Data Processing Addendum

Effective August 30, 2026Version 1.0

This Data Processing Addendum ("DPA") forms part of the Customer Terms between Tessryx LLC ("Tessryx") and the customer that has accepted or entered into the Customer Terms ("Customer"). This DPA applies to the extent Tessryx processes Customer Personal Data on Customer's behalf in connection with the Services.

Customer may act as a controller or processor of Customer Personal Data, as applicable, and Tessryx may act as a processor or subprocessor, as applicable. This DPA sets out the parties' respective obligations concerning that processing under applicable Data Protection Laws.

Capitalized terms not defined in this DPA have the meanings given in the Customer Terms.

#1. Definitions

For purposes of this DPA:

"CCPA" means the California Consumer Privacy Act of 2018, as amended, and its implementing regulations.

"Customer Personal Data" means Personal Data contained in Customer Content that Tessryx processes on behalf of Customer in connection with the Services.

"Data Protection Laws" means all data protection and privacy laws applicable to the processing of Customer Personal Data under this DPA, including, where applicable, the GDPR, UK GDPR and applicable United Kingdom data protection legislation, the Swiss FADP, and the CCPA.

"GDPR" means Regulation (EU) 2016/679, the General Data Protection Regulation.

"Personal Data" means any information relating to an identified or identifiable natural person and includes "personal information" or an equivalent concept where applicable under Data Protection Laws.

"Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data.

"Services" has the meaning given in the Customer Terms.

"Subprocessor" means a third party engaged by Tessryx to process Customer Personal Data on behalf of Customer in connection with the Services.

"UK GDPR" means the GDPR as it forms part of the law of the United Kingdom.

Terms such as "controller," "processor," "processing," "data subject," and "supervisory authority" have the meanings assigned to them by the GDPR where the GDPR applies and the corresponding meanings under other applicable Data Protection Laws. Where the CCPA applies, "Business," "Service Provider," "sell," and "share" have the meanings assigned to them by the CCPA.

#2. Scope and Roles of the Parties

This DPA applies only to Tessryx's processing of Customer Personal Data on Customer's behalf in connection with the Services.

Where Customer determines the purposes and means of processing Customer Personal Data, Customer acts as controller and Tessryx acts as processor. Where Customer processes Customer Personal Data on behalf of another controller, Customer acts as processor and Tessryx acts as subprocessor.

Where Customer acts as a processor on behalf of another controller, Customer represents that it is authorized to appoint Tessryx as a subprocessor and to provide instructions to Tessryx concerning the processing of Customer Personal Data on behalf of that controller.

To the extent the CCPA applies and Customer is a Business, Tessryx acts as a Service Provider with respect to Customer Personal Data processed on Customer's behalf.

Tessryx acts as an independent controller with respect to Personal Data that it processes for its own account administration, billing, security, fraud prevention, service operation, and similar business purposes, as described in the Tessryx Privacy Policy. This DPA does not govern Tessryx's processing of Personal Data in that independent capacity.

#3. Processing Instructions

Tessryx will process Customer Personal Data only:

(a) to host, store, structure, retrieve, transmit, cache, render, secure, support, and delete Customer Personal Data as necessary to provide the Services described in the Customer Terms and Annex A;

(b) in accordance with Customer's documented instructions, including the Customer Terms, this DPA, Customer's configuration and use of the Services, and other documented instructions agreed by the parties; or

(c) as required by applicable law, in which case Tessryx will inform Customer of the applicable legal requirement before processing unless applicable law prohibits Tessryx from doing so.

Customer instructs Tessryx to process Customer Personal Data as reasonably necessary to provide and secure the Services and to perform the processing activities described in this DPA and Annex A.

If Tessryx reasonably believes that a Customer instruction infringes applicable Data Protection Laws, Tessryx will inform Customer and may suspend the affected processing to the extent reasonably necessary while the parties address the issue.

Tessryx will not process Customer Personal Data for its own advertising purposes or use Customer Personal Data to train machine learning or artificial intelligence models.

