Data Processing Addendum.
This Data Processing Addendum ("DPA") amends and forms part of the written agreement between Customer and Tensorlake, Inc. ("Tensorlake") (collectively, "the parties") for the provision of services to Customer (the "Agreement"). This DPA prevails over any conflicting term of the Agreement but does not otherwise modify the Agreement.
Definitions
In this DPA:
1.1 "Data Protection Law" means all laws that apply to the Processing of Personal Data under the Agreement, including European Data Protection Law and the laws and regulations of the United States and its states, as amended from time to time, to the extent such laws and regulations apply to the relevant party.
1.2 "European Data Protection Law" means the General Data Protection Regulation (EU) 2016/679 ("GDPR") and all other privacy and data protection laws of the European Economic Area ("EEA"), and their respective Member States, Switzerland and the United Kingdom ("UK") and all laws implementing or supplementing the foregoing.
1.3 "Personal Data" means any information that reasonably relates, directly or indirectly, to an identified or identifiable natural person that Tensorlake may Process on Customer’s behalf in performing the Services under the Agreement.
1.4 "Processing" (including its cognate "Process") means any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
1.5 "Security Incident" means any breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data.
1.6 "Services" means the services that Tensorlake provides to Customer pursuant to the Agreement.
1.7 "Standard Contractual Clauses" means (i) Module Two (transfer controller to processor) and Module Three (transfer processor to processor) of the Standard Contractual Clauses for the transfer of Personal Data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and the Council approved by European Commission Implementing Decision (EU) 2021/914 of 4 June 2021, as currently set out at https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj (the "EU SCCs"), in each case as applicable to the parties’ respective roles in relation to the relevant Processing as described in Section 2.3; and (ii) where the UK GDPR applies, the EU SCCs as supplemented by the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the Commissioner under S119A(1) Data Protection Act 2018 (the "UK SCCs").
1.8 Capitalized terms used but not defined herein have the meaning given to them in the Agreement.
Scope and Roles
2.1 The subject matter, nature and purpose of the Processing, the types of Personal Data and categories of Data Subjects are set out in Annex I.
2.2 Tensorlake agrees that it will Process Personal Data only in accordance with the Agreement and this DPA. To the extent applicable, Tensorlake will Process Personal Data as a "processor" or "service provider" as such terms are defined under applicable Data Protection Law.
2.3 Where Customer Processes Personal Data as a controller, Customer is the controller and Tensorlake is the processor, and Module Two of the EU SCCs applies. Where Customer Processes Personal Data as a processor on behalf of a third-party controller, Customer is the processor and Tensorlake is the subprocessor, Module Three of the EU SCCs applies, and Customer is responsible for obtaining that controller’s authorization for Tensorlake’s appointment. Each Module applies only to the Processing to which it is relevant.
2.4 Tensorlake Processes Personal Data relating to Customer’s account, billing and use of the Services as an independent controller for the purposes of account administration, billing, security, fraud prevention and compliance with its legal obligations. This Section 2.4 does not apply to Personal Data that Tensorlake Processes on Customer’s behalf under Section 2.2.
Data Protection
3.1 When Tensorlake Processes Personal Data, it will:
(a) Process the Personal Data in accordance with Customer’s documented instructions as described in the Agreement or this DPA. Tensorlake will notify Customer if it considers that an instruction from Customer is in breach of Data Protection Law, unless it is prohibited from doing so by law on important grounds of public interest;
(b) assist Customer, taking into account the nature of the Processing and the information available to Tensorlake, in complying with Customer’s obligations to respond to requests concerning Personal Data from individuals under applicable Data Protection Law;
(c) implement and maintain appropriate physical, technical and organizational measures to ensure a level of security appropriate to the risk, including the measures set out in Annex II and any further measures required by applicable Data Protection Law;
(d) only entrust the Processing of Personal Data to personnel who have undertaken to comply with confidentiality requirements; and
(e) upon termination or expiry of the Agreement, at Customer’s choice, return or securely and irretrievably delete all Personal Data (and all copies, including in backups) within ninety (90) days and certify in writing that it has done so, unless retention is required by applicable law, in which case Tensorlake shall keep the Personal Data confidential and Process it only to the extent and for the period required by that law.
