Typillar

Data Processing Addendum

Last updated: August 5, 2026

This Data Processing Addendum ("DPA") forms part of the Terms of Service between Premsan Inc ("Premsan", "we") and the customer accepting them ("Customer", "you"), and applies wherever we process personal data on your behalf in providing Typillar. It takes effect when you accept the Terms; no signature is needed for it to apply. If your organization needs a countersigned copy, email privacy@typillar.com with your legal entity name and registered address.

1. Definitions

Data Protection Laws means all laws applicable to a party's processing under this DPA, including the EU General Data Protection Regulation 2016/679 ("GDPR"), the GDPR as incorporated into UK law ("UK GDPR") together with the Data Protection Act 2018, the Swiss Federal Act on Data Protection ("FADP"), and the Japanese Act on the Protection of Personal Information ("APPI"). Customer Personal Data means personal data that we process on your behalf under the Terms. SCCs means the Standard Contractual Clauses annexed to Commission Implementing Decision (EU) 2021/914. UK Addendum means the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018. Controller, processor, data subject, processing, personal data and personal data breach have the meanings given in the GDPR. A sub-processor is a processor we engage to process Customer Personal Data.

2. Roles of the parties

2.1 You are the controller of Customer Personal Data and Premsan is the processor. Where you are yourself acting as a processor for another controller, Premsan is a sub-processor and you confirm you have the authority you need to engage us on that controller's behalf.

2.2 Each party complies with the obligations that apply to it in its own role under Data Protection Laws.

2.3 You are responsible for the lawfulness of the personal data you put into Typillar: that you have a lawful basis for it, that you have given the notices and obtained the consents your own law requires, and that your instructions to us do not put us in breach of Data Protection Laws.

3. Scope and instructions

3.1 We process Customer Personal Data only on your documented instructions. The Terms, this DPA, and your use of the console, the API and the agent are your documented instructions. We will not process Customer Personal Data for any other purpose.

3.2 We do not sell Customer Personal Data, and we do not use it to train machine-learning models. Typillar runs no inference of its own: the model calls that plan and write your project run on the Cloudflare account you connect, under your own account and your own bill.

3.3 We will tell you if, in our opinion, an instruction infringes Data Protection Laws. We may suspend the affected processing until the instruction is confirmed, changed or withdrawn.

3.4 If a law we are subject to requires us to process Customer Personal Data other than on your instructions, we will tell you before we do so unless that law prohibits us from telling you on important grounds of public interest.

4. What we process — and what we do not

4.1 The subject matter, duration, nature and purpose of the processing, the categories of data subjects and the types of personal data are set out in Annex I.

4.2 Your own accounts are outside this DPA. Typillar builds and deploys applications into your own Cloudflare account and, where you connect them, your own GitHub and Stripe accounts. The databases, buckets, uploads and payment records those applications use live in those accounts, under contracts between you and those providers. We do not hold a copy, we operate no proxy in front of your deployed application, and no request your end users make to it is seen by us. We are not a processor of that data, and those providers are your processors rather than our sub-processors. Our access to your accounts exists only through the credentials you grant, is limited to the resources Typillar itself created, and ends when you revoke them.

4.3 Two narrow paths are the exception, and you switch on each of them yourself. Where they carry personal data of your end users, we process it as your processor under this DPA:

4.4 We do not seek and do not require special categories of personal data under Article 9 GDPR, criminal-offence data, or protected health information. Typillar is not offered for processing protected health information and we do not enter Business Associate Agreements. If you put such data into Typillar you do so on your own responsibility and on the instruction that we process it no differently from other Customer Personal Data.

5. Confidentiality

We limit access to Customer Personal Data to those people who need it to provide, secure or support the service. Everyone with access is bound by a duty of confidentiality that survives the end of their engagement, and operator access to customer records is authenticated through a single-sign-on identity provider and written to an audit log before the read is served.

6. Security

6.1 We implement and maintain the technical and organizational measures set out in Annex II, having regard to the state of the art, the cost of implementation, and the nature, scope, context and purposes of processing, as required by Article 32 GDPR.

