Your ultimate SaaS platform for powerful, simple AI tools, PDF converters, and smart file processing.

Data Processing Addendum - Toolzip AI

Data Processing Addendum

Governing file processing streams, document privacy, and compliance with GDPR, CCPA, and global privacy standards for Toolzip AI.

1. Scope and Legal Roles

This Data Processing Addendum ("DPA") supplements the Toolzip AI Terms of Service and applies to all file conversion processing and API requests involving Personal Data.

Under applicable Data Protection Regulations (including EU/UK GDPR and CCPA/CPRA):

  • Customer (You): Acts as the Data Controller or Business retaining full control over documents, PDFs, and payloads uploaded to Toolzip AI.
  • Toolzip AI (Us): Acts as the Data Processor or Service Provider executing automated file transformations strictly per your instructions.

2. Data Security & Technical Commitments

Toolzip AI enforces technical and organizational controls to protect document data from unauthorized access or exposure during the conversion process.

🔒 In-Transit & At-Rest Encryption

All file uploads and converted outputs utilize TLS 1.3 in transit and AES-256 encryption at rest.

Protocol: AES-256

⚡ Temporary Processing Buffer

Files exist in isolated temporary server memory only for the duration required to complete the AI conversion.

Short Lifecycle

🛡️ Automated Deletion

Converted documents are automatically purged from our caching layers after download expiration.

Zero Retention

🔐 Restricted Infrastructure

Automated engine execution operates under multi-factor access protocols without human access to document content.

Isolated Workflows

3. Sub-Processors & Data Transfers

3.1 Cloud Infrastructure Sub-Processors

Customer authorizes Toolzip AI to engage vetted third-party cloud hosting and compute providers (such as AWS and GCP) strictly to run conversion algorithms. All sub-processors are bound by data protection obligations no less restrictive than this DPA.

3.2 Cross-Border Transfers

If file processing involves cross-border transfers outside the European Economic Area (EEA), UK, or Switzerland, Toolzip AI ensures compliance using Standard Contractual Clauses (SCCs) approved by the European Commission.

4. Incident Management & Controller Rights

4.1 72-Hour Security Incident Notice

In the event of a confirmed security incident impacting your account data, Toolzip AI will notify you without undue delay (and no later than 72 hours after verification) with incident details to support your regulatory reporting requirements.

4.2 Data Subject Requests

We provide standard account tools enabling you to delete files, revoke API keys, or erase account records in fulfillment of Data Subject Access Requests (DSARs).

Scroll to Top