In effect as of 21 July 2026.
This Data Processing Agreement (the "DPA") forms part of the Terms of Use between Cohesium AI ("Processor") and the customer ("Controller"). It governs the processing of personal data that the Controller submits to the Tonael service, and is concluded pursuant to Article 28(3) of Regulation (EU) 2016/679 (GDPR).
Article 1 — Roles of the Parties
Where the customer submits audio or lyrics relating to identifiable individuals other than itself (for example, its own end users' recordings), the customer acts as Controller and Cohesium AI acts as Processor on its behalf. This DPA governs that processing.
Cohesium AI remains an independent Controller for the data it processes for its own purposes: account management, authentication, billing, security and fraud prevention, and aggregate service statistics. That processing is described in the Privacy Policy and is not governed by this DPA.
Where the customer submits only content relating to itself, or content containing no personal data, no controller-to-processor relationship arises and this DPA does not engage.
Article 2 — Subject Matter, Duration, Nature and Purpose
Subject matter: the forced alignment of lyrics to audio, producing word-level and character-level timestamps.
Duration: for the term of the Terms of Use, and for each item of content, the retention period set out in Article 8.
Nature of the processing: automated reception, decoding, machine analysis, temporary storage and return of results. No human review of content takes place in the ordinary course.
Purpose: solely to deliver the alignment result requested by the Controller.
Article 3 — Types of Personal Data and Categories of Data Subjects
Types of personal data: audio recordings, which may contain the voice of an identifiable person; lyrics text, which may contain personal data if the Controller includes any; and the technical metadata associated with a request (timestamps, duration, model used).
Categories of data subjects: the individuals whose voices appear in the audio submitted, and any individuals referred to in the lyrics submitted — typically the Controller's artists, performers or end users.
Special categories (Art. 9): the Service is not designed for special-category data. A voice recording may, depending on the processing applied to it, be capable of identifying a person; Cohesium AI does not perform biometric identification, biometric categorisation or emotion recognition, and does not derive a voiceprint. The Controller undertakes not to submit special-category data without an appropriate legal basis of its own.
Article 4 — Instructions (Art. 28(3)(a))
Cohesium AI processes the Controller's personal data only on the Controller's documented instructions, including as regards transfers to a third country. The Controller's instructions are constituted by this DPA, the Terms of Use, and the parameters of each API request.
Cohesium AI shall immediately inform the Controller if, in its opinion, an instruction infringes the GDPR or another data protection provision.
Cohesium AI does not use the Controller's content to train its models. The optional training programme described in Section 4 of the Privacy Policy operates only where the Controller has expressly opted in, which constitutes a distinct documented instruction, and is withdrawable at any time.
Article 5 — Confidentiality (Art. 28(3)(b))
Cohesium AI ensures that persons authorised to process the personal data are bound by an appropriate obligation of confidentiality, and that access is restricted to those who need it to deliver the Service.
Article 6 — Security (Art. 28(3)(c) and Art. 32)
Cohesium AI implements appropriate technical and organisational measures, including: encryption of data in transit (HTTPS/TLS); password hashing with argon2id; access control and an immutable administrative audit log; segregation between the session plane and the API-key plane; automatic deletion of results at the end of the retention period; and anti-abuse controls.
Cohesium AI takes reasonable steps to ensure the ongoing confidentiality, integrity, availability and resilience of the processing systems, and the ability to restore access in a timely manner following an incident.
Article 7 — Sub-Processors (Art. 28(2) and 28(4))
The Controller grants Cohesium AI a general authorisation to engage sub-processors. The sub-processors engaged as at the effective date of this DPA are:
| Sub-processor | Purpose | Location of processing |
|---|---|---|
| Modal Labs | GPU compute (alignment processing) | European Economic Area — workloads are region-pinned to the EEA |
| Cloudflare R2 | Temporary storage of results | European Union — bucket pinned to the EU jurisdiction |
Cohesium AI shall inform the Controller of any intended addition or replacement of a sub-processor at least thirty (30) days in advance, giving the Controller the opportunity to object. If the Controller objects on reasonable data protection grounds and the parties cannot agree a solution, the Controller may terminate the affected part of the Service and obtain a refund of any unconsumed credit.
Cohesium AI imposes on each sub-processor data protection obligations equivalent to those set out in this DPA, and remains fully liable to the Controller for the performance of that sub-processor's obligations.
The processors used for Cohesium AI's own controller-level purposes (Stripe for payments, Brevo for transactional email, Google and GitHub for optional OAuth sign-in) do not receive the Controller's submitted content and are not sub-processors under this DPA.
Article 8 — Transfers Outside the European Union (Chapter V)
The Controller's submitted content does not leave the European Economic Area. GPU processing is region-pinned to the EEA and temporary result storage is pinned to the European Union jurisdiction.
Should a transfer outside the EEA ever become necessary, Cohesium AI shall not carry it out without first informing the Controller and putting in place an appropriate safeguard within the meaning of Articles 44 et seq. GDPR.
Article 9 — Assistance with Data Subject Rights (Art. 28(3)(e))
Taking into account the nature of the processing, Cohesium AI assists the Controller by appropriate technical and organisational measures, insofar as possible, in fulfilling its obligation to respond to requests to exercise data subject rights under Chapter III GDPR.
Because submitted content is retained only for the short periods set out in Article 11, a request generally resolves through the ordinary operation of those retention limits. Where a request requires specific action, Cohesium AI responds to the Controller within ten (10) working days. If a data subject contacts Cohesium AI directly regarding content submitted by a Controller, Cohesium AI does not respond on the substance and refers the data subject to the Controller.
Article 10 — Assistance with Articles 32 to 36 (Art. 28(3)(f))
Cohesium AI assists the Controller in ensuring compliance with the obligations under Articles 32 to 36 GDPR, taking into account the nature of the processing and the information available to it.
Personal data breach: Cohesium AI notifies the Controller without undue delay and at the latest within forty-eight (48) hours of becoming aware of a personal data breach affecting the Controller's data, providing the information the Controller reasonably requires to meet its own obligations under Articles 33 and 34.
Article 11 — Deletion or Return of Data (Art. 28(3)(g))
| Data | Retention |
|---|---|
| Submitted audio and lyrics, and the alignment results | 24 hours after processing (72 hours for batch jobs), then automatically deleted |
| Request metadata (timestamps, duration, model, amount charged — no content) | 90 days |
At the end of the provision of the Service, Cohesium AI deletes the Controller's personal data, unless Union or Member State law requires storage. The results remain downloadable by the Controller throughout the retention window above, which constitutes the return of the data.
Article 12 — Audits and Demonstration of Compliance (Art. 28(3)(h))
Cohesium AI makes available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR, and allows for and contributes to audits, including inspections, conducted by the Controller or another auditor mandated by it.
Audits are conducted at reasonable intervals (not more than once per twelve-month period, save following a personal data breach), on at least thirty (30) days' written notice, during business hours, without disrupting the Service, and subject to the auditor accepting appropriate confidentiality obligations.
Article 13 — Liability and Governing Law
Each party's liability under this DPA is subject to Article 82 GDPR. This DPA is governed by French law. In the event of a conflict between this DPA and the Terms of Use, this DPA prevails in respect of the processing of the Controller's personal data.
Article 14 — Contact
For any question relating to this DPA or to exercise a right hereunder: contact@tonael.com.