TemsAI DPA
TemsAI, TemsSoft B.V.
DATA PROCESSING AGREEMENT
Document: Data Processing Agreement, annex to the TemsAI Subscription Agreement
Processor / Service Provider: TemsSoft B.V., a private limited company incorporated under the laws of the Netherlands, VAT number NL867296859B01, trading as "TemsAI"
Applies to: All customers and licensees of the TemsAI Services
Version: Published version 2.0, effective 01.09.2026
Applicable law: GDPR Art. 28; UK GDPR; Swiss FADP; US State Privacy Laws incl. CCPA/CPRA
Aligned with Commission Implementing Decision (EU) 2021/915; SCCs (EU) 2021/914
Data Processing Agreement
This Data Processing Agreement (the “DPA”) forms part of, and is subject to, the agreement between the parties for the provision of the TemsAI platform and related services (the “Agreement”). It applies to all processing of Personal Data carried out by TemsAI on behalf of the Customer.
Application. This DPA is entered into between TemsSoft B.V., a private limited company incorporated under the laws of the Netherlands, trading as “TemsAI” (the “Processor” or “TemsAI”), and any customer, licensee or organisation that accepts the Agreement or otherwise uses the Services (the “Customer” or “Licensee”). It takes effect automatically on the earlier of the Customer’s acceptance of the Agreement and the commencement of the Services, and requires no separate signature.
Identification of the Customer. The Customer is the entity identified in the order form, subscription or account registration under which the Services are provided. Where an individual accepts the Agreement on behalf of an organisation, that individual warrants that they are authorised to bind it, and the organisation is the Customer for the purposes of this DPA.
Negotiated agreements. Where the Processor and a Customer have executed a separately negotiated data processing agreement, that agreement prevails over this published version for that Customer.
Each of the Processor and the Customer is a “Party” and together they are the “Parties”.
Definitions and interpretation
1.1 Capitalised terms not defined here have the meaning given in the Agreement. The following definitions apply:
“Customer Personal Data” means Personal Data contained in Customer Data that the Processor processes on behalf of the Customer under the Agreement, as described in Annex II.
“Data Protection Laws” means all laws applicable to the processing of Customer Personal Data, including: Regulation (EU) 2016/679 (“GDPR”); the Dutch UAVG; the UK GDPR and Data Protection Act 2018; the Swiss Federal Act on Data Protection (“FADP”); Regulation (EU) 2024/1689 (the “EU AI Act”); and US State Privacy Laws.
“US State Privacy Laws” means the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA”) and its implementing regulations, and all other US state privacy or consumer data protection statutes applicable to the processing, together with applicable state biometric privacy statutes including the Illinois Biometric Information Privacy Act (“BIPA”).
“Controller, Processor, Data Subject, Personal Data, Personal Data Breach, Processing, Supervisory Authority” have the meanings given in the GDPR. Business, Service Provider, Consumer, Personal Information, Sell, Share and Business Purpose have the meanings given in the CCPA.
“Restricted Transfer” means a transfer of Customer Personal Data to a country that is not the subject of an adequacy decision under the applicable Data Protection Law.
“Security Measures” means the technical and organisational measures set out in Annex III.
“Sub-processor” means any third party engaged by the Processor to process Customer Personal Data, excluding the Processor’s own personnel.
“EU SCCs” means the standard contractual clauses adopted by Commission Implementing Decision (EU) 2021/914.
“Source Media” means photographs, video and audio recordings captured by or on behalf of the Customer for the purpose of knowledge capture and content generation within the Services.
“Agreement” means the TemsAI Subscription Agreement, Terms of Service or executed order form under which the Customer is licensed to use the Services, including any online terms accepted by the Customer. This DPA forms an integral part of the Agreement, and prevails over it in respect of the processing of Customer Personal Data.
“Customer, Licensee” are used interchangeably and mean the entity identified above that is licensed to use the Services. References to the Customer include its Authorised Users.
“Authorised Users” means the Customer’s employees, officers, contractors, associates, agents and any other person or third party to whom the Customer grants access to the Services or on whose behalf the Customer submits content to the Services.
“Customer Content” means all data, documents, images, video, audio, Source Media and other material uploaded to, captured within, submitted to, or generated from material supplied to the Services by or on behalf of the Customer or any Authorised User.
1.2 This DPA is drafted to satisfy Article 28(3) GDPR and equivalent contractual requirements under UK, Swiss and US State Privacy Laws, and follows the structure of the standard contractual clauses between controllers and processors in Commission Implementing Decision (EU) 2021/915.
1.3 Where a provision applies only to a particular jurisdiction, it applies only to the extent the relevant Data Protection Law governs the processing. Jurisdiction-specific terms are set out in Annex V.
Roles of the Parties
2.1 In relation to Customer Personal Data, the Customer is the Controller (or a processor acting on behalf of a third-party controller) and the Processor is the Processor. For processing subject to the CCPA, the Customer is the Business and the Processor is a Service Provider.
2.2 The subject matter, duration, nature and purpose of the processing, the types of Personal Data and the categories of Data Subjects are set out in Annex II.
2.3 The Processor acts as an independent controller only in respect of: (a) account administration, contract and billing data of the Customer’s authorised administrators; (b) aggregated and anonymised or deidentified data as permitted by clause 13; and (c) processing necessary to comply with its own legal obligations or to secure the Services. That processing is governed by the Processor’s privacy notice and not by this DPA.
