Data Processing Addendum
The Article 28 terms that govern our processing of personal data on your behalf. They apply automatically to every customer — you do not need to ask us to sign anything.
1. Scope and incorporation
This Addendum forms part of the Terms of Service between you (“Customer”) and Naveen Kumar, sole proprietor, trading as ThinkingRoot(“ThinkingRoot”). It applies whenever ThinkingRoot processes personal data on the Customer's behalf in providing the service.
This Addendum is in force for every customer as a term of the agreement. There is no separate signature step and no gate on your plan — if you need a countersigned copy for procurement, email [email protected] and we will provide one.
“Data Protection Law” means the EU GDPR, the UK GDPR and Data Protection Act 2018, the Swiss FADP, the India Digital Personal Data Protection Act 2023, the California Consumer Privacy Act, and any other applicable privacy law. Terms such as “controller”, “processor”, “personal data” and “processing” carry the meanings given in that law. If this Addendum conflicts with the Terms of Service, this Addendum governs for matters of data protection.
2. Roles of the parties
For Customer Personal Data — the personal data contained in content the Customer or its end-users submit to the service — the Customer is the controller and ThinkingRoot is the processor. Where the Customer is itself a processor for another controller, ThinkingRoot is a sub-processor and this Addendum applies accordingly.
ThinkingRoot is an independent controller for the limited data it processes for its own purposes: Customer account records, billing, security and audit logging, and site analytics. Its Privacy Policy governs that data.
The Customer is responsible for the lawfulness of the personal data it submits, for having a valid legal basis, and for providing the notices and obtaining the consents its own end-users are owed.
3. Details of processing (Article 28(3))
| Item | Detail |
|---|---|
| Subject matter | Provision of the ThinkingRoot memory and cognition platform. |
| Duration | The term of the agreement, plus the deletion period in section 10. |
| Nature and purpose | Storing, indexing, embedding, retrieving, extracting facts from, and synthesising answers over Customer Content, at the Customer's direction. |
| Types of personal data | Determined by the Customer. May include identifiers, contact details, professional and personal history, communications, uploaded documents and media, and any other category the Customer chooses to submit — including special-category data. |
| Categories of data subjects | The Customer's personnel and the Customer's end-users, and any individual referenced within submitted content. |
4. ThinkingRoot's obligations
ThinkingRoot will:
- 01Process Customer Personal Data only on the Customer's documented instructions, including as to international transfers. The agreement, this Addendum, and the Customer's use of the service constitute those instructions. If law requires processing beyond them, ThinkingRoot will inform the Customer first unless that law prohibits it.
- 02Ensure that everyone authorised to process Customer Personal Data is bound by an obligation of confidentiality.
- 03Implement and maintain the technical and organisational measures described in section 7.
- 04Engage sub-processors only under section 5, on terms no less protective than this Addendum, and remain fully liable for their performance.
- 05Assist the Customer in responding to data subject requests, as set out in section 6.
- 06Assist the Customer with security, breach notification, data protection impact assessments and prior consultation, taking into account the nature of the processing and the information available.
- 07Delete or return Customer Personal Data at the end of the service, as set out in section 10.
- 08Make available the information necessary to demonstrate compliance with Article 28, and allow for and contribute to audits, as set out in section 11.
ThinkingRoot will tell the Customer if, in its opinion, an instruction infringes Data Protection Law.
ThinkingRoot does not use Customer Personal Data to train or fine-tune any machine learning model, does not use it for any purpose outside the direct business relationship, and does not make it accessible across tenants. Embedding and reranking run on models hosted within ThinkingRoot's own infrastructure.
5. Sub-processors
The Customer gives general written authorisation for ThinkingRoot to engage sub-processors. The current list is published at thinkingroot.com/subprocessors and forms part of this Addendum.
ThinkingRoot will give at least 30 days' notice before a new sub-processor begins processing, by email to subscribers of that page. The Customer may object on reasonable data-protection grounds within that period. The parties will work in good faith to resolve it; if they cannot, the Customer may terminate the affected service and receive a pro-rata refund of prepaid fees.
Each sub-processor is bound by a written contract imposing obligations equivalent to this Addendum. ThinkingRoot remains fully liable to the Customer for their acts and omissions.
6. Data subject requests
The service gives the Customer direct, self-service means to access, export, correct and delete personal data within its projects — including deleting an individual memory or every memory derived from a source, with search indexes rebuilt so deleted material stops being retrievable.
Where a data subject contacts ThinkingRoot directly about Customer Personal Data, ThinkingRoot will not respond substantively but will refer them to the Customer and inform the Customer promptly. To the extent the Customer cannot satisfy a request through the service itself, ThinkingRoot will provide reasonable assistance at no additional charge.
7. Security measures (Article 32)
ThinkingRoot maintains at least the following:
- Encryption in transit — TLS on all external connections. Origin servers accept traffic only from the edge network and are not directly reachable from the public internet.
