Last Updated: September 2026
This DPA is automatically incorporated into and forms part of the TensorX Terms of Service for all customers. By using our Services, you agree to this DPA. No separate signature is required.
TensorX (“TensorX”) provides a secure enterprise AI inference platform, offering API access to various open-source large language models through AI model routing services. The Services are operated exclusively on EU-sovereign infrastructure physically located in Dublin and Helsinki. The Customer (“Customer”) uses the Services to process requests containing data submitted by or on behalf of the Customer or, where the Customer acts as a Processor, by or on behalf of the relevant third-party Controller. In providing the Services, TensorX may Process Personal Data contained in the Customer API Data solely on behalf of the Customer and in accordance with the Customer’s documented instructions.
This Data Processing Agreement (“DPA”) governs the Processing of Personal Data by TensorX in connection with the Services and forms part of the agreement between the Parties.
This DPA forms an integral part of the Agreement entered into between the Customer and TensorX, consisting of Terms and Conditions, Linked Documents and Order Form (if applicable) (together “Agreement”). In the event of a conflict between this DPA and any other part of the Agreement, this DPA shall prevail with respect to the Processing of Personal Data.
Capitalised terms used and not defined herein shall have the meaning set out in the TensorX Terms of Service.
1. Introduction
1.1 In providing the Services under the Agreement, TensorX may be required to Process Personal Data on the Customer’s behalf. Where the Customer Processes Personal Data as a Controller, the Customer shall act as Controller and TensorX shall act as Processor. Where the Customer Processes Personal Data on behalf of a third-party Controller, the Customer shall act as Processor and TensorX shall act as Subprocessor in respect of such Personal Data. The parties shall exercise their rights hereunder acting in good faith and in a reasonable manner.
1.2 Customer shall, at all times, comply with its obligations under applicable Data Protection Legislation in respect of the Personal Data and shall be responsible for the Processing of all Personal Data processed under or in connection with the Agreement by its Authorised Users. Where the Customer acts as a Processor, the Customer represents and warrants that it is authorised by the relevant Controller to appoint TensorX as a Subprocessor, to provide the instructions set out in this DPA and to engage TensorX’s Sub-processors in accordance with this DPA. Customer shall have sole responsibility for the accuracy, quality and legality of Personal Data and the means by which Customer acquires or otherwise Processes the Personal Data.
1.3 Customer shall ensure that it has, or that the relevant Controller has, provided all notices, obtained all consents and established all other lawful bases or authorisations necessary for TensorX to Process (and have Processed by Sub-processors) Personal Data under or in connection with this DPA in accordance with Data Protection Legislation. Furthermore, Customer shall not, by act or omission, cause TensorX to violate Data Protection Legislation as a result of TensorX or its Sub-processors Processing the Personal Data in accordance with this DPA.
1.4 Annex 1 to this DPA sets out certain information regarding TensorX and its Sub-processors’ processing of the Personal Data.
1.5 Customer hereby instructs TensorX (and, where the Customer acts as a Processor, confirms that it is authorised by the relevant Controller to instruct TensorX) and consents and authorises TensorX to instruct each Sub-processor to Process Personal Data as reasonably necessary for the provision of the Services.
