DPA
Language notice: The German version of this document is legally binding and controlling. The English version is provided for information purposes only. In the event of any discrepancy or conflict, the German version shall prevail.
This Data Processing Agreement (“DPA”) is entered into between
Sebastian Spohr Media, Haydnstraße 17a, 93053 Regensburg, Germany
– hereinafter “Tasia” or “Processor” –
and
the respective customer using Tasia on the basis of a registration, order, quotation or other agreement
– hereinafter “Customer”, “Client” or, where applicable, “Controller” –
jointly the “Parties”.
This DPA supplements the agreement governing the use of Tasia, including the Terms of Use, order, service description and individual agreements (“Main Agreement”). It applies insofar as Tasia processes personal data on behalf of the Customer within the meaning of Article 28 GDPR.
Where the Customer itself acts as a processor for a third party, Tasia shall be considered a further processor in the relevant processing chain. The Customer shall ensure that it is authorized to engage Tasia in this capacity and may issue the necessary instructions.
1. Subject Matter, Duration and Roles
Tasia provides a SaaS offering for the structured collection of customer requests and the extensive preparation of quotations. The Service may include, in particular, request forms, price and service rules, document imports, team, delivery, export, interface and AI functions.
This DPA covers personal data that the Customer, its users, prospects, end customers or systems designated by the Customer enter, upload, import, generate, transmit, edit or have processed in Tasia (“Customer Data”).
The subject matter, nature, purpose and duration of the processing, the categories of data and the data subjects are set out in Appendix 1.
The Customer decides on the purposes, legal bases, content, recipients, approvals and deletion periods for its Customer Data. Where forms are embedded or provided through a Tasia address, quotations are sent, data is exported or transferred to third-party systems, this takes place at the Customer’s request and under the Customer’s responsibility.
This DPA does not cover processing for which Tasia itself determines the purposes and essential means. This includes in particular contract administration, billing, payment processing, accounting, Tasia’s own business communications, newsletters, analysis of Tasia’s own website, security and abuse prevention under Tasia’s own responsibility, statutory retention and the establishment, exercise or defense of legal claims.
Insofar as the same technical data is also processed to provide the Service on behalf of the Customer, this DPA applies to that processing purpose.
Processing on behalf of the Customer begins with the first processing of Customer Data and continues until its return or deletion after termination of the Main Agreement, including the stipulated retrieval, backup and run-off periods.
2. Customer Responsibility and Instructions
The Customer is responsible for the lawfulness of the Customer Data and its processing. In particular, the Customer shall ensure that:
- the required legal bases, consents and agreements are in place;
- data subjects are properly informed;
- only necessary and appropriate data is collected;
- deletion periods and access restrictions are established;
- Tasia is used only for permissible business purposes;
- its request forms, quotations and end-customer processes are designed lawfully.
The Customer remains the Controller, in particular, for the collection and use of information relating to its prospects or end customers. It shall make its privacy information appropriately available at the embedded or hosted form and identify itself there as the Controller, insofar as applicable.
The Customer may have special categories of personal data under Article 9 GDPR, data relating to criminal convictions and offenses under Article 10 GDPR or other particularly sensitive or regulated data processed only if Tasia has expressly approved the specific use case in text form, the processing is lawful and necessary, and the Parties have agreed any required additional technical and organizational measures.
Without an express agreement, Tasia is not intended for data whose loss, disclosure or incorrect processing can typically create immediate risks to life, physical integrity, critical infrastructure or comparable high-risk consequences.
Instructions arise from the Main Agreement, this DPA, the settings and functions selected by the Customer, actions by authorized users and documented support or administration requests. Additional instructions may be issued in text form.
The Customer shall designate authorized contacts and securely manage accounts, roles, permissions, API keys, approval links and its own integrations. Tasia may treat instructions issued through the customer account, administrators or registered contact addresses as authorized unless there are reasonable grounds for doubt.
If Tasia considers an instruction to violate data protection law, Tasia shall inform the Customer without undue delay. Tasia may suspend execution until the instruction is confirmed or amended or its lawfulness has been clarified. Tasia is not required to conduct a comprehensive legal review of instructions.
Instructions outside the agreed scope of services, or instructions that cannot technically be implemented without disproportionate effort, impair security or stability, or affect the rights of other customers or third parties, require separate coordination. Tasia may charge reasonable remuneration for this where the effort was not caused by a circumstance attributable to Tasia and the Customer is informed in advance.
