Data Processing Addendum

Totalum, Inc.

Effective: · Version 2.0 · Binds users registered before that date from

How this addendum applies

This Data Processing Addendum (the “DPA”) forms part of the Terms of Service and applies automatically, without signature, to every customer whose use of the Service involves personal data inside a Project for which the customer is the controller or business and Totalum is the processor or service provider. Where this DPA and the Terms conflict on a data-protection matter, this DPA prevails; where this DPA and the Standard Contractual Clauses conflict, the Standard Contractual Clauses prevail.

1. Scope, parties and how this DPA applies

This DPA is entered into between Totalum, Inc., a corporation organized under the laws of the State of Delaware, United States of America, with notices to c/o Legalinc Corporate Services Inc., 131 Continental Drive, Suite 305, Newark, DE 19713, New Castle County, United States (“Totalum”, “we”), and the person or entity that holds the Totalum account under which a Project is created (“Customer”, “you”). It reflects the requirements of Article 28(3) of Regulation (EU) 2016/679 (the “GDPR”), of the UK GDPR and the Data Protection Act 2018, of the Swiss Federal Act on Data Protection, of Spanish Organic Law 3/2018 (the “LOPDGDD”), of the California Consumer Privacy Act and its regulations (the “CCPA”), of the other US state privacy laws that impose contract terms on processors and service providers, and, on request, of the Brazilian Lei Geral de Proteção de Dados (“LGPD”).

This DPA covers only Customer Personal Data as defined in Section 2: the personal data that you put into your Projects, that your Projects collect from their own users, or that we otherwise process on your behalf. It does not cover the personal data we process as an independent controller about you, your team members and the visitors of our own websites (account, billing, support, marketing and analytics data), which is governed by our Privacy Policy.

By creating a Project that processes personal data you accept this DPA on behalf of yourself and, if applicable, of the entity you represent. No signature is required; Section 18 explains how to obtain a signed copy for your own records or for your supervisory authority.

2. Definitions

  • “Customer Data”: all data, content, code, files and configuration that you or your Projects submit to, store in or generate through the Service, including the database contents and uploaded files of each Project.
  • “Customer Personal Data”: any personal data (information relating to an identified or identifiable natural person) contained in Customer Data, including personal data of your end users, customers, employees, visitors and any other data subjects listed in Annex I.
  • “Data Protection Laws”: all laws applicable to the processing of Customer Personal Data under this DPA, including the GDPR, the UK GDPR, the Swiss FADP, the LOPDGDD, the ePrivacy rules transposed in the Member States, the CCPA and the other US state privacy laws, the LGPD, and any successor legislation.
  • “Processing”, “controller”, “processor”, “data subject”, “personal-data breach”, “supervisory authority” and similar terms have the meaning given in the GDPR; “business”, “service provider”, “consumer”, “sell”, “share” and similar terms have the meaning given in the CCPA. References to a controller include a business, and references to a processor include a service provider, where a US state law applies.
  • “Sub-processor”: any third party engaged by Totalum to process Customer Personal Data on Totalum's behalf in providing the Service.
  • “Standard Contractual Clauses” or “SCCs”: the standard contractual clauses for the transfer of personal data to third countries adopted by Commission Implementing Decision (EU) 2021/914, available at EUR-Lex.
  • “UK Addendum”: the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018, version B1.0, in force from 21 March 2022.
  • “Service”, “Project”, “Terms”, “Order Form” and other capitalized terms not defined here have the meaning given in the Terms.

3. Roles of the parties

For Customer Personal Data, you are the controller (or business) and Totalum is the processor (or service provider). Where you act as a processor for a third party (for example, an agency building an app for its client, or a whitelabel partner serving its own customers), you are a processor, your client is the controller, and Totalum is your sub-processor; in that case you warrant that your own agreement with the controller authorizes you to engage Totalum on the terms of this DPA and to give us the instructions in it, and the SCC module referred to in Section 13 is Module 3.

You determine the purposes and means of the processing carried out by your Projects: what data they collect, from whom, why, for how long, and with which third-party services they share it. Totalum determines only the technical means strictly necessary to provide the Service, as described in the Terms and Annex II.

Totalum acts as an independent controller, not as your processor, for the account, identity, billing, credit, support, security-log, anti-fraud, product-analytics and marketing data described in the Privacy Policy, and for the metadata the Service records about how the Service itself is used (such as run timestamps, credit consumption and infrastructure metrics). Each party is separately responsible for its own compliance in its own role.

4. Processing on documented instructions

Totalum will process Customer Personal Data only on your documented instructions, including with regard to transfers to a third country or an international organization, unless required to do so by Union or Member State law (or another law) to which Totalum is subject; in that case Totalum will inform you of that legal requirement before processing, unless the law prohibits such information on important grounds of public interest.

Your documented instructions are:

  • the Terms, this DPA and any Order Form;
  • the configuration of your Projects, including the code the AI agent writes at your direction, the database schema, the integrations you enable and the domains you connect;
  • the prompts, commands, API calls and MCP requests you or your authorized users and agents submit through the Service; and
  • any further reasonable written instruction consistent with the Terms that you send to contacto@totalum.app.

Totalum will immediately inform you if, in its opinion, an instruction infringes Data Protection Laws; Totalum is not obliged to carry out a legal analysis of every instruction, and it may suspend execution of an instruction it reasonably believes to be unlawful until the matter is resolved. Totalum will not process Customer Personal Data for its own purposes, and in particular will not use Customer Personal Data to train, retrain or fine-tune any artificial-intelligence model, and requires the same commitment from its model providers.

5. Customer obligations

You are responsible, in your role as controller or as the processor acting for a controller, for:

  • having a valid legal basis for every processing of Customer Personal Data you carry out through the Service, and for the lawfulness of your instructions;
  • providing the privacy notice, cookie information and consents that your Projects must give to and obtain from their own users under the laws that apply to you, and for honouring the rights of your data subjects; the Service does not publish any notice on your behalf and our policies do not apply to your app's users;
  • the accuracy, quality and legality of Customer Personal Data and of the means by which you acquired it;
  • not submitting to the Service the categories of data that the Terms prohibit (Section 10.3 of the Terms), including protected health information subject to HIPAA, full payment-card numbers subject to PCI DSS, data subject to GLBA, criminal-record data, biometric identifiers and any other data subject to a specific legal regime, unless agreed with us in writing, and processing special categories of personal data only where you hold a valid condition under Article 9 of the GDPR or equivalent;
  • configuring your Projects securely: authentication, authorization, input validation, secret management, dependency updates and the security of any third-party service you connect, as set out in Sections 8 and 10 of the Terms;
  • carrying out any data-protection impact assessment, prior consultation, record of processing and appointment of a data-protection officer or representative that your own processing requires; and
  • informing your data subjects, where Data Protection Laws require it, that Customer Personal Data is processed by Totalum and its Sub-processors, including in the United States.

6. Confidentiality of personnel

Totalum ensures that every person it authorizes to process Customer Personal Data, whether an employee or a contractor, is bound by a contractual or statutory obligation of confidentiality, has received appropriate training on data protection and on the handling of AI systems, and accesses Customer Personal Data only to the extent necessary to provide, secure, maintain and support the Service or to comply with law. Totalum staff do not read the contents of your Projects in the ordinary course; access for support or incident response is logged and limited to what the task requires.

7. Security of processing

Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, Totalum implements and maintains the technical and organizational measures described in Annex II to ensure a level of security appropriate to the risk, as required by Article 32 of the GDPR and Article 28 of the LOPDGDD. Totalum may update those measures from time to time, provided the updates do not materially reduce the overall level of protection during the term of your subscription.

