Data Processing Agreement
Effective Date: June 17th, 2026
Last Updated: September 9th, 2026
Introduction
This Data Processing Agreement ("DPA") is incorporated into and forms part of the ToolPool.Garden Terms of Service ("Principal Agreement") between you, the Customer, and IllumAlign LLC, operator of the ToolPool.Garden platform ("ToolPool.Garden").
For most personal data processed through the platform, IllumAlign LLC determines the purposes and means of processing and therefore acts as the data controller, as described in our Privacy Policy. This DPA applies where the opposite is true: where you use the platform on behalf of an organization, club, association, or other entity that itself qualifies as a data controller of personal data processed through the platform (for example, the contact details of people your pool invites or administers). In that case you are the "Data Controller" or "Customer" and ToolPool.Garden acts as the "Data Processor".
This DPA is intended to satisfy the service-provider and data-processing contract requirements of applicable data protection and privacy laws. This agreement lays down the rights and obligations of both parties regarding the processing of personal data.
1. Definitions and Interpretation
Unless otherwise defined herein, capitalized terms in this DPA shall have the meaning given to them under applicable Data Protection Laws. The terms of the Principal Agreement shall apply to this DPA.
-
Customer Personal Data: Any Personal Data Processed by ToolPool.Garden on behalf of the Customer in connection with the Principal Agreement.
-
Data Protection Laws: All applicable laws and regulations relating to privacy and data protection, including applicable U.S. federal and state privacy laws such as the California Consumer Privacy Act (CCPA) and, where it applies, the EU General Data Protection Regulation (GDPR).
-
Services: The ToolPool.Garden tool-sharing platform and related services provided by ToolPool.Garden as described in the Principal Agreement, through which members form pools, list tools, and coordinate borrows.
-
Sub-processor: Any third party appointed by ToolPool.Garden to process Customer Personal Data.
2. Processing of Customer Personal Data
ToolPool.Garden shall comply with all applicable Data Protection Laws in the Processing of Customer Personal Data and shall not Process Customer Personal Data other than on the Customer's documented instructions, unless required to do so by applicable law.
The Customer instructs ToolPool.Garden to process Customer Personal Data to provide the Services as described in the Principal Agreement and this DPA. The details of the processing are described in Annex 1.
3. Processor Personnel
ToolPool.Garden shall take reasonable steps to ensure the reliability of any employee, agent, or contractor who may have access to the Customer Personal Data, ensuring that access is strictly limited to those individuals who need to know or access the relevant data for the purposes of the Principal Agreement. All such individuals shall be subject to confidentiality undertakings or professional or statutory obligations of confidentiality.
4. Security
Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of Processing, ToolPool.Garden shall implement and maintain appropriate technical and organizational measures to ensure a level of security appropriate to the risk, as required by applicable Data Protection Laws. This includes protecting data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access.
5. Sub-processing
The Customer provides a general written authorization for ToolPool.Garden to engage Sub-processors to support the provision of the Services. ToolPool.Garden shall maintain an up-to-date list of its Sub-processors, which is available in our Privacy Policy.
ToolPool.Garden will inform the Customer of any intended changes concerning the addition or replacement of other Sub-processors, by sending an email to the email address on file for the Customer's pool or user account, thereby giving the Customer the opportunity to object to such changes. If the Customer objects on reasonable grounds, the parties will work together in good faith to find a mutually acceptable resolution.
ToolPool.Garden engages each Sub-processor under a data-processing agreement. This is either the Sub-processor's own data-processing addendum, incorporated by reference into ToolPool.Garden's agreement with it, or a separately signed agreement. The basis that applies to each Sub-processor is noted alongside it in the Sub-processor list in the ToolPool.Garden Privacy Policy.
6. Data Subject Rights
Taking into account the nature of the Processing, ToolPool.Garden shall assist the Customer by implementing appropriate technical and organizational measures, insofar as this is possible, for the fulfilment of the Customer's obligation to respond to requests from Data Subjects to exercise their rights under Data Protection Laws.