3. Obligations of Tasia
Tasia shall process Customer Data exclusively on documented instructions from the Customer unless required to do so by the law of the European Union or a Member State. In that case, Tasia shall inform the Customer of that legal requirement before processing, unless the law concerned prohibits such information on important grounds of public interest.
Tasia shall ensure that persons authorized to access Customer Data have committed themselves to confidentiality or are subject to an appropriate statutory duty of confidentiality.
Access shall be restricted to persons who require it for operation, maintenance, security, support, error analysis or implementation of documented instructions.
Tasia does not sell or rent Customer Data and does not use it for its own advertising.
Without a separate express agreement, Tasia shall not use personal Customer Data, form entries, prompts or quotation content, either itself or through AI service providers it engages, for cross-customer training, fine-tuning or general improvement of its own or third-party foundation AI models.
The use of approved quotations, price and service rules and manual corrections to improve future results for the same Customer forms part of the commissioned processing, insofar as the corresponding function is enabled or used in the customer account.
Tasia may use non-personal, anonymized or sufficiently aggregated information for error analysis, security, capacity planning, statistical evaluation and product improvement where re-identification of individual persons or customers is excluded. Such information is not personal Customer Data within the meaning of this DPA.
Tasia shall implement appropriate technical and organizational measures pursuant to Article 32 GDPR. The measures envisaged as of the date of this DPA are described in Appendix 2. They may be adjusted in line with technological developments and the risk situation, provided that the overall level of protection is not materially reduced.
Tasia shall assist the Customer to the extent required by law and possible in view of the nature of the processing with:
- requests and rights of data subjects;
- security of processing;
- notification and documentation of personal data breaches;
- data protection impact assessments;
- prior consultations with supervisory authorities;
- evidence provided to competent supervisory authorities.
If Tasia receives a request from a data subject that clearly concerns Customer Data, Tasia shall generally forward it to the Customer and shall not respond independently unless Tasia is legally required to do so. The Customer remains responsible for the substantive review and timely response.
Assistance extending beyond the usual product and support functions and Tasia’s mandatory obligations may be charged at a reasonable rate following prior notice. This shall not apply insofar as the effort results from a breach of duty by Tasia.
4. Security of Processing
In its measures, Tasia shall take into account the state of the art, implementation costs, the nature, scope, context and purposes of processing, and the likelihood and severity of potential risks to data subjects.
The measures described in Appendix 2 include, in particular, access and authorization controls, logical tenant separation, encrypted transmission, secure management of secrets, security logging, backups, recovery procedures, vulnerability management and procedures for security incidents.
The Customer acknowledges that security is a shared responsibility. In particular, it must:
- use available access protection functions;
- regularly review roles and permissions;
- secure end devices and its own integrations;
- protect approval links, API keys and access credentials;
- collect and provide only necessary data;
- report security incidents without undue delay.
Tasia may modify security measures at short notice where necessary to remedy vulnerabilities, defend against attacks, maintain availability or comply with legal requirements.
Where possible, planned material changes that are expected to adversely affect the agreed level of protection shall be communicated to the Customer with reasonable advance notice. Changes that do not materially reduce the overall level of protection do not require separate prior notice. Where urgent security, legal or data protection grounds exist, Tasia may implement changes at short notice and shall inform the Customer, where required, without undue delay.
Without a separate agreement, Tasia does not guarantee compliance with every customer-specific regulatory, industry-related or internal security requirement. Before using the Service for particularly sensitive processing, the Customer must assess whether the measures described are sufficient for its risk.
5. Subprocessors
The Customer grants Tasia general prior authorization to engage subprocessors. The subprocessors engaged as of the date of this DPA are listed in Appendix 3.
Tasia shall contractually impose on subprocessors data protection obligations that are substantially equivalent to the applicable obligations under this DPA. Tasia remains responsible to the Customer for the performance of a subprocessor’s obligations under Article 28(4) GDPR.
Tasia shall actively inform the Customer of any intended addition or replacement of a subprocessor with reasonable advance notice, generally 14 calendar days before its engagement, in particular by email to the registered administrative contact address or through a prominent account notification.
A permanently accessible list of subprocessors may supplement the active notice and document changes, but does not replace it.
Where an urgent security, availability or legal reason requires engagement on shorter notice, Tasia shall inform the Customer in advance where possible, otherwise without undue delay. The Customer retains its right to object. Tasia shall limit any short-notice engagement to what is necessary.
