● Legal
Data Processing Agreement
Effective Last updated Version 1.0
The short version
- This agreement applies to every customer, not only customers in Europe or California. It is part of our Terms, so it binds without anyone signing anything.
- For the content inside your workspace, your organization decides and we follow instructions. We do not use it for our own purposes, and we do not train AI models on it.
- If your process needs an executed copy, ask and we will send one. Section 18 says how.
This summary is for orientation only. The sections below are the actual agreement.
How this agreement works
This Data Processing Agreement (“DPA”) is between Tinu Inc, a Michigan corporation based in Ann Arbor, Michigan, United States (“Tinu,” “we,” “us”) and the organization that agreed to our Terms of Service (“Customer,” “you”).
It is incorporated into and forms part of the Terms of Service (the “Agreement”). You do not need to sign it for it to apply.
Who it applies to. This DPA applies to every customer, as contract terms, whether or not any particular privacy law reaches you. Only two sections are conditional: section 15 applies to the international transfers it describes, and section 16 applies where a US state privacy law governs the processing. Where a law named here does not reach you, the obligations we take on still do.
When it takes effect. It applies from the moment you accept a version of the Agreement that incorporates it, and lasts as long as we process personal data on your behalf. If you accepted the Agreement before the effective date above, it applies once you accept the updated Terms, on the notice terms in section 14 of the Agreement.
Order of precedence. If this DPA conflicts with the rest of the Agreement on the subject of personal data, this DPA controls. If Tinu and Customer have signed a separate negotiated data processing agreement, that one controls instead.
Liability. Each party’s liability arising out of or in connection with this DPA is subject to the exclusions and limitations of liability set out in the Agreement. Nothing in this DPA limits any liability that cannot be limited under applicable law.
Definitions
Terms defined in applicable data protection law carry their meaning from that law. Controller, processor, data subject, personal data and processing are used as the GDPR uses them. Under US state privacy laws, read “controller” as business or controller and “processor” as service provider or processor, as those laws define them.
Customer Personal Data means personal data we process on your behalf to provide the service: the content your organization puts into Tinu, the content our integrations retrieve from sources you connect, and the account and membership records that identify your people inside your workspace.
Customer Personal Data does not include the data we process as a controller for our own business: billing records, support conversations, and our own service and infrastructure telemetry that does not contain workspace content. Section 02 of the Privacy Policy explains that split and governs that data. Records of who inside your organization viewed or changed what, which your admins can see and may need in order to answer a data subject request, are Customer Personal Data.
Subprocessor means a third party we engage to process Customer Personal Data on our behalf.
What we process, and why
Article 28(3) of the GDPR requires this to be written down, and it is the description a security review asks for regardless of which law applies to you.
| Item | Detail |
|---|---|
| Roles | For Customer Personal Data you are the controller and Tinu is your processor. If you use Tinu to process personal data on behalf of your own client, you are a processor and Tinu is your subprocessor, and this DPA applies with those roles substituted. For our own business records and service telemetry, Tinu is a controller and the Privacy Policy governs |
| Subject matter | Providing the Tinu service under the Agreement |
| Duration | The term of the Agreement, plus the return and deletion period in section 13 |
| Nature and purpose | Hosting, storage, indexing and retrieval of organizational knowledge; AI-assisted summarizing, extraction, embedding and question answering; notifications; support |
| Types of personal data | Names, work email addresses, hashed credentials, organization, team and role; free-text workspace content that may name or describe individuals; content and identities from sources you connect |
| Categories of data subjects | Your personnel, including employees, contractors and admins, and any individual mentioned in the content they enter |
| Special category data | Not requested, and not permitted under the Agreement unless we agree in writing to support it. Because workspace content is free text, it may nevertheless be submitted by your people. See section 05 |
| Frequency | Continuous, for as long as you use the service |
Your instructions
We process Customer Personal Data only on your documented instructions, including for international transfers, unless a law we are subject to requires otherwise. If that happens we will tell you first, unless the law forbids telling you.
Your documented instructions are:
- the Agreement and this DPA;
- how your organization configures the product, including which integrations you connect, which AI features you enable, and the retention window your admin sets for departed members;
- any order form or written instruction we accept in writing.
We will immediately inform you if, in our opinion, an instruction infringes applicable data protection law. We are not obliged to carry it out while that question is open.
What we will not do. We will not sell Customer Personal Data, use it for our own purposes, or use it to train AI models, ours or anyone else’s. The public demo workspaces run on a separate free-tier provider account that does permit training, which is why they are seeded with synthetic data and are not part of any customer workspace. Section 05 of the Privacy Policy covers this in full.
