DATA PROCESSING ADDENDUM#
Last updated: September 24, 2026
This Data Processing Addendum (DPA) supplements, and is incorporated into and forms part of, the agreement between Customer and TensorCase Inc. (TensorCase) comprising the TensorCase Order Form executed by the Parties and the TensorCase Terms and Conditions available at https://www.tensorcase.com/terms (together, the Agreement), governing Customer’s use of the TensorCase investigations case management platform and related services (the Services), and applies to TensorCase’s processing of Customer Personal Data. Capitalised terms used but not defined in this DPA have the meanings given in the Agreement. TensorCase may amend this DPA from time to time on reasonable notice to Customer to the extent required by changes in Applicable Data Protection Laws. If there is any conflict between this DPA and the Agreement, this DPA governs to the extent of the conflict.
1. Definitions#
1.1 Applicable Data Protection Laws means all privacy and data protection laws and regulations applicable to TensorCase’s processing of Customer Personal Data in connection with the Services, as amended from time to time, including, where applicable, the GDPR, the UK GDPR and UK Data Protection Act 2018, the Swiss Federal Act on Data Protection (FADP), the New Zealand Privacy Act 2020, Canadian Privacy Laws, the Australian Privacy Act 1988 (Cth), and U.S. Privacy Laws.
1.2 Customer Personal Data means Personal Data contained within Customer Data that TensorCase processes on behalf of Customer or its Affiliates under the Agreement, as further described in Schedule 1.
1.3 Data Subject Request means a request from a data subject to exercise rights under Applicable Data Protection Laws, such as rights of access, correction, deletion, or portability.
1.4 GDPR means Regulation (EU) 2016/679. UK GDPR means the GDPR as it forms part of the law of the United Kingdom by virtue of section 3 of the European Union (Withdrawal) Act 2018.
1.5 SCCs means Module Two (controller to processor) and Module Three (processor to processor) of the standard contractual clauses approved by European Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
1.6 Security Breach means a breach of TensorCase’s security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or unauthorised access to, Customer Personal Data.
1.7 Subprocessor means an entity engaged by TensorCase to process Customer Personal Data. TensorCase Personnel are not Subprocessors.
1.8 TensorCase Personnel means TensorCase’s employees and the individual contractors engaged directly by TensorCase who act under TensorCase’s direct authority and on its instructions in connection with the Services.
1.9 UK Addendum means the International Data Transfer Addendum to the SCCs (version B1.0) issued by the UK Information Commissioner under section 119A(1) of the Data Protection Act 2018.
1.10 U.S. Privacy Laws means the subset of Applicable Data Protection Laws applicable to residents of the United States, including the California Consumer Privacy Act, as amended (CCPA), and other U.S. state comprehensive privacy laws.
1.11 The terms personal data, data subject, processing, controller, processor, and supervisory authority have the meanings given by Applicable Data Protection Laws or, absent such meaning, by the GDPR. Controller includes business and processor includes service provider as those terms are defined under U.S. Privacy Laws.
1.12 Canadian Privacy Laws means the Personal Information Protection and Electronic Documents Act (Canada) and applicable provincial private-sector privacy laws, including the Act respecting the protection of personal information in the private sector (Quebec) and the Personal Information Protection Acts of Alberta and British Columbia.
1.13 Storage Region means the jurisdiction and AWS region in which Customer Personal Data is stored at rest, as specified in the Order Form and described in Section 10.5.
2. Processing of Customer Personal Data#
2.1 Roles. With respect to Customer Personal Data, Customer is the controller (or, where Customer acts on behalf of a third-party controller, a processor) and TensorCase is Customer’s processor (or subprocessor, as applicable). TensorCase anticipates that Customer will in many cases act as a processor on behalf of its own clients, in which case Module Three of the SCCs applies. Where Customer is itself a processor, Customer warrants that it has the authority of the relevant controller to engage TensorCase as a subprocessor on the terms of this DPA and that its instructions reflect those of that controller, and Customer is responsible for passing on to that controller any notice or information TensorCase provides under this DPA, including notices under Sections 4.3, 5.1 and 8.1. Each Party will comply with its respective obligations under Applicable Data Protection Laws in connection with the Services. The subject matter, duration, nature, and purpose of the processing, and the categories of personal data and data subjects, are set out in Schedule 1. TensorCase processes account information relating to Customer and its Authorised Users, and Usage Data, as an independent controller in accordance with the TensorCase Privacy Policy, and this DPA does not apply to that processing.