3.2 Tensorlake certifies that it will not (a) "sell" (as defined in Data Protection Law) the Personal Data; (b) share the Personal Data for "cross-context behavioral advertising" (as defined in Data Protection Law); (c) retain, use, combine or disclose the Personal Data for any purpose other than as permitted under this DPA and in accordance with the Agreement; or (d) retain, use, or disclose the Personal Data other than in the context of the direct relationship with Customer in accordance with the Agreement.
3.3 For the avoidance of doubt, and notwithstanding any term of the Agreement permitting Tensorlake to collect, retain or use usage data, aggregated data or de-identified data, Tensorlake will not use Personal Data to create or derive such data except to the extent necessary to provide, secure and maintain the Services for Customer.
Customer Responsibilities
4.1 Customer is responsible for the lawfulness of Personal Data Processing under or in connection with the Services. Customer will (i) provide all required notices and obtain all required consents, permissions and rights necessary under applicable Data Protection Law for Tensorlake to lawfully Process Personal Data for the purposes contemplated by the Agreement; (ii) make appropriate use of the Services to ensure a level of security appropriate to the particular content of the Personal Data; (iii) comply with all Data Protection Law applicable to the collection of Personal Data and the transfer of such Personal Data to Tensorlake; and (iv) ensure its processing instructions comply with applicable laws (including applicable Data Protection Law).
4.2 Customer acknowledges that Tensorlake makes available information regarding the security measures applicable to the Services at https://trust.tensorlake.ai (the "Trust Center"). Customer represents that it has reviewed the then-current information made available in the Trust Center and will not submit or permit access through the Services to Personal Data, including any sensitive or special-category data, unless Customer has determined that the security measures described in the Trust Center are sufficient for such data and Customer’s intended use of the Services complies with Data Protection Law.
4.3 Customer will not submit to the Services, and will not instruct Tensorlake to Process, (a) special categories of Personal Data within the meaning of Article 9 of the GDPR, (b) protected health information subject to the Health Insurance Portability and Accountability Act, or (c) personal information of children subject to the Children’s Online Privacy Protection Act or equivalent laws, unless the parties have agreed in writing to the applicable use case and to any additional technical, organizational or contractual safeguards reasonably required by Tensorlake.
Subprocessing
5.1 Customer agrees that Tensorlake may use third-party suppliers to Process Personal Data ("Subprocessors") in accordance with the terms of this DPA. The Trust Center has a mechanism allowing Customer to subscribe to notifications of new Subprocessors (the "Notification Mechanism"). Tensorlake will provide Customer reasonable notice of the appointment of additional Subprocessors by posting to https://trust.tensorlake.ai and sending email notification to Customers who have subscribed to the Notification Mechanism. If Customer does not subscribe to such notifications, Customer shall be deemed to have received notice of a new Subprocessor when such changes are posted to the Trust Center. Customer may object to Tensorlake’s use of a new Subprocessor on the basis of reasonable data privacy or data security concerns within fifteen (15) days of the notice. In response to Customer’s reasonable objection, the parties will work together in good faith to determine an appropriate resolution.
5.2 Tensorlake will ensure that any Subprocessors to which it transfers Personal Data enter into written agreements with Tensorlake requiring that the Subprocessor abide by terms substantially similar to those contained in this DPA. Tensorlake will remain liable for any breaches of this DPA caused by its Subprocessors.
5.3 The current list of Subprocessors is maintained at https://trust.tensorlake.ai and constitutes Annex III to the Standard Contractual Clauses.
Restricted Data Transfers
6.1 In the event that Customer is subject to European Data Protection Law and the transfer of Personal Data to Tensorlake would be restricted in the absence of the Standard Contractual Clauses, the parties agree that the Standard Contractual Clauses shall be incorporated into this DPA with Customer as the "data exporter" and Tensorlake as the "data importer", applying Module Two or Module Three in accordance with Section 2.3.
6.2 The Standard Contractual Clauses are further completed as follows: the optional docking clause in Clause 7 is implemented; Clause 9(a) option 2 is implemented and the time period therein is specified as seven (7) business days; the optional redress clause in Clause 11(a) is struck; the governing law in Clause 17 is the law of the Republic of Ireland; the courts in Clause 18(b) are the Courts of the Republic of Ireland; and Annex 1, 2 and 3 to the Standard Contractual Clauses are Annex I, Annex II, and Section 5 of this DPA respectively. To the extent required by Data Protection Law in the UK, Part 1, tables 1, 2 and 3 of the UK SCCs will be deemed to be completed like their equivalent provisions in the EU SCCs. For the purpose of Part 1, Table 4, the party that may end the UK SCCs in accordance with Section 19 of the UK Addendum is the importer.
