Data Processing Addendum

This Data Processing Addendum («DPA») forms part of the Terms of Use between WALLMANS LTD («Processor») and the organization that uses Taktia («Controller»). Last updated: 13 August 2026.

1. Roles

For customer, project, task, file, comment, and similar work data entered into an organization, the organization is the Controller and WALLMANS LTD is the Processor. For account registration, authentication, billing identifiers, and marketing-site logs, WALLMANS LTD is an independent controller, as described in the Privacy Policy.

2. Subject matter and duration

The Processor hosts and processes work data so the Controller can use Taktia. Processing lasts for the life of the organization plus the retention windows in the Privacy Policy (30-day purge after deletion; 60-day read-only after a lapsed subscription).

3. Nature and purpose

Storage, retrieval, display, search, notification, export, and deletion of work data, and related security, backup, and support operations.

4. Types of data and data subjects

Data subjects are the Controller’s members and the people whose details the Controller records (customers, contacts, and anyone named in tasks, comments, or files). Categories include names, emails, phone numbers, addresses, work notes, files, and timestamps. The Controller must not upload special-category data unless it has a lawful basis and has instructed the Processor in writing.

5. Processor obligations

  1. Process work data only on documented instructions from the Controller.
  2. Ensure persons authorised to process the data are bound by confidentiality.
  3. Implement appropriate technical and organisational measures (encryption in transit, access control, tenant isolation, backups).
  4. Assist the Controller with data-subject requests, DPIAs, and breach notification (without undue delay, and within 72 hours of becoming aware of a personal-data breach affecting the Controller’s data).
  5. Delete or return work data at the end of the service, subject to statutory retention.
  6. Make available information necessary to demonstrate compliance and allow audits on reasonable notice.

6. Sub-processors

The Controller authorises the following sub-processors:

  • Vercel Inc. — application hosting (United States / EU edge).
  • Neon / Vercel Postgres — database hosting.
  • Vercel Blob — file storage.
  • Stripe, Inc. — payments (merchant of record).
  • Resend — transactional email.
  • Functional Software, Inc. (Sentry) — error reporting, when enabled.

The Processor will impose equivalent data-protection obligations on sub-processors and remains liable for their performance. New sub-processors will be listed here; the Controller may object on reasonable grounds within 14 days.

7. International transfers

Where a sub-processor processes data outside the EEA, the Processor relies on an adequacy decision or Standard Contractual Clauses.

8. Security incidents

The Processor will notify the Controller without undue delay after becoming aware of a personal-data breach affecting the Controller’s work data, with sufficient information for the Controller to meet its own notification duties.

9. Governing law

This DPA is governed by the same law as the Terms of Use. For GDPR Article 28 questions: info@taktia.app.