This Data Processing Agreement ("DPA") forms part of the TarraOne SaaS Terms of Service between TarraCoata ("Processor") and the customer organisation subscribing to TarraOne ("Controller"). It applies whenever TarraCoata processes personal data on the Controller's behalf. A countersigned copy is available on request from [privacy@tarracoata.com].
1. Roles of the parties
The Controller determines the purposes and means of processing personal data within its workspace. The Processor processes that data only on the Controller's documented instructions, including those given through the platform's configuration and features. The Processor informs the Controller if, in its opinion, an instruction infringes applicable data protection law.
The Controller is responsible for the lawfulness of the data it uploads, including having a valid legal basis and providing required notices to data subjects.
2. Subject matter, duration and nature of processing
- Subject matter: provision of the TarraOne CRM and AI business operating system.
- Duration: the term of the subscription, plus the deletion period in Section 9.
- Nature and purpose: hosting, storage, retrieval, structuring, analysis, AI-assisted enrichment, automation, notification and backup.
- Categories of data subjects: the Controller's employees, users, customers, leads, suppliers and contacts.
- Categories of personal data: identification and contact details, professional details, communication content, workspace activity, files uploaded by the Controller, and technical identifiers.
- Special categories: not intended; the Controller must not upload them without a prior written agreement.
3. Processor obligations
The Processor shall:
- Process personal data only on documented instructions, including for international transfers.
- Ensure that personnel authorised to process personal data are bound by confidentiality obligations.
- Implement the technical and organisational measures described in Section 4 and in the Security Policy.
- Respect the conditions in Article 28(2) and 28(4) GDPR for engaging sub-processors.
- Assist the Controller, taking into account the nature of processing, in responding to data subject requests.
- Assist the Controller with data protection impact assessments and prior consultations.
- Delete or return personal data at the end of the engagement, as instructed.
- Make available all information necessary to demonstrate compliance and allow for audits.
4. Security measures
Technical and organisational measures include, at minimum:
- Encryption in transit (TLS 1.2 or higher) and encryption at rest for databases, files and backups.
- Row-level authorisation so that each workspace can access only its own records.
- Role-based access control, least privilege, and multi-factor authentication for administrative access.
- Segregation of production, staging and development environments.
- Centralised audit logging of administrative and security-relevant events.
- Automated dependency and configuration vulnerability scanning, with prioritised remediation.
- Documented backup, restoration and disaster-recovery procedures with periodic testing.
- Secure software development practices, code review and least-privilege service credentials.
5. Data processing purposes
The Processor processes personal data solely to provide, secure, support, maintain and improve the service for the Controller, to comply with legal obligations, and to prevent abuse. The Processor does not sell personal data, does not use Controller data for its own marketing, and does not use Controller content to train foundation models.
6. Sub-processors
The Controller grants general authorisation for the Processor to engage sub-processors, subject to written terms no less protective than this DPA. Current categories are:
| Category | Purpose | Region |
|---|---|---|
| Cloud application and database hosting | Hosting, storage, backups | EU / US |
| Transactional email delivery | Notifications and system email | EU / US |
| AI model providers | AI-assisted features | EU / US |
| Analytics | Aggregated product usage | EU / US |
| Payment processing | Subscription billing | EU / US |
An itemised, named list including entity details is available at [privacy@tarracoata.com]. The Processor notifies Controllers of intended additions or replacements at least 30 days in advance; the Controller may object on reasonable data protection grounds, and if the parties cannot resolve the objection the Controller may terminate the affected subscription without penalty.
7. International transfers
Where personal data is transferred outside the EEA or Israel, the Processor relies on an adequacy decision, the European Commission's Standard Contractual Clauses (Module Two or Three as applicable), or another lawful mechanism, supported by supplementary measures including encryption and access minimisation.
8. Personal data breach notification
The Processor notifies the Controller without undue delay and in any event within 48 hours of becoming aware of a personal data breach affecting the Controller's data. The notification includes the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point. The Processor assists the Controller with its own notification duties under Articles 33 and 34 GDPR and under Israeli law.
9. Retention, return and deletion
During the subscription the Controller may export its data at any time. On termination, workspace data remains available for export for 30 days, after which it is deleted from production systems; encrypted backups are purged within a further 35 days. The Processor may retain data where required by law, in which case it continues to protect it under this DPA.
10. Audits
Once per twelve months, and on 30 days' written notice, the Controller may request documentation demonstrating compliance, including security summaries and, where available, third-party assessment reports. On-site audits are permitted where legally required, during business hours, without disrupting operations, subject to confidentiality and at the Controller's cost.
11. Data subject requests
If the Processor receives a request directly from a data subject relating to Controller data, it will not respond substantively but will forward the request to the Controller without undue delay and assist as reasonably required.
12. Liability and precedence
Liability under this DPA is subject to the limitations in the SaaS Terms of Service. In case of conflict between this DPA and other agreement documents, this DPA prevails on matters of personal data processing.
13. Contact
Data protection contact: [privacy@tarracoata.com] · TarraCoata, [Registered Address], company number [Company Number].
