Legal
Data Processing Agreement
Last updated: 7 September 2026
This Data Processing Agreement ("DPA") forms part of the agreement between Hyper Viral LLC, trading as Totomoko ("Totomoko", "we", "us"), and the client named in that agreement ("Client", "you") for the services described in it (the "Agreement"). It applies wherever Totomoko processes personal data on the Client's behalf in the course of an engagement. It is published so that it can be read before an engagement begins; it takes effect when the Agreement does.
1. Definitions
1.1 Data protection law
“Data Protection Law” means every law that applies to the processing of personal data under this DPA, including the EU General Data Protection Regulation (Regulation (EU) 2016/679), the UK GDPR and the Data Protection Act 2018, the Swiss Federal Act on Data Protection, and any United States state privacy law that applies to the Client.
1.2 Terms from the law
“Personal data”, “processing”, “controller”, “processor”, “data subject”, “personal data breach”, and “supervisory authority” have the meanings given in Data Protection Law.
1.3 Client personal data
“Client Personal Data” means personal data that Totomoko processes on the Client’s behalf under the Agreement, as described in Annex 1.
1.4 Subprocessor
“Subprocessor” means a third party engaged by Totomoko to process Client Personal Data.
2. Roles and scope
2.1 Controller and processor
For Client Personal Data, the Client is the controller (or a processor acting for its own controller) and Totomoko is the processor. Where the Client is itself a processor, the Client warrants that its instructions to Totomoko are authorized by the relevant controller.
2.2 Subject matter
Annex 1 sets out the subject matter, duration, nature and purpose of the processing, the types of personal data, and the categories of data subjects. It is completed for each engagement and forms part of this DPA.
2.3 Precedence
If this DPA and the Agreement conflict on the processing of personal data, this DPA prevails. If this DPA and the Standard Contractual Clauses in Article 10 conflict, the Clauses prevail.
3. Instructions
3.1 Documented instructions
Totomoko processes Client Personal Data only on the Client’s documented instructions, which are the Agreement, this DPA, Annex 1, and any further written instruction the Client gives. Totomoko does not process Client Personal Data for its own purposes.
3.2 Unlawful instructions
If Totomoko considers that an instruction infringes Data Protection Law, it informs the Client without delay and may suspend the processing concerned until the instruction is confirmed or changed.
3.3 Required by law
Totomoko may process Client Personal Data where required by a law to which it is subject, in which case it informs the Client of that requirement before processing unless the law prohibits it.
4. Confidentiality
4.1 Persons authorized
Totomoko limits access to Client Personal Data to the people who need it to perform the Agreement, each of whom is bound by a written duty of confidentiality, and applies the personnel measures described in the Security statement, Article 9.
5. Security
5.1 Measures
Totomoko implements the technical and organizational measures described in the Security statement and summarized in Annex 2, taking into account the state of the art, the costs of implementation, the nature and risk of the processing, and the classification of the data agreed under Article 10.3 of that statement.
5.2 Changes to measures
Totomoko may update the measures over time provided the level of protection does not fall below that in Annex 2.
6. Subprocessors
6.1 General authorization
The Client gives Totomoko general authorization to engage the Subprocessors listed on the Subprocessors page, and any further Subprocessor named in Annex 1 for the engagement.
6.2 Notice and objection
Totomoko gives the Client at least thirty (30) days’ written notice before adding or replacing a Subprocessor that will process Client Personal Data. The Client may object in writing on reasonable data-protection grounds within that period. If the objection cannot be resolved, either party may terminate the affected services on notice without penalty.
6.3 Flow-down
Totomoko imposes on each Subprocessor, by written contract, data-protection obligations no less protective than those in this DPA, and remains liable to the Client for the Subprocessor’s performance.
7. Data subject rights
7.1 Requests
Totomoko forwards to the Client, without undue delay, any request it receives from a data subject about Client Personal Data, and does not respond to it except on the Client’s instruction.
7.2 Assistance
Taking into account the nature of the processing, Totomoko assists the Client with appropriate technical and organizational measures in responding to requests to exercise data subject rights.
8. Personal data breach
8.1 Notification
Totomoko notifies the Client in writing without undue delay, and in any case within seventy-two (72) hours of confirming a personal data breach affecting Client Personal Data, stating what is known about the breach, its likely consequences, and the measures taken or proposed. Further information follows as it becomes available.
