Totalum, Inc.
Effective: · Version 2.0 · Binds users registered before that date from
How this addendum applies
This Data Processing Addendum (the “DPA”) forms part of the Terms of Service and applies automatically, without signature, to every customer whose use of the Service involves personal data inside a Project for which the customer is the controller or business and Totalum is the processor or service provider. Where this DPA and the Terms conflict on a data-protection matter, this DPA prevails; where this DPA and the Standard Contractual Clauses conflict, the Standard Contractual Clauses prevail.
This DPA is entered into between Totalum, Inc., a corporation organized under the laws of the State of Delaware, United States of America, with notices to c/o Legalinc Corporate Services Inc., 131 Continental Drive, Suite 305, Newark, DE 19713, New Castle County, United States (“Totalum”, “we”), and the person or entity that holds the Totalum account under which a Project is created (“Customer”, “you”). It reflects the requirements of Article 28(3) of Regulation (EU) 2016/679 (the “GDPR”), of the UK GDPR and the Data Protection Act 2018, of the Swiss Federal Act on Data Protection, of Spanish Organic Law 3/2018 (the “LOPDGDD”), of the California Consumer Privacy Act and its regulations (the “CCPA”), of the other US state privacy laws that impose contract terms on processors and service providers, and, on request, of the Brazilian Lei Geral de Proteção de Dados (“LGPD”).
This DPA covers only Customer Personal Data as defined in Section 2: the personal data that you put into your Projects, that your Projects collect from their own users, or that we otherwise process on your behalf. It does not cover the personal data we process as an independent controller about you, your team members and the visitors of our own websites (account, billing, support, marketing and analytics data), which is governed by our Privacy Policy.
By creating a Project that processes personal data you accept this DPA on behalf of yourself and, if applicable, of the entity you represent. No signature is required; Section 18 explains how to obtain a signed copy for your own records or for your supervisory authority.
For Customer Personal Data, you are the controller (or business) and Totalum is the processor (or service provider). Where you act as a processor for a third party (for example, an agency building an app for its client, or a whitelabel partner serving its own customers), you are a processor, your client is the controller, and Totalum is your sub-processor; in that case you warrant that your own agreement with the controller authorizes you to engage Totalum on the terms of this DPA and to give us the instructions in it, and the SCC module referred to in Section 13 is Module 3.
You determine the purposes and means of the processing carried out by your Projects: what data they collect, from whom, why, for how long, and with which third-party services they share it. Totalum determines only the technical means strictly necessary to provide the Service, as described in the Terms and Annex II.
Totalum acts as an independent controller, not as your processor, for the account, identity, billing, credit, support, security-log, anti-fraud, product-analytics and marketing data described in the Privacy Policy, and for the metadata the Service records about how the Service itself is used (such as run timestamps, credit consumption and infrastructure metrics). Each party is separately responsible for its own compliance in its own role.
Totalum will process Customer Personal Data only on your documented instructions, including with regard to transfers to a third country or an international organization, unless required to do so by Union or Member State law (or another law) to which Totalum is subject; in that case Totalum will inform you of that legal requirement before processing, unless the law prohibits such information on important grounds of public interest.
Your documented instructions are:
Totalum will immediately inform you if, in its opinion, an instruction infringes Data Protection Laws; Totalum is not obliged to carry out a legal analysis of every instruction, and it may suspend execution of an instruction it reasonably believes to be unlawful until the matter is resolved. Totalum will not process Customer Personal Data for its own purposes, and in particular will not use Customer Personal Data to train, retrain or fine-tune any artificial-intelligence model, and requires the same commitment from its model providers.
You are responsible, in your role as controller or as the processor acting for a controller, for:
Totalum ensures that every person it authorizes to process Customer Personal Data, whether an employee or a contractor, is bound by a contractual or statutory obligation of confidentiality, has received appropriate training on data protection and on the handling of AI systems, and accesses Customer Personal Data only to the extent necessary to provide, secure, maintain and support the Service or to comply with law. Totalum staff do not read the contents of your Projects in the ordinary course; access for support or incident response is logged and limited to what the task requires.
Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, Totalum implements and maintains the technical and organizational measures described in Annex II to ensure a level of security appropriate to the risk, as required by Article 32 of the GDPR and Article 28 of the LOPDGDD. Totalum may update those measures from time to time, provided the updates do not materially reduce the overall level of protection during the term of your subscription.
You acknowledge that the measures in Annex II relate to the Service itself. The security of the application code and configuration of your Projects, of the data flows you build, and of the third-party services you connect remains your responsibility, and you must assess whether the Service, together with your own measures, provides a level of security appropriate to the risk of your specific processing.
Totalum will notify you by email to the address on your account at least 30 days before authorizing any new Sub-processor to process Customer Personal Data, or before replacing an existing one, and will update the list accordingly. Within that period you may object on reasonable, documented grounds relating to data protection by writing to contacto@totalum.app. Totalum will then use reasonable efforts to make available a change in the Service, or to recommend a configuration, that avoids the processing of Customer Personal Data by the new Sub-processor without unreasonably burdening you. If Totalum cannot do so within 30 days of your objection, you may terminate the affected Project or, if the Sub-processor concerns the whole Service, your subscription, without penalty and with a pro-rata refund of any prepaid fees for the unexpired period, by notice given before the new Sub-processor starts processing. Where an emergency replacement is required for security or availability reasons, Totalum will notify you as soon as reasonably practicable and the same objection right applies from that notice.
Totalum imposes on each Sub-processor, by a written contract, data-protection obligations that are substantially the same as those in this DPA, in particular providing sufficient guarantees to implement appropriate technical and organizational measures, and, where the Sub-processor is located outside the EEA, UK or Switzerland, a valid transfer mechanism under Section 13. Totalum remains fully liable to you for the performance of each Sub-processor's obligations.
The Service gives you direct means to access, export, correct, restrict and delete Customer Personal Data in your Projects (database panel, API, export and deletion functions), which is the primary way in which Totalum assists you in responding to requests from data subjects. If a data subject sends a request directly to Totalum that concerns Customer Personal Data in your Projects, Totalum will not respond on the merits (other than to say that the request should be addressed to you) and will forward the request to you at the email address on your account within 5 business days of identifying you as the relevant controller. Where you cannot fulfil a request through the Service, Totalum will provide reasonable additional assistance on request, taking into account the nature of the processing, and may charge a reasonable fee for assistance that is manifestly excessive or that the Service does not otherwise provide.
Taking into account the nature of the processing and the information available to it, Totalum will assist you in ensuring compliance with your obligations under Articles 32 to 36 of the GDPR (security, breach notification, data-protection impact assessments and prior consultation with a supervisory authority) and the corresponding provisions of other Data Protection Laws, by making available the information in this DPA, Annex II, the Sub-processor list and our security documentation, and by answering reasonable written questions about the Service. Totalum will also assist you, on request, with the risk assessments and cybersecurity documentation that US state privacy laws may require of you.
Totalum will notify you without undue delay, and in any event within 48 hours after confirming a personal-data breach affecting Customer Personal Data, by email to the address on your account and, where it is a critical incident, by every other contact channel you have provided. The notification will, to the extent the information is available at that time and otherwise in phases without further undue delay, (a) describe the nature of the breach, including where possible the categories and approximate number of data subjects and of records concerned; (b) give the name and contact details of the point of contact where more information can be obtained; (c) describe the likely consequences of the breach; and (d) describe the measures taken or proposed to address the breach, including, where appropriate, measures to mitigate its possible adverse effects. Totalum will cooperate with you and take the reasonable steps you direct to investigate, contain and remedy the breach.