Customer responsibilities and warranties
3.1 The Customer warrants that it has and will maintain a valid legal basis for the processing of Customer Personal Data, and that it has given all notices and obtained all consents, authorisations or approvals required under Data Protection Laws and under applicable employment or labour law, including any works council or employee representative information or consultation.
3.2 Customer Content. The Processor processes only such Customer Content as is uploaded to, captured within or submitted to the Services by the Customer or its Authorised Users, and does so solely as a Processor acting on the Customer’s instructions. The Customer is solely and fully responsible for all Customer Content, including its accuracy, quality, legality, appropriateness, the manner in which it was collected, and its compliance with all applicable laws, regulations and internal policies. The Processor exercises no control over Customer Content, does not select or determine what is submitted, and accepts no responsibility and no liability whatsoever for Customer Content or for any consequence of its submission to or use within the Services.
3.3 Authorised Users and third parties. The Customer is responsible for the acts and omissions of its Authorised Users as if they were its own. It is the full responsibility of the Customer, its employees, associates and any third party to whom it grants access to comply with all applicable laws and regulations, including the GDPR and all other data protection and privacy laws applicable in their respective jurisdictions, and with the Customer’s own internal policies. The Customer shall ensure that all consents, notices, authorisations, works council or employee representative approvals and any other documentation required in respect of its employees, associates, contractors and any third parties are obtained before those persons are granted access to the Services and before any content or Personal Data relating to them is submitted to the Services. The Processor bears no responsibility or liability in respect of any of the foregoing.
3.4 Closed platform; the Customer controls access. The Services are not a publicly available platform. No content within the Customer’s environment is accessible to the general public, and the Processor does not determine, select or approve who may access the Customer’s account or Customer Content. The Customer alone decides which of its employees, associates, contractors and third parties are granted access to the Services and to Customer Content, at what level of permission, and for how long. It is accordingly the Customer’s sole responsibility to satisfy itself, before granting any such access, that the access complies with all applicable external laws and regulations - including the GDPR and all other applicable data protection, privacy, confidentiality and employment laws - and with the Customer’s own internal policies, works council arrangements and confidentiality obligations, and to obtain any approvals or consents required for that access. The Processor bears no responsibility or liability in respect of the Customer’s decisions on access, or the acts or omissions of any person to whom the Customer grants access.
3.5 The Customer is responsible for configuring user roles, permissions, recording settings and retention periods within the Services consistently with its own obligations, and for the secure administration of accounts and credentials.
3.6 The Customer shall not submit to the Services any special categories of Personal Data within the meaning of Article 9 GDPR, Personal Data relating to criminal convictions or offences, government identifiers, payment card data, or Personal Data of children, unless expressly agreed in writing in Annex II together with any additional safeguards.
3.7 The Customer shall defend, indemnify and hold harmless the Processor and its affiliates against all claims, proceedings, losses, damages, fines, penalties and reasonable costs (including legal fees) arising from or in connection with: (a) the Customer’s breach of clauses 3.1 to 3.6; (b) instructions that infringe Data Protection Laws; (c) content or Source Media submitted to the Services in breach of third-party rights or without required notices, consents or approvals; (d) the Customer disabling or circumventing any privacy-protective feature of the Services, including automated face blurring; or (e) any use of the Services outside the Permitted Use described in clause 13; or (f) the granting of access to the Services or to Customer Content to any person in breach of clause 3.4.
3.8 The indemnity in clause 3.7 is not subject to any limitation or exclusion of liability in the Agreement or in this DPA.
Processor obligations
4.1 Documented instructions
(a) The Processor shall process Customer Personal Data only on the Customer’s documented instructions. The Agreement, this DPA, and the Customer’s authorised use and configuration of the Services constitute the Customer’s complete documented instructions.
(b) Additional or divergent instructions require written agreement and may be subject to reasonable additional charges where they require material effort or changes to the Services. The Processor may decline instructions that are technically infeasible or that would require modification of the Services.
(c) The Processor shall inform the Customer without undue delay if, in its opinion, an instruction infringes Data Protection Laws, and may suspend the affected processing until the instruction is confirmed, amended or withdrawn.
(d) Where required by law to process Customer Personal Data other than on the Customer’s instructions, the Processor shall inform the Customer before processing unless legally prohibited from doing so on important grounds of public interest.
4.2 Purpose limitation, duration and confidentiality
(a) The Processor shall process Customer Personal Data only for the purposes set out in Annex II and only for the duration set out there.
(b) The Processor shall ensure that persons authorised to process Customer Personal Data are bound by an appropriate statutory or contractual duty of confidentiality, are granted access strictly on a need-to-know basis, and receive data protection and security training at onboarding and annually.
4.3 Security
(a) Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, the Processor shall implement and maintain the Security Measures set out in Annex III.
(b) The Processor maintains certification to ISO/IEC 27001 and shall maintain that certification, or an equivalent recognised standard, throughout the term.
(c) The Processor may update the Security Measures provided the updated measures do not materially reduce the overall level of security.