The Customer may object within the notified period on specific, substantiated data protection grounds. The Parties shall endeavor to find a reasonable solution. If continuation without the provider concerned is impossible or would involve disproportionate effort, either Party may terminate the affected service for cause. Claims relating to services already duly provided remain unaffected.
Tasia shall keep current information on the name, address, contact point, role, processing location and relevant further processing chains for all subprocessors involved in processing Customer Data. Tasia shall provide supplementary information to the Customer via privacy@tasia.io without undue delay.
No subprocessing relationship within the meaning of this DPA exists insofar as:
- a service provider exclusively supports processing for which Tasia itself is the Controller, for example Tasia’s own payment processing, accounting or newsletter;
- the Customer itself selects a recipient, third-party system or service provider and merely instructs Tasia to transfer data to it.
A different allocation of roles under applicable data protection law remains possible.
6. Third-Country Transfers and Government Access
Tasia generally processes Customer Data within the European Union or the European Economic Area and uses the EU/EEA configurations described in Appendix 3 unless otherwise stated there.
A transfer to a third country or an international organization shall take place only on documented instructions from the Customer or in compliance with Articles 44 et seq. GDPR.
Appropriate mechanisms may include, in particular, an adequacy decision, binding corporate rules or the European Commission’s Standard Contractual Clauses together with any required supplementary measures.
Mere remote access from a third country shall be treated as a third-country transfer insofar as it is classified as such under data protection law.
Disclosures required by law shall be limited to what is necessary. Tasia shall inform the Customer before disclosure where legally permissible, review the lawfulness of a request and challenge disproportionate or unlawful requests to a reasonable extent.
If the intended processing location of a subprocessor changes materially, the notification and objection rules under Section 5 apply.
7. Personal Data Breaches
Tasia shall inform the Customer without undue delay after becoming aware of a personal data breach insofar as Customer Data is affected.
To the extent available at that time, the notification shall include:
- the nature and scope of the incident;
- the categories of data and persons affected;
- the likely consequences;
- remedial measures taken or proposed;
- a contact for follow-up questions.
Missing information shall be provided in stages without undue delay.
Tasia shall take reasonable measures to contain, investigate and remedy the incident and document it to the extent required by law. The notification does not constitute an admission of a breach of duty or liability.
The Customer shall decide on notifications to supervisory authorities and data subjects insofar as it is the Controller. Tasia shall assist the Customer to the extent required by law and available.
8. Evidence, Data Subject Rights and Audits
Tasia shall make available to the Customer the information necessary to demonstrate compliance with the obligations under Article 28 GDPR.
For this purpose, Tasia may use, in particular, descriptions of technical and organizational measures, questionnaires, self-declarations, audit reports, certificates or comparable documents.
The Customer may conduct reasonable audits itself or have them conducted by an independent auditor bound to confidentiality. Audits shall generally begin with a review of documents and a remote audit.
On-site audits are permissible where a document review is insufficient and there is a legitimate reason.
Audits shall generally be announced at least 30 days in advance, conducted during customary business hours and limited to the necessary scope. They may not unreasonably interfere with operations, security, trade secrets or the rights of other customers.
In the absence of a specific reason, the right to conduct an audit exists no more than once per calendar year.
The Customer shall bear its own costs for auditors it engages. Tasia shall bear the reasonable expense required to fulfill its statutory obligations to provide evidence and cooperate. Only additional effort outside a legally required reasonable audit that has been announced in advance and requested by the Customer may be separately agreed and charged, in particular for special formats, repeated audits without a new reason or customer-specific advice. No fee shall be charged where the audit is prompted by a breach attributable to Tasia, a security incident or reasonable suspicion. Audits prompted by a specific reason may take place on shorter notice.
Statutory audit and access rights of competent supervisory authorities remain unaffected.
During the term of the contract, Tasia shall provide the Customer with the available functions for rectification, restriction, deletion and export of Customer Data and shall assist it with data subject requests in accordance with Section 3.
9. Return and Deletion
During the term of the contract, the Customer may rectify, delete or export Customer Data using the functions provided. The form and scope of an export are governed by the Service, the Main Agreement and mandatory law.
After termination of the Main Agreement, Tasia shall, at the Customer’s choice, return or delete Customer Data and delete existing copies, unless the law of the European Union or a Member State requires further storage.
