updated October 3, 2026
Data processing addendum
This addendum is part of the terms of service between an organization using Tokaware (the customer) and Playpals Studio, established in Tunisia, which runs Tokaware (we), and applies whenever we process personal data for the customer through the service. It is written to meet Article 28 of the GDPR and of the UK GDPR. Where it and the terms differ about personal data, this addendum decides.
Roles
The customer is the controller of the personal data it brings into the service through its organization, and we process it as its processor. For what we need to run our own business, such as accounts, billing and security logs, we are a controller, as the privacy policy says.
The processing
| Item | Details |
|---|---|
| Subject | Providing the service to the customer's organization |
| Duration | While the organization uses the service, then until deleted as below |
| Nature and purpose | Hosting; collecting from the organization's computers and linked accounts; computing and showing usage, costs and limits; sending notices; running the remote sessions the customer's people start |
| People concerned | The customer's members and invited people, and the people behind the AI accounts and computers connected to the organization |
| Personal data | Account details (email, name); AI account emails, plans and usage; computer details and activity (host names, projects, sessions, token counts, times); where the customer's settings and the computers allow it, the text of conversations, prompts, commands and images; billing contacts |
| Special categories | None intended, and the customer should not bring any in; conversations can hold whatever their authors typed |
Instructions
We process the data only on the customer's documented instructions: the terms, this addendum and what the customer sets in the service. If we believe an instruction breaks data protection law, we say so. If the law requires other processing of us, we tell the customer first, unless that law forbids it.
Confidentiality
Everyone we allow to process the data is bound to keep it confidential.
Security
We keep the technical and organizational measures on the security page, including encryption in transit and at rest, stored secrets only as hashes, roles checked on every request, limits on attempts, retention limits and restricted access to production. We may improve them, never lower their overall level.
Subprocessors
The customer authorizes the subprocessors on the subprocessors page. We bind each to data protection terms at least as protective as these, and remain responsible for them. We tell the organization's owners by email at least 30 days before adding or replacing one; if the customer objects on reasonable grounds and we cannot resolve it, the customer may end the affected service and have back what it prepaid for the time after.
Helping the customer
Through the service's own tools, and when asked, we help the customer answer people exercising their rights, and with security, breach notifications, impact assessments and consultations with authorities, as far as our part of the processing goes. A request we receive directly from someone we pass on to the customer.
Personal data breaches
We tell the customer without undue delay, and within 72 hours of becoming aware of a breach affecting its data, with what we know and what we are doing about it, and keep it informed.
Deletion and return
The customer's owner can download a copy of all of the organization's data at any time, and before it is deleted. When the organization is deleted, what it holds is deleted from the service at once; when the service ends, the customer can first ask for a copy of its data, and we delete it within 30 days. Either way it leaves our backups as they expire, unless the law requires us to keep it.
Audits
We make available the information needed to show that we meet this addendum: the security page, this document, and answers to reasonable security questionnaires. Where that is not enough, an Enterprise customer may audit us once a year, with 30 days' notice and at its own cost, through an independent auditor bound to confidentiality.
International transfers
Where the processing moves personal data out of the European Economic Area, the United Kingdom or Switzerland to a country without an adequacy decision, the Standard Contractual Clauses (module two, or module three for subprocessors) apply as if signed, with the UK addendum and the Swiss amendments where needed; the customer is the data exporter.
Liability
Each side's liability under this addendum is subject to the limits in the terms.
A signed copy
Customers who need this addendum signed can ask at support@tokaware.com.