Data Processing Addendum
This Data Processing Addendum (“DPA”) forms part of the agreement between TensoraAI (“Processor,” “Service Provider,” “we,” “our,” or “us”) and the customer (“Controller,” “Client,” or “Customer”) that purchases or uses TensoraAI’s services (collectively, the “Services”).
This DPA applies when TensoraAI processes Personal Data on behalf of the Customer in connection with the Services.
If there is any conflict between this DPA and the primary service agreement, this DPA shall govern with respect to the processing of Personal Data.
1.Definitions
For purposes of this DPA:
Applicable Data Protection Laws means all applicable privacy and data protection laws, including, where relevant, the General Data Protection Regulation (GDPR), UK GDPR, California Consumer Privacy Act (CCPA), California Privacy Rights Act (CPRA), and other applicable laws.
Controller means the entity that determines the purposes and means of processing Personal Data.
Processor means the entity that processes Personal Data on behalf of the Controller.
Personal Data means any information relating to an identified or identifiable natural person, as defined by applicable law.
Processing means any operation performed on Personal Data, including collection, storage, use, disclosure, transfer, deletion, or destruction.
Subprocessor means any third party engaged by TensoraAI to process Personal Data on behalf of the Customer.
2.Scope
This DPA applies to Personal Data processed by TensoraAI while providing:
- AI chatbot services
- AI voice agents
- Workflow automation
- CRM integrations
- Appointment booking systems
- Customer support automation
- Website development
- API integrations
- Digital marketing automation
- AI consulting
- Custom software development
- Managed technology services
3.Roles of the Parties
Unless otherwise agreed in writing:
- The Customer acts as the Controller (or Business, where applicable).
- TensoraAI acts as the Processor (or Service Provider, where applicable).
Each party shall comply with its obligations under applicable data protection laws.
4.Processing Instructions
TensoraAI will process Personal Data only:
- To provide the Services;
- In accordance with the Customer’s documented instructions;
- As required by applicable law; or
- As otherwise agreed in writing.
If applicable law requires processing beyond the Customer’s instructions, TensoraAI will notify the Customer unless prohibited by law.
5.Categories of Personal Data
Depending on the Services used, Personal Data processed may include:
- Name
- Email address
- Phone number
- Mailing address
- Company name
- Job title
- Appointment information
- Customer communications
- Chat conversations
- Voice recordings
- Call transcripts
- IP addresses
- Device identifiers
- CRM records
- User account information
- Marketing preferences
- Technical logs
The exact categories depend on the Customer’s implementation.
6.Categories of Data Subjects
Data subjects may include:
- Customers
- Prospective customers
- Employees
- Contractors
- Vendors
- Business partners
- Website visitors
- End users
- Applicants
- Subscribers
- Other individuals whose data the Customer submits for processing
7.Purpose of Processing
Personal Data may be processed for purposes including:
- Operating AI chatbots
- AI voice interactions
- Appointment scheduling
- Customer support
- Workflow automation
- CRM synchronization
- Analytics
- Software hosting
- Service monitoring
- Technical support
- Security
- Fraud prevention
- Performance improvement
8.Confidentiality
TensoraAI shall ensure that personnel authorized to process Personal Data:
- Are bound by confidentiality obligations; or
- Are subject to appropriate statutory duties of confidentiality.
Access to Personal Data shall be limited to personnel who require it to perform the Services.
9.Security Measures
TensoraAI will implement reasonable technical and organizational measures designed to protect Personal Data, which may include:
- Encryption in transit using TLS/SSL
- Encryption at rest where appropriate
- Role-based access controls
- Multi-factor authentication for administrative access where feasible
- Firewalls and network protections
- Security monitoring and logging
- Regular software updates and patch management
- Backup and disaster recovery procedures
- Employee security awareness training
- Secure development practices
Security measures may evolve as technology and industry standards develop.
10.Subprocessors
The Customer authorizes TensoraAI to engage Subprocessors as reasonably necessary to provide the Services.
Examples of Subprocessors may include providers of:
- Cloud infrastructure
- AI model services
- Payment processing
- Appointment scheduling
- Email delivery
- SMS delivery
- CRM platforms
- Analytics
- Customer support tools
- Monitoring services
TensoraAI will require Subprocessors to maintain appropriate contractual obligations regarding the protection of Personal Data.
