Data Processing Addendum (DPA)
This Data Processing Addendum ("DPA") supplements the Tayeno Terms of Service and applies where Tayeno processes personal data on behalf of business customers ("Controllers") in the United Kingdom or European Economic Area.
1. Scope and Processing Details
Subject Matter: Provision of AI chief-of-staff services (email triage, meeting prep, drafting).
Duration: The duration of the active subscription plus a 30-day post-termination deletion buffer.
Data Subjects: Customer's employees, correspondents, clients, and prospective business contacts.
Categories of Data: Names, email addresses, email message headers & bodies, calendar event metadata, publicly accessible company web data.
2. Obligations of Processor (Tayeno)
- Process personal data strictly on documented instructions from the Controller.
- Ensure all personnel and subprocessors are bound by statutory confidentiality duties.
- Maintain technical measures including AES-256-GCM vault encryption, per-tenant Linux isolation, and outside-LLM secret resolution.
- Notify the Controller without undue delay and in any event within 24 hours upon becoming aware of any confirmed personal data breach.
- Delete or return all customer personal data upon termination of the subscription.
3. Sub-Processors & International Transfers
Controller grants general authorization for Tayeno to engage the sub-processors listed in our Privacy Policy (Hetzner Online GmbH, DeepSeek [Hangzhou DeepSeek AI Co., Ltd.], Stripe Payments UK Ltd, Telegram FZ-LLC). Inference prompts are processed via DeepSeek API endpoints located in China. <!-- TODO (Clint): Formalize UK International Data Transfer Agreement (IDTA) or Standard Contractual Clauses schedule with DeepSeek -->. Tayeno will notify Controller of any intended changes to sub-processors at least 14 days in advance.