Data Processing Agreement

Last updated: 10 October 2026

This agreement is between Toniqe Labs Private Limited ("Toniqe", the processor) and the customer who holds a Toniqe account ("you", the controller). It applies automatically to every account as part of the Terms of Service; you do not need to sign it. If you need a signed copy for your records, email privacy@toniqe.com and we will return one.

It covers the personal data in material you submit for reports — your own, or your clients' if you are an agency — for which you decide the purpose and we act on your instructions. Data about you as our customer (your account) is covered by the Privacy Policy, where we are the controller.

1. What is processed, and why

2. Our obligations

Toniqe will:

  • process the data only on your documented instructions, which are the Terms, this agreement and your use of the product, unless the law requires otherwise, in which case we tell you first where the law allows;
  • make sure everyone with access is bound to confidentiality;
  • keep the security measures in Annex 2;
  • use only the subprocessors in Annex 1 and tell you of changes (section 4);
  • help you answer requests from data subjects, with the self-service tools first (section 6) and by hand where needed;
  • help you with security, breach notification and impact assessments, given what we know;
  • delete or return the data at the end (section 7);
  • give you the information needed to show these obligations are met, and allow audits (section 8).

3. Your obligations

You confirm you have the right to submit the material, including your clients' permission where it is theirs; that your instructions comply with the law that applies to you; and that you will not submit special-category data. You are responsible for what you ask Toniqe to judge.

4. Subprocessors

You give general authorisation for the subprocessors in Annex 1. We will email the account holder at least 30 days before adding one. If you object on reasonable data-protection grounds and we cannot resolve it, you may end your subscription and we will delete the data under section 7. Each subprocessor is bound by written terms at least as protective as this agreement, and we remain responsible for them.

5. International transfers

Toniqe is established in India and processes data in the United States (Annex 1). Where your data is subject to the GDPR, UK GDPR or Swiss law, transfers to us and to our subprocessors are made under the European Commission's Standard Contractual Clauses (Module Two, controller to processor), which are incorporated into this agreement, with the UK International Data Transfer Addendum where UK law applies and the Swiss amendments where Swiss law applies. For the clauses: the options chosen are docking permitted, general subprocessor authorisation with 30 days' notice, governing law and courts of Ireland (UK law and courts under the Addendum), and the annexes of the clauses are Annexes 1 and 2 here. We will provide a completed copy on request.

6. Data subject requests and breaches

If a person contacts us directly about data you control, we will pass the request to you without undue delay and not respond ourselves except to say so. Reports and uploads can be deleted from the product by you at any time, and your whole account from Settings.

If we become aware of a personal data breach affecting your data, we will notify the account holder without undue delay and within 48 hours of confirming it, with what we know: what happened, which data and roughly how many people, the likely consequences, what we have done, and a contact. We may give details in phases as we learn them.

7. Deletion and return

At the end of the service, or on your request, we delete the data within 30 days unless the law requires us to keep it. You can take a copy first: Settings downloads everything we hold. Subprocessors' copies expire on their own schedules (Annex 1); Google's within 48 hours; backups within 30 days.

8. Audit

We will answer written questions about our compliance within 30 days and share available security documentation. We hold no third-party certification yet and say so. If that is not enough, you may audit once a year, on 30 days' notice, during business hours, without disrupting the service, at your cost, excluding competitors as auditors, and under confidentiality.

9. Liability and term

Liability under this agreement is subject to the limits in the Terms of Service. This agreement lasts as long as we process data for you and ends when the data is deleted under section 7. If this agreement and the Terms conflict about personal data, this agreement wins.

Annex 1 — Subprocessors

Current as of 10 October 2026. This list is checked against our code on every release.

Annex 2 — Technical and organisational measures

Access

  • Every database table is protected by row-level rules so one account can never read another’s data; the public share link exposes an allow-list of report fields only.
  • Administrator actions that act as a customer or change a plan require a fresh identity check each time; a signed-in session alone is not enough.
  • Secrets exist only on the production host, marked sensitive, and are not available to preview builds.

Encryption

  • TLS on every connection; HTTP Strict Transport Security on.
  • Encryption at rest at the database and file host (AES-256).
  • Figma access tokens stored encrypted with a key held only in production.

Application security

  • An enforced Content Security Policy, with violations logged.
  • Cross-site request checks on every state-changing route.
  • Rate limits on every paid route, per account and per plan.
  • Dependencies monitored for known vulnerabilities; build actions pinned.

Data handling

  • The page visit never enters personal details into a site and never sends account details to it.
  • Copies at the AI vendors are for one job; Google’s expire within 48 hours; neither vendor trains on them.
  • Account deletion is one transaction that removes reports, creatives, market reports, clients, share links, uploads, answers and the login, and it cannot be undone.
  • A daily job deletes the work of lapsed accounts 30 days after the lapse, files included.
  • Logs that record cost and service health hold no personal data.

Process

  • Automated checks run on every release and fail the build when a protection above is removed from the code, or when a vendor appears in the code but not in Annex 1.
  • Breach handling as in section 6.