Data Processing Agreement

Last Updated: July 2026

This DPA is automatically incorporated into and forms part of the TensorX Terms of Service for all customers. By using our Services, you agree to this DPA. No separate signature is required.

If your organisation requires a countersigned copy for your records, please contact [email protected].

This Data Processing Agreement (“DPA”) forms part of the TensorX Terms of Service (“Terms”) between TensorX Limited (“TensorX”, “we”, “us”) and the Customer (“you”, “Customer”). It sets out the additional terms, requirements, and conditions on which TensorX will process Customer Personal Data when providing its Services.

1. Definitions

All capitalised terms not defined herein shall have the meaning set forth in the Terms. The following additional definitions apply:

  • “Controller” means the Customer or the entity, alone or jointly with others, that determines the purposes and means of the Processing of Personal Data.
  • “Data Subject” means an identified or identifiable natural person.
  • “Data Protection Legislation” means (a) the General Data Protection Regulation (Regulation (EU) 2016/679) (“GDPR”); (b) the Irish Data Protection Acts 1988 and 2018; (c) the European Communities (Electronic Communications Networks & Services) (Privacy & Electronic Communications) Regulations 2011; (d) the UK GDPR and the UK Data Protection Act 2018; (e) the EU ePrivacy Directive 2002/58/EC (as amended); and (f) any relevant transposition of, or successor or replacement to, the laws detailed at (a) to (e) inclusive; and all other industry guidelines (whether statutory or non-statutory) or applicable codes of practice and guidance notes issued from time to time by the Irish Data Protection Commission or other relevant national or supra-national authority relating to the processing of Personal Data or privacy; all as amended, re-enacted and/or replaced from time to time.
  • “Delete” means to remove or obliterate Personal Data such that it cannot be recovered or reconstructed.
  • “Personal Data” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a Data Subject.
  • “Personal Data Breach” means any breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data processed by TensorX or its Sub-processors.
  • “Process”, “Processed” or “Processing” means any operation or set of operations performed on Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
  • “Processor” means TensorX or an entity that Processes Personal Data on behalf of the Controller.
  • “Sensitive Personal Data” has the meaning given in Clause 2.4.
  • “Standard Contractual Clauses” means the European Union standard contractual clauses for international transfers from the European Economic Area to third countries, Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
  • “Sub-processor” means any third party processor engaged by TensorX or its Affiliates in the Processing of Customer Personal Data.

2. Roles and Responsibilities

2.1 In providing the Services, TensorX may be required to process Customer Personal Data on the Customer’s behalf. The parties record their intention that the Customer and its Affiliates (as applicable) shall be the Controller and TensorX shall be a Processor. The parties shall exercise their rights hereunder acting in good faith and in a reasonable manner.

2.2 The Customer shall, at all times, comply with its obligations as Controller and shall be responsible for the Processing of all Customer Personal Data processed under or in connection with the Terms by its Authorised Users in accordance with applicable Data Protection Legislation. The Customer shall have sole responsibility for the accuracy, quality, and legality of Customer Personal Data and the means by which the Customer acquires the Personal Data.

2.3 The Customer shall ensure valid consents are obtained from, and shall cause appropriate notices to be provided to, Data Subjects, in each case that are necessary for TensorX to Process (and have Processed by Sub-processors) Personal Data under or in connection with this DPA in accordance with Data Protection Legislation.

2.4 The Customer shall inform TensorX in writing prior to engaging with the Services if the Customer Personal Data includes any of the following: (i) credit, debit or other payment card data subject to the Payment Card Industry Data Security Standards; (ii) patient, medical or other protected health information regulated by HIPAA; or (iii) any other personal data deemed to be in a “special category” under the GDPR (collectively, “Sensitive Personal Data“).

2.5 Annex 1 to this DPA sets out certain information regarding TensorX and its Sub-processors’ Processing of the Customer Personal Data.

2.6 The Customer hereby instructs TensorX (and consents and authorises TensorX to instruct each Sub-processor) to process Customer Personal Data as reasonably necessary for the provision of the Services.