4.4 No monitoring obligation
(a) The Processor has no obligation to review, monitor, verify or moderate Customer Data, Source Media or content generated within the Services, and does not do so except as necessary to provide, secure and support the Services or as required by law. The Processor is not responsible for the content, accuracy or lawfulness of Customer Data.
(b) The Processor is not responsible for the Customer’s own systems, identity provider, network, devices, third-party integrations or configuration choices, or for any loss arising from them.
Knowledge capture, media and biometrics
5.1 Customer determines all content. The Customer alone decides what Customer Data and Source Media is uploaded to, or captured within, the Services, by whom, in what form and for what purpose. The functionality of the Services does not require images of individuals’ faces, or recordings of individuals’ voices. Whether any such material is submitted to the Services is a decision of the Customer alone.
5.2 Default configuration - no voice retained or played back. In the default configuration the Services do not store, display or play back the voice of any individual. Audio contained in Source Media is processed transiently for the sole purpose of automated transcription, and the content delivered to users consists of captions, text-based guidance and visual instruction.
5.3 Optional synthetic voice-over. Certain subscription plans offer machine-generated voice-over of video content. Where the Customer elects that option, narration uses a synthesised voice generated by the Processor’s technology. The Services do not clone, reproduce or synthesise the voice of any individual appearing in Source Media.
5.4 Optional retention of original audio. Certain subscription plans permit the Customer to retain and display the original audio contained in Source Media. That option is activated solely by the Customer’s own election. Where the Customer so elects, the Customer alone determines the purposes and means of that processing and bears sole and full responsibility for compliance with all applicable Data Protection Laws - both in its own jurisdiction and in the jurisdiction of any individual appearing or heard in the material - including the provision of notices and the obtaining of consents, authorisations and works council or employee representative approvals. The Processor bears no responsibility and no liability whatsoever in respect of that election or its consequences.
5.5 Faces and optional automated blurring. The functionality of the Services does not require the faces of individuals to appear in Source Media. Certain subscription plans offer automated blurring of faces in images and video. The selection of a subscription plan, and of the features activated within it, is the decision of the Customer alone. The Processor does not select, recommend or determine the configuration appropriate to the Customer’s legal, operational or jurisdictional circumstances, and shall have no liability arising from the Customer’s selection or non-selection of any plan or feature.
5.6 No biometric processing. In any configuration, the Processor does not create, derive, store or use biometric templates, faceprints, voiceprints or other biometric identifiers, and does not perform facial recognition, facial identification, voice identification or voice authentication. The Processor does not process biometric data for the purpose of uniquely identifying a natural person within the meaning of Article 9 GDPR, and does not collect, capture, store or use biometric identifiers or biometric information within the meaning of applicable US biometric privacy statutes, including BIPA.
5.7 Customer responsibility for individuals appearing in content. Before any Source Media containing the image or voice of an individual is uploaded to or captured within the Services, the Customer shall provide all notices and obtain all consents, authorisations and works council or employee representative approvals required in every relevant jurisdiction, including the jurisdiction of the individual concerned. The Customer is solely responsible for the lawfulness of such material and of its continued use, and shall indemnify the Processor in accordance with clause 3.7.
5.8 Scope of representations. The statements in clauses 5.2, 5.3 and 5.6 describe the Services as supplied and configured by the Processor. They do not apply to material that has been altered, exported or processed outside the Services, nor to features the Customer has elected to enable or disable. The Processor makes no representation that any particular plan, configuration or feature is sufficient for the Customer’s compliance obligations, and nothing in this DPA, in the Processor’s documentation or in any communication from the Processor constitutes legal or compliance advice.
Data subject and consumer requests
6.1 The Services provide functionality enabling the Customer to access, correct, export and delete Customer Personal Data. The Customer shall use that functionality to respond to requests from Data Subjects or Consumers in the first instance.
6.2 Where the Processor receives a request relating to Customer Personal Data, it shall not respond other than to acknowledge receipt, shall promptly inform the Customer, and shall direct the individual to the Customer.
6.3 Taking into account the nature of the processing, the Processor shall provide reasonable assistance to the Customer in responding to such requests insofar as this is possible. Assistance that cannot be provided through the standard functionality of the Services may be charged at the Processor’s then-current professional services rates.
Assistance, assessments and cooperation
7.1 Taking into account the nature of processing and the information available to it, the Processor shall provide reasonable assistance to the Customer in complying with Articles 32 to 36 GDPR, including data protection impact assessments and prior consultation, and with equivalent assessment obligations under US State Privacy Laws.
7.2 The Processor makes available documentation describing the Services, the categories of data processed, the Security Measures, and information reasonably required for the Customer’s obligations as a deployer under the EU AI Act. Assistance beyond the provision of such documentation may be charged in accordance with clause 6.3.
Sub-processors
8.1 General authorisation. The Customer grants the Processor general written authorisation, within the meaning of Article 28(2) GDPR, to engage Sub-processors for the provision, hosting, security, support and continuous improvement of the Services. The selection of Sub-processors is a technical and operational decision of the Processor.