Your responsibilities
As the controller, you are responsible for:
- determining the purposes of the processing, and for the lawfulness of your instructions;
- having a lawful basis for the Customer Personal Data you put into Tinu, and giving your own people whatever notice employment and privacy law requires;
- the accuracy and legality of the Customer Personal Data you provide; and
- how you configure access, roles and retention inside your workspace, and who you invite.
Special category data. The Agreement does not permit special-category personal data in Tinu unless we have agreed in writing to support it. Workspace content is free text, so we cannot prevent it being entered. If it is entered anyway it does not lose the protection of this DPA, but that does not mean the service is designed or approved to hold it: you remain responsible for the lawful basis, and we may ask you to remove it.
Confidentiality
Everyone we authorize to process Customer Personal Data is bound by a duty of confidentiality, by contract or by statute, that survives the end of their engagement with us. We limit access to the people who need it to provide, support or secure the service.
Subprocessors
You give us general authorization to engage subprocessors. The current list is public and kept up to date at tinuai.com/legal/subprocessors, with a dated log of every change.
Before a new subprocessor begins processing Customer Personal Data, we notify your organization’s admins by email at least 30 days in advance. You may object on reasonable data protection grounds within that window. If we cannot resolve your objection, you may terminate the affected part of the service and receive a pro-rated refund of prepaid fees for the terminated portion.
Urgent replacement. If urgent security, legal or service-continuity circumstances make 30 days impracticable, we may shorten the notice period to the minimum reasonably practicable. We will still notify you before the replacement begins processing Customer Personal Data, and your objection right is unchanged.
Every subprocessor is bound by a written contract imposing the same data protection obligations as are set out in this DPA, in particular sufficient guarantees to implement appropriate technical and organizational measures. We remain liable to you for their performance as if it were our own, subject to section 01.
Security
We implement the technical and organizational measures required by Article 32 of the GDPR to protect Customer Personal Data, taking account of the state of the art, the cost of implementation, and the risk to individuals. These include encryption in transit and at rest, tenant isolation enforced in the database rather than only in application code, role-based access control, session revocation, append-only audit logging the application cannot rewrite, rate limiting, and least-privilege access for our own people.
Section 09 of the Privacy Policy describes our security posture in plain language. We may update specific measures over time, provided the overall level of protection does not decrease.
Personal data breaches
If we become aware of a personal data breach affecting Customer Personal Data, we notify you without undue delay, by email to your organization’s admins. We do not wait for a complete picture before telling you, because your own regulatory clock may already be running.
The notice will describe, as far as we know it at the time:
- the nature of the breach, including where possible the approximate number of data subjects concerned and of personal data records concerned;
- the likely consequences;
- the measures we have taken or propose to take; and
- a contact point for more information.
We will follow up as we learn more, and will reasonably assist you in meeting your own notification obligations. Notifying you is not an admission of fault.
Unsuccessful attempts that do not compromise the security of Customer Personal Data are not personal data breaches and are not individually reported. Port scans, blocked intrusion attempts and failed sign-ins are examples.
Helping you answer data subject requests
Tinu gives your admins the tools to find, export, correct and delete data directly, so in most cases you can answer a request without us. Where you cannot, we provide reasonable assistance by appropriate technical and organizational measures, taking into account the nature of the processing.
If a data subject contacts us directly about data we process for you, we will not respond on your behalf beyond telling them to contact you, unless you instruct us otherwise or the law requires more. We will pass the request on to you promptly.
Helping you with impact assessments
Taking into account the nature of the processing and the information available to us, we will assist you in meeting your obligations under Articles 32 to 36 of the GDPR, or their equivalents under other applicable law. That includes security, breach notification to regulators and individuals, data protection impact assessments, and prior consultation of a supervisory authority.
Assistance under this section and section 10 is included at no charge where the effort is reasonable. If a request requires substantial engineering work beyond that, we will tell you before starting and agree the cost with you first.
Government and legal demands
If a government body or other third party demands access to Customer Personal Data, we will tell you before disclosing anything, so that you can seek to challenge it, unless we are legally barred from telling you. Where we are barred, we will use reasonable efforts to have the restriction lifted.
We will redirect the requester to you where we can, and disclose only the minimum the demand actually requires. Where, after a careful assessment, we conclude there are reasonable grounds to consider the demand unlawful under applicable law, we will challenge it, and will pursue interim measures where they are available.
