Skip to main content
Tayvo
  • Features
  • Pricing
  • About
Request beta access
  • Home
  • Features
  • Pricing
  • About
Request beta accessjustin@tayvo.app

Data processing agreement

Effective date: 7 October 2026

This Data Processing Agreement ("DPA") is part of the Tayvo Terms of Service between Cobalt Software LLC, an Arizona limited liability company ("Tayvo", "we", "processor"), and the studio or agency that uses Tayvo ("you", "controller"). It applies whenever we process personal data on your behalf through Tayvo. By accepting the Terms of Service, you accept this DPA. If this DPA and the Terms conflict on data protection, this DPA wins.

On this page

  1. Definitions
  2. Scope and roles
  3. Processing only on your instructions
  4. Confidentiality
  5. Security
  6. Subprocessors
  7. Helping with data subject requests
  8. Security incidents
  9. Other help
  10. Return and deletion
  11. Audits
  12. International transfers
  13. Liability
  14. Term
  15. Law
  16. Contact
  17. Annex 1. Details of the processing
  18. Annex 2. Security measures
  19. Annex 3. Subprocessors

1. Definitions

  • "Personal data": any information about an identified or identifiable person that you or your users put into Tayvo, or that Tayvo collects for you while you use it.
  • "Processing": any operation on personal data, such as storing, viewing, sending or deleting.
  • "Data protection law": the laws that apply to the processing, which can include US state privacy laws (such as the California Consumer Privacy Act), the EU and UK General Data Protection Regulation and similar laws.
  • "Subprocessor": a third party we engage to process personal data for Tayvo.
  • "Security incident": a confirmed breach of security that leads to the accidental or unlawful destruction, loss, change, disclosure of, or access to personal data we process for you.
  • "Data subject": the person the personal data is about, such as your team members and your clients.

2. Scope and roles

  • You are the controller of the personal data you and your users put into Tayvo. We are your processor (a "service provider" under California law).
  • Annex 1 describes the processing. This DPA does not cover data we control ourselves, such as our own website and beta request emails; our Privacy Policy covers that.
  • You are responsible for having a lawful basis to collect the personal data, for the notices you give your clients, and for the instructions you give us.

3. Processing only on your instructions

  • We process personal data only to provide Tayvo under the Terms, on your documented instructions. The Terms, this DPA and the settings you choose in Tayvo are your instructions.
  • We do not sell personal data, share it for cross-context advertising, use it to train AI models, or use it for our own purposes outside providing, securing and supporting Tayvo.
  • If we believe an instruction breaks data protection law, we will tell you.
  • If the law requires us to process personal data in another way, we will tell you first unless the law forbids it.

4. Confidentiality

Everyone at Tayvo who can access personal data is bound by confidentiality and accesses data only as needed to run, secure and support Tayvo.

5. Security

We keep the technical and organizational measures in Annex 2 in place for as long as we process personal data for you. We may improve them over time, but we will not lower the overall level of protection.

6. Subprocessors

  • You authorize the subprocessors listed in Annex 3.
  • Each subprocessor is bound by a written agreement with data protection terms no less protective than this DPA, and we remain responsible for its work.
  • We will email you at least 30 days before adding or replacing a subprocessor. You can object on reasonable data protection grounds within that period. If we cannot resolve the objection, you may close your account before the change applies and receive the export described in section 10.

7. Helping with data subject requests

  • If a data subject contacts us about personal data we process for you, we will send the request to you and not answer it ourselves unless you ask us to.
  • We will help you answer requests to access, correct, delete, export or restrict personal data, using Tayvo's features or, where they are not enough, by hand.

8. Security incidents

  • We will notify you without undue delay, and within 72 hours, after we confirm a security incident affecting your personal data.
  • The notice will say what happened, the data and people affected as far as we know, what we are doing about it and who to contact. We will add details as we learn them.
  • We will take reasonable steps to contain the incident and help you meet any duty you have to notify authorities or the people affected.

9. Other help

We will give you reasonable information to help you with data protection impact assessments and consultations with authorities, as far as they relate to Tayvo.

