Back

Data Processing Addendum

Last updated: September 28, 2026

1. Scope and Parties

This Data Processing Addendum (“DPA”) is between Itay Rose Ari, operating Tonpit, Yehuda HaNasi 13, Tel Aviv 6920013, Israel (“Tonpit”), and the account holder that uses Tonpit for a business, trade or profession (“Customer”). It is part of the Terms of Service and applies automatically whenever Tonpit processes personal data on Customer’s behalf (“Customer Personal Data”). No separate signature is needed; a signed copy is available on request from hello@tonpit.com.

It applies to processing subject to the GDPR, the UK GDPR, the Israeli Privacy Protection Law 5741-1981 and its regulations, and other data protection laws that apply to Customer Personal Data (“Data Protection Law”). Terms such as “controller,” “processor,” “personal data,” “processing” and “data subject” have the meanings Data Protection Law gives them.

2. Roles

Customer is the controller of Customer Personal Data, or a processor acting for its own clients; Tonpit is Customer’s processor, or sub-processor. Tonpit is a controller only of the account and billing data it needs to run Customer’s account, which its Privacy Policy covers.

Customer is responsible for having a lawful basis for the Customer Personal Data it puts into Tonpit, for giving the notices and getting the consents required, including from people who appear in its images, video and audio, and for its instructions complying with Data Protection Law.

3. Processing on Instructions

Tonpit processes Customer Personal Data, including any transfer to a third country, only on Customer’s documented instructions, unless the law requires otherwise, in which case Tonpit tells Customer before processing unless the law forbids it. Those instructions are the Terms, this DPA, and Customer’s use and settings of the Service, including instructions given through AI agents Customer connects. Tonpit tells Customer if it believes an instruction breaks Data Protection Law, unless the law forbids telling. Tonpit does not sell Customer Personal Data or use it to train AI models.

The details of the processing are in Annex 1.

4. Confidentiality

Everyone Tonpit authorizes to process Customer Personal Data is bound by confidentiality, and may access it only to provide and operate the Service, including monitoring its quality and cost, to give support Customer asks for, or for security, abuse prevention and legal obligations.

5. Security

Tonpit maintains the technical and organizational measures in Annex 2, and may improve them as long as the overall level of protection does not go down.

6. Sub-processors

Customer authorizes Tonpit to use the sub-processors in Annex 3. Tonpit binds each one to data protection terms that protect Customer Personal Data at least as well as this DPA, and remains responsible to Customer for their performance.

Before adding or replacing a sub-processor, including a model developer, Tonpit updates Annex 3 at least 14 days in advance, with the date it takes effect, and emails the change to every Customer who has asked to receive these notices by writing to hello@tonpit.com. Customer may object on reasonable data protection grounds within that time. If the parties cannot resolve the objection, Customer may cancel its subscription and receive a pro-rated refund of prepaid fees for the rest of the billing period.

7. Data Subject Requests and Assistance

Tonpit helps Customer answer requests from data subjects to exercise their rights. Customer can do most of this itself in the Service by viewing, exporting and deleting content. If Tonpit receives a request about Customer Personal Data directly, it forwards the request to Customer and does not answer it unless Customer asks. Tonpit also gives reasonable help with data protection impact assessments and consultations with authorities, as far as they concern Tonpit’s processing.

8. Personal Data Breaches

Tonpit notifies Customer without undue delay, and no later than 48 hours after becoming aware of a personal data breach affecting Customer Personal Data. The notice describes what is known of the breach, the data and people affected, the likely consequences, and the measures taken, and Tonpit updates it as it learns more. Tonpit takes reasonable steps to contain the breach and reduce its effects.

9. Deletion and Return

Customer can download its media and exports, and delete files, projects or its whole account, at any time in the Service. Deleting a project does not delete its media files, because other projects may use them; they are deleted individually or with the account. When Customer deletes its account, Tonpit deletes Customer Personal Data from its systems right away, except cached copies of public media files, which expire from the content delivery network within 30 days, and data the law requires Tonpit to keep. Exported videos are deleted from the rendering service one day after rendering. Sub-processors delete what Tonpit sent them under their own retention terms, typically within 30 days.

10. Information and Audits

Tonpit makes available the information reasonably needed to show that it meets this DPA, including by answering a reasonable written security questionnaire once a year. Where Data Protection Law requires an audit beyond that, Customer may carry one out, or have an independent auditor bound by confidentiality do so, with at least 30 days’ notice, during business hours, at Customer’s cost, and without access to other customers’ data.