You acknowledge that the measures in Annex II relate to the Service itself. The security of the application code and configuration of your Projects, of the data flows you build, and of the third-party services you connect remains your responsibility, and you must assess whether the Service, together with your own measures, provides a level of security appropriate to the risk of your specific processing.

8. Sub-processors

8.1 General authorization

You give Totalum a general written authorization to engage Sub-processors to process Customer Personal Data, provided Totalum complies with this Section. The Sub-processors engaged at the effective date, with their location, function and transfer mechanism, are listed at https://www.totalum.app/legal/subprocessors (Annex III), and you accept them by accepting this DPA.

8.2 Notice of changes and right to object

Totalum will notify you by email to the address on your account at least 30 days before authorizing any new Sub-processor to process Customer Personal Data, or before replacing an existing one, and will update the list accordingly. Within that period you may object on reasonable, documented grounds relating to data protection by writing to contacto@totalum.app. Totalum will then use reasonable efforts to make available a change in the Service, or to recommend a configuration, that avoids the processing of Customer Personal Data by the new Sub-processor without unreasonably burdening you. If Totalum cannot do so within 30 days of your objection, you may terminate the affected Project or, if the Sub-processor concerns the whole Service, your subscription, without penalty and with a pro-rata refund of any prepaid fees for the unexpired period, by notice given before the new Sub-processor starts processing. Where an emergency replacement is required for security or availability reasons, Totalum will notify you as soon as reasonably practicable and the same objection right applies from that notice.

8.3 Flow-down and responsibility

Totalum imposes on each Sub-processor, by a written contract, data-protection obligations that are substantially the same as those in this DPA, in particular providing sufficient guarantees to implement appropriate technical and organizational measures, and, where the Sub-processor is located outside the EEA, UK or Switzerland, a valid transfer mechanism under Section 13. Totalum remains fully liable to you for the performance of each Sub-processor's obligations.

9. Assistance with data-subject requests, DPIAs and consultations

9.1 Data-subject requests

The Service gives you direct means to access, export, correct, restrict and delete Customer Personal Data in your Projects (database panel, API, export and deletion functions), which is the primary way in which Totalum assists you in responding to requests from data subjects. If a data subject sends a request directly to Totalum that concerns Customer Personal Data in your Projects, Totalum will not respond on the merits (other than to say that the request should be addressed to you) and will forward the request to you at the email address on your account within 5 business days of identifying you as the relevant controller. Where you cannot fulfil a request through the Service, Totalum will provide reasonable additional assistance on request, taking into account the nature of the processing, and may charge a reasonable fee for assistance that is manifestly excessive or that the Service does not otherwise provide.

9.2 Impact assessments and prior consultation

Taking into account the nature of the processing and the information available to it, Totalum will assist you in ensuring compliance with your obligations under Articles 32 to 36 of the GDPR (security, breach notification, data-protection impact assessments and prior consultation with a supervisory authority) and the corresponding provisions of other Data Protection Laws, by making available the information in this DPA, Annex II, the Sub-processor list and our security documentation, and by answering reasonable written questions about the Service. Totalum will also assist you, on request, with the risk assessments and cybersecurity documentation that US state privacy laws may require of you.

10. Personal-data breach notification

Totalum will notify you without undue delay, and in any event within 48 hours after confirming a personal-data breach affecting Customer Personal Data, by email to the address on your account and, where it is a critical incident, by every other contact channel you have provided. The notification will, to the extent the information is available at that time and otherwise in phases without further undue delay, (a) describe the nature of the breach, including where possible the categories and approximate number of data subjects and of records concerned; (b) give the name and contact details of the point of contact where more information can be obtained; (c) describe the likely consequences of the breach; and (d) describe the measures taken or proposed to address the breach, including, where appropriate, measures to mitigate its possible adverse effects. Totalum will cooperate with you and take the reasonable steps you direct to investigate, contain and remedy the breach.