3. Data Protection Obligations

To the extent that TensorX Processes Customer Personal Data pursuant to the Terms, TensorX warrants, represents, and undertakes to Customer that it shall:

  • 3.1.1 Process Customer Personal Data only on the Customer’s documented instructions, including the Terms. TensorX will immediately inform the Customer if, in its opinion, an instruction infringes Data Protection Legislation or other data protection provisions.
  • 3.1.2 Process any Customer Personal Data only to the extent required to provide the Services and in a manner in accordance with all Data Protection Legislation, unless required to do otherwise by law, in which case TensorX shall inform the Customer of such legal requirement before Processing (where legally permitted).
  • 3.1.3 Not Process Customer Personal Data for any purpose other than for the business purposes specified in the Terms, or otherwise retain, use, or disclose Personal Data outside of the direct business relationship between TensorX and the Customer.
  • 3.1.4 Taking into account the nature and extent of Processing, implement and maintain technical and organisational measures to ensure a level of security appropriate to the risk presented by Processing the Customer Personal Data, in particular from accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Customer Personal Data.
  • 3.1.5 Not permit any Processing of any Customer Personal Data outside of the European Economic Area and/or the United Kingdom without the Customer’s prior written consent and subject to the execution of an appropriate data transfer agreement in compliance with Data Protection Legislation in accordance with Section 6, unless TensorX or Sub-processors are required to transfer the Personal Data to comply with applicable laws.
  • 3.1.6 Cooperate as reasonably requested by the Customer to enable the Customer to comply with any exercise of rights by a Data Subject under the Data Protection Legislation. TensorX shall implement and maintain appropriate technical and organisational measures to assist the Customer in responding to Data Subject requests and shall notify the Customer promptly upon receipt of any such request. TensorX will not respond to any request from a Data Subject except on the documented instructions of the Customer or as required by law.
  • 3.1.7 Upon the Customer’s request, provide reasonable cooperation and assistance to fulfil the Customer’s obligations under Data Protection Legislation, including with regard to data privacy impact assessments and consultations with supervisory authorities.
  • 3.1.8 Maintain proper up-to-date records of any Customer Personal Data Processed by or on behalf of TensorX pursuant to this DPA.
  • 3.1.9 Ensure that any person authorised to process the Customer’s Personal Data: (i) has committed themselves to appropriate contractual confidentiality obligations; (ii) Processes the Personal Data solely on behalf of and in accordance with the instructions from the Customer; and (iii) is appropriately reliable, qualified, and trained in relation to their Processing of Personal Data.
  • 3.1.10 Appoint and identify to the Customer a named individual within TensorX to act as a point of contact for any enquiries relating to Customer Personal Data.
  • 3.1.11 At the Customer’s option within forty-five (45) days of a written request, either: (i) return to the Customer (by way of a final export via TensorX APIs); or (ii) Delete from its systems and records all Customer Personal Data and any copies. TensorX shall provide a certificate of confirmation that this clause has been complied with in full.

3.2 TensorX shall not store, log or otherwise persist Customer prompts, inputs or outputs (“Inference Data”) to any storage system; Inference Data is processed transiently in ephemeral enclaves solely as necessary to provide the Services. TensorX shall not use Inference Data or any other Customer Personal Data to train, fine-tune or otherwise improve any AI model.

4. Personal Data Breach

4.1 TensorX shall promptly upon becoming aware, and in any event within seventy-two (72) hours of becoming aware of a Personal Data Breach, notify the Customer of the Personal Data Breach where the Personal Data Breach directly affects Customer Personal Data or the Services being offered to the Customer.

4.2 TensorX shall, at no additional cost to the Customer (save where the Customer shall reimburse TensorX’s reasonable costs where TensorX has complied fully with its obligations and such breach is not due to TensorX default or neglect), provide sufficient information and assistance to the Customer in ensuring compliance with its obligations in relation to notification of Personal Data Breaches, and communication of Personal Data Breaches to Data Subjects where the breach is likely to result in a high risk to the rights of such Data Subjects, and take such reasonable commercial steps as are directed by the Customer to assist in the investigation, mitigation, and remediation of such Personal Data Breach.

5. Sub-processors

5.1 The Customer confirms its prior general consent to sub-processing of the Customer Personal Data by TensorX’s current Sub-processors, a list of which is set out in Annex 1 to this DPA and on our Sub-processors page.