ToolPool.Garden shall promptly notify the Customer if it receives a request from a Data Subject concerning Customer Personal Data and shall not respond to the request except on the documented instructions of the Customer or as required by applicable law.
7. Personal Data Breach
ToolPool.Garden shall notify the Customer without undue delay upon becoming aware of a Personal Data Breach affecting Customer Personal Data. ToolPool.Garden will provide the Customer with sufficient information to allow the Customer to meet its obligations to report or inform Data Subjects of the breach.
ToolPool.Garden shall cooperate with the Customer and take reasonable commercial steps as directed by the Customer to assist in the investigation, mitigation, and remediation of each such breach.
8. Data Protection Impact Assessment and Prior Consultation
ToolPool.Garden shall provide reasonable assistance to the Customer with any data protection impact assessments and prior consultations with regulatory authorities, which the Customer reasonably considers to be required by applicable Data Protection Laws, in each case solely in relation to Processing of Customer Personal Data by ToolPool.Garden.
9. Deletion or Return of Customer Personal Data
Upon termination of the Principal Agreement, ToolPool.Garden shall, at the Customer's choice, delete or return all Customer Personal Data. If the Customer makes no choice, the data will be deleted in line with the deletion and retention practices described in the Principal Agreement and the Privacy Policy. Data deleted from live systems may persist in rolling database backups until those backups expire.
10. Audit Rights
ToolPool.Garden shall make available to the Customer on request all information necessary to demonstrate compliance with this DPA and allow for and contribute to audits, including inspections, by the Customer or an auditor mandated by the Customer, provided such audits are conducted during regular business hours, with reasonable advance notice, and do not unreasonably interfere with ToolPool.Garden's business activities.
11. Data Transfers
ToolPool.Garden operates in the United States, and Customer Personal Data is stored and processed in the United States. Some Sub-processors may process data in other countries to provide their services. Where a Sub-processor processes Customer Personal Data across borders, ToolPool.Garden relies on the safeguards included in that Sub-processor's standard data-processing terms.
12. General Terms
Confidentiality: The parties shall maintain the confidentiality of information exchanged under this DPA as outlined in the Principal Agreement.
Status of Negotiated Compliance Agreements: This DPA is offered as-is, by incorporation into the Principal Agreement, and is today the only data-processing agreement ToolPool.Garden enters into. ToolPool.Garden does not yet sign individually negotiated data-processing agreements, HIPAA Business Associate Agreements (BAAs), or similar dedicated compliance agreements, though it may offer them in the future. Until such an agreement is in place with you, the Services must not be used to process data that requires one: for example, protected health information.
Governing Law and Jurisdiction: This DPA is governed by the laws of the State of South Carolina. Any dispute arising in connection with this DPA will be subject to the jurisdiction of the courts of Greenville County, South Carolina, as specified in the Principal Agreement.
Annex 1: Details of Data Processing
Subject-matter of the Processing
The subject-matter of the Processing is the provision of the Services by ToolPool.Garden to the Customer, as detailed in the Principal Agreement.
Duration of the Processing
The Processing will continue for the duration of the Principal Agreement, and until the data is deleted in accordance with the terms of this DPA.
Nature and Purpose of the Processing
The purpose of the Processing is to enable ToolPool.Garden to provide the Services, which include: enabling the Customer to create and manage pools, their membership, and their settings; inviting people to join a pool; listing tools and skills into pools, coordinating borrows and teaching through one-on-one chats, and letting members of a pool message one another directly; managing each pool's recurring subscription, its designated subscriber, and payment records; and operating, securing, and improving the Service.
Categories of Data Subjects
- Pool admins and members
- People invited to join a pool
- Tool owners and borrowers
- Skill teachers and learners
- The designated subscriber who pays for a pool
- Visitors who use the anonymous 3D sign generator
-
People who file reports, people a report is about, and people who process them
Types of Personal Data
-
Anonymous Sign Generator Data: The PNG or JPG artwork and settings a visitor submits, the generated STL and 3MF models, preview, filament-change instructions, job status and timestamps, and a hash of the job's access token. The source image is cleared when success or failure is recorded. Access expires 1 hour from submission, and the remaining row is removed by the next successful scheduled cleanup; an outage can delay deletion. The row has no account identifier or IP address. Separate in-memory rate-limit counters hold the proxy-provided IP address, route, count, window, and expiry through their minute or daily window and for no more than 10 minutes afterward.
