← Back to Tightly

Data Processing Agreement

Last updated: 3 June 2026 · Version 1.0

ℹ️ Who needs this? This DPA is for business customers who are themselves data controllers under GDPR (e.g. companies, non-profits, public institutions) and need a formal GDPR Art. 28 processing agreement. If you are an individual using Tightly for personal journaling, the Privacy Policy and Terms of Service are sufficient.

1. Definitions

2. Scope and duration

This DPA forms part of the Terms of Service between you and Tightly. It applies to all personal data processed through Tightly on your behalf and remains in force for as long as your account is active, plus 30 days for backup deletion.

3. Subject matter and nature of processing

4. Categories of data and data subjects

4.1 Categories of data subjects

Determined by you (the Controller), typically:

4.2 Categories of personal data

Determined by you, typically:

5. Obligations of the Processor (Tightly)

We (the Processor) shall:

  1. Process personal data only on your documented instructions (via the Tightly interface, API, or support requests), unless required by EU or Member State law.
  2. Ensure personnel processing personal data are bound by confidentiality obligations.
  3. Implement appropriate technical and organisational measures (see Section 9 below).
  4. Assist you with data subject rights requests (access, erasure, rectification, portability) by providing the built-in export and deletion tools.
  5. Assist you with compliance for security, breach notification, and data protection impact assessments (DPIAs) by providing information about our technical safeguards and sub-processors.
  6. Delete or return all personal data at the end of services (account deletion), except where EU/Member State law requires retention.
  7. Make available all information necessary to demonstrate compliance with GDPR Art. 28 and allow for audits (see Section 11).

6. Obligations of the Controller (you)

You (the Controller) shall:

  1. Ensure you have a valid legal basis (GDPR Art. 6) for all personal data stored in Tightly.
  2. Provide appropriate privacy notices to your data subjects informing them that you use Tightly as a processor.
  3. Ensure you have necessary consents or other lawful grounds for processing sensitive categories of personal data (GDPR Art. 9), if applicable.
  4. Respond to data subject rights requests as the responsible controller. Tightly provides the tools; you handle the legal response.
  5. Not instruct us to process data in violation of GDPR. If we believe an instruction violates GDPR, we will inform you immediately (Art. 28(3)(a)).

7. Sub-processors

You give general written authorisation for us to engage the sub-processors listed in Section 7.1 below. We will notify you of any intended changes (new sub-processors or replacement) at least 14 days in advance by email to your account email or via an in-app announcement. You may object within 14 days if you have legitimate GDPR-related concerns. If we cannot accommodate your objection, you may terminate your account and request a refund of prepaid fees.

7.1 Current sub-processors

Sub-processor Service Location Safeguards
Supabase, Inc. Database, authentication, file storage EU (Frankfurt) DPA with SCCs
Vercel Inc. Web hosting, serverless APIs Global (EU edge preferred) DPA with SCCs
OpenAI, L.L.C. AI text generation, transcription, image analysis United States EU SCCs, Business Terms (no model training)
Stripe, Inc. Payment processing United States + EU DPA with SCCs, PCI-DSS Level 1
Functional Software, Inc. (Sentry) Error and crash diagnostics EU (Frankfurt) + US DPA with SCCs
PostHog, Inc. Product analytics (opt-in only) EU (Frankfurt) DPA

Each sub-processor is bound by obligations equivalent to this DPA through their own GDPR-compliant Data Processing Agreements.

8. International transfers

Most processing occurs within the EU (Supabase in Frankfurt, Germany). Where personal data is transferred to processors outside the EEA (OpenAI, Stripe, Sentry — all in the United States), we rely on the EU Standard Contractual Clauses (SCCs) adopted by the European Commission (Decision 2021/914).

You acknowledge and accept these international transfers and the associated SCCs.

9. Security measures (Art. 32 GDPR)

We implement the following technical and organisational measures:

9.1 Technical measures

9.2 Organisational measures

10. Personal data breach notification

If we become aware of a personal data breach (Art. 33/34 GDPR), we will:

  1. Notify you without undue delay and at latest within 72 hours of becoming aware, by email to your account email and via in-app notice.
  2. Provide:
  3. Cooperate with you to enable you to meet your own notification obligations to supervisory authorities and data subjects (where applicable).

Your responsibility: You (as Controller) must determine whether the breach requires notification to your supervisory authority or to affected data subjects. We provide the facts; you handle the legal obligation.

11. Audits and inspections

Upon reasonable written notice (at least 30 days), you may audit our compliance with this DPA by:

On-site inspections are limited to once per year unless a breach has occurred. You will bear all costs of audits, including our reasonable time charges if the audit exceeds 8 hours of our staff time.

12. Data subject rights assistance

We provide the following built-in tools to help you respond to data subject rights requests:

For complex requests (e.g., partial deletion, restriction with specific conditions), contact us at hello@tightly.nl with subject line "[DPA] Data Subject Request". We will respond within 5 business days with instructions or clarifications.

13. Deletion and return of data

Upon termination of the Terms of Service or account deletion:

  1. All personal data in active storage is immediately and irreversibly deleted.
  2. Backup copies are deleted within 30 days.
  3. We do not provide a "return" mechanism; instead, you must export data before account deletion using the built-in export tool.
  4. Retention beyond 30 days only occurs if required by EU or Member State law (e.g., tax records for Stripe transactions — 7 years).

14. Liability and indemnification

Each party's liability under this DPA is subject to the limitation of liability clause in the Terms of Service. However:

15. Governing law and disputes

This DPA is governed by the same law and dispute resolution provisions as the Terms of Service (Dutch law, courts of the Netherlands). However, GDPR rights and obligations apply regardless of governing law.

16. Order of precedence

If there is a conflict between this DPA and the Terms of Service, this DPA prevails on matters of data protection. If there is a conflict between this DPA and the Privacy Policy, this DPA prevails for business customers; the Privacy Policy prevails for individual consumers.

17. Accepting this DPA

By creating an account for your organisation, purchasing a Team or Enterprise plan, or otherwise using Tightly on behalf of a business entity, you accept this DPA on behalf of that entity.

If you need a signed (countersigned) copy of this DPA for your records or compliance team, email hello@tightly.nl with subject line "[DPA] Signature Request" and provide:

We will return a signed PDF within 10 business days.

18. Changes to this DPA

We may update this DPA to reflect changes in law or our practices. Material changes will be notified by email at least 30 days in advance. If you object, you may terminate your account within 30 days and receive a pro-rata refund.

19. Contact

DPA-related questions: hello@tightly.nl with subject line "[DPA]"

Data breach notifications: security@tightly.nl

Privacy Policy · Terms of Service · Cookie Policy