Data Processing Agreement

Last Updated: March 2026

This DPA is automatically incorporated into and forms part of the Tensorix Terms of Service for all customers. By using our Services, you agree to this DPA. No separate signature is required.

If your organisation requires a countersigned copy for your records, please contact legal@tensorix.ai.

This Data Processing Agreement (“DPA”) forms part of the Tensorix Terms of Service (“Terms”) between Tensorix Limited (“Tensorix”, “we”, “us”) and the Customer (“you”, “Customer”). It sets out the additional terms, requirements, and conditions on which Tensorix will process Customer Personal Data when providing its Services.

1. Definitions

All capitalised terms not defined herein shall have the meaning set forth in the Terms. The following additional definitions apply:

  • “Controller” means the Customer or the entity, alone or jointly with others, that determines the purposes and means of the Processing of Personal Data.
  • “Data Subject” means an identified or identifiable natural person.
  • “Data Protection Legislation” means (a) the General Data Protection Regulation (Regulation (EU) 2016/679) (“GDPR”); (b) the Irish Data Protection Acts 1988 and 2018; (c) the European Communities (Electronic Communications Networks & Services) (Privacy & Electronic Communications) Regulations 2011; (d) the UK GDPR and the UK Data Protection Act 2018; (e) the EU ePrivacy Directive 2002/58/EC (as amended); and (f) any relevant transposition of, or successor or replacement to, the laws detailed at (a) to (e) inclusive; and all other industry guidelines (whether statutory or non-statutory) or applicable codes of practice and guidance notes issued from time to time by the Irish Data Protection Commission or other relevant national or supra-national authority relating to the processing of Personal Data or privacy; all as amended, re-enacted and/or replaced from time to time.
  • “Delete” means to remove or obliterate Personal Data such that it cannot be recovered or reconstructed.
  • “Personal Data” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a Data Subject.
  • “Personal Data Breach” means any breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data processed by Tensorix or its Sub-processors.
  • “Process”, “Processed” or “Processing” means any operation or set of operations performed on Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
  • “Processor” means Tensorix or an entity that Processes Personal Data on behalf of the Controller.
  • “Sensitive Personal Data” has the meaning given in Clause 2.4.
  • “Standard Contractual Clauses” means the European Union standard contractual clauses for international transfers from the European Economic Area to third countries, Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
  • “Sub-processor” means any third party processor engaged by Tensorix or its Affiliates in the Processing of Customer Personal Data.

2. Roles and Responsibilities

2.1 In providing the Services, Tensorix may be required to process Customer Personal Data on the Customer’s behalf. The parties record their intention that the Customer and its Affiliates (as applicable) shall be the Controller and Tensorix shall be a Processor. The parties shall exercise their rights hereunder acting in good faith and in a reasonable manner.

2.2 The Customer shall, at all times, comply with its obligations as Controller and shall be responsible for the Processing of all Customer Personal Data processed under or in connection with the Terms by its Authorised Users in accordance with applicable Data Protection Legislation. The Customer shall have sole responsibility for the accuracy, quality, and legality of Customer Personal Data and the means by which the Customer acquires the Personal Data.

2.3 The Customer shall ensure valid consents are obtained from, and shall cause appropriate notices to be provided to, Data Subjects, in each case that are necessary for Tensorix to Process (and have Processed by Sub-processors) Personal Data under or in connection with this DPA in accordance with Data Protection Legislation.

2.4 The Customer shall inform Tensorix in writing prior to engaging with the Services if the Customer Personal Data includes any of the following: (i) credit, debit or other payment card data subject to the Payment Card Industry Data Security Standards; (ii) patient, medical or other protected health information regulated by HIPAA; or (iii) any other personal data deemed to be in a “special category” under the GDPR (collectively, “Sensitive Personal Data“). Where the Customer intends to process Sensitive Personal Data through the Services, the parties shall execute a supplementary agreement setting out additional technical and organisational measures. Until such supplementary agreement is in place, the Customer shall not use the Services to process Sensitive Personal Data.

2.5 Annex 1 to this DPA sets out certain information regarding Tensorix and its Sub-processors’ Processing of the Customer Personal Data.

