Data Processing Agreement
Last updated: 7 July 2026
Effective for all active subscriptions from this date
Introduction
This Data Processing Agreement (“DPA”) applies where a business or organisation (“Controller”) uses Thinkspaces, operated by Kim Taylor (ABN 39 952 416 436) (“Processor”), and, in doing so, causes Thinkspaces to process personal data of the Controller’s employees, contractors, or end users (“Data Subjects”).
This DPA is incorporated into and forms part of the Thinkspaces Terms & Conditions and takes effect on the date the Controller accepts those Terms. It is intended to satisfy the requirements of Article 28 of the UK and EU General Data Protection Regulations (“GDPR”).
Individual consumers using Thinkspaces for personal use are not Controllers under this DPA; the Privacy Policy governs the processing of their personal data.
If you require a countersigned copy of this DPA, contact us at communications@thinkspaces.app.
1. Subject Matter & Duration
Thinkspaces will process personal data on behalf of the Controller for the purpose of providing the Thinkspaces collaborative canvas Service as described in the Terms & Conditions. Processing continues for the duration of the Controller’s active subscription and ceases, subject to the deletion terms in Section 8 below, upon termination of that subscription.
2. Nature & Purpose of Processing
Thinkspaces processes personal data to:
- Create, authenticate, and maintain user accounts
- Store, retrieve, and display space content created by authorised users
- Facilitate real-time collaboration (cursor presence during active sessions; not persisted)
- Send transactional emails (account verification, password resets, billing notices)
- Record and process subscription and billing status via Lemon Squeezy
- Monitor for errors and security incidents
3. Types of Personal Data
- Account identifiers: Email addresses, display names, profile pictures (Google OAuth users only)
- Authentication credentials: Bcrypt-hashed passwords, signed session tokens
- User-generated content: Text, images, to-do items, links, and other canvas items created by authorised users
- Billing data: Lemon Squeezy customer ID and subscription status (full payment card details are held by Lemon Squeezy, not Thinkspaces)
- Server logs: IP addresses and request timestamps, retained for 14 days
- Collaboration session data: Cursor positions, display names, and assigned colours during real-time sessions (held in memory only; not persisted to the database)
4. Categories of Data Subjects
The Data Subjects are the Controller’s employees, contractors, or other individuals to whom the Controller has granted access to its Thinkspaces account.
5. Processor Obligations
Thinkspaces will, in its capacity as Processor:
- Process only on documented instructions. Process personal data only in accordance with the Controller’s instructions as set out in the Terms & Conditions and this DPA, except where required to do so by applicable law (in which case Thinkspaces will inform the Controller before processing unless prohibited from doing so).
- Ensure confidentiality. Ensure that personnel authorised to process personal data are under an obligation of confidentiality.
- Implement appropriate security measures. Implement the technical and organisational measures described in Section 6 and in the Security page.
- Assist with data subject rights. Assist the Controller, by appropriate technical and organisational measures, in responding to requests from Data Subjects exercising their rights under applicable data protection law (access, rectification, erasure, portability, restriction, and objection). Most user data is self-serviceable within the Thinkspaces app (account settings, space export, account deletion).
- Assist with Controller obligations. Taking into account the nature of processing and the information available to Thinkspaces, assist the Controller in ensuring compliance with its obligations relating to security, breach notification, data protection impact assessments, and prior consultation.
- Not engage additional sub-processors without notice. Where Thinkspaces intends to engage a new sub-processor (other than those listed in Section 7), it will update the sub-processor list and notify Controllers via the registered email address, giving at least 14 days’ notice. The Controller may object to the addition by contacting us within that window; if no resolution is reached, the Controller may terminate the subscription.
