Skip to content
Tinu AI
Continue→

● Legal

Data Processing Agreement

Effective 14 September 2026Last updated 14 September 2026Version 1.0

The short version

  • This agreement applies to every customer, not only customers in Europe or California. It is part of our Terms, so it binds without anyone signing anything.
  • For the content inside your workspace, your organization decides and we follow instructions. We do not use it for our own purposes, and we do not train AI models on it.
  • If your process needs an executed copy, ask and we will send one. Section 18 says how.

This summary is for orientation only. The sections below are the actual agreement.

Contents

  1. 01How this agreement works
  2. 02Definitions
  3. 03What we process, and why
  4. 04Your instructions
  5. 05Your responsibilities
  6. 06Confidentiality
  7. 07Subprocessors
  8. 08Security
  9. 09Personal data breaches
  10. 10Helping you answer data subject requests
  11. 11Helping you with impact assessments
  12. 12Government and legal demands
  13. 13Return and deletion
  14. 14Audits and information
  15. 15International transfers
  16. 16US state privacy laws
  17. 17Changes to this agreement
  18. 18Signing, and how to reach us

01How this agreement works

This Data Processing Agreement (“DPA”) is between Tinu Inc, a Michigan corporation based in Ann Arbor, Michigan, United States (“Tinu,” “we,” “us”) and the organization that agreed to our Terms of Service (“Customer,” “you”).

It is incorporated into and forms part of the Terms of Service (the “Agreement”). You do not need to sign it for it to apply.

Who it applies to. This DPA applies to every customer, as contract terms, whether or not any particular privacy law reaches you. Only two sections are conditional: section 15 applies to the international transfers it describes, and section 16 applies where a US state privacy law governs the processing. Where a law named here does not reach you, the obligations we take on still do.

When it takes effect. It applies from the moment you accept a version of the Agreement that incorporates it, and lasts as long as we process personal data on your behalf. If you accepted the Agreement before the effective date above, it applies once you accept the updated Terms, on the notice terms in section 14 of the Agreement.

Order of precedence. If this DPA conflicts with the rest of the Agreement on the subject of personal data, this DPA controls. If Tinu and Customer have signed a separate negotiated data processing agreement, that one controls instead.

Liability. Each party’s liability arising out of or in connection with this DPA is subject to the exclusions and limitations of liability set out in the Agreement. Nothing in this DPA limits any liability that cannot be limited under applicable law.

02Definitions

Terms defined in applicable data protection law carry their meaning from that law. Controller, processor, data subject, personal data and processing are used as the GDPR uses them. Under US state privacy laws, read “controller” as business or controller and “processor” as service provider or processor, as those laws define them.

Customer Personal Data means personal data we process on your behalf to provide the service: the content your organization puts into Tinu, the content our integrations retrieve from sources you connect, and the account and membership records that identify your people inside your workspace.

Customer Personal Data does not include the data we process as a controller for our own business: billing records, support conversations, and our own service and infrastructure telemetry that does not contain workspace content. Section 02 of the Privacy Policy explains that split and governs that data. Records of who inside your organization viewed or changed what, which your admins can see and may need in order to answer a data subject request, are Customer Personal Data.

Subprocessor means a third party we engage to process Customer Personal Data on our behalf.

03What we process, and why

Article 28(3) of the GDPR requires this to be written down, and it is the description a security review asks for regardless of which law applies to you.

ItemDetail
RolesFor Customer Personal Data you are the controller and Tinu is your processor. If you use Tinu to process personal data on behalf of your own client, you are a processor and Tinu is your subprocessor, and this DPA applies with those roles substituted. For our own business records and service telemetry, Tinu is a controller and the Privacy Policy governs
Subject matterProviding the Tinu service under the Agreement
DurationThe term of the Agreement, plus the return and deletion period in section 13
Nature and purposeHosting, storage, indexing and retrieval of organizational knowledge; AI-assisted summarizing, extraction, embedding and question answering; notifications; support
Types of personal dataNames, work email addresses, hashed credentials, organization, team and role; free-text workspace content that may name or describe individuals; content and identities from sources you connect
Categories of data subjectsYour personnel, including employees, contractors and admins, and any individual mentioned in the content they enter
Special category dataNot requested, and not permitted under the Agreement unless we agree in writing to support it. Because workspace content is free text, it may nevertheless be submitted by your people. See section 05
FrequencyContinuous, for as long as you use the service

04Your instructions

We process Customer Personal Data only on your documented instructions, including for international transfers, unless a law we are subject to requires otherwise. If that happens we will tell you first, unless the law forbids telling you.

Your documented instructions are:

  • the Agreement and this DPA;
  • how your organization configures the product, including which integrations you connect, which AI features you enable, and the retention window your admin sets for departed members;
  • any order form or written instruction we accept in writing.