-
Account and Profile Data: Name, display name, email address, hashed password, two-factor authentication settings (chosen method and, for the authenticator-app method, the verification secret and the time the last code was accepted; emailed login codes are stored only as short-lived hashes, and one-time recovery codes only as hashes), the Google account identifier of a user who has chosen to log in with Google, a record that the 18+ age check passed (the birth date used for the check is not stored), and optional profile details such as avatar, bio, and social links.
-
Pool Data: Pool name, description, an optional logo image, pinned geographic location, membership, roles, and settings, including the date the pool was created (shown as a month and year on the pool's page and wherever it is listed) and the date each membership and each tool or skill share began (which a pool's own members see as its activity feed).
-
Session Data: For each browser a user is signed in on, the time they signed in, the time that device was last used, and the browser identification string their browser sends, which names the browser and its operating system. It is shown back to that user in their own account settings so they can log a device out, and is deleted when the session is logged out, or within a day of its sixty-day expiry.
-
Device Location: Where a user presses the pool list's "Sort by distance" button, the coordinates their browser's geolocation prompt supplies, received solely to order that list by proximity and held in memory for the life of that page; it is not stored, associated with the account, or included in the page's web address.
-
API Token Data: For each token a user creates so that a program can act as their account, the name they gave it, when it was created, and when it was last used; the token itself is held only as a hash and is shown to the user once, at creation. A token is revoked by its own user in their account settings and does not expire on its own. Where a user gives a token to an outside program, that program acts with the user's own access and is that user's own choice of processor rather than a Sub-processor engaged by ToolPool.Garden.
-
Connected App Data: Where a program obtains access by asking the user to allow it on a page here rather than by taking a token, a record of which program the user allowed: the name and web address it supplied when it registered itself, neither of which is verified, together with when they allowed it and when it last acted. The credentials it uses are held only as hashes, are short-lived, and are renewed as it works. The user disconnects it in their account settings, which stops its access at once. Such a program acts with the user's own access and is that user's own choice of processor rather than a Sub-processor engaged by ToolPool.Garden.
-
-
Chat App Connection Data: Where a user connects a Slack or Discord account, the identifiers that platform uses for the user, its workspace or server, and the group channel if they connected from one; its name; when they connected and when it last acted; whether request posts are on; and whether the platform reports permission to post. Separately, when a Slack workspace installs the app, ToolPool.Garden stores the workspace identifier and name, the permissions it granted, and its encrypted bot token. The one-use link that creates a connection is held only as a hash, lasts fifteen minutes, and unfinished links are deleted daily. A connected chat app can search public tools, skills, and requests in the user's selected pools. It also posts new public requests to the saved group channel by default; the user can move or turn off those posts. Searches and automatic posts carry no owner's identity, and an automatic request post leaves out its poster's identity too. Search words, replies, and automatic posts pass through Slack or Discord, which are the user's own choice of platform rather than Sub-processors engaged by ToolPool.Garden. The user can disconnect it in account settings or from the chat app, which stops its access at once.
Photo Upload Link Data: Where a program acting as a user asks for a link to upload a photo to one of that user's own listings, a record of the link: a hash of it, which listing it is for, how many uploads remain on it, and when it expires. A link lasts about fifteen minutes, covers a small number of photos on that one listing, and permits nothing else. Revoking a token, disconnecting an app, or connecting that app again cancels every upload link on that user's account, because a link does not record which app asked for it. Expired links are deleted daily.
-
Tool, Skill, Request, and Borrow Data: Tool and skill listings and member requests (names/titles, descriptions, photos, and pool visibility; embedded metadata such as EXIF and GPS location is stripped from uploaded photos during processing and the original is not retained), borrow, teaching, and request-response chat messages, direct and pool-admin messages between members of a pool, discussion checklist state, reveal and hide records, and reviews.