You are responsible for deciding whether and how to notify your supervisory authority, the Attorney General of a US state, your own users or any other person, and for doing so within the deadlines that apply to you (for example 72 hours under Article 33 of the GDPR, 30 days under California Civil Code § 1798.82, 60 days under 6 Del. C. § 12B-102, or 3 business days under the LGPD). Totalum's notification to you is not an acknowledgement of fault or liability. Totalum will not notify your data subjects or your authorities directly unless required by law to do so, and will inform you if it is so required.
At any time during the term you can export the complete source code and database of each Project, and delete Customer Personal Data, using the Service. Upon termination of the Service or deletion of a Project, and in line with Regulation (EU) 2023/2854 (the Data Act) and Section 14 of the Terms, export remains available for a retrieval period of 30 days after the termination or the end of any transitional switching period. After that retrieval period Totalum will delete all Customer Personal Data, including copies held by Sub-processors, within 90 days, with backup media cycling out within the same period, unless Union, Member State, US or other applicable law requires Totalum to store the personal data for longer, in which case Totalum will keep it only for as long as that law requires, keep it isolated and protected, and continue to apply this DPA to it. Where you delete a Project yourself, deletion of its live data is immediate and backups cycle within the same 90-day window. Totalum will confirm deletion in writing on request.
Totalum will make available to you all information necessary to demonstrate compliance with the obligations laid down in Article 28 of the GDPR and this DPA, and will allow for and contribute to audits, including inspections, conducted by you or by another auditor mandated by you, as follows. Once every 12 months, and additionally after a personal-data breach affecting your Customer Personal Data, you may send Totalum a written security questionnaire, and Totalum will respond within 30 days with written answers and with the most recent third-party audit reports, certifications or attestations that it or its infrastructure providers hold. Where those written materials are not sufficient to demonstrate compliance, or where a supervisory authority requires it, you may conduct an on-site or remote audit of the systems and premises used to process your Customer Personal Data, limited to the purpose of verifying compliance with this DPA, no more than once in any 12-month period unless a breach has occurred, on at least 30 days' written notice, during normal business hours, at your cost, through personnel or an independent auditor bound by written confidentiality obligations and not a competitor of Totalum, in a manner that does not unreasonably interfere with Totalum's business or compromise the security or confidentiality of other customers' data. Totalum may require that audits of a Sub-processor's facilities be conducted through the Sub-processor's own audit programme. The parties will agree in advance on the scope, timing and duration of any audit and will treat the results as confidential information of both parties.
The databases and build sandboxes of your Projects are hosted in datacenters in the European Union. Some Sub-processors, and Totalum itself as a company established in the United States, process Customer Personal Data in the United States or in other third countries; the location of each is stated in the Sub-processor list. Totalum will not transfer Customer Personal Data originating from the EEA, the United Kingdom or Switzerland to a third country without a transfer mechanism that is valid under the applicable Data Protection Laws.
Totalum, Inc. is not currently self-certified under the EU-US Data Privacy Framework. Transfers of Customer Personal Data to Totalum from the EEA, the UK and Switzerland therefore rely on the Standard Contractual Clauses described in Section 13.3, supplemented by the transfer impact assessment Totalum maintains and makes available on request. Several Sub-processors are themselves certified under the Data Privacy Framework, as noted in the Sub-processor list, and transfers to them may rely on that certification.
To the extent that Totalum's processing of Customer Personal Data involves a transfer subject to Chapter V of the GDPR from you (as data exporter) to Totalum (as data importer), the parties enter into the Standard Contractual Clauses, which are hereby incorporated into this DPA by reference and completed as follows:
Where Totalum transfers Customer Personal Data onward to a Sub-processor in a third country, Totalum enters into the Standard Contractual Clauses (Module Three) or relies on another valid mechanism with that Sub-processor, and the transfer impact assessment covers those onward transfers.
