Tabula · Legal
Data Processing Agreement
Last updated [EFFECTIVE_DATE]
This Data Processing Agreement (“DPA”) is entered into between [COMPANY_NAME] (“Processor”) and the customer (“Controller”) and forms part of the Terms of Service.
This DPA applies where Tabula processes personal data on behalf of a Controller (e.g., a business using Tabula for team operations).
Definitions
“Personal Data” means any information relating to an identified or identifiable natural person.
“Processing” means any operation performed on Personal Data.
“Controller” means the entity that determines the purposes and means of processing Personal Data.
“Processor” means the entity that processes Personal Data on behalf of the Controller (Tabula).
Subject Matter
Tabula processes Personal Data submitted by the Controller through use of the Service, including:
- User account data (email, name, profile)
- Canvas and scene data (tile positions, URLs)
- Usage analytics
Duration
This DPA remains in effect for as long as the underlying Terms of Service are in force.
Nature and Purpose of Processing
Tabula processes Personal Data to:
- Provide the Tabula Service
- Sync canvas data across devices
- Maintain user accounts
- Process payments (via LemonSqueezy)
- Provide customer support
Types of Personal Data Processed
- Contact information (email, name)
- Profile information (username, bio, avatar)
- Usage data (features used, session data)
- Canvas metadata (scene layouts, tile positions)
- Payment confirmation data (not card details)
Obligations of the Processor (Tabula)
We agree to:
- Process Personal Data only on documented instructions from the Controller (these Terms)
- Ensure persons authorized to process the data are bound by confidentiality obligations
- Implement appropriate technical and organizational security measures
- Not engage sub-processors without prior notice and the ability to object
- Assist the Controller in responding to data subject rights requests
- Delete or return all Personal Data upon termination of services
- Provide all necessary information to demonstrate compliance with GDPR Article 28
Sub-processors
We use the following sub-processors:
| Sub-processor | Location | Purpose |
|---|---|---|
| Supabase | USA (EU region available) | Database |
| Vercel | USA/Global | Hosting |
| LemonSqueezy | USA | Payments |
| Resend | USA | |
| Anthropic | USA | AI features |
We will notify you of any intended changes to sub-processors at least 14 days in advance.
Security Measures
We implement the following measures:
- TLS encryption for all data in transit
- AES-256 encryption for data at rest
- Row-level security and access controls
- Regular security assessments
- Employee access controls
Data Transfers
Where Personal Data is transferred outside the EEA, we rely on Standard Contractual Clauses or other appropriate transfer mechanisms.