Version 0.1Effective September 17, 2026

TurboDemand Data Processing Agreement

Status: Draft — for legal review; not legal advice Version: 0.1 Released: 2026-09-17 Effective date: 2026-09-17 Note: this is the published version's effective date; a signed Order Form incorporates the version current at signing. Owner: Pranab Document key: dpa (see docs/specs/contracting-flow.md) Execution: Annex A to every Order Form (signed with it); also published at /dpa and incorporated by reference into the Terms of Service for self-serve clients.


This Data Processing Agreement ("DPA") forms part of the Master Subscription Agreement or, for self-serve clients, the Terms of Service (either, the "Agreement") between [MISSING: entity.legal_name] ("TurboDemand") and the Client. It reflects the parties' agreement on the processing of personal data under the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018, the Swiss FADP, and, per Annex 5, India's Digital Personal Data Protection Act 2023 ("DPDP Act"). Where local law is stricter, the stricter rule applies.

1. Definitions

"Personal Data", "Controller", "Processor", "Data Subject", "Processing", "Personal Data Breach", "Supervisory Authority", and "Sub-processor" have the meanings in the GDPR. "Client Personal Data" means Personal Data that TurboDemand processes on Client's behalf, as described in Annex 1. "SCCs" means the standard contractual clauses adopted by the European Commission in Decision (EU) 2021/914, and the UK International Data Transfer Addendum where UK data is transferred.

2. Roles

2.1 Client as Controller, TurboDemand as Processor for: Lead Data submitted through Microsite forms; Microsite visitor analytics; personal data contained in Client Content that Client uploads, connects, or authorises TurboDemand to crawl (for example staff names on a team page, customer testimonials, case-study contacts); personal data in Client's CRM or mailbox that flows through integrations Client connects; and personal data Client places in prompts, feedback rules, or content briefs. This DPA governs that processing.

2.2 TurboDemand as independent Controller for: account data of Client's Authorised Users (name, email, credentials, roles), billing and contract data, session and security logs, activity and audit logs, support communications, and dashboard usage analytics. TurboDemand processes this data under its Privacy Policy (privacy-policy.md Part A), which sets out purposes, retention, and rights. The parties are not joint controllers.

2.3 Client as Controller of the Microsite. The Microsite is published on Client's domain under Client's name. Client is responsible for the visitor-facing privacy notice, cookie consent, and consent-checkbox wording, using the configuration the Service provides.

3. Client instructions

3.1 TurboDemand will process Client Personal Data only on Client's documented instructions, which are: the Agreement, this DPA, the Order Form, Client's configuration and actions in the dashboard (including integrations Client connects and destinations Client configures), and other written instructions Client gives. TurboDemand will inform Client if it believes an instruction infringes data-protection law, and may suspend the instruction until resolved.

3.2 Client warrants that it has a lawful basis for the processing it instructs, has provided required notices, and that the Client Content it authorises TurboDemand to crawl is content Client is entitled to process.

4. Confidentiality and personnel

TurboDemand ensures that persons authorised to process Client Personal Data are bound by confidentiality, receive appropriate training, and access data only as needed. Access to production data and to logs containing prompts or lead data is limited to internal and administrative roles, requires two-factor authentication, and is audit-logged. Support access to a Client organisation uses an impersonation mode that records both the staff identity and the impersonated user for every action and cannot perform owner-only actions.

5. Security

TurboDemand implements the technical and organisational measures in Annex 4 and will not materially reduce them during the term. TurboDemand will regularly test and evaluate the effectiveness of these measures.

6. Personal Data Breach

6.1 TurboDemand will notify Client without undue delay and in any event within 48 hours after becoming aware of a Personal Data Breach affecting Client Personal Data, at the notice addresses in the Order Form or the client administrators' email addresses.

6.2 The notification will describe the nature of the breach, categories and approximate numbers of Data Subjects and records, the likely consequences, measures taken or proposed, and a contact point, and will be supplemented as information becomes available. TurboDemand will document breaches in its incident register and provide Client with the information reasonably needed for Client's own notifications to Supervisory Authorities (GDPR Art. 33, within 72 hours) and Data Subjects (Art. 34), and to the Data Protection Board of India (Annex 5).

6.3 TurboDemand will not notify Data Subjects or authorities on Client's behalf about a breach of Client Personal Data unless required by law or agreed with Client, except that TurboDemand may notify authorities about the same incident in its own capacity as Controller of the data in Section 2.2.

