Data Processing Addendum
This DPA forms part of the Tonaura Terms of Service for customers who require one for procurement, vendor risk, or data protection compliance purposes.
1. Definitions
“Personal Data”, “Processing”, “Controller”, and “Processor” have the meanings given in applicable data protection law (including the GDPR, where relevant).
2. Scope
This addendum applies to Personal Data processed by Tonaura on behalf of a user who has created an account, strictly limited to what's described in our Privacy Policy: sign-in identifiers, synced presets, streak data, and subscription entitlement status.
3. Roles
For signed-in users, Tonaura (via Empowered Dynamics FZ-LLC) acts as the data Processor, and the individual user is the Controller of their own personal data. For account-free (guest) use, no data is processed by us at all.
4. Nature and purpose of processing
Processing is limited to enabling cross-device sync of presets and streak, and restoring subscription entitlement on a new device.
5. Sub-processors
We use the following categories of sub-processor: authentication (Firebase/Google), subscription management (RevenueCat), and payment processing (Apple, Google, Stripe). Each is bound by its own data protection terms.
6. Security measures
Encryption in transit and at rest, access controls, and minimal data collection by design — we only store what's strictly necessary for sync and entitlement.
7. International transfers
Data may be processed outside your country of residence by our sub-processors. Appropriate safeguards are used where required by law.
8. Assistance with data subject requests
We'll assist users in exercising their rights under applicable law, including access, correction, deletion, and portability requests.
9. Contact us
For DPA-related inquiries: privacy@tonaura.io