Last updated: July 7, 2026
This Data Protection Addendum ("Addendum") forms part of the agreement between Tartabit, LLC ("Tartabit") and the customer that receives Tartabit services ("Customer"). It applies when Tartabit processes Personal Data or Personal Information in connection with Tartabit IoT Bridge, related application services, support, hosted services, backend systems, webhook processing, or other services provided under the agreement.
This Addendum is intended to address privacy and data protection requirements for customer data processed by Tartabit. If there is a conflict between this Addendum and the agreement, this Addendum controls for the processing of Personal Data to the extent required by applicable Data Protection Laws.
In this Addendum:
Customer is the controller of Personal Data contained in Customer Data, except where Tartabit independently determines the purposes and means of processing for its own business operations. Tartabit acts as processor when it processes Customer Personal Data on Customer's behalf to provide the Services.
Tartabit acts as an independent controller for limited business operations data, such as account administration, billing, direct customer communications, service security, service performance, analytics for Tartabit's own website, and legal compliance. Tartabit's Privacy Policy describes these controller activities.
Customer is responsible for ensuring that it has all required rights, notices, consents, lawful bases, authorizations, and instructions necessary for Tartabit to process Personal Data under the agreement.
The subject matter of processing is Tartabit's provision, operation, maintenance, support, security, and improvement of the Services for Customer.
Tartabit processes Personal Data for the term of the agreement and for any additional period required for transition, deletion, backup expiration, dispute handling, legal compliance, or other permitted retention under the agreement or applicable law.
Tartabit processes Personal Data to:
Depending on Customer's configuration and use of the Services, Personal Data may include:
Customer controls the content of Customer Data and should avoid submitting sensitive or special category Personal Data unless necessary and permitted under the agreement and applicable Data Protection Laws.
Depending on Customer's use of the Services, Data Subjects may include:
Tartabit will process Customer Personal Data only on documented instructions from Customer, including the agreement, this Addendum, Customer's configuration of the Services, Customer's use of APIs and integrations, and Customer's written instructions, unless required to do otherwise by applicable law.
If Tartabit is required by law to process Customer Personal Data outside Customer's instructions, Tartabit will inform Customer before processing unless prohibited by law.
Tartabit will promptly inform Customer if, in Tartabit's opinion, an instruction infringes applicable Data Protection Laws.
Tartabit will ensure that personnel authorized to process Customer Personal Data are subject to confidentiality obligations or are under an appropriate statutory obligation of confidentiality.
Tartabit will implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data against unauthorized or unlawful processing and against accidental loss, destruction, damage, alteration, or disclosure.
Measures may include, as appropriate to the Services and risk:
Customer is responsible for secure configuration of Customer-controlled accounts, credentials, devices, integrations, payloads, and destinations.
Tartabit will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.
The notice will include, to the extent known and legally permitted:
Tartabit will reasonably cooperate with Customer in investigating, mitigating, and responding to the Personal Data Breach. Customer is responsible for determining whether notices to Data Subjects, regulators, customers, or other parties are required, except where Tartabit has an independent legal notification obligation.
Customer authorizes Tartabit to use subprocessors to provide the Services, subject to this Section 8.
Tartabit will enter into a written agreement with each subprocessor that imposes data protection obligations no less protective in substance than those applicable to Tartabit under this Addendum, to the extent applicable to the subprocessor's services.
Tartabit remains responsible for its subprocessors' performance of their data protection obligations to the extent required by applicable Data Protection Laws.
Tartabit will maintain a list of subprocessors that includes the provider, service, processing role, data categories, processing location, transfer mechanism, and effective date, where available. Tartabit may update the list from time to time.
Customer may object to a new subprocessor on reasonable data protection grounds by notifying Tartabit within 30 days after notice or publication of the update. The parties will work in good faith to address the objection. If the objection cannot be resolved, Customer may terminate the affected Services to the extent required by applicable Data Protection Laws and the agreement.
