Data Processing Addendum
Last updated:
This Data Processing Addendum ("DPA") supplements our Terms of Service and applies where Tesselith, Inc. processes personal data on behalf of a customer ("Customer") who is a controller subject to the GDPR, UK GDPR, or comparable laws.
1. Roles
For personal data that Customer submits to the Service (including the content and connected accounts within a workspace), Customer is the controller and Tesselith is the processor. Tesselith processes such data only on Customer's documented instructions, which include the Terms of Service and use of the Service's features.
2. Scope of processing
- Subject matter: provision of the Tesselith scheduling and analytics Service.
- Duration: for the term of the customer relationship, plus deletion periods.
- Nature & purpose: hosting, storing, scheduling, publishing, and analyzing content across connected networks.
- Data subjects: Customer's team members and the audiences of their social accounts.
- Data types: account and workspace data, content, connected-account tokens and profile data, and usage data.
3. Our obligations
- Process personal data only on documented instructions.
- Ensure personnel are bound by confidentiality.
- Implement appropriate technical and organizational security measures (see our Security page).
- Assist Customer with data-subject requests and with security, breach-notification, and impact-assessment obligations, taking into account the nature of processing.
- Notify Customer without undue delay after becoming aware of a personal-data breach.
- Delete or return personal data at the end of the relationship, subject to legal retention.
4. Subprocessors
Customer authorizes Tesselith to engage subprocessors to provide the Service. A current list of subprocessor categories is in our Privacy Policy. We impose data-protection terms on subprocessors no less protective than this DPA, and we remain responsible for their performance. We will give notice of new subprocessors and an opportunity to object on reasonable grounds.
5. International transfers
Where personal data is transferred out of the EEA, UK, or other regulated regions, the parties rely on Standard Contractual Clauses or another valid transfer mechanism, which are incorporated by reference.
6. Audits
Tesselith will make available information reasonably necessary to demonstrate compliance with this DPA and will allow for audits, subject to reasonable confidentiality and security conditions.
7. Requesting a signed DPA
To execute a countersigned copy of this DPA, contact [email protected].