Hoppa till innehållet
Logga inKom igång gratis

Personuppgiftsbiträdesavtal

Senast uppdaterad 28 september 2026

Det här dokumentet finns bara på engelska, och det är den engelska texten som gäller.

This addendum covers our processing of personal data on a workspace's behalf. It applies alongside the Terms of Service to every workspace, and needs no separate signature unless your organisation requires one.

1. Roles

For personal data inside a workspace, the organisation that owns the workspace is the controller and Taktoria LLC is the processor. Each party complies with the data protection law that applies to it.

Where we act as controller instead, meaning account records, billing, and the logs we keep to run the service, the Privacy Policy governs rather than this agreement.

2. Subject matter and duration

We process personal data to provide the apps a workspace has subscribed to, for as long as the workspace exists. Processing ends when the workspace is deleted or the agreement ends.

3. Categories of data and data subjects

Data subjects are the workspace's own people and anybody they invite in:

  • Members: name, email, profile picture, authentication records, and whatever they put in the apps: launches and their reviews, objectives, key results and check-ins, go links, memes and uploaded templates.
  • Event participants: a cookie token, an optional display name, the questions, votes and poll answers they submit, and when they joined and were last seen.
  • People named in the workspace's configuration: who created each API key (stored only as a hash), single sign-on and email domain settings, and who an admin removed, by whom and when.
  • Recipients of notifications: email address and the content of the message sent to them.

4. Our obligations

  • We process personal data only on the controller's documented instructions, which include using the service as it is built.
  • People with access to it are bound by confidentiality.
  • We keep appropriate technical and organisational measures, described in the security section below.
  • We assist the controller with data subject requests, impact assessments and breach notifications, so far as the service allows.
  • On request we delete or return the data at the end of the agreement, unless the law requires us to keep it.

5. Security

  • Data in transit is encrypted with TLS; data at rest is encrypted by the underlying providers.
  • Passwords are stored only as hashes. Two-factor authentication is available to every account.
  • Every query in the product is scoped to one workspace, and access to an app additionally requires a seat.
  • Administrative access to production is limited to the people who need it and is authenticated individually.

6. Sub-processors

The controller gives general authorisation for the sub-processors listed in the annex below. When we add or replace one, we update the annex here: the list on this page is always the current one, and the date at the top says when it last changed.

7. International transfers

Where a sub-processor processes personal data outside the United States, the transfer relies on the Standard Contractual Clauses or another mechanism recognised under applicable law.

8. Personal data breaches

We will notify the controller without undue delay, and in any case within 30 days of becoming aware of a personal data breach affecting their data, with what we know and what we are doing about it.

9. Audits

On reasonable notice and no more than once a year, we will make available the information needed to demonstrate compliance with this agreement, and submit to an audit conducted by the controller or an auditor they appoint, at the controller's cost.

10. Annex: sub-processors

This is the current list. Each of these does one job, and a workspace that does not use the feature does not reach the provider behind it.

  • Vercel: application hosting and content delivery, cookieless page analytics and performance measurement, and serving a workspace's own hostnames, which are added to the project through its API.
  • Cloudflare: transactional email, and object storage for uploaded pictures and Memegen templates.
  • PlanetScale: the managed MySQL database the product's records live in.
  • Stripe: payments, subscriptions and invoices. It receives the workspace's name and its owner's email address, and, for a Dory event that went over its capacity, the event's title and attendance on the invoice line.
  • Inngest: delivery of background jobs, including notification and digest emails.
  • Slack: only for a workspace that has connected it: the notifications it has asked us to post, and members' email addresses, to find them in Slack for a direct message.
  • Google: sign-in with a Google account, where a person chooses it or their workspace requires it; Google Analytics, for people signed in and for visitors who have opted in to it in the cookie notice; and Google reCAPTCHA Enterprise, which checks that the sign-in, sign-up, single sign-on, two-step and password reset pages, and Dory's join page and attendee actions, are being used by people rather than scripts, from what its script sees on the page and the token, IP address and user-agent our servers send it.
  • PostHog: product analytics, for people signed in and for visitors who have opted in to analytics in the cookie notice; and error reports, from the browser for the same people, and from our servers without any identifier.

11. Contact

Questions about this addendum, or a request for a signed copy: legal@taktoria.com.