Legal
Data Processing Agreement.
Version 1.0 · 2026-07-25
This DPA governs our processing of personal data on your behalf when you use the hosted Tavsin workspace. It is written to satisfy Article 28 of the GDPR and is offered as part of Team and Enterprise plans.
Need this signed? Email enterprise@tavsin.xyz with your entity name and we'll return a countersigned copy. We can also review your own DPA paper.
Note on scope. This document reflects how the product actually works and is provided in good faith, but it is not legal advice, and it has not yet been reviewed by external counsel. For a binding agreement, have your legal team review it — we expect and welcome redlines.
1. Parties & roles
"Customer" is the entity that agreed to the Tavsin Terms of Service. "Tavsin" is the provider of the Services. For personal data contained in Customer content, the Customer acts as the controller and Tavsin acts as the processor. For account and billing data that Tavsin needs to run its business, Tavsin acts as a controller and its Privacy Policy applies.
2. Scope & the local-first default
Tavsin's desktop app and CLI store project data on the Customer's own machines. In that mode Tavsin does not receive, host, or process that data at all, and this DPA has nothing to operate on. This DPA is therefore concerned with the hosted workspace and with account data.
3. Processing instructions
Tavsin processes personal data only on the Customer's documented instructions, which comprise this DPA, the Terms, and the Customer's use of the Services. Tavsin will inform the Customer if, in its opinion, an instruction infringes applicable data protection law. Tavsin does not sell personal data, and does not use Customer content to train models.
4. Confidentiality
Personnel authorised to process personal data are bound by confidentiality obligations and are granted access only to the extent required to perform their duties.
5. Security measures
Tavsin implements the technical and organisational measures set out in Annex II, taking into account the state of the art, cost of implementation, and the risks to data subjects.
6. Sub-processors
The Customer grants general authorisation for the sub-processors listed in Annex III. Tavsin will give notice before adding or replacing a sub-processor; the Customer may object on reasonable data-protection grounds, and if the parties cannot resolve the objection the Customer may terminate the affected Services. Tavsin remains liable for its sub-processors' performance.
7. Assistance to the Customer
- Data subject rights. The Services provide self-service export and deletion. Where those are insufficient, Tavsin will assist with access, rectification, erasure, restriction, portability, and objection requests.
- DPIAs and prior consultation. Tavsin will provide information reasonably necessary for the Customer's impact assessments.
- Security incidents. See section 8.
8. Personal data breach notification
Tavsin will notify the Customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Customer personal data. The notification will describe the nature of the breach, the categories and approximate volume of data and data subjects affected so far as known, the likely consequences, and the measures taken or proposed. Tavsin will provide further information as the investigation progresses.
9. Deletion & return
On termination, or on request, Tavsin will delete or return Customer personal data. Customers can export their data at any time from the account settings, and can trigger account deletion themselves. Residual copies in encrypted backups are deleted on the ordinary backup-rotation cycle (no longer than 35 days), during which they remain protected by the measures in Annex II.
10. Audits
Tavsin will make available the information necessary to demonstrate compliance with Article 28 and will contribute to audits, including inspections, conducted by the Customer or an auditor it mandates. In practice this means responding to security questionnaires and, for Enterprise customers, a security review call. Where a compliance report exists in future, Tavsin may satisfy an audit request by providing it. Audits are limited to once per twelve months absent a security incident or regulator requirement.
11. International transfers
Hosted workspace data is stored in Germany (EU). Where a sub-processor causes a transfer outside the EEA, that transfer relies on an adequacy decision or on the European Commission's Standard Contractual Clauses, together with supplementary measures where required. Tavsin will execute the SCCs with the Customer where applicable.
12. Order of precedence
In the event of a conflict, this DPA prevails over the Terms of Service with respect to the processing of personal data.
Annex I — Details of processing
| Subject matter | Provision of the Tavsin hosted workspace: an AI-assisted software engineering environment. |
|---|---|
| Duration | The term of the Customer's subscription, plus the deletion windows in section 9. |
| Nature & purpose | Hosting, storage, retrieval, transmission to the Customer's chosen model provider, and deletion — in order to operate the Services. |
| Types of personal data | Account identifiers (name, email), authentication material (hashed), IP addresses and audit events, subscription state, and any personal data the Customer chooses to place in project content (source code, prompts, files, memories). |
| Categories of data subjects | The Customer's personnel and authorised users; any individuals referenced within Customer content. |
| Special categories | Not requested and not required. The Customer should not place special-category data in project content. |
Annex II — Technical & organisational measures
- Encryption in transit: TLS for all traffic, with HSTS enforced.
- Secrets at rest: provider API keys, connector tokens, and licence keys are encrypted using the operating system keystore on the desktop; secrets are never written to model-call audit records.
- Access control: scrypt password hashing with constant-time verification and enumeration resistance; opaque, revocable server-side sessions with
HttpOnly/Secure/SameSitecookies; CSRF-protected OAuth; rate limiting on authentication endpoints. - Tenant isolation: each account's project data is held in a separate database rather than a shared multi-tenant table.
- Application hardening: Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy; fail-closed SSRF protection on server-side outbound requests; redaction of server errors.
- Agent containment: deterministic tool-execution policy refusing catastrophic and credential-accessing commands, an OS-level sandbox for agent shell commands (macOS), a project-directory filesystem boundary resistant to symlink and hard-link escape, and an optional network-egress allowlist. See Security for the honest scope of each.
- Auditability: append-only traces of meaningful actions; authentication and account events logged with timestamp and IP.
- Backups: encrypted, versioned snapshots with defined rotation.
- Data minimisation: no telemetry or analytics in the desktop app and CLI; no use of Customer content for model training.
- Payments: handled by Stripe; Tavsin does not receive or store card numbers.
Annex III — Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Hosting of the workspace and its databases | Germany (EU) |
| Vercel Inc. | Static marketing-site delivery (no customer data) | Global edge |
| Stripe, Inc. | Payments and subscription management | Global |
| Resend (Plus Five Five, Inc.) | Transactional email (verification, password reset, invitations) | Global |
AI model providers
When a user runs chat or an agent, prompt content is sent to the model provider configured for that workspace — which may be Anthropic, OpenAI, Google, OpenRouter, or an endpoint the Customer operates. The Customer chooses this provider, and it acts as a sub-processor for that content. Enterprise customers can supply their own endpoint so that prompt content never reaches a third-party provider. The current list is maintained in the Privacy Policy.
Contact
Data protection enquiries: privacy@tavsin.xyz. Enterprise agreements: enterprise@tavsin.xyz.