You are responsible for deciding whether and how to notify your supervisory authority, the Attorney General of a US state, your own users or any other person, and for doing so within the deadlines that apply to you (for example 72 hours under Article 33 of the GDPR, 30 days under California Civil Code § 1798.82, 60 days under 6 Del. C. § 12B-102, or 3 business days under the LGPD). Totalum's notification to you is not an acknowledgement of fault or liability. Totalum will not notify your data subjects or your authorities directly unless required by law to do so, and will inform you if it is so required.

11. Return and deletion of Customer Personal Data

At any time during the term you can export the complete source code and database of each Project, and delete Customer Personal Data, using the Service. Upon termination of the Service or deletion of a Project, and in line with Regulation (EU) 2023/2854 (the Data Act) and Section 14 of the Terms, export remains available for a retrieval period of 30 days after the termination or the end of any transitional switching period. After that retrieval period Totalum will delete all Customer Personal Data, including copies held by Sub-processors, within 90 days, with backup media cycling out within the same period, unless Union, Member State, US or other applicable law requires Totalum to store the personal data for longer, in which case Totalum will keep it only for as long as that law requires, keep it isolated and protected, and continue to apply this DPA to it. Where you delete a Project yourself, deletion of its live data is immediate and backups cycle within the same 90-day window. Totalum will confirm deletion in writing on request.

12. Information and audits

Totalum will make available to you all information necessary to demonstrate compliance with the obligations laid down in Article 28 of the GDPR and this DPA, and will allow for and contribute to audits, including inspections, conducted by you or by another auditor mandated by you, as follows. Once every 12 months, and additionally after a personal-data breach affecting your Customer Personal Data, you may send Totalum a written security questionnaire, and Totalum will respond within 30 days with written answers and with the most recent third-party audit reports, certifications or attestations that it or its infrastructure providers hold. Where those written materials are not sufficient to demonstrate compliance, or where a supervisory authority requires it, you may conduct an on-site or remote audit of the systems and premises used to process your Customer Personal Data, limited to the purpose of verifying compliance with this DPA, no more than once in any 12-month period unless a breach has occurred, on at least 30 days' written notice, during normal business hours, at your cost, through personnel or an independent auditor bound by written confidentiality obligations and not a competitor of Totalum, in a manner that does not unreasonably interfere with Totalum's business or compromise the security or confidentiality of other customers' data. Totalum may require that audits of a Sub-processor's facilities be conducted through the Sub-processor's own audit programme. The parties will agree in advance on the scope, timing and duration of any audit and will treat the results as confidential information of both parties.

13. International transfers

13.1 Where processing takes place

The databases and build sandboxes of your Projects are hosted in datacenters in the European Union. Some Sub-processors, and Totalum itself as a company established in the United States, process Customer Personal Data in the United States or in other third countries; the location of each is stated in the Sub-processor list. Totalum will not transfer Customer Personal Data originating from the EEA, the United Kingdom or Switzerland to a third country without a transfer mechanism that is valid under the applicable Data Protection Laws.

13.2 EU-US Data Privacy Framework

Totalum, Inc. is not currently self-certified under the EU-US Data Privacy Framework. Transfers of Customer Personal Data to Totalum from the EEA, the UK and Switzerland therefore rely on the Standard Contractual Clauses described in Section 13.3, supplemented by the transfer impact assessment Totalum maintains and makes available on request. Several Sub-processors are themselves certified under the Data Privacy Framework, as noted in the Sub-processor list, and transfers to them may rely on that certification.

