Tending data processing agreement — template
Last reviewed: 16 September 2026
This is the service template for contracting discussions. It should be reviewed and completed with each client before signature and is not a substitute for legal advice.
1. Parties and scope
This Data Processing Agreement (DPA) forms part of the agreement between the customer using Tending (the Controller) and the entity providing Tending (the Processor) where the Processor processes personal data on the Controller's behalf.
The Processor will process personal data only to provide, secure, support and maintain Tending, and only on documented instructions from the Controller unless applicable law requires otherwise.
2. Processing details
Subject matter: relationship-management and organisational-learning information recorded or deliberately imported into Tending.
Duration: for the term of the service agreement plus the period needed to return or securely delete data in accordance with section 9.
Nature and purposes: hosting relationship records; storing moments and contact details; generating relationship stories and network links; stewardship and resilience analysis; connected-source suggestions; optional AI-assisted extraction and quality inference; export, support and security operations.
Types of personal data: names; work contact details; organisations/groups; relationship notes and interaction history; source/provenance information; stewardship information; inferred relationship-quality signals where enabled; relevant connected-source message/calendar metadata and content; user account identifiers.
Categories of data subjects: the Controller's staff and users; contacts, partners, stakeholders, participants and other people the Controller records in Tending.
The Controller must not intentionally use Tending for special-category or criminal-offence data unless this has been agreed in writing and appropriate safeguards have been documented.
3. Controller responsibilities
The Controller determines the purposes and lawful basis for the personal data it records, provides required privacy information to data subjects, configures access appropriately, and ensures its instructions comply with applicable data protection law.
Tending provides first-class fields for recording source, lawful basis, consent status where relevant, and supporting notes. These fields support the Controller's governance but do not determine the lawful basis on its behalf.
4. Processor obligations
The Processor will:
- process personal data only on documented instructions from the Controller;
- ensure authorised personnel are subject to confidentiality obligations;
- implement appropriate technical and organisational security measures;
- assist the Controller, taking into account the nature of processing, with data-subject requests and with compliance obligations concerning security, breaches, DPIAs and regulator consultation;
- notify the Controller without undue delay after becoming aware of a personal-data breach affecting Controller data;
- make information reasonably necessary to demonstrate compliance with Article 28 UK GDPR available to the Controller; and
- inform the Controller if, in the Processor's opinion, an instruction infringes applicable data protection law.
5. Security measures
Current measures include organisation-scoped access controls; role-based permissions; encrypted transport; encrypted credentials for connected sources; database access controls; deletion cascades for disconnected context sources; restricted AI routing; application and dependency security controls; and export capability.
The primary Tending Postgres database is hosted by Neon in AWS eu-west-2 (London, United Kingdom).
6. AI processing
Tending may use AI services for features selected by the Controller. OpenRouter requests are configured to require Zero Data Retention endpoints and to deny providers marked as collecting request data. Underlying eligible model providers process prompts transiently to produce the requested response.
Relationship-quality inference can be disabled by an organisation administrator. New organisations have this feature disabled by default. AI-generated relationship qualities are stored as inferred signals rather than confirmed facts.
Voice transcription may use ElevenLabs or OpenAI depending on the configured route. Source audio is not retained by Tending after transcription.
7. Subprocessors
The Controller gives general authorisation for the Processor to use the subprocessors listed in docs/legal/subprocessors.md for the purposes described there.
The Processor will keep that schedule current and will provide reasonable notice of a material new subprocessor where required by the customer agreement, allowing the Controller to raise a reasoned data-protection objection.
The Processor remains responsible for ensuring subprocessors are subject to data-protection obligations appropriate to the services they provide.
8. International transfers
Where processing involves a transfer restricted by UK data protection law, the Processor will ensure an appropriate transfer mechanism and applicable supplementary safeguards are in place. The subprocessor schedule records known primary processing locations and should be read alongside each provider's contractual terms.
9. Return and deletion
The Controller can export organisation data from Tending during the service term. Whole-organisation deletion is currently initiated through a verified email request to the Tending support address rather than a self-service control.
On termination or a valid Controller instruction, the Processor will delete or return Controller personal data, at the Controller's choice where technically practicable, unless applicable law requires retention. Backup and provider-level deletion may complete on the relevant service's documented backup lifecycle.
Connected-source context is deleted when that source is disconnected, subject to data already deliberately kept by a user as ordinary Tending organisation data.
10. Data-subject requests
Where the Processor receives a request relating to personal data for which a client is Controller, it will not independently determine the request unless legally required. It will direct or relay the request to the Controller and provide reasonable assistance with searches, correction, export or deletion.
11. Audit and information rights
On reasonable request, the Processor will provide relevant security, subprocessor and processing information needed for the Controller to demonstrate compliance. Any audit should be proportionate, protect other customers' confidentiality and avoid unnecessary disruption; documentary assurance should normally be used before an on-site audit.
12. Order of precedence and signatures
If this DPA conflicts with the service agreement on data-protection matters, this DPA prevails to the extent of that conflict. Commercial liability and governing-law terms remain as set out in the service agreement unless the parties expressly agree otherwise.
Controller: ______
Name / role: ________
Date: ________
Processor: _______
Name / role: ________
Date: ________