Data Processing Addendum
Effective date pending publicationVersion 1.0
This Data Processing Addendum ("DPA") forms part of the Customer Terms of Service between Tessryx LLC ("Tessryx," "Processor") and the customer agreeing to them ("Customer," "Controller"). It applies where Tessryx processes Personal Data on Customer's behalf in the course of providing the Services.
If there is a conflict, this DPA controls over the Customer Terms with respect to the processing of Personal Data.
#1. Definitions
"Data Protection Laws" means all laws applicable to the processing of Personal Data under this DPA, including the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and the California Consumer Privacy Act as amended ("CCPA").
"Personal Data," "processing," "controller," "processor," "data subject," and "personal data breach" have the meanings given in the GDPR. "Business," "service provider," "sell," and "share" have the meanings given in the CCPA.
"Customer Personal Data" means Personal Data contained in Customer Content, as defined in the Customer Terms.
"Subprocessor" means a third party engaged by Tessryx to process Customer Personal Data.
#2. Roles of the parties
Customer is the controller of Customer Personal Data. Tessryx is the processor, and under the CCPA a service provider.
Tessryx is an independent controller of the account, billing, security, and usage data described in its Privacy Policy, which it processes to operate its business. This DPA does not apply to that processing.
Where Customer is itself a processor for a third party, Customer warrants that it has the authority to appoint Tessryx as a subprocessor on that party's instructions.
#3. Scope and instructions
Tessryx will process Customer Personal Data only:
(a) to provide, maintain, secure, and support the Services; (b) in accordance with Customer's documented instructions, which include the Customer Terms, this DPA, and the configuration choices Customer makes in the Services; and (c) as required by applicable law, in which case Tessryx will inform Customer unless legally prohibited.
Tessryx will not sell or share Customer Personal Data, will not retain, use, or disclose it for any purpose other than performing the Services, and will not combine it with Personal Data received from other sources except as permitted by the CCPA.
Tessryx will not use Customer Personal Data to train machine learning models.
Tessryx will notify Customer if, in its opinion, an instruction infringes Data Protection Laws.
#4. Where Tessryx's obligations end
Where Customer configures the Services to transmit Personal Data to a third-party system — including an external API, a webhook destination, or a language model provider whose credentials Customer supplies — that transmission is made on Customer's instruction, and Tessryx's obligations under this DPA cease with respect to that data once it leaves the Services. The agreement between Customer and that third party governs from that point, and that third party is not a Subprocessor of Tessryx.
The same applies where Customer connects an AI assistant, agent, or other client to the Services through the Model Context Protocol interface or the API. Content that client reads from Customer's workspace is disclosed to the operator of that client on Customer's instruction. Customer is responsible for choosing which clients to connect, for the scope of access it grants them, and for ensuring that disclosure is consistent with Customer's own obligations to the data subjects concerned. The operator of such a client is Customer's subprocessor, not Tessryx's.
#5. Customer's responsibilities
Customer is responsible for:
(a) the lawfulness of the Personal Data it submits and of the instructions it gives; (b) having a valid legal basis for the processing, and providing any required notices to and obtaining any required consents from data subjects; (c) the accuracy, quality, and legality of Customer Personal Data; (d) its own relationship with visitors to and members of the sites it operates, including any record it builds keyed on the visitor identifier the Services provide, any name, email address, or other information it collects itself, and any linkage between them; and (e) not submitting the categories of data excluded by Section 8 of the Acceptable Use Policy.
Customer must publish its own privacy notice covering what it collects from its visitors and members, respond to their requests directly, and remain responsible for that data after a visitor stops using its sites or a member leaves its workspace.
#6. Confidentiality
Tessryx will ensure that personnel authorized to process Customer Personal Data are bound by confidentiality obligations, and will limit access to those who need it to provide the Services.
#7. Security
Tessryx will implement appropriate technical and organizational measures to protect Customer Personal Data, as described in Annex C. Customer has reviewed those measures and agrees they are appropriate to the risk, taking account of the nature of the data and the state of the art.