13.3 Standard Contractual Clauses (EU)

To the extent that Totalum's processing of Customer Personal Data involves a transfer subject to Chapter V of the GDPR from you (as data exporter) to Totalum (as data importer), the parties enter into the Standard Contractual Clauses, which are hereby incorporated into this DPA by reference and completed as follows:

  • Module: Module Two (transfer controller to processor) where you act as controller; Module Three (transfer processor to processor) where you act as processor on behalf of a controller.
  • Clause 7 (docking clause): included. Affiliates of yours may accede to the Clauses by agreeing to this DPA.
  • Clause 9 (use of sub-processors): Option 2, general written authorization, with a prior notice period of 30 days, as set out in Section 8.
  • Clause 11 (redress): the optional language allowing data subjects to lodge complaints with an independent dispute-resolution body is not included.
  • Clause 13 (supervision): the competent supervisory authority is the authority of the EU Member State in which you are established; if you are not established in the EU but are subject to the GDPR under Article 3(2), the competent authority is the Spanish Agencia Española de Protección de Datos.
  • Clause 17 (governing law): Option 1; the Clauses are governed by the law of Ireland.
  • Clause 18 (choice of forum and jurisdiction): disputes arising from the Clauses are resolved by the courts of Ireland.
  • Annex I.A (parties): data exporter: you, with the name, address and contact details on your account, role as stated above; data importer: Totalum, Inc., c/o Legalinc Corporate Services Inc., 131 Continental Drive, Suite 305, Newark, DE 19713, New Castle County, United States, contact contacto@totalum.app, role: processor.
  • Annex I.B (description of transfer): as set out in Annex I of this DPA.
  • Annex I.C (competent supervisory authority): as determined under Clause 13 above.
  • Annex II (technical and organizational measures): as set out in Annex II of this DPA.
  • Annex III (list of sub-processors): as set out in Annex III of this DPA.

Where Totalum transfers Customer Personal Data onward to a Sub-processor in a third country, Totalum enters into the Standard Contractual Clauses (Module Three) or relies on another valid mechanism with that Sub-processor, and the transfer impact assessment covers those onward transfers.

13.4 United Kingdom

For transfers of Customer Personal Data subject to the UK GDPR, the Standard Contractual Clauses as completed above apply as amended by the UK Addendum, which is incorporated by reference. Part 1 of the UK Addendum is completed as follows: Table 1 (parties) with the information in Clause Annex I.A above; Table 2 (selected SCCs, modules and clauses) as set out in Section 13.3, with the Addendum applying to the version of the Clauses in force on the date of transfer; Table 3 (appendix information) with Annexes I, II and III of this DPA; Table 4 (ending the Addendum when the Approved Addendum changes): neither party may end the Addendum on that basis, unless the change makes the Addendum unenforceable. For the purposes of the UK Addendum, the governing law and the courts under Clauses 17 and 18 are those of England and Wales.

13.5 Switzerland

For transfers of Customer Personal Data subject to the Swiss Federal Act on Data Protection, the Standard Contractual Clauses apply with the following amendments: references to the GDPR are read as references to the Swiss FADP; the competent supervisory authority under Clause 13 is the Swiss Federal Data Protection and Information Commissioner; the term “Member State” is read so as not to exclude data subjects in Switzerland from exercising their rights in their place of habitual residence; and the Clauses also protect the data of legal entities until the Swiss FADP no longer does so.

13.6 Brazil and other jurisdictions

For Customer Personal Data subject to the LGPD, Totalum will, on request to contacto@totalum.app, enter into the standard contractual clauses approved by the Brazilian Autoridade Nacional de Proteção de Dados (Resolution CD/ANPD 19/2024) with you. For Customer Personal Data subject to other laws that restrict international transfers (for example the laws of Argentina, Colombia, Peru, Japan or Quebec), Totalum will cooperate in good faith to put in place the contractual safeguards that those laws recognize.

14. California and US state privacy laws: service-provider terms

To the extent Customer Personal Data includes personal information of consumers protected by the CCPA, or personal data protected by the comprehensive privacy laws of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Iowa, Indiana, Tennessee, New Hampshire, New Jersey, Delaware, Kentucky, Maryland, Minnesota, Rhode Island, Nebraska or any other US state, Totalum acts as a service provider or processor and you act as the business or controller, and the following terms apply, in accordance with California Civil Code § 1798.100(d) and § 1798.140(ag) and section 7051 of the CCPA regulations (11 CCR § 7051):