| Provider or Category | Service | Role | Data Categories | Processing Location | Transfer Mechanism | Effective Date |
|---|---|---|---|---|---|---|
| Microsoft Azure | Hosting, infrastructure, storage, networking, and related cloud services | Subprocessor | Customer Data, service logs, configuration, account and operational data | Regions selected for the Services or otherwise used to provide the Services | Adequacy, SCCs, UK Addendum/IDTA, Data Privacy Framework, or other applicable safeguard as available | Existing |
| Hosting and cloud providers | Website, application, infrastructure, security, logging, and availability services | Subprocessor/vendor | Customer Data, service logs, website data, operational data | United States, EU, UK, or other service locations depending on deployment | Adequacy, SCCs, UK Addendum/IDTA, Data Privacy Framework, or other applicable safeguard as available | Existing |
| Tartabit backend and webhook systems | Contact forms, service workflows, broken-link reports, API and webhook processing | Processor/internal systems | Contact data, webhook data, payloads, logs, technical data | United States or configured service regions | Internal controls and applicable transfer safeguards | Existing |
| Paddle | Checkout, subscription, tax, and payment processing | Independent controller or processor depending on context | Billing contact data, transaction data, tax and checkout records | Locations used by Paddle | Paddle terms and applicable transfer safeguards | Existing |
| Google Analytics | Website analytics after visitor consent | Vendor/independent provider | Website analytics identifiers, device/browser data, usage data | Locations used by Google | Google terms and applicable transfer safeguards | Existing |
| Microsoft Azure Marketplace and AWS Marketplace | Marketplace listing, procurement, subscription, and deployment workflows | Independent marketplace provider | Marketplace account, subscription, purchase, and deployment data | Locations used by the marketplace provider | Marketplace terms and applicable transfer safeguards | Existing |
Customer should request the current production subprocessor list before relying on this table for procurement or audit purposes.
Taking into account the nature of the processing and information available to Tartabit, Tartabit will reasonably assist Customer with:
Customer is responsible for receiving, validating, and responding to Data Subject requests where Customer is the controller. If Tartabit receives a request directly from a Data Subject concerning Customer Personal Data, Tartabit may direct the request to Customer or notify Customer unless prohibited by law.
Upon termination or expiration of the Services, Tartabit will delete or return Customer Personal Data in accordance with the agreement, Customer's written instructions, and applicable law.
Tartabit may retain Customer Personal Data to the extent required by law, backup retention, security, dispute resolution, compliance, or legitimate business records, provided that retained Personal Data remains protected under this Addendum and is not processed for other purposes except as permitted by law.
Deletion from backups may occur according to Tartabit's standard backup lifecycle.
Upon reasonable written request, Tartabit will make available information necessary to demonstrate compliance with this Addendum and applicable processor obligations.
Customer may request an audit of Tartabit's processing of Customer Personal Data no more than once in any 12-month period, unless a Personal Data Breach or Data Protection Law requires earlier review. Audits must be limited to the relevant processing, conducted during normal business hours, subject to reasonable advance notice, and performed in a manner that does not compromise security, confidentiality, service availability, or other customers' data.
Tartabit may satisfy audit requests through security documentation, third-party reports, certifications, written responses, or other appropriate evidence where reasonable. If an audit identifies a material non-compliance, Tartabit will reasonably remediate it.
Tartabit and its subprocessors may process Customer Personal Data in the United States and other countries where Tartabit or its subprocessors operate.
Where Customer Personal Data is subject to GDPR, UK GDPR, or similar transfer restrictions, Tartabit will use appropriate transfer safeguards where required. These may include:
Customer authorizes Tartabit to enter into SCCs, the UK Addendum, the IDTA, or other transfer instruments with subprocessors on Customer's behalf where necessary for Tartabit to provide the Services.
Tartabit does not rely on Data Subject consent alone as the basis for Customer Personal Data transfers performed under this Addendum.
Customer will:
Tartabit is not currently subject to the California Consumer Privacy Act, as amended by the California Privacy Rights Act, because Tartabit is below the applicability thresholds. This Section 14 applies only to the extent Customer is a business subject to the CCPA/CPRA and the parties' processing relationship requires service provider or contractor terms.
For purposes of this Section 14, terms such as "business", "business purpose", "commercial purpose", "consumer", "contractor", "personal information", "sell", "share", and "service provider" have the meanings given under the CCPA/CPRA.
Tartabit will process Customer personal information only for the limited and specified business purposes described in the agreement, this Addendum, Customer's instructions, and Customer's configuration of the Services.
Tartabit will not:
Tartabit will provide the same level of privacy protection required by CCPA/CPRA for service providers and contractors, will notify Customer if Tartabit determines it can no longer meet its applicable obligations, and will cooperate with reasonable steps by Customer to verify and remediate Tartabit's use of Customer personal information.
Tartabit may use subcontractors to process Customer personal information only under a written contract requiring privacy protections consistent with this Section 14.
For Personal Data not governed by the GDPR, UK GDPR, CCPA/CPRA, or another specific law addressed above, Tartabit will process Personal Data in accordance with the agreement, this Addendum, and applicable Data Protection Laws.
Tartabit may create aggregated, de-identified, or anonymized information from service data for security, operations, analytics, research, and service improvement, provided the information does not identify Customer or any individual and is not reasonably linkable to an individual where applicable law requires de-identification.
Liability under this Addendum is governed by the agreement, except to the extent applicable Data Protection Laws require otherwise.