2.6 The Customer hereby instructs Tensorix (and consents and authorises Tensorix to instruct each Sub-processor) to process Customer Personal Data as reasonably necessary for the provision of the Services.

3. Data Protection Obligations

To the extent that Tensorix Processes Customer Personal Data pursuant to the Terms, Tensorix warrants, represents, and undertakes to Customer that it shall:

  • 3.1.1 Process Customer Personal Data only on the Customer’s documented instructions, including the Terms. Tensorix will immediately inform the Customer if, in its opinion, an instruction infringes Data Protection Legislation or other data protection provisions.
  • 3.1.2 Process any Customer Personal Data only to the extent required to provide the Services and in a manner in accordance with all Data Protection Legislation, unless required to do otherwise by law, in which case Tensorix shall inform the Customer of such legal requirement before Processing (where legally permitted).
  • 3.1.3 Not Process Customer Personal Data for any purpose other than for the business purposes specified in the Terms, or otherwise retain, use, or disclose Personal Data outside of the direct business relationship between Tensorix and the Customer.
  • 3.1.4 Taking into account the nature and extent of Processing, implement and maintain technical and organisational measures to ensure a level of security appropriate to the risk presented by Processing the Customer Personal Data, in particular from accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Customer Personal Data.
  • 3.1.5 Not permit any Processing of any Customer Personal Data outside of the European Economic Area and/or the United Kingdom without the Customer’s prior written consent and subject to the execution of an appropriate data transfer agreement in compliance with Data Protection Legislation in accordance with Section 6, unless Tensorix or Sub-processors are required to transfer the Personal Data to comply with applicable laws.
  • 3.1.6 Cooperate as reasonably requested by the Customer to enable the Customer to comply with any exercise of rights by a Data Subject under the Data Protection Legislation. Tensorix shall implement and maintain appropriate technical and organisational measures to assist the Customer in responding to Data Subject requests and shall notify the Customer promptly upon receipt of any such request. Tensorix will not respond to any request from a Data Subject except on the documented instructions of the Customer or as required by law.
  • 3.1.7 Upon the Customer’s request, provide reasonable cooperation and assistance to fulfil the Customer’s obligations under Data Protection Legislation, including with regard to data privacy impact assessments and consultations with supervisory authorities.
  • 3.1.8 Maintain proper up-to-date records of any Customer Personal Data Processed by or on behalf of Tensorix pursuant to this DPA.
  • 3.1.9 Ensure that any person authorised to process the Customer’s Personal Data: (i) has committed themselves to appropriate contractual confidentiality obligations; (ii) Processes the Personal Data solely on behalf of and in accordance with the instructions from the Customer; and (iii) is appropriately reliable, qualified, and trained in relation to their Processing of Personal Data.
  • 3.1.10 Appoint and identify to the Customer a named individual within Tensorix to act as a point of contact for any enquiries relating to Customer Personal Data.
  • 3.1.11 At the Customer’s option within forty-five (45) days of a written request, either: (i) return to the Customer (by way of a final export via Tensorix APIs); or (ii) Delete from its systems and records all Customer Personal Data and any copies. Tensorix shall provide a certificate of confirmation that this clause has been complied with in full.

4. Personal Data Breach

4.1 Tensorix shall promptly upon becoming aware, and in any event within seventy-two (72) hours of becoming aware of a Personal Data Breach, notify the Customer of the Personal Data Breach where the Personal Data Breach directly affects Customer Personal Data or the Services being offered to the Customer.

4.2 Tensorix shall, at no additional cost to the Customer (save where the Customer shall reimburse Tensorix’s reasonable costs where Tensorix has complied fully with its obligations and such breach is not due to Tensorix default or neglect), provide sufficient information and assistance to the Customer in ensuring compliance with its obligations in relation to notification of Personal Data Breaches, and communication of Personal Data Breaches to Data Subjects where the breach is likely to result in a high risk to the rights of such Data Subjects, and take such reasonable commercial steps as are directed by the Customer to assist in the investigation, mitigation, and remediation of such Personal Data Breach.

