MH MediaHarvester Web Context API
DPA PROCESSING SECURITY

Data Processing Addendum

DPA readiness notes for customers who need processor/subprocessor, retention and security controls.

Roles

Controller and processor model

Customers decide which public or authorized sources are processed; MediaHarvester processes requests according to API instructions.

customer_instructions
Retention

Retention controls

Cache and generated asset retention are explicit controls; hosted production should expose organization-level deletion workflows.

DELETE /v1/compliance/data-retention/cache
Subprocessors

No hosted subprocessors locally

Local development does not connect hosted billing, CDN, search or LLM providers unless credentials are configured.

local_only
DPA status Implementation-ready template

A production DPA requires legal review, subprocessor inventory and customer agreement workflow.

This page documents technical readiness and does not claim a signed production DPA.

Trust resources