Tokenize Data Processing and Security Addendum

Last updated: September 2, 2026

This Data Processing and Security Addendum ("DPA") forms part of the agreement between Palindrome Labs, Inc. dba Tokenize ("Tokenize"), and the organization or other customer using the Services ("Customer"). If Customer accepts the Terms of Use without executing an Order Form, the "Agreement" consists of those Terms, this DPA, and each incorporated exhibit or schedule. If Customer executes an Order Form, the Agreement consists of the Master Services Agreement (the "MSA"), each Order Form, this DPA, and each incorporated exhibit or schedule. This DPA takes effect when Customer first accepts the Terms of Use or on the effective date of Customer's first Order Form, as applicable.

1. Definitions

1.1 Applicable Data Protection Law means a law that applies to Tokenize's processing of Customer Personal Data under the Agreement, including the EU General Data Protection Regulation 2016/679 ("EU GDPR"), the EU GDPR as incorporated into United Kingdom law ("UK GDPR"), the Swiss Federal Act on Data Protection, and applicable U.S. state comprehensive privacy laws.

1.2 Customer Personal Data means Personal Data contained in Customer Data that Tokenize processes on Customer's behalf.

1.3 Personal Data means information defined as personal data, personal information, or a similar term under Applicable Data Protection Law.

1.4 Process and processing mean an operation performed on Personal Data, including collection, storage, use, disclosure, transmission, alteration, retrieval, or deletion.

1.5 Sensitive Data means Personal Data that Applicable Data Protection Law classifies as sensitive data, special-category data, or data about criminal convictions or offenses. Sensitive Data also includes protected health information subject to the Health Insurance Portability and Accountability Act, payment cardholder data subject to the Payment Card Industry Data Security Standard, biometric identifiers used for identification, government-issued identification numbers, and financial account credentials.

1.6 Security Incident means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data while that data is processed by Tokenize or a Subprocessor.

A Security Incident does not include an unsuccessful access attempt, scan, probe, vulnerability, alert, or other event that does not compromise the confidentiality, integrity, or availability of Customer Personal Data. It also does not include an incident affecting a Customer-Directed Service unless Tokenize caused the incident through its breach of the Agreement.

1.7 Subprocessor means a third party that Tokenize appoints to process Customer Data on Customer's behalf to provide the Services. A Customer-Directed Service is not a Subprocessor.

1.8 Customer-Directed Service means a third-party product, model provider, MCP server, data source, or integration that Customer directs Tokenize to connect to the Services and that Tokenize does not provide as a Subprocessor.

1.9 Operational Data means business contact information; account and organization administration records; subscription, billing, payment, and tax records; and fraud-prevention, security, and legal-compliance information that Tokenize processes as a controller for its own customer-relationship and business-administration purposes, as described in the Privacy Policy. Operational Data excludes prompts, responses, transcripts, telemetry, source code, files, tool content, and other information that Tokenize processes on Customer's behalf. Operational Data is not Customer Data for purposes of this DPA.

Capitalized terms not defined in this DPA have the meanings stated in the applicable Agreement.

2. Scope, Roles, and Instructions

2.1 Customer acts as the controller or processor, as applicable, for Customer Personal Data. Tokenize acts as Customer's processor when Customer is a controller and as Customer's subprocessor when Customer is a processor. Under applicable U.S. state privacy laws, Tokenize acts as a processor, service provider, or contractor, as applicable. If Customer acts as a processor, Customer confirms that the relevant controller has authorized Customer to appoint Tokenize as a subprocessor and to provide the instructions described in this DPA.

Tokenize acts as an independent controller of Operational Data and processes it for the purposes described in the Privacy Policy. Operational Data is outside the scope of this DPA.

2.2 Customer instructs Tokenize to process Customer Personal Data to:

  • provide, secure, maintain, and support the Services;
  • apply Customer's configurations and documented instructions;
  • prevent and address fraud, abuse, Security Incidents, and technical problems;
  • comply with law; and
  • perform the Agreement.

The Agreement, Customer's use and configuration of the Services, and documented support requests constitute Customer's instructions. Tokenize will notify Customer if Tokenize believes an instruction violates Applicable Data Protection Law, unless law prohibits notice.

2.3 Customer will ensure that its instructions comply with law and that it has a lawful basis, rights, notices, and consents for the processing. Customer will not intentionally submit Sensitive Data or use the Services primarily to process Sensitive Data without first obtaining Tokenize's written authorization.

2.4 Sections 4 through 7 and Section 10 apply to all Customer Data, whether or not Customer Data contains Personal Data. The other data-protection provisions of this DPA apply to Customer Personal Data.

