Data Governance Policy
Data Governance
Our Commitment
Mitochondria Ventures B.V. builds agentic AI systems responsibly. We maintain high standards for data protection, ethical AI use, and regulatory compliance across all jurisdictions where we operate.
Data Architecture & Processing
How We Handle Your Data
No data storage and mastering - Mitochondria does not store or master your business data
Limited cloud processing - A portion of your business data is processed in our secure cloud instance for operations purposes and performance
Your Role vs Our Role
You are the Data Controller/Data Fiduciary - You determine what data is processed and why
We are the Data Processor - We process data only according to your instructions
You maintain compliance responsibility - including consent collection and privacy notices
Data Protection
Regulatory Compliance
GDPR compliant (EU 2016/679)
DPDP Act 2023 compliant (India)
Data minimisation by design
Right to erasure honoured within 30 days
Cross-border transfers follow SCCs (Standard Contractual Clauses)
Your Obligations
Obtain necessary end-user consents
Implement appropriate privacy notices
Respond to data subject/principal rights requests
Ensure a lawful basis for all processing
Maintain compliance with applicable laws
Data Security
Technical Measures
End-to-end encryption for all data in transit
Encryption at rest in cloud instances
Secure API implementations
Access control mechanisms
Audit logging capabilities
ISO 27001 principles followed
Annual security assessments
Incident response within 72 hours
Operational Security
Processing occurs in a private, secure environment
Cloud processing uses enterprise-grade infrastructure
No permanent data storage outside your systems
Complete audit trails are maintained
AI Ethics & Transparency
Our AI Principles
Human oversight maintained
Explainable AI decisions - every automated decision is traceable
No discriminatory algorithms
Regular bias audits
85% accuracy threshold for deployment
Transparency Commitments
Clients are informed when AI makes decisions
Model limitations documented
No "black box" deployments
Decision logic available for review
Performance metrics are shared regularly
Third-Party Data Handling
Integration Security
Client maintains accounts with third parties (WhatsApp, databases, etc.)
We process data through your authorised integrations only
No data sharing with unauthorised third parties
Client is responsible for third-party compliance
Intellectual Property
Client warrants rights to all processed content
Mitochondria assumes no liability for third-party IP claims
Automated filtering was implemented where feasible
Organisational Governance
Review Schedule
Monthly security reviews during implementation
Quarterly compliance assessments
Annual policy updates
Continuous monitoring of regulatory changes
Client Rights
Even though Mitochondria doesn't store your data, you always have the right to:
Access - Understand what data is being processed
Rectification - Correct any inaccuracies in processing logic
Erasure - Stop all processing immediately
Portability - Export processing configurations
Object - Opt-out of specific automated decisions
Complain - Lodge complaints with supervisory authorities
Data Breach Protocol
Notification within 72 hours of awareness
Full cooperation in the investigation
Detailed incident report provided
Remediation support included
Contractual Safeguards
What We Guarantee
Processing only within agreed parameters
No unauthorised data retention
Security measures appropriate to risk
Cooperation with compliance audits
What You're Responsible For
Lawful basis for processing
End-user consent management
Privacy notice accuracy
Regulatory compliance in your jurisdiction
Contact Information
For data protection queries and security concerns, you can contact us.
This policy forms part of our contractual commitment to data protection. Specific terms in your agreement may provide additional protections (as, when and if applicable). In case of conflict, the more protective provision applies.
Our Commitment
Mitochondria Ventures B.V. builds agentic AI systems responsibly. We maintain high standards for data protection, ethical AI use, and regulatory compliance across all jurisdictions where we operate.
Data Architecture & Processing
How We Handle Your Data
No data storage and mastering - Mitochondria does not store or master your business data
Limited cloud processing - A portion of your business data is processed in our secure cloud instance for operations purposes and performance
Your Role vs Our Role
You are the Data Controller/Data Fiduciary - You determine what data is processed and why
We are the Data Processor - We process data only according to your instructions
You maintain compliance responsibility - including consent collection and privacy notices
Data Protection
Regulatory Compliance
GDPR compliant (EU 2016/679)
DPDP Act 2023 compliant (India)
Data minimisation by design
Right to erasure honoured within 30 days
Cross-border transfers follow SCCs (Standard Contractual Clauses)
Your Obligations
Obtain necessary end-user consents
Implement appropriate privacy notices
Respond to data subject/principal rights requests
Ensure a lawful basis for all processing
Maintain compliance with applicable laws
Data Security
Technical Measures
End-to-end encryption for all data in transit
Encryption at rest in cloud instances
Secure API implementations
Access control mechanisms
Audit logging capabilities
ISO 27001 principles followed
Annual security assessments
Incident response within 72 hours
Operational Security
Processing occurs in a private, secure environment
Cloud processing uses enterprise-grade infrastructure
No permanent data storage outside your systems
Complete audit trails are maintained
AI Ethics & Transparency
Our AI Principles
Human oversight maintained
Explainable AI decisions - every automated decision is traceable
No discriminatory algorithms
Regular bias audits
85% accuracy threshold for deployment
Transparency Commitments
Clients are informed when AI makes decisions
Model limitations documented
No "black box" deployments
Decision logic available for review
Performance metrics are shared regularly
Third-Party Data Handling
Integration Security
Client maintains accounts with third parties (WhatsApp, databases, etc.)
We process data through your authorised integrations only
No data sharing with unauthorised third parties
Client is responsible for third-party compliance
Intellectual Property
Client warrants rights to all processed content
Mitochondria assumes no liability for third-party IP claims
Automated filtering was implemented where feasible
Organisational Governance
Review Schedule
Monthly security reviews during implementation
Quarterly compliance assessments
Annual policy updates
Continuous monitoring of regulatory changes
Client Rights
Even though Mitochondria doesn't store your data, you always have the right to:
Access - Understand what data is being processed
Rectification - Correct any inaccuracies in processing logic
Erasure - Stop all processing immediately
Portability - Export processing configurations
Object - Opt-out of specific automated decisions
Complain - Lodge complaints with supervisory authorities
Data Breach Protocol
Notification within 72 hours of awareness
Full cooperation in the investigation
Detailed incident report provided
Remediation support included
Contractual Safeguards
What We Guarantee
Processing only within agreed parameters
No unauthorised data retention
Security measures appropriate to risk
Cooperation with compliance audits
What You're Responsible For
Lawful basis for processing
End-user consent management
Privacy notice accuracy
Regulatory compliance in your jurisdiction
Contact Information
For data protection queries and security concerns, you can contact us.
This policy forms part of our contractual commitment to data protection. Specific terms in your agreement may provide additional protections (as, when and if applicable). In case of conflict, the more protective provision applies.