8.2 Standard applied to every Sub-processor. The Processor shall engage only Sub-processors that provide sufficient guarantees to implement appropriate technical and organisational measures meeting the requirements of Data Protection Laws. Before engagement, each Sub-processor is assessed under the Processor’s ISO/IEC 27001 supplier management process for security posture, certifications, data protection compliance and, where relevant, transfer safeguards. Each Sub-processor is bound by a written contract imposing data protection obligations substantially equivalent to those in this DPA, including confidentiality, purpose limitation, security and assistance obligations, and - for providers of artificial intelligence models - a prohibition on using Customer Personal Data to train models.
8.3 Transparency and notification. The Processor maintains a current list of Sub-processors, by category and by name, at tems.ai/legal/sub-processors. The Processor shall notify additions and replacements by updating that list at least fifteen (15) days before the new Sub-processor begins processing Customer Personal Data. The Customer may subscribe at that page to receive notifications automatically, and it is the Customer’s responsibility to subscribe and to monitor notifications. Publication on that page and, where subscribed, the corresponding notification constitute the information required under Article 28(2) GDPR, and no separate or individually negotiated notice is required.
8.4 Objection. The Customer may object to a new Sub-processor within fifteen (15) days of the notification, by written notice setting out specific and reasonable data protection grounds. Objections on commercial grounds, or on grounds of preference for an alternative provider, are not valid. The Parties shall discuss the objection in good faith and the Processor may propose alternative safeguards. Where no resolution is reached within thirty (30) days, the Customer’s sole and exclusive remedy is to terminate the affected Services on written notice, with a pro-rata refund of prepaid fees for the unused period. An objection does not suspend or delay the engagement of the Sub-processor, and does not entitle the Customer to withhold fees, to require the Processor to appoint a different provider, or to any other remedy.
8.5 Urgent replacement. Where a Sub-processor must be added or replaced without delay in order to maintain the security, availability or continuity of the Services - including on termination, insolvency or material failure of an existing Sub-processor, or to address a security vulnerability - the Processor may make the change immediately and shall update the list and notify the Customer as soon as reasonably practicable thereafter.
8.6 Confidentiality of arrangements. The Processor is not required to disclose the commercial terms of, or any commercially sensitive information relating to, its arrangements with Sub-processors.
8.7 Responsibility. The Processor remains fully liable to the Customer for the performance of each Sub-processor’s data protection obligations.
Personal data breach
9.1 The Processor shall notify the Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data.
9.2 The notification shall include, to the extent known: the nature of the breach, the categories and approximate number of individuals and records concerned, likely consequences, measures taken or proposed, and a contact point. Information may be provided in phases as the investigation progresses.
9.3 The Processor shall take reasonable steps to contain, investigate and mitigate the breach and shall cooperate reasonably with the Customer’s own notification obligations.
9.4 Notification is not an acknowledgement of fault or liability. Unsuccessful attempts that do not result in unauthorised access to Customer Personal Data - including pings, port scans, failed log-in attempts and denial-of-service attempts - are not Personal Data Breaches.
9.5 Each Party bears its own costs of investigating, notifying and remediating a Personal Data Breach, including the costs of notifying individuals and regulators, unless and to the extent the breach was caused by the other Party’s negligence or breach of this DPA.
9.6 The Processor is not responsible for a Personal Data Breach to the extent it results from the Customer’s own systems or credentials, the acts or omissions of the Customer’s personnel, or the Customer’s configuration of the Services.
Audits and demonstration of compliance
10.1 The Processor shall make available information reasonably necessary to demonstrate compliance with this DPA. It shall satisfy this obligation in the first instance by providing its current ISO/IEC 27001 certificate and statement of applicability, summary penetration test results, and a completed security questionnaire.
10.2 Where that documentation is insufficient, the Customer may, no more than once in any twelve (12) month period and on at least thirty (30) days’ written notice, audit the Processor’s processing of Customer Personal Data. Additional audits may be conducted where required by a Supervisory Authority or following a confirmed Personal Data Breach affecting the Customer.
10.3 Audits shall take place during normal business hours, shall not unreasonably disrupt operations, shall be limited to systems and documentation relevant to Customer Personal Data, and are subject to confidentiality. The Customer bears its own costs and shall reimburse the Processor’s reasonable costs of supporting an audit. Audits shall not include penetration testing of shared infrastructure or access to other customers’ data or environments.
10.4 Any auditor shall not be a competitor of the Processor and shall be bound by confidentiality obligations in favour of the Processor.
International transfers
11.1 Customer Personal Data is hosted in the region specified in Annex II. Unless otherwise agreed, hosting is within the European Economic Area.
11.2 Where a Restricted Transfer occurs, the Parties shall ensure an appropriate safeguard applies under the relevant Data Protection Law. The EU SCCs are incorporated by reference and completed as set out in Annex V, with Module Two applying where the Customer is a controller and Module Three where the Customer is a processor.
11.3 For transfers subject to UK or Swiss law, the modifications in Annex V apply.
11.4 Where required, the Processor shall carry out and document a transfer impact assessment and make it available to the Customer on request.
11.5 Government and law enforcement access. If the Processor receives a legally binding request from a public authority for disclosure of Customer Personal Data, it shall, unless legally prohibited: notify the Customer without undue delay; seek to redirect the authority to the Customer; challenge the request where there are reasonable grounds to consider it unlawful; and disclose only the minimum amount of data lawfully required. The Processor shall document such requests and provide the Customer with the information reasonably available to it.
