Data Processing Addendum
Last updated 23 September 2026
This addendum forms part of the Terms of Service between [Company legal name] ("Processor") and the Customer ("Controller"). It applies when Tenet processes personal data contained in Customer content. If you need a signed copy, email [email protected].
1. Scope
- Subject matter and purpose: providing Tenet — extracting, validating, matching and routing supplier invoices and related documents, and posting approved bills to accounting systems the Customer connects.
- Duration: the term of the subscription plus the deletion periods below.
- Data subjects: Customer's users; employees and contacts of the Customer's suppliers named in documents.
- Personal data: names, business contact details, bank or payment details appearing on invoices, and other data in uploaded documents.
- Special category data: not intended. The Customer should not upload it.
2. Processor obligations
- Process personal data only on the Customer's documented instructions, including these terms and the Customer's use of the product.
- Ensure personnel with access are bound by confidentiality.
- Implement the technical and organisational measures in section 6.
- Assist the Customer, taking into account the nature of processing, with data subject requests, security, breach notification and data protection impact assessments.
- Notify the Customer without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting Customer data.
- Make available information necessary to demonstrate compliance and allow for audits, by way of our security documentation or, at the Customer's cost and on reasonable notice, an independent audit.
3. Subprocessors
The Customer authorises the subprocessors listed at /legal/subprocessors. We give at least 30 days' notice of new subprocessors; the Customer may object on reasonable data protection grounds, and if we cannot resolve the objection the Customer may terminate the affected service and receive a pro-rata refund of prepaid fees.
4. International transfers
Customer data is hosted in the United States. Transfers of personal data from the EEA, UK or Switzerland to countries without an adequacy decision are governed by the EU Standard Contractual Clauses (Module 2, and Module 3 for onward transfers), with the UK International Data Transfer Addendum and Swiss amendments as applicable, which are incorporated by reference. Transfers from Australia and New Zealand are made in accordance with APP 8 and IPP 12 respectively.
5. Deletion and return
The Customer can export its data while subscribed and for 30 days after termination. We then delete Customer data within 30 days, and from backups within a further 35 days, unless retention is required by law.
6. Security measures
- Encryption in transit (TLS 1.2+) and at rest; OAuth tokens encrypted with AES-256-GCM using keys held outside the database.
- Logical tenant isolation enforced at the data-access layer on every query.
- Role-based access within workspaces; immediate revocation when a user is removed or their password is reset.
- Passwords stored as salted bcrypt hashes; rate limiting on sign-in and password reset.
- Audit trail of approvals, corrections and administrative actions.
- Automated daily database backups with point-in-time recovery; restores tested periodically.
- Error monitoring configured to exclude document contents and credentials.
7. US state privacy laws
Where the CCPA/CPRA or similar laws apply, we act as a service provider: we will not sell or share personal data, retain, use or disclose it outside the direct business relationship, or combine it with other data except as those laws permit.