#4. Customer Responsibilities

Customer is responsible for ensuring that its processing of Customer Personal Data and its instructions to Tessryx comply with applicable Data Protection Laws. Without limiting that responsibility, Customer is responsible for:

(a) the lawfulness of Customer Personal Data submitted to the Services and the instructions it provides to Tessryx;

(b) establishing and maintaining any legal basis required for Customer's collection and processing of Customer Personal Data;

(c) providing legally required privacy notices and obtaining any consent or authorization required by applicable law;

(d) the accuracy, quality, and legality of Customer Personal Data;

(e) determining whether the Services are appropriate for Customer's intended processing activities;

(f) configuring Customer's sites, applications, forms, workflows, permissions, integrations, and access controls appropriately; and

(g) complying with the restrictions contained in the Acceptable Use Policy, including restrictions on categories of data that the Services are not designed or authorized to process.

Customer is responsible for its relationship with visitors to and members of sites it operates through the Services. This includes responsibility for records Customer creates or maintains using identifiers provided through the Services, information Customer independently collects about those individuals, and any linkage Customer creates between those records.

Customer is responsible for responding to requests relating to Customer's own processing of Personal Data. Customer remains responsible for Personal Data it collects or controls after a visitor stops using Customer's site or a member leaves Customer's workspace.

#5. CCPA Service Provider Terms

To the extent Tessryx processes Customer Personal Data as a Service Provider on behalf of Customer under the CCPA, the following additional terms apply.

Tessryx will process Customer Personal Data only for the specific business purposes described in this DPA, including providing, hosting, securing, supporting, maintaining, and improving the operation and reliability of the Services on Customer's behalf, and as otherwise permitted by the CCPA.

Tessryx will not:

(a) sell or share Customer Personal Data;

(b) retain, use, or disclose Customer Personal Data for any purpose other than the specific business purposes described in this DPA or as otherwise permitted by the CCPA;

(c) retain, use, or disclose Customer Personal Data outside the direct business relationship between Customer and Tessryx, except as permitted by the CCPA; or

(d) combine Customer Personal Data with Personal Data received from or on behalf of another person, or collected from Tessryx's own interaction with a consumer, except to the extent permitted by the CCPA.

Tessryx certifies that it understands the restrictions imposed by this Section and will comply with them.

Tessryx will notify Customer if it determines that it can no longer meet its applicable obligations under the CCPA. To the extent provided by applicable law, Customer may take reasonable and appropriate steps to help ensure that Tessryx processes Customer Personal Data consistently with Customer's CCPA obligations and may take reasonable and appropriate steps to stop and remediate unauthorized use of Customer Personal Data.

Tessryx will reasonably cooperate with Customer in connection with applicable CCPA compliance obligations concerning Customer Personal Data, including any cybersecurity audit or risk assessment to the extent required by applicable law and reasonably related to Tessryx's processing.

Nothing in this Section prohibits Tessryx from processing Customer Personal Data as otherwise expressly permitted for a Service Provider under the CCPA.

#6. Restricted and Sensitive Data

The Services are not designed or authorized for the processing of categories of regulated or sensitive data prohibited by the Acceptable Use Policy.

Customer must not submit, store, transmit, or otherwise process through the Services any category of data prohibited by the Acceptable Use Policy, including health information subject to specialized health privacy laws, payment card data, government-issued identifiers, financial account numbers, biometric identifiers, Personal Data concerning children under 13, or other prohibited regulated data.

Customer must not process special categories of Personal Data within the meaning of Article 9 of the GDPR through the Services unless Tessryx has expressly agreed in writing to such processing and the parties have implemented any additional safeguards or contractual terms Tessryx reasonably requires.

Customer's submission of prohibited data does not expand the agreed scope or purpose of the Services, modify Tessryx's role under this DPA, or constitute Tessryx's agreement that the Services are designed or authorized to satisfy a specialized legal or regulatory regime.

Customer remains responsible for determining whether its proposed use of the Services is permitted under applicable law and the Acceptable Use Policy.

Nothing in this Section excludes or limits any responsibility of Tessryx that cannot lawfully be excluded or limited under applicable Data Protection Laws.

#7. Customer-Directed Third-Party Services

Customer may configure the Services to transmit Customer Personal Data to third-party systems selected by Customer, including through APIs, webhooks, integrations, external applications, and artificial intelligence providers connected using Customer-selected accounts or credentials.

