Data Processing Addendum
This Data Processing Addendum ("DPA") forms part of the Terms of Service ("Terms") between Tonecast and the Customer. It applies where Tonecast processes Customer Personal Data on the Customer's behalf and that processing is subject to Data Protection Laws. For customers subject to the GDPR, it is incorporated into the Terms upon their acceptance, without the need for a separate signature. A countersigned copy is available on request at privacy@tonecast.io.
1. Definitions
Capitalised terms not defined in this DPA have the meaning given in the Terms.
- Data Protection Laws
- As applicable to the processing: Regulation (EU) 2016/679 ("GDPR"); Italian Legislative Decree 196/2003 (the Italian Privacy Code), as amended; the UK GDPR and the UK Data Protection Act 2018; the Swiss Federal Act on Data Protection ("FADP"); and any laws implementing or supplementing them.
- Customer Personal Data
- Personal data contained in Customer Data that Tonecast processes on behalf of the Customer.
- Sub-processor
- Any processor engaged by Tonecast to process Customer Personal Data.
- SCCs
- The standard contractual clauses annexed to Commission Implementing Decision (EU) 2021/914.
- UK Addendum
- The International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018 (version B1.0), as amended.
- Restricted Transfer
- A transfer of Customer Personal Data to a country that has not been recognised as providing an adequate level of protection under the applicable Data Protection Laws.
"Controller", "processor", "data subject", "personal data", "processing", "personal data breach" and "supervisory authority" have the meaning given in the GDPR.
2. Scope and roles
2.1 The Customer is the controller of Customer Personal Data, or a processor acting on behalf of its own clients (for example an agency). Tonecast is the Customer's processor or, in the second case, sub-processor. Where the Customer acts as a processor, it confirms that its instructions have been authorised by the relevant controller.
2.2 This DPA does not apply to data for which Tonecast is an independent controller, namely Account Data, Usage Data, Aggregated Data and Public Web Content held in Tonecast's own source index; that data is governed by the Privacy Policy. The analyses Tonecast produces for the Customer's campaigns, including analyses of Public Web Content in relation to the Customer's subject, are Campaign Data and fall within this DPA.
2.3 The subject matter, nature, purpose and duration of the processing, and the types of data and data subjects, are described in Annex I.
3. Instructions
3.1 Tonecast processes Customer Personal Data only on the Customer's documented instructions, including with regard to transfers to third countries. The Customer's instructions are the Terms, this DPA, the Customer's configuration and use of the Service (such as campaigns, prompts, selected engines and exports), and any other reasonable written instructions consistent with the Terms.
3.2 Tonecast may process Customer Personal Data otherwise only where required by Union or Member State law to which it is subject; in that case it informs the Customer before processing, unless that law prohibits it.
3.3 Tonecast informs the Customer immediately if, in its opinion, an instruction infringes Data Protection Laws. Tonecast is not obliged to carry out a legal review of the Customer's instructions.
3.4 The Customer instructs Tonecast to create Aggregated Data as described in the Terms. Once de-identified, Aggregated Data is not Customer Personal Data.
4. Customer obligations
4.1 The Customer is responsible for having a lawful basis for the processing it instructs, for providing any notices required towards data subjects, and for ensuring that its instructions comply with Data Protection Laws.
4.2 The Customer will not include in Customer Inputs special categories of personal data (Article 9 GDPR), personal data relating to criminal convictions and offences (Article 10 GDPR) or personal data of children. The Customer acknowledges that AI answers and Public Web Content about public figures may incidentally contain such data, and will not use the Service to analyse it in relation to individuals.
4.3 The Customer will run campaigns about a natural person only where that person is a public figure and only in relation to their public role, as set out in the Acceptable Use Policy.
4.4 The Customer is responsible for the security of its accounts, including the management of its Users and their roles.
5. Tonecast obligations
5.1 Confidentiality. Tonecast ensures that personnel authorised to process Customer Personal Data are bound by confidentiality obligations and access it only as needed to operate, maintain, secure and support the Service.
5.2 Security. Tonecast implements the technical and organisational measures described in Annex II, which are designed to ensure a level of security appropriate to the risk under Article 32 GDPR. Tonecast may update these measures, provided that the overall level of protection is not materially reduced.
5.3 Minimisation. Tonecast sends to AI Providers and search-data providers only the prompts and Customer Inputs that the sampling and analysis requested by the Customer require.