2. Data Protection Obligations
2.1 To the extent that TensorX processes Personal Data pursuant to the Agreement, TensorX warrants, represents and undertakes to Customer that it shall:
- 2.1.1 process Personal Data only on the Customer’s documented instructions including the Agreement. TensorX will immediately inform Customer if, in its opinion, an instruction infringes Data Protection Legislation or other data protection provisions;
- 2.1.2 process any Personal Data only to the extent required to provide the Services and in such a manner and at all times in accordance with all Data Protection Legislation, unless required to do otherwise by law, in which case, where legally permitted, TensorX shall inform Customer of such legal requirement before processing;
- 2.1.3 not process Personal Data for any purpose other than for the business purposes specified in the Agreement or otherwise retain, use or disclose Personal Data outside of the direct business relationship between TensorX and Customer;
- 2.1.4 taking into account the nature and extent of processing, implement and maintain technical and organisational measures to ensure a level of security appropriate to the risk presented by processing the Personal Data, in particular from accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Personal Data processed;
- 2.1.5 not permit any processing of any Personal Data outside of the European Economic Area and/or the United Kingdom without Customer’s prior written consent and subject then in any event to the execution of an appropriate data transfer agreement in compliance with Data Protection Legislation in accordance with Section 5, unless TensorX or Sub-processors are required to transfer the Personal Data to comply with applicable laws and such laws prohibit notice to Customer on public interest grounds;
- 2.1.6 considering the nature of the processing, with appropriate technical and organisational measures to the extent possible, cooperate as reasonably requested by Customer to enable Customer to: comply with any exercise of rights by a Data Subject under the Data Protection Legislation in respect of Customer Personal Data processed by TensorX under this DPA and shall implement and maintain appropriate technical and organisational measures to assist Customer in responding to such requests from Data Subjects and shall notify Customer promptly upon receipt of any such request from a Data Subject. TensorX will not respond to any request from a Data Subject except on the documented instructions of Customer or as required by law, in which case TensorX shall to the extent permitted by law inform Customer of that legal requirement before TensorX responds to the request;
- 2.1.7 upon Customer’s request, TensorX shall provide Customer with reasonable cooperation and assistance needed to fulfil Customer’s obligations under Data Protection Legislation, including with regards to data privacy impact assessments and consultations with supervisory authorities, to the extent Customer does not otherwise have access to the relevant information, and to the extent such information is available to TensorX. Any such reasonable assistance shall be at the cost of Customer;
- 2.1.8 ensure that any person authorised to process the Personal Data: (i) has committed themselves to appropriate contractual confidentiality obligations or is under an appropriate statutory obligation of confidentiality; (ii) Processes the Personal Data solely on behalf and in accordance with the instructions from Customer; and (iii) is appropriately reliable, qualified, and trained in relation to their processing of Personal Data.
- 2.1.9 appoint and identify to Customer a named individual within TensorX to act as a point of contact for any enquiries from Customer relating to Personal Data and cooperate in good faith with Customer concerning all such enquiries within a reasonable time period.
2.2 Return and deletion of Data
- 2.2.1 TensorX will, to the extent that it is possible, after the completion of the Service, either return or delete all Personal Data, unless there is an obligation to store Personal Data under the law.
- 2.2.2 Notwithstanding general deletion obligation.
- 2.2.3 The Customer acknowledges and agrees that TensorX does not store, log, or otherwise retain Customer API Data. Customer API Data is processed only transiently in ephemeral memory solely to the extent necessary to provide the Services and is not persisted to any storage system. Accordingly, the return or recovery of Customer API Data by TensorX is technically impossible.
- 2.2.4 TensorX shall not use Customer Data or Customer API Data to train, fine-tune, or otherwise improve any artificial intelligence model.
3. Personal Data Breach
3.1 Without prejudice to the other provisions of this DPA, TensorX shall promptly upon becoming aware and in any event within seventy-two (72) hours of becoming aware of a Personal Data breach, notify Customer of the Personal Data breach where the Personal Data breach directly affects Personal Data or the Services being offered to Customer.
3.2 TensorX shall, at no additional cost to Customer (save that Customer shall reimburse TensorX’s reasonable costs where TensorX has complied fully with its obligations under this DPA and such Personal Data Breach is not due to TensorX default or neglect), provide sufficient information and assistance to Customer in ensuring compliance with its obligations in relation to notification of Personal Data breaches, and communication of Personal Data breaches to Data Subjects where the breach is likely to result in a high risk to the rights of such Data Subjects, and take such reasonable commercial steps as are directed by Customer to assist in the investigation, mitigation and remediation of such Personal Data breach.
4. Sub-processors
4.1 Customer confirms its prior general consent to sub-processing of the Personal Data by TensorX’s current Sub-processors, a list of which is set out in Annex 1 to this DPA and which may be updated in accordance with Clause 4.2. The Sub-processor list shall include the identities of the Sub-processors, their country of location as well as a description of the processing they perform.
4.2 TensorX will provide written notice to Customer of any intended addition or replacement of a Sub-processor at least fourteen (14) calendar days before the Sub-processor first processes Personal Data (the “Sub-processor Notice Period”). The Customer is responsible for ensuring that its nominated contact details are kept up to date with TensorX for the purposes of receiving such notices. The Customer may object, on reasonable data-protection grounds, by notifying TensorX in writing within the Sub-processor Notice Period; if no objection is received, the Sub-processor will be deemed accepted.