11.International Data Transfers
Where Personal Data is transferred across national borders, TensoraAI will take appropriate measures required by applicable law to safeguard such transfers.
Where required, such safeguards may include:
- Standard Contractual Clauses (SCCs)
- UK International Data Transfer Addendum
- Adequacy decisions
- Other legally recognized transfer mechanisms
12.Assistance to the Customer
Taking into account the nature of the processing and the information available to TensoraAI, we will provide reasonable assistance to the Customer in responding to requests or obligations relating to:
- Access requests
- Correction requests
- Deletion requests
- Data portability requests
- Objections to processing
- Restriction requests
- Regulatory inquiries
- Privacy impact assessments, where applicable
Such assistance may be subject to reasonable costs where permitted by law or contract.
13.Data Subject Requests
If TensoraAI receives a request directly from a data subject relating to Personal Data processed on behalf of the Customer, TensoraAI will, unless prohibited by law:
- Promptly notify the Customer; and
- Not respond to the request except as instructed by the Customer or as required by applicable law.
14.Personal Data Breach
If TensoraAI becomes aware of a confirmed Personal Data breach affecting Customer Personal Data, TensoraAI will:
- Notify the Customer without undue delay after becoming aware of the breach;
- Provide available information reasonably necessary for the Customer to assess the incident;
- Take appropriate steps to contain and remediate the breach; and
- Cooperate with the Customer regarding the incident, as reasonably necessary.
Notification does not constitute an admission of fault or liability.
15.Data Retention and Deletion
Upon termination of the Services, and subject to applicable law and any agreed retention periods, TensoraAI will, upon the Customer’s written request:
- Return Customer Personal Data in a commonly used format where feasible; or
- Securely delete or anonymize Customer Personal Data.
We may retain limited information where required by law, for legitimate business purposes such as security, fraud prevention, or compliance, or as otherwise permitted by applicable law.
16.Audit Rights
Upon reasonable written request and no more than once annually (unless required by law or following a material security incident), TensoraAI will make available information reasonably necessary to demonstrate compliance with this DPA.
Where additional verification is required, the parties will cooperate in good faith to determine an appropriate method that protects the confidentiality and security of other customers and TensoraAI’s systems.
17.Customer Responsibilities
The Customer is responsible for:
- Providing lawful processing instructions;
- Obtaining all required notices and consents;
- Ensuring the lawful collection of Personal Data;
- Determining the legal basis for processing;
- Responding to data subject requests where required;
- Configuring Services appropriately for their intended use;
- Using the Services in compliance with applicable law.
18.Limitation of Liability
The liability of each party under this DPA shall be subject to the limitations of liability set forth in the applicable service agreement or Terms & Conditions, unless prohibited by applicable law.
19.Changes to This DPA
TensoraAI may update this DPA to reflect changes in applicable laws, regulations, or business operations.
Material changes will become effective upon notice to Customers or publication on our Website, as appropriate.
20.Governing Law
This DPA shall be governed by the governing law specified in the applicable service agreement or, if none is specified, the laws of the State of New Jersey, United States, without regard to conflict of law principles.
21.Contact Information
If you have questions regarding this Data Processing Addendum, please contact:
TensoraAI
Website: https://www.tensoraai.com
Email: info@tensoraai.com
Business Hours:
Monday–Friday
9:00 AM – 6:00 PM (Eastern Time)
Annex A – Processing Details
Subject Matter
Provision of AI-powered business automation, software development, consulting, and related services.
Duration
For the duration of the applicable service agreement and any agreed retention period.
Nature of Processing
- Collection
- Recording
- Organization
- Storage
- Retrieval
- Consultation
- Use
- Disclosure
- Transmission
- Synchronization
- Automation
- Analysis
- Deletion
- Destruction
Categories of Personal Data
As described in Section 5.
Categories of Data Subjects
As described in Section 6.
Technical and Organizational Measures
As described in Section 9.
Acknowledgment
By entering into a service agreement with TensoraAI or using our Services where this DPA applies, the Customer acknowledges that it has read, understood, and agrees to the terms of this Data Processing Addendum.