7. Assistance to Client

7.1 Data Subject requests. TurboDemand will promptly (within 5 business days) forward to Client any request it receives from a Data Subject relating to Client Personal Data, and will not respond except to direct the person to Client. TurboDemand will assist Client in responding through the tools in the Service: lead search, edit, export (CSV with full metadata), and deletion in the dashboard; and, where those tools are insufficient, by reasonable manual assistance at no charge for reasonable requests; extensive or repeated assistance is billed at TurboDemand's then-current time-and-materials rates.

7.2 DPIAs and consultation. TurboDemand will provide reasonably available information to assist Client with data protection impact assessments and prior consultation with a Supervisory Authority concerning the Service.

7.3 Records. TurboDemand maintains records of processing activities under Art. 30(2) and will make the relevant records available on request.

8. Audit

8.1 TurboDemand will make available to Client the information necessary to demonstrate compliance with this DPA, including this DPA's annexes, a summary of its security programme, results of any penetration tests or third-party assessments it has obtained (with sensitive details redacted), and its incident register entries affecting Client.

8.2 Client (or an independent auditor bound by confidentiality and not a competitor of TurboDemand) may audit TurboDemand's compliance once per 12 months, or additionally after a Personal Data Breach affecting Client or where required by a Supervisory Authority, on at least 30 days' written notice, during business hours, without unreasonable disruption, and limited to systems and records relevant to Client Personal Data. Audits are at Client's cost unless they reveal a material breach of this DPA. TurboDemand may require that an audit be satisfied first by written responses and documentary evidence.

8.3 Where a sub-processor is a major infrastructure provider (Annex 3) that does not permit on-site audits of its facilities, Client accepts that provider's published certifications and audit reports (for example SOC 2 or ISO 27001) as satisfying the audit right for that provider.

9. Sub-processors

9.1 Client authorises TurboDemand to engage the Sub-processors listed in Annex 3, which is the authoritative list for the Agreement and the Privacy Policy.

9.2 TurboDemand will give Client at least 30 days' prior notice of any intended addition or replacement of a Sub-processor by email to client administrators and by updating Annex 3 at https://app.turbodemand.com/dpa#annex-3. Client may object in writing within that period on reasonable data-protection grounds. If the parties cannot resolve the objection in good faith within 30 days, Client may terminate the affected Order Form on notice and receive a refund of prepaid Fees for the unused remainder, as its sole remedy.

9.3 TurboDemand will impose on each Sub-processor data-protection obligations that are no less protective than this DPA, by written contract, and remains fully liable to Client for the Sub-processor's performance.

9.4 Client-directed recipients (integrations Client connects: Slack, Zapier, generic webhooks, HubSpot, Salesforce, WordPress, Shopify, Google Search Console, Google Business Profile, Trustpilot, Google Ads, Client's own SMTP, Gmail, or Microsoft 365 mailbox, and Client's own web host or Cloudflare account) are not Sub-processors. Client is the Controller for data sent to them, and their terms apply.

9.5 Client BYOK keys. Where Client provides its own LLM API keys, the LLM provider processes prompts under Client's own agreement with that provider, and Client's failure-policy choice (fall back to TurboDemand's platform key, or fail closed) determines whether TurboDemand's Sub-processor terms apply to the fallback calls. TurboDemand notifies Client of every fallback.

10. International transfers

10.1 TurboDemand may transfer Client Personal Data to the locations in Annex 3. Where a transfer of personal data protected by the GDPR, UK GDPR, or Swiss FADP is made to a country without an adequacy decision, the parties rely on the SCCs, which are incorporated as follows: Module Two (controller to processor) between Client and TurboDemand where TurboDemand is outside the EEA; Module Three (processor to processor) between TurboDemand and each Sub-processor. Clause 7 (docking) is included; Clause 9 option 2 (general authorisation) with the 30-day notice period in Section 9.2; Clause 11 optional language is not included; Clause 13 and Annex I.C: the Supervisory Authority of Ireland; Clause 17: the law of Ireland; Clause 18: the courts of Ireland. Annex I of the SCCs is completed by Annexes 1 and 2 of this DPA; Annex II by Annex 4; Annex III by Annex 3.

10.2 For UK transfers, the UK International Data Transfer Addendum applies to the SCCs with the parties' details in Annexes 1 and 2 and "Importer" chosen for Table 4. For Swiss transfers, references to the GDPR are read as the FADP and the FDPIC is the competent authority.

10.3 Where a Sub-processor is certified under the EU-US Data Privacy Framework (or UK or Swiss extensions), TurboDemand may rely on that certification instead of SCCs for that transfer.

10.4 TurboDemand will notify Client if it can no longer comply with the SCCs, and Client may suspend the affected transfer or terminate the affected Order Form.