2.2 Instructions. The Parties agree that this DPA, the Agreement (including any Order Form), and Customer’s configuration and use of the Services through their normal functionality constitute Customer’s complete documented instructions (Customer Instructions). TensorCase will process Customer Personal Data only to provide and maintain the Services and in accordance with Customer Instructions, unless required to do otherwise by applicable law to which TensorCase is subject, in which case TensorCase will inform Customer of that legal requirement before processing unless legally prohibited from doing so. Additional instructions require the Parties’ prior written agreement, including any fees.
2.3 U.S. Privacy Law Restrictions. Without limiting Section 2.2, TensorCase will not: (a) sell or share Customer Personal Data, as those terms are defined by U.S. Privacy Laws; (b) retain, use, or disclose Customer Personal Data outside of the direct business relationship between the Parties or for any purpose other than the business purposes specified in the Agreement and Schedule 1, or as otherwise permitted by U.S. Privacy Laws; or (c) except as otherwise permitted by U.S. Privacy Laws, combine Customer Personal Data with personal data that TensorCase receives from or on behalf of any other person, or collects from its own interaction with the data subject.
2.4 Compliance Notice. TensorCase certifies that it understands and will comply with the restrictions in Section 2.3. TensorCase will promptly inform Customer if it determines that it can no longer comply with its processing obligations under this DPA, in which case Customer may take reasonable and appropriate steps in accordance with the Agreement to stop or remediate any unauthorised processing of Customer Personal Data.
2.5 Unlawful Instructions. TensorCase will promptly inform Customer if, in its opinion, a Customer Instruction violates Applicable Data Protection Laws. TensorCase is not obliged to undertake a legal review of the adequacy of Customer Instructions.
2.6 Assistance. TensorCase will cooperate with and provide reasonable assistance to Customer for: (a) Customer’s performance of any data protection impact assessment of the processing of Customer Personal Data by TensorCase; and (b) related consultation with supervisory authorities, either or both of which Customer reasonably considers to be required by Applicable Data Protection Laws.
2.7 Confidentiality and Personnel. TensorCase ensures that each member of TensorCase Personnel authorised to process Customer Personal Data, whether engaged as an employee or as an individual contractor, is engaged under a written agreement with TensorCase imposing confidentiality obligations that survive termination of that engagement, has been subject to background screening where lawful, receives data protection and security training at onboarding and at least annually, and is granted access only to the extent required to provide and support the Services. TensorCase remains fully responsible for the acts and omissions of TensorCase Personnel in respect of Customer Personal Data.
2.8 Government Requests. To the extent legally permitted, TensorCase will inform Customer if it receives a legally binding request for disclosure of Customer Personal Data from a law enforcement or other governmental authority, and will attempt to redirect the authority to request the data directly from Customer. TensorCase will give Customer reasonable notice of the request, unless legally prohibited from doing so, to allow Customer to seek a protective order or other appropriate remedy. TensorCase will review each such request for validity and will challenge any request that it determines to be unlawful or overbroad, where a lawful basis to do so is available to it. TensorCase will disclose only the minimum data necessary to respond to a valid and binding request.
3. Customer Obligations#
3.1 Notices and Authorisations. Customer is responsible for the accuracy, quality, and legality of Customer Personal Data and the means by which it was acquired. Customer represents and warrants that it has provided all necessary notices, and has and will maintain all necessary rights, consents, authorisations, and lawful bases required under Applicable Data Protection Laws, to provide Customer Personal Data to TensorCase and to authorise the processing contemplated by the Agreement and this DPA. Customer will not take any action that would render the provision of Customer Personal Data to TensorCase a sale or share under U.S. Privacy Laws, or render TensorCase not a service provider or processor thereunder.