Where Customer directs such a transmission, Tessryx processes and transmits the applicable Customer Personal Data on Customer's documented instruction.

A third-party provider independently selected and configured by Customer is not a Tessryx Subprocessor merely because the Services enable Customer to transmit information to, receive information from, or interact with that provider. Customer is responsible for evaluating the provider, determining the provider's role under applicable Data Protection Laws, establishing any required legal basis or contractual terms, and determining the scope of information transmitted.

The same principles apply where Customer authorizes a third-party service, application, AI assistant, agent, or provider to access Customer Personal Data through an API, MCP server, or other integration made available through the Services.

Tessryx is not responsible under this DPA for the independent processing practices of a Customer-selected third party after Customer Personal Data has been transmitted to or made available to that third party on Customer's instruction, except to the extent responsibility cannot lawfully be excluded under applicable Data Protection Laws.

#8. Confidentiality

Tessryx will ensure that persons authorized to process Customer Personal Data are subject to appropriate contractual or statutory confidentiality obligations.

Access to Customer Personal Data will be limited to personnel who require access to provide, secure, maintain, or support the Services or to perform Tessryx's obligations under this DPA.

Tessryx will maintain appropriate controls designed to prevent unauthorized personnel from accessing Customer Personal Data.

The obligations in this Section continue for so long as Tessryx retains Customer Personal Data.

#9. Security

Taking into account the state of the art, costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risks to the rights and freedoms of natural persons, Tessryx will implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access.

Tessryx's current technical and organizational measures are described in Annex C.

Tessryx may modify its technical and organizational measures from time to time to reflect technological developments, operational changes, and evolving security practices, provided that Tessryx will not materially decrease the overall level of protection afforded to Customer Personal Data during the applicable term.

Customer acknowledges that security is a shared responsibility and is responsible for properly configuring its workspace, permissions, authentication settings, integrations, endpoints, and other features under Customer's control.

#10. Subprocessors

Customer provides Tessryx with general written authorization to engage Subprocessors to process Customer Personal Data in connection with the Services.

Tessryx's current Subprocessors are identified in Annex B and on Tessryx's Subprocessor page.

Tessryx will provide Customer with direct written notice at least 30 days before authorizing a new Subprocessor or replacing an existing Subprocessor that will process Customer Personal Data. Tessryx will also update its Subprocessor page accordingly.

Customer may object to a proposed Subprocessor during the applicable notice period by contacting privacy@tessryx.com and identifying reasonable grounds relating to data protection. Tessryx and Customer will work in good faith to address the objection.

If the parties cannot reasonably resolve the objection, Tessryx may make available an alternative configuration where commercially reasonable. If no reasonable alternative is available, either party may terminate the affected portion of the Services. Where Customer has prepaid fees for the terminated portion of the Services, Tessryx will provide a pro-rated refund of prepaid fees attributable to the unused terminated portion, where applicable.

Tessryx will enter into a written agreement with each Subprocessor that imposes data protection obligations substantially equivalent to the obligations applicable to Tessryx under this DPA with respect to the processing performed by that Subprocessor.

Tessryx remains responsible for its Subprocessors' performance to the extent required by applicable Data Protection Laws.

11. Data Subject Rights

Taking into account the nature of the processing, Tessryx will provide Customer with reasonable assistance through appropriate technical and organizational measures, insofar as reasonably possible, to enable Customer to respond to requests from data subjects exercising rights under applicable Data Protection Laws.

Where functionality within the Services enables Customer to access, retrieve, correct, export, or delete Customer Personal Data, Customer will use that functionality before requesting additional assistance from Tessryx.

If Tessryx receives a request directly from a data subject concerning Customer Personal Data, Tessryx will notify Customer without undue delay and will not substantively respond to the request except on Customer's documented instructions or as required by applicable law. Tessryx may direct the data subject to Customer where appropriate.

Tessryx will provide information reasonably available to it and reasonably necessary to assist Customer in fulfilling applicable obligations concerning data subject requests.

Tessryx may charge reasonable fees for assistance that materially exceeds functionality ordinarily provided through the Services, except to the extent the assistance is required because of Tessryx's breach of this DPA or applicable law provides otherwise.

