Runetale Data Processing Addendum
Last updated: July 13, 2026
This Data Processing Addendum ("DPA") forms part of the Main Service Agreement (or other written agreement) between Customer and Runetale Inc. ("Runetale") for the provision of the Runetale Service (the "Agreement"). This DPA applies to the extent that Runetale processes Personal Data on behalf of Customer in providing the Service. In the event of a conflict between this DPA and the Agreement, this DPA will prevail with respect to the processing of Customer Personal Data. In the event of a conflict between the Standard Contractual Clauses (where applicable) and this DPA, the Standard Contractual Clauses will prevail.
1. Definitions
In this DPA, the following terms have the meanings set out below. Capitalized terms not defined in this DPA have the meanings given in the Agreement.
"Applicable Data Protection Law" means all data protection and privacy laws applicable to the processing of Personal Data under this DPA, including (as applicable): (a) Japan's Act on the Protection of Personal Information ("APPI") and guidelines issued by the Personal Information Protection Commission ("PPC"); (b) the EU General Data Protection Regulation 2016/679 ("EU GDPR"); (c) the EU GDPR as incorporated into UK law ("UK GDPR"); (d) the Swiss Federal Act on Data Protection ("Swiss FADP"); (e) the California Consumer Privacy Act as amended by the CPRA ("CCPA"); and (f) any other applicable data protection or privacy law.
"Controller" means the entity that determines the purposes and means of processing Personal Data. Under APPI, this corresponds to a business operator handling personal information.
"Customer Data" means any data or information related to the configuration and management of Customer networks that is generated by or submitted to the Service by Customer, its authorized users, or client endpoints. Customer Data includes Customer Personal Data.
"Customer Personal Data" means any Personal Data contained within Customer Data that Runetale processes on behalf of Customer as a Processor in the course of providing the Service, as described in Schedule 1.
"Data Subject" means an identified or identifiable natural person to whom Customer Personal Data relates. Under APPI, this corresponds to the individual (principal) identified by personal information.
"European Data Protection Law" means: (a) the EU GDPR; (b) the EU e-Privacy Directive (2002/58/EC); (c) the UK GDPR; (d) the Swiss FADP; and (e) any national implementing legislation, in each case as amended or superseded.
"Personal Data" has the meaning given under Applicable Data Protection Law (and includes "personal information" under APPI and "personal information" under CCPA).
"Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data.
"Processor" means the entity that processes Personal Data on behalf of the Controller. Under APPI, this corresponds to an entrusted party handling personal data.
"Standard Contractual Clauses" or "SCCs" means the standard contractual clauses for the transfer of personal data approved by the European Commission (Implementing Decision (EU) 2021/914), as may be amended or replaced.
"Subprocessor" means any third party engaged by Runetale to process Customer Personal Data on behalf of Customer.
"Service" means the Runetale mesh networking service, including the management console, API, control plane, signaling and relay infrastructure, and client applications as described in the Agreement.
"Traffic Payload" means the content of Customer network communications encapsulated within encrypted packets transmitted between endpoints through the standard Runetale peer-to-peer or relay data plane.
"Connection Metadata" means network-level metadata processed by Runetale in the course of operating the Service, including IP addresses, ports, timestamps, connection states, and relay routing information, as further described in Schedule 1.
"Customer Log Data" means data generated through optional Service features enabled by Customer and processed by Runetale on Customer's behalf, including Network Flow Logs and Connection Telemetry.
"UK Addendum" means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, issued by the UK Information Commissioner under Section 119A of the Data Protection Act 2018.
2. Roles and Scope
2.1 Customer is the Controller of Customer Personal Data (or, where Customer acts as a Processor on behalf of its own controllers, Customer warrants that it has obtained all necessary authorizations to appoint Runetale as a sub-processor). Runetale is the Processor (or sub-processor, as applicable) of Customer Personal Data.
References to Controller, Processor, and Subprocessor describe the parties' contractual data processing roles. Obligations under APPI apply according to each party's actual handling of personal information and the requirements of APPI, irrespective of the terminology used in this DPA.
2.2 Runetale independently acts as a Controller for limited categories of data processed for its own business purposes, including billing administration and website analytics. Such processing is governed by the Runetale Privacy Policy and is not subject to this DPA.
2.3 The Processor entity under this DPA is Runetale Inc., located at 7-3-12 Roppongi, Minato-ku, Tokyo 106-0032, Japan. The designated privacy contact is privacy@runetale.com.
