How it works Live demo Pricing Security Help Contact Add to Chrome, free for 14 days
Legal

Data Processing Addendum

The terms that apply when Toser processes personal data on your behalf, under Article 28 of the GDPR.

Last updated: 10 October 2026

1.Scope and definitions#

1.1This Data Processing Addendum ("DPA") forms part of the Terms of Service between Toser and the customer. It applies to personal data contained in Your Content that Toser processes on the customer's behalf ("Customer Personal Data").

1.2"Controller", "processor", "data subject", "personal data", "processing" and "personal data breach" have the meanings given in Regulation (EU) 2016/679 (the GDPR).

1.3Annex I describes the Customer Personal Data and the processing.

2.Roles#

2.1The customer is the controller of Customer Personal Data. Toser is the processor.

2.2Where Toser processes personal data for its own purposes, as set out in the Privacy Policy, Toser acts as a controller for that data. This DPA does not apply to that processing.

3.Processing#

3.1Toser processes Customer Personal Data only to provide Toser to the customer, as described in Annex I, for the term of the agreement and any deletion period in section 11.

4.Instructions#

4.1Toser processes Customer Personal Data only on the customer's documented instructions. The Terms of Service, this DPA and the configuration choices the customer makes in Toser, such as retention settings, are those instructions.

4.2If Toser believes an instruction infringes the GDPR, it will tell the customer without undue delay.

5.Confidentiality#

5.1Toser ensures that the people authorised to process Customer Personal Data have committed to confidentiality, or are under an appropriate statutory duty of confidentiality.

6.Security#

6.1Toser implements the technical and organisational measures in Annex II. These take into account the nature, scope, context and purposes of processing, as Article 32 GDPR requires.

6.2Toser may update those measures, provided the update does not reduce the overall level of protection.

7.Sub-processors#

7.1The customer authorises Toser to engage the sub-processors listed in Annex III.

7.2Toser imposes data protection obligations on each sub-processor by contract. These obligations are equivalent to those in this DPA.

7.3Toser will give the customer at least [30] days' notice before adding or replacing a sub-processor. The customer may object on reasonable data protection grounds within that period. If the parties can't resolve the objection, the customer may end the affected service, as set out in the Terms of Service.

7.4Toser remains responsible to the customer for its sub-processors' performance of these obligations.

8.International transfers#

8.1Customer Personal Data is stored in the EU. Any processing by a sub-processor outside the EU is listed in Annex III.

8.2Transfers outside the European Economic Area are made under the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914, or another valid transfer mechanism.

9.Assistance#

9.1Taking into account the nature of the processing, Toser helps the customer, by appropriate technical and organisational measures, to respond to requests from data subjects under Chapter III of the GDPR.

9.2Toser helps the customer meet its obligations under Articles 32 to 36 GDPR, including security, breach notification, data protection impact assessments and prior consultation. This applies to the extent the customer needs it and Toser holds the relevant information.

10.Personal data breaches#

10.1Toser notifies the customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data.

10.2The notice includes the information reasonably available to Toser about the nature of the breach, the categories and approximate number of records affected, the likely consequences, and the measures taken or proposed.

11.Deletion and return#

11.1When the agreement ends, Toser deletes Customer Personal Data within [30] days, unless applicable law requires it to be kept.

11.2Backups containing Customer Personal Data are purged on a rolling basis, within [60] days.

11.3Where technically feasible, the customer may ask for the return of Customer Personal Data before it is deleted.

12.Audits and information#

12.1Toser makes available the information reasonably necessary to demonstrate compliance with this DPA. Toser allows and contributes to audits by the customer, or by an auditor the customer appoints. Audits take place once a year, on reasonable notice, during business hours, and at the customer's cost. An audit may also follow a personal data breach.

12.2Requests go through our contact page, choosing Security.

13.Liability and precedence#

13.1Liability under this DPA is subject to the limits in the Terms of Service.

13.2If this DPA conflicts with the Terms of Service on the processing of Customer Personal Data, this DPA prevails.

14.Governing law#

14.1This DPA is governed by the laws of the country where Toser's operating entity is registered, except where the Standard Contractual Clauses require otherwise.

Annex I: Processing details#

Description of processing
ItemDescription
Subject matter Providing Toser: storing policy documents, redacting personal data, generating cited Answers, and showing insights to the customer's team.
Duration For the term of the agreement, plus the deletion periods in section 11.
Nature and purpose Storing, organising and searching policy text; redacting personal data; generating Answers with an AI model; storing question logs in line with the customer's retention settings; managing accounts and billing.
Categories of data subjects The customer's team members (owners, admins and agents), and the customer's own customers, whose messages appear in questions.
Categories of personal data Account data (name, email, role, activity); Workspace content that contains personal data; question text after redaction; Answers and feedback; billing identifiers held by Stripe.
Special category data Not intended. The customer should not submit special category data. Toser's redaction does not cover it.
Retention Question logs are kept for the period the customer sets (7, 30, 90 or 365 days, or not stored). Section 11 governs deletion when the agreement ends.
Frequency Continuous, for as long as Toser is in use.

Annex II: Security measures#

  • Encryption in transit: HTTPS (TLS) for all traffic, with HTTP Strict Transport Security enabled.
  • Encryption at rest: AES-256, provided by Google Cloud.
  • Authentication: Firebase Authentication with email and password.
  • Authorisation: owner, admin and agent roles, with server-side permission checks on every request.
  • Database access: client applications have no direct access. Database security rules deny client access.
  • Workspace separation: data is stored per Workspace, and each request is checked against the caller's Workspace.
  • Data minimisation: automatic redaction of card numbers, IBANs, email addresses and phone numbers before AI processing and storage. When question storage is off, question text is not saved.
  • Retention controls: question logs are deleted automatically when they expire.
  • Extension permissions: the browser extension requests only the permissions it needs. It has no content scripts. Optional site access is requested only when you first use Insert into reply on a site.
  • Rate limiting: limits on answers per user and on public endpoints such as the contact form.
  • Staff access: [access controls and logging for Toser staff to be confirmed before signing].

Annex III: Sub-processors#

Authorised sub-processors
Sub-processorServiceLocation and safeguard
Google Cloud (Firebase) Hosting, database, authentication and API functions EU. Google Cloud data processing terms.
Anthropic AI inference (Claude) for generating Answers United States. Standard Contractual Clauses.
Stripe Payments and billing Global. Standard Contractual Clauses.