Tablewidewiki + diagrams
Pricing Leaving Confluence Security Claim a founding spot

Tablewide Data Processing Agreement

Last updated: October 1, 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service (the "Agreement") between Aaron Vontell d/b/a Tablewide ("Processor", "we", "us") and the customer named in the account ("Customer", "you"). It applies automatically when you accept the Agreement; no separate signature is needed. If you need a countersigned copy, email [email protected].

It is intended to meet Article 28 of the EU General Data Protection Regulation (EU GDPR), the UK GDPR and UK Data Protection Act 2018, the Swiss Federal Act on Data Protection (FADP), and the "service provider" / "processor" requirements of US state privacy laws, including the California Consumer Privacy Act as amended (CCPA).


1. Definitions

1.1 Terms such as "controller", "processor", "data subject", "personal data", "processing", "personal data breach" and "supervisory authority" have the meanings given in the GDPR. "Business", "service provider", "sell" and "share" have the meanings given in the CCPA.

1.2 "Customer Personal Data" means personal data in Customer Content, or about Authorized Users, that we process on your behalf in providing the Service.

1.3 "Data Protection Laws" means all privacy and data protection laws that apply to the processing of Customer Personal Data, including those listed above.

1.4 "SCCs" means the standard contractual clauses approved by European Commission Implementing Decision (EU) 2021/914. "UK Addendum" means the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner (version B1.0, in force 21 March 2022), as amended.

1.5 "Subprocessor" means a third party we engage that processes Customer Personal Data.

1.6 "AI Operator" means an AI agent service (currently Claude, provided by Anthropic, PBC) that our staff use, under human supervision, to perform work under the Agreement.

1.7 Other capitalised terms have the meaning given in the Agreement.

2. Roles and scope

2.1 You are the controller (or a processor acting for your own controller) of Customer Personal Data. We are your processor (or subprocessor). Under the CCPA and similar US laws, we are your service provider or processor.

2.2 Annex I describes the processing. We act as a controller only for our own account, billing and website data, as described in our Privacy Policy; this DPA does not cover that data.

2.3 You are responsible for having a lawful basis for the processing and for giving data subjects any required notices. You will not instruct us to process special categories of data, or other data prohibited by Section 8.1 of the Agreement.

3. Instructions

3.1 We process Customer Personal Data only on your documented instructions, unless the law requires otherwise (in which case we will tell you first, unless the law forbids it). Your instructions are: the Agreement and this DPA; your use and configuration of the Service; and support or migration requests submitted by your admins or Authorized Users.

3.2 We will tell you promptly if we believe an instruction breaks Data Protection Laws. We may then decline to follow that instruction.

4. AI Operators

4.1 Plain disclosure. Our operations are run largely by AI agents supervised by a human owner. AI Operators do not have standing access to Customer Content. They access Customer Content only when needed to perform a migration or a support request that you asked for, and only the content needed for that request.

4.2 EU region: opt-in per request. For workspaces in the EU region, an AI Operator accesses Customer Content only after an admin or the requesting Authorized User gives consent for that specific request (for example by confirming in the support ticket). Consent for one request does not cover any other. If you do not consent, we handle the request without AI access to Customer Content, and it may take longer.

4.3 US region. For workspaces in the US region, AI Operators may access Customer Content to perform a migration or support request you asked for. You may ask, in any request, that it be handled without AI access to Customer Content.

4.4 Controls. AI Operators work under the controls in Annex II, including: scoped, per-request access; no ability to delete Customer Content or backups without human approval; and logging of their actions.

4.5 No training. We do not use Customer Personal Data to train AI models, and our contract with the AI Operator provider does not allow it to train its models on the data we send.

4.6 The AI Operator provider is a Subprocessor listed in Annex III and is bound under Section 7.

5. Confidentiality and personnel

5.1 We ensure that everyone authorised to process Customer Personal Data (our owner, any staff and contractors) is bound by confidentiality obligations, and that access is limited to what their role requires.

6. Security

6.1 We implement and maintain the technical and organisational measures in Annex II, taking into account the state of the art, costs, and the nature and risks of the processing.

6.2 We may update Annex II over time, but will not materially reduce the overall level of protection during your paid term.

7. Subprocessors

7.1 General authorisation. You give general authorisation for us to use Subprocessors. The current list is Annex III (subprocessors.md).