Tessryx may update its measures provided the level of protection is not reduced.
#8. Subprocessors
Customer gives general authorization for Tessryx to engage Subprocessors. The current list is at our subprocessor page(/subprocessors).
Tessryx will post any new or replacement Subprocessor at least 30 days before it begins processing Customer Personal Data. Customer may object on reasonable grounds related to data protection within 30 days by writing to privacy@tessryx.com. If the parties cannot resolve the objection, Customer may terminate the affected Services and receive a pro-rated refund of prepaid unused fees.
Tessryx will impose data protection obligations on each Subprocessor no less protective than those in this DPA, and remains liable for its Subprocessors' performance.
#9. Assistance with data subject requests
The Services allow Customer to access, correct, export, and delete Customer Personal Data directly. Customer will use those facilities to respond to data subject requests.
If a data subject contacts Tessryx directly about Customer Personal Data, Tessryx will refer them to Customer and will not respond substantively except to confirm the referral, unless legally required.
Where Customer cannot fulfil a request through the Services, Tessryx will provide reasonable assistance, at Customer's expense where the assistance is not trivial.
#10. Personal data breach
Tessryx will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and will provide the information reasonably available to it to help Customer meet its own notification obligations.
Notification is not an acknowledgement of fault or liability.
#11. Data protection impact assessments
Tessryx will provide reasonable assistance with data protection impact assessments and prior consultations with supervisory authorities, taking into account the nature of the processing and the information available to it.
#12. Deletion and return
On termination of the Customer Terms, Tessryx will retain Customer Personal Data for 90 days so Customer may request a copy, and will then delete it from its live systems.
Deleted data persists for a bounded period in recovery and log systems before it is purged on a rolling cycle: up to 35 days in point-in-time recovery data, up to 30 days in retained object versions, and up to 90 days in logs. Tessryx does not restore deleted Customer data from these systems except to recover from a failure affecting the Services.
Tessryx may retain Customer Personal Data where required by law, in which case it will continue to protect it under this DPA.
#13. Audits
Tessryx will make available the information reasonably necessary to demonstrate compliance with this DPA, and will respond to reasonable written questionnaires about its security practices no more than once per twelve months.
Where Data Protection Laws require an on-site audit, the parties will agree its scope, timing, and duration in advance. Audits will be at Customer's expense, conducted during business hours, subject to confidentiality obligations, and will not unreasonably interfere with Tessryx's operations.
#14. International transfers
Tessryx processes Customer Personal Data in the United States.
Where Customer Personal Data originating in the European Economic Area, the United Kingdom, or Switzerland is transferred to Tessryx, the parties incorporate the European Commission's Standard Contractual Clauses (Decision 2021/914), Module Two (controller to processor), into this DPA by reference, with:
- Clause 7 (docking clause) included;
- Clause 9, Option 2 (general written authorization), with the 30-day notice period in Section 8 above;
- Clause 11 optional redress language excluded;
- Clause 17: governed by the law of Ireland;
- Clause 18(b): courts of Ireland;
- Annex I, II, and III completed by Annexes A, B, and C to this DPA.
For UK transfers, the UK International Data Transfer Addendum applies, with Tables 1 to 3 completed by the Annexes to this DPA and Table 4 selecting neither party.
For Swiss transfers, references to the GDPR are read as references to the Swiss FADP, and the Swiss Federal Data Protection and Information Commissioner is the competent authority.
#15. Liability
Each party's liability under this DPA is subject to the limitations in the Customer Terms.
Annex A — Details of processing
Data exporter: Customer, acting as controller. Data importer: Tessryx LLC, acting as processor.
Subject matter: Provision of the Tessryx platform, comprising structured content storage, workflow execution, API integration, media hosting, and the serving of pages and endpoints at public URLs.
Duration: For the term of the Customer Terms, plus the retention period in Section 12.