5. Sub-processors

5.1 The Customer confirms its prior general consent to sub-processing of the Customer Personal Data by Tensorix’s current Sub-processors, a list of which is set out in Annex 1 to this DPA and on our Sub-processors page.

5.2 Tensorix will provide written notice to the Customer of any intended addition or replacement of a Sub-processor at least fourteen (14) calendar days before the Sub-processor first Processes Customer Personal Data (the “Sub-processor Notice Period”). The Controller may object, on reasonable data-protection grounds, by notifying Tensorix in writing within the Sub-processor Notice Period; if no objection is received, the Sub-processor will be deemed accepted.

5.3 Tensorix shall ensure that: (i) it shall enter into an agreement with the Sub-processor with terms not less protective than the provisions of this DPA; and (ii) Tensorix will remain responsible and liable for the Sub-processor’s compliance with its obligations and for any acts or omissions of such Sub-processor.

6. Data Transfers

6.1 If Tensorix transfers Personal Data outside the EEA or UK to a third country that is not recognised by the European Commission (or relevant authority) as providing an adequate level of protection, such transfers shall be governed by the Standard Contractual Clauses. The parties agree that by accepting the Terms they also execute the Standard Contractual Clauses, which are incorporated by reference and form an integral part of this DPA. In case of any conflicts between the provisions of this DPA and the Standard Contractual Clauses, the Standard Contractual Clauses shall prevail.

6.2 For Personal Data of Data Subjects in the United Kingdom, the parties adopt the modifications to the Standard Contractual Clauses listed in Annex 2 to adapt the Standard Contractual Clauses to local law, as applicable.

6.3 Tensorix will enter into (and will cause its Sub-processors to enter into) any additional agreements or adhere to any additional contractual terms related to the Processing, including cross-border data transfer, of Personal Data as the Customer may instruct in writing to comply with Data Protection Legislation.

7. Audit

7.1 Subject to Clause 7.2, the Customer shall have the right to audit Tensorix systems, processes, and procedures relevant to the protection of Customer Personal Data.

7.2 An audit shall be: (i) carried out no more than once in any twelve (12) month period during the Term; (ii) conducted during Business Hours over the course of one Business Day; (iii) subject to a minimum thirty (30) days’ prior written notice; and (iv) in relation to the Customer’s Personal Data only.

7.3 The Customer shall bear any and all expenses incurred by Tensorix in respect of any such audit.

7.4 If the scope of the audit is addressed in an ISO 27001/27701 or similar audit report performed by a qualified third party auditor within the previous twelve (12) months, and Tensorix’s data protection officer certifies in writing there are no known material changes, the Customer shall agree to accept those reports in lieu of requesting an audit.

8. Indemnity

The parties shall indemnify each other (“Indemnified Party”) from and against any and all third party claims, suits, demands and actions and for resulting damages, awards of damages, losses, costs, and expenses (including but not limited to any regulatory fines and reasonable legal and professional fees) incurred by a party that result or arise from any breach by either party of the terms and conditions of this DPA and/or Data Protection Legislation. Such breaching party shall be liable on a comparative basis for the portion of those damages directly attributable to its breach, and the indemnity shall be subject to the limitations of liability in the Terms.

9. Changes in Data Protection Laws

Tensorix may propose variations to this DPA which Tensorix reasonably considers necessary to address the requirements of any Data Protection Legislation. The parties shall promptly discuss the proposed variations and negotiate in good faith. The Customer shall not unreasonably withhold or delay agreement to any consequential variations proposed by Tensorix to comply with Data Protection Legislation.

10. Term and Termination

10.1 This DPA will remain in full force and effect so long as: (a) the Terms remain in effect; or (b) Tensorix retains any of the Customer Personal Data related to the Terms in its possession or control.

10.2 Any provision of this DPA that expressly or by implication should come into or continue in force on or after termination of the Terms in order to protect the Customer Personal Data will remain in full force and effect.

Annex 1 — Details of Processing

(a) Subject Matter and Duration

The subject matter is Customer Personal Data and the duration of the Processing is set out in the Terms.