3. Processing Restrictions

3.1 Tokenize will process Customer Personal Data only under Customer's documented instructions, the Agreement, and applicable law.

3.2 Tokenize will not:

  • sell Customer Personal Data;
  • share Customer Personal Data for cross-context behavioral advertising;
  • process Customer Personal Data for targeted advertising;
  • retain, use, or disclose Customer Personal Data outside the direct business relationship with Customer except as the Agreement or law permits;
  • combine Customer Personal Data with Personal Data received from another person or collected from Tokenize's own interaction with an individual, except as Applicable Data Protection Law permits a processor or service provider to combine it; or
  • use Customer Personal Data to train or fine-tune a general-purpose machine-learning or artificial-intelligence model or a model used for the benefit of another customer.

For clarity, the preceding restriction does not prevent Tokenize from using Customer Personal Data to generate Customer-specific embeddings, classifications, clusters, summaries, and other results as necessary to provide the Services.

3.3 Tokenize certifies that it understands and will comply with the restrictions in this Section. If Tokenize determines that it can no longer meet an obligation imposed by Applicable Data Protection Law, it will notify Customer as required by law. Customer may take reasonable steps to stop and remediate unauthorized processing.

3.4 The Agreement governs Aggregated Data. Data qualifies as Aggregated Data only after it no longer identifies and cannot reasonably be used to identify Customer, an Authorized User, or an individual. Tokenize will not attempt to re-identify Aggregated Data.

4. Personnel and Confidentiality

4.1 Tokenize will limit access to Customer Data to personnel and contractors who need access to perform the Agreement.

4.2 Tokenize will require those persons to protect Customer Data through written confidentiality obligations or professional duties of confidentiality.

4.3 Tokenize will provide appropriate privacy and security training to personnel whose roles involve access to Customer Data.

5. Security Program

5.1 Tokenize will maintain administrative, technical, and organizational safeguards appropriate to the nature of Customer Data and the risks of processing. The safeguards will include the measures in Schedule 2.

5.2 Tokenize may update its safeguards as technology and risks change. An update will not materially reduce the overall protection of Customer Personal Data during the term of the Agreement.

5.3 Customer remains responsible for:

  • configuring the Services and Customer-Directed Services appropriately;
  • managing Authorized Users, credentials, roles, and access;
  • reviewing Customer's use of features that collect prompt text, responses, tool content, attachments, file history, source code, or similar content;
  • securing systems and networks that Customer controls; and
  • notifying Tokenize promptly of suspected unauthorized use.

6. Subprocessors

6.1 Customer authorizes Tokenize to use the Subprocessors listed in the Trust Center.

6.2 Tokenize will bind each Subprocessor by written terms that require data-protection and security obligations appropriate to the Customer Data and services involved, including applicable Data Privacy Framework onward-transfer requirements. Tokenize remains responsible for a Subprocessor's performance of those obligations to the same extent Tokenize would be responsible if it performed the processing itself.

6.3 Tokenize will provide at least 15 days' advance notice before authorizing a new Subprocessor to process Customer Data, unless an emergency creates a security or service-availability need that makes advance notice impracticable. In an emergency, Tokenize will provide notice as soon as practicable.

6.4 Customer may object to a new Subprocessor within 10 days after notice on reasonable, documented data-protection grounds. The parties will work in good faith to address the objection. If they cannot resolve it, Tokenize may avoid using the Subprocessor for Customer, or Customer may terminate the affected Services and receive a refund of prepaid fees for the unused terminated period. This termination and refund are Customer's sole remedies for a Subprocessor objection.

7. Security Incidents

7.1 Tokenize will notify Customer without undue delay after becoming aware of a Security Incident. For Customer Personal Data protected by Swiss law, Tokenize will provide notice as soon as possible. In all cases, Tokenize will provide notice no later than 72 hours after awareness unless law requires earlier notice. Tokenize may provide information in phases as it becomes available and will not delay the initial notice pending completion of its investigation.

7.2 Notice will include information reasonably available to Tokenize concerning:

  • the nature of the Security Incident;
  • the categories of affected Customer Personal Data and individuals;
  • the likely consequences;
  • containment and remediation measures; and
  • a contact for follow-up questions.

7.3 Tokenize will take reasonable steps to contain, investigate, and remediate a Security Incident and prevent a recurrence. Tokenize will preserve relevant evidence as required by its incident-response procedures and law.

7.4 Customer is responsible for determining whether to notify individuals, regulators, or other parties, except to the extent Applicable Data Protection Law requires Tokenize to provide a notice directly. Tokenize will provide reasonable assistance based on the nature of its processing and the information available to it. Customer will not identify Tokenize in a public statement concerning a Security Incident without prior consultation, except where law requires identification.

