Data Processing Agreement
This Data Processing Agreement (the 'DPA') applies where ToRun processes personal data on behalf of an organization customer. It forms part of, and is incorporated into, our Terms of Service, and it gives effect to Article 28 of the EU General Data Protection Regulation ('GDPR'), the corresponding provisions of the UK GDPR, and Article 12 of Turkish Law No. 6698 on the Protection of Personal Data ('KVKK').
1. When this DPA applies, and when it does not
Most people who use ToRun use it for themselves. In that case ToRun is the controller of your personal data, our Privacy Policy governs, and this DPA does not apply to you.
This DPA applies where an Organization - a company, institution, agency or other legal entity - uses ToRun to process personal data for its own purposes, and therefore decides the purposes and means of that processing. For example: a tenant whose administrators create and manage accounts for their staff; an Organization that uploads documents about its customers into a Knowledge base; an Organization that runs workflows over personal data about its own contacts. In those cases the Organization is the controller and ToRun is the processor.
Section 1 of the Privacy Policy states the same split. Where both documents describe the same service, the Privacy Policy describes ToRun acting as a controller and this DPA describes ToRun acting as a processor. Neither enlarges the other.
1.1 How this DPA takes effect
This DPA is a standing offer. It takes effect between ToRun and an Organization, without signature, when the Organization begins using the Service to process personal data for which it is the controller. An Organization that needs a countersigned copy, or terms on its own paper, may ask for one through the contact form at /company/contact?category=legal. Where a signed agreement between the Organization and ToRun exists, that agreement prevails over this DPA to the extent of any conflict.
2. Definitions
Controller, processor, personal data, data subject, processing, personal data breach and supervisory authority carry their GDPR meanings. In addition:
- 'Organization Personal Data' means personal data within Organization Content that ToRun processes on the Organization's behalf under this DPA.
- 'Organization Content' means the prompts, files, documents, knowledge bases, workflow inputs and outputs, messages and other material that the Organization or its Users submit to, or generate through, the Service.
- 'User' means an individual the Organization authorises to use the Service under the Organization's account.
- 'Sub-processor' means a third party ToRun engages to process Organization Personal Data.
- 'Model Provider' means a third-party AI provider to which an AI request is routed in order to produce the result the Organization or its User asked for.
3. Roles
3.1 The Organization as controller
The Organization decides the purposes and means of processing Organization Personal Data. It is responsible for having a lawful basis for the processing it instructs, for giving its data subjects the notices the law requires, for the accuracy and lawfulness of the Organization Content it submits, and for deciding who inside the Organization may see what.
3.2 ToRun as processor
ToRun processes Organization Personal Data only as set out in this DPA and on the Organization's documented instructions.
3.3 Where ToRun remains a controller
ToRun is an independent controller, and this DPA does not apply, for: account registration and authentication data; billing, invoicing, tax and fraud-prevention records; security, audit and abuse-prevention logs; aggregated and anonymised service telemetry; and correspondence with the Organization's administrators. That processing is governed by the Privacy Policy. Where ToRun acts as an independent controller it does not act on the Organization's instructions for that processing, and it does not use the two roles interchangeably for the same data.
4. Subject matter, duration, nature and purpose
The subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects are set out in Annex I. In summary: ToRun processes Organization Personal Data for as long as the Organization's account is active, in order to provide the Service the Organization asked for - storing content, routing AI requests to Model Providers, running workflows, and returning the results.
5. ToRun's obligations as processor
5.1 Documented instructions
ToRun processes Organization Personal Data only on the Organization's documented instructions, including as regards transfers to a third country. Those instructions consist of this DPA, the Terms of Service, the configuration the Organization chooses in the Service - including which Model Providers its requests may reach - and each request its Users make through the Service.
ToRun may process Organization Personal Data otherwise where EU, Member State or Turkish law requires it. In that case ToRun informs the Organization of that legal requirement before processing, unless the law prohibits the notice on important grounds of public interest.
If ToRun considers an instruction to infringe data-protection law, it informs the Organization without undue delay and may suspend that instruction until it is withdrawn or amended.
5.2 Confidentiality
Every person ToRun authorises to process Organization Personal Data is bound by an obligation of confidentiality, and access is limited to those who need it to provide, secure or support the Service.
