LogProductCareers
OverviewTerms of ServicePrivacy PolicyData Processing AddendumReport illegal contentSubprocessors

Tonk Data Processing Addendum

Version 1.0 — effective 28 August 2026

This Data Processing Addendum (DPA) forms part of the Tonk Terms of Service or another written agreement that refers to it (the Agreement) between Tonk Labs Limited, company number 14685404, of 64 Nile Street, London, England, N1 7SR (Tonk) and the business customer using the Service (Customer).

This DPA applies automatically where Tonk processes Customer Personal Data as Customer's processor. An individual using Tonk only for personal or household purposes is not a Customer for this DPA.

1. Definitions

In this DPA:

  • Applicable Data Protection Law means the data-protection and privacy law applicable to processing under the Agreement, including, where applicable, the UK GDPR, Data Protection Act 2018, EU GDPR and national law implementing or supplementing them;
  • Customer Personal Data means personal data contained in Space Content that Tonk processes on Customer's behalf as a processor, excluding information for which Tonk acts as an independent controller;
  • EU GDPR means Regulation (EU) 2016/679;
  • Restricted Transfer means a transfer of personal data that requires an adequacy decision, standard contractual clauses or another transfer safeguard under Applicable Data Protection Law;
  • Security Incident means a personal-data breach affecting Customer Personal Data;
  • Standard Contractual Clauses or SCCs means the European Commission clauses adopted by Implementing Decision (EU) 2021/914, as amended or replaced; and
  • UK GDPR has the meaning given in section 3(10) of the Data Protection Act 2018.

The terms controller, data subject, personal data, personal-data breach, process, processor, special categories of personal data, subprocessor and supervisory authority have the meanings given by Applicable Data Protection Law. Other capitalised terms have the meanings given in the Agreement.

2. Roles and scope

  1. Customer is controller and Tonk is processor of Customer Personal Data, except where Customer is itself a processor, in which case Tonk is Customer's subprocessor.
  2. Each party remains responsible for determining and complying with the legal duties that apply to it. The parties' labels do not override their factual roles under Applicable Data Protection Law.
  3. Tonk acts as an independent controller only where it genuinely determines separate purposes and essential means, which may include account administration, authentication, billing, Service metering, compliance with Tonk's own legal duties and establishment, exercise or defence of claims. Security, fraud prevention or content-policy work performed solely to provide the contracted processing remains processor activity; related processing for Tonk's genuinely independent safety, legal or claims purposes is controller activity described in the Privacy Policy.
  4. The subject matter, duration, nature and purpose of the processing, and the types of personal data and data subjects, are described in Annex 1.
  5. Customer must ensure that its instructions and use of the Service comply with Applicable Data Protection Law. Customer is responsible for its privacy notices, lawful bases, data-subject relationships, configuration choices and the accuracy, quality and lawfulness of Customer Personal Data.

3. Instructions

  1. Tonk will process Customer Personal Data only on Customer's documented instructions, including the Agreement, this DPA and Customer's use and configuration of the Service, or as required by applicable law and permitted under Applicable Data Protection Law.
  2. Customer instructs Tonk to process Customer Personal Data to provide the Service, enable user-directed sharing and collaboration, apply Customer's configuration and permissions, provide authorised support, maintain security, delete or return data as described in this DPA, and engage approved subprocessors for those purposes.
  3. Customer may give an additional instruction through a feature of the Service or an authorised support request. Tonk is not required to follow an instruction that is outside the Service, technically impracticable, inconsistent with the Agreement or unlawful. Additional work may require written agreement on scope, fees and timing.
  4. If Tonk believes an instruction infringes Applicable Data Protection Law, it will inform Customer unless law prohibits that notice. Tonk may suspend the affected processing until the parties resolve the issue.
  5. If law requires Tonk to process Customer Personal Data other than on Customer's instructions, Tonk will inform Customer of the legal requirement before processing unless law prohibits that notice on important grounds of public interest.

4. Restricted data and Customer safeguards

  1. The self-service Service is not designed or approved for special-category data, children's data, criminal-offence data, health records, biometric identifiers used for identification, precise financial-account credentials or other highly sensitive or regulated personal data. Customer must not submit that data unless Tonk has expressly agreed in a separate signed document.
  2. Customer must use appropriate access controls, protect keys and share links, limit access to authorised people and processes, and maintain any independent backups appropriate to its risk.
  3. Customer must not instruct Tonk to disclose Customer Personal Data to a person who lacks authority or to use it for an unlawful purpose.
  4. If Customer becomes aware that restricted data has been submitted contrary to the Agreement, it must take reasonable steps to remove or secure it and notify Tonk where assistance is required.