United States: Service Provider terms
12.1 This clause applies to Personal Information subject to US State Privacy Laws. The Customer is the Business or Controller; the Processor is a Service Provider or Processor.
12.2 The Processor shall not: (a) Sell or Share Personal Information; (b) retain, use or disclose Personal Information for any purpose other than the Business Purposes specified in this DPA and Annex II, or as otherwise permitted by US State Privacy Laws; (c) retain, use or disclose Personal Information outside the direct business relationship between the Parties; or (d) combine Personal Information received from the Customer with Personal Information received from or on behalf of any other person, except as permitted for a Service Provider.
12.3 The Processor shall not use Personal Information for cross-context behavioural advertising and shall not engage in profiling of individuals on the Customer’s behalf beyond the functionality of the Services.
12.4 The Processor shall comply with its applicable obligations under US State Privacy Laws, provide the same level of privacy protection as required of a Business, and notify the Customer if it determines it can no longer meet those obligations. On such notice the Customer may take reasonable and appropriate steps to stop and remediate any unauthorised use.
12.5 Where the Processor discloses Personal Information to a Sub-processor, it shall do so under a written contract imposing obligations equivalent to those in this clause.
12.6 Deidentified data. Where the Processor holds deidentified data, it shall take reasonable measures to prevent reidentification, publicly commit to maintain it in deidentified form, and contractually obligate any recipient to the same.
Artificial intelligence, model training and aggregated data
13.1 The Processor shall not use Customer Personal Data, or Customer Data containing Personal Data, to train, fine-tune or otherwise improve any generally available machine learning model, whether its own or a third party’s.
13.2 Where the Services use third-party model providers, the Processor contracts on enterprise terms that prohibit the use of input and output data for model training, and discloses those providers in the Sub-processor list maintained under clause 8.3.
13.3 The Processor may create and use aggregated, anonymised or deidentified data derived from operation of the Services - including usage volumes, feature adoption, performance and quality statistics - to operate, secure, benchmark and improve the Services and for its legitimate business purposes. Such data shall be irreversibly anonymised or deidentified so that no individual and no Customer is identifiable, shall not constitute Personal Data or Personal Information, and may be disclosed only in a form that does not identify the Customer.
13.4 Human oversight. The Services support human oversight and do not carry out automated decision-making producing legal or similarly significant effects concerning individuals within the meaning of Article 22 GDPR. The Customer shall not configure or use the Services to evaluate, rank, discipline or monitor the individual performance or conduct of employees in a manner producing such effects.
13.5 Generated content requires human verification. Content generated by the Services is produced from sources supplied or selected by the Customer. The Customer is responsible for reviewing, validating and approving generated work instructions, training and guidance content before operational use, and in particular before any use relating to health, safety, quality or regulatory compliance. The Processor gives no warranty as to the accuracy, completeness or fitness for a particular purpose of generated content, and is not responsible for operational, safety, employment or compliance decisions taken by the Customer or its personnel.
13.6 Permitted Use and AI Act roles. The Customer acts as deployer of the AI system and the Processor as provider, in each case within the meaning of the EU AI Act. The Services are supplied for guidance, knowledge access, onboarding, training and workflow support (the “Permitted Use”). The Customer shall not use the Services: (a) for recruitment, selection, promotion, termination or other decisions on the employment relationship; (b) to allocate tasks based on individual behaviour or personal traits; (c) to monitor or evaluate the performance or conduct of individuals; (d) for emotion recognition in the workplace; or (e) for any purpose prohibited under the EU AI Act or comparable law.
13.7 Where the Customer uses the Services outside the Permitted Use, substantially modifies them, places them on the market under its own name or trade mark, or integrates them into a high-risk AI system, the Customer assumes the obligations of a provider under the EU AI Act in respect of that use and shall indemnify the Processor in accordance with clause 3.7.
13.8 The Parties shall cooperate in good faith regarding their respective obligations under the EU AI Act and comparable AI legislation, including the provision by the Processor of technical documentation and transparency information reasonably required by the Customer as deployer.
Retention, return and deletion
14.1 The Processor shall process Customer Personal Data for the duration of the Agreement and any post-termination period set out in Annex II.
14.2 On termination or expiry, the Processor shall, at the Customer’s election notified within thirty (30) days, return Customer Personal Data in a commonly used machine-readable format or delete it. Absent an election, the Processor shall delete Customer Personal Data within ninety (90) days of termination.
14.3 The Processor may retain Customer Personal Data to the extent required by law. Copies in routine encrypted backups shall be deleted in accordance with the Processor’s backup rotation cycle, during which period such data shall be isolated and protected from further processing.
14.4 Clause 14 does not apply to aggregated, anonymised or deidentified data created under clause 13.3.
Liability
15.1 Each Party’s liability under this DPA is subject to the exclusions and limitations of liability set out in the Agreement. This DPA does not create any separate or additional liability cap.
15.2 The aggregate liability of the Processor and its affiliates under the Agreement and this DPA taken together shall not exceed the cap set out in the Agreement. Where the Agreement contains no limitation of liability, or where any such limitation is held unenforceable, the aggregate liability of the Processor and its affiliates under the Agreement and this DPA taken together shall not exceed the total fees paid by the Customer in the twelve (12) months preceding the event giving rise to the claim.