- Encryption at rest — provided by the underlying infrastructure. Connector access tokens are additionally encrypted with XSalsa20-Poly1305 authenticated encryption; project secrets use sealed-box asymmetric encryption where the storing component holds only the public key and cannot decrypt them.
- Tenant isolation — one container and one database volume per project, with a further per-end-user store inside each project. Isolation is enforced at the container boundary, not by query filtering.
- Authentication — Argon2id password hashing at OWASP-recommended parameters; session and API credentials stored only as BLAKE3 hashes with 192 bits of entropy.
- Access control — role-based access scoped by organisation membership, with per-key capability restrictions and rate limiting.
- Logging and monitoring — an append-only audit log of privileged actions, plus service health and anomaly alerting.
- Resilience — encrypted off-host backups on an approximately five-minute cycle, with a documented restore procedure.
- Least privilege — production access limited to personnel who require it, over authenticated channels.
ThinkingRoot may update these measures as the service evolves, provided the overall level of security is not reduced.
8. Personal data breach
ThinkingRoot will notify the Customer without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notice will describe the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, the measures taken or proposed, and a contact point — to the extent that information is available, with updates as the investigation proceeds.
ThinkingRoot will not make public statements identifying the Customer without the Customer's consent, except where legally required.
9. International transfers
Customer Personal Data is processed in the United States, and administered from India.
Where Data Protection Law restricts a transfer, the parties agree that the European Commission's Standard Contractual Clauses (Decision 2021/914) are incorporated by reference and apply:
- Module Two (controller to processor) where the Customer is a controller, and Module Three (processor to processor) where the Customer is itself a processor.
- Clause 7 (docking) applies. Clause 9 option 2 (general written authorisation) applies with the 30-day notice period in section 5. Clause 11 does not include the optional independent dispute-resolution body. Clause 17 selects the law of Ireland, and Clause 18(b) the courts of Ireland.
- Annex I is populated by section 3 of this Addendum and the sub-processor list; Annex II by section 7.
- For UK transfers, the ICO's International Data Transfer Addendum applies to those Clauses. For Switzerland, references to the GDPR are read as references to the FADP and the Swiss FDPIC is the competent authority.
Where a sub-processor is certified under the EU–US Data Privacy Framework, that certification operates as an additional safeguard and not as a replacement for the Clauses. ThinkingRoot maintains a transfer impact assessment and will provide it on request.
10. Deletion and return
The Customer may export Customer Personal Data at any time during the term, and for 30 days after termination. After that period ThinkingRoot will delete it, including from the systems of its sub-processors.
Deleted content stops appearing in backups within approximately one backup cycle, as backups retain the most recent snapshot rather than a history. Where ThinkingRoot must retain data to comply with law, it will keep it only for as long as required and continue to protect it under this Addendum.
11. Audits
ThinkingRoot will make available the information necessary to demonstrate compliance with this Addendum. On request it will complete a reasonable security questionnaire, no more than once a year unless a breach or a regulator requires otherwise.
Where documentation is genuinely insufficient to satisfy a regulator, the Customer may conduct an audit itself or through an independent auditor who is not a competitor of ThinkingRoot, on 30 days' notice, during business hours, no more than once a year, subject to confidentiality, and in a manner that does not disrupt the service or compromise the data of other customers. Each party bears its own costs.
12. United States state privacy law
For personal information subject to the California Consumer Privacy Act, ThinkingRoot acts as a “service provider” and, for other US state laws, as a “processor.” ThinkingRoot:
- Will not sell or share personal information, as those terms are defined by the CCPA.
- Will not retain, use or disclose personal information for any purpose other than performing the services specified in the agreement, or as otherwise permitted by the CCPA.
- Will not retain, use or disclose personal information outside the direct business relationship between the parties.
- Will not combine personal information received from the Customer with personal information from other sources, except as the CCPA permits.
- Provides the same level of privacy protection the CCPA requires of a business, and will notify the Customer if it determines it can no longer do so.
- Grants the Customer the right to take reasonable steps to ensure personal information is used in a compliant manner, and will remediate unauthorised use.
The specific business purposes are the provision, maintenance and security of the ThinkingRoot platform as described in the agreement. ThinkingRoot certifies that it understands and will comply with these restrictions.
13. General
The liability limits in the Terms of Service apply to this Addendum. This Addendum takes effect on the earlier of the Customer's acceptance of the Terms of Service or first use of the service, and remains in force for as long as ThinkingRoot processes Customer Personal Data. Every version is numbered and retained; material changes are notified at least 30 days in advance.
Current sub-processors are listed in full at /subprocessors (10 entries). Questions about this Addendum: [email protected].
We keep every previous version of this document. If you need the text that was in force on a particular date, write to [email protected] and we will send it.