5.3 Security
ToRun implements the technical and organisational measures set out in Annex II, taking account of the state of the art, the cost of implementation, and the nature, scope, context and purposes of the processing, as Article 32 GDPR requires. ToRun may update those measures provided the level of protection is not reduced.
5.4 Assistance with data-subject requests
The Service gives the Organization and its Users the means to find, export, correct and delete Organization Personal Data directly. A signed-in User can export and erase their own personal data from the Personal data page in the Service; erasure runs immediately, and the financial and audit records the law requires ToRun to keep are anonymised rather than deleted.
Where a data subject brings ToRun a request about Organization Personal Data, ToRun does not answer it on the merits: it refers the data subject to the Organization and tells the Organization about the request without undue delay. Where the Organization cannot satisfy a request with the Service's own tools, ToRun gives reasonable assistance, taking into account the nature of the processing.
5.5 Assistance with Articles 32 to 36
Taking into account the nature of the processing and the information available to it, ToRun assists the Organization with security of processing, personal data breach notification, data protection impact assessments and prior consultation. Annex I and Annex II are written to be usable as DPIA input.
5.6 Records of processing
ToRun maintains the record of processing categories carried out on behalf of controllers that Article 30(2) GDPR requires, and makes the parts relevant to the Organization available on request.
6. Sub-processors
6.1 General authorisation
The Organization gives ToRun a general written authorisation to engage Sub-processors. ToRun binds each Sub-processor by contract to data-protection obligations no less protective than those in this DPA, and remains fully liable to the Organization for a Sub-processor's performance of them.
6.2 The list, and the one category that behaves differently
Annex III lists ToRun's Sub-processors. It is part of this document and is updated when the list changes.
One category does not behave like the others, and an Organization should understand it before relying on this DPA: which Model Provider receives a request is decided by the request. It follows from the capability asked for, the model the User or the Organization's routing configuration selects, and - where the Organization supplies its own provider key (BYOK) - from the Organization's own contract with that provider. ToRun publishes the providers and models currently available inside the Service. An Organization that needs its Organization Personal Data confined to particular providers, regions or models restricts routing in its own configuration; it should do that rather than rely on the default.
6.3 Changes to the list
ToRun gives the Organization's administrative contact at least 30 days' notice before a new Sub-processor begins processing Organization Personal Data. The Organization may object on reasonable data-protection grounds within those 30 days. The parties will work in good faith to resolve the objection — for example by routing the Organization's processing away from that Sub-processor. If it cannot be resolved, the Organization may terminate the affected part of the Service and receive a pro-rata refund of prepaid fees for the unused remainder of its term.
Where a Sub-processor has to be replaced faster than that to keep the Service running or secure, ToRun gives as much notice as the circumstances allow and explains why the period was shortened. The objection and termination rights above are unaffected.
Adding a Model Provider to the in-product catalogue is not by itself a change requiring notice: it becomes one when the Organization's own routing configuration allows requests to reach that provider.
7. International transfers
ToRun operates from Istanbul, Turkey, and its Sub-processors are located in Turkey, the European Economic Area, the United Kingdom, the United States and other jurisdictions. Where Organization Personal Data is transferred out of the EEA, the United Kingdom or Turkey, the transfer relies on:
- EU GDPR Chapter V - the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module Two (controller to processor) or Module Three (processor to processor) as applicable. The Clauses are incorporated into this DPA by reference and prevail over it in the event of conflict. Annex I and Annex II of this DPA serve as Annexes I and II of the Clauses; the docking clause applies; the competent supervisory authority is that of the Organization's EU establishment or, where it has none, of the Member State in which its data subjects are located.
- UK GDPR - the UK International Data Transfer Addendum to the EU Standard Contractual Clauses.
- KVKK Article 9 - a transfer basis available under Article 9, including an undertaking or a standard contract notified to the Turkish Personal Data Protection Authority where that is required.
The Organization may request a copy of the transfer documentation through the contact form at /company/contact?category=legal.
8. Personal data breach
ToRun notifies the Organization of a personal data breach affecting Organization Personal Data without undue delay after becoming aware of it, and in any event within 72 hours. The notification describes, so far as it is known at the time, the nature of the breach and the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point for further information. Where the information is not all available at once, ToRun provides it in phases without further undue delay.
