Legal / Data processing addendum

Data processing addendum

Last revised

Draft — not yet reviewed by counsel

This document describes how Tenza actually behaves and is published so you can read it before you commit to anything. It has not been reviewed by a qualified lawyer, so it is not a final contractual instrument and should not be relied on as legal advice. If you need an executed, countersigned version — or you are evaluating Tenza against a procurement or compliance requirement — ask support and we will get the reviewed text to you.

This addendum forms part of the terms of service. It applies where Tenza processes personal data on your behalf — principally data about the customers of your storefront. In that processing you are the controller and Tenza is the processor.

1. Subject matter and duration

We process personal data only to provide the platform, for as long as your workspace exists, plus the retention windows in the privacy policy.

2. Categories of data and data subjects

  • Data subjects — your storefront customers, your invited team members, and people who contact you through your storefront.
  • Categories — contact details, delivery addresses, order and cart contents, payment references (never full card numbers), communication preferences, and behavioural data such as product views and search queries.

3. Our obligations

  • Process personal data only on your documented instructions, which for ordinary operation are the actions available in the platform.
  • Keep the data confidential and limit access to personnel who need it.
  • Implement appropriate technical and organisational measures, including encryption in transit and at rest, tenant scoping enforced at the query layer, and an append-only audit log.
  • Assist you with data-subject requests, and with your own security and impact assessments.
  • Notify you without undue delay if we become aware of a personal-data breach affecting your data.
  • Delete or return personal data on termination, except where we must retain it by law.

4. Tenant isolation

Every business record carries a workspace identifier and every query is scoped to it. This is verified by an automated scan that reads the database schema catalogue and fails a release if any business table lacks that scoping — so isolation is a test we run, not an assurance we merely give.

5. Subprocessors

We use subprocessors for hosting and database, email delivery, payment processing, object storage and AI inference. Each is bound by terms no less protective than these. We will give you notice of a new subprocessor before it begins processing your data, and you may object on reasonable data-protection grounds.

6. International transfers

Where personal data is transferred out of its region of origin, the transfer relies on an appropriate mechanism — adequacy, or standard contractual clauses with the relevant supplementary measures.

7. Audit

On reasonable notice, and no more than once a year unless a regulator requires otherwise, we will provide the information you need to verify our compliance with this addendum.

8. AI processing

The creative studio and the support diagnostic agent send the minimum necessary data to an inference provider. Product and catalog content is sent for creative generation. Support diagnostics send operational signals and the text of your own ticket. Neither is used to train third-party models, and neither sends your customers’ personal data.

9. Contact

To request the current subprocessor list, raise an objection, or execute a countersigned copy, contact support and mark the ticket as a legal request.

Contact

Anything in this document that is unclear, or that you need in a different form, goes to support. Mark the ticket as a legal request.