15.3 Nothing limits liability that cannot be limited by law, including an individual’s right to compensation under Article 82 GDPR.
15.4 Where one Party has paid compensation for damage caused by processing, it may claim back from the other Party the part corresponding to that Party’s responsibility, in accordance with Article 82(5) GDPR.
15.5 Each Party bears any administrative fine imposed on it by a Supervisory Authority or regulator in respect of its own acts or omissions. Neither Party is liable for fines imposed on the other Party except to the extent those fines result from that Party’s breach of this DPA.
15.6 Neither Party is liable for indirect or consequential loss, loss of profits, revenue, goodwill, anticipated savings, business interruption, or loss or corruption of data caused by the other Party, in each case as further set out in the Agreement.
15.7 No claim may be brought under this DPA more than twelve (12) months after the claiming Party became aware, or ought reasonably to have become aware, of the facts giving rise to the claim, save where a longer period is required by mandatory law.
15.8 The Processor’s total liability is reduced to the extent that loss is caused or contributed to by the Customer’s breach of clause 3, its submission of Customer Content, its configuration of the Services, its disabling of privacy-protective features, its use of the Services outside the Permitted Use, or its failure to review generated content under clause 13.5.
15.9 For the avoidance of doubt, the Processor shall have no liability of any kind in respect of Customer Content, including its content, accuracy, lawfulness, the manner of its collection, the absence of any required consent, notice, authorisation or approval, the Customer’s decisions as to who may access the Services or Customer Content, or any claim brought by an Authorised User, an employee of the Customer, or any other individual arising from Customer Content or from such access. Responsibility for all of the foregoing rests exclusively with the Customer.
Term, precedence and general provisions
16.1 This DPA takes effect on the date of the Agreement and continues for as long as the Processor processes Customer Personal Data.
16.2 Order of precedence in the event of conflict: (a) the EU SCCs, where incorporated; (b) Annex V jurisdiction-specific terms; (c) this DPA; (d) the Agreement.
16.3 Changes in law. Where a change in Data Protection Laws requires amendment of this DPA, the Parties shall negotiate in good faith. The Processor may amend this DPA on thirty (30) days’ notice where necessary to reflect a change in law, regulatory guidance or certification requirements, provided the amendment does not materially reduce protection for Customer Personal Data.
16.4 If any provision is held invalid or unenforceable, the remainder continues in force and the Parties shall replace the affected provision with a valid one of equivalent effect.
16.5 Survival. Clauses 3.2, 3.3, 3.4, 3.7, 3.8, 5.6, 13.3, 14, 15 and 16 survive termination or expiry of this DPA and the Agreement.
16.6 Third-party rights. Save as required by mandatory law, no person other than the Parties has any right to enforce this DPA. The Processor’s affiliates and Sub-processors may rely on the limitations and exclusions in clause 15.
16.7 Neither Party may assign this DPA without the other’s written consent, except that either Party may assign it to an affiliate or to a successor in connection with a merger, reorganisation or sale of substantially all of its assets.
16.8 This DPA constitutes the entire agreement between the Parties in relation to the processing of Customer Personal Data and supersedes any prior data protection terms, including any terms contained in the Customer’s purchase orders, vendor portals, supplier codes or standard terms, which shall have no effect.
16.9 This DPA is governed by the laws of the Netherlands and the courts of Midden-Nederland have exclusive jurisdiction, without prejudice to any individual’s rights under Article 79 GDPR or mandatory provisions of applicable law.
16.10 Publication and acceptance. The Processor may publish this DPA at tems.ai/legal/dpa. Where the Customer accepts the Agreement electronically, including by ticking an acceptance box or by executing an order form that incorporates the Agreement, the Customer thereby accepts this DPA, and that acceptance satisfies the requirement of Article 28(9) GDPR that the contract be in writing, including in electronic form. Where the Parties execute a separately negotiated data processing agreement, that agreement prevails over the published version.
Acceptance. By accepting the Agreement, by creating an account, or by using the Services, the Customer accepts this DPA. In accordance with Article 28(9) GDPR, that acceptance constitutes a contract in writing in electronic form and no signature is required. A countersigned copy is available on request to privacy@tems.ai for Customers whose internal procedures require one.
Annex I - The Parties
Customer (Controller / Business)
Field: Name and address
Detail: The entity identified in the order form, subscription or account registration for the Services
Field: Contact person
Detail: The account administrator or privacy contact designated by the Customer in its account
Field: Data protection officer
Detail: As notified by the Customer, where one is appointed
Field: Role
Detail: Controller / Business (or processor acting for a third-party controller)
Field: Notice address for clause 8.2
Detail: The email address held on the Customer’s account, and the subscription facility at tems.ai/legal/sub-processors
TemsAI (Processor / Service Provider)
Field: Name and address
Detail: TemsSoft B.V. (TemsAI), [REGISTERED ADDRESS], Netherlands · KvK [NUMBER] · VAT NL867296859B01
Field: Contact person
Detail: Data Protection Contact, TemsSoft B.V.
