Download for Mac

Tabula · Legal

Data Processing Agreement

Last updated July 28, 2026

This Data Processing Agreement (“DPA”) is entered into between Maksim Kiselev (“Processor”) and the customer (“Controller”) and forms part of the Terms of Service.

This DPA applies where Tabula processes personal data on behalf of a Controller (e.g., a business using Tabula for team operations).

01

Definitions

“Personal Data” means any information relating to an identified or identifiable natural person.

“Processing” means any operation performed on Personal Data.

“Controller” means the entity that determines the purposes and means of processing Personal Data.

“Processor” means the entity that processes Personal Data on behalf of the Controller (Tabula).

02

Subject Matter

Tabula processes Personal Data submitted by the Controller through use of the Service, including:

  • User account data (email, name, profile)
  • Canvas and scene data (tile positions, URLs)
  • Usage analytics
03

Duration

This DPA remains in effect for as long as the underlying Terms of Service are in force.

04

Nature and Purpose of Processing

Tabula processes Personal Data to:

  • Provide the Tabula Service
  • Sync canvas data across devices
  • Maintain user accounts
  • Process payments (via Polar)
  • Provide customer support
05

Types of Personal Data Processed

  • Contact information (email, name)
  • Profile information (username, bio, avatar)
  • Usage data (features used, session data)
  • Canvas metadata (scene layouts, tile positions)
  • Payment confirmation data (not card details)
06

Obligations of the Processor (Tabula)

We agree to:

  • Process Personal Data only on documented instructions from the Controller (these Terms)
  • Ensure persons authorized to process the data are bound by confidentiality obligations
  • Implement appropriate technical and organizational security measures
  • Not engage sub-processors without prior notice and the ability to object
  • Assist the Controller in responding to data subject rights requests
  • Delete or return all Personal Data upon termination of services
  • Provide all necessary information to demonstrate compliance with GDPR Article 28
07

Sub-processors

We use the following sub-processors:

Sub-processorLocationPurpose
SupabaseUSA (EU region available)Database
VercelUSA/GlobalHosting
PolarUSAPayments
ResendUSAEmail
AnthropicUSAAI features

We will notify you of any intended changes to sub-processors at least 14 days in advance.

08

Security Measures

We implement the following measures:

  • TLS encryption for all data in transit
  • AES-256 encryption for data at rest
  • Row-level security and access controls
  • Regular security assessments
  • Employee access controls
09

Data Transfers

Where Personal Data is transferred outside the EEA, we rely on Standard Contractual Clauses or other appropriate transfer mechanisms.

10

Contact for DPA Matters

tabulaap@gmail.com

The web, arranged around you.

PrivacyTermsCookiesRefundsAcceptable UseSecurityAccessibilityGDPRData ProcessingDMCALicenses
tabulaap@gmail.com© 2026 Tabula