Data Processing Agreement
Last updated: June 15, 2026
Effective June 15, 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between ThinkingDBx Pvt. Ltd.("Processor") and the customer ("Controller") and applies where we process personal data contained in Your Data on your behalf. It is designed to meet GDPR Art. 28 and the data-processor obligations of India's DPDP Act, 2023.
1. Roles
For Your Data, the Controller (you) determines the purposes and means of processing, and we act as Processor, processing personal data only on your documented instructions (including via your use of the Service and its API).
2. Subject-matter & details (Art. 28(3))
- Subject-matter: provision of the ThinkingMemory memory service.
- Duration: the term of your account.
- Nature & purpose: storage, retrieval, and lifecycle management of memories you submit.
- Types of data & data subjects: as determined by you through the content you choose to store.
3. Our obligations
- process personal data only on your documented instructions;
- ensure personnel are bound by confidentiality;
- implement appropriate technical & organisational security measures (Section 6);
- engage sub-processors only under written terms and equivalent obligations, with the list at /legal/subprocessors and notice of material changes;
- assist you, taking into account the nature of processing, with data-subject requests and with security, breach-notification, and impact-assessment obligations;
- at your choice, delete or return personal data at the end of the service, subject to legal retention of audit records.
4. Data-subject requests
The Service lets you fulfil access, export, and erasure requests directly (self-serve export and delete endpoints; see the Privacy Policy, Section 6). Where you need our help, contact dpo@thinkingdbx.com.
5. International transfers
Your Data is stored in a managed PostgreSQL database in the United Kingdom (Supabase, on AWS), with application/compute on Contabo GmbH infrastructure in the United Kingdom. Where a sub-processor processes personal data across borders, we rely on appropriate safeguards (e.g. Standard Contractual Clauses and applicable adequacy decisions).
6. Security measures
We maintain measures including: per-tenant isolation enforced at the database (row-level security); hashed credentials and API keys; encryption in transit (TLS); encryption at rest on the managed database (AES-256); append-only audit logging; rate limiting and access controls.
7. Personal-data breach
We will notify you without undue delay after becoming aware of a personal-data breach affecting Your Data, and provide information reasonably available to assist your own notification obligations.
8. Audits
On reasonable request and subject to confidentiality, we will make available information necessary to demonstrate compliance with this DPA.
9. How to execute
This DPA is incorporated by reference into the Terms and applies automatically when we process personal data on your behalf. For a countersigned copy or a customer-specific DPA, write to dpo@thinkingdbx.com.