7.2 Contracts. We impose on each Subprocessor, by written contract, data protection obligations that give at least the same level of protection as this DPA, to the extent applicable to the services it provides. We remain liable to you for our Subprocessors' performance of those obligations.

7.3 Notice of changes. We give at least 30 days' notice before a new or replacement Subprocessor begins processing Customer Personal Data, by updating the subprocessor list and emailing your workspace admins (and anyone subscribed to notices).

7.4 Objection. You may object on reasonable data protection grounds by emailing [email protected] within that 30-day period. We will discuss the objection in good faith and, where possible, offer an alternative (for example, not using that Subprocessor for your workspace). If we cannot resolve it within 30 days of your objection, you may terminate the Agreement by notice, and we will refund prepaid fees for the unused part of your term. This is your sole remedy for a Subprocessor objection.

7.5 Emergency replacement. If we must replace a Subprocessor urgently (for example because it failed or had a security incident), we may do so immediately and will notify you as soon as practicable; your objection right in Section 7.4 then applies from that notice.

8. International transfers

8.1 Region commitment. Customer Content in the EU region is hosted and backed up only in the European Economic Area. Customer Content in the US region is hosted and backed up in the United States.

8.2 Transfers that do occur. We are a US company, and some processing involves the United States even for the EU region: remote administration by us; billing through Stripe and its merchant-of-record service Link (no Customer Content); transactional and support email; and, only with your per-request consent, AI Operators (Section 4.2).

8.3 SCCs (EU). To the extent that processing of Customer Personal Data by us involves a transfer from the EEA to a country without an adequacy decision, the SCCs are incorporated into this DPA by reference and apply as follows:

  • (a) Module 2 (controller to processor) applies where you are a controller; Module 3 (processor to processor) applies where you are a processor. You are the "data exporter" and we are the "data importer".
  • (b) Clause 7 (docking clause) applies.
  • (c) Clause 9: option 2 (general written authorisation) applies, with the notice period in Section 7.3.
  • (d) Clause 11: the optional redress wording does not apply.
  • (e) Clause 13: the competent supervisory authority is the one determined under Clause 13(a) based on your establishment or, if you have no EU establishment, the Irish Data Protection Commission.
  • (f) Clauses 17 and 18: the SCCs are governed by the law of Ireland, and disputes go to the courts of Ireland.
  • (g) Annex I of the SCCs is completed by Annex I of this DPA; Annex II by Annex II; Annex III by Annex III.

We are not certified under the EU-U.S. Data Privacy Framework. Transfers from the EEA, UK and Switzerland to us rely on the SCCs as set out above.

8.4 Onward transfers. Where a Subprocessor outside the EEA processes Customer Personal Data, we ensure a valid transfer mechanism is in place, such as the SCCs (Module 3) or the Subprocessor's certification under the EU-U.S. Data Privacy Framework.

8.5 UK. For transfers from the UK, the UK Addendum is incorporated by reference. Table 1: parties as in Annex I. Table 2: the SCC modules and options above. Table 3: Annexes I–III of this DPA. Table 4: either party may end the UK Addendum as set out in its Section 19.

8.6 Switzerland. For transfers from Switzerland, the SCCs apply with these changes: the Swiss Federal Data Protection and Information Commissioner is the competent authority for transfers governed by the FADP; references to "Member State" include Switzerland so that Swiss data subjects can bring claims in their place of habitual residence; and references to the GDPR include the FADP.

8.7 Order of precedence. If the SCCs conflict with this DPA or the Agreement, the SCCs win.

9. Assistance

9.1 Data subject requests. Most requests (access, correction, deletion, export) can be handled by your admins directly in the Service. If we receive a request directly from one of your data subjects, we will forward it to you within 5 business days and not respond ourselves except to redirect them to you. We will provide reasonable help with requests you cannot handle yourself.

9.2 Other assistance. Taking into account the nature of the processing and the information we have, we will reasonably help you with data protection impact assessments, prior consultations with supervisory authorities, and your security obligations. We may charge a reasonable fee for help that requires significant effort beyond providing our standard documentation.

10. Personal data breaches

10.1 We will notify you of a personal data breach affecting Customer Personal Data without undue delay, and in any event within 48 hours after we confirm it.

10.2 The notice goes to your workspace admins by email and will include, as far as then known: what happened; the categories and approximate number of data subjects and records affected; likely consequences; measures taken or proposed; and a contact point. We will provide more information as it becomes available.

