Data Processing Agreement
Last updated: 10 October 2026
This agreement is between Toniqe Labs Private Limited ("Toniqe", the processor) and the customer who holds a Toniqe account ("you", the controller). It applies automatically to every account as part of the Terms of Service; you do not need to sign it. If you need a signed copy for your records, email privacy@toniqe.com and we will return one.
It covers the personal data in material you submit for reports — your own, or your clients' if you are an agency — for which you decide the purpose and we act on your instructions. Data about you as our customer (your account) is covered by the Privacy Policy, where we are the controller.
1. What is processed, and why
| Item | Detail |
|---|---|
| Subject matter | Judging ad creatives against the landing page they point at, and researching public opinion of a brand. |
| Duration | While your account is active and for 30 days after a subscription lapses, or until you delete the account or the report. |
| Nature | Storing, reading with AI, visiting the landing page with a cloud browser, writing a report, emailing you about it. |
| Purpose | Delivering the report you asked for, and nothing else except as the Privacy Policy section 4 describes. |
| Types of personal data | Whatever appears in the ads and pages you submit: names, faces, testimonials, prices, and the like. Contact details of your clients if you enter them as client names. |
| Data subjects | People shown or named in the ads and pages; your clients’ staff; your own users. |
| Special categories | None expected. Do not submit material containing health, biometric or similar data unless the Privacy Policy allows it. |
2. Our obligations
Toniqe will:
- process the data only on your documented instructions, which are the Terms, this agreement and your use of the product, unless the law requires otherwise, in which case we tell you first where the law allows;
- make sure everyone with access is bound to confidentiality;
- keep the security measures in Annex 2;
- use only the subprocessors in Annex 1 and tell you of changes (section 4);
- help you answer requests from data subjects, with the self-service tools first (section 6) and by hand where needed;
- help you with security, breach notification and impact assessments, given what we know;
- delete or return the data at the end (section 7);
- give you the information needed to show these obligations are met, and allow audits (section 8).
3. Your obligations
You confirm you have the right to submit the material, including your clients' permission where it is theirs; that your instructions comply with the law that applies to you; and that you will not submit special-category data. You are responsible for what you ask Toniqe to judge.
4. Subprocessors
You give general authorisation for the subprocessors in Annex 1. We will email the account holder at least 30 days before adding one. If you object on reasonable data-protection grounds and we cannot resolve it, you may end your subscription and we will delete the data under section 7. Each subprocessor is bound by written terms at least as protective as this agreement, and we remain responsible for them.
5. International transfers
Toniqe is established in India and processes data in the United States (Annex 1). Where your data is subject to the GDPR, UK GDPR or Swiss law, transfers to us and to our subprocessors are made under the European Commission's Standard Contractual Clauses (Module Two, controller to processor), which are incorporated into this agreement, with the UK International Data Transfer Addendum where UK law applies and the Swiss amendments where Swiss law applies. For the clauses: the options chosen are docking permitted, general subprocessor authorisation with 30 days' notice, governing law and courts of Ireland (UK law and courts under the Addendum), and the annexes of the clauses are Annexes 1 and 2 here. We will provide a completed copy on request.
6. Data subject requests and breaches
If a person contacts us directly about data you control, we will pass the request to you without undue delay and not respond ourselves except to say so. Reports and uploads can be deleted from the product by you at any time, and your whole account from Settings.
If we become aware of a personal data breach affecting your data, we will notify the account holder without undue delay and within 48 hours of confirming it, with what we know: what happened, which data and roughly how many people, the likely consequences, what we have done, and a contact. We may give details in phases as we learn them.
7. Deletion and return
At the end of the service, or on your request, we delete the data within 30 days unless the law requires us to keep it. You can take a copy first: Settings downloads everything we hold. Subprocessors' copies expire on their own schedules (Annex 1); Google's within 48 hours; backups within 30 days.
8. Audit
We will answer written questions about our compliance within 30 days and share available security documentation. We hold no third-party certification yet and say so. If that is not enough, you may audit once a year, on 30 days' notice, during business hours, without disrupting the service, at your cost, excluding competitors as auditors, and under confidentiality.
9. Liability and term
Liability under this agreement is subject to the limits in the Terms of Service. This agreement lasts as long as we process data for you and ends when the data is deleted under section 7. If this agreement and the Terms conflict about personal data, this agreement wins.
Annex 1 — Subprocessors
Current as of 10 October 2026. This list is checked against our code on every release.
| Company | Purpose | Location |
|---|---|---|
| Clerk | Sign-in and account security | United States |
| Supabase | Database and file storage | United States |
| Vercel | Hosting | United States |
| Inngest | Background job processing | United States |
| Upstash | Request limiting | United States |
| Google (Gemini API) | AI processing | United States |
| Anthropic (Claude API) | AI processing | United States |
| Firecrawl | Web page capture | United States |
| Browserbase | Cloud browser | United States |
| ScreenshotOne | Page screenshots | See their policy |
| ScrapeCreators | Public ad library lookups | United States |
| Tavily | Web search | United States |
| Resend | Email delivery | United States |
| PostHog | Product analytics (with your consent) | United States |
| Figma | Design file access (only if you connect it) | United States |
| Google (favicon service) | Site icons | United States |
Annex 2 — Technical and organisational measures
Access
- Every database table is protected by row-level rules so one account can never read another’s data; the public share link exposes an allow-list of report fields only.
- Administrator actions that act as a customer or change a plan require a fresh identity check each time; a signed-in session alone is not enough.
- Secrets exist only on the production host, marked sensitive, and are not available to preview builds.
Encryption
- TLS on every connection; HTTP Strict Transport Security on.
- Encryption at rest at the database and file host (AES-256).
- Figma access tokens stored encrypted with a key held only in production.
Application security
- An enforced Content Security Policy, with violations logged.
- Cross-site request checks on every state-changing route.
- Rate limits on every paid route, per account and per plan.
- Dependencies monitored for known vulnerabilities; build actions pinned.
Data handling
- The page visit never enters personal details into a site and never sends account details to it.
- Copies at the AI vendors are for one job; Google’s expire within 48 hours; neither vendor trains on them.
- Account deletion is one transaction that removes reports, creatives, market reports, clients, share links, uploads, answers and the login, and it cannot be undone.
- A daily job deletes the work of lapsed accounts 30 days after the lapse, files included.
- Logs that record cost and service health hold no personal data.
Process
- Automated checks run on every release and fail the build when a protection above is removed from the code, or when a vendor appears in the code but not in Annex 1.
- Breach handling as in section 6.