2.4 Runetale will process Customer Personal Data only as necessary to perform its obligations under the Agreement and in accordance with Customer's documented instructions. The details of processing are set out in Schedule 1.
3. Instructions and Restrictions
3.1 Runetale will process Customer Personal Data only on the basis of documented instructions from Customer. The Agreement constitutes Customer's initial instructions for processing.
3.2 If Runetale reasonably believes that an instruction from Customer infringes Applicable Data Protection Law, Runetale will inform Customer without undue delay and will await further instructions before carrying out the relevant processing.
3.3 Customer is responsible for ensuring the lawfulness of its processing instructions, including obtaining all necessary notices, consents, and authorizations required under Applicable Data Protection Law.
3.4 Runetale will ensure that all persons authorized to process Customer Data are subject to written confidentiality obligations. For the avoidance of doubt, the confidentiality obligation under this Section applies to all Customer Data, not only Customer Personal Data.
3.5 Runetale will not: (a) "sell" Customer Personal Data as that term is defined in Applicable Data Protection Law; (b) use Customer Personal Data for cross-context behavioral advertising or targeted advertising; (c) combine Customer Personal Data with personal data received from or on behalf of any other person, except as necessary to provide the Service; (d) attempt to re-identify any de-identified, pseudonymized, or aggregated Customer Personal Data without Customer's express written permission; or (e) process Customer Personal Data for any purpose other than the specific purposes set forth in the Agreement and this DPA.
3.6 Customer acknowledges that Runetale is not a "Business Associate" under HIPAA, does not act as a "school official" under FERPA, and does not require special categories of personal data (GDPR Article 9) or sensitive personal information (including government identification numbers) to perform the Service. Customer will not provide any such information in connection with the Service unless the parties have entered into a supplementary agreement addressing such data.
3.7 The parties acknowledge that the exchange of Customer Personal Data between the parties does not constitute a "sale" of personal data under any Applicable Data Protection Law, and does not form part of any monetary or other valuable consideration exchanged between the parties.
3.8 If Runetale determines that it can no longer meet its obligations under this DPA or Applicable Data Protection Law, Runetale will promptly notify Customer and will cease processing Customer Personal Data until Customer provides further instructions. Such notice will entitle Customer to terminate the Agreement and receive a pro-rata refund of prepaid fees for the remainder of the term.
3.9 The parties will operate in good faith and provide reasonable cooperation and assistance to each other to facilitate performance under this DPA.
4. Traffic Payload Exclusion
4.1 All peer-to-peer traffic transmitted through the standard Runetale data plane is end-to-end encrypted using the WireGuard protocol. Cryptographic keys are generated exclusively on the client device; private keys never leave that device and are never transmitted to Runetale. Relay servers forward encrypted packets without any decryption capability. Runetale performs no deep packet inspection, no traffic decryption, and does not access, read, copy, or store Traffic Payload in plaintext through the standard peer-to-peer or relay data plane. The technical details of the cryptographic protocols are described in Schedule 2 ("Encryption").
4.2 Traffic Payload may constitute Personal Data in Customer's environment. However, to the extent Traffic Payload is transmitted solely through the standard Runetale peer-to-peer or relay data plane, Runetale does not decrypt, inspect, access in plaintext, or store that Traffic Payload. Accordingly, such Traffic Payload falls outside the scope of Customer Personal Data Processed by Runetale under this DPA. The Traffic Payload Exclusion does not limit Runetale's processing of Connection Metadata and other data necessary to configure, secure, operate, monitor, and troubleshoot the Service, as further described in Schedule 1.
4.3 The Traffic Payload Exclusion applies solely to data transmitted through the standard peer-to-peer and relay data plane. It does not apply to: (a) content intentionally submitted by Customer or its users through support channels, diagnostic uploads, or other direct communications with Runetale; or (b) content processed through optional application-layer features that Customer orders, enables, or uses. Processing under clause (b) will be described in the applicable Documentation, feature-specific notice, Order Form, or an updated Schedule before Customer enables or uses the applicable feature. The introduction of an optional application-layer feature will not expand the scope of processing applicable to the standard peer-to-peer or relay data plane, will not apply retroactively to existing Customers who have not enabled the feature, and will be subject to any consent or contractual amendment required under Applicable Data Protection Law.
5. Subprocessors
5.1 Customer grants Runetale general written authorization to engage Subprocessors for the processing of Customer Personal Data in connection with the Service.
5.2 The current list of Subprocessors is set out in Schedule 3 to this DPA and is maintained at the Runetale subprocessors page.
