1. Parties and scope
These terms apply between the customer that controls a ToolRoster workspace (“Customer”) and Eastbase Studio, the operator of ToolRoster (“Processor”), when ToolRoster processes personal data in workspace content for Customer.
Customer is the controller or authorized processor of that data. Eastbase Studio remains an independent controller for account, billing, security, support, and product-operation data as described in the Privacy Policy.
2. Processing details and documented instructions
The subject matter is providing the ToolRoster service. Processing continues for the subscription or account term and any limited retention period. It may include collection, recording, organization, hosting, retrieval, display, transmission, export, backup, troubleshooting, anonymization, and deletion.
Data subjects may include Customer’s workspace members, employees, contractors, vendor contacts, and customer contacts. Data may include names, business contact details, roles, approval and acknowledgment records, identifiers, and any personal data Customer chooses to include in workspace content.
Customer instructs ToolRoster to process this data only to provide, secure, maintain, and support the service; comply with Customer’s use and configuration; handle documented support requests; and comply with applicable law. If we believe an instruction violates applicable data-protection law, we will inform Customer unless legally prohibited.
3. Customer obligations
Customer is responsible for lawful instructions; the accuracy and minimization of workspace data; required rights, notices, authority, and legal bases; account and admin security; and responding to data subjects and regulators. Customer must not use ToolRoster to process data prohibited by the Terms, including secrets or unnecessary sensitive and regulated data in free-text fields.
4. Confidentiality
We limit access to personnel and contractors who need it to operate or support the service and who are bound by confidentiality obligations. Those obligations continue after their access ends.
5. Security measures
We maintain measures appropriate to ToolRoster’s nature and risk, including transport encryption; password hashing; signed sessions; server-side authentication, authorization, and workspace scoping; least-privilege provider access; rate limiting and abuse protection; append-only audit and policy records; backups; dependency and deployment controls; and minimized, scrubbed diagnostics.
ToolRoster does not claim that these measures make every use compliant or eliminate all risk. Customer remains responsible for its own endpoint, identity, vendor, and organizational controls.
6. Subprocessors and other providers
Customer authorizes the providers below for the purposes shown. We require subprocessors that process workspace data on our behalf to protect it under contractual obligations appropriate to their role. Lemon Squeezy and OAuth providers may act as independent controllers for payment or authentication data under their own terms.
| Provider | Purpose | Data processed | Required / optional | Region note |
|---|---|---|---|---|
| Vercel | Application hosting, content delivery, deployment, and optional web analytics and performance measurement | HTTP request metadata, IP address, app responses, and optional usage/performance metrics | Required for hosting; analytics optional | Global edge network; provider is US-based |
| Neon | Managed PostgreSQL database hosting | Account, workspace, registry, request, policy, acknowledgment, audit, and subscription-reference data | Required | Configured database project: AWS US East |
| Resend | Transactional email delivery | Recipient address and the content and delivery metadata of each email | Required when transactional email is enabled | Provider is US-based |
| Lemon Squeezy | Hosted checkout, subscriptions, tax handling, and refunds as merchant of record | Billing identity, transaction, subscription, tax, and payment-related data | Required for paid plans | International processing under Lemon Squeezy's buyer terms |
| PostHog | Optional product analytics | Consent-gated page paths without query strings, device metadata, and opaque user identifiers | Optional; disabled until analytics consent | US cloud |
| Sentry | Error monitoring and performance diagnostics | Scrubbed error, stack-trace, route, device, and runtime diagnostics | Optional operational provider | Provider is US-based; processing may occur internationally |
| Upstash | Distributed rate limiting and abuse prevention | Hashed rate-limit identifiers, counters, and expiry times | Optional but recommended in production | Global service; selected database region applies |
| Cloudflare Turnstile | Bot verification on sign-up and password-reset requests | Challenge token, request hostname, IP address, and browser/device signals | Optional but recommended in production | Cloudflare global network |
| Google OAuth | Optional Google account sign-in | OAuth identifier, name, email, profile image, and authentication tokens | Optional; only when enabled and chosen | Google's global infrastructure |
| GitHub OAuth | Optional GitHub account sign-in | OAuth identifier, name, email, profile image, and authentication tokens | Optional; only when enabled and chosen | GitHub's global infrastructure |
We may replace or add a provider as the service changes. Material changes will be reflected in these terms or the Privacy Policy and, where required, notified before the new provider begins processing. Customers with a legally required objection may contact support@eastbase.studio.
7. International transfers
ToolRoster is operated from Vietnam, and providers may process data in other countries, including the United States. Where applicable law requires a transfer mechanism, we will use appropriate contractual or other lawful safeguards and provide available documentation on request.
8. Data-subject requests
Taking into account the nature of the processing, we will provide reasonable assistance for Customer to respond to requests to access, correct, export, delete, restrict, or object to processing. If a request is sent directly to us about Customer-controlled workspace data, we will direct it to Customer unless law requires us to respond.
9. Security incidents and compliance assistance
We will notify Customer without undue delay after becoming aware of a confirmed personal-data breach affecting Customer workspace data and provide information reasonably available to help Customer meet applicable notification duties. Notification is not an admission of fault or liability.
We will provide reasonable documentation and assistance relating to the security of processing, data-protection impact assessments, and regulator consultations, taking into account the information available to us and the nature of ToolRoster.
10. Return, deletion, and record integrity
Customer can export registry and evidence data through the service. After a verified deletion request or termination, we target deletion or anonymization from active systems within 30 days. Backups and security, delivery, and diagnostic logs may persist for approximately 90 days, and billing, tax, fraud, accounting, or dispute records may be retained longer where required.
Where append-only audit events, policy versions, or acknowledgments must remain for integrity, ToolRoster may retain the event while deleting, anonymizing, or tombstoning the former actor’s identifying account information. We do not promise removal from third-party copies of intentionally public pages.
11. Documentation-first audit support
On reasonable written request, we will first provide available policies, architecture and security documentation, provider information, test results, and questionnaire responses needed to demonstrate compliance with these terms. Additional inspection will be considered only where documentation is insufficient and applicable law requires it, subject to confidentiality, security, reasonable scope, and avoidance of disruption or exposure of other customers’ data.
12. Priority, liability, and contact
If these Data Processing Terms conflict with the Terms of Service on processing Customer workspace personal data, these Data Processing Terms control for that conflict. The liability provisions in the Terms of Service apply to these Data Processing Terms to the maximum extent permitted by law.
Questions, assistance requests, or deletion instructions should be sent to support@eastbase.studio.