Tasia may provide electronic return through existing export, download, interface or support channels. A customer-specific migration or transfer to a particular third-party system is owed only if agreed or mandatorily required by law.
Unless otherwise agreed, required by law or instructed by the Customer in due time, Tasia shall generally maintain an existing retrieval or export option for 30 days after the end of the contract or after the end of an applicable Data Act transition period.
Thereafter, Customer Data shall be deleted or anonymized in active systems without undue delay, no later than within a further 30 days.
The Parties agree that the later point of complete deletion, including technically separate backup copies that are not routinely accessible, shall be the end of the regular backup cycle, no later than 90 days after deletion from active systems.
Until then, the data in backup copies shall not be used for other purposes and shall be processed only where required for recovery. Following a restoration, deletions that have already taken effect shall be implemented again.
Tasia, as Processor, may retain substantive Customer Data only where a specific statutory retention obligation or a binding authority or court preservation order requires this. Tasia shall inform the Customer where legally permissible, restrict the data and access to what is necessary, and delete the data once the obligation ceases to apply. Independent contract, billing and evidence data lawfully processed by Tasia as Controller does not fall under this DPA and does not automatically include the substantive Customer Data from the customer process.
Tasia cannot ensure deletion from systems it does not control, in particular after the Customer has exported, sent or transferred data through an integration or disclosed it to third parties.
Upon request, Tasia shall confirm to the Customer in text form completion of the return or complete deletion owed under this Section. As long as only the regular backup cycle remains outstanding, Tasia may instead state the intended date of complete deletion.
10. AI Functions and Customer-Specific Optimization
Where an AI function is used, Tasia processes the Customer Data selected or technically required for execution of the respective request. This may include in particular:
- prompts and instructions;
- form entries and requirements;
- price, service, quantity and dependency data;
- existing quotations, emails, files and attachments;
- quotation drafts, line items and generated outputs;
- manual changes, approvals and corrections;
- technical usage and billing metadata.
The purposes include, in particular, extraction, structuring, classification, identification of missing information, suggestion of follow-up questions, assignment to price and service rules, wording and preparation of quotation drafts, and customer-specific improvement of future results.
Tasia currently uses TensorX Limited (formerly Tensorix) for this purpose as the AI subprocessor named in Appendix 3.
Tasia uses the contractually agreed EU/EEA configuration for Customer Data. Under this configuration:
- request and output content is processed by TensorX only temporarily for inference;
- this content is not stored or logged there on a permanent basis;
- it is not disclosed to model developers or other model providers;
- it is not used to train, fine-tune or generally improve AI models.
Technical usage, security and billing metadata may be stored to the extent necessary. This may include timestamps, model identifiers, token quantities, status, error and cost information. As of the date of this DPA, TensorX documents retention of usage metadata, API logs and security logs for up to twelve months. Request and output content is not included and, under the intended configuration, is not stored or logged on a permanent basis.
Tasia may store form entries, documents, rules and results adopted or saved by the Customer in its own system in accordance with the Main Agreement and the Customer’s instructions. Temporary processing at TensorX does not alter this storage in Tasia.
The use of approved quotations, customer-specific rules and manual corrections to improve future results for the same Customer forms part of the commissioned service. Personal Customer Data is not used across customers.
Tasia may change models and AI subprocessors, provided that the requirements of this DPA are complied with. Changes to subprocessors or the relevant processing chain are governed by Section 5.
The Customer decides which data is transmitted to AI functions and is responsible for the lawfulness of such transmission. Special categories of personal data, data under Article 10 GDPR, professional secrets or comparably highly sensitive content may be processed only following express approval and an additional agreement pursuant to Section 2.3.
AI outputs may be incomplete or incorrect. The Customer must appropriately review them before use where legal, financial, security-related or other significant effects may result. This quality provision does not alter Tasia’s data protection obligations as Processor.
11. Forms, Delivery and Integrations
Where the Customer provides a request form through a Tasia address or embedded in its website, Tasia processes the form data on the Customer’s instructions. The Customer decides on questions, required fields, recipients, visibility, legal basis and deletion.
Tasia may provide technically necessary security, transparency and abuse-prevention notices. The Customer remains responsible for its own provider and privacy information and any required consents.
Where the Customer instructs Tasia to send a quotation, notification or other Customer Data to a prospect, end customer or other recipient, Tasia processes the required recipient, content, delivery and delivery-status data to carry out that instruction.
