← Back to Tightly
Data Processing Agreement
Last updated: 3 June 2026 · Version 1.0
ℹ️ Who needs this?
This DPA is for
business customers who are themselves data controllers under GDPR (e.g. companies, non-profits, public institutions) and need a formal GDPR Art. 28 processing agreement. If you are an individual using Tightly for personal journaling, the
Privacy Policy and
Terms of Service are sufficient.
1. Definitions
- Controller: You, the business customer, who determines the purposes and means of processing.
- Processor: Tightly (Magnus Jerono, eenmanszaak, Netherlands), who processes personal data on your behalf.
- Data Subject: The individuals whose personal data you process using Tightly (e.g., your employees, customers, collaboration partners).
- Personal Data: All content you store in Tightly that relates to identified or identifiable individuals.
- Sub-processor: Third-party service providers we engage to assist with processing (e.g., Supabase, OpenAI).
2. Scope and duration
This DPA forms part of the Terms of Service between you and Tightly. It applies to all personal data processed through Tightly on your behalf and remains in force for as long as your account is active, plus 30 days for backup deletion.
3. Subject matter and nature of processing
- Subject matter: Provision of a journaling and memory-capturing service with optional AI-powered features.
- Nature of processing: Storage, retrieval, encryption, backup, optional AI text generation, transcription, and image analysis; export and deletion on instruction.
- Purpose: Enable the Controller to provide a secure journaling tool to its users/employees/members.
4. Categories of data and data subjects
4.1 Categories of data subjects
Determined by you (the Controller), typically:
- Employees or contractors of the Controller
- Customers, clients, or members of the Controller
- Third parties mentioned in journal entries
4.2 Categories of personal data
Determined by you, typically:
- Email addresses, names, user-generated profile data
- Journal entries (free-text, potentially including sensitive data)
- Voice recordings and transcripts
- Photos and image files (potentially including biometric data if face recognition enabled)
- Location text (place names)
- Usage metadata (timestamps, device type)
5. Obligations of the Processor (Tightly)
We (the Processor) shall:
- Process personal data only on your documented instructions (via the Tightly interface, API, or support requests), unless required by EU or Member State law.
- Ensure personnel processing personal data are bound by confidentiality obligations.
- Implement appropriate technical and organisational measures (see Section 9 below).
- Assist you with data subject rights requests (access, erasure, rectification, portability) by providing the built-in export and deletion tools.
- Assist you with compliance for security, breach notification, and data protection impact assessments (DPIAs) by providing information about our technical safeguards and sub-processors.
- Delete or return all personal data at the end of services (account deletion), except where EU/Member State law requires retention.
- Make available all information necessary to demonstrate compliance with GDPR Art. 28 and allow for audits (see Section 11).
6. Obligations of the Controller (you)
You (the Controller) shall:
- Ensure you have a valid legal basis (GDPR Art. 6) for all personal data stored in Tightly.
- Provide appropriate privacy notices to your data subjects informing them that you use Tightly as a processor.
- Ensure you have necessary consents or other lawful grounds for processing sensitive categories of personal data (GDPR Art. 9), if applicable.
- Respond to data subject rights requests as the responsible controller. Tightly provides the tools; you handle the legal response.
- Not instruct us to process data in violation of GDPR. If we believe an instruction violates GDPR, we will inform you immediately (Art. 28(3)(a)).
7. Sub-processors
You give general written authorisation for us to engage the sub-processors listed in Section 7.1 below. We will notify you of any intended changes (new sub-processors or replacement) at least 14 days in advance by email to your account email or via an in-app announcement. You may object within 14 days if you have legitimate GDPR-related concerns. If we cannot accommodate your objection, you may terminate your account and request a refund of prepaid fees.
7.1 Current sub-processors
| Sub-processor |
Service |
Location |
Safeguards |
| Supabase, Inc. |
Database, authentication, file storage |
EU (Frankfurt) |
DPA with SCCs |
| Vercel Inc. |
Web hosting, serverless APIs |
Global (EU edge preferred) |
DPA with SCCs |
| OpenAI, L.L.C. |
AI text generation, transcription, image analysis |
United States |
EU SCCs, Business Terms (no model training) |
| Stripe, Inc. |
Payment processing |
United States + EU |
DPA with SCCs, PCI-DSS Level 1 |
| Functional Software, Inc. (Sentry) |
Error and crash diagnostics |
EU (Frankfurt) + US |
DPA with SCCs |
| PostHog, Inc. |
Product analytics (opt-in only) |
EU (Frankfurt) |
DPA |
Each sub-processor is bound by obligations equivalent to this DPA through their own GDPR-compliant Data Processing Agreements.
8. International transfers
Most processing occurs within the EU (Supabase in Frankfurt, Germany). Where personal data is transferred to processors outside the EEA (OpenAI, Stripe, Sentry — all in the United States), we rely on the EU Standard Contractual Clauses (SCCs) adopted by the European Commission (Decision 2021/914).
You acknowledge and accept these international transfers and the associated SCCs.
