Data Processing Agreement

Print / Download

parties & scope

This Data Processing Agreement ("DPA") is entered into between Tarosyn LLC, United States ("Tarosyn", "Processor"), and the customer organisation or individual identified in the applicable order form or Terms of Service ("Controller").

This DPA supplements the Tarosyn Terms of Service and Privacy Policy. In the event of any conflict between this DPA and those documents on data-protection matters, this DPA controls.

This DPA applies where Tarosyn processes personal data on behalf of the Controller in connection with providing the Tarosyn platform and services (the "Services"), and where applicable data-protection law (including the EU General Data Protection Regulation 2016/679 ("GDPR"), UK GDPR, or similar legislation) requires a written data-processing agreement.

1. controller & processor roles

The parties agree that, with respect to personal data processed by Tarosyn in connection with the Services:

The Controller determines the purposes and means of processing personal data submitted to the Services. Tarosyn acts as the Processor and processes personal data only on documented instructions from the Controller, including as set out in this DPA and the Terms of Service. Where Tarosyn also determines purposes and means for its own operational data (e.g. account security, fraud prevention, platform analytics), it acts as an independent Controller for those activities under its Privacy Policy.

2. details of processing

The subject matter, duration, nature, and purpose of the processing, as well as the types of personal data and categories of data subjects, are set out below:

SUBJECT MATTER

Operation of the Tarosyn platform — including tarot readings, astrological services, social features, messaging, and related AI-generated content — on behalf of the Controller.

DURATION

For the term of the Controller's subscription or agreement, plus any retention period required by law or this DPA.

NATURE & PURPOSE

Collection, storage, retrieval, use, disclosure, and deletion of personal data to deliver and improve the Services as described in the Privacy Policy.

TYPES OF PERSONAL DATA

Identity & contact: name, username, email address, profile photo Astrological & birth data: date of birth, birth time, birth location User-generated content: readings, journal entries, messages, Chant posts Payment & subscription identifiers (tokenised; no raw card data) Device & usage data: IP address, session data, interaction logs Push notification tokens

CATEGORIES OF DATA SUBJECTS

End users of the Services (individuals who create a Tarosyn account or interact with the platform on behalf of the Controller).

3. sub-processors

The Controller grants Tarosyn general authorisation to engage sub-processors. Tarosyn will maintain and publish below the current list of approved sub-processors. Tarosyn will notify the Controller of intended changes (additions or replacements) by updating this page, providing at least 30 days notice where practicable, so the Controller may object before the change takes effect.

SUB-PROCESSOR PURPOSE COUNTRY

OpenAI, LLC AI text and image generation for readings, personas, and interpretations United States Stripe, Inc. Payment processing, subscription billing, and fraud prevention United States Twilio SendGrid Transactional and verification email delivery United States Replit, Inc. Application hosting, managed PostgreSQL database, and object storage United States Apple Inc. In-app purchase validation, Apple Push Notification service, and Sign in with Apple United States Google LLC Google Play in-app purchase validation and Firebase Cloud Messaging push notifications United States Printful, Inc. Physical merchandise fulfilment (name and shipping address only) United States / Latvia

Each sub-processor is bound by a data-processing agreement with Tarosyn that provides at least equivalent protections to those in this DPA.

4. security measures

Tarosyn implements appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures include, but are not limited to:

Encryption of data in transit using TLS (minimum 1.2) for all client-server communication. Encryption at rest for sensitive fields including passwords (hashed using an adaptive algorithm), session tokens, and payment references. Access controls based on the principle of least privilege — production systems are accessible only to authorised personnel. Multi-factor authentication required for administrative system and infrastructure access. Rate limiting, abuse detection, and DDoS mitigation measures to protect availability. Regular automated backups of the production database, tested periodically for recoverability. A software development lifecycle that incorporates security review at design, development, and deployment stages. Ongoing dependency scanning and a public Bug Bounty programme for responsible disclosure.

A full description of our security programme is available in our Information Security Policy.

5. data-subject rights assistance

Tarosyn will provide reasonable assistance to the Controller in fulfilling the Controller's obligation to respond to requests from data subjects exercising their rights under applicable law, including rights to access, rectification, erasure, restriction, portability, and objection.