5.4 No other use. Tonecast does not sell Customer Personal Data and does not use it to train or evaluate machine-learning models, except to produce the Customer's own results or with the Customer's opt-in.
5.5 Records. Tonecast maintains a record of processing activities carried out on behalf of its customers as required by Article 30(2) GDPR.
6. Sub-processors
6.1 The Customer gives Tonecast a general written authorisation to engage Sub-processors. The Sub-processors listed on the sub-processors page (Annex III) at the date the Customer accepts the Terms are authorised.
6.2 Tonecast engages each Sub-processor under a written contract imposing data-protection obligations that provide at least the level of protection required by Article 28(4) GDPR and this DPA, to the extent applicable to the services the Sub-processor provides. Tonecast remains fully liable to the Customer for the performance of its Sub-processors' obligations.
6.3 Tonecast gives at least 30 days' notice before authorising any new or replacement Sub-processor to process Customer Personal Data, by updating the sub-processors page and informing the owners of the Customer's Organization by e-mail or in the Service.
6.4 The Customer may object to a new Sub-processor on reasonable grounds relating to data protection by writing to privacy@tonecast.io within the notice period. The parties will discuss the objection in good faith, and Tonecast may propose an alternative, such as not using that Sub-processor for the Customer's campaigns. If no solution is agreed within 30 days of the objection, the Customer may terminate the affected Subscription by written notice and receive a refund of the prepaid Fees for its unused part.
6.5 The Customer chooses which AI engines each campaign uses, within its Plan. Removing an engine from a campaign stops new prompts for that campaign from being sent to the corresponding AI Provider.
6.6 Where a Sub-processor must be replaced urgently for security or continuity reasons, Tonecast may do so and will notify the Customer as soon as reasonably practicable; the objection right in Section 6.4 applies.
7. Assistance
7.1 Data subject requests. Tonecast promptly forwards to the Customer any request from a data subject relating to Customer Personal Data and does not answer it except to redirect the data subject to the Customer. Taking into account the nature of the processing, Tonecast assists the Customer through appropriate technical and organisational measures, including the export features of the Service, in answering such requests.
7.2 Impact assessments. Tonecast provides reasonable assistance with data protection impact assessments and prior consultations with supervisory authorities that relate to the Service, taking into account the nature of the processing and the information available to it. Tonecast may charge reasonable costs for assistance that goes beyond the documentation it makes generally available.
7.3 Authority requests. Unless prohibited by law, Tonecast informs the Customer of any legally binding request by a public authority for access to Customer Personal Data.
8. Personal Data Breach
8.1 Tonecast notifies the Customer without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data.
8.2 The notification describes, to the extent known: the nature of the breach, including the categories and approximate number of data subjects and records concerned; its likely consequences; the measures taken or proposed to address it and mitigate its effects; and a contact point. Where not all information is available at once, Tonecast provides it in phases without undue further delay.
8.3 Tonecast takes reasonable steps to contain, investigate and mitigate the breach and cooperates with the Customer so that it can meet its own obligations to notify supervisory authorities and data subjects.
8.4 Notifications are sent to the e-mail addresses of the owners of the Customer's Organization. A notification is not an admission of fault. Unsuccessful attempts that do not compromise the security of Customer Personal Data, such as pings, port scans or failed sign-in attempts, are not breaches.
9. Audits and information
9.1 On request, Tonecast makes available the information necessary to demonstrate compliance with Article 28 GDPR, by providing: (a) this DPA and the documentation of its security measures; (b) answers to the Customer's reasonable security and privacy questionnaire, no more than once a year; and (c) where available, summaries of relevant third-party audit reports or certifications of Tonecast or its hosting provider.
9.2 If that information is not sufficient to demonstrate compliance, or where a supervisory authority requires it, or following a personal data breach affecting the Customer, the Customer may carry out an audit, including an on-site inspection, itself or through an independent auditor who is bound by confidentiality and is not a competitor of Tonecast. The Customer must give at least 30 days' written notice; audits take place no more than once in any 12 months (except where required by a supervisory authority or after a breach), during business hours, within a scope agreed in advance, without access to other customers' data and without disrupting the Service or compromising its security. The Customer bears its own costs and reimburses Tonecast's reasonable costs of supporting the audit.
9.3 For Sub-processors, Tonecast relies on their audit reports and certifications and makes available those it is permitted to share.
9.4 Audit information and findings are Tonecast's Confidential Information.
10. Return and deletion
10.1 During the term of the Terms, the Customer can export Customer Data at any time using the export features of the Service.