For transfers of Customer Personal Data subject to the UK GDPR, the Standard Contractual Clauses as completed above apply as amended by the UK Addendum, which is incorporated by reference. Part 1 of the UK Addendum is completed as follows: Table 1 (parties) with the information in Clause Annex I.A above; Table 2 (selected SCCs, modules and clauses) as set out in Section 13.3, with the Addendum applying to the version of the Clauses in force on the date of transfer; Table 3 (appendix information) with Annexes I, II and III of this DPA; Table 4 (ending the Addendum when the Approved Addendum changes): neither party may end the Addendum on that basis, unless the change makes the Addendum unenforceable. For the purposes of the UK Addendum, the governing law and the courts under Clauses 17 and 18 are those of England and Wales.
For transfers of Customer Personal Data subject to the Swiss Federal Act on Data Protection, the Standard Contractual Clauses apply with the following amendments: references to the GDPR are read as references to the Swiss FADP; the competent supervisory authority under Clause 13 is the Swiss Federal Data Protection and Information Commissioner; the term “Member State” is read so as not to exclude data subjects in Switzerland from exercising their rights in their place of habitual residence; and the Clauses also protect the data of legal entities until the Swiss FADP no longer does so.
For Customer Personal Data subject to the LGPD, Totalum will, on request to contacto@totalum.app, enter into the standard contractual clauses approved by the Brazilian Autoridade Nacional de Proteção de Dados (Resolution CD/ANPD 19/2024) with you. For Customer Personal Data subject to other laws that restrict international transfers (for example the laws of Argentina, Colombia, Peru, Japan or Quebec), Totalum will cooperate in good faith to put in place the contractual safeguards that those laws recognize.
To the extent Customer Personal Data includes personal information of consumers protected by the CCPA, or personal data protected by the comprehensive privacy laws of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Iowa, Indiana, Tennessee, New Hampshire, New Jersey, Delaware, Kentucky, Maryland, Minnesota, Rhode Island, Nebraska or any other US state, Totalum acts as a service provider or processor and you act as the business or controller, and the following terms apply, in accordance with California Civil Code § 1798.100(d) and § 1798.140(ag) and section 7051 of the CCPA regulations (11 CCR § 7051):
Totalum certifies that it understands the restrictions in this Section and will comply with them. Totalum will process Customer Personal Data in a manner that is consistent with the standard of protection, deletion, purpose-limitation, security and confidentiality that these laws impose on processors, and will assist you, taking into account the nature of the processing and the information available, in meeting your obligations relating to consumer requests, security, breach notification and data-protection assessments. Nothing in this Section authorizes you to instruct Totalum to process Customer Personal Data in a manner that would itself violate those laws.
Where Spanish law applies to the processing, this DPA is also the contract required by Article 28 of the GDPR and Article 33 of the LOPDGDD, which sets out the duties of the processor (encargado del tratamiento). In particular: Totalum will process Customer Personal Data solely for the purposes set out in Annex I and in accordance with your instructions; will not communicate the data to third parties except to the Sub-processors authorized under Section 8 or where a legal obligation requires it; will maintain the record of processing activities that Article 30 of the GDPR requires of processors; will apply the security measures in Annex II, taking into account the guidance of the Agencia Española de Protección de Datos; and will assist you in the exercise of data-subject rights. Where, after termination, Totalum must retain Customer Personal Data to meet a legal obligation or to respond to potential liabilities arising from the processing, it will keep the data blocked in the sense of Article 32 of the LOPDGDD, that is, accessible only to judges and courts, the Public Prosecutor or the competent public administrations, for the limitation period of those liabilities, and will delete it afterwards. Totalum's staff and contractors are subject to the duty of confidentiality in Article 5 of the LOPDGDD, which survives the end of their relationship with Totalum.
