Data Processing Agreement
This DPA is part of the Terms of Service between your company (controller) and TON Creative Studios AB (org.nr 559029-8450), Västergatan 6D, 352 30 Växjö, Sweden (processor). It governs all personal data processed in your Handled workspace and is written to satisfy Article 28(3) GDPR. If this DPA conflicts with the Terms on a data-protection matter, this DPA prevails.
1. Details of processing
| Subject matter | Operation of the Handled workspace your company uses: routing, holding, and answering internal work items. |
|---|---|
| Duration | The term of the Terms of Service, plus the deletion window in section 8. |
| Nature and purpose | Storage, organisation, routing, retrieval, display and transmission, including notifications and messages through a customer-connected service where enabled; directory import into reviewable setup drafts; configured AI routing; explicitly requested conversation assistance and setup suggestions; and supervised delegated agent work, including authorized subject-help briefs. Applying setup and sending invitations are separate customer actions. Solely to provide the service; never for our own purposes, and never for training AI models. |
| Types of personal data | Names, work email addresses, profile photos, department and directory status, source identifiers (including Slack and Microsoft identifiers where connected), authorized message excerpts used for requested research and separately enabled Outlook checks, the content your people write (posts, replies, review notes), attachments, and operational records about that content (timestamps, ownership, routing decisions, audit events). Handled is not intended for special categories of data (Art. 9); your company instructs its users accordingly. |
| Categories of data subjects | Your company’s employees, contractors and imported profiles, including people not yet invited or joined, and any individuals mentioned in the content they write (for example customers referenced in a post). |
Optional subject-agent research: an administrator may permit sources for an agent; the responsible person separately authorizes their own accounts for the displayed agent subjects. Eligible new work can trigger bounded research using authorized context and connected-service excerpts. Encrypted findings and supporting evidence remain private to that person for up to 30 days, separate from ordinary Recent searches and shared agent records. Current ownership, consent and source access are checked before review, sharing and personal export. Revocation or loss of required access invalidates preparation. Only text explicitly reviewed and shared by the person becomes ordinary company work. Configured AI processing and transfers described in this agreement apply. Up to 50 preparation snapshots are retained separately from manual research; older already-shared preparations may be removed at capacity. Minimal attempt identifiers and timestamps remain until the corresponding run is removed to prevent automatic replay; mutation fingerprints expire after 30 days. Personal export and erasure cover these records. These feature-specific controls do not amend previously agreed erasure, recovery-copy or provider-retention commitments.
Optional Outlook checks: where available and separately enabled by the connected person, the service periodically reads bounded recent Inbox and Sent Items content to prepare private suggestions. Requested drafts use the suggestion’s supporting excerpt and context. Configured Anthropic processing, transfers and safeguards described in this agreement apply; this does not authorize automatic email sending or mailbox changes. Connecting a mailbox alone does not enable scheduled checks. Personal mailbox suggestions and their source-validated export are restricted to the connected person’s company membership, not made available to company administrators through these tools. Only content explicitly reviewed and published by the person becomes ordinary company work.
Active-service records for optional Outlook checks: encrypted pending suggestions, supporting excerpts, links and identifiers expire after 30 days. Keyed dismissal and expiry fingerprints contain no message text and expire after 90 days from their creation. Check records are retained for up to 90 days; encrypted source cursors are retained to continue enabled checks. Turning checks off clears pending suggestions, cursors and dismissal fingerprints. Disconnecting clears the mailbox’s derived records; it does not delete previously published company work. A person can export their pending suggestions when current source access can be verified; unverifiable evidence is omitted. Requested reply drafts are not automatically persisted. These feature-specific operational periods do not amend the agreed closure, erasure, recovery-copy or provider-retention commitments in section 8, or any previously accepted stronger rights.
2. Instructions
We process personal data only on your documented instructions — which this DPA, the Terms, and your company’s configuration and use of the product constitute — unless EU or member-state law requires otherwise, in which case we inform you before processing unless that law forbids it. We will tell you immediately if we believe an instruction infringes the GDPR.
3. Confidentiality
People authorised by us to process personal data are bound by contractual confidentiality obligations. Access to production data is limited to what operating the service requires and is logged.
4. Security
We implement the technical and organisational measures in Annex 1, taking into account the state of the art and the risks of the processing (Art. 32). We may update them, but never in a way that reduces the overall level of protection.