  1. Totalum will not sell or share Customer Personal Data, as those terms are defined in the CCPA.
  2. Customer Personal Data is disclosed to Totalum only for the limited and specified business purposes of providing, securing, maintaining, supporting and improving the Service as described in the Terms and in Annex I, and Totalum will process it only for those purposes.
  3. Totalum will not retain, use or disclose Customer Personal Data for any purpose other than the business purposes specified in this DPA, including for any commercial purpose of its own, except as otherwise permitted by the CCPA and its regulations.
  4. Totalum will not retain, use or disclose Customer Personal Data outside the direct business relationship between you and Totalum.
  5. Totalum will not combine Customer Personal Data with personal information that it receives from or on behalf of another person, or that it collects from its own interaction with a consumer, except as expressly permitted by the CCPA regulations for a service provider.
  6. Totalum will comply with all applicable obligations under the CCPA and other US state privacy laws, and will provide the same level of privacy protection as those laws require of businesses and controllers, including by implementing reasonable security procedures and practices appropriate to the nature of the personal information.
  7. You have the right to take reasonable and appropriate steps to help ensure that Totalum uses Customer Personal Data in a manner consistent with your obligations under those laws, including through the questionnaire and audit rights in Section 12.
  8. Totalum will notify you at the address on your account, without undue delay and in any event within 10 business days, if it determines that it can no longer meet its obligations under the CCPA, other US state privacy laws or this DPA.
  9. Upon receiving such notice, or if you otherwise reasonably believe that Totalum is using Customer Personal Data in violation of this DPA, you have the right to take reasonable and appropriate steps to stop and remediate the unauthorized use, including by instructing Totalum to cease the processing concerned, and Totalum will comply with such instructions without undue delay.
  10. Totalum will cooperate with you in responding to verifiable consumer requests and will flow down obligations at least as protective as these to any Sub-processor that processes Customer Personal Data, by written contract, and will notify you of Sub-processors in accordance with Section 8.

Totalum certifies that it understands the restrictions in this Section and will comply with them. Totalum will process Customer Personal Data in a manner that is consistent with the standard of protection, deletion, purpose-limitation, security and confidentiality that these laws impose on processors, and will assist you, taking into account the nature of the processing and the information available, in meeting your obligations relating to consumer requests, security, breach notification and data-protection assessments. Nothing in this Section authorizes you to instruct Totalum to process Customer Personal Data in a manner that would itself violate those laws.

15. Spain: LOPDGDD provisions

Where Spanish law applies to the processing, this DPA is also the contract required by Article 28 of the GDPR and Article 33 of the LOPDGDD, which sets out the duties of the processor (encargado del tratamiento). In particular: Totalum will process Customer Personal Data solely for the purposes set out in Annex I and in accordance with your instructions; will not communicate the data to third parties except to the Sub-processors authorized under Section 8 or where a legal obligation requires it; will maintain the record of processing activities that Article 30 of the GDPR requires of processors; will apply the security measures in Annex II, taking into account the guidance of the Agencia Española de Protección de Datos; and will assist you in the exercise of data-subject rights. Where, after termination, Totalum must retain Customer Personal Data to meet a legal obligation or to respond to potential liabilities arising from the processing, it will keep the data blocked in the sense of Article 32 of the LOPDGDD, that is, accessible only to judges and courts, the Public Prosecutor or the competent public administrations, for the limitation period of those liabilities, and will delete it afterwards. Totalum's staff and contractors are subject to the duty of confidentiality in Article 5 of the LOPDGDD, which survives the end of their relationship with Totalum.

16. Liability

Each party's liability, taken together in the aggregate, arising out of or related to this DPA, the Standard Contractual Clauses and any other transfer mechanism, whether in contract, tort or under any other theory of liability, is subject to the exclusions and limitations of liability in Section 17 of the Terms, and any reference in that Section to liability of a party means the aggregate liability of that party under the Terms and this DPA together. Nothing in this Section limits either party's liability towards data subjects under Article 82 of the GDPR, under Clause 12 of the Standard Contractual Clauses or under any other provision of Data Protection Laws that cannot be limited by contract, or limits Totalum's liability for the acts of its Sub-processors under Section 8.3.