10.5 India: see Annex 5 §4.

11. Return and deletion

11.1 During the term, Client can export Client Personal Data at any time in portable formats (leads as CSV with full metadata; brand knowledge, strategy, and configuration as JSON; articles and Microsite source as files) and delete leads and other records from the dashboard.

11.2 On expiry or termination of the Agreement, Client selects a cancellation option under the Agreement. TurboDemand will: (a) keep export-only dashboard access available for 30 days; (b) where Client selected static export, deliver an archive of the published Microsite (HTML and assets) that remains downloadable for 90 days with reminders at 14 and 3 days before expiry; (c) retain Client Personal Data for 90 days after the end date to support export and reactivation, notifying Client at 60 and 80 days; and (d) at the end of the 90 days, delete all Client Personal Data from production systems, including brand knowledge, articles, leads, analytics, feedback rules, and LLM call logs, and crypto-shred encrypted credentials, unless Client has instructed retention in writing or law requires retention. Backups are rotated on the schedule in Annex 4 (7 daily, 4 weekly, 3 monthly), so a deleted record can persist in an encrypted backup for up to 90 days after deletion; backups are encrypted, access-restricted, used only for disaster recovery, and never restored to production except to recover from data loss, and any restore is followed by re-application of deletions recorded in the deletion tombstone log.

11.3 Client may instead request deletion at any time through the account-deletion flow (72-hour grace period, then cascading purge) or in writing; TurboDemand will complete deletion within 30 days and confirm in writing. Deletion is recorded in a tombstone containing only hashed identifiers and timestamps.

11.4 Published Microsite pages on Client's own domain or host are Client's copies; TurboDemand does not delete them (see Product-Specific Authorizations §6). If the Microsite is served from TurboDemand infrastructure through a proxy or subdomain, TurboDemand removes the served copy after the 90-day retention period unless Client has moved to the hosting-only plan.

12. Liability

Each party's liability under this DPA is subject to the limitations and exclusions in the Agreement (Section 13), except that liability which cannot be limited under applicable law — which, depending on the jurisdiction, may include statutory data-protection liability — is not capped. Nothing in this DPA limits a Data Subject's rights under the GDPR, the DPDP Act, or the SCCs.

13. Term and precedence

This DPA lasts for as long as TurboDemand processes Client Personal Data. For data-protection matters it prevails over the Agreement; the SCCs prevail over this DPA where they conflict.


Annex 1 — Details of processing

Item Description
Subject matter Provision of the TurboDemand Service: building, publishing, and hosting AI-generated marketing Microsites for Client; capturing and managing leads; analytics; integrations
Duration The Subscription Term plus the 90-day retention period, or until earlier deletion
Nature and purpose Hosting, storage, crawling of Client websites, text and image generation with LLMs, publishing to Client Domains, receipt and storage of form submissions, spam filtering, lead scoring, notification and forwarding of leads, first-party page analytics, export
Categories of Data Subjects Visitors to Client's Microsite; individuals who submit lead forms (prospects, customers); individuals named in Client Content (Client staff, customers giving testimonials, case-study participants, reviewers); individuals in Client's connected CRM or mailbox to the extent data flows through the Service
Categories of Personal Data Lead form fields (name, email, phone, company, job title, message, and any custom fields Client configures); consent status; referrer and UTM parameters; page-by-page visitor journey on the Microsite; hashed IP address; user agent; anonymous session id; lead score and status; names, roles, quotes, and images in Client Content; personal data Client includes in prompts, feedback rules, or briefs
Special categories None intended. Client must not configure forms to collect special-category data or direct content containing health, biometric, or similar data without a separate written agreement
Frequency Continuous
Retention See Section 11 and the Privacy Policy

Annex 2 — Parties (for SCC Annex I.A)

Data exporter (Client) Data importer (TurboDemand)
Name Per Order Form [MISSING: entity.legal_name]
Address Per Order Form [MISSING: entity.registered_address]
Contact Per Order Form privacy@turbodemand.com
Role Controller Processor
Signature and date Per Order Form Per Order Form

Annex 3 — Sub-processors

This list is identical to Privacy Policy §A4 and is the authoritative list. Locations in brackets must be confirmed before publication.