5.3 Runetale will enter into a written contract with each Subprocessor imposing data protection obligations no less protective than those set out in this DPA.
5.4 Runetale will provide Customer with at least 30 days' prior written notice before engaging any new or replacement Subprocessor, including the name, location, and processing activities of the proposed Subprocessor.
5.5 Customer may object to a new or replacement Subprocessor in writing within 30 days of receiving notice, provided the objection is based on reasonable data protection grounds. The parties will engage in good faith discussion to resolve the objection. If no resolution is reached within a further 30 days, Customer may terminate the affected portion of the Service with a pro-rata refund of prepaid fees for the terminated period.
5.6 In the event of an emergency requiring immediate engagement of a replacement Subprocessor to maintain Service continuity (for example, failure of an existing Subprocessor), Runetale will notify Customer as soon as reasonably practicable and in any event within 5 business days of engagement. Customer's objection right under Section 5.5 will be preserved.
5.7 Where the parties have entered into Standard Contractual Clauses as described in Part C, the authorizations in this Section 5 will constitute Customer's prior written consent to the subcontracting of processing if such consent is required under the SCCs. Upon Customer's written request, Runetale will make available copies of its agreements with Subprocessors (redacted as necessary to protect commercial information unrelated to the SCCs) pursuant to Clause 9(c) of the EU SCCs.
5.8 For the avoidance of doubt, "Subprocessor" does not include ancillary services such as telecommunications, postal or transport services, maintenance and user support services, or measures to ensure the confidentiality, availability, integrity, and resilience of hardware and software of data processing equipment.
6. Security
6.1 Runetale will implement and maintain appropriate technical and organizational measures to protect Customer Personal Data against Personal Data Breach, as described in Schedule 2. In determining the appropriate level of security, Runetale will take into account the state of the art, the costs of implementation, the nature, scope, context, and purposes of processing, and the risks to the rights and freedoms of Data Subjects.
6.2 Runetale may update the security measures from time to time, provided that any such update will not result in a material decrease in the overall level of protection afforded to Customer Personal Data.
7. Data Subject Rights Assistance
7.1 Runetale will provide reasonable assistance to Customer in fulfilling its obligations to respond to Data Subject requests exercising their rights under Applicable Data Protection Law, including rights of access, rectification, erasure, restriction of processing, data portability, and objection, as well as rights under APPI Articles 32 through 37.
7.2 If Runetale receives a request directly from a Data Subject regarding Customer Personal Data, Runetale will redirect the Data Subject to Customer unless required by Applicable Data Protection Law to respond directly.
7.3 Runetale will respond to Customer's assistance requests without undue delay. The first request per 12-month period will be provided at no additional cost; subsequent requests may be subject to a reasonable fee based on Runetale's administrative costs.
8. Personal Data Breach Notification
Runetale will notify Customer without undue delay (and in any event within seventy-two (72) hours) of any known breach of security leading to the accidental, unauthorized, or unlawful destruction, loss, alteration, disclosure of, or access to Customer Personal Data stored or otherwise processed in connection with the Service (a "Personal Data Breach"). Runetale will also provide reasonable assistance to Customer in Customer's compliance with Customer's own breach notification obligations under Applicable Data Protection Law, including without limitation by: (a) taking reasonable steps to contain, investigate, and mitigate the effects of the Personal Data Breach and reduce the risk to Data Subjects whose Personal Data was involved (such steps to be determined by Runetale in its reasonable discretion); and (b) providing Customer with the following information, to the extent known at the time of notification: (i) the nature of the Personal Data Breach, including, where possible, how the breach occurred, the categories and approximate number of Data Subjects concerned, and the categories and approximate number of Customer Personal Data records concerned; (ii) the likely consequences of the Personal Data Breach; and (iii) the measures Runetale has taken or proposes to take to address the Personal Data Breach, including where appropriate measures to mitigate its possible adverse effects.
Where, and insofar as, it is not possible to provide all information at the same time, the initial notification will contain the information then available and further information will, as it becomes available, subsequently be provided without undue delay. Runetale will cooperate with Customer and take reasonable commercial steps to assist in the investigation, mitigation, and remediation of the Personal Data Breach, and will preserve evidence related to the breach for a reasonable period.
For the avoidance of doubt, "Personal Data Breach" does not include unsuccessful attempts or activities that do not result in the accidental, unauthorized, or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data, including but not limited to unsuccessful log-in attempts, pings, port scans, denial-of-service attacks, and other network attacks on firewalls or networked systems. The parties agree that notification under this Section is not an acknowledgment of fault or liability by the notifying party.