3.2 Configurations. Without prejudice to TensorCase’s obligations under Section 6, Customer is responsible for its configurations and design decisions within the Services (including retention and deletion settings) and for implementing them in a manner that complies with Applicable Data Protection Laws, and for securing its account credentials.
4. Subprocessors#
4.1 General Authorisation. Customer provides general authorisation for TensorCase to engage the Subprocessors listed in Schedule 4 (the Subprocessor List) and any additional Subprocessors in accordance with Section 4.3.
4.2 Flow-Down; Liability. TensorCase will: (a) enter into a written agreement with each Subprocessor imposing data protection obligations substantially as protective as TensorCase’s obligations under this DPA, to the extent applicable to the nature of the services the Subprocessor provides; and (b) remain liable to Customer for each Subprocessor’s acts and omissions related to this DPA to the same extent TensorCase would be liable if it performed them itself, subject to the limitations of liability in the Agreement. Subprocessors that provide AI services may retain content submitted to them for a limited period for abuse monitoring in accordance with their published terms.
4.3 Changes; Objection. TensorCase will provide notice of any intended addition or replacement of a Subprocessor at least 30 days before the Subprocessor processes Customer Personal Data, by updating the Subprocessor List and notifying the Customer contact specified in the Order Form by email. Customer may object on reasonable data protection grounds by written notice within 30 days of such notice, failing which Customer is deemed to have consented. If Customer objects, the Parties will work together in good faith to reach a mutually acceptable resolution, including commercially reasonable alternatives. If no resolution is reached within 30 days of the objection, either Party may terminate the portion of the Services that cannot be provided without the new Subprocessor, and TensorCase will refund any prepaid fees covering the period after termination.
4.4 Personnel. TensorCase Personnel are not Subprocessors, and changes in TensorCase Personnel are not subject to the notice and objection procedure in Section 4.3. Access by TensorCase Personnel is governed by Sections 2.7 and 10.6 and by Schedule 2.
5. Data Subject Requests#
5.1 TensorCase will promptly forward to Customer any Data Subject Request it receives relating to Customer Personal Data and may direct the data subject to submit the request to Customer. TensorCase will not otherwise respond to such a request without Customer’s prior written authorisation, except as legally required. TensorCase will not identify Customer to a data subject or any other third party as the holder of Customer Personal Data without Customer’s prior written authorisation, except as legally required.
5.2 Taking into account the nature of the processing, TensorCase will provide Customer with reasonable and timely assistance, including by appropriate technical and organisational measures and the self-service functionality of the Services, to enable Customer to respond to Data Subject Requests as required by Applicable Data Protection Laws. TensorCase may charge a reasonable fee for assistance under this DPA that exceeds the Services’ self-service functionality or requires material effort, to the extent permitted by Article 28 GDPR.
6. Security#
6.1 TensorCase will comply with the data security obligations of Applicable Data Protection Laws and will implement and maintain appropriate technical and organisational measures designed to ensure a level of security appropriate to the risk of the processing, as set out in Schedule 2. TensorCase may update those measures from time to time, provided the updates do not materially reduce the overall security of the Services.
6.2 The Parties agree that the measures in Schedule 2 provide a level of security appropriate to the risk presented by the processing described in the Agreement and this DPA.
7. Compliance and Audits#
7.1 TensorCase obtains an independent SOC 2 Type II examination report addressing the Security trust services category. Upon Customer’s written request, and subject to the confidentiality obligations in the Agreement or a separate non-disclosure agreement, TensorCase will provide Customer with its most recent report, together with any other information reasonably necessary to demonstrate compliance with this DPA.
