Tolloz Data Processing Agreement
Last updated: 23 August 2026
This Data Processing Agreement ("DPA") forms part of the agreement between:
TOLLOZ UK LIMITED, company number 17112837, whose registered office is 189 Belmont Road, Erith, DA8 1LE, United Kingdom ("Tolloz" or "Processor"),
and
the organisation subscribing to or using the Tolloz Services ("Customer" or "Controller").
1. Purpose
This DPA applies where Tolloz processes Personal Data on behalf of the Customer in connection with the Tolloz Services.
It is intended to satisfy applicable requirements concerning controller–processor relationships, including Article 28 of the UK GDPR where applicable.
2. Definitions
Applicable Data Protection Law means data-protection legislation applicable to processing under this DPA, including where applicable the UK GDPR and Data Protection Act 2018.
Customer Personal Data means Personal Data processed by Tolloz on behalf of the Customer.
Data Subject, Personal Data, Processing, Controller and Processor have the meanings given under Applicable Data Protection Law.
Subprocessor means another Processor appointed by Tolloz to process Customer Personal Data.
3. Roles
The Customer is the Controller of Customer Personal Data.
Tolloz acts as Processor where it processes Customer Personal Data on behalf of the Customer.
The Customer determines:
what customer information it collects;
why it collects it;
how long it requires it;
what communications are sent;
what lawful basis applies; and
what instructions are provided to Tolloz.
4. Customer Instructions
Tolloz will process Customer Personal Data only:
on documented instructions from the Customer;
as necessary to provide the Services;
as set out in the Customer's configuration and use of Tolloz; or
where required by applicable law.
Use of the Services in accordance with the Terms constitutes documented instructions.
Additional instructions may be provided in writing.
If Tolloz reasonably believes an instruction infringes applicable data-protection law, we may notify the Customer and suspend the affected processing while the matter is resolved.
5. Confidentiality
Tolloz will ensure that persons authorised to process Customer Personal Data:
are subject to appropriate confidentiality obligations; and
only access the information where necessary for their responsibilities.
6. Security
Tolloz will maintain appropriate technical and organisational measures proportionate to the risks associated with Customer Personal Data.
These measures may include:
encrypted connections;
encryption at rest through cloud infrastructure;
authentication;
tenant isolation;
database-level access controls;
role-based access;
restricted administrative privileges;
secrets management;
backup systems;
monitoring;
logging;
vulnerability management;
incident-response procedures; and
confidentiality controls.
Further measures are described in Schedule 2.
7. Subprocessors
The Customer provides Tolloz with general authorisation to engage Subprocessors required to provide the Services.
Potential providers include infrastructure and communications providers such as:
Supabase;
Vercel;
Resend;
Brevo;
Twilio; and
payment providers where they process Customer Personal Data on behalf of Tolloz.
PostHog, Sentry or other providers may be added if relevant functionality is introduced.
Where a payment provider acts independently rather than on Tolloz's instructions, it may act as an independent Controller rather than a Subprocessor.
8. Changes to Subprocessors
Tolloz should maintain an up-to-date Subprocessor list.
Where practicable, Tolloz will provide advance notice of a material new Subprocessor that will process Customer Personal Data.
The Customer may object on reasonable data-protection grounds.
The parties will attempt in good faith to resolve any objection.
Where no reasonable solution is available, the Customer may terminate the affected Service without penalty for the unused portion of that affected Service, notwithstanding the general no-refund provisions of the Terms where required to provide a meaningful remedy under this clause.
9. Subprocessor Obligations
Tolloz will impose data-protection obligations on Subprocessors appropriate to their processing.
Tolloz remains responsible for its Subprocessors to the extent required by Applicable Data Protection Law.
10. Data Subject Requests
Taking into account the nature of the processing, Tolloz will provide reasonable assistance to enable the Customer to respond to Data Subject requests.
These may include requests concerning:
access;
correction;
deletion;
restriction;
objection;
portability; and
other applicable rights.
If Tolloz receives a request directly relating to Customer Personal Data, we will normally direct the individual to the Customer unless law requires otherwise.
11. Data Protection Assistance
Taking into account the nature of the processing and information available to Tolloz, we will provide reasonable assistance relating to applicable obligations concerning:
security;
Personal Data breaches;
data-protection impact assessments;
regulatory consultations; and
Data Subject rights.
12. Personal Data Breaches
Tolloz will notify the Customer without undue delay after becoming aware of a Personal Data breach affecting Customer Personal Data.
Where available, the notification will provide relevant information concerning
the nature of the incident;
affected information;
affected Data Subjects;
likely consequences;
measures taken or proposed; and
a contact for further information.
Information may be supplied in stages where all details are not immediately available.
Notification does not constitute an admission of fault or liability.
13. International Transfers
Tolloz may use Subprocessors located outside the United Kingdom.
Where a restricted transfer occurs, Tolloz will use an appropriate transfer mechanism where required.
Depending on the transfer, this may include:
adequacy regulations;
the UK International Data Transfer Agreement;
the UK Addendum to EU Standard Contractual Clauses; or
another lawful safeguard.
Where required, Tolloz will conduct or rely upon an appropriate transfer-risk assessment/data-protection test.
14. Return and Deletion
During an active subscription, the Customer may access its Customer Personal Data through functionality made available by Tolloz.
Following termination:
First 30 days
Tolloz may retain Customer Personal Data in the active environment for up to 30 days to permit recovery or export.
The Customer should contact support@tolloz.com during this period if assistance is required.
After 30 days
Tolloz will normally delete or anonymise Customer Personal Data from production systems unless retention is required by law.
Backups
Residual copies may remain in encrypted backups for up to a further 90 days before being automatically overwritten or deleted.
Backup data will not normally be restored except for legitimate disaster-recovery or security purposes.
15. Audit Information
Tolloz will make available information reasonably necessary to demonstrate compliance with applicable Processor obligations.
Where reasonable documentation is insufficient, the Customer may request an audit.
Unless required by a regulator or following a material Personal Data breach:
audits should normally occur no more than once in a 12-month period;
reasonable advance notice must be provided;
audits must not compromise other customers' confidentiality or security;
the parties should first use existing security documentation where possible; and
the Customer normally bears its audit costs unless material non-compliance by Tolloz is identified.
16. Customer Responsibilities
The Customer warrants that:
its instructions comply with applicable law;
it has an appropriate lawful basis for Customer Personal Data;
it provides required privacy information;
Customer Personal Data is collected lawfully;
required marketing consent has been obtained;
it will not instruct Tolloz to process Personal Data unlawfully; and
it maintains appropriate controls over its authorised users.
17. Liability
Liability relating to this DPA is subject to the liability provisions of the main Tolloz Terms unless Applicable Data Protection Law requires otherwise.
18. Precedence
If there is a conflict between this DPA and the general Terms regarding the processing of Customer Personal Data, this DPA will take precedence for that issue.
19. Duration
This DPA remains effective for as long as Tolloz processes Customer Personal Data on behalf of the Customer.
Still Have Questions?
We're building Tolloz to make running a bakery simpler, not more complicated.
Whether you have questions about moving from your current system, payments, multiple locations or how Tolloz could work for your bakery, we're happy to help.
Contact: support@tolloz.com