-
Payment Data: Stripe and Dodo Payments customer, subscription, payment, and discount references, the raw event payload from the payment provider, amounts, pool ledger entries including subscription charges and refunds, and the email address and pool and account identifiers shared with the payment provider to initiate a subscription checkout.
-
Legal Records: Terms of Service and Liability Waiver acceptances, comprising the document version, the typed signature, and timestamps.
-
Notification Data: Per-user delivery preferences for each notification type (email on or off, browser push on or off), and, for each browser where the user has turned browser notifications on, the push-service address that browser supplied, the two keys used to encrypt notifications to it, and a browser description.
-
Announcement Read Data: For each platform announcement a user marks read on their home page, a record that they marked it and when. It orders that user's own view of the announcement carousel and is not shown to anyone else. Unmarking a card removes the record, and it is deleted with the account or with the announcement it refers to.
-
Export Data: Data exports initiated by users, including status, expiration, the data for export, a token for access, and the stored archive the export is delivered as, which holds that data as a JSON file together with a copy of each image it refers to. The archive is stored privately, is downloadable only by the user it belongs to while signed in, and is deleted with the export record when it expires, which takes a day.
-
Invite Data: Email addresses and optional first and last names for invitations, invite tokens, per-pool join codes, and associated pool and user IDs. An accepted invitation is retained, stamped with the date it was accepted, and where an account was created from one, the account records which invitation that was. The name on an invitation is the one the inviter supplied, and is not reconciled with the name the invitee later registers under.
-
Report and Moderation Data: Reports filed about users, chat messages, pools, reviews, tools, skills, or requests, including the reporter's identity, the free-text reason, a reference to the reported content and its author, and processing notes and outcomes. A report is disclosed to the admins of the pools it is routed to and to ToolPool.Garden, and to no one else. It is not included in a copy of a data subject's data, including in response to an access request, under Article 15(4): a report written about someone would in many cases identify its author to that person however it were redacted, and the people who file reports do so in confidence.
-
Audit and Usage Data: Audit-log events (such as moderation actions, legal acceptances, and reveal events), IP address, browser type, pages visited, and interaction data.
-
Error and Session Diagnostics: Application error reports (browser and request details, the account identifier and email address of a signed-in user, recent in-page actions and submitted form values with credentials removed, and, with consent, IP address), performance measurements (server-side request timings for a sample of requests, and, with consent, page-load and navigation timings measured in the browser), and, with consent, masked session replays reconstructing page interactions, processed by Sentry.
-
Advertising Measurement Data: Only for data subjects who have given advertising consent, the click identifier carried by an ad they arrived through (the Reddit identifier stored on the account for 28 days from the click, the Google identifier for 90 days, each being that provider's attribution window), the record that consent was given and when, and the lifecycle events reported to Reddit and to Google, comprising the event type and time, the click identifier, the amount for a subscription charge, and the data subject's email address and account identifier in irreversibly hashed form. The events are registration, email confirmation, joining or creating a first pool, setting up a subscription, and a subscription charge. Google receives all five; Reddit receives four, email confirmation being withheld from it because Reddit offers no means of acting on that event. A data subject may withdraw this at any time from the 'Ad measurement' setting on their account, which stops further reporting and erases both stored click identifiers and the consent record. Where a provider offers a means of erasing what it already holds, the request is also forwarded to it: Reddit exposes a data deletion interface, so the request is submitted automatically and resolved within thirty days. Google provides no means of deleting an advertising event once sent, so no request is forwarded there, and ToolPool.Garden raises one with Google directly on a data subject's request. Reddit and Google Ads are advertising partners rather than Sub-processors: each determines its own purposes for this data, so neither is processing it on ToolPool.Garden's behalf. (Google Workspace, listed as a Sub-processor, is a separate relationship with the same company.)
Sub-processors
The Sub-processors engaged by ToolPool.Garden are listed in the ToolPool.Garden Privacy Policy. That list also names Reddit and Google Ads, which are identified there as advertising partners rather than Sub-processors and are not engaged to process Customer Personal Data on ToolPool.Garden's behalf.