6. Security Measures (Article 32)
Thinkspaces implements the following technical and organisational measures:
- TLS encryption for all data in transit (HTTPS / WSS)
- Encryption at rest for file uploads (Railway Buckets)
- Bcrypt password hashing; plain-text passwords are never stored
- HTTP-only signed session cookies managed by NextAuth
- Database accessible only within Railway’s private network
- File access proxied through the application layer with ownership checks
- Invite links are scoped to a specific space, support optional expiry, and admit collaborators only up to the plan’s per-space limit
- Nightly encrypted database backups with 30-day rolling retention
- Server request logs retained for 14 days only
- Error monitoring via Sentry (stack traces only; no content data)
- DDoS mitigation and edge filtering via Cloudflare
For a full description of security measures, see our Security page.
7. Sub-Processors
The Controller authorises Thinkspaces to engage the following sub-processors. Each has been assessed for compliance with applicable data protection law:
- Railway (US) — Cloud hosting, PostgreSQL database, and object storage. Processes account data and user-generated content. Privacy policy.
- Cloudflare (US) — DNS, edge network, and DDoS protection. Request traffic passes through Cloudflare’s network. Privacy policy.
- Resend (US) — Transactional email delivery. Receives email addresses solely for the purpose of delivering account and billing emails. Privacy policy.
- Lemon Squeezy (US) — Payment processing and tax collection. Acts as merchant of record; handles all payment card data (PCI DSS Level 1 certified). Thinkspaces only stores the resulting customer ID and subscription status. Privacy policy.
- Google (US) — OAuth sign-in (name, email address, and profile picture only) and, for Pro accounts, AI image generation via the Gemini API (text prompts only; not persisted on Thinkspaces servers after the API response is returned). Privacy policy.
- Sentry (US company; error data stored in Sentry’s EU region — Frankfurt, Germany) — Application error monitoring. Receives stack traces and request metadata when an unhandled exception occurs; does not receive content data. Privacy policy.
8. Return & Deletion of Data
On termination of the subscription, the Controller may export space content from within the app at any time during the notice or grace period. Following account deletion, all database records and stored files are permanently purged by an automated process within 7 days. Nightly database backups that include the Controller’s data are retained for up to 30 days from the date of the snapshot, after which they are permanently deleted.
Lemon Squeezy retains financial transaction records independently for up to 7 years to meet their tax and legal obligations as merchant of record. This is outside Thinkspaces’s control.
9. Personal Data Breach Notification
Thinkspaces will notify the Controller of a confirmed personal data breach without undue delay and, where feasible, within 72 hours of becoming aware of the breach. The notification will include the nature of the breach, the categories and approximate number of Data Subjects and records affected, the likely consequences, and the measures taken or proposed to address the breach. Thinkspaces will provide reasonable assistance to enable the Controller to fulfil its own breach notification obligations to supervisory authorities and Data Subjects.
10. International Data Transfers
The sub-processors listed in Section 7 are based in the United States, except that Sentry stores error data in its EU region (Frankfurt, Germany). Transfers of personal data from the EEA or UK to US-based sub-processors are made under Standard Contractual Clauses (SCCs) published by each sub-processor as part of their compliance programmes. To request a summary of the applicable SCCs or transfer mechanisms, contact us at communications@thinkspaces.app.
11. Audit Rights
Thinkspaces will make available to the Controller all information reasonably necessary to demonstrate compliance with the obligations in this DPA and in Article 28 of the GDPR. The Controller may, on reasonable written notice (not less than 30 days) and at the Controller’s own expense, request an audit or inspection of Thinkspaces’s data processing activities. Thinkspaces may satisfy this obligation by providing up-to-date third-party audit reports or security assessments where available.
12. Governing Law
This DPA is governed by the laws of New South Wales, Australia, consistent with the governing law of the Thinkspaces Terms & Conditions, except where a different governing law is mandatory under applicable data protection legislation (in which case that legislation applies to the extent of the inconsistency).
13. Contact
For DPA enquiries, data subject rights requests, or to request a countersigned copy of this agreement, contact us at communications@thinkspaces.app or via our FAQ & Support page.