Toutmark

Data Processing Addendum (DPA)

Effective: April 23, 2026 | Last Updated: May 31, 2026
Legal Disclaimer: Toutmark is not your lawyer. This document is drafted pragmatically but has not been reviewed by counsel. Before onboarding enterprise customers or processing large volumes of EU/UK data, Toutmark will commission a legal review. Customers should consult their own counsel about whether these terms work for their use case.

This Data Processing Addendum (DPA) applies when Toutmark processes personal data on behalf of a customer who is a data controller (or equivalent under applicable privacy laws). This DPA supplements the main Terms of Service and Privacy Policy.

1. Definitions

2. Scope

This DPA applies only to personal data that you provide to Toutmark as part of using the Service. It does NOT apply to data that Toutmark collects independently (e.g., website analytics, account sign-up data).

Data You Provide

You may provide Toutmark with:

3. Processing Instructions

Toutmark processes personal data only in accordance with your documented instructions, which are:

If you ask Toutmark to process personal data in a way that violates applicable law, we will inform you and decline to process it in that manner.

4. Duration & Retention

Toutmark processes personal data:

5. Subprocessors

Toutmark engages subprocessors (third-party service providers) to process personal data on your behalf. The complete list is at toutmark.com/legal/subprocessors.

Notification: We will notify you at least 30 days before adding or removing a subprocessor and will provide you an opportunity to object.

Subprocessor Agreements: All subprocessors are bound by written agreements that require them to process personal data only as instructed and to maintain appropriate security measures.

6. International Data Transfers

Live Phase (US-only): All data processing occurs within the United States. No data is transferred outside the US in this phase.

Future Phases (EU/UK/Canada/Australia): When Toutmark expands internationally, we will implement appropriate transfer mechanisms, including:

7. Data Subject Rights Assistance

You have the right to request that we assist you in fulfilling data-subject requests (access, deletion, correction, portability, restriction) as required by GDPR, UK-GDPR, and CCPA. To exercise these rights on behalf of your data subjects:

Email: [email protected] with the subject "Data Subject Request"

Toutmark will respond within 30 days (or the legally required timeframe). We will assist you in fulfilling the request unless it is manifestly unfounded or excessive.

8. Data Breach Notification

If Toutmark becomes aware of a personal data breach affecting your data:

Report a breach: [email protected]

9. Security Measures

Toutmark implements technical and organizational security measures, including:

Security measures are reviewed quarterly and updated as needed to address emerging threats.

10. Audit Rights

You may request an audit of Toutmark's compliance with this DPA:

Request an audit by emailing [email protected].

11. Signatures & Acceptance

Digital Acceptance: This DPA is effective when you accept it by clicking "I agree" during account setup or by continuing to use the Service after this DPA becomes effective.

Written Signature: You may also execute this DPA by signing a hard copy and returning it to [email protected].

Customer

Company Name: _________________________ (as provided in account)

Authorized Signatory: _________________________ (if signed)

Date: _________________________ (if signed)

Toutmark

Toutmark

2712 N Ardmore Avenue
Manhattan Beach, CA 90266

Legal Contact: [email protected]

12. Amendments

Toutmark may amend this DPA to comply with changes in law or to improve data protection practices. Material changes will be communicated to you at least 30 days in advance. Continued use of the Service constitutes acceptance of amendments.

Version History: