This Data Processing Addendum (the "DPA") forms part of the agreement, design partner agreement, order form, statement of work, or other written agreement (the "Agreement") between the customer identified in the Agreement ("Customer") and Tego AI Inc. ("Tego AI"), governing Customer's access to or use of Tego AI's platform, products, APIs, features, and related services (collectively, the "Services"). This DPA applies to the extent Tego AI Processes Customer Personal Data on behalf of Customer in connection with the Services. In the event of a conflict between this DPA and the Agreement with respect to the Processing of Customer Personal Data, this DPA controls.
For clarity, "Customer Personal Data" is the subset of Customer Data (as defined in the Agreement) that constitutes Personal Data. Customer Personal Data may therefore include Personal Data contained in prompts, queries, inputs, outputs, responses, system instructions, configurations, logs, metadata, telemetry, uploaded materials, and other Customer Data Processed through the Services.
1. Definitions
“Applicable Data Protection Law.” means any law or regulation applicable to the Processing of Customer Personal Data under the Agreement, including, where applicable, the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018, the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA"), other applicable U.S. state privacy laws, and the Israeli Privacy Protection Law, 5741-1981 and regulations promulgated thereunder.
“Controller.” means the entity that determines the purposes and means of Processing Personal Data, and includes a "business" or analogous term under Applicable Data Protection Law.
“Customer Personal Data.” means Personal Data Processed by Tego AI on behalf of Customer in connection with the Services.
“Data Subject.” means an identified or identifiable natural person to whom Personal Data relates, or the equivalent term under Applicable Data Protection Law.
“Personal Data.” means information that is defined as personal data, personal information, or an equivalent term under Applicable Data Protection Law.
“Personal Data Breach.” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data, where such event constitutes a personal data breach or similar reportable security incident under Applicable Data Protection Law.
“Process, Processed, or Processing.” has the meaning given under Applicable Data Protection Law and includes any operation performed on Personal Data, such as collection, access, use, storage, disclosure, transmission, analysis, generation, retrieval, alteration, deletion, or destruction.
“Processor.” means an entity that Processes Personal Data on behalf of a Controller, and includes a "service provider", "contractor", or analogous term under Applicable Data Protection Law.
“Subprocessor.” means a third party engaged by Tego AI to Process Customer Personal Data on behalf of Customer in connection with the Services.
“Standard Contractual Clauses.” means the European Commission standard contractual clauses adopted by Commission Implementing Decision (EU) 2021/914, as amended or replaced from time to time.
2. Scope and roles
2.1 Roles. As between the parties, Customer is the Controller of Customer Personal Data and Tego AI is the Processor of Customer Personal Data, except where Customer acts as a Processor on behalf of another Controller, in which case Tego AI acts as Customer's subprocessor. Each party will comply with the obligations applicable to it under Applicable Data Protection Law.
2.2 Processing Details. The subject matter, duration, nature and purpose of the Processing, categories of Data Subjects, and types of Customer Personal Data are described in Annex A. Customer may provide additional documented instructions that are consistent with the Agreement and this DPA.
2.3 Lawful Instructions. Tego AI will Process Customer Personal Data only on documented instructions from Customer, including as necessary to provide, secure, support, maintain, and improve the Services for Customer, and as otherwise described in the Agreement and this DPA, unless Applicable Data Protection Law requires otherwise. If legally permitted, Tego AI will inform Customer before Processing Customer Personal Data pursuant to a legal requirement that is not based on Customer's instructions.
2.4 Unlawful Instructions. Tego AI will promptly inform Customer if, in Tego AI's reasonable opinion, an instruction infringes Applicable Data Protection Law. Tego AI may suspend the affected Processing until the parties resolve the issue.
3. Customer Obligations
Customer will:
- provide instructions that comply with Applicable Data Protection Law and the Agreement;
- ensure that it has all rights, notices, consents, permissions, and other lawful bases necessary for Tego AI to Process Customer Personal Data in accordance with Customer's instructions;
- use reasonable efforts to avoid providing Personal Data that is not necessary for the intended use of the Services; and
- not instruct Tego AI to Process Customer Personal Data in a manner that would violate Applicable Data Protection Law.