Where the Customer connects Tasia to a CRM, ERP, accounting, industry-specific or other third-party system, Tasia processes the data and technical permissions authorized by the Customer to establish and operate the connection.
A recipient or third-party provider selected by the Customer itself does not become a subprocessor of Tasia for that reason alone. The Customer is responsible for its contractual and data protection relationship with that recipient or third-party provider.
Tasia processes access credentials, tokens or API keys only to the extent necessary and protects them in accordance with the measures described in Appendix 2. The Customer must limit permissions to what is necessary and revoke connections that are no longer required.
12. Liability, Term and Final Provisions
The liability of the Parties is governed by the Main Agreement and mandatory law. Article 82 GDPR and other mandatory data protection liability remain unaffected.
This DPA enters into force when incorporated into the Main Agreement or electronically accepted and applies for the duration of processing on behalf of the Customer.
Confidentiality, return, deletion, evidence and liability provisions shall continue to apply insofar as their purpose so requires.
Tasia may make purely editorial corrections and adjustments required by mandatory law, regulatory requirements or technical security requirements by giving notice in text form, provided that this does not materially change the subject matter, scope or level of protection of the processing to the Customer’s detriment.
Non-urgent material changes shall be notified with reasonable advance notice, generally 30 calendar days before they take effect, in text form or through a contractually provided electronic mechanism. A shorter period is permissible where required by mandatory statutory, regulatory, security or data protection grounds.
Changes that materially expand or reduce the subject matter, duration, nature or purpose of the processing, the types of personal data, categories of data subjects or the level of protection, and that are not already covered by the Main Agreement, require an express agreement. Changes to technical and organizational measures and subprocessors are additionally governed by the provisions applicable to them. If a mandatorily required change is unreasonable for the Customer on specific data protection grounds and no reasonable solution can be found, the Customer may terminate the affected service for cause as of the date of the change.
In the event of a conflict between this DPA and the Main Agreement, this DPA shall prevail with respect to processing on behalf of the Customer. Mandatory data protection law takes precedence.
Amendments and additions may be agreed in text form and electronically. If any provision is invalid or unenforceable, the validity of the remaining provisions remains unaffected.
German law applies, excluding conflict-of-laws rules, insofar as this is not precluded by mandatory data protection provisions. To the extent legally permissible, the place of jurisdiction is Regensburg.
Appendix 1 – Description of Processing
| Item | Description |
|---|---|
| Subject matter | Technical provision, storage, structuring, editing, analysis, display, transmission, backup, restoration, export and deletion of Customer Data in connection with the preparation of requests and quotations using Tasia. |
| Duration | Term of the Main Agreement plus the return, retrieval, deletion and backup periods stipulated in this DPA. |
| Nature of processing | Collection, recording, storage, organization, arrangement, structuring, extraction, classification, adaptation, retrieval, consultation, use, display, calculation, comparison, generation, disclosure by transmission or provision, restriction, export, deletion and destruction. |
| Purposes | Provision and protection of Tasia; creation and provision of embedded or hosted request forms; structured collection of information and requirements; import and analysis of existing quotations, price lists, service data, emails, files and manual information; configuration of price, service, quantity and dependency rules; AI-assisted extraction, structuring, follow-up questions, assignment and wording; preparation, editing, review and approval of quotation drafts; delivery, export and transfer to connected systems; customer-specific improvement of future results based on approved quotations and corrections; customer-side organization, team, role and permission configuration, insofar as processed as Customer Data on instructions; transactional messages on the Customer’s instructions; support, maintenance, error analysis, backups, restoration and deletion. |
| Data categories | Master and contact data; company, organization and contact-person data; customer-side user, team, role and permission assignments and technical access data, insofar as the Customer determines the purposes and essential means for the relevant processing purpose; address, property, project, requirement, service, quantity, scheduling and specification data; price, calculation, discount, tax, quotation, line-item and contract data; form responses, free text, emails, images, files, attachments and notes; prompts, instructions, AI outputs, corrections and approvals; delivery, access, export, integration, version and status data; technical usage, access, API, log, device, browser, error and security data; support and communications data insofar as they contain Customer Data. |
| Data subjects | Employees, freelancers, members of governing bodies and users of the Customer; prospects, leads, customers and end customers of the Customer; contacts at customers, suppliers, partners and service providers; persons at service, project or property locations; recipients of quotations and messages; other persons whose data the Customer processes in Tasia. |
| Special categories of data | Not routinely required and not permissible without express approval in text form. Processing takes place only where it is lawful and necessary and Tasia has expressly agreed the specific use case and additional safeguards. |
| Frequency | Ongoing or whenever the respective functions are used. |
Independent registration, contract, billing, authentication and tenant-independent security data does not fall under this Appendix insofar as Tasia itself determines the purposes and essential means. Insofar as the same technical or organizational data is also required for a separate processing purpose determined by the Customer, this DPA applies to that purpose.
