Data Processing and Customer Data Terms
The customer decides what data is submitted, why it is processed and who may access it. In those cases the customer is the controller and MorpheusOS is the processor.
Last updated 13 August 2026
Customer as controller
For most customer workflows, the customer determines what data is submitted to MorpheusOS, why it is processed, who may access it and what outputs are approved. In those cases, the customer acts as controller or business, and MorpheusOS acts as processor or service provider.
MorpheusOS as processor
MorpheusOS processes Customer Data to provide the service, maintain security, support users, troubleshoot issues, comply with law and perform agreed workflows.
Instructions
MorpheusOS processes Customer Data according to the customer’s instructions, these terms, product settings, signed agreements and applicable law.
Confidentiality and access
Personnel and subprocessors with access to Customer Data must be subject to confidentiality obligations and access controls appropriate to their role.
Access within a customer instance is controlled by organisation roles and workspace-level permissions. Certain destructive or sensitive administrative actions require fresh step-up verification.
Deletion and export
Customers may request export or deletion of Customer Data, subject to technical feasibility, security, legal obligations, backup retention and signed agreement terms.
Subprocessors
MorpheusOS may use subprocessors to deliver the service. Current subprocessors are listed on Security and subprocessors.
We will give at least 30 days’ notice before a new subprocessor begins processing Customer Data, by updating that page and notifying the contact on your account. You may object on reasonable data-protection grounds, and we will work with you to resolve it.
