01Scope and parties
This Data Processing Addendum (the “DPA”) is part of the Terms of Service between Tako (“Tako”) and the business that uses Tako (the “Customer”). It applies automatically whenever Tako processes Personal Information on the Customer’s behalf. No signature is needed; accepting the Terms accepts this DPA.
If this DPA conflicts with the Terms, this DPA controls for Personal Information. Anything not covered here is governed by the Terms.
02Definitions
- Privacy Laws: US privacy laws that apply to the processing, including the California Consumer Privacy Act as amended by the California Privacy Rights Act and its regulations (the “CCPA”), and other state consumer privacy laws.
- Personal Information: information about an identified or identifiable person that Tako processes for the Customer through the Service, mainly information about the Customer’s clients, contacts and team. Terms such as business, service provider, controller, processor, consumer, sell, share and business purpose have the meanings given in the Privacy Laws.
- Subprocessor: a company Tako engages that may process Personal Information to help provide the Service.
- Security Incident: a confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to Personal Information.
03Roles and instructions
The Customer is the business (or controller) for Personal Information, and Tako is its service provider (or processor). Tako processes Personal Information only on the Customer’s documented instructions. Those instructions are the Terms, this DPA, and the Customer’s use and configuration of the Service, such as the records it creates, the messages it approves and the features it switches on.
Tako will tell the Customer if it believes an instruction breaks a Privacy Law. The Customer is responsible for the lawfulness of its instructions and for giving its clients any notices and obtaining any consents the Privacy Laws require.
04CCPA service-provider terms
For Personal Information subject to the CCPA, Tako:
- processes it only for the limited and specified business purpose of providing, securing, supporting and improving the Service for the Customer, as described in the Terms and Annex 1;
- does not sell it or share it (including for cross-context behavioral advertising);
- does not retain, use or disclose it for any purpose other than that business purpose, including any commercial purpose, or outside the direct business relationship between Tako and the Customer, except as the CCPA and its regulations permit;
- does not combine it with personal information Tako receives from or on behalf of anyone else, or collects from its own interactions with consumers, except as the CCPA regulations permit;
- complies with the CCPA obligations that apply to it as a service provider, and gives the Personal Information the same level of privacy protection the CCPA requires of businesses;
- allows the Customer to take reasonable and appropriate steps to make sure Tako uses the Personal Information in a way consistent with the Customer’s CCPA obligations (see Information and audits);
- will notify the Customer if Tako determines it can no longer meet its CCPA obligations;
- allows the Customer, on notice, to take reasonable and appropriate steps to stop and remediate any unauthorized use of the Personal Information;
- helps the Customer respond to consumer requests: the Customer will tell Tako about any request Tako must act on, and Tako will act on it as described in Consumer requests.
Tako certifies that it understands these restrictions and will comply with them. Tako does not receive Personal Information as consideration for the Service; the Customer pays a subscription fee.
05Other state privacy laws
Where another state’s privacy law (such as those of Virginia, Colorado, Connecticut, Utah, Texas or Oregon) applies, Tako acts as the Customer’s processor and, in addition to the rest of this DPA: keeps Personal Information confidential; deletes or returns it at the end of the Service as described in Return and deletion; makes available the information needed to show compliance; allows reasonable assessments; and binds its Subprocessors to equivalent written terms.
06Confidentiality of personnel
Tako limits access to Personal Information to the people who need it to provide or support the Service, and makes sure they are bound by confidentiality obligations.
07Security
Tako maintains reasonable administrative, technical and physical safeguards appropriate to the nature of the Personal Information, including the measures in Annex 2. Tako may update those measures over time, but will not reduce the overall level of protection.
08Subprocessors
The Customer authorizes Tako to use the Subprocessors listed in Annex 3. Tako binds each one by written contract to data-protection terms at least as protective as this DPA, and remains responsible for their work.
Before a new Subprocessor starts processing Personal Information, Tako will update Annex 3 and email the workspace owner at least 30 days in advance. If the Customer objects on reasonable data-protection grounds, the parties will discuss it in good faith; if they can’t resolve it, the Customer may cancel and receive a refund of prepaid fees for the unused part of its billing period.
09Consumer requests
The Service lets the Customer find, correct, export and delete its clients’ records itself. If Tako receives a request directly from one of the Customer’s clients, it will pass it to the Customer without undue delay and will not respond itself except to direct the person to the Customer. Where the Customer cannot handle a request through the Service, Tako will provide reasonable help.