Nature and purpose: Hosting, storage, structuring, retrieval, transmission, caching, rendering, and deletion of Customer Personal Data as instructed by Customer through its use of the Services.
Frequency: Continuous.
#Categories of data subjects
- Customer's personnel and workspace members
- Visitors to websites Customer operates on the Services, including people who sign in with a Tessryx account and people who submit information to Customer's forms and endpoints without signing in
- Customer's own customers, contacts, and end users whose data Customer stores in the Services
- Any other individual whose Personal Data Customer chooses to submit
#Categories of Personal Data
Determined by Customer. Typically includes:
- Workspace members: name, email address, role, and activity within the workspace
- Site visitors who sign in: the pseudonymous identifier the Services generate for that visitor, unique to Customer's workspace. For visitors who are also members of Customer's workspace, and only on pages Customer restricts by role, also email address and roles
- Form and endpoint submissions: whatever Customer's forms collect, which may include names, email addresses, messages, and free text
- Content stored by Customer: any Personal Data contained in datafiles, media assets, model prompts and completions, and workflow definitions
#Special categories
None. The Acceptable Use Policy prohibits submitting health data, payment card data, government identifiers, financial account numbers, biometric identifiers, and data concerning children under 13. Customer must not submit special category data within the meaning of Article 9 GDPR.
#Competent supervisory authority
Determined under Clause 13 of the Standard Contractual Clauses by reference to Customer's establishment or representative in the EEA.
Annex B — Subprocessors
The current list is maintained at our subprocessor page(/subprocessors) and is incorporated here.
As at the effective date:
| Subprocessor | Processing | Location |
|---|---|---|
| Amazon Web Services, Inc. | Compute, storage, database, email delivery | United States |
| Cloudflare, Inc. | Content delivery, edge caching, DNS, TLS, network security | Global edge network |
| Stripe, Inc. | Payment processing | United States |
Annex C — Technical and organizational measures
Encryption. Personal Data is encrypted in transit using TLS. All data stores used by the Services are encrypted at rest, and point-in-time recovery data inherits the encryption of the store it derives from. Session cookies are encrypted rather than merely signed, and are cryptographically bound to the hostname that issued them.
Access control. Access to production systems is restricted to authorized personnel, requires multi-factor authentication, and is logged. Access is granted on a need-to-know basis and reviewed periodically.
Tenant isolation. Customer data is logically separated by workspace. Authorization is evaluated on every request against the requesting workspace.
Credential handling. Credentials Customer stores in the Services are write-only: once saved, a value cannot be read back through the interface, the API, or the MCP server, and is resolved only at execution time.
Cache segregation. Endpoints requiring sign-in are never served from a shared cache. This is enforced by the platform and cannot be disabled by configuration.
Egress restriction. Where the Services fetch remote content on Customer's instruction, requests to internal, loopback, and link-local network addresses are blocked.
Retention limits. Workflow execution traces are deleted after 14 days. Service and operational logs are retained for up to 90 days. Security and audit logs are retained for up to 90 days. Session records are retained for the life of the session, to a maximum of 90 days.
Resilience. Structured Customer Content is held in stores with continuous point-in-time recovery enabled over a rolling 35-day window. Derived and published artifacts are versioned, with non-current versions retained for 30 days. Media assets uploaded by Customer are not versioned and are not backed up: a media asset that Customer deletes or overwrites cannot be recovered. Customer is responsible for retaining its own copies of media it cannot replace.
Personnel. Personnel with access to Personal Data are bound by written confidentiality obligations. Console access to production infrastructure requires multi-factor authentication.
Incident response. Tessryx maintains procedures for detecting, investigating, and responding to security incidents, including notification to affected customers.
Subprocessor assurance. Infrastructure Subprocessors maintain recognized security certifications, including SOC 2 and ISO 27001.
Tessryx LLC, 8605 Santa Monica Blvd #347695, West Hollywood, CA 90069 privacy@tessryx.com