Legal
Data Processing Agreement
Version 1.0 · Last updated: May 8, 2026
This DPA is a starting point provided for reference. Tessarac legal will provide the definitive contract. Enterprise customers requiring an executed DPA should email legal@tessarac.com.
1. Introduction and Roles
This Data Processing Agreement ("DPA") forms part of the TessaracTerms of Service between Tessarac, LLC ("Tessarac") and the customer ("Customer") and reflects the parties' agreement on the processing of Personal Data in connection with the Tessarac platform (the "Service").
For the purposes of the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR, the California Consumer Privacy Act (as amended by the CPRA, "CCPA"), and other applicable data protection laws (collectively, "Data Protection Laws"), Customer is thecontroller (or "business" under the CCPA) of Customer Personal Data, and Tessarac is theprocessor (or "service provider" under the CCPA).
2. Definitions
- Customer Personal Data means any Personal Data that Tessarac processes on behalf of Customer in connection with providing the Service.
- Personal Data, data subject, processing,controller, processor, and personal data breach have the meanings given in the GDPR.
- Sub-processor means any third party engaged by Tessarac to process Customer Personal Data in connection with providing the Service.
- Standard Contractual Clauses or SCCs means the standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission Decision 2021/914.
3. Scope of Processing
Tessarac processes Customer Personal Data only on the documented instructions of Customer, including instructions provided through Customer's configuration of the Service. The subject matter, duration, nature, purpose, types of Personal Data, and categories of data subjects are described inAnnex A.
Tessarac will inform Customer if it believes Customer's instructions infringe Data Protection Laws and may, in such case, suspend the affected processing pending Customer's confirmation or withdrawal of the instruction.
4. Tessarac Obligations as Processor
Tessarac will:
- process Customer Personal Data only as documented in this DPA, the Terms, and the Order;
- ensure that personnel authorized to process Customer Personal Data are bound by confidentiality obligations;
- implement and maintain the technical and organizational measures described inAnnex C;
- assist Customer in responding to data subject requests, conducting data protection impact assessments, and consulting with supervisory authorities, taking into account the nature of the processing and the information available to Tessarac;
- notify Customer without undue delay (and in any event within seventy-two (72) hours) after becoming aware of a personal data breach affecting Customer Personal Data;
- delete or return Customer Personal Data after the end of the Service per Section 12.
5. Customer Obligations as Controller
Customer represents and warrants that:
- it has all necessary rights and consents to provide Customer Personal Data to Tessarac for the purposes described in the Order;
- it will provide notice to and obtain consent from data subjects as required by Data Protection Laws;
- it has implemented appropriate measures to secure access credentials, API keys, and configuration artifacts that protect Customer Personal Data;
- it has assessed Tessarac's technical and organizational measures and determined them to be appropriate for the Customer's use case and risk profile.
6. Sub-processors
Customer authorizes Tessarac to engage Sub-processors to process Customer Personal Data, subject to the following conditions:
- Tessarac maintains a current list of Sub-processors in theTrust Center and inAnnex B;
- Tessarac will provide notice of any new Sub-processor at least thirty (30) days before that Sub-processor begins processing Customer Personal Data; Customer may object on reasonable, documented grounds within that period;
- Tessarac imposes data-protection obligations on each Sub-processor that are no less protective than the obligations set out in this DPA;
- Tessarac remains liable for the acts and omissions of its Sub-processors to the same extent as for its own.
7. Technical and Organizational Measures
Tessarac implements and maintains appropriate technical and organizational measures designed to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing. The measures are described inAnnex C.
8. International Data Transfers
Where Tessarac transfers Customer Personal Data from the European Economic Area, the United Kingdom, or Switzerland to a third country that has not been recognized as providing an adequate level of protection, such transfers are made pursuant to the Standard Contractual Clauses, which are hereby incorporated by reference. The UK International Data Transfer Addendum and the Swiss Addendum apply where relevant.
Where offered for the applicable plan (US by default, with EU data residency available on Enterprise and Federal plans), Customer may select a regional Hosted SaaS deployment so that Customer Personal Data is processed within the chosen region.
9. Data Subject Rights
Tessarac will, taking into account the nature of the processing, assist Customer by appropriate technical and organizational measures, insofar as possible, in fulfilling Customer's obligations to respond to requests from data subjects to exercise their rights under Data Protection Laws.
