreement, including the adoption of a new version of the Standard Contractual Clauses, the finalisation of rules under the DPDP Act 2023, or new guidance from the DIFC Commissioner of Data Protection, we will make the changes needed to stay compliant and will update this document to state what changed and when. Any such change is notified as set out in Privacy Policy Section 19.

8. Self-Hosted Services

The following tools are self-hosted on maivis's own Google Cloud Platform infrastructure. No personal data is transmitted to external third parties for these services. No separate DPA is required as Mango Technologies Ltd. acts as both data controller and processor.

  • Native AI Chat (SSE): in-app chat widget and customer communication via native server-sent events implementation on Cloud Run within maivis VPC. Powered by Gemini Flash (via Gemini Enterprise Agent Platform), Claude Sonnet (via Google Cloud Model Garden), and Google Search Grounding (market queries) via PII gateway. No conversation data leaves maivis GCP infrastructure.
  • Cloud Scheduler + Cloud Functions: serverless workflow automation for email notifications and internal processes. GCP-native, no additional infrastructure.

8A. Document Version Cross-Reference

These four documents are intended to be read together and to agree with each other. As at the date of this version, the set in force is:

DocumentVersionWhere
Terms of Servicev2.11 (July 2026)maiviswealth.com/legal/terms-of-service
Privacy Policyv2.12 (July 2026)maiviswealth.com/legal/privacy-policy
Data Processing Agreementv2.6 (July 2026)this page
Cookie Policyv2.6 (July 2026)maiviswealth.com/legal/cookie-policy

Where any of these documents conflict on a matter of data protection, this agreement and the Privacy Policy govern. Where they conflict on a contractual term, the Terms of Service govern. If you find a genuine inconsistency between them, tell us at legal@maiviswealth.com and we will correct it and record the correction at maiviswealth.com/corrections.

9. Contact and DPA Requests

Privacy enquiries:
privacy@maiviswealth.com
Data Protection Officer:
dpo@maiviswealth.com
Signed DPA requests:
privacy@maiviswealth.com with subject line "DPA Request"

Mango Technologies Ltd. will respond to DPA requests within 10 business days.

Data Processing Agreement v2.6 · July 2026.

See also: Privacy Policy | Terms of Service | Cookie Policy