This Data Processing Agreement (“DPA”) forms part of the Terms of Service between [[LEGAL ENTITY NAME, form & registered address]] (“Processor”, “TonWise”) and the customer (“Controller”, “you”), and applies where TonWise processes Personal Data on your behalf in providing the Service, to the extent the EU General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”) or equivalent data-protection laws apply.
For Personal Data you submit, or that we process on your behalf via the API, you act as Controller and TonWise acts as Processor. Where TonWise determines the purposes and means of processing (for example, for its own Telegram Bot users), it acts as an independent controller under the Privacy Policy.
We process Personal Data only to provide, secure, and support the Service, on your documented instructions (these Terms, this DPA, and your configuration and use of the API), and as required by law — in which case we will inform you unless legally prohibited. Processing details are in Annex 1.
Personnel authorized to process Personal Data are bound by appropriate confidentiality obligations.
We implement appropriate technical and organizational measures as described in Annex 2, taking into account the state of the art, costs, and the nature and risk of processing.
You authorize us to engage the sub-processors listed in Annex 3. We bind sub-processors to data-protection obligations no less protective than this DPA and remain responsible for their performance. We will give notice of intended changes and you may object on reasonable data-protection grounds.
Taking into account the nature of processing, we will assist you by appropriate measures to respond to requests from data subjects exercising their rights (access, rectification, erasure, restriction, portability, objection).
We will notify you without undue delay after becoming aware of a Personal Data breach affecting your data, with information reasonably available to help you meet your own notification obligations.
On termination, we will delete or return Personal Data processed on your behalf within [[N]] days, except where retention is required by law. Audit logs are retained for 90 days and backups are cycled out on a rolling basis.
Hosting and primary processing take place in the EU (DigitalOcean, Amsterdam / AMS3, Netherlands). Where a sub-processor processes Personal Data outside the EEA (for example, OpenAI in the United States), transfers are made under an appropriate safeguard such as the EU Standard Contractual Clauses. [[Confirm transfer mechanism / SCCs with counsel]].
We will make available information necessary to demonstrate compliance with Article 28 GDPR and allow for and contribute to audits, subject to reasonable confidentiality and frequency limits (for example, once per 12 months or following a breach).
Liability under this DPA is subject to the limitations in the Terms. In case of conflict between this DPA and the Terms regarding the processing of Personal Data, this DPA prevails.
| Sub-processor | Purpose | Location |
|---|---|---|
| DigitalOcean | Hosting / infrastructure | Amsterdam, NL (EU) |
| Cloudflare | CDN, TLS termination, DDoS protection | Global edge |
| TONAPI | TON blockchain data | [[confirm operator / location]] |
| OpenAI | AI-assisted analysis | United States |
| Telegram | Bot & Mini App delivery | [[confirm]] |
| TG Analytics | Anonymous usage statistics | [[confirm]] |
[[Confirm this list is complete and accurate before publishing; add a payment processor if/when card payments are activated]].