Each party's liability, taken together in the aggregate, arising out of or related to this DPA, the Standard Contractual Clauses and any other transfer mechanism, whether in contract, tort or under any other theory of liability, is subject to the exclusions and limitations of liability in Section 17 of the Terms, and any reference in that Section to liability of a party means the aggregate liability of that party under the Terms and this DPA together. Nothing in this Section limits either party's liability towards data subjects under Article 82 of the GDPR, under Clause 12 of the Standard Contractual Clauses or under any other provision of Data Protection Laws that cannot be limited by contract, or limits Totalum's liability for the acts of its Sub-processors under Section 8.3.
In the event of a conflict, the following order of precedence applies with regard to the processing of Customer Personal Data: first, the Standard Contractual Clauses (and the UK Addendum or Swiss amendments, where they apply); second, this DPA; third, the Terms and any Order Form; fourth, any other policy or documentation. Nothing in this DPA reduces the protection that the Standard Contractual Clauses give to data subjects.
Totalum may update this DPA to reflect changes in Data Protection Laws, in supervisory-authority guidance, in the Standard Contractual Clauses or in the Service, in the manner set out in Section 21 of the Terms. Updates will not reduce the level of protection of Customer Personal Data below what Data Protection Laws require. This DPA takes effect when you first create a Project that processes personal data and remains in force for as long as Totalum processes Customer Personal Data on your behalf, including during the retrieval and deletion periods in Section 11, and the provisions that by their nature should survive (in particular Sections 6, 11, 13, 14, 15 and 16) survive its termination.
Totalum keeps a record of the version of this DPA in force at each date, of the Sub-processor list and of the notices sent under Section 8. If you need a copy of this DPA signed by Totalum, for your own records, for your controller or for a supervisory authority, send a request from the email address on your account to contacto@totalum.app indicating your account email, your legal entity name and address, and the SCC module that applies to you; Totalum will return a countersigned PDF of the then-current version within 10 business days. A countersigned copy has the same content as this page; it does not modify this DPA.
| Item | Description |
|---|---|
| Subject matter | The provision of the Totalum Service: an AI-assisted application builder with hosting, database, file storage, authentication, integrations, API and MCP access, in which the Customer builds, runs and publishes its own applications (Projects). |
| Duration | The term of the Customer's use of the Service for each Project, plus the retrieval period and the deletion period described in Section 11 of this DPA. |
| Nature of the processing | Collection (through the Customer's Projects), storage, hosting, organization, structuring, retrieval, transmission, display, backup, export, erasure and, at the Customer's instruction, transformation of data by the AI agent and by the code the Customer's Projects execute. |
| Purpose of the processing | To provide, secure, maintain, support and improve the Service in accordance with the Terms, this DPA and the Customer's documented instructions, and for no other purpose. Totalum does not use Customer Personal Data for its own analytics, advertising, profiling or model training. |
| Categories of data subjects | The Customer's end users and website visitors; the Customer's customers, prospects and suppliers; the Customer's employees, contractors and collaborators; and any other natural person whose personal data the Customer chooses to process through its Projects. |
| Categories of personal data | Whatever data the Customer chooses to submit or to have its Projects collect. Typically: identifiers (name, username, email address, telephone number, IP address, device identifiers); account and authentication data (credentials, session tokens); contact and postal data; commercial and transactional data (orders, invoices, payment references); content the data subject creates or uploads (messages, documents, images, audio); usage and technical data generated by the Project; and, where the Customer's Project provides it, location data. |
| Special categories of data | None, unless the Customer decides to process them through its Projects; in that case the Customer warrants that it holds a valid condition under Article 9 of the GDPR (or equivalent) and applies the additional restrictions and safeguards its law requires. The categories of data prohibited by Section 10.3 of the Terms may not be processed without prior written agreement. |
| Frequency of the transfer | Continuous, for as long as the Customer uses the Service for the Project concerned. |
| Retention | For the duration of the Project and thereafter as set out in Section 11 (30-day retrieval period, then deletion within 90 days including backups), subject to legal retention obligations and the blocking rule in Section 15. |
| Sub-processor transfers | To the Sub-processors listed in Annex III, for the functions and in the locations stated there, for the same subject matter, nature and duration. |
Totalum implements the following measures for the systems it uses to process Customer Personal Data. They serve as Annex II to the Standard Contractual Clauses.