5. Confidentiality and personnel

  1. Tonk will ensure that people authorised to process Customer Personal Data are bound by an appropriate duty of confidentiality and receive instructions appropriate to their role.
  2. Tonk will limit personnel access to what is reasonably necessary for the relevant function.
  3. Tonk personnel do not ordinarily retrieve or inspect Space Content to provide routine hosting, synchronisation, backup, restoration, maintenance, diagnostics or support. Intentional access is limited to the circumstances described in the Agreement and Privacy Policy, including specifically authorised support, investigation and enforcement concerning illegal or restricted content or a Terms breach, and valid legal process.

6. Security

  1. Taking account of the state of the art, cost, nature, scope, context and purposes of processing and the risks to people, Tonk will implement and maintain appropriate technical and organisational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.
  2. The current categories of measures are described in Annex 2. Tonk may update the measures as technology and risks change, provided the overall level of protection is not materially reduced during the Agreement.
  3. Customer acknowledges that no online service is completely secure and that Customer's configuration, code, devices, keys, permissions and share links affect risk.

7. Subprocessors

  1. Customer gives Tonk general written authorisation to engage subprocessors to process Customer Personal Data for the purposes of the Agreement.
  2. Tonk will maintain a current list of subprocessors, their processing functions and relevant processing countries at https://tonk.network/legal/subprocessors or another location notified to Customer. The list need not disclose Tonk's detailed architecture.
  3. Tonk will give business customers at least 15 days' advance notice of a new subprocessor that will process Customer Personal Data, except where an urgent replacement is reasonably necessary for security, continuity or legal compliance. Notice may be given by email, through the Service or through a subscription mechanism on the subprocessor page.
  4. Customer may object during the notice period on reasonable and documented data-protection grounds. The parties will work in good faith to address the objection. If no reasonable solution is available, Tonk may choose not to appoint the subprocessor for Customer's data or Customer may stop using the affected feature and terminate the affected paid Service before the appointment takes effect. On termination under this paragraph, Tonk will refund prepaid fees for the unused terminated period, excluding usage already incurred.
  5. Tonk will impose in substance the same data-protection obligations on each subprocessor as the obligations imposed on Tonk by this DPA, to the extent relevant to the processing entrusted to that subprocessor.
  6. Tonk remains responsible to Customer for a subprocessor's performance of its data-protection obligations to the extent required by Applicable Data Protection Law.

8. International transfers

  1. Tonk may process Customer Personal Data in the United Kingdom, European Economic Area, United States and other countries identified through the subprocessor information.
  2. Tonk will not make a Restricted Transfer of Customer Personal Data unless it uses a mechanism permitted by Applicable Data Protection Law and applies any additional assessment and supplementary measure required by that law.
  3. The United Kingdom currently benefits from an EU adequacy decision. No SCCs are required solely for an EU-to-UK transfer while that decision applies.
  4. If Customer Personal Data protected by the EU GDPR is transferred to Tonk and an adequacy decision does not cover the transfer, the SCCs apply only where the transfer and Tonk's relevant processing fall within the formal scope of the then-current SCCs. Where they apply:
    • Module Two applies where Customer is controller and Tonk is processor;
    • Module Three applies where Customer is processor and Tonk is subprocessor;
    • the optional docking clause applies;
    • for Clause 9, Option 2 general written authorisation applies with the notice period in section 7;
    • the optional language in Clause 11 does not apply;
    • the governing law is the law of the EU Member State in which Customer is established or, if that law does not permit third-party beneficiary rights, the law of Ireland;
    • the courts are those specified by the SCCs by reference to that governing law; and
    • the parties are identified by the Agreement and their account or order-form contact information;
    • the competent supervisory authority is determined under Clause 13 by reference to Customer's establishment or EU representative or, where applicable, the location of affected data subjects; and
    • Annexes 1 and 2 and the current subprocessor list provide the processing, security and transfer details, supplemented by the relevant account or order form.
  5. If the then-current SCCs cannot lawfully be used because Tonk's relevant processing is itself subject to the EU GDPR or for another reason, the parties will execute or implement another valid transfer mechanism before making the Restricted Transfer.
  6. If UK transfer rules require a UK International Data Transfer Addendum, International Data Transfer Agreement or successor instrument, the parties will complete and execute the then-current instrument before making the Restricted Transfer. This DPA does not claim to complete mandatory tables or selections that have not actually been supplied.
  7. If a transfer mechanism is invalidated or materially changed, the parties will cooperate in good faith to implement a lawful replacement. Tonk may suspend the affected transfer or processing where no lawful mechanism is reasonably available.

9. Data-subject requests

  1. Taking account of the nature of processing, Tonk will provide reasonable assistance through appropriate technical and organisational measures to help Customer respond to requests to exercise data-protection rights.
  2. If Tonk receives a request relating to Customer Personal Data for which Customer is controller, Tonk will not independently respond except to acknowledge it, direct it to Customer, act on Customer's instruction or comply with law.
  3. Customer should use Service functionality to locate, access, correct, export, restrict or delete Customer Personal Data where reasonably possible.
  4. Tonk may charge reasonable fees agreed in advance for bespoke or disproportionate assistance outside standard Service functionality, except to the extent the assistance is required because Tonk breached this DPA.

