Data Processing Addendum
Terms under which Tutti processes personal data on behalf of customers under applicable data protection laws.
Effective September 27, 2026
1. Scope and parties
This Data Processing Addendum ("DPA") is between the customer that has accepted the Terms of Service ("Customer") and Mikayel Grigoryan, doing business as Tutti ("Tutti"). It forms part of the Terms and applies only to the extent Tutti processes Customer Personal Data subject to Data Protection Laws. It takes effect when the Customer accepts the Terms; no signature is required.
2. Definitions
- "Data Protection Laws" means all data protection and privacy laws applicable to the processing of Customer Personal Data under the Terms, which may include the EU GDPR, the UK GDPR, the Swiss Federal Act on Data Protection, and US state privacy laws.
- "Customer Personal Data" means personal data within Customer Data that Tutti processes on behalf of the Customer in providing the Service.
- "Sub-processor" means a third party engaged by Tutti to process Customer Personal Data.
- "SCCs" means the standard contractual clauses approved by European Commission Implementing Decision (EU) 2021/914.
- Other capitalized terms have the meanings given in the Terms or in Data Protection Laws.
3. Roles and instructions
The Customer is the controller (or a processor on behalf of its controllers) and Tutti is a processor (or sub-processor) of Customer Personal Data. Tutti is an independent controller of personal data it processes for its own business purposes, such as account management, billing, security, and legal compliance, as described in its Privacy Policy.
Tutti processes Customer Personal Data only on the Customer's documented instructions, which consist of the Terms, this DPA, and the Customer's use and configuration of the Service, unless otherwise required by law. Tutti will inform the Customer if, in its opinion, an instruction infringes Data Protection Laws, and may suspend the affected processing. Additional instructions require Tutti's written agreement.
The Customer is solely responsible for the accuracy, quality, and lawfulness of Customer Personal Data, for the means by which it was acquired, and for providing all notices and obtaining all consents and lawful bases required for its processing through the Service.
4. Confidentiality and security
Tutti ensures that persons authorized to process Customer Personal Data are bound by confidentiality. Tutti implements appropriate technical and organizational measures as described in Annex II, which it may update from time to time provided the updates do not materially reduce the overall level of protection. The Customer is responsible for its own secure use of the Service, including account credentials and access it grants to its users.
5. Sub-processors
The Customer grants general authorization for Tutti to engage Sub-processors, including those in the categories listed in Annex III. A current list is available on request to mikayel@tutti.work. Tutti will give notice of new Sub-processors by updating that list or by other reasonable means. The Customer may object on reasonable data protection grounds within 10 days of notice; if the parties cannot resolve the objection, the Customer's sole remedy is to terminate the Service. Tutti will impose data protection obligations on each Sub-processor that are substantially similar to those in this DPA.
6. Assistance
Taking into account the nature of the processing and the information available to it, Tutti will provide reasonable assistance to the Customer, primarily through the Service's self-service features, in responding to data subject requests, and with data protection impact assessments and consultations with supervisory authorities where required by Data Protection Laws. Tutti will forward to the Customer any data subject request it receives about Customer Personal Data and will not respond to it except as required by law. Tutti may charge a reasonable fee for assistance beyond what the Service provides.
7. Personal data breaches
Tutti will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and will provide information reasonably available to it to help the Customer meet its own obligations. Tutti's notification of or response to a breach is not an acknowledgement of fault or liability.
8. International transfers
Tutti and its Sub-processors may process Customer Personal Data in countries outside the Customer's jurisdiction. To the extent a transfer of Customer Personal Data from the EEA to a country without an adequacy decision is not covered by another valid transfer mechanism, the SCCs are incorporated by reference: Module Two where the Customer is a controller and Module Three where it is a processor. Clause 7 does not apply; Clause 9 option 2 applies with the notice period in this DPA; the optional wording in Clause 11 does not apply; for Clauses 17 and 18, the law and courts of Ireland apply; and Annexes I to III of this DPA complete the SCCs' annexes.
For transfers subject to the UK GDPR, the International Data Transfer Addendum issued by the UK Information Commissioner applies to the SCCs. For transfers subject to Swiss law, the SCCs apply with references to the GDPR read as references to the Swiss Federal Act on Data Protection. If this DPA conflicts with the SCCs, the SCCs prevail to the extent of the conflict.
9. Deletion
The Customer can delete Customer Personal Data through the Service at any time. After termination of the Service, Tutti will delete Customer Personal Data within a reasonable period, except to the extent retention is required or permitted by law, and except for copies in backups, which will be deleted in the normal course and protected in the meantime. The Customer is responsible for exporting any data it wishes to keep before termination.
10. Audits
Tutti will make available, on request, information reasonably necessary to demonstrate compliance with this DPA, such as written responses to reasonable security questionnaires. Where Data Protection Laws require more, the Customer may request an audit no more than once in any 12-month period, with at least 30 days' written notice, at the Customer's expense, conducted by an independent auditor bound by confidentiality, in a manner that does not disrupt Tutti's operations or give access to other customers' data. The parties will agree the scope and timing in advance.
11. US state privacy laws
To the extent US state privacy laws apply, Tutti acts as a service provider or processor and will not sell or share Customer Personal Data, retain, use, or disclose it outside the direct business relationship or for any purpose other than the business purposes specified in the Terms, or combine it with other personal data except as permitted by those laws.
12. Liability and precedence
Each party's aggregate liability arising out of or relating to this DPA, including the SCCs to the extent permitted by law, is subject to the exclusions and limitations of liability in the Terms. If this DPA conflicts with the Terms regarding the processing of Customer Personal Data, this DPA prevails. This DPA terminates automatically when Tutti no longer processes Customer Personal Data.
13. Annex I: Details of processing
- Data exporter: the Customer, as identified in its account. Data importer: Mikayel Grigoryan, doing business as Tutti, mikayel@tutti.work, acting as processor.
- Data subjects: the Customer's authorized users, and individuals whose personal data is contained in Customer Data, such as email correspondents and contacts.
- Categories of personal data: identification and contact details, email content and metadata, and any other personal data the Customer chooses to include in Customer Data.
- Sensitive data: none intended. Any sensitive data included by the Customer is at its sole responsibility and is protected by the measures in Annex II.
- Frequency: continuous, for the duration of the Service.
- Nature and purpose: providing the Service under the Terms, including hosting, storage, synchronization, organization, analysis, AI-assisted generation and classification, and transmission of data as directed by the Customer.
- Duration: for the term of the Terms, and afterwards until deletion in accordance with this DPA.
- Competent supervisory authority: as determined under Clause 13 of the SCCs.
14. Annex II: Security measures
- Encryption of data in transit and encryption of sensitive credentials at rest.
- Logical separation of each customer's data and role-based access controls.
- Authentication through established identity providers and secure session management.
- Access to production systems restricted to authorized personnel.
- Input validation, secure development practices, and dependency monitoring.
- Rate limiting and abuse prevention.
- Logging designed to exclude message content and secrets.
- Contractual or technical restrictions on AI providers against retaining customer content or using it for training.
15. Annex III: Sub-processor categories
- Cloud hosting, database, and infrastructure providers.
- Artificial intelligence routing and model providers.
- Email delivery and communications providers.
- Customer support and operational tooling providers.
The current list of Sub-processors, with their locations, is available on request to mikayel@tutti.work. Payment processors and resellers act as independent controllers, not Sub-processors. Third-party services the Customer connects, such as its email or identity provider, are engaged by the Customer under its own agreements and are not Sub-processors.
Related