Legal
Data Processing Addendum
Last updated:
In plain English: When you sync your systems into Tesylate, some of that data is about people — your staff, customers, suppliers. The law (UK GDPR Article 28) requires a written contract saying we only touch it on your instructions, keep it secure, and give it back or delete it when you leave. This is that contract. It forms part of the Terms of service.
This Addendum applies whenever Tesylate Ltd (“Tesylate”, the processor) processes personal data on behalf of a customer (the controller) in providing the Tesylate service. Terms defined in the UK GDPR have the same meaning here.
1. What processing this covers
| Subject matter | Personal data contained in the business-system data you connect to the Tesylate service. |
| Duration | The subscription term, plus the exit period in clause 9. |
| Nature and purpose | Syncing data from your source systems into a governed data warehouse; transforming and modelling it; serving it back as reports, dashboards, modules, email snapshots and (if enabled) AI-assistant answers; support and troubleshooting. |
| Types of personal data | Whatever your connected systems contain — typically names, business contact details, job roles, transaction and communication records relating to your staff, customers and suppliers. You control which systems and fields are synced. |
| Categories of data subjects | Your employees, customers, suppliers and other business contacts. |
| Special category data | The service is not designed for it. Do not sync it without a prior written agreement with us covering the extra safeguards. |
2. Your instructions
We process personal data only on your documented instructions — being these terms, your configuration of the service (which systems, tables and features you enable), and written instructions you give us — unless UK law requires otherwise, in which case we tell you first if the law allows. If an instruction would, in our view, break data protection law, we tell you rather than quietly follow it.
3. Confidentiality
Everyone we authorise to process your data is bound by a contractual or statutory duty of confidentiality.
4. Security
We implement appropriate technical and organisational measures under UK GDPR Article 32, including: hosting on Microsoft Azure in UK/EU regions; encryption of data in transit; access on a credentialed, restricted basis; per-customer separation of warehouses (no customer’s database references another’s); and secrets management rather than embedded credentials. We make no certification claims (no ISO 27001 or SOC 2) because we hold none.
5. Sub-processors
- You give general written authorisation for the sub-processors listed at /legal/subprocessors.
- We will give you at least 30 days’ notice before adding or replacing one. If you reasonably object on data protection grounds and we cannot resolve it, you may cancel under the Terms before the change takes effect.
- Every sub-processor is bound by data protection obligations equivalent to this Addendum, and we remain fully liable to you for their performance.
- Anthropic is engaged only if you enable the AI assistant features; with the feature off, none of your data goes there.
6. Assisting you
Taking into account the nature of the processing, we assist you with:
- Data subject rights — if a request under UK GDPR Articles 15–22 reaches us instead of you, we pass it to you without undue delay and help you meet it.
- Security, breach notification, DPIAs and prior consultation (Articles 32–36) — with the information available to us.
7. Personal data breaches
We notify you without undue delay after becoming aware of a personal data breach affecting your data, with enough detail for you to meet your own 72-hour ICO obligation, and keep you updated as we investigate.
8. International transfers
Processing under this Addendum happens in UK/EU regions. Transfers outside the UK occur only via listed sub-processors and only under a UK adequacy regulation, the UK Extension to the EU-US Data Privacy Framework (where certified), or the ICO’s IDTA / UK Addendum to the EU SCCs — as recorded per supplier in the sub-processor list.
9. Return and deletion
At the end of the service, on your request within 30 days, we return your data as described in the Terms (clause 10), then delete personal data from live systems and from backups on the normal backup cycle, unless UK law requires us to keep specific records.
10. Audit
We make available the information reasonably necessary to demonstrate compliance with Article 28, and allow audits — starting with written questions and our documentation, escalating to an on-site or remote audit at your cost with reasonable notice, no more than once a year unless a breach or a regulator gives cause.
11. Precedence
If this Addendum conflicts with the Terms on personal data, this Addendum wins.
Tesylate Ltd, registered in England and Wales, No. 11281502. Registered office: 22 Apollo Way, Hemel Hempstead, HP2 5QG.