10. Security Incidents

  1. Tonk will notify Customer without undue delay after becoming aware of a Security Incident affecting Customer Personal Data.
  2. The notice will provide information reasonably available to Tonk that Customer needs to meet its notification duties, which may include:
    • the nature of the incident;
    • categories and approximate numbers of affected people and records where known;
    • likely consequences;
    • measures taken or proposed to contain, investigate and mitigate it; and
    • a contact for further information.
  3. Tonk may provide information in phases as investigation continues. Notification is not an admission of fault or liability.
  4. Customer is responsible for deciding whether and how to notify supervisory authorities, affected people or other parties, except for notifications Tonk must make in its independent-controller capacity.
  5. Tonk will take reasonable steps to contain, investigate and mitigate the Security Incident and provide reasonable cooperation, taking account of the nature of processing and information available to it.
  6. Tonk's notice duties do not apply to incidents caused by Customer or its users, devices, code, keys, credentials, integrations or configuration unless the incident also constitutes a breach of Customer Personal Data processed by Tonk.

11. DPIAs, consultation and regulatory cooperation

  1. Taking account of the nature of processing and information available to Tonk, Tonk will provide reasonable assistance with Customer's data-protection impact assessments and prior consultation duties relating to use of the Service.
  2. Tonk will provide information reasonably necessary to demonstrate compliance with the processor obligations in this DPA and Applicable Data Protection Law.
  3. Each party will cooperate with a competent supervisory authority as required by law.
  4. Tonk may charge reasonable fees agreed in advance for substantial bespoke assistance, except to the extent required because Tonk breached this DPA.

12. Return and deletion

  1. During the Agreement, Customer may use available Service functionality to export or delete Customer Personal Data. Customer should export data it wishes to retain before termination.
  2. Following termination or Customer's valid deletion instruction, Tonk will, at Customer's choice, delete or return Customer Personal Data and delete existing processor copies, unless applicable law requires storage. Customer may exercise the return choice by using the available export functionality before termination or by requesting a return during the 30-day period after termination. If Customer does not request return during that period, Customer instructs Tonk to delete the data.
  3. Tonk will delete Customer Personal Data from active processor systems within 30 days after the relevant account or Space deletion, subject only to paragraph 5. Deletion may occur sooner and does not create a recovery period.
  4. Where information cannot immediately be isolated from a backup or immutable technical record, Tonk will protect it from ordinary use and delete or overwrite it in accordance with its normal technical cycle. Tonk does not maintain Customer Personal Data in backups for the purpose of extending retention.
  5. Tonk may retain processor copies of Customer Personal Data only to the extent applicable law requires storage and will limit processing to that legal requirement while continuing to protect the data. Separate account, security, moderation, transaction or claims records for which Tonk acts as independent controller are retained under the Privacy Policy and are not treated as processor copies merely because they relate to Customer.
  6. This section does not require Tonk to delete copies controlled by Customer, another user or a third party.

13. Information and audits

  1. On reasonable request not more than once in a 12-month period, Tonk will provide Customer with available information reasonably necessary to demonstrate compliance with this DPA. This may include security summaries, completed questionnaires, policies, third-party reports or certifications, subject to confidentiality, security and third-party restrictions. The annual limit does not apply following a material Service change affecting Customer Personal Data, credible evidence of non-compliance, a relevant Security Incident or a requirement of Customer as controller or a competent supervisory authority.
  2. If that information is insufficient for a reasonable compliance need, Customer may request a remote audit by an independent qualified auditor bound by confidentiality. An onsite audit is available only where required by a competent supervisory authority or Applicable Data Protection Law, or where a confirmed material Security Incident reasonably justifies it and remote evidence is insufficient.
  3. Audits must:
    • be arranged on at least 30 days' notice unless a regulator or urgent incident requires less;
    • occur during normal business hours;
    • avoid unreasonable disruption;
    • not access another customer's information, security secrets or information that Tonk cannot lawfully disclose; and
    • comply with Tonk's reasonable security procedures.
  4. Customer bears its audit costs and Tonk's reasonable costs of bespoke assistance, except where the audit identifies Tonk's material breach of this DPA. Fees, notice and remote-first procedures will not be applied in a way that makes an audit or inspection required by Article 28 or a supervisory authority practically unavailable.
  5. Nothing in this section restricts a supervisory authority's lawful powers.

