Product and ecosystem
Mopbe means Making Operations Better. It is a software product, not a separate legal entity, and is part of the EVDATI All-in-One Business Ecosystem. It may be purchased and used as a standalone product/module or with separately identified EVDATI services. Buying Mopbe does not require purchasing the ecosystem or grant rights to unrelated products; buying another product does not include Mopbe unless the applicable agreement says so.
Contracting entity
The default contracting entity for U.S. customers is EVDATI Innovated LLC, a Florida, United States entity operating in Orlando, with Florida governing law. For Jamaican customers it is EVDATI Innovated Ltd., a separate Jamaican entity operating in Kingston, with Jamaican governing law. International orders must expressly identify the contracting entity and applicable law. These entities are not interchangeable. The signed Order Form identifies the actual counterparty; neither entity guarantees the other’s obligations merely by affiliation.
Parties and incorporation
This DPA is between the customer and identified EVDATI contracting entity and applies to personal data processed on customer’s documented instructions under the purchased services. Customer is controller (or an authorized processor); EVDATI is processor (or subprocessor). It does not govern EVDATI’s independent controller purposes, described in the Privacy Policy. Mandatory transfer instruments prevail where required.
Processing schedule
Subject: purchased Mopbe operations services. Duration: subscription plus the limited retention/return period. Nature: collection, organization, storage, retrieval, transmission, requested analysis/extraction, support, export and deletion. Subjects may include authorized users, customers’ staff and supplier contacts. Data includes account/contact, invoice, supplier, operational and customer-authorized personnel information. Special-category, biometric, payroll identifier or applicant processing requires an explicit documented schedule and controls before use; it is not presumed supported.
Instructions and confidentiality
Process only documented lawful instructions, including authorized international transfers, unless law requires otherwise; notify customer of that requirement where lawful. Inform customer if an instruction appears unlawful and suspend the affected instruction while resolving it. Bind personnel to confidentiality and need-to-know access. No independent model-training or unrelated marketing purpose is authorized.
Security and incidents
Apply risk-appropriate technical and organizational measures, including access control, session safeguards, segregation, change control and recovery procedures as verified in the security schedule. Notify customer without undue delay after becoming aware of a personal-data breach, with known nature, affected categories, likely consequences, mitigation and contact; supplement as facts develop. Preserve evidence and assist customer’s lawful notifications. No unverified fixed-hour incident promise or certification is asserted.
Subprocessors
Use only disclosed authorized subprocessors with appropriate written data-protection obligations. EVDATI remains responsible for delegated processing under this DPA. Provide notice of proposed changes and a reasonable opportunity to raise data-protection objections before new processing, except justified emergency continuity measures followed by prompt notice. [LEGAL/OPERATIONAL CONFIRMATION REQUIRED]: notice period, subscription channel, objection resolution and termination remedy must be agreed in the schedule.
Rights, assessments and audit
Provide reasonable assistance with data-subject requests, security, breach obligations and applicable impact assessments, considering available information. Customer controls responses unless law requires otherwise. Make compliance information available and permit proportionate audits under confidentiality and security safeguards, avoiding access to other customers’ data. Agree reasonable scope, frequency and costs; regulators’ mandatory powers are unaffected.
Return and deletion
Following expiration or termination, customers have up to 30 days to access and/or export available Customer Data, subject to law, security requirements, technical availability and any different written agreement. After that period, EVDATI is not obligated to retain data for retrieval unless legally required or expressly agreed. Customer Data will be deleted or properly de-identified from active production systems within 90 days, subject to legitimate legal, regulatory, tax/accounting, litigation-hold, dispute, fraud-prevention, security-investigation and contractual-enforcement requirements. Exception records remain protected, restricted to the justified purpose and reviewed for continued necessity.
Residual copies of Customer Data may remain temporarily in backup or disaster-recovery systems after deletion from active systems. Such copies are isolated from ordinary business use and are deleted or overwritten in accordance with our normal backup lifecycle, subject to applicable legal requirements. No specific backup-retention duration is represented here; the production lifecycle remains to be verified.
Termination of Mopbe alone does not automatically terminate another separately purchased EVDATI service. A broader account and shared data legitimately required for an active purchased service may remain in use under that service’s agreement. Mopbe-specific data no longer needed follows the retention policy. Ecosystem-wide termination applies only when the customer terminates that subscription, the agreement makes services inseparable, or cross-service termination for cause is legally permitted. Shared data is not destroyed merely because one module ends.
Customer may instruct return or deletion subject to lawful exceptions. Document exceptions, protect retained data, and on restoration reapply relevant deletion restrictions. A termination workflow, exception register and deletion evidence must be operational before policy activation.
Ecosystem and transfers
Cross-module access, synchronization, reuse or migration occurs only where technically implemented, purchased or otherwise authorized, consistent with customer instructions, permissions, configuration, applicable agreements and law. A shared EVDATI identity is a future architectural possibility, not a verified current Mopbe feature. Shared identity would not confer an entitlement to unpurchased modules. Same-entity internal processing is not an unrelated third-party disclosure; flows to other EVDATI entities or service providers must still be disclosed and lawfully safeguarded.
Map each receiving entity and country. Use legally required transfer mechanisms, supplementary safeguards and approvals; this document is not a substitute for executed transfer clauses.
Ownership and AI
Customer retains ownership of its Customer Data, including recipes, invoices, vendors, products, inventory, operational and sales records, uploaded files and, where supported, personnel, applicant, scheduling and timekeeping information. Customer grants EVDATI a limited license to host, copy, transmit and process that data only as necessary to provide, secure, support and improve purchased services under the agreement, Privacy Policy, DPA and law. This is not a transfer of ownership or an unrestricted right to commercialize proprietary information.
Processing data to deliver requested AI functionality is distinct from permitted de-identified service improvement and from training generalized, internal or external AI models on identifiable or proprietary Customer Data. No unrestricted model-training license is granted. [AI TRAINING/DATA USE CONFIRMATION REQUIRED] before any such training program or representation about provider retention/training is approved.
Liability and notices
The signed agreement’s lawful liability allocation applies without restricting mandatory data-subject rights or regulator remedies. Contact support@evdati.com. Operating locations: Orlando, Florida, United States and Kingston, Jamaica.