10Security incidents
Tako will notify the Customer without undue delay, and in any case within 72 hours, after confirming a Security Incident affecting the Customer’s Personal Information. The notice will describe what happened, the data affected, and the steps taken, as far as Tako knows at the time, and Tako will update it as it learns more. Tako will take reasonable steps to contain the incident and will help the Customer meet any breach-notification duties it has under state law. Notifying the Customer is not an admission of fault.
11Return and deletion
The Customer can export its data as CSV files at any time while its workspace is active or lapsed. When the Service ends (a trial or subscription lapses), Tako keeps the Personal Information for at least 90 days so the Customer can renew or export it; after that, Tako may delete it. When Tako deletes it, backup copies are overwritten on the backups’ normal rotation. The Customer may ask for deletion earlier, at any time, at legal@takobms.com, and Tako will delete it on that request, except where the law requires Tako to keep it.
Whatever Tako keeps, during the retention period or because the law requires it, it keeps protecting under this DPA and uses only to provide the Service or meet that legal duty.
12Information and audits
On written request, no more than once a year (or after a Security Incident), Tako will answer a reasonable security and privacy questionnaire and provide the information reasonably needed to show compliance with this DPA. Any further audit will be agreed in advance, at the Customer’s cost, during business hours, and under confidentiality terms.
13Where data is processed
Tako’s primary database is hosted in the United States. Subprocessors may process Personal Information in other countries, only under the protections required by this DPA.
14Liability and term
Each party’s liability under this DPA is subject to the limitation of liability in the Terms. This DPA lasts as long as Tako processes Personal Information for the Customer.
15Annex 1 — Details of processing
- Subject matter and purpose: providing the Service: storing and organizing the Customer’s records, producing documents and drafts, sending messages the Customer approves or switches on, collecting inquiries, bookings and signatures, and supporting and securing the Service.
- Duration: while the Customer uses the Service, plus the retention period in Return and deletion.
- Nature of processing: collection, storage, organization, retrieval, display, transmission, AI-assisted drafting the Customer requests, and deletion.
- People concerned: the Customer’s clients, leads and contacts, their representatives, and the Customer’s team members.
- Types of Personal Information: names, email addresses, phone numbers, postal and project addresses, project and event details, notes, messages, quotes, invoices, payment status, e-signatures with IP address and browser details, and any other information the Customer chooses to store.
- Sensitive information: none is required. The Customer should not store sensitive personal information in Tako unless the Service is designed for it.
16Annex 2 — Security measures
- Encryption in transit (HTTPS/TLS) for all traffic to the Service.
- Data stored with infrastructure providers that encrypt it at rest.
- Workspace isolation enforced in the database itself (row-level security), so each request can reach only the records of the workspace the signed-in user belongs to.
- Role-based access inside each workspace (owner, admin, staff), with billing and finance actions limited to owners and admins.
- Client-facing links use long random tokens and are excluded from search engines.
- Secrets and API keys kept out of source code and limited to the servers that need them.
- Access to production systems limited to the people who need it.
- Automated backups through the database provider.
- Incident response: investigation, containment and customer notice as described in this DPA.
17Annex 3 — Subprocessors
| provider | what they do for us | data involved |
|---|---|---|
| Supabase | Database, authentication and file storage | All workspace data and account credentials |
| Vercel | Application hosting and content delivery | Request data passing through the application, server logs |
| Stripe | Subscription billing, and client payments on each business's own connected Stripe account | Billing contact and payment details; connected-account status; client payment amounts and references |
| Resend | Sending email on the customer's behalf, and reporting bounces and spam complaints | Recipient addresses, message content and delivery events |
| Anthropic | AI drafting features (when used) | The records an AI feature is asked to work from |
These services receive limited data only when the related feature is used or switched on:
| provider | what they do for us | data involved |
|---|---|---|
| Sentry | Error monitoring (only when enabled) | Error details and the request context around them |
| OpenStreetMap Nominatim | Turning job addresses into map points | The address text being looked up |
| CARTO | Map background tiles | The viewer's IP address and the map area requested |
AI drafting through Anthropic is used only on plans that include AI features: when someone in the workspace asks for a draft, or when a new inquiry arrives and a suggested reply is prepared. Personal Information sent for drafting is not used to train AI models, by Tako or by Anthropic under its commercial terms.