Legal
Data Processing Addendum
CloudOverture Data Processing Addendum
Effective: August 25, 2026
This Data Processing Addendum (“DPA”) is part of the CloudOverture Terms of Service between Touchtone Corporation (“Touchtone”, “we”) and the customer (“you”). It covers the personal information inside the data your business stores in CloudOverture (“Customer Personal Information”): for example, your customers’ names, contact details, addresses, and transaction records.
Plainly: this document is our contract-level promise about how we handle the people-data inside your business records.
1. Roles
You decide what data goes into CloudOverture and why. Under US state privacy laws, you are the “business” or “controller” for Customer Personal Information, and Touchtone is your “service provider” or “processor”. Touchtone is the business for its own account, billing, and website data, which the Privacy Policy covers.
2. What we may do with Customer Personal Information
We process Customer Personal Information only:
- to provide, secure, support, and maintain the Services under the Terms of Service,
- on your instructions given through the Services (for example, when you tell the Services to send an invoice), and
- as the law requires.
3. What we will never do with it
We certify that we will not:
- sell Customer Personal Information, or share it for cross-context behavioral advertising,
- keep, use, or disclose it for any purpose other than providing the Services, or outside our direct business relationship with you,
- combine it with personal information from other customers or other sources, except as the Services require to serve you (for example, spam filtering),
- use it to train AI models,
- use it to contact your customers, except when you tell the Services to send something on your behalf.
We will tell you in writing if we ever determine that we can no longer meet these commitments, and you may then stop or fix our processing as the law allows.
4. Confidentiality
Everyone we allow to touch Customer Personal Information, employee or contractor, is bound by a written confidentiality duty and gets access only if their job requires it. We log that access.
5. Security
We maintain administrative, technical, and physical safeguards appropriate to the data we hold, including:
- encryption of data in transit and at rest,
- tenant isolation, so one business cannot read another’s data,
- role-based access with unique logins, and audit logging of access,
- vulnerability management and monitoring,
- backups, and a tested restore process.
We will not lower the overall protection of these safeguards during your subscription.
6. Breach notice
If we confirm a breach of security that affects Customer Personal Information, we notify you without undue delay, and no later than 72 hours after confirmation. The notice states what happened, what data is affected, what we are doing, and a contact. We then give you the reasonable help you need for your own legal notices.
7. Subprocessors
We use these subprocessors to run the Services:
| Subprocessor | Location | Purpose |
|---|---|---|
| Amazon Web Services | United States | Hosting, storage, and email delivery (Amazon Simple Email Service) |
| Stripe, Inc. | United States | Payment processing |
| OpenAI (AI model provider) | United States | Answering AI requests and sorting incoming email, no training on your data |
Each subprocessor is bound by a written contract with duties at least as protective as this DPA. We remain responsible for their work.
Services you connect are not subprocessors. An outside service that you or your team connects, like a mailbox, your own Stripe account, an outside AI assistant, or your own AI provider account, is your own vendor, not our subprocessor. It handles data under its own terms, we are not responsible for it, and you can disconnect it at any time in Settings.
The current list is always available at this page. Before adding or replacing a subprocessor, we email account owners at least 30 days ahead. If you object on reasonable data-protection grounds and we cannot resolve it, you may cancel and receive a pro rata refund of any prepaid unused term.
8. Helping you with privacy requests
If your customer sends you an access, correction, or deletion request, the Services give you the tools to answer it yourself: search, edit, export, and delete. If a request needs help beyond the tools, we assist you within a reasonable time. If a person contacts us directly about data your business holds, we point them to you.
If a law ever requires an assessment of your processing, we give you the reasonable information you need about the Services to complete it.
9. Deletion and return
While your subscription is active, you can export and delete data at any time. When your subscription ends, the retention table in the Terms of Service and the Privacy Policy applies: for 90 days after the end date you can still sign in and export your data, deletion completes 90 days after the end date, deleted data leaves our backups within 35 days, and we keep billing and tax records 7 years as tax law requires.
10. Showing our work
On your written request, no more than once a year, we will answer a reasonable security questionnaire or provide summaries of our security measures and any third-party assessments we hold. If a law gives you an audit right that these materials do not satisfy, we will cooperate with a mutually agreed audit, at your expense, under confidentiality, no more than once a year, and without access to other customers’ data. You may also take other reasonable and appropriate steps to check that we use Customer Personal Information as this DPA allows, and we will cooperate with those steps.
11. Scope and precedence
This DPA covers US law duties. CloudOverture is offered to businesses in the United States, and we do not market it in the European Union. If we later offer the Services in a place whose law requires more, we will add those terms before serving it. If this DPA conflicts with the Terms of Service on the handling of Customer Personal Information, this DPA controls. The warranty disclaimer and the limits of liability in the Terms of Service apply to this DPA. The dispute-resolution section of the Terms of Service applies to this DPA.