1. Scope and parties
This Data Processing Addendum forms part of the Tokenforest Terms of service or another written agreement between Strateal Oy and the customer. It applies when we process personal data on the customer's behalf in connection with Tokenforest.
The customer is the controller and we are the processor, except where either party acts as an independent controller under applicable law. Terms such as controller, processor, personal data, processing and supervisory authority have the meanings given in the General Data Protection Regulation (EU) 2016/679.
If this Addendum conflicts with the Terms on processing customer personal data, this Addendum controls. The Terms continue to apply to all other matters.
2. Documented instructions
We will process customer personal data only to provide, secure and support Tokenforest; as described in this Addendum and the agreement; and as otherwise documented by the customer. The customer's account settings, support requests and use of service features are documented instructions.
If law requires other processing, we will tell the customer before processing unless the law forbids notice. We will notify the customer if, in our opinion, an instruction infringes applicable data-protection law and may pause that instruction while the parties resolve it.
3. Customer responsibilities
- The customer must have a lawful basis and give all required notices for the personal data it sends to Tokenforest.
- The customer must limit data to what is needed, manage member access and configure public visibility correctly.
- Tokenforest is not designed to receive prompts, model output, source code, file paths, repository names, special-category data or criminal-conviction data. The customer must not intentionally submit such data through usage events.
- The customer is responsible for responding to requests and instructions from its data subjects unless the agreement assigns a task to us.
4. Confidentiality and security
We will allow access to customer personal data only to people who need it for their work and who are bound by confidentiality duties. Taking account of the processing risks, We will maintain appropriate technical and organisational measures under Article 32 GDPR.
Measures used for Tokenforest include:
- encrypted network connections and restricted production access;
- role-based organisation access and authenticated service endpoints;
- one-way hashing for Tokenforest connector credentials;
- data minimisation that excludes prompts, output, code and repository details;
- logging, rate limits, backups and incident-response procedures; and
- service-provider review and staff confidentiality controls.
Security measures may change as technology and risks change, provided that protection is not materially reduced during a paid service term.
5. Subprocessors
The customer gives us general written authorisation to appoint subprocessors needed to run Tokenforest. These may include cloud application and database hosting, transactional email, authentication, payment-support, monitoring and tree-fulfilment providers. Current named providers include Resend for email, Stripe for billing and Ecologi for tree-funding fulfilment. Some providers, including Stripe, also act as independent controllers for parts of their regulated service.
We will bind each processor to data-protection duties that provide substantially the same protection as this Addendum. We remain responsible for our subprocessors' performance to the extent required by Article 28 GDPR.
We will give reasonable prior notice of a new processor that handles customer personal data. The customer may object on reasonable data-protection grounds within 14 days. The parties will work in good faith on a solution. If no reasonable solution is available, the customer may end the affected service without a penalty beyond charges already incurred.
6. International transfers
We will not transfer customer personal data outside the European Economic Area unless the transfer complies with Chapter V GDPR. Where needed, the parties incorporate the European Commission's 2021 standard contractual clauses, Module Two, with the customer as data exporter and us as data importer. For onward transfers, we will use an adequacy decision, standard contractual clauses or another lawful safeguard and apply supplementary measures where the transfer assessment calls for them.
7. Assistance and data-subject requests
Taking account of the nature of processing, we will give reasonable assistance so the customer can respond to requests to access, correct, delete, restrict, object to or port personal data. If we receive a request about customer-controlled data, we will direct the person to the customer unless law requires another response.
We will also give reasonable assistance with security obligations, breach notices, data-protection impact assessments and prior consultation, taking account of the information available to it. Work beyond standard service features may be charged at an agreed rate unless the need arises from our breach.
8. Personal-data breaches
We will notify the customer without undue delay after becoming aware of a personal-data breach affecting customer personal data. The notice will describe the known nature and likely consequences, affected data and people, mitigation taken, and a contact point. Information may be supplied in phases as it becomes available. We will take reasonable steps to contain, investigate and remedy the breach. Notice is not an admission of fault or liability.
9. Return and deletion
During the service term, the customer may access available account and usage records through Tokenforest. At the end of the service, we will delete or return customer personal data on request, unless law requires retention. Data may remain in protected rotating backups until overwritten and will not be used for another purpose. Billing and legal records held by us as an independent controller are governed by the Privacy policy.
10. Information and audits
We will provide information reasonably needed to show compliance with Article 28 GDPR. The customer should first use current security documentation, policies and written answers. If those are not enough, the customer may request one audit in a 12-month period, or an extra audit after a relevant breach or supervisory-authority request.
An audit must use an independent qualified auditor, give reasonable notice, protect other customers and confidential systems, and avoid disrupting the service. The customer bears its audit costs unless the audit finds a material breach by us.
11. Details of the processing
Subject matter and duration
Processing needed to provide Tokenforest for the term of the customer agreement, plus the limited deletion, backup and legal-retention periods described above.
Nature and purpose
Collection, recording, organisation, calculation, storage, retrieval, display, support, transmission to authorised providers and deletion of account, organisation, AI usage, subscription and tree-funding data.
Data subjects
Customer administrators, members, invited users and other people whose authorised AI usage events are submitted by the customer.
Personal-data categories
Names, work email addresses, account identifiers, membership roles, session and device data, connector metadata, model and tool names, token counts, timestamps, calculated emissions and tree progress, and support communications. Payment-card data is handled by Stripe and is not included in Tokenforest usage events.
12. Law and contact
The liability and governing-law terms in the customer agreement apply to this Addendum, subject to rights and remedies that cannot be limited by law. Data-protection questions and signed-copy requests can be sent to hello@tokenforest.ai.