10.3 We will take reasonable steps to contain and investigate the breach and reduce its harm, and will cooperate with you.

10.4 Notifying you of a breach is not an admission of fault. You are responsible for notifying supervisory authorities and data subjects where required, except where the law places that duty on us.

11. Audits

11.1 Documentation first. We do not yet hold a SOC 2 or ISO 27001 certification. On request, no more than once per 12 months (or after a personal data breach, or when a supervisory authority requires it), we will provide: this DPA and its annexes; our security overview; written answers to a reasonable security questionnaire; and any available third-party reports of our Subprocessors (such as Hetzner's ISO 27001 certificate).

11.2 On-site audits. We allow on-site audits only where a supervisory authority or other regulator with jurisdiction over you requires one, or where the documentation above is not enough to demonstrate compliance with Article 28 GDPR. Any such audit must be on at least 30 days' written notice, during business hours, by you or an independent auditor bound by confidentiality, limited to what is necessary, and without access to other customers' data. You bear the costs of the audit, including our reasonable time at US$150 per hour.

11.3 Audits of our Subprocessors take place through the documentation they make available, or as their own terms allow.

12. Deletion and return

12.1 During the term, you can export Customer Content at any time.

12.2 After the Agreement ends, the workspace is kept in export-only mode for 30 days so you can export your data. We then delete Customer Personal Data from the live systems within 30 days after that period (deletions run in monthly batches). Backups containing it are deleted as they roll off, within a further 30 days.

12.3 We may keep Customer Personal Data longer only where the law requires it, and then only for as long as required, protected under this DPA, and not processed for any other purpose.

12.4 On request we will confirm deletion in writing.

13. US state privacy laws (CCPA and similar)

13.1 For Customer Personal Data that is "personal information" under the CCPA or similar US state laws, we will:

  • (a) process it only for the limited and specified business purposes of providing, securing, supporting and maintaining the Service, performing requested migrations and support, and as the Agreement otherwise permits;
  • (b) not sell or share it (including for cross-context behavioural advertising);
  • (c) not retain, use or disclose it outside our direct business relationship with you or for any purpose other than those in (a), except as those laws allow;
  • (d) not combine it with personal information we receive from others or collect ourselves, except as those laws allow;
  • (e) comply with applicable obligations under those laws and give it the same level of privacy protection they require;
  • (f) notify you if we determine we can no longer meet our obligations under them; and
  • (g) allow you to take reasonable and appropriate steps to stop and remediate unauthorised use, including by exercising your rights in Sections 11 and 12.

13.2 We certify that we understand and will comply with the restrictions in this Section 13.

14. Liability and precedence

14.1 Each party's liability under this DPA is subject to the limitations and exclusions in the Agreement, except where Data Protection Laws or the SCCs do not allow liability to be limited (for example, liability to data subjects under the SCCs).

14.2 If this DPA conflicts with the Agreement on data protection, this DPA wins. The SCCs win over both, as stated in Section 8.7.

15. Term

15.1 This DPA lasts as long as we process Customer Personal Data under the Agreement, including the deletion periods in Section 12.


Annex I: Parties and description of processing

A. Parties

Data exporter / controller: the Customer named in the account.

  • Contact: the workspace admin(s) listed in the account.
  • Activities: use of the Service under the Agreement.
  • Role: controller (or processor on behalf of its own controller).

Data importer / processor: Aaron Vontell d/b/a Tablewide, New York, NY, USA (postal address on request).

  • Contact: [email protected].
  • EU and UK representative (GDPR Art. 27): none appointed. Contact [email protected].
  • Activities: providing the hosted Tablewide Service, migrations and support.
  • Role: processor.

B. Description of processing

ItemDescription
Categories of data subjectsCustomer's Authorized Users (employees, contractors, invited guests); individuals named or described in Customer Content (for example colleagues, customers' contacts, vendors); visitors to public pages the Customer publishes (access logs only)
Categories of personal dataUser identity data from the Customer's identity provider (name, email address, provider user ID, tenant/group identifiers, profile picture if provided); user activity in the workspace (page edits, comments, revision history, timestamps); IP addresses and user agents in access logs; any personal data the Customer puts in Customer Content
Special categories / sensitive dataNone intended. Prohibited by Section 8.1 of the Agreement
Frequency of transferContinuous, for the term of the Agreement
Nature of processingHosting, storage, backup, retrieval, display, transmission, search indexing, export, deletion; migration of content from other tools; support troubleshooting
PurposeProviding the Service under the Agreement, including migrations and support that the Customer requests
RetentionFor the term of the Agreement; then 30 days in export-only mode; then deletion from live systems within a further 30 days; backups deleted within 30 days after that. Access logs: 30 days
Subprocessor transfersAs listed in Annex III, for the purposes and in the regions stated there

C. Competent supervisory authority

As set out in Section 8.3(e).