7.2 Upon Customer’s written request, where the information made available under Section 7.1 is not sufficient to demonstrate compliance, TensorCase will permit Customer to audit TensorCase’s applicable controls and compliance with this DPA (an Audit), at Customer’s expense, provided that: (a) the Audit is conducted by Customer or a third-party auditor designated by Customer that has executed an appropriate confidentiality agreement with TensorCase; (b) Customer gives at least 60 days’ prior written notice, unless a shorter period is required by a supervisory authority, and the Parties mutually agree on the reasonable details of the Audit, including start date, scope, duration, and applicable security and confidentiality controls; (c) the Audit does not exceed five business days, takes place during normal business hours, does not unreasonably disrupt TensorCase’s operations, and excludes access to data of other customers and to portions of TensorCase’s systems unrelated to the processing of Customer Personal Data; and (d) a similar Audit has not been conducted within the prior twelve (12) months, unless there are indications of non-compliance or an Audit is required by a supervisory or other regulatory authority responsible for enforcing Applicable Data Protection Laws.
7.3 Customer will pay the reasonable costs and expenses incurred by TensorCase for any Audit that is not (a) required by Applicable Data Protection Laws or (b) conducted in response to a Security Breach. Audit results and documentation are TensorCase’s Confidential Information, and Customer may use them only to meet its regulatory audit requirements and to confirm compliance with this DPA.
8. Security Breaches#
8.1 TensorCase will notify Customer in writing without undue delay after becoming aware of a Security Breach, and will assist Customer in complying with Customer’s obligations under Applicable Data Protection Laws by reasonably cooperating with Customer’s investigation. TensorCase’s notification of, or response to, a Security Breach is not an acknowledgment of any fault or liability.
8.2 Upon becoming aware of a Security Breach, TensorCase will: (a) investigate it and take appropriate measures to address it, including measures to mitigate adverse effects; and (b) provide timely information relating to its nature, including, where reasonably possible, the categories and approximate numbers of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address it. Information may be provided in phases as it becomes available.
8.3 An unsuccessful security event that does not result in unauthorised access to Customer Personal Data or to TensorCase systems storing Customer Personal Data (such as pings, port scans, unsuccessful log-on attempts, or denial-of-service attacks that do not compromise data) is not a Security Breach subject to this Section 8.
9. Deletion and Return#
9.1 Following expiry or termination of the Agreement, TensorCase will make Customer Data available for export through the Services for 30 days. At Customer’s choice exercised within that period, TensorCase will return or delete all Customer Personal Data held in active production systems within 30 days of termination or, if later, within 30 days of the end of the export period, except to the extent that (a) applicable law requires storage, (b) retention is necessary to resolve a dispute between the Parties, or (c) retention is necessary to combat harmful or abusive use of the Services, in which case TensorCase will isolate and protect the retained data from further processing except as so required.
9.2 Residual copies of Customer Personal Data held in automated database backups are deleted through the expiry of TensorCase’s backup retention cycle. Residual copies held in non-current object-storage versions are deleted through the expiry of TensorCase’s storage lifecycle retention cycle, and in any event within 30 days of the deletion of the active data. Residual copies remain subject to the confidentiality and security obligations of this DPA until deleted and are not processed for any other purpose.
9.3 During the term of the Agreement, upon Customer’s written request, TensorCase will delete the Customer Personal Data specified in the request from active production systems, and from backups in accordance with Section 9.2, within 30 days of the request, except where retention is required by applicable law.
10. International Data Transfers#
10.1 The Parties agree that, to the extent required by Applicable Data Protection Laws, the SCCs (Module Two and/or Module Three, as applicable), completed as described in Schedule 3, are incorporated into this DPA by reference and are deemed to have been executed by the Parties. For the avoidance of doubt, the SCCs are not required for transfers covered by a valid adequacy decision under Article 45 GDPR. TensorCase is not certified under the EU-US Data Privacy Framework and does not rely on it as a transfer mechanism.
10.2 To the extent required by Applicable Data Protection Laws, the jurisdiction-specific addenda set out in Schedule 3 (including the UK Addendum and the Swiss Addendum) are incorporated by reference and deemed executed by the Parties.
10.3 If there is any conflict between this DPA, the Agreement, and the SCCs (including any jurisdiction-specific addenda), the following order of precedence applies: (1) the SCCs; (2) this DPA; (3) the Agreement. Nothing in the Agreement or this DPA varies or modifies the SCCs.