9. Security measures (Art. 32 GDPR)
We implement the following technical and organisational measures:
9.1 Technical measures
- Encryption in transit: TLS 1.3, HTTPS enforced, HSTS preload
- Encryption at rest: Database and file storage encrypted by Supabase (AES-256)
- Access control: Row-level security (RLS) in Postgres; every query scoped to user ID
- Authentication: Supabase Auth with argon2/bcrypt hashing, JWT-based API access
- Network security: Firewalled database (no public Postgres port), API behind Vercel edge with rate limits
- Security headers: CSP, X-Content-Type-Options, frame-ancestors none, CORS restrictions
9.2 Organisational measures
- Principle of least privilege: staff and service accounts have minimal necessary permissions
- Pseudonymisation: users identified by random UUIDs, not by email in database keys
- Logging and monitoring: server logs (30 days), Sentry alerts for anomalies
- Backup and recovery: automated daily backups retained for 30 days, tested quarterly
- Vendor security: all sub-processors selected based on their ISO 27001, SOC 2, or equivalent certifications
10. Personal data breach notification
If we become aware of a personal data breach (Art. 33/34 GDPR), we will:
- Notify you without undue delay and at latest within 72 hours of becoming aware, by email to your account email and via in-app notice.
- Provide:
- Nature of the breach (categories and approximate number of data subjects and records affected)
- Likely consequences
- Measures taken or proposed to mitigate
- Cooperate with you to enable you to meet your own notification obligations to supervisory authorities and data subjects (where applicable).
Your responsibility: You (as Controller) must determine whether the breach requires notification to your supervisory authority or to affected data subjects. We provide the facts; you handle the legal obligation.
11. Audits and inspections
Upon reasonable written notice (at least 30 days), you may audit our compliance with this DPA by:
- Reviewing our Security Policy and documentation of technical measures
- Requesting copies of our sub-processors' DPAs and certifications (SOC 2, ISO 27001)
- Engaging a mutually agreed-upon third-party auditor (at your expense) to review our practices, subject to a mutual NDA
On-site inspections are limited to once per year unless a breach has occurred. You will bear all costs of audits, including our reasonable time charges if the audit exceeds 8 hours of our staff time.
12. Data subject rights assistance
We provide the following built-in tools to help you respond to data subject rights requests:
- Right of access (Art. 15): Settings → Data & Privacy → Export (downloads JSON with all user data)
- Right to rectification (Art. 16): Users can edit entries directly in the app
- Right to erasure (Art. 17): Settings → Delete Account (immediate, irreversible)
- Right to data portability (Art. 20): Export provides machine-readable JSON
- Right to restriction (Art. 18): Contact us to temporarily suspend processing without deletion
For complex requests (e.g., partial deletion, restriction with specific conditions), contact us at hello@tightly.nl with subject line "[DPA] Data Subject Request". We will respond within 5 business days with instructions or clarifications.
13. Deletion and return of data
Upon termination of the Terms of Service or account deletion:
- All personal data in active storage is immediately and irreversibly deleted.
- Backup copies are deleted within 30 days.
- We do not provide a "return" mechanism; instead, you must export data before account deletion using the built-in export tool.
- Retention beyond 30 days only occurs if required by EU or Member State law (e.g., tax records for Stripe transactions — 7 years).
14. Liability and indemnification
Each party's liability under this DPA is subject to the limitation of liability clause in the Terms of Service. However:
- If you (the Controller) instruct us to process data in violation of GDPR and we inform you but you insist, you indemnify us against fines, claims, and costs arising from that unlawful instruction.
- If we (the Processor) fail to comply with GDPR obligations specifically directed at processors (Art. 28-36) and you suffer a fine or claim as a result, we are liable to the extent permitted by the Terms of Service.
15. Governing law and disputes
This DPA is governed by the same law and dispute resolution provisions as the Terms of Service (Dutch law, courts of the Netherlands). However, GDPR rights and obligations apply regardless of governing law.
16. Order of precedence
If there is a conflict between this DPA and the Terms of Service, this DPA prevails on matters of data protection. If there is a conflict between this DPA and the Privacy Policy, this DPA prevails for business customers; the Privacy Policy prevails for individual consumers.
17. Accepting this DPA
By creating an account for your organisation, purchasing a Team or Enterprise plan, or otherwise using Tightly on behalf of a business entity, you accept this DPA on behalf of that entity.
If you need a signed (countersigned) copy of this DPA for your records or compliance team, email hello@tightly.nl with subject line "[DPA] Signature Request" and provide:
- Your full legal entity name and registration number
- Billing address
- Signatory name and title
We will return a signed PDF within 10 business days.
18. Changes to this DPA
We may update this DPA to reflect changes in law or our practices. Material changes will be notified by email at least 30 days in advance. If you object, you may terminate your account within 30 days and receive a pro-rata refund.
19. Contact
DPA-related questions: hello@tightly.nl with subject line "[DPA]"
Data breach notifications: security@tightly.nl
Privacy Policy · Terms of Service · Cookie Policy