10.2 After the Subscription ends, Tonecast keeps Customer Personal Data for a 30-day Export Period, then deletes it from its active systems; copies in backups are overwritten within a further 30 days. On request, Tonecast confirms the deletion in writing.
10.3 Where Union or Member State law requires Tonecast to keep Customer Personal Data, Tonecast protects it and processes it only for the purpose required by that law.
10.4 The Customer may at any time ask Tonecast in writing to delete specific Customer Personal Data (for example a campaign); Tonecast deletes it within the timelines in Section 10.2.
11. International transfers
11.1 Tonecast hosts Customer Personal Data in the European Union. It makes Restricted Transfers only to the Sub-processors listed in Annex III and in compliance with Chapter V GDPR: on the basis of an adequacy decision (including the EU-US Data Privacy Framework for certified recipients) or of the SCCs, with supplementary measures where a transfer impact assessment shows they are needed.
11.2 For onward transfers to Sub-processors in countries without an adequacy decision, Tonecast, as data exporter, enters into the SCCs, Module Three (processor to processor), with each Sub-processor concerned.
11.3 To the extent the processing of Customer Personal Data between the Customer and Tonecast involves a Restricted Transfer, the SCCs are incorporated into this DPA by reference: Module Two (controller to processor) where the Customer is a controller; Module Three (processor to processor) where the Customer is a processor; and, where the Customer is established in a third country without an adequacy decision, Module Four (processor to controller) for Customer Personal Data returned by Tonecast to the Customer. For these purposes: clause 7 (docking) applies; under clause 9(a), option 2 (general written authorisation) applies with the notice period in Section 6.3; the optional wording of clause 11(a) does not apply; clause 13 is completed as in Annex I.C; under clause 17, the SCCs are governed by Italian law; under clause 18, disputes are resolved by the courts of Rome, Italy; and Annexes I, II and III of the SCCs are completed with the corresponding Annexes of this DPA.
11.4 For Restricted Transfers subject to the UK GDPR, the UK Addendum is incorporated into this DPA: Table 1 is completed with the details in Annex I.A; Table 2 with the modules and options in Section 11.3; Table 3 with the Annexes of this DPA; and, for Table 4, either party may end the UK Addendum as set out in its Section 19. Tonecast may also rely on the UK extension of the EU-US Data Privacy Framework for certified recipients.
11.5 For Restricted Transfers subject to the FADP, the SCCs apply with the adaptations required by Swiss law, including that the Swiss Federal Data Protection and Information Commissioner is the competent supervisory authority for such transfers.
11.6 If there is a conflict between the SCCs (or the UK Addendum) and this DPA or the Terms, the SCCs (or the UK Addendum) prevail.
12. Liability
Each party's liability under this DPA is subject to the limitations in Section 20 of the Terms, including the specific limit for data-protection claims in Section 20.4. Nothing in this DPA limits the rights of data subjects under the SCCs or Data Protection Laws.
13. Duration and precedence
13.1 This DPA applies for as long as Tonecast processes Customer Personal Data, including during the Export Period and until deletion.
13.2 For the processing of Customer Personal Data, this DPA prevails over the Terms. Tonecast may update this DPA to reflect changes in law or in its Sub-processors (following Section 6) or under Section 22 of the Terms, provided that the protection of Customer Personal Data is not reduced.
14. Governing law
This DPA is governed by the law and subject to the jurisdiction that govern the Terms (Italian law; courts of Rome, Italy), except where the SCCs or Data Protection Laws provide otherwise.
Annex I — Description of processing
A. Parties
Data exporter: the Customer, as identified by its Organization details in the Service. Role: controller or, where it acts for its own clients, processor. Activities: use of the Service under the Terms. Signature and date: acceptance of the Terms.
Data importer: Tonecast (VAT number IT18201491000), Via dei Compositori 85, 00128 Rome, Italy; contact: privacy@tonecast.io. Role: processor or sub-processor. Activities: provision of the Service. Signature and date: acceptance of the Terms by the Customer.