5. Sub-processors
Your company gives general authorisation for the sub-processors below. We impose data-protection obligations on each sub-processor equivalent to those in this DPA and remain fully liable to you for their performance.
Changes: we announce additions or replacements in the product and by email to your administrators at least 30 days before they take effect. You may object in writing on reasonable data-protection grounds within that period; if we cannot resolve the objection (for example by offering the service without the new sub-processor), you may terminate the affected service and receive a pro-rata refund of prepaid fees.
| Provider | Purpose | Location | Transfer arrangements and limitations |
|---|---|---|---|
| Neon (contracting entity per applicable terms) | PostgreSQL database | Data stored in the EU (eu-central-1) | SCCs in provider’s DPA for any non-EEA access |
| Neon object storage (S3-compatible) | Attachment files | EU | SCCs in provider’s DPA for any non-EEA access |
| Vercel Inc. | Web application hosting | Global edge; US | EU–US Data Privacy Framework; SCCs as fallback |
| Railway Corp. | API hosting | API processing in the EU (Netherlands) since 22 September 2026, including request content; before that in the United States. Primary database and attachment storage in the EU | Bilateral DPA naming TON Creative Studios AB received; account linkage, exporter annex completion and transfer assessment remain under review |
| Twilio SendGrid | Transactional and notification email (sign-in and invitation content; update notifications contain workflow metadata and a link, not post or reply text; previously delivered messages remain subject to provider retention) | Global; may process outside the EEA | EU–US Data Privacy Framework; SCCs as fallback |
| Anthropic (contracting entity depends on account and region) | Configured AI routing, explicitly requested conversation assistance and explicit personal research, separately enabled Outlook checks and requested reply drafts, configured advisory notes, reviewed setup suggestions and supervised delegated work, using the purpose-specific data described in the AI statement; not used for model training | US | Standard contractual clauses in the provider’s data-processing terms, with supplementary measures; EU–US Data Privacy Framework if and when the provider certifies |
| Slack Technologies (Salesforce) | Only if your company connects its own Slack workspace: receiving text explicitly submitted with /handled for a private preview; creating Public or Private work only after the sender confirms the audience, with optional Urgent delivery under the existing service rules; returning private routing confirmations and a generic private completion message with an authenticated Handled link. Optional administrator-approved recent-message retrieval for configured AI advisory notes; explicitly requested personal research of available older messages and limited thread context in approved channels, using the requesting person’s Slack access. Queries and excerpts may be sent to the configured AI provider. Questions, findings and supporting excerpts are retained in requester-only encrypted research history for up to 30 days, capped at 50 searches per person and company, subject to current source access and user deletion; they are not automatically posted as company work; a person may explicitly review and share text into a request or reply under its normal audience and retention rules; automatic notes and agent execution records may retain excerpts. No full Slack archive import or reply mirroring. | Per your company’s own Slack agreement | Your company’s direct controller relationship with Slack; Handled stores workspace and personal Slack credentials encrypted; provider processing and retention remain subject to the applicable terms and section 8 |
| Stripe Payments Europe | Billing and payment processing where your company pays for the service (payer contact and payment details; we do not store full card numbers) | Ireland (EU); US access under provider terms | SCCs in provider’s DPA for any non-EEA access |
The table records published provider arrangements, not confirmation that every account-specific agreement or transfer assessment is complete. Stripe may act as controller or processor depending on the payment activity. Customer-connected services operate under the customer’s own agreement for their service; they are not automatically Handled subprocessors for every activity. Google Workspace and Microsoft 365 directory access is customer-authorized and read-only. Optional Microsoft research requires separate personal read-only authorization and service configuration. Outlook research uses the connected person’s own work or school mailbox; Teams research is restricted by Handled to approved channels and current personal access. Microsoft’s provider permissions are disclosed during consent. Authorized question and message excerpts may be processed by the configured AI provider. Questions, findings and supporting excerpts are saved in requester-only encrypted research history for up to 30 days, capped at 50 searches per person and company. Expiry, deletion and access validation apply to this private history; explicitly shared content follows the retention of Handled work; personal credentials are encrypted and not supplied to background agents. Microsoft service processing remains under the customer’s Microsoft agreement.
How the AI features work, what they read, and what they can never do is described in the AI purpose statement.
