Last updated: July 16, 2026
Note: In case of any discrepancy between the English and translated versions, the English version shall prevail.
This Data Processing Addendum (DPA) forms part of the Tatsulok Terms of Service whenever Tatsulok processes personal data on behalf of a business customer whose use is subject to the EU GDPR, the UK GDPR, or similar data protection laws. For that personal data, the customer is the controller and Aquila Smart City Technologies Inc. (Tatsulok) is the processor. By using Tatsulok for business purposes subject to those laws, you accept this DPA; a countersigned copy is available on request from legal@tatsulok.com.
Tatsulok processes the workspace content the customer chooses to store or connect (files, threads, memory, integrations, and the account identifiers of team members) for one purpose: providing the Tatsulok service as described in the Terms of Service and the Privacy Policy. Data subjects are the customer's team members and the individuals appearing in the content the customer brings. Processing lasts for the duration of the customer's use of the service, plus the deletion schedule described below.
We process personal data only on the customer's documented instructions, which are: the Terms of Service, this DPA, and the customer's configuration and use of the product's features. We will inform the customer if we believe an instruction violates applicable data protection law.
We apply the measures described in the Privacy Policy's security section: TLS in transit on every connection, AES-256 at rest for files (Cloudflare R2) and application data (Convex), provider-managed encryption at rest for other processors, least-privilege and audit-logged production access, and zero-data-retention routing for AI requests as described in the Privacy Policy (prompts and outputs are not retained by inference endpoints; the routing provider may retain operational metadata such as token counts for billing and abuse prevention). Personnel with access to personal data are bound by confidentiality obligations.
The customer gives general authorization for the subprocessors listed in the Privacy Policy's processors section: OpenRouter and the inference endpoints it dispatches to under the data-retention restrictions described in the Privacy Policy, Cloudflare, Convex, WorkOS, Resend, and PostHog (Paddle acts as an independent controller for billing and is not a subprocessor). We announce material subprocessor changes in-product before they take effect. If the customer reasonably objects on data protection grounds and we cannot offer an alternative, the customer may terminate the affected service and export their workspace.
Personal data is processed in the United States (our processors) and may be accessed from the Philippines and Japan (our operating company). For transfers of EEA, UK, or Swiss personal data, the European Commission's Standard Contractual Clauses (2021, Module Two, controller to processor) are incorporated into this DPA by reference, together with the UK International Data Transfer Addendum for UK data; transfers to Japan are additionally covered by the EU adequacy decision for Japan. Where a US processor is certified under the EU-US Data Privacy Framework, we may also rely on that certification.
Taking into account the nature of the processing, we assist the customer in responding to data subject requests (access, rectification, erasure, portability, restriction, objection) through the product's export and deletion features and, where those do not suffice, through legal@tatsulok.com. We also assist with data protection impact assessments and consultations with supervisory authorities to the extent the required information is in our possession.
We notify the customer without undue delay after becoming aware of a personal data breach affecting the customer's personal data, and provide the information reasonably required for the customer to meet its own notification obligations.
The customer can export the full workspace at any time from Settings and can delete items or the entire account. On termination, account data is deleted from active systems on a defined schedule (a 30-day grace window, followed by erasure), except where retention is required by law.
On request, we make available the information reasonably necessary to demonstrate compliance with this DPA, including summaries of third-party security attestations available from our subprocessors, and we allow for audits within the limits of a multi-tenant SaaS service.
For questions about this DPA, contact legal@tatsulok.com. Aquila Smart City Technologies Inc.