Sub-processor Service Personal Data processed Location Transfer mechanism
Hetzner Online GmbH Application and worker servers, PostgreSQL All Client Personal Data Germany EEA (none) or the EU Standard Contractual Clauses, and for transfers involving India the permitted-transfer provisions of the DPDP Act
Cloudflare, Inc. DNS, CDN, reverse proxy, Workers, R2 asset storage, Turnstile, TLS Visitor traffic metadata and IPs at the edge; published assets; Client DNS records where DNS is delegated Global edge; R2 Germany SCCs / DPF
DreamHost, LLC Static hosting origin for Microsites Published pages and assets (public content) United States SCCs
Backblaze, Inc. Encrypted backups and export archives Encrypted copies of all Client Personal Data the European Union SCCs
Anthropic, PBC LLM provider Prompts and outputs containing Client Content United States SCCs / DPF
OpenAI, L.L.C. LLM provider Same United States SCCs / DPF
Google LLC LLM provider (Gemini API) Same United States SCCs / DPF
OpenRouter, Inc. LLM routing Same, to the routed provider United States SCCs
fal.ai (Features and Labels, Inc.) Image generation (primary) Image prompts derived from Client Content United States SCCs
Replicate, Inc. Image generation (fallback) Same United States SCCs
Resend, Inc. Transactional email (default) Recipient name, email, message content (lead notifications to Client users, reports) United States SCCs / DPF
Mailgun Technologies, Inc. Transactional email (alternative) Same United States / EU SCCs / DPF
Stripe, Inc. Payments Billing contact and transaction data (Section 2.2 data, listed for completeness) United States / global SCCs / DPF
Razorpay Software Pvt. Ltd. Payments (India) Same India the EU Standard Contractual Clauses, and for transfers involving India the permitted-transfer provisions of the DPDP Act
PayPal Holdings, Inc. Payments Same United States / global SCCs / DPF
Telegram Messenger Inc. Operator alerts (on-call) Organisation names and event types; for new-lead alerts the lead's name, email, and company (Client Personal Data) Global; Telegram's operating entities are in the UAE and EU Standard Contractual Clauses where Telegram offers them; new-lead alerts otherwise rely on the operator-alerting basis and are being reduced to a lead identifier only (roadmap)
Dropbox, Inc. (Dropbox Sign) Contract signature and storage (first provider; ADR 025) Signatory name, email, IP, signed document (Section 2.2 data) United States SCCs / DPF

Prompt-processing note: TurboDemand uses the API products of the LLM and image providers above, under terms that exclude the use of API inputs and outputs for model training and limit retention to abuse monitoring (typically 30 days). Client Personal Data in prompts is minimised to what the content task requires.

Annex 4 — Technical and organisational measures

Drawn from docs/specs/security-and-compliance.md and docs/specs/auth-security.md; items marked "planned" are policy requirements not yet fully implemented and must be verified before this annex is issued to a client.

Area Measures
Access control and authentication Owned authentication layer; email verification before dashboard access; passwords hashed with bcrypt (cost 12) or argon2id; TOTP two-factor authentication available to all users and required for TurboDemand staff by internal policy (application-level enforcement for staff roles: planned; verify before issuing this annex); recovery codes hashed; magic-link, verification, reset, and invitation tokens single-use and time-limited; rate limits on signup, login, reset, and magic-link endpoints; account lockout after 10 consecutive failures with exponential backoff (5 min to 24 h); CAPTCHA (Cloudflare Turnstile) escalation; suspended and deactivated users cannot log in
Session security Server-side sessions in PostgreSQL (not JWT-only); httpOnly, Secure, SameSite=Strict cookies; 7-day sliding expiry; revoke-one and revoke-all; admin force-revoke; session id regenerated on login, 2FA completion, and impersonation start and end
Authorisation and tenant isolation Role-based permissions enforced server-side on every route; organisation id taken from the session, never from the request; every organisation-scoped query filtered by organisation id; tenant-isolation tests required for every organisation-scoped model; cross-tenant admin access explicit and audited
Administrative access Impersonation mode records real and impersonated identity on every action; owner-only actions (billing ownership, account deletion, agreement acceptance, password change, secret reveal) blocked during impersonation; secrets masked in all admin views with no reveal endpoint
Input validation and output encoding Validation at every boundary (API routes, webhooks, lead endpoints, connector endpoints, admin config); canonical output encoders for HTML, attributes, JSON-LD, and URLs; allow-list HTML sanitiser for rich text; nonce-based Content Security Policy and baseline security headers (HSTS, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, frame protection); CSRF tokens on all cookie-authenticated state-changing routes; deny-by-default CORS
Encryption TLS for all traffic; AES-256-GCM encryption at rest with per-record IVs for BYOK keys, integration credentials, connector secrets, SSH deploy keys, and TOTP secrets, with the master key held outside the database; inbound API keys stored as SHA-256 hashes and shown once; backups encrypted
Deployment credentials Per-client deploy keys admin-managed, encrypted, never returned after save, decrypted only by the deploy worker; SSH key authentication only (no passwords); host-key fingerprint pinning; key material written to a 0600 temporary file and deleted after each deploy; safe-path guard on remote sync destinations
Webhooks and integrations Signature verification for Stripe, Razorpay, and PayPal webhooks; idempotency table and 5-minute staleness window; connector callbacks authenticated by hashed per-organisation keys with expiry and rotation overlap
LLM and prompt security No LLM call bypasses the common adapter; no key material in prompts or logs; prompt and response logs restricted to internal roles; BYOK keys isolated per organisation and provider with a client-chosen failure policy and mandatory owner notification; replay always uses platform keys
Lead capture anti-abuse Honeypot, timing checks, disposable-email checks, per-IP rate limiting (over 5 submissions per hour blocked), optional Turnstile; server-side validation before storage; IP addresses hashed
Logging and monitoring Audit log of security-relevant actions (login, logout, reset, 2FA changes, session revocation, impersonation, key operations, config changes, deletion); operator alerting for lockouts, webhook verification failures, BYOK invalidation, and deletion failures; logs containing prompts or lead data restricted to authorised staff
Backup and recovery Daily encrypted backups to Backblaze B2 with 7 daily, 4 weekly, 3 monthly retention (a deleted record can persist in a backup for up to ~90 days; see §11.2); documented restore procedures for the database, object storage, and Microsite rehydration; restore tests quarterly with documented results
Incident response Severity classification (Critical, High, Medium, Low); Critical and High acknowledged within 1 hour and staffed within 2 hours; incident register; post-mortem within 7 days; containment checklist (revoke credentials, isolate tenants, preserve evidence); Client notification per Section 6
Data lifecycle Data minimisation; self-serve export (full and partial) with expiring download links; deletion workflow with 72-hour grace, cascading purge, crypto-shredding of encrypted records, and non-identifying tombstone; explicit retention windows
Secure development Mandatory review for changes to auth, billing, public endpoints, secrets, prompt execution, and deploy credentials; tests shipped with every change; dependency vulnerability scanning in CI; lockfile committed; external code review before release
Physical and infrastructure Servers at Hetzner data centres (Germany) with the provider's physical security certifications; no production data on staff laptops beyond what support requires; continuous uptime monitoring