6. Transfers
The primary database and attachment store are in the EU. The API processes requests in the EU (Netherlands, since 22 September 2026), and other providers may process data outside the EEA. Handled remains responsible for applicable lawful transfer arrangements and any required supplementary measures. Account-specific evidence is still being completed; listing a published DPA, certification or contractual clause is not confirmation that it applies to the Handled account. On request we provide available contractual information and identify outstanding verification. This disclosure does not waive applicable transfer requirements or existing obligations.
7. Assistance
Taking into account the nature of the processing, we assist your company:
Data-subject rights (Art. 12–23): authorized administrators can use the available account and export controls. JSON export includes authorized records and attachment metadata; file contents require separate authorized downloads. Where a request cannot be satisfied in-product, we assist within 10 business days of your written request. Requests about workspace processing are forwarded to your administrators and supported by us. We answer requests about processing for which Handled is controller ourselves. Applicable statutory response deadlines are unaffected.
Security, breach notification, DPIAs (Art. 32–36): we notify your administrators without undue delay, and in any case within 48 hours of becoming aware, of a personal-data breach affecting your workspace, with the information Art. 33(3) requires as it becomes available. We provide the information reasonably needed for your data-protection impact assessments and prior consultations, to the extent it concerns processing by Handled and is not otherwise available to you.
8. Return, deletion and retention
On termination, at your choice, your company exports (returns) its records from Settings and/or we delete them. We delete workspace personal data from the active Handled service within 30 days of account closure. Individual erasure requests have a separate 7-day grace period before the erasure process runs; deactivation alone does not instruct deletion. These periods do not extend a shorter applicable legal deadline. The Privacy Policy explains residual personal data in retained company work and how to request assistance.
Recovery archives and provider-held records have distinct purposes and periods, set out below. Handled will exclude erased records and files from new Handled-managed recovery archives and remove them from existing Handled-managed local and off-host archives no later than 35 days after active-service erasure. Copying or replacing an archive does not restart its original expiry. This bounded commitment applies to Handled-managed archives; it is not a promise that every provider-held record disappears within 35 days.
Recovery copies must be restricted from ordinary use. Before returning a restored copy to service, Handled must reapply all relevant subsequent erasure instructions and verify file cleanup. Enforcement across every recovery path has not been fully verified. Restored data cannot be returned to the production service until this safeguard is demonstrated.
Retention schedule — 15 September 2026
Published provider periods below describe the identified category, not a new guarantee covering every service or exception. Account-specific scope and unresolved periods are stated explicitly. Unresolved entries do not authorize indefinite retention: Handled must resolve the period and lawful scope before approving new customer use involving real personal data on the affected service. Handled remains responsible for its appointed sub-processors and for implementing lawful controller instructions.
| Category and purpose | Period or trigger | Scope and limitations |
|---|---|---|
| Handled-managed recovery archives | At most 35 days after active-service erasure; copies keep their original expiry. | Scheduled rotation targets 34 days from archive creation. Complete verification over the full retention period remains outstanding. |
| Neon database recovery history | Rolling 24-hour point-in-time recovery window. | The primary database is configured for a 24-hour recovery window. Separate exports and provider-internal copies have different retention periods. |
| Neon provider backups and attachment recovery copies | Published encrypted, versioned cloud-backup period: 30 days. | Neon security overview. Actual-account trigger and object-storage/beta coverage remain unconfirmed; do not apply the database period to attachment copies without evidence. |
| SendGrid email delivery and activity | Bodies: up to 72 hours for retries; scheduled messages: up to 6 days before sending; content samples: 7 days; activity/recipient metadata: 37 days; pseudonymized, reidentifiable events: up to 1 year; short links: 60 days if used. | SendGrid retention table. Periods follow each delivery/event category, not workspace closure. Activity-feed records are excluded from its recipient-erasure API. Suppressions require customer-managed deletion; a workspace-specific removal process remains to be verified. Legal holds may extend retention. |
| SendGrid backup customer content | Published DPA permits deletion within 1 year after termination of Handled’s provider agreement. | Twilio DPA, Schedule 1 §6. This is not a deadline measured from workspace closure or evidence that every message remains for a year. Workspace-level recovery-copy expiry remains unresolved. |
| Anthropic API processing and safety records | Ordinary inputs/outputs: within 30 days of receipt/generation. Flagged inputs/outputs: up to 2 years; safety classification scores: up to 7 years. Submitted feedback data: 5 years. | Commercial retention policy. Service-specific storage, covered-model safety requirements, contractual arrangements and legal exceptions can differ. Handled does not claim a zero-retention arrangement. The applicable account, model and service scope have not been fully confirmed. |
| Railway API hosting records and recovery copies | No numeric all-copy expiry established by the published DPA. | Railway DPA provides return/deletion obligations and protection of residual data. Log visibility is not physical erasure. Category-specific expiry remains unresolved. |
| Vercel hosting records and recovery copies | Deletion within a commercially reasonable time following provider-agreement termination, subject to legal retention. | Vercel DPA §12. This does not establish a numeric workspace-closure deadline; deployment/log and recovery-copy expiry remain unresolved. |
Where applicable law requires retention, we identify the data, legal requirement and period to your company unless legally prohibited, restrict use to that requirement and delete the data when it ends. Supplier safety or operational exceptions must be assessed for the actual purpose and lawful scope; listing them does not grant unrestricted use of workspace data. A provider-policy change does not automatically amend an agreed retention schedule.