6.3 Where the Swiss Federal Act on Data Protection ("FADP") applies to a transfer, the EU SCCs apply with the following modifications: references to the GDPR are to be understood as references to the FADP; the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner; and the term "Member State" shall not be interpreted so as to exclude data subjects in Switzerland from bringing proceedings in Switzerland.
Assistance and Notifications
7.1 Upon Customer’s request, Tensorlake will provide Customer with reasonable cooperation and assistance to the extent required to fulfil Customer’s obligation under European Data Protection Law to:
(a) reply to investigations and inquiries from data protection regulators; and
(b) carry out a data protection impact assessment related to the Services, where Customer does not otherwise have access to the relevant information necessary to perform such assessment.
7.2 Unless prohibited by Data Protection Law, Tensorlake must inform Customer without undue delay if Tensorlake:
(a) receives a request, complaint or other inquiry regarding the Processing of Personal Data;
(b) receives a binding or non-binding request to disclose Personal Data from law enforcement, courts or any government body;
(c) is subject to a legal obligation that requires Tensorlake to Process Personal Data in contravention of Customer’s instructions; or
(d) is otherwise unable to comply with Data Protection Law or this DPA.
7.3 Upon becoming aware of a Security Incident, Tensorlake will inform Customer without undue delay and will provide timely information relating to the Security Incident as it becomes known or as is reasonably requested by Customer to allow Customer to fulfil its data breach reporting obligations under applicable Data Protection Law.
Audit
8.1 Tensorlake will make available to Customer at Customer’s request information which is necessary to demonstrate compliance with this DPA.
8.2 Tensorlake maintains a SOC 2 Type II report prepared by independent third-party security professionals (the "Audit Report"), which is made available through the Trust Center subject to confidentiality requirements. Customer agrees to accept the Audit Report in satisfaction of its audit right; however, if Customer can demonstrate that it requires additional information beyond the Audit Report, then Customer may request, at Customer’s cost and no more than once annually, that Tensorlake provide for an audit subject to reasonable confidentiality procedures, which will: (i) not include access to any information that could compromise confidential information relating to other Tensorlake customers or suppliers, Tensorlake’s technical and organizational measures, or any trade secrets; and (ii) be performed upon not less than thirty (30) days’ notice, during regular business hours and in such a manner as not to unreasonably interfere with Tensorlake’s normal business activities.
8.3 Where an audit reveals a material breach of this DPA by Tensorlake, Tensorlake shall bear the reasonable costs of that audit and shall timely remediate the breach.
General
9.1 If there is any conflict between this DPA and the Agreement, this DPA will prevail to the extent of that conflict in connection with the Processing of Personal Data.
9.2 If any provision of this DPA is found by any court or administrative body of competent jurisdiction to be invalid or unenforceable, then the invalidity or unenforceability of such provision does not affect any other provision of this DPA and all provisions not affected by such invalidity or unenforceability will remain in full force and effect.
9.3 Notwithstanding anything to the contrary in the Agreement or this DPA, the liability of each party under this DPA is subject to the limitations of liability set out in the Agreement.
9.4 This DPA will be governed by and construed in accordance with the governing law and jurisdiction provisions in the Agreement.
Annex I: Description of Processing
A. List of Parties
Customer is the data exporter and Tensorlake is the data importer. Where Customer Processes Personal Data as a controller, Customer is the controller and Tensorlake is the processor. Where Customer Processes Personal Data as a processor on behalf of a third-party controller, Customer is the processor and Tensorlake is the subprocessor. Full details of the parties, including contact details for data protection matters, are set out in the signature block above or in the Agreement.