| Area | Measures |
|---|---|
| Encryption in transit | All connections between browsers, the Service, its internal components and its Sub-processors use HTTPS/TLS. Published Projects are served over TLS by Cloudflare; custom domains receive automatically provisioned certificates. |
| Encryption at rest | Disk-level encryption on the database, sandbox and object-storage infrastructure of Totalum's providers. Secrets and environment variables of Projects are stored encrypted and are never sent to the browser. |
| Tenant isolation | Each Project organization has its own MongoDB database; data of different customers is never held in shared collections. Each Project is built in a dedicated, isolated virtual machine (sandbox) that is archived after about 6 hours of inactivity and destroyed about 2 days later; sandboxes are recreated from the stored source code and are not shared between customers. |
| Access control | Role-based access for the account owner and team members within the seat limits of the plan; API keys are individual, scoped to the account, revocable at any time and revoked automatically when the account closes; internal service-to-service calls are authenticated with HMAC signatures over timestamped, single-use nonces; no credential is exposed in client-side code. |
| Authentication | Email one-time codes, passwords stored with a salted adaptive hash, or Google sign-in; login attempts are logged with timestamp and IP for anomaly detection; automated sign-up validation and per-IP rate limits protect against abuse. |
| Logging and monitoring | Application, access and agent-run logs are kept for security, incident investigation and support; they are stored with access restricted to authorized personnel and retained for the periods in the Privacy Policy. |
| Backups and resilience | Automated backups of Totalum's databases on a regular schedule, stored encrypted; published Projects are served from Cloudflare's global network with DDoS protection; a static snapshot of each published Project keeps it available while its sandbox is archived. |
| Secure development | Code review, dependency management and staged deployment for the Service; separate development and production environments; the AI agent operates within the sandbox of a single Project and cannot reach another customer's data. |
| Sub-processor management | Written contracts with every Sub-processor imposing confidentiality, security and data-protection obligations; transfer mechanisms under Section 13; the list in Annex III kept current with 30 days' notice of changes. |
| Personnel | Confidentiality obligations for all staff and contractors; least-privilege access; training on data protection and on the safe operation of AI systems; access to production data limited to what support and incident response require and logged. |
| Incident response | A documented process to detect, contain, assess and remediate security incidents, with customer notification under Section 10 within 48 hours of confirmation and cooperation with the customer's own notifications. |
| Data portability and deletion | Export of source code and database in structured, commonly used, machine-readable formats at any time and during the retrieval period; verified deletion within 90 days after that, including backup cycling; blocking of data that must be retained under Section 15. |
| Physical security | Databases and sandboxes are hosted in the datacenters of an ISO 27001-certified infrastructure provider in the European Union with access control, redundant power and network; object storage in Google Cloud and edge delivery in Cloudflare facilities with equivalent physical controls. |
Totalum reviews these measures at least annually and after any significant incident. A description of the current measures, together with any third-party certifications of Totalum's providers, is available on request under Section 12.
The authorized Sub-processors, with their legal entity, location, function, the categories of Customer Personal Data they may process and the transfer mechanism that applies to each, are published and kept current at https://www.totalum.app/legal/subprocessors, which is incorporated into this DPA as Annex III and as Annex III to the Standard Contractual Clauses. Changes to that list are notified in accordance with Section 8.2.
Questions about this DPA, objections to Sub-processors, requests for a signed copy, transfer impact assessments or security documentation: contacto@totalum.app (privacy) and contacto@totalum.app (legal), or by post to Totalum, Inc., c/o Legalinc Corporate Services Inc., 131 Continental Drive, Suite 305, Newark, DE 19713, New Castle County, United States.
Related documents
This document can be printed or saved as a PDF from your browser.
© 2026 Totalum, Inc.