If Tessarac receives a request from a data subject directly, it will not respond to the request itself (except to confirm that the request has been forwarded) and will promptly forward the request to Customer.
10. Personal Data Breach Notification
Tessarac will notify Customer without undue delay (and in any event within seventy-two (72) hours) after becoming aware of a personal data breach affecting Customer Personal Data. The notification will include, to the extent then known, the nature of the breach, categories and approximate number of affected data subjects and records, likely consequences, and measures taken or proposed to address the breach.
Customer is responsible for notifying supervisory authorities and affected data subjects as required by Data Protection Laws.
11. Audits and Inspections
Tessarac will make available to Customer all information necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by Customer or an independent auditor mandated by Customer.
Customer agrees that Customer's audit rights are satisfied in the first instance by Tessarac's most recent SOC 2 Type II report and ISO 27001 certificate, copies of which are available in theTrust Center upon request and execution of an NDA. On-site inspections are reserved for cases where Customer has reasonable grounds to believe that Tessarac is not complying with this DPA, are scheduled with at least thirty (30) days' written notice, and are conducted at Customer's expense during normal business hours and in a manner that does not disrupt Tessarac's operations.
12. Deletion or Return of Customer Data
On expiration or termination of the Service, Tessarac will, at Customer's election, delete or return to Customer all Customer Personal Data within ninety (90) days, except to the extent retention is required by law. Tessarac will provide written confirmation of deletion upon request.
13. Liability
Each party's liability arising out of or related to this DPA is subject to the limitation of liability provisions of theTerms of Service.
14. Term and Termination
This DPA takes effect on the Effective Date of the Order and remains in force for the duration of the Service, plus any period during which Tessarac retains Customer Personal Data. Sections that by their nature should survive termination will survive.
Annex A: Processing Details
- Subject matter: provision of the Tessarac platform (the Service).
- Duration: for the term of the Service plus a ninety (90) day post-termination retention window.
- Nature and purpose: hosting, authentication, authorization, secret management, AI request routing and usage metering, billing, audit logging, and related platform operations.
- Categories of data subjects: Customer's employees, contractors, agents, end-users, and other individuals whose data Customer chooses to process through the Service.
- Categories of personal data: identity attributes (name, email, employee ID), authentication artifacts (authentication-provider identifiers, MFA enrollment status, session tokens), authorization data (roles, group membership, policy grants), configuration and credential material Customer chooses to store (including provider API keys), usage and request metadata (timestamps, model and endpoint, token counts), audit data (timestamps, IP addresses, user agents, action types), billing-contact data, and any additional data the Customer chooses to submit through the Service.
- Special categories: none, unless Customer specifically chooses to process them.
Annex B: Sub-processors
The current list of approved Sub-processors is published in the TessaracTrust Center. Customer may subscribe to notification of changes via the Trust Center or by emailing privacy@tessarac.com.
Annex C: Security Measures
Tessarac implements the following technical and organizational measures:
- Encryption — TLS 1.2+ in transit; AES-256-GCM at rest; envelope encryption of secrets and customer-provided provider API keys, with key management via cloud key-management systems and BYOK/HYOK options (single-tenant HSM custody available as the Dedicated HSM add-on).
- Access control — least-privilege RBAC, MFA for all administrative access, just-in-time elevation for privileged operations, comprehensive audit logging.
- Network security — segmented production networks, mTLS service mesh, WAF, DDoS protection.
- Application security — secure SDLC with code review, static and dynamic analysis, dependency scanning, regular third-party penetration testing.
- Infrastructure — production deployments hosted on SOC 2 / ISO 27001 / FedRAMP-authorized cloud providers; IaC with peer-reviewed change control.
- Incident response — 24/7 on-call, documented runbooks, breach-notification SLAs that meet or exceed regulatory requirements.
- Personnel — background checks where lawful, mandatory annual security training, confidentiality agreements.
- Business continuity — multi-Availability-Zone replication (with multi-region options where offered for the applicable plan), automated backups, regularly tested restore procedures, documented disaster-recovery objectives (RTO/RPO published to Customer on request).
- Compliance — SOC 2 Type II audit cycle, ISO 27001 certification, FedRAMP Moderate (in process), HIPAA Security Rule alignment, PCI-DSS controls applicable to the Service.