6.2 We may update those measures as the service evolves, provided we do not materially reduce the level of protection.

7. Sub-processors

7.1 You give us general authorization to engage sub-processors. Those engaged as at the date of this DPA are listed in Annex III; the current list is maintained on the Trust & Security page and that page governs.

7.2 We give account owners notice before a new sub-processor begins processing Customer Personal Data. To subscribe to change notices, email security@typillar.com.

7.3 You may object to a new sub-processor on reasonable data-protection grounds within 30 days of notice. We will work with you in good faith to find an alternative. If we cannot, you may terminate the affected part of the service without penalty and receive a pro-rata refund of fees paid for the terminated part covering the period after termination.

7.4 We impose data-protection obligations on each sub-processor that are no less protective than those in this DPA, and we remain fully liable to you for their performance.

8. Data subject rights

8.1 Typillar gives you the means to satisfy most requests yourself: you can read, correct, export and delete account and project data from the console at any time, and deleting an account removes its data immediately.

8.2 Taking into account the nature of the processing, we assist you by appropriate technical and organizational measures, so far as possible, in responding to requests to exercise rights under Chapter III of the GDPR. Where the console cannot satisfy a request, we will help on request; if the work is substantial and repeated we may charge a reasonable fee, agreed with you first.

8.3 If a data subject contacts us directly about Customer Personal Data, we will not respond substantively except to confirm the request has been forwarded to you, unless legally required to do otherwise.

9. Personal data breach

9.1 We notify you without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Customer Personal Data. Notice goes to the account owner's email address, so keep it current.

9.2 The notice will describe the nature of the breach, the categories and approximate number of data subjects and records concerned so far as known, the likely consequences, the measures taken or proposed, and a contact point for more information. Where we cannot provide all of it at once we will provide it in phases without undue further delay.

9.3 We assist you in meeting your own notification obligations to supervisory authorities and data subjects. Our notice is not an acknowledgement of fault or liability.

10. Impact assessments

Taking into account the nature of the processing and the information available to us, we provide reasonable assistance with data protection impact assessments and prior consultation with supervisory authorities under Articles 35 and 36 GDPR.

11. International transfers

11.1 Premsan is established in Japan. Japan holds an adequacy decision from the European Commission, and equivalent adequacy recognition from the United Kingdom and Switzerland. Transfers of Customer Personal Data from the EEA, the United Kingdom or Switzerland to Premsan in Japan are made on the basis of that adequacy, and we handle personal data received from the EEA in accordance with the Supplementary Rules that adequacy depends on.

11.2 If an adequacy decision relied on in clause 11.1 is withdrawn, suspended, invalidated or does not cover a particular transfer, the SCCs are incorporated into this DPA by reference and apply to that transfer automatically, without either party needing to take any further step. For those SCCs: Module Two (controller to processor) applies, or Module Three (processor to processor) where you are acting as a processor; the optional docking clause in Clause 7 applies; in Clause 9, Option 2 (general written authorization) applies with the notice period in clause 7.2 of this DPA; the optional redress wording in Clause 11 does not apply; Clause 17 is governed by the law of Ireland; and Clause 18(b) designates the courts of Ireland. Annexes I, II and III of this DPA populate Annexes I, II and III of the SCCs.

11.3 For transfers subject to the UK GDPR, the UK Addendum applies to the SCCs incorporated by clause 11.2. Tables 1 to 3 of the UK Addendum are populated by this DPA and its Annexes; in Table 4, neither party may end the Addendum when the ICC's Approved Addendum changes.

11.4 For transfers subject to the FADP, references in the SCCs to the GDPR are read as references to the FADP, the competent authority is the Swiss Federal Data Protection and Information Commissioner, and the term "member state" does not prevent data subjects in Switzerland from suing in their place of habitual residence.

11.5 Our sub-processors are located in the United States and are engaged under their own transfer mechanisms, which we verify before engaging them.

12. Audits and information

12.1 We make available the information necessary to demonstrate compliance with Article 28 GDPR. In the first instance that means this DPA and its Annexes, the Trust & Security page, and our written answers to a reasonable security questionnaire, once in any twelve-month period.

