Skip to content

Data processing agreement

Terms governing Turbyn's processing of personal data on behalf of its customers.

Effective date: 25 September 2026

Last updated: 24 September 2026

1. Scope and definitions

This Data Processing Agreement (“DPA”) forms part of the Terms of Service or other service agreement between Turbyn and the customer (“Agreement”). It applies when Turbyn processes personal data on the customer’s behalf to provide the Service.

“Customer Personal Data” means personal data submitted to, stored in or otherwise processed by the Service on the customer’s behalf. “Data Protection Laws” means privacy and data-protection laws applicable to that processing. “Controller”, “processor”, “personal data” and “processing” have the meanings given in those laws.

The customer acts as controller and Turbyn as processor. Where the customer acts as a processor for another organization, Turbyn acts as its subprocessor and the customer confirms it has authority to engage Turbyn. Information Turbyn processes for its own account administration, billing and website purposes is described in the privacy policy.

2. Customer instructions and responsibilities

Turbyn will process Customer Personal Data only on documented customer instructions, including the Agreement, configured actions and written instructions concerning the Service, unless applicable law requires otherwise. Where legally permitted, Turbyn will inform the customer of that legal requirement before processing.

Turbyn will inform the customer if it considers an instruction to infringe Data Protection Laws or is unable to comply with an instruction. The parties will cooperate to resolve the issue, and Turbyn may suspend the affected processing while doing so.

The customer is responsible for the lawfulness of its collection, disclosure and instructions, including required notices, permissions and any lawful basis. The customer controls the data submitted, workflow configuration, authorized users and third-party destinations.

3. Confidentiality and security

Turbyn will ensure that people authorized to process Customer Personal Data are subject to appropriate confidentiality obligations and access it only as required for their responsibilities.

Turbyn will maintain technical and organizational measures appropriate to the nature of the processing and the risks to individuals. The measures in Schedule 2 form part of this DPA. Turbyn may update those measures provided it does not materially reduce the overall protection of Customer Personal Data.

The customer is responsible for securing its account, limiting permissions and credentials, and configuring its actions appropriately. These responsibilities do not reduce Turbyn’s obligations under this DPA.

4. Subprocessors

The customer gives general authorization for Turbyn to use the relevant providers listed on the subprocessors page to process Customer Personal Data. Authorization applies only to providers acting as subprocessors for the Service, not to separate processing for Turbyn’s own website or business purposes.

Before engaging a subprocessor, Turbyn will enter into a written agreement imposing data-protection obligations appropriate to the processing and no less protective than the applicable obligations in this DPA. Turbyn remains responsible for the subprocessor’s performance of those obligations.

Turbyn will notify the customer’s account contact at least 30 days before a new or replacement subprocessor begins processing Customer Personal Data. The notice will identify the provider, processing purpose and relevant locations. The customer may object during that period on reasonable data-protection grounds by contacting hello@useturbyn.com.

The parties will work in good faith to address an objection before the affected processing begins. If no reasonable solution is available, the customer may terminate the affected Service before the change takes effect and receive a proportional refund of prepaid fees for the unused subscription period.

5. International transfers

Turbyn may process Customer Personal Data in countries where it and its subprocessors operate, subject to Data Protection Laws and any location restrictions expressly agreed in writing.

Where a transfer requires additional safeguards, the parties will put the applicable transfer mechanism in place before the transfer. This may include the European Commission’s Standard Contractual Clauses and, for UK transfers, an applicable UK transfer addendum or agreement. Required party details, processing descriptions and security annexes will form part of those transfer terms.

Any mandatory transfer terms take precedence over conflicting provisions of this DPA or the Agreement. Contact hello@useturbyn.com to arrange the transfer terms applicable to your use of the Service.

6. Individual requests and assistance

Turbyn will promptly notify the customer of a request concerning Customer Personal Data received directly from an individual, unless prohibited by law. Turbyn will not respond on the customer’s behalf without authorization, except to direct the individual to the customer or as required by law.

Taking account of the nature of the processing and information available to it, Turbyn will assist the customer with requests to exercise individual rights, security obligations, data-protection impact assessments and required consultations with supervisory authorities.

Turbyn will inform the customer of legally binding requests for disclosure of Customer Personal Data where permitted by law and limit disclosure to what is legally required.