5.2 TensorX will provide written notice to the Customer of any intended addition or replacement of a Sub-processor at least fourteen (14) calendar days before the Sub-processor first Processes Customer Personal Data (the “Sub-processor Notice Period”). The Controller may object, on reasonable data-protection grounds, by notifying TensorX in writing within the Sub-processor Notice Period; if no objection is received, the Sub-processor will be deemed accepted.

5.3 TensorX shall ensure that: (i) it shall enter into an agreement with the Sub-processor with terms not less protective than the provisions of this DPA; and (ii) TensorX will remain responsible and liable for the Sub-processor’s compliance with its obligations and for any acts or omissions of such Sub-processor.

6. Data Transfers

6.1 If TensorX transfers Personal Data outside the EEA or UK to a third country that is not recognised by the European Commission (or relevant authority) as providing an adequate level of protection, such transfers shall be governed by the Standard Contractual Clauses. The parties agree that by accepting the Terms they also execute the Standard Contractual Clauses, which are incorporated by reference and form an integral part of this DPA. In case of any conflicts between the provisions of this DPA and the Standard Contractual Clauses, the Standard Contractual Clauses shall prevail.

6.2 For Personal Data of Data Subjects in the United Kingdom, the parties adopt the modifications to the Standard Contractual Clauses listed in Annex 2 to adapt the Standard Contractual Clauses to local law, as applicable.

6.3 TensorX will enter into (and will cause its Sub-processors to enter into) any additional agreements or adhere to any additional contractual terms related to the Processing, including cross-border data transfer, of Personal Data as the Customer may instruct in writing to comply with Data Protection Legislation.

7. Audit

7.1 Subject to Clause 7.2, the Customer shall have the right to audit TensorX systems, processes, and procedures relevant to the protection of Customer Personal Data.

7.2 An audit shall be: (i) carried out no more than once in any twelve (12) month period during the Term; (ii) conducted during Business Hours over the course of one Business Day; (iii) subject to a minimum thirty (30) days’ prior written notice; and (iv) in relation to the Customer’s Personal Data only.

7.3 The Customer shall bear any and all expenses incurred by TensorX in respect of any such audit.

7.4 If the scope of the audit is addressed in an ISO 27001/27701 or similar audit report performed by a qualified third party auditor within the previous twelve (12) months, and TensorX’s data protection officer certifies in writing there are no known material changes, the Customer shall agree to accept those reports in lieu of requesting an audit.

8. Indemnity

The parties shall indemnify each other (“Indemnified Party”) from and against any and all third party claims, suits, demands and actions and for resulting damages, awards of damages, losses, costs, and expenses (including but not limited to any regulatory fines and reasonable legal and professional fees) incurred by a party that result or arise from any breach by either party of the terms and conditions of this DPA and/or Data Protection Legislation. Such breaching party shall be liable on a comparative basis for the portion of those damages directly attributable to its breach, and the indemnity shall be subject to the limitations of liability in the Terms.

9. Changes in Data Protection Laws

TensorX may propose variations to this DPA which TensorX reasonably considers necessary to address the requirements of any Data Protection Legislation. The parties shall promptly discuss the proposed variations and negotiate in good faith. The Customer shall not unreasonably withhold or delay agreement to any consequential variations proposed by TensorX to comply with Data Protection Legislation.

10. Term and Termination

10.1 This DPA will remain in full force and effect so long as: (a) the Terms remain in effect; or (b) TensorX retains any of the Customer Personal Data related to the Terms in its possession or control.

10.2 Any provision of this DPA that expressly or by implication should come into or continue in force on or after termination of the Terms in order to protect the Customer Personal Data will remain in full force and effect.

Annex 1 — Details of Processing

(a) Subject Matter and Duration

The subject matter is Customer Personal Data and the duration of the Processing is set out in the Terms.

(b) Nature and Purpose

TensorX Limited is a secure enterprise AI inference platform, providing API access to various open-source large language models. Infrastructure is EU-sovereign, physically located in Dublin and Helsinki. A core feature of the platform is a zero data retention guarantee: prompts and completions are processed in ephemeral enclaves and are never stored. The service targets regulated industries including finance, healthcare, and government.

