Data processing addendum
This addendum is part of the Terms of Service between Argosity, LLC (“Argosity”) and a customer that uses the Service for business and is subject to a data protection law that requires a written processing agreement. It applies automatically to such a customer. No signature is needed. If you need a signed copy, email legal@tinycld.com.
1. Roles
For the personal data stored in the customer’s cloud, the customer is the controller and Argosity is the processor. For account, billing, and log data that Argosity collects to run the Service, Argosity is the controller, and the Privacy Policy applies.
2. Processing
- Subject matter. Hosting of the customer’s TinyCld cloud: mail, calendar, contacts, files, documents, boards, and any installed package.
- Duration. While the customer’s cloud exists, plus the deletion period in section 8.
- Nature and purpose. Storage, backup, transmission, indexing for the customer’s own search, spam and malware filtering, and display to the people the customer chooses.
- Data subjects. The customer’s members and guests, and anyone whose data they store or correspond with.
- Categories of data. Whatever the customer chooses to store. We do not restrict categories, and we do not inspect content to classify it.
3. Instructions
Argosity processes personal data only on the customer’s documented instructions. The Terms of Service, this addendum, and the customer’s use of the Service’s features are those instructions. If the law requires Argosity to process data otherwise, it tells the customer first unless the law forbids that. If Argosity believes an instruction breaks data protection law, it tells the customer.
4. Confidentiality
Only Argosity staff who need access to run the Service have it. Each is bound by a duty of confidentiality. Staff access the content of a cloud only in the cases listed in section 4 of the Privacy Policy.
5. Security
Argosity maintains at least these measures:
- TLS for every connection to the Service.
- Each cloud isolated in its own process and database.
- Production access limited to named staff, authenticated, and logged.
- Backups on the schedule of the customer’s plan.
- Automated scanning of mail for malware.
- Open-source software, so the customer can audit the code that handles its data.
6. Sub-processors
The customer authorizes the sub-processors below. Argosity binds each to data protection terms no weaker than this addendum and remains responsible for their performance.
| Provider | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Servers that run customer clouds and store their data and backups | United States data centers |
| Cloudflare, Inc. | DNS, TLS termination, and protection of traffic in transit | Global network; traffic is processed at the edge nearest the visitor |
| Stripe, Inc. | Payment processing and invoices for paid plans | United States |
| Resend, Inc. | Sending account and service email, and recording delivery and bounce status | United States |
| Postmark (ActiveCampaign, LLC) | Sending account and service email, and recording delivery and bounce status | United States |
| Functional Software, Inc. (Sentry) | Crash and error reports from the apps and the service, with user content removed | United States |
Argosity also processes data on hardware it owns in a facility it owns in Jefferson City, Missouri.
Argosity publishes a change to this list on this page, and emails cloud owners, at least 30 days before a new sub-processor processes customer data. A customer that objects on reasonable data protection grounds may cancel its cloud before the change takes effect. Cancellation is the sole remedy for an objection.
7. Assistance
The Service lets the customer answer most data subject requests itself: data can be read, corrected, exported through IMAP, CalDAV, CardDAV, and WebDAV, and deleted from within the cloud. Where the customer cannot, Argosity gives reasonable assistance, and with data protection impact assessments and consultations with a supervisory authority, taking into account the nature of the processing. If Argosity receives a request directly from a data subject, it refers the request to the customer.
8. Deletion and return
The customer may export its data at any time while the cloud exists. Within 10 days after the cloud ends, Argosity deletes the cloud, its data, and all backups, except data the law requires Argosity to keep, such as billing records.
9. Personal data breach
Argosity tells the customer without undue delay, and within 72 hours of confirming a personal data breach that affects the customer’s data. The notice describes the breach, the data and people likely affected, the likely consequences, and the measures taken or proposed. Argosity updates the notice as it learns more.
10. Audit
On request, no more than once a year, Argosity answers a reasonable written security questionnaire and provides documentation of the measures in section 5. Where a law requires more and the documentation is not enough, the parties agree on the scope, timing, and cost of a further audit by an independent auditor bound by confidentiality.
11. International transfers
All processing takes place in the United States, apart from Cloudflare’s handling of traffic in transit. A customer subject to the GDPR or UK GDPR transfers data to the United States by using the Service. [TRANSFER MECHANISM (STANDARD CONTRACTUAL CLAUSES) TO BE CONFIRMED].
12. Liability and precedence
The limits on liability in the Terms of Service apply to this addendum. If this addendum conflicts with the Terms of Service on the processing of personal data, this addendum prevails. Data protection law that cannot be contracted out of prevails over both.
13. Contact
Argosity, LLC
legal@tinycld.com