7. Personal data breaches

Turbyn will notify the customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. Turbyn will take reasonable steps to contain, investigate and mitigate the breach.

The notice will include available information about the nature of the breach, affected data and individuals, likely consequences, remedial measures and a contact for further information. Information may be provided in stages as it becomes available.

The customer is responsible for notifications to individuals and authorities required of it by law. Turbyn will provide reasonable assistance. A notification is not an admission of fault or liability.

8. Return and deletion

On termination of the Service, Turbyn will, at the customer’s choice, return or delete Customer Personal Data and delete remaining copies, unless applicable law requires retention. The customer may communicate its choice through hello@useturbyn.com. Turbyn will carry out those instructions without undue delay.

Where data remains in backups pending secure deletion, it will be isolated from ordinary use and remain subject to this DPA. Data retained to comply with law will be protected and used only for that purpose. Turbyn will confirm completion of deletion on request.

This DPA continues to apply for as long as Turbyn or its subprocessors retain Customer Personal Data.

9. Compliance information and audits

Turbyn will provide information reasonably necessary to demonstrate compliance with this DPA and allow and contribute to audits, including inspections, by the customer or an independent auditor acting on its behalf.

The parties will coordinate the scope, timing and confidentiality safeguards of an audit to avoid unnecessary disruption and protect other customers’ data. Reasonable advance notice is required unless an urgent incident, regulator or applicable law requires otherwise. These arrangements do not restrict mandatory audit or regulatory rights.

10. US service-provider terms

Where applicable US privacy law treats Turbyn as a service provider or contractor, Turbyn will process Customer Personal Data only for the specified business purposes of providing the Service and as otherwise permitted by that law.

Turbyn will not sell Customer Personal Data, share it for cross-context behavioral advertising, retain, use or disclose it outside the direct business relationship or specified purposes, or combine it with personal information from other sources except as permitted by applicable law.

Turbyn will provide the level of privacy protection required by applicable law and notify the customer if it determines it can no longer meet those obligations. The customer may take reasonable and appropriate steps to verify compliant use and to stop and remedy unauthorized processing. Turbyn certifies that it understands and will comply with the restrictions in this section.

11. Liability and precedence

The Agreement’s liability provisions apply to this DPA to the extent permitted by Data Protection Laws. Nothing in this DPA limits an individual’s rights or liability that cannot lawfully be limited.

This DPA prevails over conflicting terms of the Agreement concerning Customer Personal Data. Applicable mandatory transfer terms prevail over both. A separately executed data processing agreement controls to the extent it expressly replaces this DPA.

Schedule 1. Processing details

Item Description
Subject matter Provision of Turbyn’s custom workflow action service.
Nature and purpose Receiving, storing, organizing, retrieving, building, testing and executing customer-defined actions; transmitting results; maintaining operational records; providing support; and deleting data.
Data subjects Customer personnel and the contacts, leads, customers or other individuals whose information the customer includes in its workflows.
Personal data Identifiers, contact and business details, workflow inputs and outputs, stored values, and personal information included in code, configuration, logs and error messages.
Sensitive data Special-category and other restricted data may not be submitted unless expressly authorized in a separate written agreement.
Frequency Ongoing, as the customer uses the Service and instructs processing.
Duration The term of the Service and the period necessary to return or delete data in accordance with this DPA.

Schedule 2. Technical and organizational measures

  • Access control: authenticated accounts, workspace membership and role-based authorization.
  • Credential protection: encrypted storage of vault values and connection credentials, made available to authorized operations.
  • Execution isolation: isolated environments for building and running customer code.
  • Storage access: access-controlled storage of source code, build artifacts and service records.
  • Operational security: service monitoring, diagnostic records and controls on execution admission and usage.
  • Confidentiality and handling: access limited to authorized personnel and providers, with confidentiality and processing obligations as described above.

Customer code can expose data through logs, outputs and outbound requests. Customers should limit submitted data, use appropriately scoped credentials and avoid logging secrets. Further information is available on our security page.

For questions about this DPA, contact hello@useturbyn.com.


Adapted from the Common Paper Data Processing Agreement, version 1.1, available under CC BY 4.0. Modified for Turbyn; this is not the unmodified Common Paper standard agreement.

Questions about this document?

Use our contact page to reach the team. Please avoid including sensitive data in your initial message.

Contact us →