10.4 Upon Customer’s written request, TensorCase will provide the information reasonably necessary for Customer to complete a transfer impact assessment in respect of the transfers and access described in this Section 10 and in Schedule 4, including information about the jurisdictions in which Customer Personal Data is stored and from which it may be accessed. If a transfer mechanism relied upon is invalidated, suspended, or allowed to lapse, including any adequacy decision under Article 45 GDPR or the equivalent provision of the UK GDPR, the Parties will cooperate in good faith and without undue delay to implement a lawful alternative, which may include TensorCase making an alternative storage region available to Customer.
10.5 Storage Regions and Processing. Customer Personal Data at rest, including backups, is stored in the Storage Region specified in the Order Form, being the United States, Canada, Australia or the United Kingdom. Customer Personal Data subject to the GDPR or the UK GDPR is stored in the United Kingdom, and for Customer Personal Data subject to the GDPR, TensorCase relies on the European Commission's adequacy decision for the United Kingdom. Task execution and AI inference are carried out in the United Kingdom for the United Kingdom Storage Region and in the United States for the other Storage Regions, through Amazon Bedrock under terms that prohibit the retention of customer content and its use for model training. If Amazon Bedrock is unavailable, inference requests fail over to the Anthropic API and are processed by Anthropic PBC in the United States under the SCCs and the UK Addendum. Customer's execution of the Order Form constitutes its consent to this processing.
10.6 Access by TensorCase Personnel. Customer acknowledges that TensorCase Personnel located outside the Storage Region may access Customer Personal Data for the purpose of providing and supporting the Services. Such access is subject to the measures set out in Schedule 2. TensorCase Personnel are not Subprocessors, and TensorCase remains responsible for their acts and omissions.
11. General#
11.1 Liability. Liability arising out of or related to this DPA (including the SCCs and any jurisdiction-specific addenda) is subject to the limitations and exclusions of liability in the Agreement, and references to the liability of a Party in the Agreement mean that Party’s aggregate liability under the Agreement and this DPA together. Nothing in this Section limits a data subject’s rights as a third-party beneficiary under the SCCs.
11.2 Term. This DPA remains in effect for as long as the Agreement remains in effect or TensorCase retains any Customer Personal Data, whichever is longer. Any provision that by its nature should survive termination in order to protect Customer Personal Data will survive.
11.3 Changes in Law. If a change in Applicable Data Protection Laws prevents either Party from fulfilling its obligations regarding the processing of Customer Personal Data, the Parties will cooperate in good faith to bring the processing into compliance, and may suspend the affected processing in the interim.
11.4 Execution. This DPA is incorporated into the Agreement by reference in the Order Form and takes effect on the Effective Date. No separate signature is required unless a Party requests one. Notwithstanding any amendment provision in the Terms and Conditions, the version of this DPA in effect on the Effective Date continues to apply to Customer until amended in accordance with the first paragraph of this DPA or by written agreement of the Parties.
Schedule 1 – Details of Processing and Transfers#
A. List of Parties#
1. Data Exporter: the Customer entity identified in the Agreement and/or its Affiliates exporting Customer Personal Data. Contact details, and (if appointed) data protection officer and (if relevant) representative details, are set out in the Agreement or will be provided to TensorCase upon request. Role: controller (Module Two) or, where Customer processes Customer Personal Data on behalf of its own clients, processor (Module Three). Signature and date: by entering into the Agreement, the data exporter is deemed to have signed the SCCs, including their Annexes, as of the Effective Date.
2. Data Importer: TensorCase Inc., a Delaware corporation (file number 10073146), 28 Geary Street, Suite 650 #73, San Francisco, CA 94108, USA, contact: Lindsay Kim Chung, Chief Executive Officer, privacy@tensorcase.com. Activities relevant to the data transferred: provision of the investigations case management Services described in the Agreement. Role: processor. Signature and date: by entering into the Agreement, the data importer is deemed to have signed the SCCs, including their Annexes, as of the Effective Date.