17. Precedence, changes and term

In the event of a conflict, the following order of precedence applies with regard to the processing of Customer Personal Data: first, the Standard Contractual Clauses (and the UK Addendum or Swiss amendments, where they apply); second, this DPA; third, the Terms and any Order Form; fourth, any other policy or documentation. Nothing in this DPA reduces the protection that the Standard Contractual Clauses give to data subjects.

Totalum may update this DPA to reflect changes in Data Protection Laws, in supervisory-authority guidance, in the Standard Contractual Clauses or in the Service, in the manner set out in Section 21 of the Terms. Updates will not reduce the level of protection of Customer Personal Data below what Data Protection Laws require. This DPA takes effect when you first create a Project that processes personal data and remains in force for as long as Totalum processes Customer Personal Data on your behalf, including during the retrieval and deletion periods in Section 11, and the provisions that by their nature should survive (in particular Sections 6, 11, 13, 14, 15 and 16) survive its termination.

18. Records and signed copies

Totalum keeps a record of the version of this DPA in force at each date, of the Sub-processor list and of the notices sent under Section 8. If you need a copy of this DPA signed by Totalum, for your own records, for your controller or for a supervisory authority, send a request from the email address on your account to contacto@totalum.app indicating your account email, your legal entity name and address, and the SCC module that applies to you; Totalum will return a countersigned PDF of the then-current version within 10 business days. A countersigned copy has the same content as this page; it does not modify this DPA.

Annex I: Description of the processing

This Annex serves as Annex I.B to the Standard Contractual Clauses and as Table 3 of the UK Addendum.
ItemDescription
Subject matterThe provision of the Totalum Service: an AI-assisted application builder with hosting, database, file storage, authentication, integrations, API and MCP access, in which the Customer builds, runs and publishes its own applications (Projects).
DurationThe term of the Customer's use of the Service for each Project, plus the retrieval period and the deletion period described in Section 11 of this DPA.
Nature of the processingCollection (through the Customer's Projects), storage, hosting, organization, structuring, retrieval, transmission, display, backup, export, erasure and, at the Customer's instruction, transformation of data by the AI agent and by the code the Customer's Projects execute.
Purpose of the processingTo provide, secure, maintain, support and improve the Service in accordance with the Terms, this DPA and the Customer's documented instructions, and for no other purpose. Totalum does not use Customer Personal Data for its own analytics, advertising, profiling or model training.
Categories of data subjectsThe Customer's end users and website visitors; the Customer's customers, prospects and suppliers; the Customer's employees, contractors and collaborators; and any other natural person whose personal data the Customer chooses to process through its Projects.
Categories of personal dataWhatever data the Customer chooses to submit or to have its Projects collect. Typically: identifiers (name, username, email address, telephone number, IP address, device identifiers); account and authentication data (credentials, session tokens); contact and postal data; commercial and transactional data (orders, invoices, payment references); content the data subject creates or uploads (messages, documents, images, audio); usage and technical data generated by the Project; and, where the Customer's Project provides it, location data.
Special categories of dataNone, unless the Customer decides to process them through its Projects; in that case the Customer warrants that it holds a valid condition under Article 9 of the GDPR (or equivalent) and applies the additional restrictions and safeguards its law requires. The categories of data prohibited by Section 10.3 of the Terms may not be processed without prior written agreement.
Frequency of the transferContinuous, for as long as the Customer uses the Service for the Project concerned.
RetentionFor the duration of the Project and thereafter as set out in Section 11 (30-day retrieval period, then deletion within 90 days including backups), subject to legal retention obligations and the blocking rule in Section 15.
Sub-processor transfersTo the Sub-processors listed in Annex III, for the functions and in the locations stated there, for the same subject matter, nature and duration.