9. Audit Rights
Runetale shall first make available existing third-party attestation reports and certifications to demonstrate compliance. The scope of audit assistance available may vary based on Customer's service plan.
Upon Customer's written request, and no more than once during each 12-month period, Runetale will provide Customer with its most recent security review reports and applicable certifications for the Service (including ISO 27001/27017 certificates and, when available, SOC 2 Type II reports) and provide reasonable assistance and information to Customer to understand the information in such reports. Customer agrees that such third-party reports and certifications are sufficient to demonstrate Runetale's compliance with the obligations set out in this DPA in the ordinary course.
If Customer has a reasonable objection that the information provided is not sufficient to demonstrate Runetale's compliance with this DPA, provided such objection is based on reasonable grounds related to data protection, Customer may: (a) submit a written security questionnaire, which Runetale will complete within a reasonable period; or (b) if the questionnaire does not resolve the concern, conduct an audit, or select a mutually agreed-upon third party to conduct an audit, of Runetale's practices related to compliance with this DPA, at Customer's sole expense (an "Audit"). General DPA compliance Audits will occur not more than once every 12 calendar months, except where Customer has a reasonable documented basis for believing a Personal Data Breach has occurred affecting Customer Personal Data.
To the extent Customer uses a third-party representative to conduct the Audit, Customer will ensure that such auditor is bound by obligations of confidentiality no less protective than those contained in this DPA and the Agreement, and must not be a direct competitor of Runetale. Customer will provide Runetale with at least 30 days' prior written notice of its intention to conduct an Audit. Before any Audit, the parties will mutually agree upon the scope, timing, and duration of the Audit, as well as the Runetale reimbursement rate for which Customer will be responsible (all such rates to be reasonable, taking into account the resources expended by or on behalf of Runetale). Customer and its auditors will conduct Audits: (i) acting reasonably, in good faith, and in a proportional manner, taking into account the nature and complexity of the Service; and (ii) in a manner that will result in minimal disruption to Runetale's business operations and during Runetale's normal business hours. Neither Customer nor its auditors will be entitled to receive data or information of other Runetale customers or any other Runetale Confidential Information that is not directly relevant for the authorized purposes of the Audit. Customer will promptly provide Runetale with the Audit results upon completion. All Audit-related materials will be considered "Confidential Information" subject to the confidentiality provisions of the Agreement. Nothing in this Section will limit the audit rights of any supervisory authority, the Personal Information Protection Commission (PPC), or other competent regulatory body under Applicable Data Protection Law.
10. DPIA Assistance
Runetale will provide reasonable assistance to Customer in conducting data protection impact assessments and in any prior consultations with supervisory authorities required under Articles 35 and 36 of the EU GDPR or equivalent provisions of Applicable Data Protection Law, to the extent such assessments relate to Runetale's processing of Customer Personal Data. Customer will be responsible for any costs beyond those reasonably necessary for Runetale to provide such assistance.
11. International Data Transfers
11.1 Customer Personal Data is primarily stored and processed in AWS facilities located in Tokyo, Japan (ap-northeast-1 region).
11.2 The following categories of cross-border transfers of Customer Personal Data occur in connection with the Service. The specific Subprocessors involved in each transfer are identified in Schedule 3.
| Processing Purpose | Data Transferred | Destination | Transfer Mechanism |
|---|---|---|---|
| Payment processing | Billing data | US | APPI Art. 28: Equivalent standards |
| Email delivery | Email addresses | US | APPI Art. 28: Equivalent standards |
| Support communications | Support correspondence | US | APPI Art. 28: Equivalent standards |
| Issue management | Support issues | US | APPI Art. 28: Equivalent standards |
Data transfers relating to Runetale's Controller activities described in Section 2.2 are not subject to this DPA.
11.3 International transfers of Customer Personal Data will be made in accordance with the following mechanisms: (a) transfers from Japan will rely on APPI Article 28 equivalent standards (systems conforming to standards prescribed by the PPC) established through written data processing agreements with each Subprocessor; (b) transfers from the EU/EEA will be governed by the SCCs as set out in Part C; (c) transfers from the United Kingdom will be governed by the UK Addendum as set out in Part C; and (d) transfers from Switzerland will be governed by the SCCs as modified for Swiss transfers in Part C.
11.4 Runetale will implement supplementary measures to protect transferred Customer Personal Data where required by Applicable Data Protection Law or by a competent supervisory authority.