(b) Nature and Purpose

Tensorix Limited is a secure enterprise AI inference platform, providing API access to various open-source large language models. Infrastructure is EU-sovereign, physically located in Dublin and Helsinki. A core feature of the platform is a zero data retention guarantee: prompts and completions are processed in ephemeral enclaves and are never stored. The service targets regulated industries including finance, healthcare, and government.

Tensorix will Process Personal Data as necessary to perform the Services pursuant to the Terms and as further instructed by the Customer in its use of the Services.

(c) Types of Personal Data Processed

Identity and contact data

  • First name, last name, email address

Authentication and security data

  • Hashed password, email verification status
  • Login timestamps, IP address of login attempts
  • Device user agent strings
  • Geographic location derived from login IP address

Account and organisational data

  • User identifier (UUID), team and organisation membership and role
  • API key metadata (name, prefix, hash)
  • Marketing email preferences

Financial and usage data

  • Wallet balance and transaction history
  • Stripe customer identifier
  • Cryptocurrency deposit records (amounts, currency, network, transaction identifiers)
  • API usage metrics (token counts, model used, spend)

⚠️ Note: Tensorix does not store prompt content or inference results. All prompts and completions are processed in ephemeral enclaves and are not persisted to any storage system.

(d) Categories of Data Subjects

  • Authorised Users (as defined in the Terms)
  • Customer’s customers

(e) Sub-processors

The following Sub-processors are engaged by Tensorix. A current list is always available at /sub-processors.

Sub-processorPurposeLocation
Cloudflare, Inc.CDN, DNS, network security and DDoS protectionEU (European data centres)
Amazon Web Services, Inc. (AWS)Cloud infrastructureEU (European data centres)
Railway Corp.Application deployment and hosting infrastructureEU (European data centres)
VerdaData centre / colocation infrastructureFinland, EU
Digital Realty Trust, Inc.Data centre / colocation infrastructureDublin, Ireland, EU
Google LLC (Workspace)Email and internal communicationsEU (European data centres)
Stripe, Inc.Payment processing (card payments)EU (European data centres)
DeusXPayCryptocurrency payment processingEU (European data centres)
Resend (Plus Five Five, Inc.)Transactional and marketing email deliveryUnited States (SCCs in place)

Annex 2 — Information for International Transfers

Categories of data subjects: See Annex 1.

Categories of personal data transferred: See Annex 1.

Frequency of the transfer: Data is transferred on a continuous basis during the term of the Terms, unless otherwise specifically agreed.

Nature of the processing: Tensorix will Process Personal Data as necessary to perform the Services, including storage, organisation, structuring, disclosure by transmission, dissemination or making available, and other forms of processing.

Purpose(s) of the data transfer: The purpose is to provide the Services to the Customer, as further specified in the Terms.

Retention period: As a Processor, Tensorix retains Personal Data for the duration of the Terms and consistent with its obligations under applicable law.

Standard Contractual Clauses — Selections

  • Clause 9(a) (Module 2 and 3): Option 2. The time period is 30 days.
  • Clause 11(a): The parties do not select the independent dispute resolution option.
  • Clause 17: Option 1. The governing jurisdiction is Ireland.
  • Clause 18: The forum is Ireland.
  • Annex I(A): The data exporter is Customer and the data importer is Tensorix.
  • Annex I(B): The parties agree that Annex 1 describes the transfer.
  • Annex I(C): The competent supervisory authority is the Irish Data Protection Commission.

United Kingdom

  • For transfers of personal data from the UK, the parties agree to comply with the terms of Part 2: Mandatory Clauses of the Addendum, being the template UK International Data Transfer Addendum B.1.0 issued by the UK Information Commissioner.
  • The Standard Contractual Clauses are deemed amended to the extent necessary so they operate for transfers from the United Kingdom to a Third Country and provide appropriate safeguards for transfers according to Article 46 of the UK GDPR.
  • Clause 17: The governing jurisdiction is the United Kingdom.
  • Clause 18: The forum is the courts of England and Wales. Data Subjects may bring legal proceedings in the courts of any country in the United Kingdom.

Questions?

If you have any questions about this DPA or need a countersigned copy, contact us at:

Tensorix Ltd.
Unit 25, Classon House
Dundrum Business Park
Dublin 14, Ireland
Email: legal@tensorix.ai