Draft — not reviewed by counsel
This document is a working draft. It has not been reviewed by a lawyer, it contains unfilled placeholders, and it does not yet bind anyone. Do not rely on it.
Data Processing Addendum
Applies where Tensvia processes personal data on your behalf. It forms part of the Terms of Service and takes precedence over them on this subject.
[LEGAL ENTITY NAME], LLC · Effective [EFFECTIVE DATE] · Last updated [LAST UPDATED]
1.Roles
For Customer Data, you are the controller (or a processor acting for your own controller) and Tensvia is the processor. We process Customer Data only on your documented instructions — which include your use of the Service's features and the settings you choose.
If we believe an instruction breaches data-protection law, we will tell you and may pause that processing rather than carry it out.
2.Scope of processing
- Subject matter — providing the Tensvia Service.
- Duration — the term of the Terms, plus the deletion window in clause 8.
- Nature and purpose — receiving, classifying, drafting responses to, storing and sending customer communications; maintaining consent state; recording an audit trail.
- Categories of data subject — your customers, prospects and enquirers; your own personnel who use the Service.
- Categories of personal data — identifiers (name, phone, email, social handle), message content, consent records, booking details, and where enabled, call audio and transcripts.
- Special category data — not contemplated. The Service is not built for it and you should not route it through the Service without a written agreement.
3.Confidentiality and personnel
Personnel with access to Customer Data are bound by confidentiality obligations, receive access only where needed to perform their role, and have that access logged and removed when it is no longer needed.
4.Security measures
We maintain technical and organisational measures appropriate to the risk, including:
- encryption in transit and at rest;
- tenant isolation enforced at the database through row-level security, so a failure in application logic does not become a cross-tenant disclosure;
- credentials held as vault references, excluded from logs, model context and anything sent to the browser;
- role-based access control and an append-only audit trail of actions taken in the Service;
- policy evaluation that fails closed — absent or ambiguous consent is treated as no consent.
We hold no third-party security certification at this time. We will say so plainly rather than imply otherwise, and will update this clause if that changes.
5.Sub-processors
You authorise the sub-processors listed below. Each is engaged under a written contract imposing data-protection obligations no less protective than this Addendum, and we remain liable for their performance.
| Sub-processor | Purpose | Data | Location | Status |
|---|---|---|---|---|
| Supabase | Primary database, authentication, file storage | All Customer Data | United States | in use |
| Vercel | Application hosting and edge delivery | Request metadata, application logs | United States | in use |
| Anthropic | Model inference — classification, drafting, summarisation | Message content and business context sent for a single inference | United States | in use |
| Telnyx | SMS and voice delivery | Phone numbers, message bodies, call audio and transcripts | United States | in use |
| Resend | Outbound and transactional email | Email addresses, message bodies | United States | in use |
| Cal.com | Calendar availability and booking | Name, email, appointment details | United States | in use |
| Stripe | Subscription billing and payment processing | Billing contact and payment method. Card details go to Stripe directly and are never held by Tensvia | United States | in use |
We will give at least 30 days' notice before adding or replacing a sub-processor that processes Customer Data. You may object on reasonable data-protection grounds within that period; if we cannot resolve the objection, you may terminate the affected Service and receive a pro-rata refund of prepaid fees.
6.Assistance
Taking into account the nature of the processing, we will assist you with data-subject requests, data-protection impact assessments, and consultations with a supervisory authority. Where a data subject contacts us directly about Customer Data, we will not respond substantively — we will refer them to you and tell you.
7.Personal data breach
We will notify you without undue delay, and in any event within 72 hours, of becoming aware of a personal data breach affecting Customer Data. The notice will describe what we know, the likely consequences, and the measures taken — and we will send what we have rather than wait for a complete picture.
8.Return and deletion
On termination you may export Customer Data in a machine-readable format for 30 days. We then delete it, and instruct sub-processors to delete it, within 30 days — except where law requires retention, in which case the data remains isolated and protected until the obligation lapses. Backups expire on their ordinary cycle.
9.Audit
We will make available the information reasonably necessary to demonstrate compliance with this Addendum. You may request an audit no more than once a year, on 30 days' notice, at your cost, subject to confidentiality and to not disrupting the Service — or more often where a supervisory authority requires it.
10.International transfers
Processing takes place in the United States. For transfers of personal data from the UK or EEA, the parties incorporate the Standard Contractual Clauses (and the UK Addendum where applicable), with Tensvia as data importer, Module Two (controller to processor), and the details in clause 2 completing their annexes.
11.Precedence
This Addendum forms part of the Terms of Service. Where it conflicts with them on the processing of personal data, this Addendum prevails.
Questions about this document: legal@tensvia.com