Legal

Data Processing Addendum

Effective July 5, 2026

In plain terms

When a broker organization uses Tenon, they decide what deal data goes in and we process it for them. This addendum sets out how — the roles, the security commitments, and the specific providers we rely on (our “subprocessors”), including our AI provider.

The headline commitments: we process customer data only to run the Service, we keep it confidential and secured, and deal documents are not used to train shared AI models.

01Roles and scope

This Data Processing Addendum (“DPA”) forms part of the agreement between the customer organization (“Customer,” the controller) and [LEGAL ENTITY NAME] (“Tenon,” the processor) for the Service. It governs Tenon’s processing of personal data contained in Customer’s deal content and account data (“Customer Data”) on Customer’s behalf.

Customer determines the purposes and means of processing Customer Data; Tenon processes it only per this DPA and Customer’s documented instructions (which include operating the Service as configured). Where a buyer is an independent party, this DPA does not alter the parties’ own relationships — it governs Tenon’s handling of the data.

02Processing details

Subject matter and duration: processing for the term of the agreement and any wind-down period. Nature and purpose: hosting, organizing, and displaying deal rooms; generating summaries, an index, and grounded answers; producing engagement signals for the broker; and delivering notifications. Data subjects:Customer’s personnel and the buyers they invite. Data categories: business contact and identity data (name, email, organization, role), deal documents and details, questions and messages, and room engagement/usage data. See Appendix A.

03Tenon's obligations

  • process Customer Data only per this DPA and Customer’s instructions, unless law requires otherwise (and then we’ll tell you unless prohibited);
  • ensure personnel with access are bound by confidentiality;
  • implement the technical and organizational security measures in Appendix C;
  • assist Customer, taking into account the nature of processing, with data-subject requests and with security, breach-notification, and impact-assessment obligations;
  • on termination, delete or return Customer Data as described in Section 8;
  • make available information reasonably necessary to demonstrate compliance. [REVIEW audit rights and mechanics].

04Subprocessors

Customer authorizes Tenon to engage the subprocessors below to provide the Service. Each is bound by data-protection terms no less protective than this DPA for the relevant processing. We’ll give notice of a new or replacement subprocessor and a chance to object on reasonable grounds. [CONFIRM the objection/notice mechanism and each provider’s current DPA terms and processing locations].

SubprocessorPurposeData
AnthropicAI processing — summaries, document classification, and grounded answersDocument text and questions sent for a given task
SupabaseDatabase, file storage, and authenticationAccount data, deal content, and engagement data
VercelApplication hosting and deliveryRequest data and content in transit
ResendTransactional and notification email deliveryRecipient email address and message content

[KEEP THIS TABLE ACCURATE as the stack changes; confirm each entity’s legal name and sub-processing locations].

05AI processing and the training commitment

Our AI subprocessor (Anthropic) processes the document text and questions we send it to return a result. We configure our use of that provider so that Customer Data sent for AI processing is not used to train the provider’s general or shared models, and we do not use Customer’s deal documents to train any model of our own. Summaries and the index are generated once and stored; the live AI surface is the smart-ask bar. [VERIFY against the AI provider’s current commercial terms (zero data retention / no-training) and update if they change].

06International transfers

Where processing involves a cross-border transfer that requires a safeguard, the parties will rely on an appropriate transfer mechanism. [REVIEW and attach the transfer mechanism (e.g. Standard Contractual Clauses / UK addendum) and identify processing regions].

07Security incidents

Tenon will notify Customer without undue delay after becoming aware of a personal-data breach affecting Customer Data, and will provide information reasonably available to help Customer meet its notification obligations. [SET a notification timeframe and contact process].

08Return and deletion

On termination, and at Customer’s choice, Tenon will delete or return Customer Data within a reasonable period, except where retention is required by law, and will then delete remaining copies, subject to routine backup cycles. [SET the deletion window and backup-expiry period].

09Liability and precedence

This DPA is subject to the liability terms of the agreement between the parties. If there is a conflict between this DPA and the agreement regarding processing of Customer Data, this DPA controls. [REVIEW interaction with the master agreement’s liability cap and any data-specific carve-outs].

10Contact

Data-protection questions or requests: privacy@tenoncre.com [CONFIRM DPA contact, signing entity, and whether a countersigned version is offered to customers].

AAppendix A — Processing details

Data subjects, categories, nature, purpose, and duration are described in Sections 1–2 above and incorporated here. [EXPAND into a formal schedule if a customer or regulation requires it].

BAppendix B — Subprocessors

The current subprocessor list is the table in Section 4.

CAppendix C — Security measures

  • Row-level access controls enforced at the database, segregating data across visibility tiers so broker-private data is not reachable from buyer or anonymous sessions;
  • Email-based (magic-link) authentication and scoped, tokenized room access;
  • Encryption of data in transit (TLS) and at rest through our infrastructure providers;
  • Least-privilege access to production systems and secrets held in managed environment configuration;
  • Rate limiting and bot protection on public entry points; per-identity and per-room usage caps;
  • Automated test coverage asserting the access-control boundaries before changes ship.

[REVIEW and formalize; add backup, logging/monitoring, vulnerability-management, and incident-response specifics as the program matures].