We will immediately inform you if, in our opinion, an instruction infringes applicable data protection law. We are not obliged to carry it out while that question is open.

What we will not do. We will not sell Customer Personal Data, use it for our own purposes, or use it to train AI models, ours or anyone else’s. The public demo workspaces run on a separate free-tier provider account that does permit training, which is why they are seeded with synthetic data and are not part of any customer workspace. Section 05 of the Privacy Policy covers this in full.

05Your responsibilities

As the controller, you are responsible for:

  • determining the purposes of the processing, and for the lawfulness of your instructions;
  • having a lawful basis for the Customer Personal Data you put into Tinu, and giving your own people whatever notice employment and privacy law requires;
  • the accuracy and legality of the Customer Personal Data you provide; and
  • how you configure access, roles and retention inside your workspace, and who you invite.

Special category data. The Agreement does not permit special-category personal data in Tinu unless we have agreed in writing to support it. Workspace content is free text, so we cannot prevent it being entered. If it is entered anyway it does not lose the protection of this DPA, but that does not mean the service is designed or approved to hold it: you remain responsible for the lawful basis, and we may ask you to remove it.

06Confidentiality

Everyone we authorize to process Customer Personal Data is bound by a duty of confidentiality, by contract or by statute, that survives the end of their engagement with us. We limit access to the people who need it to provide, support or secure the service.

07Subprocessors

You give us general authorization to engage subprocessors. The current list is public and kept up to date at tinuai.com/legal/subprocessors, with a dated log of every change.

Before a new subprocessor begins processing Customer Personal Data, we notify your organization’s admins by email at least 30 days in advance. You may object on reasonable data protection grounds within that window. If we cannot resolve your objection, you may terminate the affected part of the service and receive a pro-rated refund of prepaid fees for the terminated portion.

Urgent replacement. If urgent security, legal or service-continuity circumstances make 30 days impracticable, we may shorten the notice period to the minimum reasonably practicable. We will still notify you before the replacement begins processing Customer Personal Data, and your objection right is unchanged.

Every subprocessor is bound by a written contract imposing the same data protection obligations as are set out in this DPA, in particular sufficient guarantees to implement appropriate technical and organizational measures. We remain liable to you for their performance as if it were our own, subject to section 01.

08Security

We implement the technical and organizational measures required by Article 32 of the GDPR to protect Customer Personal Data, taking account of the state of the art, the cost of implementation, and the risk to individuals. These include encryption in transit and at rest, tenant isolation enforced in the database rather than only in application code, role-based access control, session revocation, append-only audit logging the application cannot rewrite, rate limiting, and least-privilege access for our own people.

Section 09 of the Privacy Policy describes our security posture in plain language. We may update specific measures over time, provided the overall level of protection does not decrease.

09Personal data breaches

If we become aware of a personal data breach affecting Customer Personal Data, we notify you without undue delay, by email to your organization’s admins. We do not wait for a complete picture before telling you, because your own regulatory clock may already be running.

The notice will describe, as far as we know it at the time:

  • the nature of the breach, including where possible the approximate number of data subjects concerned and of personal data records concerned;
  • the likely consequences;
  • the measures we have taken or propose to take; and
  • a contact point for more information.

We will follow up as we learn more, and will reasonably assist you in meeting your own notification obligations. Notifying you is not an admission of fault.

Unsuccessful attempts that do not compromise the security of Customer Personal Data are not personal data breaches and are not individually reported. Port scans, blocked intrusion attempts and failed sign-ins are examples.

10Helping you answer data subject requests

Tinu gives your admins the tools to find, export, correct and delete data directly, so in most cases you can answer a request without us. Where you cannot, we provide reasonable assistance by appropriate technical and organizational measures, taking into account the nature of the processing.

If a data subject contacts us directly about data we process for you, we will not respond on your behalf beyond telling them to contact you, unless you instruct us otherwise or the law requires more. We will pass the request on to you promptly.

11Helping you with impact assessments

Taking into account the nature of the processing and the information available to us, we will assist you in meeting your obligations under Articles 32 to 36 of the GDPR, or their equivalents under other applicable law. That includes security, breach notification to regulators and individuals, data protection impact assessments, and prior consultation of a supervisory authority.

Assistance under this section and section 10 is included at no charge where the effort is reasonable. If a request requires substantial engineering work beyond that, we will tell you before starting and agree the cost with you first.

12Government and legal demands

If a government body or other third party demands access to Customer Personal Data, we will tell you before disclosing anything, so that you can seek to challenge it, unless we are legally barred from telling you. Where we are barred, we will use reasonable efforts to have the restriction lifted.