12.2 Where Data Protection Laws require an audit or inspection and the information in clause 12.1 is genuinely insufficient, we will contribute to one on 30 days' written notice, during business hours, no more than once in any twelve-month period, in a way that does not disrupt the service or compromise the confidentiality or security of other customers. Any auditor must be independent, must not be a competitor of ours, and must be bound by confidentiality. You bear the cost. The twelve-month limits in this clause and in clause 12.1 do not apply where a supervisory authority requires otherwise, or following a personal data breach affecting your Customer Personal Data.

12.3 We hold no third-party security certification of our own application-layer controls today. Our infrastructure provider's certifications are its own and are not a certification of Typillar. We say so plainly on the Trust & Security page and will not represent otherwise.

13. Return and deletion

13.1 You can export your project data from the console at any time during the term.

13.2 On termination, or earlier at your request, we delete Customer Personal Data. Deleting an account removes its data immediately: there is no recovery window and no undo. Residual copies in backups and operational logs are purged on their ordinary retention cycle.

13.3 We may retain Customer Personal Data where a law we are subject to requires it, for as long as it requires, and we will keep it protected under this DPA and process it only for that purpose.

13.4 Deleting your Typillar account also removes the Workers, databases and buckets Typillar created in your own connected accounts, so nothing is left there that you can no longer reach through us. Resources you created yourself are untouched and remain governed by your contracts with those providers.

14. Liability

Each party's liability under this DPA is subject to the exclusions and limitations of liability in the Terms, and the aggregate cap there applies to claims under the Terms and this DPA taken together, not separately to each. Nothing in this clause limits either party's liability to a data subject, or any liability that cannot be limited under Data Protection Laws. Where the SCCs apply, nothing in this clause limits liability arising under them.

15. Term, conflict and governing law

15.1 This DPA takes effect when you accept the Terms and continues for as long as we process Customer Personal Data. Clauses that by their nature should survive, do.

15.2 If this DPA conflicts with the Terms, this DPA governs in respect of personal data. If the SCCs or the UK Addendum conflict with this DPA, they govern.

15.3 This DPA is governed by the law that governs the Terms, except where the SCCs or the UK Addendum specify otherwise, and except that nothing here deprives a data subject of the protection of the Data Protection Laws that apply to them.

15.4 We may update this DPA to reflect a change in Data Protection Laws, in the service, or in our sub-processors. Material changes are announced in the console or by email before they take effect.

Annex I — Description of processing

A. Parties

Data exporter / controller: the Customer accepting the Terms, whose identity and contact details are the account and billing details held in the console. Activities: use of Typillar to build, deploy and operate applications in its own cloud accounts.

Data importer / processor: Premsan Inc, 530-0001, 12-12, Osaka Ekimae Dai-2 Bldg., 1-2-2 Umeda, Kita-ku, Osaka-shi, Osaka, Japan. Contact: privacy@typillar.com. Activities: providing the Typillar control plane and agent harness.

B. Description of the processing

C. Competent supervisory authority

Where the SCCs apply under clause 11.2, the competent supervisory authority is that of the EEA member state in which the data exporter is established; or, where the data exporter is not established in the EEA but has appointed a representative under Article 27 GDPR, the supervisory authority of the member state in which that representative is established; or, failing that, the supervisory authority of the member state in which the data subjects whose personal data is transferred are located.

Annex II — Technical and organizational measures

Annex III — Sub-processors

As at the date of this DPA. The current list is maintained on the Trust & Security page and governs.

Sub-processor Processing Data Location
Cloudflare, Inc. Control-plane compute and storage (Workers, Durable Objects, D1, KV, Analytics Engine) Account metadata, project content and history, encrypted connection credentials, operational telemetry United States / global edge
Resend Transactional email Recipient email address and the contents of the message United States
Stripe, Inc. Subscription billing Billing name, email address, and subscription state United States

The cloud providers a Customer connects to run its own applications — Cloudflare, GitHub and Stripe under the Customer's own accounts — are the Customer's processors, not ours, and are not listed here. See clause 4.2.

Contact

Premsan Inc — 530-0001, 12-12, Osaka Ekimae Dai-2 Bldg., 1-2-2 Umeda, Kita-ku, Osaka-shi, Osaka, Japan. privacy@typillar.com.