Legal · Effective 2026-07-20

Data processing addendum

This Data Processing Addendum (DPA) forms part of the Terms of Service between tgme ("Processor") and the Customer identified in the tgme account ("Controller"). It applies to the extent Processor processes Personal Data on behalf of Controller under applicable data-protection law, including the EU GDPR, UK GDPR, Malaysia PDPA, and Singapore PDPA.

1. Roles and scope

Controller determines the purposes and means of processing Personal Data of its subscribers, team members, and end-users. Processor processes such Personal Data solely on Controller's documented instructions, unless required otherwise by applicable law.

This DPA does not apply to Personal Data of Controller's own personnel that Controller submits to Processor for account management or billing purposes — that data is governed by our Privacy Policy.

2. Subject matter, duration, and nature

Subject matter: Processor's operation of the tgme Service on Controller's behalf. Duration: for as long as Controller maintains an active account, plus the retention window in the Privacy Policy. Nature: automated broadcasting, message routing, bot execution, inbox aggregation, and analytics.

3. Categories of data and data subjects

Data subjects: Controller's Telegram subscribers, bot users, team members, and other end-users interacting with the Service.

Categories of Personal Data: Telegram user IDs, usernames, first names, message content, timestamps, delivery status, subscription preferences, tags, and any additional fields Controller chooses to store.

4. Processor obligations

Processor will: - Process Personal Data only on Controller's documented instructions - Ensure personnel processing Personal Data are bound by confidentiality - Implement technical and organisational measures appropriate to the risk (see Security below) - Assist Controller in responding to data-subject requests and regulator enquiries - Notify Controller of any Personal Data breach without undue delay (target: 72 hours) - Make available information necessary to demonstrate compliance

5. Sub-processors

Controller authorises Processor to engage sub-processors for the operation of the Service. Current sub-processors include cloud infrastructure providers (region-specific), payment processors (for billing only), and analytics providers.

A current list of sub-processors is available on request via the Telegram handle listed on tgme1.com. Processor will notify Controller before onboarding new sub-processors, giving Controller a reasonable opportunity to object.

6. Security measures

Processor implements security measures including: - TLS 1.2+ for all data in transit - AES-256 encryption at rest for sensitive fields (bot tokens, credentials) - Least-privilege access controls with audit logging - Regular vulnerability scanning - Encrypted backups with retention no longer than 90 days - Employee background checks and security awareness training

7. International transfers

Where Personal Data of EU, UK, or Swiss data subjects is transferred outside the European Economic Area, transfers rely on the European Commission's Standard Contractual Clauses (2021/914) or equivalent safeguards. Controller and Processor agree to use the SCCs applicable to their respective roles.

8. Data-subject requests

If Processor receives a data-subject request relating to Personal Data processed on Controller's behalf, Processor will promptly forward the request to Controller and, if requested, provide reasonable assistance to Controller in responding.

9. Audit

Controller may audit Processor's compliance with this DPA once per calendar year (or more often after a Personal Data breach), on 30 days' written notice, during normal business hours, and at Controller's expense. Where a third-party report (e.g., SOC 2, ISO 27001) is available, Processor may elect to make that report available in lieu of on-site audit.

10. Return or deletion at termination

On termination of the underlying agreement, Processor will, at Controller's choice, return or delete Personal Data within 60 days, except where retention is required by applicable law. Encrypted backups may persist for up to 90 days thereafter before being overwritten.

11. Liability

Each party's liability under this DPA is subject to the limitation-of-liability provisions in the underlying Terms of Service, except to the extent applicable law prohibits such limitation for data-protection breaches.

12. Governing law

This DPA is governed by the same law as the underlying Terms of Service, without prejudice to the mandatory application of data-protection law of the data subject's residence.

Not legal advice. This document is provided as a professionally-drafted starting point. tgme’s operator should have qualified legal counsel review before relying on it for any specific jurisdiction.