10. Return and deletion

  • You can request an export of your workspace data at any time, including when your account ends. During the beta we prepare exports by hand and send them within 30 days of your request.
  • We delete your workspace data 90 days after your account ends, except records the law requires us to keep.
  • Deleted data can remain in database history for up to 30 days, then is gone.

11. Audits

  • Once a year, on your written request, we will answer a reasonable written security and data protection questionnaire about Tayvo.
  • If a data protection authority requires more, we will cooperate with reasonable requests at your cost, with notice and during business hours.

12. International transfers

  • We process personal data in the United States. Our subprocessors may process it in the United States and other countries.
  • Where data protection law requires a transfer mechanism for personal data from the EU, the EEA, the UK or Switzerland, the Standard Contractual Clauses (and the UK Addendum where relevant) apply, and we will sign them on request.

13. Liability

Each party's liability under this DPA is subject to the limits in the Terms of Service.

14. Term

This DPA lasts as long as we process personal data for you and ends when we have deleted it under section 10.

15. Law

Arizona law governs this DPA, and the courts in Maricopa County, Arizona have jurisdiction, unless data protection law or the Standard Contractual Clauses require otherwise.

16. Contact

Cobalt Software LLC
Chandler, Arizona
justin@tayvo.app

Annex 1. Details of the processing

  • Subject matter: providing Tayvo, the client portal and studio workspace, to you.
  • Duration: for as long as you use Tayvo, plus the deletion periods in section 10.
  • Nature: hosting, storing, organizing, displaying, sending and deleting data, and processing card payments through your own Stripe account.
  • Purpose: to let you run client work in Tayvo: proposals, projects, tasks, files, messages, time, invoices, payments and the client portal.
  • Data subjects: your team members, and your clients and their contacts.
  • Categories of personal data: names, email addresses and company details; sign-in records; project content, tasks and updates; files; messages; proposals and acceptance details (typed name and consent); time entries; invoices and payment status (amounts, tips, Stripe references; no full card numbers); and, only if you connect a mailbox with inbox access, the email in that mailbox that Tayvo reads to show and reply to it in the studio.
  • Special categories: none expected. Do not upload health records, government ID numbers or other special category data to Tayvo.

Annex 2. Security measures

  • All traffic over HTTPS.
  • Sign-in by emailed link that expires after 15 minutes and works once, or a 6-digit code from the same email. No passwords to steal.
  • Session cookies set HttpOnly, Secure and SameSite=Lax, so page scripts cannot read them and they travel only over HTTPS.
  • Session tokens stored as hashes, not in readable form.
  • Connected mailbox authorizations stored encrypted.
  • Inbox access only when a studio picks "Connect with inbox access", and replies drafted there need a person to review them before sending.
  • Each agency's data kept separate from other agencies' data in the database and checked on every request.
  • Card details handled only by Stripe; Tayvo never receives full card numbers.
  • Hosting on Cloudflare's infrastructure, with error logging and automatic database history for up to 30 days.
  • Access to production systems limited to the people who run Tayvo.

Annex 3. Subprocessors

Annex 3. Subprocessors
SubprocessorWhat it does for TayvoData
Cloudflare, Inc.Hosting (Workers), database (D1), file storage (R2), sending email, logsAll workspace data
Stripe, Inc.Card payments through your own Stripe account (Stripe Connect)Payment amounts, status, client name and email for receipts
Google LLCGmail, only when a studio connects a Google mailbox; Google Workspace for the Tayvo support inboxMailbox data the studio connects; support emails you send us
Microsoft CorporationMicrosoft 365 mail, only when a studio connects a Microsoft mailboxMailbox data the studio connects
Web push services (Apple, Google, Mozilla)Delivering notifications a user turned onPush subscription and notification text
Tayvo

Tayvo is made by Cobalt Software LLC, Chandler, Arizona.

justin@tayvo.app

Product

  • Features
  • Pricing
  • Request beta access

Company

  • About
  • Contact
  • Privacy
  • Terms
  • DPA

© 2026 Cobalt Software LLC

Website byJT Studio
Request beta access