12. Personal Data Breach

Tessryx will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.

To the extent information is reasonably available to Tessryx, the notification will describe:

(a) the nature of the Personal Data Breach;

(b) the categories and approximate number of affected data subjects, where known;

(c) the categories and approximate number of affected Personal Data records, where known;

(d) the likely consequences of the Personal Data Breach; and

(e) the measures taken or proposed to address the Personal Data Breach, including measures intended to mitigate its possible adverse effects where appropriate.

Where all relevant information is not available at the time of Tessryx's initial notification, Tessryx may provide information in phases as it becomes reasonably available.

Tessryx will provide reasonable cooperation and additional information as it becomes available to assist Customer in meeting applicable breach investigation and notification obligations.

Tessryx's notification of, or response to, a Personal Data Breach is not an acknowledgement of fault or liability.

13. Data Protection Impact Assessments and Regulatory Cooperation

Taking into account the nature of the processing and information available to Tessryx, Tessryx will provide reasonable assistance to Customer with data protection impact assessments relating to Tessryx's processing of Customer Personal Data where such assessments are required by applicable Data Protection Laws.

Tessryx will also provide reasonable assistance with prior consultations with competent supervisory authorities where required by applicable Data Protection Laws and relating to Tessryx's processing of Customer Personal Data.

If a competent supervisory authority contacts Tessryx directly concerning Customer's processing of Customer Personal Data, Tessryx will, to the extent legally permitted and reasonably practicable, notify Customer and reasonably cooperate with Customer concerning the matter.

Nothing in this Section requires Tessryx to disclose information relating to another customer, compromise the security or confidentiality of the Services or another person's information, waive legal privilege, or disclose information that Tessryx is prohibited by law from disclosing.

14. Legally Required Disclosures

If Tessryx receives a binding request from a governmental, regulatory, judicial, law-enforcement, or other public authority requiring disclosure of Customer Personal Data, Tessryx will, to the extent permitted by applicable law, notify Customer before making the disclosure.

Where legally permitted and reasonably appropriate, Tessryx will review the request and limit any disclosure to Customer Personal Data that Tessryx reasonably determines it is legally required to disclose.

If applicable law prohibits Tessryx from notifying Customer, Tessryx may take reasonable steps to seek permission to provide notice where Tessryx determines that doing so is appropriate and legally permissible.

Nothing in this Section requires Tessryx to challenge a lawful request, initiate litigation, or incur material expense unless required by applicable Data Protection Laws or separately agreed with Customer.

Where the SCCs apply, Tessryx will comply with the obligations concerning access by public authorities contained in the applicable SCC module, and the SCCs will control in the event of any conflict with this Section.

15. Return and Export of Customer Personal Data

During the term of the Services, Customer may access and export Customer Personal Data using the functionality Tessryx makes available through the Services.

Depending on the applicable feature and Customer's use of the Services, exportable Customer Content may include schemas, datafiles, workflow and endpoint definitions, applications, and media assets.

Stored secret or credential values are not made available for retrieval or export. Credentials stored through the Services are handled in accordance with the security measures described in Annex C.

Following termination or expiration of the Services, Customer may, during the 90-day post-termination retention period described in Section 16, request an export of Customer Personal Data that is made available for export through the Services.

Tessryx is not required to create a new export format, expose stored credentials or secret values, or reconstruct information that has already been deleted in accordance with Customer's instructions or the applicable retention schedule.

16. Deletion and Retention

Following termination or expiration of the Services involving the processing of Customer Personal Data, Customer may instruct Tessryx to delete Customer Personal Data or may request its return as provided in Section 15.

Unless Customer provides a contrary documented instruction, Customer instructs Tessryx to retain Customer Personal Data for up to 90 days following termination or expiration solely to permit Customer to request an available export and to facilitate orderly account closure. Tessryx will then delete Customer Personal Data from its live systems.

If Customer requests deletion before the end of that period, Tessryx will delete Customer Personal Data from its live systems as soon as reasonably practicable, subject to the residual retention described below and any retention required by applicable law.

Following deletion from live systems, residual copies may remain for limited periods in recovery, versioning, and logging systems before being automatically purged on their ordinary retention cycles, including:

  • up to 35 days in point-in-time recovery data;

  • up to 30 days in retained object versions; and

  • up to 90 days in applicable logs.