Annex 5 — India Digital Personal Data Protection Act 2023

This Annex applies where Client is a Data Fiduciary under the DPDP Act, or where Data Principals in India are concerned.

  1. Roles. Client is the Data Fiduciary for Client Personal Data; TurboDemand is its Data Processor engaged under a valid contract (this DPA) per Section 8(2) of the DPDP Act. TurboDemand is a Data Fiduciary in its own right for the data in Section 2.2.
  2. Processing only under contract. TurboDemand processes Client Personal Data only for the purposes and in the manner Client instructs, and only for lawful purposes for which Client has obtained consent or which are legitimate uses under Section 7.
  3. Consent and notice. Client is responsible for giving the notice required by Section 5 and obtaining consent under Section 6, including in any of the languages specified in the Eighth Schedule to the Constitution that Client's visitors require. The Microsite consent banner and form consent checkbox are tools for this purpose; Client sets their wording.
  4. Cross-border transfer. TurboDemand transfers Client Personal Data only to countries not restricted by the Central Government under Section 16, as listed in Annex 3.
  5. Security and breach. TurboDemand implements the Annex 4 safeguards. On a personal data breach TurboDemand notifies Client per Section 6 so that Client can notify the Data Protection Board of India and affected Data Principals in the form and time the Rules prescribe. TurboDemand will provide the details Client needs for those notifications.
  6. Erasure. When Client withdraws an instruction, a Data Principal withdraws consent, or the specified purpose is served, TurboDemand erases the relevant Client Personal Data on Client's instruction and in any case per Section 11, unless retention is required by law.
  7. Data Principal rights. TurboDemand forwards requests received (access, correction, erasure, grievance) to Client within 5 business days and assists Client per Section 7.1.
  8. Grievance Officer. TurboDemand's contact for DPDP matters is the Grievance Officer, privacy@turbodemand.com. Client will publish its own Grievance Officer details on the Microsite.
  9. Children. Client will not configure Microsite forms to target or knowingly collect data of children under 18 without verifiable parental consent, and will not direct TurboDemand to process such data.
  10. Significant Data Fiduciary. If Client is notified as a Significant Data Fiduciary, the parties will cooperate on additional obligations (data-protection officer, independent audit, DPIA) at Client's cost.
  11. Precedence. For Data Principals in India, this Annex prevails over the body of the DPA where they conflict; for Data Subjects in the EEA, UK, or Switzerland, the body of the DPA and the SCCs prevail.