EU-only processing. GDPR DPA on file. 72-hour breach notification SLA. Account and infrastructure data stays in the EU. The only cross-border hop is when a prompt is forwarded to an upstream model provider — covered by EU Standard Contractual Clauses and the UK Addendum.
GDPR-compliant Data Processing Agreement
A standard Article 28 DPA is included with every paid TokenBridge account. It covers subject matter and duration, nature and purpose of processing, data categories, processor obligations, international transfers, sub-processors, security measures, audit rights, and breach notification.
Current version: v1.0, last updated 26 May 2025. Procurement teams can review the full text or download a machine-readable copy for their records:
Data residency — EU-only processing, no US transfer
Your account and infrastructure data — email, billing details, API key metadata — is stored in EU-hosted databases. It does not leave the EU.
Your prompt content passes through the upstream model provider's region when you make an API call. This is the only cross-border hop. We cannot avoid it — the model runs where its provider operates:
Transfers from the EEA to sub-processors in China are governed by EU Standard Contractual Clauses Module 2 (Controller → Processor) with the UK Addendum incorporated for UK GDPR transfers. Supplementary measures (data minimisation, no PII required, pseudonymisation encouraged, no persistence by Processor) reduce reliance on the sufficiency of safeguards in the destination country.
Stripe (our payment processor) is US-based. Stripe is certified under the EU-U.S. Data Privacy Framework — a recognised adequacy mechanism — so payment-data transfers do not require SCCs.
Sub-processor list
We engage the following sub-processors. Controller grants general written authorisation to engage them per DPA Section 6, with equivalent data protection obligations imposed down the chain:
| Sub-processor | Country | Purpose | Website |
|---|---|---|---|
| Stripe (Stripe Payments Europe Ltd.) | US (data transfers under EU-U.S. DPF) | Payment processing, VAT invoicing, fraud detection | stripe.com |
| Postmark (ActiveCampaign LLC) | US (data transfers under EU-U.S. DPF) | Transactional email delivery (welcome, receipts, low-balance alerts) | postmarkapp.com |
| DeepSeek (Hangzhou DeepSeek Intelligence Innovation Technology Co., Ltd.) | China | Upstream AI model provider | deepseek.com |
| Alibaba Qwen (Alibaba Group Holding Ltd.) | China | Upstream AI model provider | qwen.ai |
| ByteDance Doubao (ByteDance Ltd.) | China | Upstream AI model provider | doubao.com |
Notice and objection: TokenBridge will notify controllers at least 30 days before engaging any new sub-processor. Controllers may object in writing within 15 days; we will make reasonable efforts to address the objection or terminate the sub-processor engagement. Processor remains liable to Controller for the performance of its sub-processors per DPA §4(d).
Data retention and deletion
Operational metadata. We keep API metadata — timestamps, which model you used, how many tokens — for up to 90 days. This is for operational monitoring and debugging.
Prompt and completion text. We do not store your prompt text or the model's response text after the response is delivered. That is by design, not a policy we could change tomorrow.
Account data on termination. On termination of the Service, all Personal Data is deleted (or returned, at the controller's election) within 30 days. Written certification of compliance is provided on request.
Customer-initiated erasure. Customer-initiated erasure requests are handled within 30 days of receipt, per DPA §4(e) — covering access, rectification, erasure, restriction, portability, and objection.
Breach-notification SLA
TokenBridge will notify the controller by email at the address associated with the controller's account within 72 hours of becoming aware of a Personal Data Breach.
The notification will include:
SOC 2 & ISO 27001 readiness
We do not currently hold SOC 2 Type II or ISO 27001 certification. We are honest about this so your DPO does not find out from a vendor questionnaire surprise.
Audit rights are retained. Per DPA §4(h) and §9, the controller may audit Processor's compliance with the DPA no more than once per calendar year, on 30 days written notice, during business hours, at the controller's expense. Processor will cooperate and provide evidence of compliance, including a summary of security controls and relevant policies.
Roadmap. Reportable roadmap items: SOC 2 Type I in progress [Q4 2026]; Type II audit planned once controls mature. We will announce certification status on this page.
Need the DPA on file? TokenBridge ships with a standard DPA on every paid account. Contact our team → and we'll have the paperwork on your desk within one business day.