Last updated: September 28, 2026
This Data Processing Addendum (“DPA”) is between Itay Rose Ari, operating Tonpit, Yehuda HaNasi 13, Tel Aviv 6920013, Israel (“Tonpit”), and the account holder that uses Tonpit for a business, trade or profession (“Customer”). It is part of the Terms of Service and applies automatically whenever Tonpit processes personal data on Customer’s behalf (“Customer Personal Data”). No separate signature is needed; a signed copy is available on request from hello@tonpit.com.
It applies to processing subject to the GDPR, the UK GDPR, the Israeli Privacy Protection Law 5741-1981 and its regulations, and other data protection laws that apply to Customer Personal Data (“Data Protection Law”). Terms such as “controller,” “processor,” “personal data,” “processing” and “data subject” have the meanings Data Protection Law gives them.
Customer is the controller of Customer Personal Data, or a processor acting for its own clients; Tonpit is Customer’s processor, or sub-processor. Tonpit is a controller only of the account and billing data it needs to run Customer’s account, which its Privacy Policy covers.
Customer is responsible for having a lawful basis for the Customer Personal Data it puts into Tonpit, for giving the notices and getting the consents required, including from people who appear in its images, video and audio, and for its instructions complying with Data Protection Law.
Tonpit processes Customer Personal Data, including any transfer to a third country, only on Customer’s documented instructions, unless the law requires otherwise, in which case Tonpit tells Customer before processing unless the law forbids it. Those instructions are the Terms, this DPA, and Customer’s use and settings of the Service, including instructions given through AI agents Customer connects. Tonpit tells Customer if it believes an instruction breaks Data Protection Law, unless the law forbids telling. Tonpit does not sell Customer Personal Data or use it to train AI models.
The details of the processing are in Annex 1.
Everyone Tonpit authorizes to process Customer Personal Data is bound by confidentiality, and may access it only to provide and operate the Service, including monitoring its quality and cost, to give support Customer asks for, or for security, abuse prevention and legal obligations.
Tonpit maintains the technical and organizational measures in Annex 2, and may improve them as long as the overall level of protection does not go down.
Customer authorizes Tonpit to use the sub-processors in Annex 3. Tonpit binds each one to data protection terms that protect Customer Personal Data at least as well as this DPA, and remains responsible to Customer for their performance.
Before adding or replacing a sub-processor, including a model developer, Tonpit updates Annex 3 at least 14 days in advance, with the date it takes effect, and emails the change to every Customer who has asked to receive these notices by writing to hello@tonpit.com. Customer may object on reasonable data protection grounds within that time. If the parties cannot resolve the objection, Customer may cancel its subscription and receive a pro-rated refund of prepaid fees for the rest of the billing period.
Tonpit helps Customer answer requests from data subjects to exercise their rights. Customer can do most of this itself in the Service by viewing, exporting and deleting content. If Tonpit receives a request about Customer Personal Data directly, it forwards the request to Customer and does not answer it unless Customer asks. Tonpit also gives reasonable help with data protection impact assessments and consultations with authorities, as far as they concern Tonpit’s processing.
Tonpit notifies Customer without undue delay, and no later than 48 hours after becoming aware of a personal data breach affecting Customer Personal Data. The notice describes what is known of the breach, the data and people affected, the likely consequences, and the measures taken, and Tonpit updates it as it learns more. Tonpit takes reasonable steps to contain the breach and reduce its effects.
Customer can download its media and exports, and delete files, projects or its whole account, at any time in the Service. Deleting a project does not delete its media files, because other projects may use them; they are deleted individually or with the account. When Customer deletes its account, Tonpit deletes Customer Personal Data from its systems right away, except cached copies of public media files, which expire from the content delivery network within 30 days, and data the law requires Tonpit to keep. Exported videos are deleted from the rendering service one day after rendering. Sub-processors delete what Tonpit sent them under their own retention terms, typically within 30 days.
Tonpit makes available the information reasonably needed to show that it meets this DPA, including by answering a reasonable written security questionnaire once a year. Where Data Protection Law requires an audit beyond that, Customer may carry one out, or have an independent auditor bound by confidentiality do so, with at least 30 days’ notice, during business hours, at Customer’s cost, and without access to other customers’ data.
Tonpit operates from Israel, which the European Commission has recognized as providing an adequate level of data protection, so transfers of Customer Personal Data from the EU to Tonpit need no further safeguard. Tonpit’s sub-processors process data in the countries shown in Annex 3. Where Data Protection Law requires a safeguard for those onward transfers, Tonpit relies on the sub-processors’ standard contractual clauses, the EU–U.S. Data Privacy Framework, or another mechanism Data Protection Law recognizes.
For Customers subject to Israeli law, this DPA is also the agreement for outsourced processing under the Privacy Protection (Data Security) Regulations 5777-2017. Tonpit applies the security measures in Annex 2, uses Customer Personal Data only for the purposes in Annex 1, returns or deletes it as section 9 describes, and gives Customer a written statement of its compliance once a year on request.
Each party’s liability under this DPA is subject to the limitations in the Terms, as far as Data Protection Law allows. This DPA lasts as long as Tonpit processes Customer Personal Data. If this DPA and the Terms conflict about personal data, this DPA prevails. Tonpit may update this DPA to reflect changes in law or in the Service, with notice as the Terms describe, and no update will lower the protection it gives Customer Personal Data.
| Provider | Purpose | Based in |
|---|---|---|
| Google Firebase and Google Cloud | Sign-in, database, file storage and media delivery (CDN) | United States |
| Vercel | Hosting the website and app, performance measurement | United States |
| Railway | Render and capture servers | United States |
| Amazon Web Services | Video rendering, temporary storage of exports, download delivery | United States |
| Anthropic | Built-in AI assistants, conversation summaries, brand kit asset selection, some design and text features | United States |
| Google (Gemini API) | Motion assistant, captions, some design and text features | United States |
| OpenAI | Audio transcription, static ad planning | United States |
| fal.ai | AI image and video generation; fal runs the model you choose or passes the request to its developer (listed below) | United States |
| BytePlus Pte. Ltd. | AI video and image generation with select models, for users outside the United States | Singapore |
| ElevenLabs | Voiceover generation | United States |
| Mapbox | Maps in map-based templates | United States |
fal.ai runs the model Customer chooses in the app or passes the request to the model’s developer. The developers who may receive a request:
| Model developer | Models | Based in |
|---|---|---|
| OpenAI | GPT Image | United States |
| Nano Banana, Gemini Omni | United States | |
| ByteDance | Seedance, Seedream, video upscaling | China |
| Kuaishou | Kling | China |
| MiniMax | MiniMax | China |
| Alibaba | Wan | China |
| Black Forest Labs | Flux | Germany |