12. Return and Deletion
Except to the extent required by applicable law, Runetale will return or destroy Customer Personal Data upon Customer's request and within thirty (30) days of termination or expiration of the Agreement. Customer will have the period specified in the Agreement or applicable Order Form (the "Export Window") following termination or expiry to request return of Customer Personal Data in a commonly used machine-readable format or to request deletion. Where no period is specified in the Agreement or Order Form, the default Export Window will be thirty (30) days. If no request is received within the Export Window, Runetale will proceed with deletion.
Data remaining in backups or other isolated systems is deleted in accordance with Runetale's standard backup rotation schedule. Runetale will also ensure that Customer Personal Data held by Subprocessors is deleted in accordance with applicable Subprocessor agreements and standard deletion cycles. Where applicable legal retention requirements (including tax record retention obligations under applicable law) or Runetale's standard operational procedures require retention of specific data categories beyond the deletion timeline, such data will be retained solely for the applicable legal or operational purpose, subject to the confidentiality and security obligations of this DPA, and deleted promptly upon expiry of the retention requirement.
Runetale will provide Customer with a written certificate of deletion only upon Customer's written request, to be delivered within 30 days of receipt of such request. In cases where Applicable Data Protection Law prohibits the return or deletion of Customer Personal Data, Runetale warrants that it will continue to ensure compliance with this DPA and will only process the affected Customer Personal Data to the extent and for as long as required under such law, maintaining full confidentiality and security protections throughout the retention period.
13. Public Authority Requests
13.1 If Runetale receives a request from a public authority for disclosure of Customer Personal Data, Runetale will notify Customer of the request before making any disclosure, unless prohibited from doing so by law.
13.2 Runetale will challenge any request for disclosure that Runetale reasonably considers to be unlawful and will limit disclosure to the minimum data legally required.
13.3 Where Runetale is prohibited by law from notifying Customer of a disclosure request, Runetale will use reasonable efforts to obtain a waiver of that prohibition or to narrow the scope of the request.
13.4 Runetale will provide an annual transparency report to Customer upon written request, summarizing the number and nature of public authority requests received during the preceding period.
13.5 Runetale does not provide any government with direct access to Customer Personal Data. The architectural design described in Section 4 means that Runetale does not possess Traffic Payload in plaintext and does not hold the private keys necessary to decrypt it. Accordingly, Runetale cannot produce Traffic Payload content to any party, including public authorities.
14. Liability
14.1 Each party's liability arising out of or in connection with this DPA will be subject to the limitations of liability set out in the Agreement, and all claims under this DPA will be aggregated with claims under the Agreement for the purposes of such limitations.
14.2 Nothing in this Section 14 will limit either party's liability to Data Subjects under Applicable Data Protection Law or liability arising under the Standard Contractual Clauses where applicable.
15. Updates
15.1 Runetale may update this DPA from time to time to reflect changes in Applicable Data Protection Law, regulatory guidance, or Runetale's processing activities. Runetale will provide Customer with at least 30 days' prior written notice of any material changes.
15.2 Unless Customer objects in writing within the 30-day notice period, material changes will become effective upon the next renewal date or new order date following the notice period.
15.3 If Customer objects to a material change, the prior version of this DPA will continue to apply until the earlier of the date on which the parties reach agreement on amended terms or the expiry of the current Agreement term.
15.4 Non-material changes (such as corrections of typographical errors or updates to contact information) will become effective upon posting.
16. Governing Law
16.1 This DPA will be governed by and construed in accordance with the laws of Japan, without regard to conflict of law principles. Where the Standard Contractual Clauses apply, they will be governed by the law specified therein.
16.2 Any dispute arising out of or in connection with this DPA will be submitted to the exclusive jurisdiction of the Tokyo District Court, except where Applicable Data Protection Law grants Data Subjects the right to bring proceedings in another forum or where the Standard Contractual Clauses require a different jurisdiction.
17. General Provisions
17.1 This DPA, together with the Agreement and the Standard Contractual Clauses (where applicable), constitutes the entire agreement between the parties with respect to the processing of Customer Personal Data and supersedes all prior representations, understandings, and agreements on this subject matter.
17.2 If any provision of this DPA is found to be invalid or unenforceable, the remaining provisions will continue in full force and effect, and the parties will negotiate in good faith a valid provision that achieves the original intent.
17.3 No failure or delay by either party in exercising any right under this DPA will constitute a waiver of that right.
17.4 Sections 12 through 14, together with any accrued obligations, will survive termination or expiry of this DPA and the Agreement.