Notice is given to the Organization's administrative contact. As controller, the Organization is responsible for notifying its supervisory authority and its data subjects where the law requires it.
9. Deletion and return
On termination of the Organization's account, and at any time on the Organization's written request, ToRun deletes or returns Organization Personal Data at the Organization's choice and deletes existing copies, unless EU, Member State or Turkish law requires ToRun to keep them.
In practice:
- Return. The Organization and its Users can export Organization Content from the Service at any time while the account is active. An Organization that wants an export after termination should ask for it before the deletion window closes.
- Deletion. Content is deleted on account closure. Deletion from the primary stores is final; there is no backup rotation from which a deleted copy could resurface.
- What is kept. Records ToRun must retain by law - billing, tax, and hash-chained audit records - are kept for the periods in that same section, with personal identifiers severed where the record still serves its purpose without them.
10. Audits and information
ToRun makes available to the Organization the information necessary to demonstrate compliance with Article 28 GDPR, including this DPA and its Annexes, and its answers to a reasonable security and privacy questionnaire.
Where an Organization requires more than that - an on-site visit, a third-party auditor, or a bespoke assessment - it may audit once in any 12-month period, on 30 days' written notice, during business hours, in a way that does not disrupt the Service. The auditor may not be a competitor of ToRun and must be bound by confidentiality obligations at least as protective as those in the Agreement. The Organization bears its own and its auditor's costs; ToRun bears its own, except where the audit finds a material breach of this DPA, in which case ToRun bears the reasonable cost of the audit.
These limits do not apply where a supervisory authority requires an audit, or following a personal data breach affecting the Organization's data: in those cases an audit may be carried out as often as the circumstances require.
ToRun does not refuse an audit the law entitles the Organization to. It asks for the mechanics to be agreed in writing so that auditing a multi-tenant platform cannot expose another customer's data - a constraint that protects the Organization's own data in exactly the same way.
11. AI-specific terms
11.1 No training on Organization Content
ToRun does not use Organization Content - prompts, files, conversations or generated outputs - to train, fine-tune or otherwise improve any AI model, its own or anyone else's. For requests routed through ToRun's own provider accounts, ToRun uses providers under terms that prohibit them from training on customer content. Where the Organization supplies its own provider key (BYOK), the provider's training posture is governed by the Organization's own contract with that provider, and the Organization should review it.
11.2 What a Model Provider receives
A Model Provider receives the content needed to answer the specific request - the prompt, the material attached to or referenced by it, and the conversation context that request requires - and receives it only when a User's action, or automation the Organization has configured, causes a request to be sent. ToRun does not send Organization Content to a Model Provider for any other purpose.
11.3 Output
ToRun makes no representation that AI output is accurate, complete or fit for a particular purpose. Where the Organization uses output to make a decision about a person, the Organization is the controller of that decision and carries the obligations that arise from it, including those under Article 22 GDPR.
11.4 Content screening
Uploaded images, and text published to a public surface, are screened by an automated moderation classifier as described in Section 4 of the Acceptable Use Policy. That screening is carried out in ToRun's own legitimate interest and to meet its legal obligations. It is not processing on the Organization's instruction.
12. Liability
Each party's liability under this DPA is subject to the exclusions and limitations of liability in the Terms of Service, or in the signed agreement between the Organization and ToRun where one exists. Nothing in this DPA limits a data subject's rights under the Standard Contractual Clauses or under applicable law.
13. Precedence, changes, and governing law
This DPA prevails over the Terms of Service in the event of a conflict about the processing of Organization Personal Data. The Standard Contractual Clauses prevail over this DPA.
ToRun may amend this DPA where the amendment is required by law, by a supervisory authority, or by a change in the Service, provided the amendment does not reduce the protection of Organization Personal Data. The version and effective date shown with this document are the authoritative record of the text in force.
This DPA is governed by the law stated in the Terms of Service, without prejudice to mandatory data-protection law and to the governing law of the Standard Contractual Clauses.
14. Contact
Data-protection questions, requests for a signed copy, transfer documentation, security questionnaires and audit enquiries: the contact form at /company/contact?category=legal, or [email protected].