11. International Transfers

Tonpit operates from Israel, which the European Commission has recognized as providing an adequate level of data protection, so transfers of Customer Personal Data from the EU to Tonpit need no further safeguard. Tonpit’s sub-processors process data in the countries shown in Annex 3. Where Data Protection Law requires a safeguard for those onward transfers, Tonpit relies on the sub-processors’ standard contractual clauses, the EU–U.S. Data Privacy Framework, or another mechanism Data Protection Law recognizes.

12. Israeli Data Security Regulations

For Customers subject to Israeli law, this DPA is also the agreement for outsourced processing under the Privacy Protection (Data Security) Regulations 5777-2017. Tonpit applies the security measures in Annex 2, uses Customer Personal Data only for the purposes in Annex 1, returns or deletes it as section 9 describes, and gives Customer a written statement of its compliance once a year on request.

13. Liability, Term and Precedence

Each party’s liability under this DPA is subject to the limitations in the Terms, as far as Data Protection Law allows. This DPA lasts as long as Tonpit processes Customer Personal Data. If this DPA and the Terms conflict about personal data, this DPA prevails. Tonpit may update this DPA to reflect changes in law or in the Service, with notice as the Terms describe, and no update will lower the protection it gives Customer Personal Data.

Annex 1: Details of Processing

  • Subject matter: providing Tonpit, the AI video production studio, to Customer
  • Duration: as long as Customer uses Tonpit, then until deletion under section 9
  • Nature and purpose: storing, hosting and delivering content; generating images, video, voiceover and text with AI; rendering and exporting video; transcribing audio; capturing web pages Customer names; running AI assistants and agents Customer directs
  • Data subjects: people who appear in, speak in, or are named in Customer content, such as Customer’s clients, employees, actors and presenters
  • Personal data: images and video of people, voices, names and other details in scripts, prompts and captions, and any personal data in content Customer uploads or web pages it captures
  • Special categories: none intended. Customer should not submit special categories of data unless it is necessary and lawful. Tonpit does not use face recognition or other biometric identification. Some video model providers automatically check reference images for photorealistic faces and may refuse them, without identifying anyone

Annex 2: Security Measures

  • Encryption in transit (HTTPS) and at rest with Tonpit’s storage providers
  • Per-user authorization on every data request; each account reaches only its own content
  • Administrative access limited to an allowlist of verified accounts
  • A fresh sign-in required before sensitive actions, such as deleting an account or creating an agent token
  • Agent access tokens stored only in hashed form, limited by permissions and spend ceilings, and revocable at any time
  • Code written for animations runs in an isolated sandbox in the browser
  • Web pages fetched for Customer are loaded through an egress policy that blocks private networks, and their content is treated as untrusted by AI assistants
  • Signature verification on payment notifications
  • Automatic expiry of logs and temporary files, and complete deletion of accounts on request
  • Security review as part of developing the Service

Annex 3: Sub-processors

ProviderPurposeBased in
Google Firebase and Google CloudSign-in, database, file storage and media delivery (CDN)United States
VercelHosting the website and app, performance measurementUnited States
RailwayRender and capture serversUnited States
Amazon Web ServicesVideo rendering, temporary storage of exports, download deliveryUnited States
AnthropicBuilt-in AI assistants, conversation summaries, brand kit asset selection, some design and text featuresUnited States
Google (Gemini API)Motion assistant, captions, some design and text featuresUnited States
OpenAIAudio transcription, static ad planningUnited States
fal.aiAI image and video generation; fal runs the model you choose or passes the request to its developer (listed below)United States
BytePlus Pte. Ltd.AI video and image generation with select models, for users outside the United StatesSingapore
ElevenLabsVoiceover generationUnited States
MapboxMaps in map-based templatesUnited States

fal.ai runs the model Customer chooses in the app or passes the request to the model’s developer. The developers who may receive a request:

Model developerModelsBased in
OpenAIGPT ImageUnited States
GoogleNano Banana, Gemini OmniUnited States
ByteDanceSeedance, Seedream, video upscalingChina
KuaishouKlingChina
MiniMaxMiniMaxChina
AlibabaWanChina
Black Forest LabsFluxGermany