4. Tego AI Processor Obligations
4.1 Confidentiality. Tego AI will ensure that personnel authorized to Process Customer Personal Data are subject to appropriate confidentiality obligations and access Customer Personal Data only as necessary to perform their duties.
4.2 Security. Taking into account the state of the art, costs of implementation, and the nature, scope, context, and purposes of Processing, Tego AI will implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. The measures are described in Annex C and may be updated from time to time, provided that the overall level of security is not materially decreased.
4.3 Data Subject Requests. If Tego AI receives a request from a Data Subject concerning Customer Personal Data, Tego AI will notify Customer without undue delay and will not respond except on Customer's documented instructions or as required by law. Taking into account the nature of the Processing, Tego AI will provide reasonable assistance to Customer, through appropriate technical and organizational measures where feasible, to enable Customer to respond to Data Subject requests.
4.4 Assistance. Taking into account the nature of the Processing and information available to Tego AI, Tego AI will provide reasonable assistance to Customer with data protection impact assessments, prior consultations with regulators, and Customer's obligations relating to security and breach notifications, in each case to the extent required by Applicable Data Protection Law.
4.5 Personal Data Breach. Tego AI will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data and, where feasible, within forty-eight (48) hours. Tego AI will provide information reasonably available to it to assist Customer in meeting applicable notification obligations, including the nature of the incident, categories of affected data and Data Subjects, likely consequences, and measures taken or proposed to address the incident. Tego AI's notification of an incident is not an admission of fault or liability.
4.6 Return and Deletion. Upon termination or expiration of the Services, Tego AI will delete or return Customer Personal Data in accordance with the Agreement and Customer's documented instructions, unless retention is required by law. Customer Personal Data contained in backups may remain until overwritten or deleted in the ordinary course, provided it remains protected under this DPA and is not used for other purposes.
4.7 Records. Tego AI will maintain records of Processing activities as required by Applicable Data Protection Law and will make information reasonably necessary to demonstrate compliance with this DPA available to Customer in accordance with Section 8.
4.8 AI and Model Use. Tego AI will not sell Customer Personal Data. Tego AI will not use Customer Personal Data to train a general-purpose or foundation model for the benefit of other customers or third parties unless Customer expressly authorizes such use in writing. Tego AI may Process Customer Personal Data to provide, secure, support, debug, and maintain the Services for Customer and to comply with law. Any use of de-identified or aggregated data will be subject to the Agreement and Applicable Data Protection Law.
5. Subprocessors
5.1 General Authorization. Customer provides Tego AI with general written authorization to engage Subprocessors to Process Customer Personal Data for the purposes described in this DPA. Tego AI will maintain a current list of authorized Subprocessors in Annex B or at another location identified to Customer in writing.
5.2 Subprocessor Terms. Tego AI will enter into a written agreement with each Subprocessor that imposes data protection obligations that provide a level of protection for Customer Personal Data substantially equivalent to the protection required by this DPA, to the extent applicable to the services performed by that Subprocessor. Tego AI remains responsible for its Subprocessors' performance of their data protection obligations to the extent required by Applicable Data Protection Law.
5.3 Changes and Objections. Tego AI will provide reasonable advance notice of any new Subprocessor that will Process Customer Personal Data. Customer may object on reasonable data-protection grounds by providing written notice within fifteen (15) days after receiving notice. The parties will work in good faith to resolve the objection. If they cannot resolve it, Tego AI may make available a commercially reasonable change to the affected Services or Customer may terminate only the affected portion of the Services, without penalty, as its sole remedy for the unresolved objection.
5.4 Authorized Subprocessors. Tego AI engages a limited number of subprocessors to help deliver the Services, including cloud infrastructure, data storage, and AI-assisted development providers. A current list of subprocessors, including their role and processing location, is set out in Annex B of our Data Processing Addendum and is available to customers on request or as part of the security review process.
6. International Data Transfers
6.1 Transfers Generally. Tego AI will ensure that any transfer of Customer Personal Data across national borders complies with Applicable Data Protection Law and uses an appropriate transfer mechanism where required.