B. Description of Transfer
| Subject Matter | Provision of the Services by Tensorlake to Customer under the Agreement, including the ingestion, parsing, extraction, structuring and return of content submitted by Customer, and the hosting, operation, maintenance and support of the Services. |
| Duration of the Processing | For the term of the Agreement and for any additional period during which Tensorlake Processes Personal Data on behalf of Customer in accordance with the Agreement and this DPA. |
| Retention Period | Personal Data contained in content submitted to the Services is retained for the duration of the Agreement and is deleted when Customer deletes it. Customer may delete submitted content, workflow inputs and outputs, and sandbox files and state at any time through the Services’ APIs; upon such a request the data is removed from Tensorlake’s active systems immediately and cannot be recovered. Tensorlake does not apply a fixed retention period to submitted content and does not retain it beyond what is necessary to provide the Services. Account and contact information of Customer’s authorized users is retained for the duration of the Agreement and thereafter only as required for Tensorlake’s legal, accounting and security obligations. On termination or expiry of the Agreement, Personal Data is returned or deleted in accordance with Section 3.1(e) of this DPA, including copies held in backups, within ninety (90) days. |
| Nature and Purpose of the Processing | Processing necessary to provide, secure, maintain and support the Services, including document ingestion, parsing and extraction, account administration, user authentication, customer support, troubleshooting, service monitoring and related operational activities. |
| Frequency of the Processing | Continuous. |
| Categories of Data | (i) Contact information, account credentials and user profile information of Customer’s authorized users; (ii) usage data generated through the Services; and (iii) any Personal Data contained within documents, files or other content submitted to the Services by Customer or its authorized users, which may include names, contact details, identifiers and other information appearing in such content. |
| Special Categories of Data Processed | None. The Services are not intended for the Processing of special categories of Personal Data. Customer shall not provide, make available, or instruct Tensorlake to Process special categories of Personal Data except as provided in Section 4.3 of this DPA. |
| Data Subjects | Customer’s employees, contractors and other authorized users; and, where Customer acts as a processor, individuals whose Personal Data appears in content submitted to the Services by or on behalf of Customer’s own customers. |
C. Competent Supervisory Authority
The competent supervisory authority is the Information Commissioner’s Office (ICO) where the UK GDPR applies, the Irish Data Protection Commission where the EU GDPR applies, and the Federal Data Protection and Information Commissioner where the Swiss FADP applies.
Annex II: Technical and Organizational Measures
Tensorlake shall implement and maintain the controls listed in this Annex II in accordance with industry standards generally accepted by information security professionals as necessary to reasonably protect Personal Data during storage, Processing and transmission.
Independent Assurance. Maintain an annual SOC 2 Type II examination performed by an independent third-party auditor covering the Services. The current report is made available through the Trust Center at https://trust.tensorlake.ai subject to confidentiality requirements.
Information Security Program. Maintain an information security program that includes administrative, technical, and physical safeguards designed to protect the confidentiality, integrity, and availability of Personal Data.
Encryption. Encrypt Personal Data in transit using TLS and at rest using industry-standard encryption algorithms, and ensure that credentials, API keys, and other authentication information provided by customers are stored in an encrypted credential-management system and protected by access controls.
Access Controls. Limit access to personnel and systems that require such access to provide, secure, maintain, or support the Services, and log access to Personal Data. Access privileges will be assigned based on job responsibilities using centralized administrative controls to manage personnel access to Personal Data.
Infrastructure and Network Security. Host Personal Data using reputable cloud infrastructure providers that maintain appropriate physical, environmental, and infrastructure security controls.
Vulnerability Management. Maintain processes designed to identify, evaluate, and remediate security vulnerabilities affecting the Services. Provide a channel for third parties to report suspected security vulnerabilities and use reasonable efforts to investigate and remediate validated vulnerabilities in a timely manner, taking into account their severity and risk.
Incident Management. Maintain procedures designed to identify, investigate, contain, mitigate, and remediate security incidents affecting Personal Data. Document material security incidents and take reasonable steps to reduce the risk of recurrence.
Personnel. Require personnel authorized to access Personal Data to be bound by appropriate confidentiality obligations and to comply with applicable information security policies and procedures.
Evaluation. Periodically assess the effectiveness of technical and organizational measures and update those measures from time to time as appropriate, provided that any update does not materially decrease the overall security of the Services during the applicable subscription term.
Secure Deletion. Securely delete or overwrite Personal Data when no longer reasonably required, using methods designed to prevent recovery, and in accordance with Section 3.1(e) of this DPA.
Questions about this document?
Reach the Tensorlake legal team at legal@tensorlake.ai, or write to TensorLake, Inc., San Francisco, California.
For security or privacy incidents: security@tensorlake.ai.