Version 1.0 · Last updated: August 13, 2026
This Data Processing Agreement (“DPA”) forms part of the Master Services Agreement (the “Agreement”) between Migna Safety Solutions LLC(“Processor,” “Migna”) and the customer identified on the Order Form (“Controller,” “Customer”). Capitalized terms not defined here have the meaning given in the Agreement.
1.1 For personal information contained in worker and safety records that Customer and its Users submit to the Service (“Customer Personal Data”), Customer is the controller and Migna is the processor, processing only on Customer’s documented instructions.
1.2 Customer’s instructions are: (a) this DPA and the Agreement; (b) Customer’s use and configuration of the Service; and (c) any further written instructions Customer gives that are consistent with the Service. Migna will inform Customer if, in its reasonable opinion, an instruction violates applicable data-protection law.
1.3 This DPA applies to the extent Migna processes Customer Personal Data subject to applicable data-protection laws.
Migna will:
2.1 Purpose limitation. Process Customer Personal Data only to provide and support the Service and per Customer’s instructions, and not for its own purposes, not sell it, and not use it to train AI models.
2.2 Confidentiality. Ensure personnel authorized to process Customer Personal Data are bound by confidentiality obligations and access it only as needed.
2.3 Security. Implement and maintain the technical and organizational measures described in Annex II, appropriate to the risk.
2.4 Sub-processors. Use only the sub-processors listed in Annex III or others engaged under Section 4.
2.5 Assistance. Taking into account the nature of the processing, provide reasonable assistance to Customer for: (a) responding to data-subject requests (Section 3); (b) security, breach notification, and data-protection impact assessments; and (c) demonstrating compliance under Section 5.
2.6 Breach notification. Notify Customer without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data, with the information reasonably available to help Customer meet its own notification obligations.
2.7 Return or deletion. On termination or expiration, make Customer Personal Data available for export for thirty (30) days, then delete it, except where retention is required by law or reasonably needed for backups, security, or dispute resolution (with continued protection until deleted).
If Migna receives a request from a data subject (e.g., a worker) to exercise rights of access, correction, deletion, or restriction, Migna will refer the request to Customer and, taking into account the nature of the processing, reasonably assist Customer in responding. Customer, as controller, is responsible for responding to data-subject requests.
4.1 Customer authorizes Migna to engage the sub-processors listed in Annex III.
4.2 Migna will give Customer notice (to account admins and/or by updating the sub-processor list) before adding or replacing a sub-processor, at least 15 days in advance where practicable. Customer may object on reasonable data-protection grounds within 15 days; if the parties cannot resolve the objection, Customer may terminate the affected subscription and receive a pro-rata refund of prepaid, unused fees.
4.3 Migna remains responsible for its sub-processors’ performance of the obligations in this DPA.
Migna will make available information reasonably necessary to demonstrate compliance with this DPA and allow for audits by Customer or an auditor Customer mandates, no more than once per year (or after a breach), on reasonable prior notice, during business hours, subject to confidentiality and without unreasonably disrupting Migna’s operations. Migna may satisfy audit requests by providing its security documentation and sub-processors’ certifications where available.
Customer Personal Data is stored in the United States (see Annex I). If Migna transfers Customer Personal Data across borders in a way that requires a transfer mechanism under applicable law, the parties will put an appropriate mechanism in place.
This DPA is subject to the limitation-of-liability provisions of the Agreement. For data-protection matters, this DPA controls over any conflicting term of the Agreement.
| Subject matter | Provision of the Migna health & safety management Service |
|---|---|
| Duration | The Subscription Term, plus the 30-day export window and any legally required retention |
| Nature & purpose | Hosting, storing, processing, and displaying safety records; computing analytics/compliance; sending configured alerts and summaries; providing optional AI-assisted features; security and support |
| Categories of data subjects | Customer’s Users (administrators, members); Customer’s workers, employees, and on-site contractors; individuals named in safety records |
| Categories of personal data | Names, email addresses, phone numbers, roles/job titles, trades, employer/subcontractor, job-site assignments, preferred language; salted password hashes (Users); safety records that may include injury/illness details (OSHA 300/301), training/certification status, exposure-sampling results, and uploaded photos/documents; job-site addresses and coordinates; audit-log and technical logs |
| Special-category / sensitive data | Injury and illness information in incident and OSHA records is health-related. Customer should submit only what its safety and recordkeeping purposes require. |
| Frequency | Continuous, for the duration of the Subscription Term |
| Storage location | United States (hosting and database sub-processors, Annex III) |
Migna maintains administrative and technical safeguards appropriate to the Service, including:
A public demonstration instance is a separate installation with its own database, containing generated sample data only. It processes no Customer Data and is out of scope of this Agreement. Visitors share one limited account and the instance is wiped and reseeded daily; anything a visitor enters is visible to other visitors until then, and the demo states this on every screen.
| Sub-processor | Purpose | Location |
|---|---|---|
| Vercel Inc. | Application hosting, and file storage for uploaded documents and photos where enabled | United States |
| Neon Inc. | Database hosting & storage | United States |
| Anthropic PBC (Claude) | AI features (photo analysis, document reading, assistant, generated content). Inputs are not used to train models under Anthropic’s commercial terms. Only when the AI add-on is enabled. | United States |
| Resend (Plus Five Five, Inc.) | Transactional & notification email (password resets, reminders, summaries), if configured | United States |
| Twilio Inc. | SMS alerts, only if the SMS add-on is enabled | United States |
| Open-Meteo | Weather data, using job-site coordinates only | EU/US |
| U.S. National Weather Service | Severe-weather alerts, using job-site coordinates only | United States |
| Sentry (Functional Software, Inc.) | Error monitoring. Reports contain the page, the technical error and the signed-in account identifier | United States |
| OpenStreetMap Foundation | Map tiles and address geocoding. Receives the device IP and the coordinates or address text being looked up; no safety records | United Kingdom / EU |
Migna Safety Solutions LLC · Miami, FL · info@mignasafetysolutions.com