Data Processing Addendum
Effective date: 7 July 2026 · Version 1.0
This Data Processing Addendum ("DPA") forms part of the
Typegate Terms of Service between
Typegate (typegate.ch), United States
("Typegate", the "Processor") and the customer accepting the Terms (the
"Customer", the "Controller"). It applies to the extent Typegate processes personal
data on the Customer's behalf in providing the Service, and is entered into automatically upon
acceptance of the Terms – no signature is required. Customers who require a signed copy can request
one at hello@typegate.ch.
1. Roles and scope
- Typegate as processor. Typegate processes "Customer Data" -
content the Customer uploads to the Service (font software and its metadata) and any personal
data contained in it – solely on the Customer's documented instructions.
- Typegate as independent controller. Typegate acts as an independent controller
for: (a) the Customer's own account data (email, credentials, foundry name, settings); and (b)
trial-protection telemetry the Service collects from trial users (aggregate CDN load counters and
Figma plugin import records), which Typegate collects for its own purpose of operating and
protecting the platform, as described in the Privacy Policy. Such
processing is outside the scope of this DPA.
- "Data protection law" means the Swiss FADP and, where applicable, the EU/UK GDPR.
2. Customer instructions
The Customer's complete and final instructions are: processing as needed to provide the Service as
described in the Terms and the Service's documentation (hosting, storing, transforming – including
subsetting, instancing and format conversion – caching, and delivering trial versions of uploaded
content). Additional instructions require mutual written agreement. Typegate will inform the Customer
if, in its opinion, an instruction infringes data protection law.
3. Typegate's obligations as processor
Typegate shall:
- process Customer Data only on documented instructions, including with regard to transfers to
third countries, unless required to do otherwise by law (in which case Typegate will inform the
Customer before processing, unless the law prohibits it);
- ensure that persons authorised to process Customer Data are bound by confidentiality;
- implement appropriate technical and organisational measures as described in Annex II and on the
Security page;
- respect the subprocessor conditions in Section 4;
- taking into account the nature of the processing, assist the Customer with appropriate measures
in fulfilling data subject requests (access, rectification, erasure, restriction, portability,
objection);
- assist the Customer in ensuring compliance with its obligations regarding security, breach
notification, data protection impact assessments and prior consultation, taking into account the
information available to Typegate;
- notify the Customer without undue delay after becoming aware of a personal
data breach affecting Customer Data, providing the information reasonably required for the
Customer's own notification obligations as it becomes available;
- at the Customer's choice, delete or return all Customer Data after the end of the provision of
the Service, and delete existing copies unless law requires storage. Deleting a font or the
account in the dashboard permanently removes the underlying stored objects and database
records;
- make available the information necessary to demonstrate compliance with this DPA and, at the
Customer's reasonable request (no more than once per year, at the Customer's cost, under
confidentiality), allow for and contribute to audits, which shall in the first instance be
satisfied through documentation and third-party attestations of Typegate's infrastructure
providers.
4. Subprocessors
- The Customer grants Typegate general authorisation to engage subprocessors for
the processing of Customer Data. The current list is published at
typegate.ch/legal/subprocessors.
- Typegate will update that page at least 14 days before adding or replacing a
subprocessor. The Customer may object on reasonable data-protection grounds within that period;
if the objection cannot be resolved, the Customer may terminate the affected Service and delete
its data as its exclusive remedy.
- Typegate imposes data protection obligations on each subprocessor that are materially
equivalent to those in this DPA and remains liable for its subprocessors' performance.
5. International transfers
Typegate is based in the United States, and Customer Data is processed on Cloudflare's global edge
network, so it may be processed outside Switzerland and the EEA. Where Customer Data originating in
Switzerland or the EEA is transferred to a country without an adequacy decision, the transfer is
protected by the EU Standard Contractual Clauses (Module 2 or 3, as applicable) with the Swiss
addendum, and/or the subprocessor's certification under the EU–US / Swiss–US Data Privacy Framework,
as identified on the Subprocessor List.
6. Liability and precedence
Liability under this DPA is subject to the limitations of liability in the Terms. In case of
conflict between this DPA and the Terms regarding the processing of personal data, this DPA
prevails. If mandatory data protection law requires stricter terms, the stricter terms apply.
7. Term
This DPA applies for as long as Typegate processes Customer Data and terminates automatically upon
deletion of all Customer Data.
Annex I – Description of processing
Annex II – Technical and organisational measures
- Encryption in transit (TLS) for all endpoints and encryption at rest on the storage services
used.
- Private object storage; trial files reachable only through tokenised, revocable URLs; per-font
and per-account suspension controls.
- Credential protection: salted, iterated password hashing; short-lived, single-purpose email
tokens; sessions revocable server-side.
- Staff access to administrative functions restricted to authorised personnel via single sign-on
with server-side re-verification; every mutating administrative action is written to an audit
log.
- Runtime isolation and patching delegated to a managed serverless platform; no self-managed
servers.
- Data minimisation by design: no analytics trackers; CDN statistics aggregated without IP
addresses; raw IP addresses not persisted.
Further detail: typegate.ch/legal/security.
Annex III – Authorised subprocessors
As published and maintained at typegate.ch/legal/subprocessors.