B. Description of the processing
| Categories of data subjects | (a) Individuals who are the subject of a campaign or are named in the Customer's subject profile, such as public figures, founders, executives and spokespeople, and representatives of competitors named in Customer Inputs; (b) individuals mentioned in AI answers sampled for the Customer's campaigns; (c) authors, publishers and individuals discussed in Public Web Content, to the extent analyses relating to them are stored as Campaign Data; (d) the Customer's personnel and Users, to the extent identified in Customer Data (for example in a fact sheet, or as the author of a correction). |
|---|---|
| Categories of personal data | Names, aliases and name variants; professional titles, roles and affiliations; statements, opinions and reviews contained in AI answers or public content, and analyses of their tone towards the subject; usernames and author names as published; URLs and publication dates; any personal data the Customer includes in prompts, fact sheets or files. |
| Sensitive data | None intended. AI answers or public content about public figures may incidentally reveal special categories of data (for example political opinions). Safeguards: no analysis of such data in relation to individuals, access limited to the Customer's Users and authorised Tonecast personnel, encryption in transit, and the deletion timelines in Section 10. |
| Frequency of transfer | Continuous, for the duration of the Terms, following each campaign's sampling cadence. |
| Nature of the processing | Collection through AI Provider APIs and open sources; storage; organisation; automated analysis (mention detection, tone, claim checks, citations, influence weighting); display; export; deletion. |
| Purpose | Providing the Service to the Customer under the Terms: sampling AI answers to the Customer's prompts, analysing them, and building the source graphs of the Customer's campaigns; support and security. |
| Duration and retention | For the duration of the Terms, plus the 30-day Export Period; backup copies are overwritten within a further 30 days. |
| Transfers to Sub-processors | Subject matter, nature and duration as described in Annex III and on the sub-processors page. |
C. Competent supervisory authority
Where the Customer is established in an EU Member State, the supervisory authority of that Member State. Where the Customer is not established in the EU but has appointed a representative under Article 27 GDPR, the authority of the Member State where the representative is established. Otherwise, the Italian Garante per la protezione dei dati personali.
Annex II — Technical and organisational security measures
Encryption
- Data in transit is encrypted with TLS between browsers and the Service and between the Service and the APIs of Sub-processors.
- Data at rest is encrypted by the storage encryption of the hosting provider.
- Passwords are stored only as salted, iterated hashes.
Access control for customers
- E-mail verification at sign-up.
- Role-based access control at Organization level (owner, billing, member) and Workspace level (owner, admin, editor, viewer); data is segregated by Workspace in the application logic.
- Session cookies that are HTTP-only and, in production, sent only over HTTPS; protection against cross-site request forgery.
Access control for Tonecast personnel
- Least privilege: access to production systems and Customer Data only for personnel who need it to operate and support the Service.
- Multi-factor authentication for staff access to infrastructure, code hosting and administrative tools.
- Access reviewed and removed promptly on a change of role or departure; confidentiality obligations for all personnel.
- API keys and other secrets kept outside the source code, in the configuration of the hosting environment, and rotated if compromise is suspected.
Logging and monitoring
- Application and infrastructure logs, kept for up to 90 days.
- Alerts to staff on failures of background tasks; error monitoring, where enabled, configured to limit the personal data it receives.
Availability and resilience
- Regular automated database backups, kept on a rolling basis for up to 30 days, with restore procedures.
- Hosting in data centres located in the European Union.
- Spending and rate limits on AI engine usage, checked before every call.
Secure development
- Changes are version-controlled and tested before deployment; automated tests run on synthetic data and never against production data or live third-party services.
- Separate development and production environments; regular dependency updates.
- Every score is versioned with the model that produced it, so results can be traced and re-computed.
Data minimisation
- Public Web Content is collected only from open sources and publicly accessible pages, never from closed platforms; the crawler identifies itself and honours robots.txt.
- Only page text and publication metadata are kept; prompts sent to AI Providers are limited to what sampling requires, and no Account Data is sent to them.
Vendor management, incidents and deletion
- Sub-processors are assessed for security and data protection before engagement and bound by data-processing terms; the list is public and changes are notified 30 days in advance.
- A documented procedure to detect, assess, contain and notify personal data breaches within the timelines of Section 8.
- Deletion of Customer Data at the end of the Subscription, as set out in Section 10.
Annex III — Sub-processors
The current list of Sub-processors, with their purpose, the data they process, their location and the transfer mechanism, is published on the sub-processors page, which forms part of this Annex. At the "Last updated" date it comprises: the hosting provider (EU), OpenAI, Anthropic, Google, Perplexity, DataForSEO, Brave Search, Stripe, the e-mail delivery provider and, only if enabled, Sentry.
Contact
TonecastVia dei Compositori 85, 00128 Rome, Italy
VAT number: IT18201491000
General contact: support@tonecast.io
Privacy contact: privacy@tonecast.io