Return and deletion
At your choice, after the Agreement ends we will return Customer Personal Data to you or delete it, and delete existing copies, unless a law we are subject to requires us to keep it. You can export it yourself through the product at any time while your subscription is active.
If you give us no instruction, we keep it solely to allow export for 30 days after the Agreement ends, and then delete it in line with the retention schedule in section 07 of the Privacy Policy.
Deleted data persists in encrypted backups for a limited window before rolling off. While it remains there it is put beyond ordinary use: it is not processed for any other purpose, and we do not restore a backup to recover deleted data except to recover from an incident. Where a law requires us to keep a copy, we keep it and stop processing it for any other purpose.
Audits and information
We make available the information reasonably necessary to demonstrate compliance with this DPA. In practice that means our documentation, our answers to your security questionnaire, and the public commitments on these pages.
If that is not enough for your obligations, you may audit us, or appoint an independent auditor who is not our competitor and is bound by confidentiality, on 30 days written notice, no more than once in any 12 month period, during business hours, and in a way that does not disrupt the service or compromise another customer’s data. You bear the cost, unless the audit reveals a material breach of this DPA, in which case we do.
The once-a-year limit does not apply where there has been a personal data breach affecting your data, where a regulator requires an audit, or where you have credible evidence of material non-compliance with this DPA.
Nothing in this section limits the powers of a competent supervisory or regulatory authority, or our obligation to cooperate with such an authority as applicable law requires.
International transfers
Tinu is operated from the United States and our subprocessors are primarily US-based, so using Tinu from outside the US means data is transferred to the US.
Where Customer Personal Data is transferred out of the EEA and requires an Article 46 safeguard, the mechanism we use is the European Commission’s Standard Contractual Clauses, Module Two where you are a controller and Module Three where you are yourself a processor. For the UK we apply the UK International Data Transfer Addendum, and for Switzerland the equivalent adaptations.
We execute the Clauses with you. They require choices a web page cannot make on your behalf: the general-authorization option for subprocessors, the governing law, the courts, and the identities, contacts and competent supervisory authority in the annexes. So if you are established in the EEA, the UK or Switzerland, contact privacy@tinuai.com before onboarding and we will complete and execute them with you. Sections 03 and 08 and our subprocessor list supply the substance of the annexes; the elections are made on execution. Where the Clauses apply, they control over any conflicting provision of this DPA or the Agreement.
If a transfer mechanism is invalidated, we will work with you in good faith to put a valid alternative in place.
US state privacy laws
Where you are a business or controller under a US state privacy law, including the California Consumer Privacy Act as amended and the comprehensive privacy laws of states such as Virginia, Colorado, Connecticut and Texas, and we process personal information on your behalf, you are the business or controller and Tinu acts as your service provider or processor.
We are provided personal information only for the specific business purposes set out in section 03 of this DPA, and we certify that we:
- do not sell or share it, as those laws define those terms;
- do not retain, use or disclose it for any purpose other than those business purposes, or as the applicable law otherwise permits;
- do not retain, use or disclose it outside our direct business relationship with you;
- do not combine it with personal information from other sources, except as a service provider is permitted to do;
- comply with the obligations applicable to us under those laws, and provide the same level of privacy protection those laws require of you; and
- bind any subprocessor we engage to the same obligations by written contract.
We assist you with consumer requests as described in section 10. You may take reasonable and appropriate steps to confirm we use personal information consistently with your obligations, including by the audit and information rights in section 14. We will tell you if we determine we can no longer meet these obligations, and you may take reasonable steps to stop and remediate unauthorized use.
Changes to this agreement
We version this DPA and date every change. Material changes follow the notice process in section 14 of the Agreement. An executed copy stays fixed at the version you signed; updating this page does not change it.
| Date | Change |
|---|---|
| Version 1.0. First publication. |
Signing, and how to reach us
You do not need to sign this DPA. It is part of the Agreement and binds both of us from the moment you accept the Agreement.
If your procurement or legal process requires an executed copy, email privacy@tinuai.com with your full legal entity name, jurisdiction of incorporation, and the name and title of your signatory. We will return a countersigned copy of version 1.0, by electronic signature. Redlines are welcome for enterprise agreements; a negotiated DPA supersedes this one, per section 01.
Ann Arbor, Michigan, United States
Privacy and DPA requests: privacy@tinuai.com
Security: security@tinuai.com
General: hello@tinuai.com
See also our Privacy Policy, Subprocessors and Terms of Service, or return to the Tinu AI home page.