In-app controls allow data subjects to update profile information, download their data, and request account deletion without requiring Controller intervention. Account deletion purges personal data from live systems within 30 days; backup data is overwritten within 90 days. Where a data-subject request cannot be fulfilled through in-app controls, the Controller may submit requests to [email protected] and Tarosyn will respond within a commercially reasonable time. Tarosyn will promptly notify the Controller if it receives a data-subject request that identifies the Controller as the responsible party.

6. personal data breach notification

In the event Tarosyn becomes aware of a personal data breach affecting data processed under this DPA, Tarosyn will:

Notify the Controller without undue delay, and in any event within 72 hours of becoming aware of the breach (to the extent practicable). Provide in the notification: a description of the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed to address the breach. Cooperate with the Controller and take such reasonable steps as directed by the Controller to mitigate or remedy the breach. Maintain records of all breaches, including those not required to be reported.

Notifications should be directed to the Controller's designated data-protection contact. Tarosyn's security contact is [email protected].

7. international data transfers

Personal data processed by Tarosyn and its sub-processors may be transferred to, and processed in, countries outside the European Economic Area (EEA) or United Kingdom, including the United States.

Where such transfers are subject to the GDPR or UK GDPR, Tarosyn relies on the European Commission's Standard Contractual Clauses (SCCs) — Module 2 (Controller to Processor) — as the transfer mechanism. For transfers to sub-processors outside the EEA/UK, Tarosyn ensures that appropriate safeguards (including sub-processor SCCs or adequacy decisions) are in place. Where the UK International Data Transfer Agreement (IDTA) is required, Tarosyn will provide or execute the relevant addendum upon request. Tarosyn monitors adequacy decisions and regulatory guidance and will update its transfer mechanisms as required.

Controllers requiring a copy of the applicable SCCs or a Transfer Impact Assessment may request these by contacting [email protected].

8. retention & deletion

Tarosyn retains personal data for the duration of the Controller's agreement, plus any additional period required by applicable law or for legitimate business purposes (e.g. tax records, dispute resolution).

Upon termination of the agreement, Tarosyn will, at the Controller's election, delete or return personal data within 30 days. Backup copies may persist for up to 90 days before being overwritten or deleted. Tarosyn will provide written confirmation of deletion upon request. Certain data may be retained in anonymised or aggregated form that cannot be attributed to a specific data subject.

9. audit rights & compliance

Tarosyn will make available to the Controller all information necessary to demonstrate compliance with this DPA, and will allow for and contribute to audits and inspections conducted by the Controller or a mandated auditor, subject to:

Reasonable prior written notice (minimum 30 days) and agreement on scope. Execution of a mutual non-disclosure agreement to protect proprietary and third-party information. Reasonable limitations to protect the security, confidentiality, and integrity of other customers' data. The Controller bearing the reasonable costs of any audit it initiates.

In lieu of a bespoke audit, Tarosyn may satisfy audit requests by providing relevant third-party certifications, penetration test summaries (redacted), or completed security questionnaires. To initiate an audit inquiry, contact [email protected].

10. confidentiality of processing

Tarosyn ensures that personnel authorised to process personal data under this DPA are subject to appropriate confidentiality obligations. Access to personal data is limited to personnel who require it to perform their functions in connection with the Services. Tarosyn will not disclose personal data to third parties except as expressly permitted by this DPA, the Controller's instructions, or applicable law. governing law & execution

This DPA is governed by the same law as the underlying Terms of Service unless otherwise required by applicable data-protection regulation. Where the GDPR applies, this DPA is interpreted in accordance with EU law.

This DPA comes into effect when the Controller accepts the Terms of Service, or by separate written execution. Enterprise customers requiring a countersigned copy can request one below — no email required. Our legal team will follow up with an executed copy.

request a countersigned dpa

Tell us a little about your organisation and where you operate, and we'll route a countersigned Data Processing Agreement to your contact.

Company name Contact email Governing-law jurisdiction Intended use (optional) Request countersigned DPA

Prefer email? You can also reach us at [email protected].

changes to this agreement

Tarosyn may update this DPA from time to time to reflect changes in applicable law, regulatory guidance, or our processing practices. Material changes will be communicated with reasonable advance notice. Continued use of the Services after the effective date of any update constitutes acceptance of the revised DPA.

Privacy Policy Information Security Policy

© 2026 Tarosyn LLC. All rights reserved.

Data-protection enquiries? [email protected]