Data Processing Addendum

The processor terms for the hosted service: what we process for you, who processes it with us, and what we do when something goes wrong.


Last updated

1. Roles

For personal data inside a customer workspace, the customer is the controller, or is itself a processor acting for its own controller. Toolspoke is the processor and acts only on the customer's instructions.

For account, billing, and service administration data, Toolspoke determines the purposes of processing and acts as a controller. The Privacy Policy governs that data.

The Toolspoke party to this addendum is Guidenco, Inc., a Delaware C corporation (Delaware file number 7214918) with its registered office at 651 N Broad St, Suite 201, Middletown, DE 19709, United States.

2. Scope and precedence

This addendum forms part of the Terms of Service, or of whatever written agreement is in place between the parties. Where it conflicts with that agreement on the processing of personal data, this addendum is intended to prevail.

This addendum forms part of the terms and governs where it conflicts with them on the processing of personal data. A signed order form or enterprise addendum governs over both. Where standard contractual clauses are incorporated, the clauses govern over this addendum on the subject matter they cover.

3. Subject matter, nature, purpose and duration

Subject matter. Provision of the Toolspoke gateway to the customer.

Nature of the processing. Hosting and storing workspace configuration and credentials; receiving tool calls from the customer's agents; executing those calls against the systems the customer has connected, either in process or in a sandbox; and recording each call.

Purpose. To give the customer's agents controlled access to the customer's own tools, and to give the customer a record of what those agents did.

Duration. For the term of the agreement, plus the retention described in section 12.

4. Categories of data subjects

  • The customer's own personnel who hold Toolspoke accounts, and the agent keys issued to them.
  • Any individual whose personal data appears in the content of a tool call. In practice this reaches the customer's own customers, employees, contacts, applicants, and end users, and third parties whose records happen to live in the systems the customer has connected.

The second category is open ended by design. Toolspoke does not decide which systems a customer connects or what its agents ask for, so it cannot enumerate the data subjects in advance.

5. Categories of personal data

  • Account and identity. Name, email address, verification status, optional profile photo, organisation membership and role.
  • Authentication. A hashed password where email sign-in is used; the provider account identifier and issued tokens where Google or GitHub sign-in is used; and session records carrying the IP address and browser user agent the session was created from.
  • Workspace configuration. Organisation and project names, whether a project is open to the whole workspace or restricted to named people, who is on a restricted project and who administers it, installed connectors and their configuration, which of a connector's actions a project has switched off, and agent keys with the names given to them and the projects, connectors and actions each one was granted.
  • project membership and administration: who is on a restricted project, who administers it, and the grants attached to each agent key;
  • Connected credentials. API keys, OAuth access and refresh tokens, and equivalent secrets for the customer's third-party systems. Encrypted at rest with AES-256-GCM.
  • Tool call records. The full request payload and the full response payload of every tool call, plus the acting member, the agent key, the tool and action, the status, the error where there was one, the duration, and the execution path.
  • Billing. Plan, seat count, credit balance, and the credit ledger. Payment instruments are held by Stripe, not by Toolspoke.

The tool call record is the category to examine hardest. Because request and response payloads are captured in full, any personal data an agent sends or receives passes into the record and is readable by any administrator of the organisation. Special category data will be recorded if the customer routes it through a tool call. Two limits apply: values whose field name indicates a secret are replaced with a redaction marker when a record is read back, and a connector may declare that a given operation's response is never written at all.

The customer must not send special category data or criminal offence data through the gateway without telling us first and agreeing the additional measures that processing requires. The service is not designed for it and this addendum assumes it is not present.

6. Customer instructions

Toolspoke processes personal data only on the customer's documented instructions, which comprise the agreement, this addendum, and the customer's own use of the product. Installing a connector, deciding which of its actions a project allows, putting somebody on a project, granting an agent key, and calling a tool are all instructions.

The list above is exhaustive. Toolspoke processes personal data only on the customer's documented instructions, and will tell the customer if an instruction appears to infringe applicable data protection law.

Where Toolspoke is required by law to process data beyond those instructions, it will inform the customer first unless the law prohibits it. If Toolspoke considers an instruction to infringe data protection law, it will say so.

7. Confidentiality

Personnel authorised to process customer personal data are bound by confidentiality obligations and are granted access only where their role requires it.

Everyone with access to production data is bound by written confidentiality obligations that survive the end of their engagement. Production access is granted per person, held by named members of the team, approved by an officer of Guidenco, Inc. before it is granted, reviewed when someone's role changes, and removed when their engagement ends.

8. Security measures

The measures in place today are described on the security page and summarised here:

  • Connected credentials are encrypted at rest with AES-256-GCM and are decrypted in memory only for the duration of a call that needs them.
  • Runtime secrets are resolved from a secret manager rather than read from files on disk.
  • Traffic is encrypted in transit.
  • Access to a connector is decided by the project it is installed in: the project switches individual actions on and off, and that applies to everyone on the project. An agent key can be narrowed further, and is in every case limited to what its owner can reach at the time of the call.
  • Tool execution is isolated in a per-project sandbox where the connector requires it.
  • A connector can name arguments that are withheld before the record is written, and can withhold a response payload entirely. Values whose field name indicates a secret are replaced when a record is read back.

Toolspoke does not read customer payloads in the ordinary course. Access to production data is taken only to investigate a fault or an incident, or where the customer asks for support that requires it, and it is limited to what that purpose needs.