Tessryx will not use residual Customer Personal Data retained in those systems for any purpose other than maintaining security, integrity, recovery, or legal compliance. Tessryx will not restore deleted Customer Personal Data from those systems except where necessary to recover from a failure affecting the Services.

Media assets uploaded by Customer are subject to the limitations described in Annex C. Media assets are not versioned or backed up and may not be recoverable after Customer deletes or overwrites them.

Tessryx may retain Customer Personal Data to the extent required by applicable law. Customer Personal Data retained for that purpose will remain subject to the protections of this DPA and will not be processed for another purpose except as required by applicable law.

17. Audits and Demonstration of Compliance

Tessryx will make available to Customer information reasonably necessary to demonstrate compliance with the obligations applicable to Tessryx under this DPA and applicable Data Protection Laws.

Tessryx may satisfy reasonable audit and verification requests by providing relevant third-party audit reports, security certifications, security documentation, written responses, or other compliance materials where those materials reasonably demonstrate compliance.

The availability and disclosure of third-party audit reports and compliance materials are subject to applicable confidentiality, licensing, and distribution restrictions imposed by the relevant provider. Where Tessryx is not permitted to provide a report directly, Tessryx may provide other reasonably available evidence of the applicable certification or assurance status, facilitate access through the provider's authorized process where practicable, or otherwise cooperate as reasonably necessary to demonstrate compliance.

Customer may submit a reasonable written security or compliance questionnaire no more than once in any 12-month period, unless additional information is reasonably required following:

(a) a Personal Data Breach affecting Customer Personal Data;

(b) a material change in Tessryx's processing or security practices relevant to Customer Personal Data;

(c) a reasonable basis to suspect material noncompliance with this DPA;

(d) a requirement imposed by applicable Data Protection Laws; or

(e) a request or requirement of a competent supervisory authority.

Where an on-site or other direct audit is required by applicable Data Protection Laws and the information otherwise provided by Tessryx is not sufficient to satisfy the applicable requirement, the parties will agree in advance on the audit's reasonable scope, timing, duration, and procedures.

Unless prohibited by applicable law, any direct audit will be conducted at Customer's expense, during normal business hours, subject to appropriate confidentiality and security requirements, and in a manner designed to avoid unreasonable interference with Tessryx's operations or compromise the security, confidentiality, or rights of other customers or third parties.

To the extent required by applicable Data Protection Laws, including the CCPA and its implementing regulations, Tessryx will reasonably cooperate with Customer in connection with an applicable cybersecurity audit or risk assessment, including by making available information within Tessryx's possession, custody, or control that Customer reasonably requires to satisfy those obligations.

Any limitations or conditions in this Section apply only to the extent permitted by applicable Data Protection Laws. Nothing in this Section requires Tessryx to disclose another customer's information, waive legal privilege, or compromise the security of the Services.

18. International Data Transfers

Tessryx's primary processing infrastructure is located in the United States. Certain Subprocessors may process or transmit Customer Personal Data through other locations as described in Annex B and Tessryx's Subprocessor page, including through Cloudflare's global edge network.

#18.1 European Economic Area

Where Customer Personal Data subject to the GDPR is transferred to Tessryx in a manner requiring an appropriate transfer mechanism under Chapter V of the GDPR, the parties incorporate by reference the European Commission's Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 ("SCCs").

Module Two (controller to processor) applies where Customer acts as a controller.

Module Three (processor to processor) applies where Customer acts as a processor on behalf of another controller.

For purposes of the applicable SCC module:

(a) Clause 7, the Docking Clause, applies;

(b) under Clause 9, Option 2, general written authorization applies, with the 30-day prior written notice period specified in Section 10 of this DPA;

(c) Clause 11, optional redress, does not apply;

(d) for Clause 17, the SCCs are governed by the law of Ireland;

(e) for Clause 18(b), the courts of Ireland have jurisdiction; and

(f) the information required by the Annexes to the SCCs is provided by Annexes A, B, and C of this DPA, as applicable, together with information contained in the Customer Terms, Customer's account, or applicable order.