7.5 A Security Incident notice is not an admission of fault or liability. The indemnification and liability provisions of the applicable Agreement govern any related responsibility.

8. Assistance and Individual Rights

8.1 Taking into account the nature of processing, Tokenize will provide reasonable assistance that Customer needs to respond to a verified request from an individual concerning Customer Personal Data.

8.2 If Tokenize receives a request concerning Customer Personal Data directly from an individual, Tokenize will direct the individual to Customer and will not respond substantively unless Customer instructs Tokenize or law requires a response.

8.3 Tokenize will provide reasonable information and assistance for Customer's data-protection impact assessment, regulator consultation, or legally required compliance assessment when the request relates to Tokenize's processing under the Agreement.

8.4 Tokenize may charge reasonable fees for assistance that requires material work beyond the standard Services, unless Applicable Data Protection Law requires Tokenize to provide the assistance without charge or the assistance results from Tokenize's breach.

9. Compliance Information and Audits

9.1 Tokenize is undergoing an independent SOC 2 Type II audit. Upon issuance, Tokenize will provide the report under NDA through the Trust Center.

9.2 Until the report is available, or when the report does not address a reasonable material concern, Customer may submit a reasonable written security questionnaire no more than once in a 12-month period. The annual limit does not apply after a Security Incident affecting Customer or when a regulator requires additional information.

9.3 Customer will first use reports, certifications, summaries, and written responses that Tokenize provides. If Applicable Data Protection Law requires an additional audit and the available materials are insufficient, the parties will agree on a scope, timing, duration, confidentiality protections, and an independent auditor. An audit will occur during normal business hours, avoid disruption, protect other customers' information, and not include penetration testing or access to systems without Tokenize's written approval.

9.4 Customer will bear its audit costs unless the audit identifies Tokenize's material breach of this DPA. Tokenize may charge reasonable fees for assistance beyond its standard compliance program.

10. Retention, Return, and Deletion

10.1 Unless an Order Form or applicable service plan establishes a different period, Tokenize will apply a rolling 365-day retention period to Customer Data in active and queryable systems. Tokenize may retain particular records for a shorter period based on the applicable feature or Customer configuration.

10.2 After the Agreement expires or terminates, Tokenize will make the remaining Customer Data available for export for 30 days unless an Order Form or applicable service plan states another period. Customer is responsible for completing its export during that period.

10.3 After the export period ends, Tokenize will begin deleting or irreversibly de-identifying Customer Data. Tokenize will complete deletion from active systems within 60 days and from backups, disaster-recovery systems, and archival systems within 365 days after the export period ends.

10.4 Until deletion, Tokenize will continue to protect retained Customer Data under this DPA and will not use it except for security, restoration, legal compliance, or deletion. Restoring a backup does not restart a retention period; Tokenize will reapply the deletion schedule to restored data.

10.5 Tokenize may retain Customer Data subject to a legal hold for the period law requires. Tokenize will isolate the retained data from ordinary use where practicable and delete it when the legal obligation ends.

10.6 Sections 10.1 through 10.5 do not apply to Aggregated Data that satisfies the Aggregated Data requirements in the applicable Agreement.

11. Data Locations and Transfers

11.1 Tokenize is based in the United States and processes Customer Personal Data in the United States. Tokenize will require authorized Subprocessors to process Customer Personal Data in the United States unless Customer and Tokenize agree to another location in writing after Tokenize completes the required transfer review and notice process.

11.2 Tokenize will use the applicable EU-U.S. Data Privacy Framework, UK Extension, or Swiss-U.S. Data Privacy Framework as the primary transfer mechanism while Tokenize's certification for that framework appears as active on the U.S. Department of Commerce Data Privacy Framework List. Schedule 3 incorporates fallback transfer terms when a Data Privacy Framework does not apply. The parties will cooperate to implement another valid mechanism or suspend the affected transfer if a court, regulator, or change in certification status prevents use of the existing mechanism.

11.3 Customer will not use the Services to transfer Customer Personal Data in violation of law or a written data-residency commitment.

12. Liability, Indemnification, and Order of Precedence

12.1 The indemnification and liability provisions of the applicable Agreement govern claims arising from this DPA. This DPA does not create a separate indemnity except where an Order Form expressly amends the MSA.

12.2 This DPA controls over a conflicting Terms of Use, MSA, or Order Form provision concerning Personal Data processing or Customer Data security. An Order Form modifies this DPA only if it identifies the DPA provision and states the amendment.

