Data processing agreement
How Typestream processes personal information on behalf of the organisations that use it.
This agreement forms part of the terms of service between Typestream Limited ("Typestream", "we") and the organisation that uses Typestream ("you"). It applies when Typestream processes personal information on your behalf.
1. Roles
For personal information in your content (for example, names in chats, subject profiles about people, and your members' details), you decide why and how it's processed, and we process it for you. Under the EU and UK GDPR, you are the controller and we are the processor. Under New Zealand's Privacy Act 2020, we hold it as your agent (section 11).
2. What we process
- Subject matter and duration: providing Typestream, for as long as the terms apply, and up to 30 days after, for export and deletion.
- Nature and purpose: storing, organising, analysing and displaying your content; sending the alerts and emails you configure; supporting you when you ask.
- Personal information: names, work email addresses and account identifiers of your members; anything about people that your members write in chats, profiles and monitors.
- Who it's about: your members, and people your members write about.
- We don't ask for special categories of personal information (health, political opinions, and so on). Don't put them into Typestream unless you need to and have a lawful basis.
3. Our commitments
We will:
- process personal information only to provide Typestream as the terms and your settings direct, unless the law requires otherwise (and then we'll tell you, if we're allowed to);
- make sure everyone who can access it is bound to keep it confidential;
- keep it secure with the measures in section 7;
- use only the subprocessors on our subprocessor list, bound by terms that protect personal information at least as well as this agreement, and stay responsible for them;
- help you respond to people exercising their rights, such as access and correction, through the product's tools or on request;
- tell you without undue delay, and within 72 hours of becoming aware of a breach affecting your personal information, with what we know and what we're doing, and help you meet your own obligations to notify;
- help you with privacy impact assessments and consultations with regulators, where they relate to Typestream;
- delete or return your personal information when the agreement ends, as section 5 describes;
- give you the information you reasonably need to show you're complying, and answer reasonable questions about our security.
4. Subprocessors
Our current subprocessors are on the subprocessor list. We'll give owners and admins at least 30 days' notice by email before adding or replacing one. If you object on reasonable grounds and we can't resolve it, you may end the affected part of the service and receive a pro-rata refund of prepaid fees for it.
5. At the end
When the agreement ends, you can export your content for 30 days. After that we delete it, and deletion from backups follows within their retention period. We keep only what the law requires, and protect it under this agreement while we do.
6. International transfers
Your content is stored in New Zealand. Some processing happens overseas, most importantly the AI models that answer questions; the subprocessor list says where. For personal information subject to the GDPR, transfers rely on New Zealand's adequacy decision where it applies, and otherwise on the European Commission's standard contractual clauses, which we put in place with the subprocessors concerned. For New Zealand personal information, we meet information privacy principle 12.
7. Security measures
- Encryption in transit (TLS) everywhere, and at rest for databases, storage and backups.
- Data stored in AWS's New Zealand region, in private networks; storage blocks public access.
- Access for staff limited to what their role needs, through single sign-on and multi-factor authentication. Support access to an organisation is read-only, time-limited and recorded in its audit log.
- Every query on an organisation's data is scoped to that organisation, and tested.
- Secrets held in a secrets manager; dependencies and images scanned for known vulnerabilities; infrastructure changes reviewed before they're applied.
- Logging and alerting for errors and suspicious activity, with an on-call rota.
- Backups tested by restoring them.
- An independent penetration test before launch, and regularly after.
8. Order of precedence
If this agreement and the terms of service conflict about personal information, this agreement wins.