Data Processing Addendum
Last updated: June 26, 2026
This Data Processing Addendum ("DPA") forms part of the TKO Forge Terms of Service (the "Agreement") between TKO Cloud Solutions ("we", "us", "Processor") and the customer ("you", "Controller"). It applies where we process Personal Data on your behalf and reflects the parties' obligations under data-protection laws, including the EU/UK GDPR and applicable U.S. state privacy laws (collectively, "Data Protection Laws"). If you require a signed copy, contact legal@tkoforge.com.
1. Definitions
"Personal Data", "Controller", "Processor", "Processing", "Data Subject", and "Supervisory Authority" have the meanings in the GDPR. "Customer Personal Data" means Personal Data within the Customer Data you submit to the Service. "Subprocessor" means a third party we engage to process Customer Personal Data.
2. Roles & scope
For Customer Personal Data you are the Controller and we are the Processor. For data about your own account and use of the Service we act as an independent Controller (see the Privacy Policy). We process Customer Personal Data only to provide the Service and on your documented instructions, including as set out in the Agreement and this DPA.
3. Our obligations as Processor
We will:
- Process Customer Personal Data only on your documented instructions, including for international transfers, unless required by law (in which case we notify you unless the law prohibits it).
- Ensure persons authorized to process the data are bound by confidentiality.
- Implement appropriate technical and organizational security measures (Section 7).
- Respect the conditions in Section 4 for engaging Subprocessors.
- Assist you, taking into account the nature of processing, in responding to Data Subject requests (Section 5) and in your obligations for security, breach notification, and impact assessments.
- At your choice, delete or return Customer Personal Data at the end of the Service, and delete existing copies unless retention is required by law.
- Make available information necessary to demonstrate compliance and allow for and contribute to audits (Section 8).
- Notify you without undue delay if, in our opinion, an instruction infringes Data Protection Laws.
4. Subprocessors
You grant general authorization for us to engage Subprocessors to process Customer Personal Data. Our current Subprocessors are listed in the Privacy Policy. We impose data-protection obligations on each Subprocessor no less protective than this DPA and remain responsible for their performance. We will give you a way to be informed of changes to Subprocessors and a reasonable opportunity to object on legitimate data-protection grounds.
5. Data Subject requests
Taking into account the nature of processing, we will assist you with appropriate technical and organizational measures, insofar as possible, to respond to requests by Data Subjects to exercise their rights (access, correction, deletion, portability, restriction, objection). The Service also provides self-service export and deletion tools you can use to fulfill many such requests directly.
6. Personal Data breaches
We will notify you without undue delay after becoming aware of a Personal Data breach affecting Customer Personal Data, and provide information reasonably available to help you meet your breach-notification obligations.
7. Security
We maintain technical and organizational measures designed to protect Customer Personal Data, including: encryption in transit and at rest; multi-tenant logical isolation; least-privilege and role-based access controls; optional and enforceable two-factor authentication; secret storage isolated from the browser; rate limiting and anti-abuse controls; audit logging; and regular review of our controls. You are responsible for configuring the Service appropriately and securing your accounts and credentials.
8. Audits
On reasonable prior written request, no more than once per year (unless required by a Supervisory Authority), we will make available information reasonably necessary to demonstrate compliance with this DPA. Audits are subject to confidentiality and must not compromise the security or privacy of other customers; we may satisfy audit requests by providing relevant third-party reports or documentation where available.
9. International transfers
Where Customer Personal Data is transferred from the EEA, UK, or Switzerland to a country without an adequacy decision, the parties agree the applicable Standard Contractual Clauses (and the UK Addendum / Swiss amendments, as relevant) are incorporated by reference and apply to those transfers.
10. Liability & precedence
Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Agreement. If there is a conflict between this DPA and the Agreement regarding the processing of Customer Personal Data, this DPA controls.
11. Contact
Data-protection questions or to request a signed DPA: privacy@tkoforge.com · TKO Cloud Solutions · tkoforge.com.
© 2026 TKO Cloud Solutions. All rights reserved.