Annex II: Technical and organisational measures

Isolation

  • Each customer gets its own application container and its own database. No two customers share a database or a database schema.
  • Workspaces run in the region the customer chose (EU or US). Data and backups stay in that region.

Encryption

  • In transit: all traffic to the Service uses TLS 1.2 or higher; plain HTTP redirects to HTTPS. Traffic between our servers and to backup storage is encrypted.
  • At rest: backups are encrypted with a separate key per customer before they leave our servers. Live servers run in our hosting provider's data centres under its physical and access controls; we do not add separate disk encryption to them.
  • Backups: encrypted before they leave the server, using a separate encryption key for each customer. Keys are stored separately from the backups; the backup storage provider cannot read them.

Identity and access

  • Users sign in only through Google or Microsoft (OpenID Connect): the customer's own Workspace or Entra ID, or, for admins and invited guests, their own Google or Microsoft account. We store no user passwords.
  • All administrative accounts (hosting, backup storage, billing, email, code hosting, domain registrar) require multi-factor authentication; phishing-resistant methods (hardware keys or passkeys) are used where supported.
  • Least privilege: people and AI Operators get only the access their task needs. Server access uses individual SSH keys, not shared passwords. Access is reviewed at least quarterly and removed promptly when no longer needed.

AI Operators

  • No standing access to Customer Content. Access is granted per request (migration or support ticket), scoped to the affected workspace, and removed when the request is closed.
  • For the EU region, access requires the customer's consent for that request.
  • AI Operators cannot delete customer workspaces, Customer Content or backups, or change backup retention, without explicit approval by a human.
  • AI Operator actions on production systems are logged and reviewed by a human.

Logging and monitoring

  • Administrative actions and access to production systems are logged. Logs are kept for 90 days.
  • Application access logs are kept for 30 days.
  • Uptime, error rates and resource use are monitored with alerts to the on-call human.

Backups and recovery

  • Nightly encrypted backups of each workspace's database and files to a second storage provider in the same region, kept about 30 days.
  • A restore test is performed at least monthly, restoring a sample of workspaces to an isolated environment and checking the result. Results are recorded.

Vulnerability management

  • Operating system and container images are updated at least monthly.
  • Security patches: critical severity applied within 72 hours of a fix being available; high severity within 7 days;, others in the monthly cycle.
  • We track security advisories for BookStack, draw.io and other components we run.
  • We follow security advisories for the software we run and update dependencies and container images regularly.

Incident response

  • A written incident response procedure covers detection, containment, investigation, notification (within the timeline in Section 10), recovery and post-incident review.
  • Security reports are accepted at [email protected].

Secure development and change management

  • Changes to production are made through version-controlled code and configuration, and reviewed before deployment. Changes proposed by AI Operators are approved by a human before they reach production.
  • Production secrets are kept in a secrets store, not in source code.

Data minimisation and deletion

  • We collect only the user data needed to sign users in and run the workspace.
  • Deletion follows the schedule in Section 12. Source-system exports received for migrations are deleted within 30 days after the migration is complete.

Physical security

  • We run no data centres of our own. Physical security is provided by our hosting provider (Hetzner), under its published security measures.

People

  • Everyone with access is bound by confidentiality and trained on these measures.

Annex III: Subprocessors

The current list of Subprocessors, their purposes, the data they process, their locations and the regions they apply to is at subprocessors.md (tablewide.com/subprocessors), which is incorporated into this DPA.

Pricing Security and data Terms Privacy Refunds Subprocessors Open source Service status Confluence end of life Export a Confluence space vs Confluence Cloud vs Notion Hosted vs self-hosted BookStack Support: [email protected] Security: [email protected] Privacy: [email protected]

Aaron Vontell, an individual doing business as Tablewide. Mailing address to come.

Tablewide runs BookStack, the open source wiki, for you. We are not affiliated with or endorsed by the BookStack project. Confluence, Jira and Trello are trademarks of Atlassian; Notion is a trademark of Notion Labs. We mention them only to compare.