8.2 Cooperation
Totomoko cooperates with the Client and takes reasonable steps to contain and remedy the breach. Totomoko does not notify a supervisory authority or data subjects on the Client’s behalf unless the Client instructs it to.
9. Assistance and records
9.1 Impact assessments
Totomoko assists the Client, taking into account the nature of the processing and the information available to Totomoko, with data protection impact assessments and prior consultation of a supervisory authority.
9.2 Records
Totomoko keeps a record of the processing it carries out on the Client’s behalf as required by Data Protection Law and makes it available to the Client on request.
10. International transfers
10.1 Locations
Totomoko is established in the United States. Client Personal Data is processed in the locations stated on the Subprocessors page and in Annex 1.
10.2 Transfer mechanism
Where Data Protection Law restricts a transfer of Client Personal Data to a country outside the EEA, the United Kingdom or Switzerland, the transfer is made under the European Commission’s Standard Contractual Clauses (Decision (EU) 2021/914), Module Two or Module Three as applicable, and for UK transfers the UK International Data Transfer Addendum, each of which is incorporated into this DPA by reference. Annex 1 and Annex 2 of this DPA serve as the annexes to those Clauses.
10.3 Other mechanisms
Where a transfer is covered by an adequacy decision, a certification under a recognized framework, or another valid mechanism, that mechanism applies instead.
11. Return and deletion
11.1 At the end of the engagement
Within thirty (30) days of the end of the services, or earlier on the Client’s written request, Totomoko returns Client Personal Data to the Client in a commonly used format or deletes it, at the Client’s choice, and deletes existing copies unless a law requires their retention. Data deleted from live systems is removed from backups on the next backup rotation.
11.2 Certification
On request, Totomoko confirms deletion in writing.
12. Audit
12.1 Information
Totomoko makes available to the Client the information necessary to demonstrate compliance with this DPA, including the documents listed in the Security statement, Article 16.
12.2 Audits
Where the information is not sufficient, the Client may, at its own cost, once in any twelve-month period or following a personal data breach, conduct or mandate an audit of Totomoko’s processing of Client Personal Data on thirty (30) days’ notice, during business hours, in a manner that does not unreasonably disrupt Totomoko’s operations, and subject to confidentiality.
13. AI models
13.1 No training
Totomoko does not use Client Personal Data to train, fine-tune or evaluate any artificial-intelligence model for anyone other than the Client, and does not opt Client Personal Data into any provider’s training program.
13.2 Model providers
Any model provider that will process Client Personal Data is named in Annex 1 with its role, the data it handles, its location, and its retention window, before any Client Personal Data reaches it.
14. Liability
14.1 Cap
Each party’s liability under this DPA is subject to the limitations and exclusions of liability in the Agreement, except that nothing limits liability that cannot be limited under Data Protection Law.
15. Term
15.1 Duration
This DPA takes effect when the Agreement does and remains in force for as long as Totomoko processes Client Personal Data, and Articles 4, 11 and 14 survive its end.
16. Governing law
16.1 Law and jurisdiction
This DPA is governed by the law that governs the Agreement, without prejudice to the governing-law provisions of the Standard Contractual Clauses where they apply.
Annex 1. Details of processing
A1.1 Completed per engagement
The following is completed in the Agreement or its annex for each engagement.
| Item | Detail |
|---|---|
| Subject matter | The services described in the Agreement |
| Duration | The term of the Agreement plus the period in Clause 11.1 |
| Nature and purpose | The processing necessary to design, build, operate or advise on the systems described in the Agreement |
| Types of personal data | As stated for the engagement (for example: names, business contact details, account identifiers, correspondence, transaction records) |
| Categories of data subjects | As stated for the engagement (for example: the Client’s staff, customers, suppliers, users) |
| Special categories | None, unless stated for the engagement with the additional measures agreed |
| Subprocessors | The Subprocessors page, plus any provider named for the engagement with its role, data, location and retention window |
| Locations | As stated on the Subprocessors page and for any engagement-specific provider |
Annex 2. Security measures
A2.1 Measures
The technical and organizational measures are those in the Security statement: encryption in transit and at rest (Article 7.1), multi-factor authentication and credential management (7.2), engagement isolation (7.3), infrastructure exposure (7.4), access review (7.5), endpoints (7.6), logging (7.7), secure development and code hosting (Article 8), personnel (Article 9), retention and deletion (Article 10), incident response (Article 11), and business continuity (Article 12).