Field: Data protection contact
Detail: privacy@tems.ai
Field: Role
Detail: Processor / Service Provider
Field: Certifications
Detail: ISO/IEC 27001
Annex II - Description of the processing
Categories of individuals
• Employees of the Customer, including new hires, operators, technicians, and shift and frontline workers
• Line managers, supervisors, trainers and subject-matter experts
• HR, IT and administrative personnel using the administration layer of the Services
• Contractors, temporary workers and, where enabled by the Customer, personnel of the Customer’s suppliers
Categories of personal data
Category: Account and identity data
Examples: Name, work email address, employee or personnel number, preferred language
Category: Organisational data
Examples: Role, job title, department, site or plant, shift, team, line manager, seniority
Category: Authentication data
Examples: Single sign-on identifiers, session and device identifiers, IP address, access logs
Category: Onboarding and task data
Examples: Assigned journeys, task and checklist completion, dates, status, reminders
Category: Training and competency data
Examples: Training completion, assessment results, certifications and expiry, skill matrix entries
Category: Operational content
Examples: Work instructions, quality, safety and maintenance records, with timestamps and author identity
Category: Source Media
Examples: Photographs, video and audio submitted by the Customer for knowledge capture. In the default configuration no voice is stored, displayed or played back: audio is processed transiently for transcription only and delivered content consists of captions and text guidance. Optional plan features, activated at the Customer’s election, allow synthetic voice-over, retention and display of original audio, and automated face blurring. No biometric identifiers are created in any configuration - see clause 5
Category: Interaction data
Examples: Queries submitted to the AI assistant, feedback, usage and engagement statistics
Category: Location data (where enabled)
Examples: Site, plant or work-area identifiers and, where the Customer enables location features on mobile devices, approximate device location. Not collected where the feature is disabled by the Customer
Special categories
None.
Nature and purpose of the processing
• Providing, operating, maintaining and supporting the TemsAI platform and mobile applications
• Delivering role-based onboarding journeys, guidance, reminders and task coordination
• Enterprise search and AI-assisted answers over the Customer’s own knowledge sources
• Generating, translating and maintaining digital work instructions and training content
• Recording training, competency and workflow completion for the Customer’s operational and compliance purposes
• Reporting and analytics made available to the Customer within the Services
• Security monitoring, incident response, backup and business continuity
Hosting region, duration and frequency
Hosting region: European Economic Area, unless a different region is agreed in the order form
Duration: Term of the Agreement plus the period in clause 14
Post-termination retention: 90 days, unless a different period is agreed in the order form
Frequency: Continuous for the term of the Agreement
Annex III - Technical and organisational security measures
The Processor maintains an information security management system certified to ISO/IEC 27001. The following measures apply to the processing of Customer Personal Data.
Area: Access control
Measures: Role-based access control; single sign-on and federated identity via the Customer’s identity provider; multi-factor authentication for administrative access; least-privilege provisioning; quarterly access reviews; prompt revocation on role change or departure
Area: Encryption
Measures: TLS 1.2 or above in transit; encryption at rest for stored data and backups; key management via the cloud provider’s managed key service
Area: Segregation
Measures: Logical separation of customer tenants; separated production, staging and development environments; no production data in development or testing
Area: Data location
Measures: Hosting in the region specified in Annex II; hybrid and on-premise deployment available on request
Area: Logging and monitoring
Measures: Centralised audit logging of access and administrative actions; continuous security monitoring and alerting; defined log retention
Area: Vulnerability management
Measures: Automated dependency and infrastructure scanning; risk-based remediation timelines; annual third-party penetration testing; secure development lifecycle with peer code review
Area: Business continuity
Measures: Automated encrypted backups; documented restoration procedures with periodic restore testing; multi-zone infrastructure resilience
Area: Incident management
Measures: Documented incident response plan with defined roles and escalation; notification within 72 hours per clause 9; post-incident review
Area: Personnel
Measures: Confidentiality undertakings in all employment and contractor agreements; background screening where lawful; security and data protection training at onboarding and annually
Area: Supplier management
Measures: Security and data protection assessment of Sub-processors before engagement; contractual flow-down of equivalent obligations; periodic review
Area: Data minimisation
Measures: Collection limited to account identity, organisational role and activity necessary to deliver the Services; configurable retention; export and deletion functionality available to the Customer
Area: Media and biometric controls
Measures: Default configuration stores no voice: audio processed transiently for transcription only, delivered content limited to captions and text guidance. Optional features available by subscription plan and activated solely at the Customer’s election: synthetic voice-over, retention of original audio, automated face blurring. In every configuration: no biometric templates, faceprints or voiceprints created or stored; no facial or voice recognition performed
Area: AI controls
Measures: No use of Customer Personal Data to train generally available models; enterprise terms with model providers prohibiting training on inputs and outputs; answers grounded in Customer-supplied sources with attribution; human oversight retained
Annex IV - Authorised sub-processors
The Customer authorises the engagement of Sub-processors in the categories set out below. Each Sub-processor is engaged under the standard required by clause 8.2 and is bound by a written contract imposing data protection obligations substantially equivalent to those in this DPA.
