Data Processing Addendum

In effect since

Parties and scope

Throughplan is provided by GRIIND s. r. o., Mierová 1099/66, 064 01 Stará Ľubovňa, Slovakia, company ID 53 821 173, VAT ID SK2121505331, registered in the Commercial Register of the District Court Prešov, section Sro, file no. 42298/P.

This Addendum forms part of the Terms of Service between that company (the “processor”, “we”) and the customer that holds a Throughplan workspace (the “controller”, “you”). It applies whenever we process personal data on your behalf, and it prevails over the Terms where the two differ on data protection.

It covers “customer data”: the content of your workspace’s projects and the personal data of the people you add to it. Data we handle as a controller in our own right — accounts, sign-in sessions, usage records, security logs and feedback — is covered by the Privacy Policy instead.

Subject matter, nature and purpose

We store, display, synchronize and share customer data, and send the invitation emails you trigger, solely to provide Throughplan to you. Processing lasts for as long as your workspace exists and ends with its deletion.

The AI engine runs on your own devices, against an AI provider you engage directly. We do not send customer data to any AI model, and that provider is not our sub-processor.

Data subjects and categories of data

  • Data subjects: your workspace members, people you invite, your client accounts, guests who comment through a share link, and any person your project content mentions.
  • Categories: names, email addresses, roles and access grants; comments (including a guest’s typed name); change requests, decisions and activity; assistant chat messages and attached images; and any other personal data you choose to put in a project.
  • Special categories of personal data are not needed for the service, and you must not store them unless you have a lawful basis and it is necessary.

Our obligations

  • We process customer data, including any transfer of it outside the EU/EEA, only on your documented instructions, unless EU or Slovak law requires otherwise; in that case we tell you before we process it, unless that law forbids telling you. The Terms, this Addendum and your use of the product’s features are your instructions. If we believe an instruction breaks data protection law, we tell you immediately.
  • Everyone we authorize to access customer data is bound to confidentiality.
  • We apply the security measures described below and keep them up to date.
  • We help you respond to requests from data subjects, mainly through the self-service tools in the product, and assist with data protection impact assessments and consultations where our processing is relevant.
  • We notify you of a personal data breach affecting customer data without undue delay, and where feasible within 48 hours of becoming aware of it, with the information you need to meet your own obligations.
  • We make available the information needed to demonstrate compliance with Article 28 and allow audits by you or an auditor you appoint, on 30 days’ written notice, at most once a year unless a breach or an authority requires otherwise, and without access to other customers’ data.

Security measures

  • The application, its database and its file storage run on a server in the European Union.
  • All traffic is encrypted in transit with TLS.
  • Each workspace’s data is isolated in the database with row-level security, and the application connects with a least-privilege role that cannot bypass it.
  • The database is reachable only over a private network.
  • Passwords are stored as salted hashes, sessions can be reviewed and revoked, and requests are rate-limited.
  • Sensitive actions are recorded in an append-only audit log per workspace.
  • Passwords, tokens and similar secrets are removed from logs and error reports.
  • Administrative access to the servers is limited to our own staff and protected by key-based authentication.

Sub-processors

You authorize us to use the following sub-processors:

  • Contabo GmbH — Server hosting for the application, its database and file storage. Location: Germany; the server is located in the European Union.
  • Mailjet SAS (part of the Sinch group) — Sending account, invitation and access emails. Location: France (European Union); email data is hosted in the European Union. Transfer safeguard: for its support providers outside the EU, the European Commission’s Standard Contractual Clauses in its data processing agreement.
  • Stripe Payments Europe, Limited — Taking card payments, issuing invoices and sending billing emails for paid plans. Location: Ireland (European Union). Transfer safeguard: for transfers to Stripe, Inc. in the United States, the EU–US Data Privacy Framework and the European Commission’s Standard Contractual Clauses in its data processing agreement.
  • Google Ireland Limited (Google Tag Manager) — Loading the measurement tags we have configured on our website and apps, and only for visitors who accept optional cookies. Location: Ireland (European Union), with processing by Google LLC in the United States. Transfer safeguard: EU–US Data Privacy Framework certification, with the European Commission’s Standard Contractual Clauses as a fallback.
  • Functional Software, Inc. (Sentry) — Error monitoring for our servers, and for the web app when you allow it. Location: United States. Transfer safeguard: EU–US Data Privacy Framework certification, with the European Commission’s Standard Contractual Clauses as a fallback.

Each sub-processor is bound by data protection terms at least as protective as this Addendum, and we remain responsible for its performance. We announce any new sub-processor on this page at least 14 days before it starts processing customer data. If you object on reasonable data protection grounds and we cannot address the objection, you may end the agreement and delete your workspace.

International transfers

Customer data is stored in the European Union. Where a sub-processor processes data outside the EU/EEA, the transfer relies on the safeguard stated for it above.

Return and deletion

You can export customer data at any time: all of a workspace’s projects as JSON with Markdown, and any single project as JSON, Markdown or PDF.

When a workspace owner deletes the workspace, its projects, members, invitations, client access, comments, activity, audit log and the images attached in its builder chats are deleted immediately.

When a member leaves a workspace — removed by an owner or admin, or by deleting their own account — the projects they own stay in the workspace and pass to its longest-standing owner, so your data is not lost with a person’s account.

When the agreement ends, or when we stop offering the service after the notice the Terms describe, you can export customer data until the end date. We then delete it, including any copies, unless EU or Slovak law requires us to keep it.

Liability and contact

The limitations of liability in the Terms of Service apply to this Addendum as far as the law allows.

Questions about this Addendum: info@throughplan.com.