To the extent execution information is required for the SCCs, the parties agree that acceptance of the Customer Terms and this DPA constitutes execution of the incorporated SCCs to the extent permitted by applicable law.

If the SCCs conflict with another provision of this DPA or the Customer Terms, the SCCs control with respect to the applicable Restricted Transfer.

#18.2 United Kingdom

Where Customer Personal Data subject to the UK GDPR is transferred to Tessryx in a manner requiring an international transfer mechanism, the then-current UK International Data Transfer Addendum to the EU Commission Standard Contractual Clauses ("UK Addendum") is incorporated into this DPA.

Tables 1 through 3 of the UK Addendum are completed using the information contained in this DPA, its Annexes, the Customer Terms, and Customer's applicable account or order information.

For Table 4, neither party may terminate the UK Addendum solely as a result of an approved change to the UK Addendum.

If the UK Addendum conflicts with this DPA or the Customer Terms concerning a transfer governed by the UK Addendum, the UK Addendum controls to the extent of that conflict.

#18.3 Switzerland

Where Customer Personal Data subject to the Swiss FADP is transferred to Tessryx in a manner requiring an international transfer mechanism, the SCCs apply with the modifications necessary for their use under Swiss data protection law.

References in the SCCs to the GDPR will be interpreted to include the Swiss FADP to the extent appropriate, references to EU or Member State law will be interpreted as necessary for Swiss application, and the competent Swiss data protection authority will apply where required by Swiss law.

#18.4 Transfer Assessments and Supplementary Measures

Each party will reasonably cooperate with the other, taking into account its respective role and information available to it, in assessing international transfers governed by this Section and implementing supplementary safeguards where required by applicable Data Protection Laws.

Nothing in this Section requires Tessryx to disclose information that would compromise the security of the Services or another customer's information, except to the extent disclosure is required under an applicable transfer mechanism or Data Protection Laws.

19. Term and Survival

This DPA becomes effective when Customer becomes bound by the Customer Terms or otherwise agrees to this DPA and remains in effect for as long as Tessryx processes Customer Personal Data on Customer's behalf.

Termination or expiration of the Customer Terms does not relieve either party of obligations under this DPA that, by their nature or under applicable Data Protection Laws, continue while Customer Personal Data remains in Tessryx's possession or control.

Without limiting the foregoing, obligations concerning confidentiality, security, deletion, legally required retention, international transfers, and liability will continue to the extent applicable after termination until the relevant Customer Personal Data has been deleted or otherwise ceases to be subject to those obligations.

20. Liability, Order of Precedence, and General Terms

Each party's liability arising out of or relating to this DPA is subject to the exclusions and limitations of liability set out in the Customer Terms, except to the extent those exclusions or limitations are prohibited by applicable Data Protection Laws or would limit rights or obligations under the SCCs or UK Addendum that cannot lawfully be limited.

Except as expressly modified by this DPA, the Customer Terms remain in full force and effect.

If there is a conflict concerning the processing of Customer Personal Data, the following order of precedence applies to the extent of the conflict:

  1. the SCCs or UK Addendum, where applicable;

  2. this DPA;

  3. the Customer Terms; and

  4. other incorporated policies or documentation, unless a higher-ranking document expressly provides otherwise.

The Acceptable Use Policy remains controlling with respect to categories of content and data that Customer is prohibited from submitting to or processing through the Services.

Any amendment or update to this DPA will be handled in accordance with the amendment provisions of the Customer Terms and applicable Data Protection Laws. Tessryx will not use an update to this DPA to materially reduce the protections applicable to Customer Personal Data during an existing paid service term except where reasonably necessary to comply with applicable law, address a security risk, or reflect a change to the Services that does not materially reduce the overall protection of Customer Personal Data.

Notices concerning this DPA may be provided through the notice mechanisms permitted by the Customer Terms. Privacy and data protection inquiries may be sent to privacy@tessryx.com.

Annex A - Details of Processing

#A.1 Parties and Roles

Data exporter: Customer, acting as a controller for purposes of Module Two of the SCCs or as a processor for purposes of Module Three, as applicable.

Customer's legal name, address, contact details, and applicable data protection contact are the information associated with Customer's account, applicable order, or other agreement with Tessryx.