17.5 Runetale will certify compliance with this DPA upon reasonable written request from Customer. If Runetale determines that it can no longer meet its obligations under this DPA, it will promptly notify Customer and the parties will cooperate to remedy the situation.
Part B: APPI-Specific Provisions
This Part B applies only to the extent that APPI governs the processing of Customer Personal Data under this DPA. If APPI does not apply, this Part B creates no obligations.
B.1 Where Runetale transfers Customer Personal Data outside Japan, such transfer will comply with APPI Article 28 through the establishment of a system conforming to the standards prescribed by the PPC. Runetale maintains written data processing agreements with each overseas Subprocessor that impose protections equivalent to those required under APPI. Runetale will continuously monitor each Subprocessor's compliance with these agreements and will provide information regarding the data protection regime applicable to each transfer destination upon Customer's request to the extent reasonably available.
B.2 Where Customer Personal Data constitutes retained personal data under APPI, Runetale will assist Customer in responding to requests from Data Subjects exercising their statutory rights under APPI Articles 32 through 37 (including requests for disclosure, correction, addition, deletion, cessation of use, and cessation of third-party provision). Runetale will implement corrections, deletions, or cessation of use in accordance with Customer's documented instructions within a commercially reasonable timeframe.
B.3 As an entrusted party subject to APPI Article 23, Runetale will implement necessary and appropriate security control measures for the safe management of personal data. These measures are detailed in Schedule 2 and organized across four categories: organizational security control measures (access control policies, audit logs, incident response procedures, designated security officers), personnel security control measures (confidentiality obligations, SSO-based access control, security training), physical security control measures (data center security, network segregation, deletion safeguards), and technical security control measures (WireGuard/TLS encryption, encryption at rest, SSO authentication, default-deny network access policies).
B.4 In entrusting Customer Personal Data to Subprocessors, Runetale will exercise necessary and appropriate supervision over such Subprocessors in accordance with APPI Article 25. This includes: (a) concluding written agreements that impose security management obligations, (b) periodically reviewing handling practices at each Subprocessor, and (c) requiring remedial actions upon identification of any deficiencies.
Part C: European Data Protection Law
C.1 This Part C applies only to the extent that European Data Protection Law applies to the processing of Customer Personal Data. Where this Part C applies, both parties confirm the applicability of the relevant European Data Protection Law and agree to comply with its requirements in addition to the requirements of the main body of this DPA.
C.2 To the extent that the transfer of Customer Personal Data from the EU/EEA to Runetale requires the Standard Contractual Clauses, the parties will be deemed to have entered into the SCCs as follows: Module 2 (Controller to Processor) will apply where Customer is a Controller; Module 3 (Processor to Processor) will apply where Customer is itself a Processor acting on behalf of its own controller. The optional docking clause (Clause 7) will apply to permit additional parties to accede. For the purposes of Clause 9, Option 2 (general written authorization) will apply with the prior notice period specified in Section 5.4 of this DPA. The governing law under Clause 17 will be the law of Ireland. The competent courts under Clause 18 will be the courts of Ireland.
C.3 To the extent that the transfer of Customer Personal Data from the United Kingdom requires additional transfer safeguards, the UK Addendum will be appended to the EU SCCs. For the purposes of Table 4 of the UK Addendum, "neither Party" may end the UK Addendum as set out in Section 19 of the UK Addendum.
C.4 To the extent that the Swiss Federal Act on Data Protection applies to the processing, the SCCs will be modified as follows: references to the GDPR will be interpreted as references to the Swiss FADP, the competent supervisory authority will be the Swiss Federal Data Protection and Information Commissioner, and the competent courts will be the courts of Switzerland.
C.5 The parties will cooperate in good faith to handle any complaints or claims brought by Data Subjects or supervisory authorities in connection with the processing of Customer Personal Data under European Data Protection Law.
Part D: US Privacy Laws
D.1 This Part D applies only to the extent that US state privacy laws govern the processing of Customer Personal Data. If no US state privacy law applies to Customer's use of the Service, this Part D creates no obligations. Runetale currently provides a business-to-business service and does not directly collect personal information from consumers; the CCPA and other US state privacy laws are unlikely to be triggered by Customer's use of the Service in its current form.
D.2 To the extent the CCPA applies, Runetale acts as a "service provider" as defined under the CCPA. Runetale will not sell or share Customer Personal Data, will not use Customer Personal Data for cross-context behavioral advertising, will not use Customer Personal Data outside the direct business relationship with Customer, will not attempt to re-identify de-identified information, and will not combine Customer Personal Data with personal information received from or on behalf of another person.