3. Representatives. TensorCase’s representative in the European Union for the purposes of Article 27(3) GDPR is TwoBridge Legal, contact: enquiries@twobridge.legal. TensorCase’s representative in the United Kingdom for the purposes of Article 27 UK GDPR is LS Law Limited, contact: info@lslawservices.com. TensorCase may change either representative on notice to Customer, and the current details are published in the TensorCase privacy notice.
B. Description of Processing#
| Item | Description |
|---|---|
| Categories of data subjects | Subjects of investigations, complainants, witnesses, reporters, employees, third parties named in case records, and Customer’s Authorised Users, as determined by Customer |
| Categories of personal data | Identification and contact details, employment information, case and allegation content, correspondence, documents and evidence uploaded by Customer, and metadata generated by the Services. The specific categories are determined by Customer through its use of the Services |
| Special categories of personal data | Yes. Investigation records may contain special categories of personal data within Article 9 GDPR and personal data relating to criminal convictions and offences within Article 10 GDPR. Applied restrictions and safeguards: strict purpose limitation; role-based access restrictions and least privilege; encryption in transit and at rest; logging of access; storage in the Storage Region specified in the Order Form |
| Frequency of the transfer | Continuous, for the duration of the Services |
| Subject matter and nature of the processing | Receiving, storing, organising, structuring, retrieving, analysing, and otherwise processing case data to provide investigations case management functionality, including any AI-assisted features enabled by Customer, with human-in-the-loop review |
| Purpose of the transfer and further processing | Provision of the Services to Customer pursuant to the Agreement |
| Retention period | The term of the Agreement plus the deletion periods in Section 9, subject to legal retention requirements |
| Transfers to Subprocessors | Subprocessors will process Customer Personal Data as necessary to perform the Services for the duration of the Agreement (Schedule 4) |
| Access by TensorCase Personnel | TensorCase Personnel may access Customer Personal Data stored in any Storage Region for support and operation of the Services, subject to Schedule 2.G and Section 10.6. TensorCase Personnel are not Subprocessors |
C. Competent Supervisory Authority#
The competent supervisory authority is determined in accordance with Clause 13 of the SCCs. For the UK, the Information Commissioner’s Office; for Switzerland, the Federal Data Protection and Information Commissioner (FDPIC).
Schedule 2 – Technical and Organisational Measures#
TensorCase has implemented and will maintain the following technical and organisational measures to protect the security, confidentiality, and integrity of Customer Personal Data. TensorCase may update these measures from time to time, provided updates do not materially diminish the overall security of the Services.
A. Access Control and Authentication#
Role-based access control and least-privilege access to production systems. Unique named user accounts, with authentication by individual credentials or authorised SSH keys. Multi-factor authentication is required for administrative and remote access to production systems. Access to production systems is limited to a small number of named individuals. Access is reviewed periodically and revoked promptly on role change or departure.
B. Encryption#
Encryption of Customer Personal Data in transit using TLS 1.2 or above, and encryption at rest using AES-256 through AWS Key Management Service. Keys are resident in the same region as the data they protect. Privileged access to encryption keys is restricted to authorised personnel with a business need.
C. Resilience and Availability#
Automated daily database backups and point-in-time recovery, held in the same jurisdiction as the primary data (in the same region for the United Kingdom, and in a second region within the same country for the United States, Canada and Australia). Object storage versioning with continuous replication within the same jurisdiction. Multi-availability-zone automatic failover. Backups are encrypted and access to backup infrastructure is restricted. Business continuity and disaster recovery procedures are documented and tested at least annually.
D. Logging, Monitoring, and Incident Response#
Audit logging of administrative and user access to Customer Data through named accounts. Multi-region API and infrastructure activity logging, and application logging for production services. Automated alerting on error and availability conditions routed to an on-call notification channel. A log management tool and intrusion detection are used for continuous monitoring. Documented incident response process supporting breach notification under Section 8, tested at least annually.
E. Data Segregation and Management#
Logical separation of each customer’s data within the multi-tenant environment. Network segmentation separating production from development, testing, and corporate environments. Documented deletion processes.
F. Physical Security#
Data centre physical and environmental security is managed by Amazon Web Services under its published controls, and TensorCase reviews its attestation reports at least annually. No Customer Personal Data is stored on physical premises or on removable media.