6.2 EEA Transfers. To the extent Customer Personal Data protected by the GDPR is transferred to Tego AI in a country not recognized by the European Commission as providing an adequate level of protection, the SCCs are incorporated into this DPA by reference and apply as follows: Module Two (Controller to Processor) applies where Customer is a Controller and Tego AI is a Processor; Module Three (Processor to Processor) applies where Customer is a Processor and Tego AI is a subprocessor. The optional docking clause applies; the competent supervisory authority and governing law will be determined in accordance with the SCCs and the Customer's establishment or other legally permissible choice. Annexes A, B, and C of this DPA provide the information required by Annexes I-III of the SCCs to the extent applicable.
6.3 UK Transfers. For transfers subject to the UK GDPR that require a transfer mechanism, the parties will apply the then-current UK International Data Transfer Addendum to the EU SCCs or other valid transfer mechanism, with the information in this DPA incorporated as applicable.
6.4 Alternative Mechanisms. If the SCCs or another transfer mechanism relied upon by the parties is invalidated, amended, replaced, or no longer legally sufficient, the parties will cooperate in good faith to implement another valid mechanism.
7. US state privacy laws
7.1 Service Provider / Processor. To the extent the CCPA or another U.S. state privacy law applies to Customer Personal Data, Tego AI will act as a service provider, contractor, or processor, as applicable, and will Process such data only for the limited and specified purposes described in the Agreement, this DPA, and Customer's documented instructions.
7.2 Restrictions. Tego AI will not sell or share Customer Personal Data as those terms are defined by the CCPA; retain, use, or disclose Customer Personal Data outside the direct business relationship with Customer except as permitted by applicable law; or combine Customer Personal Data received from Customer with personal information received from another person or collected from Tego AI's own interaction with a consumer, except as permitted by applicable law.
7.3 Compliance. Tego AI will notify Customer if it determines that it can no longer meet an applicable statutory obligation regarding Customer Personal Data and will allow Customer to take reasonable and appropriate steps to stop and remediate unauthorized use of Customer Personal Data as required by applicable law.
8. Information Rights and Audits
8.1 Documentation. Upon reasonable written request, Tego AI will provide information reasonably necessary to demonstrate compliance with this DPA, which may include then-current security documentation, questionnaires, summaries of third-party assessments, or other appropriate evidence, subject to confidentiality restrictions.
8.2 Audits. If the information provided under Section 8.1 is not reasonably sufficient to demonstrate compliance, Customer may, no more than once in any twelve (12) month period, request an audit of Tego AI's relevant Processing activities by Customer or a qualified independent auditor, on at least thirty (30) days' prior written notice, during normal business hours, subject to reasonable confidentiality, security, and operational requirements. The audit must not unreasonably interfere with Tego AI's business or expose information relating to other customers. Customer will bear its audit costs unless the audit identifies a material breach of this DPA by Tego AI. More frequent audits may be conducted where required by a competent regulator or following a material Personal Data Breach affecting Customer Personal Data.
9. Liability
The liability of each party and its affiliates arising out of or relating to this DPA is subject to the limitations and exclusions of liability set forth in the Agreement, unless Applicable Data Protection Law prohibits those limitations or exclusions. Nothing in this DPA creates a separate or additional indemnity unless expressly stated in the Agreement.
10. General
10.1 Order of Precedence. If there is a conflict among the Agreement, this DPA, and the SCCs, the SCCs control to the extent of the conflict for Processing governed by the SCCs, then this DPA, then the Agreement.
10.2 Changes Required by Law. If Applicable Data Protection Law changes in a manner that requires amendment of this DPA, the parties will cooperate in good faith to make the minimum changes reasonably necessary to comply with law.
10.3 Survival. Tego AI's obligations relating to Customer Personal Data survive termination of the Agreement for so long as Tego AI retains Customer Personal Data.
10.4 Counterparts. This DPA may be executed in counterparts and by electronic signature. If the Agreement is executed by both parties and incorporates this DPA by reference, a separate signature on this DPA is not required unless requested by either party.
11. Audit and certifications
- SOC 2 Type II — certified. The report is available at trust.tego.ai.
- GDPR certification — in progress.
Tego's audit reports and security documentation are available at trust.tego.ai. Upon written request, Tego will make available information reasonably necessary to demonstrate compliance with this DPA.
12. Contact
Privacy and data protection enquiries: privacy@tego.ai