Annex I - Description of the processing
| Subject matter | Provision of the ToRun AI-orchestration platform to the Organization. |
| Duration | The term of the Organization's account, plus the retention periods in Section 8 of the Privacy Policy. |
| Nature of the processing | Collection, storage, structuring, retrieval, transmission to Model Providers, generation of output, and erasure - by automated means. |
| Purpose | To provide the features the Organization and its Users invoke: chat, documents and knowledge bases, workflow execution, media generation, translation, and the account, support and security functions around them. |
| Categories of data subjects | The Organization's Users; and any individual whose personal data the Organization or its Users choose to include in Organization Content - for example the Organization's employees, customers, suppliers or contacts. |
| Categories of personal data | Identification and contact data of Users (name, e-mail address, profile details, authentication identifiers); usage and interaction data tied to a User; and any personal data the Organization chooses to submit within Organization Content, whose categories the Organization determines and which ToRun does not restrict in advance. |
| Special categories (Article 9) | Not required by the Service and not requested by it. The Organization decides whether any is submitted within Organization Content. Where it is, the Organization is responsible for the further conditions in Articles 9 and 10 GDPR and in Article 6 KVKK. |
| Frequency | Continuous, for the duration of the account. |
| Retention | As set out in Section 8 of the Privacy Policy and Section 9 of this DPA. |
Annex II - Technical and organisational measures
These are measures that are in place. Nothing is listed here that is not implemented.
Access control
- Role- and permission-based authorisation, scoped explicitly to host, tenant, organization, creator and end-user namespaces, so a permission granted in one scope does not carry into another.
- Tenant isolation enforced in the data layer, not only in the interface.
- Two-factor authentication available on every account; session list and security log visible to the account holder.
- Access to production systems limited to the people who need it, over authenticated channels.
Encryption
- TLS for data in transit, including every API request and every request to a Model Provider.
- Bring-your-own-key provider credentials: the raw key is never stored. It is fingerprinted and encrypted with an application key-management ring. The account-holder surface returns only whether a key is configured and when it was last tested - never the key and never its ciphertext. Platform administration can read the stored ciphertext, which is what key rotation and incident response require.
Auditability
- Hash-chained, tamper-evident audit records for billing, moderation and administrative actions. The chain is verified from the stored records, so a tampered row breaks verification instead of the verifier re-deriving the value it expects.
- One billing record per AI call, carrying the price applied, the fund source and the provider used, so what was processed, for whom and through which provider can be reconstructed.
Resilience and integrity
- Transactional outbox for event publication with inbox-side idempotency, so an event is neither lost on a crash nor applied twice.
- Rate limiting and abuse detection on public and authenticated surfaces.
- The primary database runs as a three-member replica set with no arbiters, so every member holds a complete copy and the loss of a node or a disk costs neither data nor availability.
Content safeguards
- Automated moderation screening of uploaded images before they are stored, and of text published to public surfaces before it goes live, as described in Section 4 of the Acceptable Use Policy.
Data subject tooling
- Self-service export and erasure of personal data from inside the Service. Erasure is synchronous and covers every module; financial and audit records are anonymised rather than deleted where the law requires them to be retained.
Vendor management
- Sub-processors are contractually bound to data-protection obligations no less protective than those in this DPA.
Annex III - Sub-processors
| Category | Sub-processor | Purpose | Location |
|---|---|---|---|
| Storage and delivery | Bunny.net (BunnyWay d.o.o.) | Object storage, CDN, image and video optimisation and streaming | Slovenia (EU), global edge network |
| Payments | Dodo Payments | Merchant of Record: payment processing, invoicing, tax calculation and remittance, refunds and chargebacks | As stated in the provider's own terms |
| Hosting and infrastructure | OVHcloud | Compute, database and cache hosting for the production cluster | Germany (EU) |
| Edge network | Cloudflare | DNS, TLS termination, caching and denial-of-service protection for torun.ai and its sub-domains | Global edge network |
| Model Providers | Determined by the request - see Section 6.2 | Producing the result of an AI request | Varies by provider |
Transactional e-mail - receipts, password resets, security alerts and notifications - is sent from mail infrastructure ToRun operates itself, and is not handed to a third-party sending service.
The current Model Provider list, with each provider's processing location, is available to an Organization on request through the contact form at /company/contact?category=legal.