Toolspoke holds no security certification, and this addendum claims none. Toolspoke holds no security certification and this addendum claims none. We will tell a customer before any certification is claimed elsewhere, and a completed security questionnaire is available on request.

9. Sub-processors

The customer authorises the sub-processors below. Each is bound to data protection obligations no less protective than those in this addendum, and Toolspoke remains responsible for their performance.

Toolspoke sub-processors, what each one does, and what personal data each one is exposed to
Sub-processorPurposeWhat it is exposed to
InfisicalSecret management. Holds the runtime secrets the deployment needs, so that they are resolved at run time rather than read from files on disk.Operator secrets. No customer content and no tool call payloads.
StripePayment processing and subscription billing. Engaged only where billing is configured, which excludes most self-hosted installs.Billing contact details and payment information, collected by Stripe directly. Card numbers never reach Toolspoke.
OpenRouterModel access for the toolkit builder and for the embeddings behind search. Engaged when those features are used.The text submitted to build a toolkit or to be embedded. This can include customer content.
HarborboxSandboxed execution. Runs tool calls that resolve to the sandbox path rather than the direct path.The request payload of a sandboxed call, the credential it needs, and the response returned. This is customer content.
CloudflareTunnel providing a public HTTPS address for a deployment that has none. Optional and off unless a tunnel is enabled.Traffic in transit to the deployment, including tool call traffic.
SMTP providerDelivery of invitation and account email. Engaged only where SMTP is configured.Recipient email addresses and the contents of those messages.
GitHubThe releases API, read while extracting a command line tool from a published release.Nothing about the customer. This is a read of a public API.

Each sub-processor's processing location and the transfer mechanism relied on for it are recorded in section 14. Each is engaged under written terms imposing data protection obligations no less protective than those in this addendum.

We will give at least 30 days' notice by email to organisation owners before engaging a new sub-processor. If the customer objects on reasonable data protection grounds within that period, we will work with them to find an alternative, and if none is available the customer may terminate the affected part of the service and receive a pro-rata refund of fees paid for it in advance.

10. Data subject assistance

Toolspoke will assist the customer, taking into account the nature of the processing, in responding to requests from data subjects exercising their rights.

What the product provides today: the audit log is readable and searchable within an organisation, so a customer can locate the records relating to a given member or tool. What it does not provide today: there is no way to delete an individual audit record through the product, and no self-service export. Records are removed in bulk by the retention sweep, or when the organisation is deleted. A targeted removal has to be carried out by the operator at the database level.

On request we will provide the personal data held for a customer in a structured, machine-readable format within 30 days, and will delete personal data on instruction within 30 days, subject to the backup period in section 12.

11. Personal data breach notification

Toolspoke will notify the customer without undue delay after becoming aware of a personal data breach affecting the customer's data, and will provide the information reasonably available: the nature of the breach, the categories and approximate volume of data and data subjects affected, the likely consequences, and the measures taken or proposed.

We will notify the customer of a personal data breach affecting their data without undue delay and in any event within 48 hours of becoming aware of it, with the information available at the time and updates as the investigation proceeds.

12. Deletion and return

On termination, and at the customer's choice, Toolspoke will delete or return the personal data it processes for the customer, unless it is required by law to retain it. Deleting an organisation removes its dependent records, including its tool call logs, its credentials, and its configuration.

One point has to be stated plainly rather than glossed: audit retention defaults to indefinite. It is a per-organisation setting whose default value is no limit, and there is no interface for changing it. Unless an operator sets a window, tool call records are kept for as long as the organisation exists.

On termination we delete the customer's personal data within 30 days. An export in a structured, machine-readable format is available on request during that period. Data in encrypted backups is deleted within a further 30 days, and remains subject to this addendum until it is.

13. Audits and information

Toolspoke will make available to the customer the information reasonably necessary to demonstrate compliance with this addendum.

The customer may audit compliance with this addendum once in any twelve-month period, on 30 days' written notice, at its own cost and during business hours, in a way that does not disrupt the service or expose another customer's data. A completed security questionnaire, or a third-party report where one exists, satisfies the obligation unless the customer has a specific and documented reason it does not.

14. International transfers

The hosted service stores and processes personal data in Germany, on servers in Falkenstein, Saxony operated by Hetzner Online GmbH. Data at rest does not leave the European Union. Two flows cross the border: administrative access by our team, who work from India, and the sub-processors outside the EEA listed in section 9, being Stripe, OpenRouter, Infisical and Cloudflare. For both we rely on the European Commission's 2021 standard contractual clauses, and we have completed a transfer impact assessment covering the destinations involved. The UK addendum is not incorporated, because the service is not offered to people in the United Kingdom. A copy of the clauses is available on request.

15. Self-hosted deployments

This addendum covers the hosted service. Where a customer runs Toolspoke on its own infrastructure, the data stays in that infrastructure and Toolspoke processes nothing on the customer's behalf. The customer is the controller, the deployment is its own, and the sub-processors are whichever external services it configures the deployment to use.

No processor terms are needed for a self-hosted deployment, because Toolspoke processes nothing on the customer's behalf in that arrangement. Where a support engagement requires our staff to touch a customer's own deployment, that access is governed by a separate written agreement made at the time.

16. Contact and execution

Questions about this addendum go to [email protected].

This addendum takes effect by incorporation into the terms and needs no signed counterpart. A customer that requires a signed copy can request one at [email protected].