Annex II: Technical and organizational security measures

Totalum implements the following measures for the systems it uses to process Customer Personal Data. They serve as Annex II to the Standard Contractual Clauses.

AreaMeasures
Encryption in transitAll connections between browsers, the Service, its internal components and its Sub-processors use HTTPS/TLS. Published Projects are served over TLS by Cloudflare; custom domains receive automatically provisioned certificates.
Encryption at restDisk-level encryption on the database, sandbox and object-storage infrastructure of Totalum's providers. Secrets and environment variables of Projects are stored encrypted and are never sent to the browser.
Tenant isolationEach Project organization has its own MongoDB database; data of different customers is never held in shared collections. Each Project is built in a dedicated, isolated virtual machine (sandbox) that is archived after about 6 hours of inactivity and destroyed about 2 days later; sandboxes are recreated from the stored source code and are not shared between customers.
Access controlRole-based access for the account owner and team members within the seat limits of the plan; API keys are individual, scoped to the account, revocable at any time and revoked automatically when the account closes; internal service-to-service calls are authenticated with HMAC signatures over timestamped, single-use nonces; no credential is exposed in client-side code.
AuthenticationEmail one-time codes, passwords stored with a salted adaptive hash, or Google sign-in; login attempts are logged with timestamp and IP for anomaly detection; automated sign-up validation and per-IP rate limits protect against abuse.
Logging and monitoringApplication, access and agent-run logs are kept for security, incident investigation and support; they are stored with access restricted to authorized personnel and retained for the periods in the Privacy Policy.
Backups and resilienceAutomated backups of Totalum's databases on a regular schedule, stored encrypted; published Projects are served from Cloudflare's global network with DDoS protection; a static snapshot of each published Project keeps it available while its sandbox is archived.
Secure developmentCode review, dependency management and staged deployment for the Service; separate development and production environments; the AI agent operates within the sandbox of a single Project and cannot reach another customer's data.
Sub-processor managementWritten contracts with every Sub-processor imposing confidentiality, security and data-protection obligations; transfer mechanisms under Section 13; the list in Annex III kept current with 30 days' notice of changes.
PersonnelConfidentiality obligations for all staff and contractors; least-privilege access; training on data protection and on the safe operation of AI systems; access to production data limited to what support and incident response require and logged.
Incident responseA documented process to detect, contain, assess and remediate security incidents, with customer notification under Section 10 within 48 hours of confirmation and cooperation with the customer's own notifications.
Data portability and deletionExport of source code and database in structured, commonly used, machine-readable formats at any time and during the retrieval period; verified deletion within 90 days after that, including backup cycling; blocking of data that must be retained under Section 15.
Physical securityDatabases and sandboxes are hosted in the datacenters of an ISO 27001-certified infrastructure provider in the European Union with access control, redundant power and network; object storage in Google Cloud and edge delivery in Cloudflare facilities with equivalent physical controls.

Totalum reviews these measures at least annually and after any significant incident. A description of the current measures, together with any third-party certifications of Totalum's providers, is available on request under Section 12.

Annex III: Sub-processors

The authorized Sub-processors, with their legal entity, location, function, the categories of Customer Personal Data they may process and the transfer mechanism that applies to each, are published and kept current at https://www.totalum.app/legal/subprocessors, which is incorporated into this DPA as Annex III and as Annex III to the Standard Contractual Clauses. Changes to that list are notified in accordance with Section 8.2.

Contact

Questions about this DPA, objections to Sub-processors, requests for a signed copy, transfer impact assessments or security documentation: contacto@totalum.app (privacy) and contacto@totalum.app (legal), or by post to Totalum, Inc., c/o Legalinc Corporate Services Inc., 131 Continental Drive, Suite 305, Newark, DE 19713, New Castle County, United States.

Related documents

This document can be printed or saved as a PDF from your browser.

© 2026 Totalum, Inc.