4.3 TensorX shall ensure that: (i) it shall enter into an agreement with the Sub-processor and the terms governing the engagement between TensorX and any Sub-processor are not less protective with respect to processing of Personal Data compared to the provisions of this DPA and any other relevant provisions of the Agreement to the extent those requirements are applicable to the nature of the services provided by the Sub-processor; and (ii) TensorX will remain responsible and liable for the Sub-processor’s compliance with its obligations and for any acts or omissions of such Sub-processor.
5. Data Transfers
5.1 If TensorX transfers Personal Data outside the EEA or UK to a third country that is not recognised by the European Commission (or relevant authority) as providing an adequate level of protection, such transfers shall be governed by the Standard Contractual Clauses. The Customer agrees that by accepting this DPA they also accept the Standard Contractual Clauses, which will be incorporated by reference and form an integral part of this DPA, and be considered duly accepted and completed upon entering into force of this DPA. The parties agree that the parties will comply with the provisions of the applicable Module of the Standard Contractual Clauses specified in Annex 1 and, with respect to the elements of the Standard Contractual Clauses that require the parties’ input, Annexes 1 and 2 contain information relevant to the Standard Contractual Clauses’ Annexes. In case of any conflicts or inconsistency between the provisions of this DPA and the Standard Contractual Clauses, the provisions of the Standard Contractual Clauses shall prevail.
5.2 The parties agree that, for Personal Data of Data Subjects in the United Kingdom, they adopt the modifications to the Standard Contractual Clauses listed in Annex 2 to adapt the Standard Contractual Clauses to local law, as applicable.
5.3 Without limiting the generality of the foregoing, TensorX will enter into (and will cause its Sub-processors to enter into) any additional agreements or adhere to any additional contractual terms and conditions related to the processing, including cross border data transfer, of Personal Data as Customer may instruct in writing that Customer deems necessary to comply with Data Protection Legislation.
6. Audit
6.1 Subject to Clause 6.2 and to the extent required by applicable Data Protection Legislation, Customer shall have the right to audit TensorX systems, processes, and procedures relevant to the protection of Personal Data.
6.2 An audit under this Section 6 shall be: (i) carried out no more than once in any twelve (12) month period during the Term (unless it needs to be carried out more than once a year to comply with a request from an authority or a legal or regulatory obligation applicable to the Customer or, where the Customer acts as a Processor, the relevant Controller); (ii) conducted during Business Hours over the course of one Business Day; (iii) subject to a minimum thirty (30) days’ prior written notice; and (iv) in relation to the Personal Data only. TensorX shall grant to Customer (or representatives of Customer that are not competitors of TensorX) a right of access to TensorX’s premises and/or systems during Business Hours for the purpose of such audit, and TensorX shall give such necessary assistance to the conduct of such audits.
6.3 Customer shall bear any and all expenses incurred by TensorX in respect of any such audit and any such audit shall not interfere with the normal and efficient operation of TensorX’s business. TensorX may require, as a condition of granting such access, that Customer (and representatives of Customer) enter into reasonable confidentiality undertakings with TensorX. The parties will work cooperatively to agree an audit plan, scope and timing in advance of any audit.
6.4 If the scope of the audit is addressed in an ISO 27001/27701 or similar audit report performed by a qualified third party auditor within the previous twelve (12) months, and TensorX’s data protection or other relevant officer certifies in writing there are no known material changes in the controls audited, Customer shall agree to accept those reports in lieu of requesting an audit of the controls covered by the report. TensorX will reasonably cooperate with and assist Customer where a Regulator requires an audit of TensorX’s Processing of Personal Data in order to ascertain or monitor Customer’s compliance with Data Protection Legislation.
7. Term and Termination
7.1 This DPA will remain in full force and effect so long as:
- 7.1.1 the Agreement remains in effect; or
- 7.1.2 the Processor retains any of the Customer Personal Data related to the Agreement in its possession or control (“Term“).
7.2 Any provision of this DPA that expressly or by implication should come into or continue in force on or after termination of the Agreement in order to protect the Customer Personal Data will remain in full force and effect.