Category: Cloud infrastructure
Purpose: Hosting, storage, backup and disaster recovery
Safeguards applied: Hosting in the region stated in Annex II; ISO 27001 or equivalent certification; encryption in transit and at rest
Category: Artificial intelligence model providers
Purpose: Model inference supporting the assistant, search, transcription, translation and content generation
Safeguards applied: Enterprise terms prohibiting use of Customer Personal Data for model training; zero or minimal retention configured where available
Category: Productivity and identity platforms
Purpose: Integration with the Customer’s Microsoft 365 environment and identity provider
Safeguards applied: Processing limited to what the integration requires; access governed by the Customer’s own tenant permissions
Category: Support and service management
Purpose: Customer support, ticketing and incident management
Safeguards applied: Access on a need-to-know basis; confidentiality obligations; audit logging
Category: Monitoring and observability
Purpose: Application performance monitoring, error reporting and security monitoring
Safeguards applied: Minimisation and, where feasible, pseudonymisation of data in telemetry
Category: Billing and payments
Purpose: Subscription management, checkout and invoicing for self-service plans
Safeguards applied: Payment card data is submitted directly to the payment provider and is never received or stored by the Processor
Named Sub-processors engaged
Sub-processor: Amazon Web Services EMEA SARL
Category: Cloud infrastructure
Purpose: Hosting, storage, database, search, backup and outbound transactional email for the Services
Processing location: European Union (Frankfurt)
Sub-processor: Amazon Web Services EMEA SARL
Category: Artificial intelligence model providers
Purpose: Model inference for the AI assistant, content generation, image understanding and AI-assisted editing
Processing location: European Union
Sub-processor: OpenAI Ireland Limited
Category: Artificial intelligence model providers
Purpose: Speech-to-text transcription of audio and video submitted by the Customer; search embeddings; fallback content generation
Processing location: United States
Sub-processor: Google Cloud EMEA Limited
Category: Artificial intelligence model providers
Purpose: Machine translation of Customer PDF-content into the Customer’s configured languages
Processing location: European Union and United States
Sub-processor: Functional Software, Inc. (trading as Sentry)
Category: Monitoring and observability
Purpose: Application error and crash reporting
Processing location: European Union
Sub-processor: PostHog, Inc.
Category: Monitoring and observability
Purpose: Product usage analytics
Processing location: European Union
Sub-processor: Stripe Payments Europe, Limited
Category: Billing and payments
Purpose: Subscription management and payment processing for self-service plans
Processing location: European Union, with onward transfer to the United States
No Sub-processor is currently engaged in the “Productivity and identity platforms” or “Support and service management” categories. Customer support is provided by the Processor’s own personnel using the infrastructure listed above.
Components of the Services that the Processor operates itself within its own infrastructure — including the identity and single sign-on service, the retrieval and search stack, the workflow engine and the embedded manufacturing module - are not Sub-processors, as no Customer Personal Data is disclosed to a third party by their use.
Transfers outside the EEA. Where a Sub-processor processes Customer Personal Data outside the EEA, the transfer is made under the EU SCCs incorporated by clause 11.2 and Annex V, or under an adequacy decision or approved certification where one applies. For providers of artificial intelligence models, the contract additionally prohibits the use of Customer Personal Data, whether as input or output, for the training of any model.
Website analytics. Analytics and cookie technologies used on the Processor’s public marketing website operate on that website only. They are not part of the Services, do not operate within the Customer’s environment, and process no Customer Personal Data. They are therefore not Sub-processors for the purposes of this DPA.
A current list identifying each Sub-processor by name, purpose and location is maintained at tems.ai/legal/sub-processors and is updated in accordance with clause 8.3. That published list forms part of this Annex IV and prevails over the table above where the two differ.
Annex V - Jurisdiction-specific terms
A. European Union
Where a Restricted Transfer of Customer Personal Data subject to the GDPR occurs, the EU SCCs apply, completed as follows: Module Two where the Customer is a controller, Module Three where the Customer is a processor; Clause 7 (docking) applies; Clause 9 Option 2 (general written authorisation) applies with a thirty (30) day notice period; Clause 11 optional redress clause does not apply; Clause 17 governing law is the law of the Netherlands; Clause 18(b) forum is the courts of the Netherlands. Annex I of the SCCs is populated by Annexes I and II of this DPA; Annex II of the SCCs is populated by Annex III of this DPA; Annex III of the SCCs is populated by Annex IV of this DPA.
B. United Kingdom
For transfers subject to the UK GDPR, the EU SCCs apply as modified by the UK International Data Transfer Addendum issued under section 119A of the Data Protection Act 2018. References to the GDPR are read as references to the UK GDPR, the Supervisory Authority is the Information Commissioner’s Office, and the governing law and forum are those of England and Wales.
C. Switzerland
For transfers subject to the Swiss FADP, the EU SCCs apply with the following adaptations: the competent authority is the Federal Data Protection and Information Commissioner; references to the GDPR are read as references to the FADP; the term “Member State” does not exclude data subjects in Switzerland from enforcing their rights in their place of habitual residence; and the SCCs also protect data of legal entities until the FADP no longer affords such protection.
D. United States
Clause 12 applies. Where the Customer is subject to state privacy laws requiring specified contractual terms, the Parties agree that clauses 4, 8, 9, 10, 12 and 14 of this DPA satisfy those requirements, including purpose limitation, confidentiality, security, sub-processor flow-down, assistance with consumer rights, deletion or return on termination, and the Customer’s right to take reasonable steps to remediate unauthorised use.
TemsSoft B.V. · Data Processing Agreement · Published version 2.0 linked to the TemsAI Privacy Policy and TemsAI Terms & Conditions.