Appendix 2 – Technical and Organizational Measures
The following measures describe the level of protection envisaged as of the date of this DPA. Individual technical implementations may change, provided that the overall level of protection is not materially reduced.
| Area | Measures |
|---|---|
| Physical security | The core production systems are operated on Scaleway infrastructure within the European Union. Physical protection of the data centers is the responsibility of the respective hosting providers. Tasia does not operate its own publicly accessible server rooms. |
| Access to systems | Individual administrative accounts; secure authentication; multi-factor authentication for privileged administrative access or equivalent risk-appropriate safeguards; restrictive allocation of administrative rights; use of secure keys or comparable access mechanisms; protection of administrative end devices through user accounts, screen locks, disk encryption and up-to-date operating systems. |
| Access and authorization control | Role- and permission-based access; least-privilege principle; access to Customer Data only for operation, support, maintenance, security or documented instructions; withdrawal of permissions that are no longer required; regular risk-based review of privileged permissions. |
| Tenant and segregation control | Logical separation of customer accounts and tenants at application level; permission checks when data is accessed; separate development and production environments; no routine use of production Customer Data for general development or testing purposes. |
| Transmission, storage and network security | Encrypted transmission using TLS for supported connections; protection of production data at rest and backup copies through encryption provided by the infrastructure provider or at application level, where technically available and appropriate to the risk; private or restricted database connections; network and firewall rules as required; separate management of access credentials, keys and secrets. |
| Passwords and secrets | Passwords are not stored in plain text but protected using appropriate hashing procedures. API keys, tokens, SMTP credentials and other secrets are managed with restricted access and are not unnecessarily stored in source code or logs. |
| Form and application security | Permission and tenant checks for access to forms, requests and quotations; protection against common web application risks; technical measures against abusive or excessive use according to the risk situation; secure handling of file and text input. |
| Logging and traceability | Technical and security-relevant events are logged to the extent necessary. Logs are access-restricted and used for operation, error analysis, abuse prevention and security investigations. |
| Availability and backup | Automated backups or snapshots of production databases and required application data; regulated retention and overwriting; procedures for restoration in the event of disruption; regular risk-based testing of recoverability; deletion from backups no later than within the 90-day period stipulated in this DPA after deletion from active systems. |
| Secure development and changes | Version-controlled changes; controlled deployment; technical testing and automated checks where appropriate; separation of development and production systems; consideration of common web and application security risks. |
| Updates and vulnerabilities | Risk-based deployment of security-relevant updates; assessment of known vulnerabilities; appropriate technical or organizational countermeasures. |
| Review of effectiveness | Risk-based and appropriately regular review of the technical and organizational measures, in particular permission reviews, restoration tests, assessment of known vulnerabilities and evaluation of security and data protection incidents. Identified deficiencies are remedied with priority according to their risk. |
| Confidentiality and organization | Confidentiality commitments for authorized persons; documented responsibilities; restricted support access; data protection and security awareness appropriate to the person’s duties. |
| Incidents | Procedures for detecting, assessing, containing, documenting and communicating security and data protection incidents; follow-up and implementation of appropriate improvement measures. |
| Deletion | Deletion or anonymization in active systems following Customer instructions, use of a product function or termination of the contract; overwriting in backups according to the regular backup cycle; consideration of statutory retention and permissible establishment, exercise or defense of legal claims. |
| AI processing | AI inference triggered by the user or request process to analyze requirements and price and service data and to prepare quotation drafts, using TensorX’s contractually agreed EU/EEA configuration; no permanent storage of request and output content at TensorX; no disclosure to model developers or model providers; no use to train or fine-tune general models; storage only of required technical usage, security and billing metadata, at TensorX for up to twelve months under the standard periods documented as of the date of this DPA. |