On written request we confirm active-service deletion separately from final recovery-copy expiry, identify any remaining copies and their expiry or lawful retention criterion, and confirm completion after verification. We assist with relevant instructions for copies independently held by your company or recipients; those copies are outside Handled’s operational control.
9. Audits and information
We make available the information necessary to demonstrate compliance with Article 28. For routine reviews, once per calendar year on reasonable notice, we will answer your written security and compliance questions and provide available sub-processor certifications and audit summaries (including penetration-test summaries when available). Where an audit is reasonably necessary to verify compliance, you (or an independent auditor you mandate, not a competitor of ours) may audit the relevant processing on at least 20 business days’ notice (or as otherwise agreed in writing), during business hours, at most once per year, under confidentiality, at your cost, and without access to other customers’ data. Findings are shared with us and used only for compliance purposes. The ordinary frequency, advance notice and documentation-first process do not prevent an additional or accelerated audit reasonably necessary after a relevant incident, a material compliance concern or a competent authority’s request. Confidentiality arrangements and reasonable charges will not prevent exercise of applicable audit rights. A supervisory authority’s audit rights are unaffected.
10. General
This DPA is governed by the same law as the Terms. Liability follows the Terms. If any clause is invalid, the rest stands, and the invalid clause is replaced by what the parties would have agreed to achieve the same data-protection outcome.
Annex 1 — Technical and organisational measures
| Measure | Implementation |
|---|---|
| Tenant isolation | Per-company row-level security enforced in the database itself (PostgreSQL RLS); application code runs under a restricted database role scoped to one company per transaction. |
| Encryption in transit | Client–API connections use HTTPS. The production database connection enforces TLS certificate verification. This statement does not claim independent verification of every provider-internal hop. |
| Encryption at rest | Database and object storage encrypted at rest by the hosting provider; third-party workspace credentials (e.g. Slack bot tokens) additionally sealed with AES-256-GCM under a key held only in the API environment. |
| Authentication | Email-code sign-in; additional methods only when configured and enabled. Microsoft sign-in is currently unavailable and is separate from Microsoft directory authorization. Session tokens are stored as hashes; invitation and claim codes have short expiry. |
| Access control | In-product administrator, member and restricted collaborator permissions; production access limited to authorized operators. Verification of multi-factor authentication across all infrastructure accounts is not complete. |
| Logging and audit | Operational and work-action records support investigation and customer-visible history where exposed in the product. Not every infrastructure event is available in the customer interface. The records are not tamper-proof against a database administrator; application logging is designed to exclude message content. |
| Backups and deletion | Section 8 distinguishes active-service deletion, Handled-managed archives and provider-held categories. The retention schedule identifies unresolved retention scope. Recovery must not return erased data to service; complete enforcement is still being verified. |
| Data location | Primary data storage in the EU (database and attachments, eu-central-1). |
| AI boundaries | AI sub-processing limited to the specific content described in the AI purpose statement; no training on customer data; agents act only through reviewable proposals. |
| Development practice | Changes tested against an automated suite before deploy; database migrations reviewed; secrets kept outside source control in the relevant protected runtime or operating-system credential storage. |