Data importer: Tessryx LLC, acting as a processor for purposes of Module Two or as a subprocessor for purposes of Module Three, as applicable.

Address: 8605 Santa Monica Blvd #347695, West Hollywood, CA 90069
Data protection contact: privacy@tessryx.com

The parties' activities relevant to the transfer are Customer's use of the Services and Tessryx's provision of the Services as described in the Customer Terms and this DPA.

For purposes of the incorporated SCCs, the parties agree that their acceptance of the Customer Terms and this DPA evidences their agreement to the applicable SCC module to the extent permitted by applicable law.

#A.2 Subject Matter

Provision of the Tessryx platform, including structured content storage, workflow execution, API integration, media hosting, and the serving of pages and endpoints at public URLs.

#A.3 Duration

Processing occurs for the period during which Tessryx provides the Services and processes Customer Personal Data on Customer's behalf, including applicable retention and deletion periods described in Section 16.

#A.4 Nature and Purpose of Processing

Tessryx may host, store, structure, retrieve, transmit, cache, render, secure, support, and delete Customer Personal Data as necessary to provide the Services and in accordance with Customer's documented instructions.

Processing may include transmitting Customer Personal Data to Customer-selected third-party services where Customer configures or instructs the Services to do so.

#A.5 Frequency

Processing occurs on a continuous basis or as initiated by Customer, Customer's authorized users, Customer's applications and workflows, or visitors interacting with Customer's sites during the applicable term.

#A.6 Categories of Data Subjects

Depending on Customer's use of the Services, data subjects may include:

  • Customer's personnel, representatives, and workspace members;

  • visitors to websites Customer operates through the Services, including individuals who sign in using a Tessryx account and individuals who submit information through Customer's forms or endpoints without signing in;

  • Customer's customers, contacts, users, and other individuals whose Personal Data Customer stores or processes through the Services; and

  • other individuals whose Personal Data Customer elects to submit to or process through the Services.

#A.7 Categories of Personal Data

The categories of Customer Personal Data are determined by Customer and may include:

Workspace members. Name, email address, workspace role, and activity within the workspace.

Site visitors who sign in. A pseudonymous identifier generated by the Services for the visitor and specific to Customer's workspace. For a visitor who is also a member of Customer's workspace, and where Customer restricts a page based on workspace membership or role, this may also include the visitor's email address and applicable role.

Form and endpoint submissions. Information Customer elects to collect through its forms or endpoints, which may include names, email addresses, messages, free-text submissions, and other information specified by Customer.

Customer Content. Personal Data contained in datafiles, media assets, workflow definitions, prompts, responses, applications, or other content Customer elects to store, transmit, or process through the Services.

#A.8 Special Categories and Restricted Data

The Services are not designed or authorized for processing special categories of Personal Data under Article 9 of the GDPR or other categories of regulated or sensitive data prohibited by the Acceptable Use Policy.

The Acceptable Use Policy prohibits Customer from submitting specified categories of regulated or sensitive data, including health information, payment card data, government identifiers, financial account numbers, biometric identifiers, and Personal Data concerning children under 13.

Customer must not submit or otherwise process through the Services Personal Data prohibited by the Acceptable Use Policy or special categories of Personal Data under Article 9 of the GDPR unless Tessryx has expressly agreed in writing to such processing.

#A.9 Retention

Customer Personal Data is retained for the duration described in this DPA and according to the applicable operational retention periods described in Section 16 and Annex C.

#A.10 Competent Supervisory Authority

For transfers subject to the GDPR and SCCs, the competent supervisory authority will be determined in accordance with Clause 13 of the applicable SCC module.

Annex B - Subprocessors

Tessryx's current list of Subprocessors is maintained on its Subprocessor page and incorporated into this DPA by reference. As of the Effective Date:

SubprocessorProcessingLocation
Amazon Web Services, Inc.Compute, storage, database, and email deliveryUnited States
Cloudflare, Inc.Content delivery, edge caching, DNS, TLS, and network securityGlobal edge network

Changes to Tessryx's Subprocessors are governed by Section 10 of this DPA.