12.3 The Privacy Policy and Cookie Policy are public notices. They do not replace or amend this DPA.

12.4 Nothing in the Agreement limits a data subject's rights or a party's liability to the extent the EU SCCs, UK Addendum, or other mandatory transfer terms prohibit that limitation.

13. General

13.1 This DPA terminates when Tokenize completes its processing of Customer Personal Data, except for provisions that must survive to protect retained data or enforce accrued rights.

13.2 If a provision of this DPA is unenforceable, the remaining provisions remain effective.

13.3 The governing-law and notice provisions in the applicable Agreement apply to this DPA, except where Schedule 3 requires another law or forum for international transfer terms.

Schedule 1: Processing Details

Subject matter

Tokenize processes Customer Personal Data to provide an AI observability, optimization, governance, and related services platform.

Duration

Processing continues for the term of the Agreement and the deletion period in Section 10.

Frequency

Tokenize processes Customer Personal Data on a continuous or event-driven basis as Customer and its Authorized Users use the Services, and as needed for support, security, and deletion.

Nature and purpose

  • ingesting, storing, organizing, analyzing, and displaying AI and developer-tool telemetry;
  • producing usage, cost, performance, governance, security, and optimization information;
  • providing recommendations, classifications, routing, alerts, and related features;
  • authenticating users, administering organizations, and enforcing access controls;
  • supporting integrations and Customer configurations;
  • providing support and maintaining service reliability; and
  • detecting and responding to fraud, abuse, security incidents, and technical problems.

Categories of Customer Personal Data

  • names, work email addresses, account, organization, user, device, and session identifiers;
  • employment, team, role, manager, and attribution information;
  • IP addresses, device, browser, operating-system, application, and security information;
  • model, token, cost, latency, usage, request, and response telemetry;
  • prompts, responses, transcripts, prompt and response metadata, and output classifications;
  • tool inputs, tool outputs, tool calls, attachments, and MCP connection data;
  • source-code, file-history, file-snapshot, configuration, workspace, and editor or agent activity; and
  • support information and other content that Customer or an Authorized User submits.

Categories of individuals

  • Customer employees, contractors, agents, and Authorized Users;
  • customer administrators, billing contacts, and support contacts; and
  • individuals whose information appears in Customer Data submitted by Customer or an Authorized User.

Sensitive data

The Services do not require Customer to submit Sensitive Data unless an Order Form or other written agreement states otherwise. Customer controls whether Customer Data contains Sensitive Data and must not intentionally submit it without an appropriate lawful basis and Tokenize's written authorization.

If Tokenize authorizes Sensitive Data in an Order Form or other written agreement, the access restrictions, encryption, logging, and other safeguards in Schedule 2 apply to that data. The applicable written agreement will identify any additional safeguards.

Schedule 2: Security Measures

Tokenize will maintain a security program that includes the following controls, as appropriate to the Services and risks:

Access and personnel security

  • role-based access and least-privilege principles for Customer Data;
  • authentication controls for production and administrative systems;
  • confidentiality obligations for personnel with access to Customer Personal Data;
  • access review and removal procedures; and
  • security awareness and role-appropriate training.

Encryption and infrastructure

  • encryption of Customer Data in transit using industry-standard transport encryption;
  • encryption of Customer Data at rest in production storage systems;
  • environment, network, and logical-access controls designed to limit unauthorized access; and
  • cloud infrastructure safeguards and restrictions on public access.

Application and operational security

  • logging and monitoring appropriate to production systems;
  • vulnerability identification, assessment, and remediation processes;
  • change-management and deployment controls;
  • backup, recovery, and service-resilience procedures; and
  • safeguards designed to maintain tenant separation.

Incident response

  • a documented incident-response process;
  • procedures for investigation, containment, remediation, and communication;
  • escalation to responsible personnel; and
  • post-incident review appropriate to the severity of the event.

Subprocessor and risk management

  • risk-based review of Subprocessors that process Customer Data;
  • written data-protection and security obligations; and
  • periodic review of the security and compliance program.

Data lifecycle

  • retention controls for active and queryable systems;
  • deletion and de-identification procedures;
  • controls restricting the use of retained backup or archival data; and
  • deletion verification appropriate to the system and storage medium.

Schedule 3: International Transfer Terms

Data Privacy Framework

Palindrome Labs, Inc. dba Tokenize participates in the EU-U.S. Data Privacy Framework, the UK Extension, and the Swiss-U.S. Data Privacy Framework for non-HR Personal Data. The U.S. Department of Commerce lists Tokenize's certification as active under all three frameworks. The applicable framework governs a transfer under this DPA only while Tokenize's certification for that framework appears as active on the Data Privacy Framework List.