8. Liability
8.1 For the avoidance of doubt, the limitations and exclusions of liability set forth in the Agreement shall apply to liability between the parties arising under or in connection with this DPA, including liability arising under applicable Data Protection Legislation, the Standard Contractual Clauses, the UK International Data Transfer Addendum, and any other data transfer mechanism adopted pursuant to Section 5 of this DPA, except to the extent that application of such limitation or exclusion would conflict with applicable law or the applicable transfer mechanism. Nothing in the Agreement or this DPA shall limit or exclude any rights or remedies of data subjects or supervisory authorities, or any other liability, to the extent that such rights, remedies or liability cannot lawfully be limited or excluded.
Annex 1 — Details of Processing of Personal Data
(a) Subject matter and duration of the processing of Personal Data
The subject matter is Personal Data and the duration of the processing of Personal Data is set out in the Agreement.
(b) The nature and purpose of the Processing of Personal Data
The Processing carried out by TensorX is limited to the activities required to deliver the Services. This includes receiving Customer API requests, processing Customer API Data in transient memory, receiving model responses, and returning those responses to the Customer.
In addition, TensorX may Process Customer Data where necessary to operate, secure, and administer the Services, including for usage measurement, billing and cost calculation, performance and reliability monitoring, abuse detection and prevention, security investigations, customer support (where requested by the Customer), data deletion, anonymisation, and the retention of operational metadata and other records permitted under this DPA.
Customer API Data is processed exclusively on a transient basis for the duration necessary to perform the requested inference operation. Upon completion of the request, TensorX does not retain Customer API Data.
(c) The types of Personal Data to be Processed
The Personal Data processed may include the following categories, depending on the data submitted by or on behalf of the Customer or, where the Customer acts as a Processor, by or on behalf of the relevant Controller:
Customer Data
Identity and contact data
- First name
- Last name
- Email address
Authentication and security data
- Hashed password
- Email verification status
- Login timestamps
- IP address of most recent and historical login attempts
- Device user agent strings
- Geographic location derived from login IP address
Account and organisational data
- User identifier (UUID)
- Team and organisation membership and role
- API key metadata (name, prefix, hash)
- Marketing email preferences
Financial and usage data
- Wallet balance and transaction history
- Stripe customer identifier
- Cryptocurrency deposit records (amounts, currency, network, transaction identifiers)
- API usage metrics (token counts, model used, spend)
Customer API Data
- Prompts
- Instructions
- Messages
- Input text
- Generated outputs
- Embeddings inputs
- Files or file references
- Images
- Audio
- Structured payloads
- Request headers
- Routing preferences
- Selected models
- Selected providers
- Customer-provided metadata
- End-user identifiers
- Related configuration data
⚠️ Note: TensorX does not store Customer API Data. All prompts and completions are processed in ephemeral enclaves and are not persisted to any storage system.
(d) The categories of Data Subject to whom Personal Data relates
- Authorised users, employees, contractors, developers, administrators and other representatives of the Customer or, where applicable, the relevant Controller;
- End users of the Customer’s or relevant Controller’s applications, products or services;
- Business contacts or other persons whose Personal Data is included by or on behalf of the Customer or relevant Controller in API requests, prompts, inputs, files, messages, metadata or other Customer API Data.
(e) The obligations and rights of Customer
These are as set out in the Agreement and this DPA.
TensorX may provide notice of change to these provisions where an update is required due to changes to services or changes required due to applicable Data Protection Legislation, including the interpretation thereof.
(f) Sub-processors
The following Sub-processors are engaged by TensorX in the Processing of Customer Personal Data. A current list is always available at /sub-processors.