G. Personnel#
Written confidentiality agreements with all TensorCase Personnel, whether engaged as employees or as individual contractors, surviving termination of the engagement. Background screening on engagement where lawful. Data protection and security awareness training on engagement and at least annually thereafter. Such access is provisioned and reviewed in accordance with Schedule 2.A. TensorCase Personnel are not permitted to store Customer Personal Data on local or unmanaged devices.
H. Vulnerability Management#
Automated code, artifact, and dependency scanning on a continuous basis. Infrastructure vulnerability scanning on a regular basis. Manual code review. Endpoint detection and anti-malware on managed endpoints. Annual third-party penetration testing, with a summary available to Customer on request. Risk-based patching.
I. Audits and Certifications#
Independent SOC 2 Type II examination addressing the Security trust services category. The most recent report is available to Customer on request under a non-disclosure agreement.
J. Vendor and Subprocessor Management#
Security assessment of Subprocessors before onboarding and periodically thereafter. Written data protection terms with each Subprocessor in accordance with Section 4.2.
K. Governance#
A named member of TensorCase’s leadership is accountable for privacy and information security governance, including maintenance of the record of processing activities, the Subprocessor List, and TensorCase’s transfer documentation. Policies are reviewed and approved at least annually.
Schedule 3 – International Data Transfers#
A. EU SCCs#
Elections for the purposes of Module Two and Module Three of the SCCs:
(a) Clause 7 (Docking clause) does not apply.
(b) Clause 9 (Use of sub-processors): Option 2 (general written authorisation) applies, and the minimum period for prior notice of Subprocessor changes is as specified in Section 4.3 of this DPA.
(c) Clause 11 (Redress): the optional wording does not apply.
(d) Clause 17 (Governing law): Option 1 applies; the governing law is the law of Ireland.
(e) Clause 18 (Choice of forum and jurisdiction): the courts of Ireland.
(f) Annex I of the SCCs: Parts A, B, and C of Schedule 1 contain the list of Parties, the description of the transfer, and the competent supervisory authority, respectively.
(g) Annex II of the SCCs: Schedule 2 contains the technical and organisational measures.
(h) Annex III of the SCCs: the Subprocessor List referenced in Section 4.1 of this DPA. Subprocessor contact details will be provided by TensorCase upon request.
B. UK Addendum#
The UK Addendum applies to any processing of Customer Personal Data subject to the UK GDPR (or both the UK GDPR and the GDPR) and is completed as follows: Table 1, the Parties’ details are as set out in Part A of Schedule 1; Table 2, the selected SCCs are the EU SCCs as completed in Part A of this Schedule 3, including the Appendix Information; Table 3, the appendix information is set out in Schedules 1, 2, and 4; Table 4, the importer may end the UK Addendum as set out in Section 19 thereof.
C. Swiss Addendum#
For any processing of Customer Personal Data subject to the FADP (or both the FADP and the GDPR), the SCCs as completed in Part A of this Schedule 3 apply with the following amendments to the extent required: references to the GDPR are to be interpreted as references to the FADP insofar as transfers are subject to the FADP; the competent supervisory authority under Clause 13 and Annex I.C is the FDPIC insofar as transfers are governed by the FADP; Clause 17, the SCCs are governed by the laws of Switzerland insofar as transfers are governed by the FADP; Clause 18, disputes relating to such transfers will be resolved by the courts of Switzerland, and data subjects may bring proceedings in the courts of their habitual residence in Switzerland. The hierarchy clause of the SCCs applies such that the provisions most protective of data subjects prevail. Customer warrants that it has made any notifications to the FDPIC required under the FADP.
Schedule 4 – Subprocessors#
The Subprocessor List is published at https://www.tensorcase.com/subprocessors and identifies each Subprocessor, its processing activity and its location. TensorCase will notify Customer of any changes to this list as described in Section 4.3. TensorCase Personnel are not Subprocessors; access by TensorCase Personnel is described in Section 10.6.
Need help? Contact us at support@tensorcase.com