D.3 To the extent that other US state privacy laws apply (including the Virginia Consumer Data Protection Act, Colorado Privacy Act, Connecticut Data Privacy Act, and Utah Consumer Privacy Act), Runetale will comply with all applicable processor obligations under those laws.
D.4 Runetale will allow Customer to take reasonable and appropriate steps to help ensure that Runetale uses Customer Personal Data in a manner consistent with Customer's obligations under US state privacy laws, including the right to take reasonable steps to stop and remediate unauthorized use.
D.5 Runetale will certify its compliance with the restrictions set out in this Part D upon reasonable written request from Customer.
Schedule 1: Details of Processing
A. List of Parties
| Role | Party | Address | Contact |
|---|---|---|---|
| Controller (or Processor) | Customer | Per Customer account registration | Customer privacy contact |
| Processor (or Sub-processor) | Runetale Inc. | 7-3-12 Roppongi, Minato-ku, Tokyo 106-0032, Japan | privacy@runetale.com |
B. Description of Processing
| Element | Description |
|---|---|
| Subject matter | Provision of Runetale mesh networking service |
| Duration | Term of the Agreement plus the Export Window and any applicable legal retention period |
| Nature | Collection, storage, organization, retrieval, use, disclosure by transmission, erasure |
| Purpose | Service delivery (network orchestration, authentication, access control), security monitoring, billing, and customer support |
| Data Subjects | Customer's authorized users, including employees, contractors, and other authorized individuals |
C. Types of Customer Personal Data Processed
- Contact and Account Information. Including email address, username, organization domain, billing contact name, profile picture URL, identity provider subject identifier, plan type, node allocation, invoice references, support ticket content, attachments, and issue descriptions. Payment card details are held exclusively by the payment processor (Stripe); PCI SAQ-A scope.
- Device and Node Information. Including IP addresses, device identifiers, operating system, hostname, cryptographic public keys, agent version, session tokens, timestamps, connection states, advertised routes, overlay IP addresses, and remote access host keys. Authentication tokens received from identity providers are redacted immediately after authentication exchange and never persisted. No passwords stored (SSO-only).
- Configuration Information. Including access control rules, network settings, DNS settings, route mappings, key authority settings, peer relationships, access policies, and audit logs (source IP address, operator identity, action performed, timestamp). Configuration data is controlled entirely by Customer and not shared with third parties. Audit logs are generated automatically for security monitoring and cannot be disabled.
- Data from Customer-Enabled Optional Features. Including Connection Telemetry (path transition events, relay connection states, filter decisions), Network Flow Logs (source/destination identifiers, IP addresses, ports, protocol identifiers, timestamps, traffic classifications, data-volume statistics), and Client Diagnostics (log level, message content, session identifier, client version). These features are disabled by default and data is collected only when enabled by the organization administrator. Certain identifiers are pseudonymized via one-way cryptographic transformation.
D. Data NOT Processed
Traffic Payload. The content of network traffic is end-to-end encrypted via the WireGuard protocol. Runetale does not decrypt, inspect, access in plaintext, or store Traffic Payload transmitted through the standard peer-to-peer or relay data plane. Accordingly, such Traffic Payload falls outside the scope of Customer Personal Data Processed by Runetale under this DPA. See Section 4 for the architectural basis and legal rationale of this exclusion.
Product Telemetry. Product telemetry is not yet implemented as a customer-facing system. No Customer Personal Data is collected or processed for product telemetry purposes at this time. Should product telemetry be introduced in the future, it will be reflected in an updated version of this DPA with appropriate notice under Section 15.
AI-Assist Inputs. No customer-facing AI features are currently available in the Service. No Customer Personal Data is processed in connection with AI-related functionality. Should AI-powered features be introduced, they will be addressed in an updated DPA with appropriate disclosures regarding data handling and model training exclusions.
E. Special Categories
Runetale does not intentionally process special categories of personal data as defined in Article 9 of the EU GDPR or sensitive personal information as defined in Article 2(3) of APPI. Customer is responsible for ensuring that its use of the Service does not result in the transmission of special category data requiring additional safeguards beyond those provided in this DPA. If Customer becomes aware that special category data has been transmitted through the Service, Customer will notify Runetale promptly so that the parties may discuss appropriate additional technical and organizational measures.