| Sub-processor | Purpose | Location |
|---|---|---|
| Cloudflare, Inc. | Turnstile Service. | EU (European data centres) |
| G-Core Labs S.A. | CDN, network security, DDoS protection, and WAF | EU (European data centres) |
| Amazon Web Services (AWS EMEA SARL) | Cloud infrastructure | EU (European data centres) |
| Scaleway SAS | Network security, cloud infrastructure | EU (European data centres) |
| Verda | Data centre / colocation infrastructure | Finland, EU |
| Digital Realty Trust, Inc. | Data centre / colocation infrastructure | Dublin, Ireland, EU |
| Google LLC (Workspace) | Email and internal communications | EU (European data centres) |
| Stripe, Inc. | Payment processing (card payments) | EU (European data centres) |
| DeusXPay | Cryptocurrency payment processing | EU (European data centres) |
| Resend (Plus Five Five, Inc.) | Transactional and marketing email delivery | United States (SCCs in place) |
| Intercom R&D Unlimited Company | Customer support chat and messaging | EU / United States (SCCs in place) |
| Attio Limited | Customer Relationship Management | EU / UK / United States |
Annex 2 — Information for International Transfers
Categories of data subjects whose personal data is transferred: See Annex 1.
Categories of personal data transferred: See Annex 1.
Sensitive data transferred (if applicable): See Annex 1.
The frequency of the transfer: Data is transferred on a continuous basis during the term of the Agreement, unless otherwise specifically agreed elsewhere between Customer and TensorX.
Nature of the processing: TensorX will Process Personal Data as necessary to perform the Services pursuant to the Agreement as further instructed by Customer and/or its Affiliates by virtue of using the Services, including storage, organisation, structuring, disclosure by transmission, dissemination or making available, and other forms of processing.
Purpose(s) of the data transfer and further processing: The purpose of the data transfer and processing by TensorX is to provide the Services to Customer and, as applicable, its Affiliates, as further specified in the Agreement and other TensorX contracts (if any).
The period for which the personal data will be retained: TensorX retains Personal Data it collects or receives from the Customer for the duration of the Agreement in accordance with the Service provided and consistent with its obligations under applicable law.
For transfers to (sub-)processors, also specify subject matter, nature and duration of the processing: TensorX uses Sub-processors and will engage Sub-processors solely as necessary to provide the Services to Customer and, as applicable, its Customer Affiliates. Sub-processors will carry out any processing of personal data only as necessary for such purposes and as further instructed by Customer and/or its Customer Affiliates by virtue of using the Services, including hosting, storage and other forms of processing. Such processing will be no longer than for the duration of the Agreement, unless otherwise agreed upon in writing.
For the purposes of the Standard Contractual Clauses
- Clause 9(a) (Module 2 and 3, as applicable): The parties select Option 2. The time period is 30 days.
- Clause 11(a): The parties do not select the independent dispute resolution option.
- Clause 17: The parties select Option 1. The parties agree that the governing jurisdiction is Ireland.
- Clause 18: The parties agree that the forum is Ireland.
- Annex I(A): The data exporter is Customer (defined above) and the data importer is TensorX (defined above).
- Annex I(B): The parties agree that Annex 1 describes the transfer.
- Annex I(C): The competent supervisory authority is the Irish Data Protection Commission.
For the purpose of localising the Standard Contractual Clauses — United Kingdom
- For the purposes of transfers of personal data from the UK, the Parties agree to comply with the terms of Part 2: Mandatory Clauses of the Addendum, being the template UK International Data Transfer Addendum B.1.0 issued by the UK Information Commissioner and laid before Parliament in accordance with s119A of the Data Protection Act 2018 on 28 January 2022, as it is revised under Section 18 of those Mandatory Clauses. The Parties also agree that the information included in Part 1 of the Addendum shall be as set out above. The parties also agree that the Exporter and Importer may end the Addendum as set out in Section 19 of the Addendum.
- The parties agree that the Standard Contractual Clauses are deemed amended to the extent necessary that they operate for transfers from the United Kingdom to a Third Country and provide appropriate safeguards for transfers according to Article 46 of the United Kingdom General Data Protection Regulation (“UK GDPR”). Such amendments include changing references to the GDPR to the UK GDPR and changing references to EU Member States to the United Kingdom.
- Clause 17: The parties agree that the governing jurisdiction is the United Kingdom.
- Clause 18: The parties agree that the forum is the courts of England and Wales. The parties agree that Data Subjects may bring legal proceedings against either party in the courts of any country in the United Kingdom.
Questions?
If you have any questions about this DPA contact us at:
TensorX Ltd.
Unit 25, Classon House
Dundrum Business Park
Dublin 14, Ireland
Email: [email protected]