TensorX will Process Personal Data as necessary to perform the Services pursuant to the Terms and as further instructed by the Customer in its use of the Services.

(c) Types of Personal Data Processed

Identity and contact data

  • First name, last name, email address

Authentication and security data

  • Hashed password, email verification status
  • Login timestamps, IP address of login attempts
  • Device user agent strings
  • Geographic location derived from login IP address

Account and organisational data

  • User identifier (UUID), team and organisation membership and role
  • API key metadata (name, prefix, hash)
  • Marketing email preferences

Financial and usage data

  • Wallet balance and transaction history
  • Stripe customer identifier
  • Cryptocurrency deposit records (amounts, currency, network, transaction identifiers)
  • API usage metrics (token counts, model used, spend)

⚠️ Note: TensorX does not store prompt content or inference results. All prompts and completions are processed in ephemeral enclaves and are not persisted to any storage system.

(d) Categories of Data Subjects

  • Authorised Users (as defined in the Terms)
  • Customer’s customers

(e) Sub-processors

The following Sub-processors are engaged by TensorX. A current list is always available at /sub-processors.

Sub-processorPurposeLocation
Cloudflare, Inc.CDN, DNS, network security and DDoS protectionEU (European data centres)
Amazon Web Services, Inc. (AWS)Cloud infrastructureEU (European data centres)
Railway Corp.Application deployment and hosting infrastructureEU (European data centres)
VerdaData centre / colocation infrastructureFinland, EU
Digital Realty Trust, Inc.Data centre / colocation infrastructureDublin, Ireland, EU
Google LLC (Workspace)Email and internal communicationsEU (European data centres)
Stripe, Inc.Payment processing (card payments)EU (European data centres)
DeusXPayCryptocurrency payment processingEU (European data centres)
Resend (Plus Five Five, Inc.)Transactional and marketing email deliveryUnited States (SCCs in place)
Intercom R&D Unlimited CompanyCustomer support chat and messagingEU / United States (SCCs in place)
Attio LimitedCustomer Relationship Management EU / UK / United States

Annex 2 — Information for International Transfers

Categories of data subjects: See Annex 1.

Categories of personal data transferred: See Annex 1.

Frequency of the transfer: Data is transferred on a continuous basis during the term of the Terms, unless otherwise specifically agreed.

Nature of the processing: TensorX will Process Personal Data as necessary to perform the Services, including storage, organisation, structuring, disclosure by transmission, dissemination or making available, and other forms of processing.

Purpose(s) of the data transfer: The purpose is to provide the Services to the Customer, as further specified in the Terms.

Retention period: As a Processor, TensorX retains Personal Data for the duration of the Terms and consistent with its obligations under applicable law.

Standard Contractual Clauses — Selections

  • Clause 9(a) (Module 2 and 3): Option 2. The time period is 30 days.
  • Clause 11(a): The parties do not select the independent dispute resolution option.
  • Clause 17: Option 1. The governing jurisdiction is Ireland.
  • Clause 18: The forum is Ireland.
  • Annex I(A): The data exporter is Customer and the data importer is TensorX.
  • Annex I(B): The parties agree that Annex 1 describes the transfer.
  • Annex I(C): The competent supervisory authority is the Irish Data Protection Commission.

United Kingdom

  • For transfers of personal data from the UK, the parties agree to comply with the terms of Part 2: Mandatory Clauses of the Addendum, being the template UK International Data Transfer Addendum B.1.0 issued by the UK Information Commissioner.
  • The Standard Contractual Clauses are deemed amended to the extent necessary so they operate for transfers from the United Kingdom to a Third Country and provide appropriate safeguards for transfers according to Article 46 of the UK GDPR.
  • Clause 17: The governing jurisdiction is the United Kingdom.
  • Clause 18: The forum is the courts of England and Wales. Data Subjects may bring legal proceedings in the courts of any country in the United Kingdom.

Questions?

If you have any questions about this DPA or need a countersigned copy, contact us at:

TensorX Ltd.
Unit 25, Classon House
Dundrum Business Park
Dublin 14, Ireland
Email: [email protected]