| Customer-specific optimization | Use of approved quotations, rules and corrections only within the respective customer tenant to improve future results for the same Customer; no cross-customer use of personal Customer Data. |
| Integrations | Restriction of integration permissions to the necessary scope; protected management of tokens and API keys; encrypted transmission where supported by the destination system; revocation or renewal of permissions as required. |
Appendix 3 – Subprocessors
A. Direct Subprocessors of Tasia
| Provider and address | Service | Processing location and transfer mechanism |
|---|---|---|
| Scaleway SAS, 8 rue de la Ville-l’Évêque, 75008 Paris, France | Primary hosting of the platform; server, network, storage, Managed MySQL, backup and infrastructure services; sending transactional account, request, security and quotation messages through Scaleway Transactional Email. Customer Data, account, usage, log, security, backup and email data may be affected. | Core infrastructure in Amsterdam, the Netherlands (nl-ams), within the European Union; transactional email processing under the EU configuration used. Tasia does not intend any third-country transfer for the core services used; the contractually agreed safeguards apply to the subprocessors engaged by Scaleway. |
| IONOS SE, Elgendorfer Straße 57, 56410 Montabaur, Germany | Domain, DNS, mailbox and email infrastructure for support, security and administrative communications insofar as these contain Customer Data within the meaning of the DPA. | Germany or European Union, depending on the product used. No third-country transfer by Tasia is intended. |
| TensorX Limited (formerly Tensorix), Unit 25, Classon House, Dundrum Business Park, Dublin 14, Ireland | AI/LLM inference triggered by the user or request process for extraction, structuring and assignment of requests, price and service data, and preparation of quotation drafts. Prompts, form entries, document content, price and service data, quotation drafts, generated outputs and technical usage and billing metadata may be affected. | European Union or EEA, in particular Dublin and Helsinki, under the configuration intended for Tasia. Under this configuration, request and output content is processed only temporarily, is not stored permanently and is not used for model training. The mechanisms under Section 6 apply to third-country transfers relevant under data protection law. |
B. Additional Subprocessing and Infrastructure Companies Used for the TensorX Service
The public TensorX documentation does not disclose whether every individual request passes through all of the providers listed below. Depending on the specific technical component used, the following companies in particular may be involved in providing the TensorX service. The decisive factor is whether the respective provider actually processes Customer Data or technically necessary metadata from Tasia:
| Additional provider | Function | Intended processing location |
|---|---|---|
| Cloudflare, Inc. | CDN, DNS, network, DDoS and web application protection | European data centers |
| Amazon Web Services, Inc. (AWS) | Cloud infrastructure, in particular region eu-west-1 | European Union |
| Railway Corp. | Application deployment and hosting infrastructure | European data centers |
| Verda | Data center and GPU hosting | Helsinki, Finland |
| Digital Realty Trust, Inc. | Data center and GPU hosting | Dublin, Ireland |
Despite the intended processing in European data centers, Cloudflare, AWS and Railway may have a corporate or group affiliation involving a third country. EU/EEA hosting alone does not exclude the application of additional legal systems. Insofar as this results in a third-country transfer or third-country access relevant under data protection law, Section 6 and the contractually agreed safeguards apply.
For the intended inference configuration, TensorX states that:
- Tasia request and output content is not disclosed to model developers or other model providers;
- this content is not stored or logged on a permanent basis;
- this content is not used to train or fine-tune AI models.
Other service providers used by TensorX for its own payment, CRM, newsletter, support or general communications purposes are not part of the regular inference path for Tasia content for that reason alone. If such a provider processes Customer Data within the meaning of this DPA in the future, the notification and objection rules under Section 5 shall apply before its engagement.
The current TensorX subprocessor list is additionally available at www.tensorx.ai/sub-processors. Tasia shall keep current the processing chain that is actually relevant to Tasia Customer Data in accordance with Section 5. A mere change to an external list does not automatically expand the Customer’s authorization; Tasia shall actively inform the Customer of relevant changes in accordance with Section 5.
C. Providers Not Covered by This DPA
STRATO is used exclusively for Tasia’s own audience measurement, for which Tasia acts as Controller, and is therefore not a subprocessor under this DPA.
Stripe, sevDesk and CleverReach are used for Tasia’s own payment, accounting and newsletter processing, respectively, and are likewise generally not subprocessors under this DPA insofar as they do not process Customer Data on the Customer’s behalf in an individual case.