Customer-selected third-party services, APIs, AI providers, assistants, agents, and other integrations are not Tessryx Subprocessors merely because Customer elects to connect them to or access them through the Services.

Stripe processes Tessryx's own subscription and payment information and does not receive Customer Personal Data from Customer workspaces for processing on Customer's behalf. Accordingly, Stripe is not listed as a Subprocessor under this DPA.

Annex C - Technical and Organizational Measures

Tessryx maintains the following technical and organizational measures with respect to Customer Personal Data processed through the Services.

Encryption. Personal Data is encrypted in transit using TLS. Data stores used by the Services are encrypted at rest, and point-in-time recovery data inherits the encryption of the store from which it derives. Session cookies are encrypted rather than merely signed and are cryptographically bound to the hostname that issued them.

Access control. Access to production systems is restricted to authorized personnel, requires multi-factor authentication, and is logged. Access is granted on a need-to-know basis and reviewed periodically.

Tenant isolation. Customer data is logically separated by workspace. Authorization is evaluated on every request against the requesting workspace.

Credential handling. Credentials Customer stores in the Services are write-only. Once saved, a credential value cannot be read back through the interface, API, or MCP server and is resolved only at execution time.

Cache segregation. Endpoints requiring sign-in are never served from a shared cache. This restriction is enforced by the platform and cannot be disabled through configuration.

Egress restriction. Where the Services fetch remote content on Customer's instruction, requests to internal, loopback, and link-local network addresses are blocked.

Retention controls. Workflow execution traces are deleted after 14 days. Service and operational logs are retained for up to 90 days. Security and audit logs are retained for up to 90 days. Session records are retained for the life of the session, up to a maximum of 90 days.

Resilience and recovery. Structured Customer Content is held in stores with continuous point-in-time recovery enabled over a rolling 35-day window. Derived and published artifacts are versioned, with non-current versions retained for 30 days.

Media assets. Media assets uploaded by Customer are not versioned and are not backed up. A media asset that Customer deletes or overwrites cannot be recovered. Customer is responsible for retaining its own copies of media that it cannot replace.

Personnel security and confidentiality. Personnel with access to Personal Data are bound by written confidentiality obligations. Access to production infrastructure is limited according to role and operational need, and console access requires multi-factor authentication.

Logging and accountability. Access to production systems is logged, and Tessryx maintains service, operational, security, and audit records subject to the retention periods described above.

Incident response. Tessryx maintains procedures for detecting, investigating, containing, and responding to security incidents, including procedures for notifying affected customers where required by this DPA or applicable Data Protection Laws.

Subprocessor assurance. Tessryx evaluates material infrastructure Subprocessors using available security and compliance information, including independent audit reports and recognized security certifications where applicable. The Amazon Web Services services currently used by Tessryx, including Amazon DynamoDB, Amazon Simple Storage Service (S3), Amazon Simple Email Service (SES), Elastic Load Balancing (ELB), and AWS Key Management Service (KMS), are within the scope of AWS's SOC 2 Type II assurance program and AWS's ISO/IEC 27001:2022 certification. AWS's ISO/IEC 27001:2022 certification is Certificate No. 2013-009, issued by EY CertifyPoint and currently valid through November 30, 2028.

The Cloudflare services currently used by Tessryx, including Cache/CDN, DNS, SSL/TLS, SSL/TLS for SaaS, Cloudflare for SaaS, Web Application Firewall (WAF), R2, and Access, are within the scope of Cloudflare's SOC 2 Type II assurance program and ISO/IEC 27001 certification. Cloudflare also maintains ISO/IEC 27701 certification and PCI DSS compliance, as described in Cloudflare's compliance documentation.

These certifications and assurance reports relate to the applicable infrastructure providers and services within their respective audit or certification scopes. They do not constitute a representation that Tessryx itself is independently SOC 2 audited or ISO/IEC 27001 certified. Third-party reports and supporting materials may be subject to confidentiality and distribution restrictions imposed by the applicable provider.

Tessryx may update these measures from time to time in accordance with Section 9 of this DPA, provided that it does not materially decrease the overall level of protection afforded to Customer Personal Data during the applicable term.

Tessryx LLC
8605 Santa Monica Blvd #347695
West Hollywood, CA 90069
privacy@tessryx.com