Tenelix
DPA

Data Processing Addendum

Effective April 28, 2026

This document is a template scaffold meant for product development. Have it reviewed by qualified legal counsel before you publish it as the operative version of your privacy policy or terms.

This Data Processing Addendum (“DPA”) supplements the Terms of Service between Tenelix Cloud (“Tenelix”) and the customer (“Customer”) and governs Tenelix's processing of personal data on the Customer's behalf.

1. Definitions

  • Personal Data means any information relating to an identified or identifiable natural person processed via the Platform.
  • Processing means any operation performed on Personal Data, whether automated or not.
  • Sub-processor means any processor engaged by Tenelix to process Personal Data on Customer's behalf.

2. Roles

Customer is the controller of Personal Data processed on the Platform. Tenelix is the processor and processes Personal Data only on Customer's documented instructions.

3. Sub-processors

Tenelix may engage Sub-processors to deliver the Platform. A current list of Sub-processors is maintained on request. Tenelix will give Customer at least 30 days' prior notice of any new Sub-processor and provide Customer the right to object on reasonable data protection grounds.

4. Security

Tenelix implements and maintains the technical and organizational measures described in our security page, including encryption in transit and at rest, tenant isolation, access controls, audit logging, and incident response. Tenelix will notify Customer without undue delay of any Personal Data breach.

5. International transfers

Where Personal Data is transferred from a jurisdiction with cross-border data transfer requirements, the parties will rely on Standard Contractual Clauses or equivalent valid transfer mechanisms.

6. Data subject requests

Tenelix will provide reasonable assistance to Customer in responding to data subject requests for access, correction, erasure, restriction, portability, or objection, taking into account the nature of the processing and information available to Tenelix.

7. Audits

Tenelix will make available to Customer information necessary to demonstrate compliance with this DPA, including third-party certifications and audit reports where available. Customer may request additional information once per year, subject to reasonable notice and confidentiality.

8. Return or deletion of data

Upon termination of the Platform, Tenelix will, at Customer's choice, delete or return all Personal Data processed on Customer's behalf and delete existing copies, subject to applicable retention obligations.

9. Liability

Each party's liability under this DPA is subject to the limitations and exclusions in the underlying Terms.

10. Contact

DPA questions: privacy@tenelix.com.