Tokenize will process covered Customer Personal Data under the applicable Data Privacy Framework Principles, including the Notice, Choice, Accountability for Onward Transfer, Security, Data Integrity and Purpose Limitation, Access, and Recourse, Enforcement and Liability Principles. If the applicable framework ceases to cover a transfer, the relevant terms below apply as a fallback unless the parties adopt another lawful mechanism or suspend the transfer.

1. European Economic Area

1.1 If Customer transfers Customer Personal Data protected by the EU GDPR to Tokenize in a country that lacks an adequacy decision, the parties incorporate the standard contractual clauses in European Commission Implementing Decision (EU) 2021/914 (the "EU SCCs") as follows:

  • Module Two applies when Customer is a controller and Tokenize is a processor.
  • Module Three applies when Customer is a processor and Tokenize is a subprocessor.
  • Clause 7, the optional docking clause, applies.
  • In Clause 9, Option 2 applies and the notice period in Section 6.3 of this DPA applies.
  • In Clause 11, the optional independent dispute-resolution language does not apply.
  • In Clause 17, Option 1 applies. The law of the EU Member State where Customer is established governs. If that law does not permit third-party beneficiary rights under the EU SCCs or Customer is not established in an EU Member State, Irish law governs.
  • Under Clause 18, courts corresponding to the law selected under Clause 17 have jurisdiction.
  • The competent supervisory authority under Clause 13 will be determined under the EU SCCs based on Customer's establishment, Article 27 representative, or the location of affected data subjects, as applicable.

1.2 Schedule 1 to this DPA supplies the processing information required by Annex I.B to the EU SCCs. Schedule 2 supplies Annex II. The Trust Center maintains the subprocessor list used for the general authorization under Clause 9, Option 2 and Section 6 of this DPA.

1.3 Customer is the data exporter. Customer's legal name, address, contact information, role, and relevant signature or acceptance information are the details supplied through Customer's account, Order Form, or other written agreement. Tokenize is the data importer with the following details:

Palindrome Labs, Inc. dba Tokenize
128 King St, Floor 3
San Francisco, CA 94107, United States
Privacy contact: privacy@tokenizehq.com

Acceptance of the Terms of Use or execution of an Order Form constitutes each party's signature and agreement to be bound by the EU SCCs. The activities relevant to the transfer are the activities described in Schedule 1.

2. United Kingdom

2.1 For a restricted transfer subject to the UK GDPR, the parties incorporate the Part 2 mandatory clauses of ICO Addendum template B1.0, laid before Parliament on February 2, 2022 under section 119A of the Data Protection Act 2018, including revisions made under Section 18 of those clauses (the "UK Addendum").

2.2 The EU SCC selections in Section 1 of this Schedule and the information in the Agreement complete Tables 1 through 3 of the UK Addendum. For Table 4, neither party may end the UK Addendum under Section 19 solely because the Information Commissioner issues a revised approved addendum.

3. Switzerland

3.1 The Swiss-U.S. Data Privacy Framework governs a transfer of Customer Personal Data protected by Swiss data-protection law while Tokenize's Swiss-U.S. certification appears as active. If that framework does not apply, the EU SCCs apply with these changes:

  • references to the EU GDPR include the Swiss Federal Act on Data Protection;
  • references to an EU Member State include Switzerland;
  • the term "personal data" includes personal data protected by Swiss law;
  • the Swiss Federal Data Protection and Information Commissioner acts as the competent supervisory authority for transfers governed by Swiss law; and
  • data subjects in Switzerland may enforce rights under the EU SCCs as Swiss law permits;
  • Swiss law governs Clause 17 to the extent Swiss law permits; and
  • the courts of Switzerland have jurisdiction under Clause 18 for a transfer governed by Swiss law.

4. Transfer Assessments and Government Requests

4.1 Each party will provide information that the other reasonably needs to assess a regulated transfer. Tokenize will use the safeguards in Schedule 2 and will notify Customer if Tokenize determines that it can no longer comply with the applicable transfer terms or that an applicable Data Privacy Framework certification is no longer active.

4.2 Tokenize will review a government demand for Customer Personal Data and, where reasonable and lawful, challenge a demand that conflicts with law or exceeds the requesting authority's powers. Tokenize will provide notice to Customer before disclosure unless law prohibits notice. If law prohibits notice, Tokenize will use lawful efforts to obtain permission to provide notice.

Schedule 4: Subprocessor Information

Tokenize maintains its current list of Subprocessors, their functions, and their processing locations in the Trust Center. That list forms part of this DPA. Section 6 governs notice of changes and Customer objections.