14. Legal requests

  1. If Tonk receives a binding request from a court, law-enforcement body or public authority for Customer Personal Data, Tonk will assess the request and disclose only information it reasonably believes it must provide.
  2. Tonk will notify Customer before disclosure where legally permitted and reasonably practicable. Tonk may challenge a request it reasonably considers unlawful or disproportionate but is not obliged to litigate at its own expense.
  3. Where legally permitted, Tonk will document the request and response and apply safeguards appropriate to the circumstances.

15. Liability and priority

  1. The liability provisions and exclusions in the Agreement apply to this DPA, subject to liability and data-subject rights that cannot lawfully be limited.
  2. This DPA does not reduce either party's direct statutory responsibility to a data subject or supervisory authority.
  3. If documents conflict concerning processing of Customer Personal Data, the following priority applies: applicable SCCs or mandatory transfer terms; an order form or signed document that expressly amends a specified part of this DPA; this DPA; the Agreement; then other Service documentation.

16. Term and changes

  1. This DPA starts when Customer accepts or enters the Agreement and continues for as long as Tonk processes Customer Personal Data on Customer's behalf.
  2. Tonk may update this DPA where reasonably necessary to reflect a change in law, a binding regulatory requirement or a change to the Service, provided the update does not materially reduce protection of Customer Personal Data.
  3. Tonk will give advance notice of a material change where reasonably practicable. If a change materially reduces protection and is not required by law, Customer may terminate the affected paid Service before it takes effect and receive a refund of prepaid fees for the unused terminated period.

17. Governing law

Except where the SCCs or mandatory law require otherwise, this DPA is governed by the law and jurisdiction specified in the Agreement.

Annex 1 — Processing details

Subject matter

Hosting, relay, synchronisation, storage, backup, restoration, access control, user-directed sharing, support, security and deletion of Customer Personal Data through the Service.

Duration

For the term of the Agreement and the limited deletion, backup, legal-hold and security periods described in this DPA and the Privacy Policy.

Nature and purpose

Receiving, storing, organising, transmitting, synchronising, making available under Customer-controlled permissions, backing up, restoring, securing, troubleshooting where specifically authorised, deleting and otherwise processing Customer Personal Data to provide the Service on Customer's instructions.

Categories of data subjects

Depending on Customer's use:

  • Customer's users, personnel, contractors and representatives;
  • Customer's customers, prospective customers and suppliers;
  • collaborators and people invited to or mentioned in a Space; and
  • other people whose personal data Customer lawfully submits.

Types of personal data

Depending on Customer's use:

  • names, business contact details, usernames and identifiers;
  • account, membership, permission and collaboration information;
  • communications, documents, files, code, datasets and other Space Content;
  • technical, access, authorisation and usage information associated with Space Content; and
  • other ordinary personal data selected by Customer in accordance with the Agreement.

Restricted categories

The self-service Service is not approved for special-category data, children's data, criminal-offence data or the other highly sensitive or regulated information prohibited by the Agreement.

Processing frequency

Continuous or as initiated by Customer and its authorised users and processes during use of the Service.

Customer instructions and retention

As set out in the Agreement, this DPA, Customer's configuration and authorised support requests. The default deletion approach is described in section 12.

Subprocessors and transfers

The current information is maintained at https://tonk.network/legal/subprocessors or provided to Customer through the Service.

Annex 2 — Categories of security measures

Tonk will maintain the following categories of measures as appropriate to the Service, the processing and the risks. Tonk may change specific implementations as technology and risks change, provided the overall level of protection is not materially reduced during the Agreement:

  1. Access control: unique accounts, access limited according to role and need, controls for privileged authentication, and removal of access when no longer required.
  2. Encryption and authorisation: encryption in transit and at rest, cryptographic access controls and limited-duration credentials where appropriate. These measures do not make the Service end-to-end encrypted or zero-knowledge.
  3. Logging and review: authentication, administrative, security and exceptional content-access records where supported by the relevant system, with review appropriate to risk.
  4. System security: risk-based vulnerability and dependency management, security updates, secrets management, environment separation where appropriate, and protective configuration.
  5. Resilience: operational backup, recovery and restoration processes, monitoring and response to availability incidents. The Service is not a guaranteed archive and Customer remains responsible for appropriate independent backups.
  6. Incident management: an incident process covering escalation, containment, assessment, required notification and follow-up.
  7. Personnel measures: confidentiality obligations, need-to-know access, security awareness and role-appropriate instructions.
  8. Provider management: risk-based selection, appropriate contractual data-protection and confidentiality terms, transfer safeguards where required, and review proportionate to risk.
  9. Data lifecycle: data minimisation, retention controls, deletion processes and legal-hold restrictions.
  10. Physical and endpoint security: provider physical safeguards and protection of company-managed endpoints used for privileged access.
LinkedInTwitterBlueskyDiscordGitHubContact
Get new posts from Tonk when they land
RSS Feed
Privacy Policy

© 2026 Tonk Labs Limited. All rights reserved.