We will redirect the requester to you where we can, and disclose only the minimum the demand actually requires. Where, after a careful assessment, we conclude there are reasonable grounds to consider the demand unlawful under applicable law, we will challenge it, and will pursue interim measures where they are available.

13Return and deletion

At your choice, after the Agreement ends we will return Customer Personal Data to you or delete it, and delete existing copies, unless a law we are subject to requires us to keep it. You can export it yourself through the product at any time while your subscription is active.

If you give us no instruction, we keep it solely to allow export for 30 days after the Agreement ends, and then delete it in line with the retention schedule in section 07 of the Privacy Policy.

Deleted data persists in encrypted backups for a limited window before rolling off. While it remains there it is put beyond ordinary use: it is not processed for any other purpose, and we do not restore a backup to recover deleted data except to recover from an incident. Where a law requires us to keep a copy, we keep it and stop processing it for any other purpose.

14Audits and information

We make available the information reasonably necessary to demonstrate compliance with this DPA. In practice that means our documentation, our answers to your security questionnaire, and the public commitments on these pages.

If that is not enough for your obligations, you may audit us, or appoint an independent auditor who is not our competitor and is bound by confidentiality, on 30 days written notice, no more than once in any 12 month period, during business hours, and in a way that does not disrupt the service or compromise another customer’s data. You bear the cost, unless the audit reveals a material breach of this DPA, in which case we do.

The once-a-year limit does not apply where there has been a personal data breach affecting your data, where a regulator requires an audit, or where you have credible evidence of material non-compliance with this DPA.

Nothing in this section limits the powers of a competent supervisory or regulatory authority, or our obligation to cooperate with such an authority as applicable law requires.

15International transfers

Tinu is operated from the United States and our subprocessors are primarily US-based, so using Tinu from outside the US means data is transferred to the US.

Where Customer Personal Data is transferred out of the EEA and requires an Article 46 safeguard, the mechanism we use is the European Commission’s Standard Contractual Clauses, Module Two where you are a controller and Module Three where you are yourself a processor. For the UK we apply the UK International Data Transfer Addendum, and for Switzerland the equivalent adaptations.

We execute the Clauses with you. They require choices a web page cannot make on your behalf: the general-authorization option for subprocessors, the governing law, the courts, and the identities, contacts and competent supervisory authority in the annexes. So if you are established in the EEA, the UK or Switzerland, contact privacy@tinuai.com before onboarding and we will complete and execute them with you. Sections 03 and 08 and our subprocessor list supply the substance of the annexes; the elections are made on execution. Where the Clauses apply, they control over any conflicting provision of this DPA or the Agreement.

If a transfer mechanism is invalidated, we will work with you in good faith to put a valid alternative in place.

16US state privacy laws

Where you are a business or controller under a US state privacy law, including the California Consumer Privacy Act as amended and the comprehensive privacy laws of states such as Virginia, Colorado, Connecticut and Texas, and we process personal information on your behalf, you are the business or controller and Tinu acts as your service provider or processor.

We are provided personal information only for the specific business purposes set out in section 03 of this DPA, and we certify that we:

  • do not sell or share it, as those laws define those terms;
  • do not retain, use or disclose it for any purpose other than those business purposes, or as the applicable law otherwise permits;
  • do not retain, use or disclose it outside our direct business relationship with you;
  • do not combine it with personal information from other sources, except as a service provider is permitted to do;
  • comply with the obligations applicable to us under those laws, and provide the same level of privacy protection those laws require of you; and
  • bind any subprocessor we engage to the same obligations by written contract.

We assist you with consumer requests as described in section 10. You may take reasonable and appropriate steps to confirm we use personal information consistently with your obligations, including by the audit and information rights in section 14. We will tell you if we determine we can no longer meet these obligations, and you may take reasonable steps to stop and remediate unauthorized use.

17Changes to this agreement

We version this DPA and date every change. Material changes follow the notice process in section 14 of the Agreement. An executed copy stays fixed at the version you signed; updating this page does not change it.

DateChange
14 September 2026Version 1.0. First publication.

18Signing, and how to reach us

You do not need to sign this DPA. It is part of the Agreement and binds both of us from the moment you accept the Agreement.

If your procurement or legal process requires an executed copy, email privacy@tinuai.com with your full legal entity name, jurisdiction of incorporation, and the name and title of your signatory. We will return a countersigned copy of version 1.0, by electronic signature. Redlines are welcome for enterprise agreements; a negotiated DPA supersedes this one, per section 01.

Tinu Inc
Ann Arbor, Michigan, United States
Privacy and DPA requests: privacy@tinuai.com
Security: security@tinuai.com
General: hello@tinuai.com

See also our Privacy Policy, Subprocessors and Terms of Service, or return to the Tinu AI home page.