Schedule 2: Technical and Organizational Measures
The following provides an overview of the Security Measures implemented by Runetale with respect to Customer Personal Data. More information is available at the Runetale security page. The Security Measures are subject to technical progress and further development, and Runetale reserves the right to implement alternative measures provided that the overall level of protection is not materially decreased.
Certifications and Standards. Runetale maintains ISO 27001 and ISO 27017 certifications, independently audited on an annual basis. SOC 2 Type II certification is in progress. Certification documentation is available to Customers upon request through Section 9.
Encryption. All peer-to-peer network traffic is end-to-end encrypted using the WireGuard protocol (Noise framework, ChaCha20-Poly1305), with encryption keys generated and stored exclusively on the client device. Control plane communications are encrypted in transit using TLS 1.2 or higher. Persistent storage containing Customer Personal Data is protected by encryption at rest with automatic key rotation.
Identity and Access Control. Customer-facing access is governed by a multi-tier role-based access control model. Authentication is SSO-only via industry-standard identity providers, with no password storage on Runetale servers. Authentication tokens received from identity providers are redacted immediately after the authentication exchange and are never persisted. Internal engineering access requires single sign-on with no long-lived access keys. Access permissions are reviewed periodically and revoked upon role change or departure.
Infrastructure. Production infrastructure operates within a dedicated cloud environment in the Tokyo region with network segmentation between services and a default-deny network access model. Databases reside in private subnets with no public endpoints. Production workloads are isolated from development and staging environments.
Change Management. All changes to production systems require peer review and are logged in an immutable audit trail. Automated rollback is available upon detection of anomalous behavior.
Monitoring and Incident Response. Runetale maintains continuous monitoring within the same region as primary data processing. Administrative actions are logged with source IP, operator identity, action performed, and timestamp. Retention periods for monitoring data are described in the Documentation. Runetale maintains a documented incident response plan including automated detection, structured investigation, defined containment procedures, and root cause analysis.
Data Minimization and Privacy by Design. Runetale's architecture is designed so that Traffic Payload is not accessed in plaintext by Runetale systems through the standard data plane — an engineering constraint embedded in the system design rather than a policy commitment. Certain telemetry identifiers are pseudonymized via a one-way cryptographic transformation before ingestion to reduce direct identifiability. Telemetry collection is disabled by default and can only be enabled for paid plans. Account deletion removes Customer Personal Data from active production systems.
Personnel. All Runetale personnel with access to Customer Personal Data are subject to written confidentiality agreements that survive termination of employment. Access to production systems is limited to personnel with a demonstrated business need (principle of least privilege). Security awareness training is provided upon onboarding and on a recurring annual basis. Access is revoked promptly upon role change or departure, with automated deprovisioning.
Schedule 3: Subprocessors
Runetale's current Subprocessor List is available at the Runetale Subprocessors page and is incorporated into this DPA by reference. The Subprocessor List identifies each Subprocessor's entity name, service description, data categories processed, and primary processing location.
For the avoidance of doubt, services used for Runetale's own Controller activities as described in Section 2.2 (such as website analytics and customer relationship management) do not involve the processing of Customer Personal Data under this DPA.
Update Procedure
Changes to the Subprocessor list will be notified in accordance with Section 5.4 (30 days' prior written notice). The authoritative current list is maintained at the Runetale Subprocessors page.
Schedule 4: EU SCCs Completion Details
This Schedule 4 applies only where the Standard Contractual Clauses are incorporated pursuant to Part C of this DPA.
Annex I(A): List of Parties. The data exporter is Customer (as identified in Schedule 1.A). The data importer is Runetale Inc. (as identified in Schedule 1.A). The contact details, activities relevant to the transfer, role, and signature details of each party are as set out in Schedule 1.A and the Agreement.
Annex I(B): Description of Transfer. The categories of Data Subjects, types of Personal Data transferred, frequency of transfer, nature and purpose of processing, retention period, and subject matter of the processing are as described in Schedule 1.B and Schedule 1.C of this DPA.
Annex I(C): Competent Supervisory Authority. The competent supervisory authority in accordance with Clause 13 of the SCCs is the Irish Data Protection Commission (An Coimisiún um Chosaint Sonraí).
Annex II: Technical and Organizational Measures. The technical and organizational measures implemented by the data importer (including any relevant certifications) to ensure an appropriate level of security are as described in Schedule 2 of this DPA.
Annex III: List of Sub-processors. General authorization is granted pursuant to Section 5 of this DPA. The current list of Sub-processors authorized by the data exporter is set out in Schedule 3 of this DPA.