Preamble

This Data Processing Agreement ("DPA") is entered into between TFALKE PRIVATE LIMITED, a company incorporated under the laws of India ("Processor," "TFALKE," "we"), and the Customer identified in the Master Services Agreement and Terms of Service (the "Agreement") between the Parties ("Controller," "Customer," "you"). This DPA is incorporated into, and forms an addendum to, the Agreement, and applies to the extent TFALKE processes Personal Data (as defined below) on Customer's behalf in the course of providing the real-time endpoint management platform and any associated natural language AI agent (collectively, the "Service"). In the event of any conflict between this DPA and the Agreement regarding the processing of Personal Data, this DPA controls.

1. Definitions

  • "Personal Data" means any information relating to an identified or identifiable natural person that TFALKE processes on Customer's behalf under this DPA, limited, per Section 2, to the categories described in Annex 1.
  • "Data Protection Laws" means all applicable laws governing the processing of Personal Data, including the EU General Data Protection Regulation (Regulation (EU) 2016/679) ("GDPR"), the UK GDPR and Data Protection Act 2018, the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA"), and India's Digital Personal Data Protection Act, 2023 ("DPDPA"), in each case to the extent applicable to the processing under this DPA.
  • "SCCs" means the European Commission's Standard Contractual Clauses for the transfer of personal data to third countries, adopted by Implementing Decision (EU) 2021/914, as set out in Annex 4, together with the UK International Data Transfer Addendum where applicable.
  • "Sub-processor" means any third party engaged by TFALKE to process Personal Data on Customer's behalf in the provision of the Service, as further defined in Section 4.
  • "Third-Party LLM Provider" means any independent large language model or generative AI provider (including without limitation OpenAI or Anthropic) that Customer connects to the AI Agent using a Customer API Key, as described in Section 4.4.
  • "Connection Metadata," "Billing Information," and "Customer API Key" have the meanings given in the Agreement and in Annex 1.

2. Roles and Scope of Processing

2.1 Controller and Processor Roles

The Parties agree that, with respect to the Personal Data described in Annex 1, Customer is the Data Controller (or, where Customer processes Personal Data on behalf of its own upstream controller, a Processor acting under that controller's instructions) and TFALKE is a Data Processor acting solely on Customer's documented instructions, within the meaning of Article 28 GDPR. For purposes of the CCPA/CPRA, Customer is the "Business" and TFALKE is a "Service Provider," and the Parties intend this DPA, together with the Agreement, to constitute the written contract required under Cal. Civ. Code § 1798.140(ag).

2.2 Severely Limited Nature and Purpose of Processing

The Parties acknowledge that TFALKE's platform is architected on a Minimal Data Collection and Zero Analytics/Zero Cookie basis, as described in TFALKE's public Privacy Policy. Accordingly, the nature and purpose of TFALKE's processing under this DPA is strictly and exclusively limited to:

  • processing Connection Metadata necessary to establish, maintain, and monitor platform connectivity and availability for Customer's enrolled Endpoints;
  • processing Billing Information necessary to administer Customer's subscription and process payment; and
  • processing Account Creation Details necessary to provision and secure Customer's account; and
  • processing AI Agent Session Data necessary to operate the AI Agent feature, including relaying Authorized Users' messages and commands to Customer's configured Third-Party LLM Provider(s) and maintaining a session record, as described in Section 4.4.

Except for AI Agent Session Data described above and in Section 4.4, TFALKE does not process, and this DPA does not otherwise authorize TFALKE to process, the substantive content of Customer's Endpoint files, documents, or organizational records. TFALKE does not conduct profiling, automated decision-making producing legal effects, or any analytics-based processing of Personal Data.

2.3 Processing on Documented Instructions

TFALKE will process Personal Data only on Customer's documented instructions, including as set out in the Agreement, this DPA, and Customer's ordinary use of the Service's configuration settings, unless required to do otherwise by applicable law, in which case TFALKE will inform Customer of that legal requirement before processing, unless legally prohibited from doing so. TFALKE will immediately inform Customer if, in its opinion, an instruction infringes Data Protection Laws.

2.4 Confidentiality of Personnel

TFALKE will ensure that any person authorized to process Personal Data is subject to an appropriate contractual or statutory obligation of confidentiality.

3. Annex-Defined Details of Processing (GDPR Art. 28(3) Requirements)

The subject matter, duration, nature and purpose of processing, types of Personal Data, and categories of data subjects are set out in Annex 1 (Details of Processing), which forms an integral part of this DPA as required under Article 28(3) GDPR.

4. Sub-processors and the BYOK AI Model

4.1 General Authorization

Customer provides TFALKE with a general authorization to engage Sub-processors to support the provision of the Service, provided that TFALKE: (a) maintains a current list of Sub-processors, made available at TFALKE's Trust & Privacy portal or on request (Annex 3); (b) imposes data protection obligations on each Sub-processor materially equivalent to those set out in this DPA; and (c) remains liable to Customer for the acts and omissions of its Sub-processors in respect of the limited Personal Data described in Annex 1, to the same extent TFALKE would be liable under this DPA for its own acts.

4.2 Notice of New Sub-processors

TFALKE will give Customer at least fifteen (15) days' prior notice of the addition of any new Sub-processor, during which Customer may object on reasonable data-protection grounds. If the Parties cannot resolve the objection, Customer's sole remedy is to terminate the affected part of the Service without penalty, and this DPA and the Agreement will otherwise remain in effect.

4.3 Sub-processor List Scope

Because TFALKE's processing is limited to Connection Metadata, Billing Information, and Account Creation Details (Section 2.2), TFALKE's Sub-processor list is correspondingly limited to infrastructure hosting providers, the payment processor, and equivalent operational vendors necessary to deliver those narrow functions.

4.4 AI Agent Session Data; Role of the Third-Party LLM Provider

TFALKE processes AI Agent Session Data, as described in Annex 1 and Section 4.4A, as a Processor acting on Customer's documented instructions in order to operate the AI Agent feature, including relaying such data to Customer's configured Third-Party LLM Provider(s) using Customer's own Customer API Key. Separately, and without limiting the foregoing, Customer acknowledges and agrees that where Customer configures the AI Agent to use a Customer API Key for a Third-Party LLM Provider:

  • the Third-Party LLM Provider processes the content relayed to it, and its own generated outputs, as a direct, independent Processor (or Sub-processor) of Customer, engaged and instructed by Customer under Customer's own account and contractual relationship with that provider;
  • TFALKE facilitates the technical relay of such content to the Third-Party LLM Provider using Customer's own Customer API Key, as described in Section 4.4A, but is not a party to, and does not control the terms of, Customer's own account or contractual relationship with that provider;
  • TFALKE will not include any Third-Party LLM Provider on its Sub-processor list (Annex 3) on the basis of Customer's own BYOK configuration, since that provider is engaged directly by Customer under Customer's own account with that provider; and
  • TFALKE bears no liability under this DPA or the Agreement for the Third-Party LLM Provider's processing, storage, retention, security practices, or compliance with Data Protection Laws, and Customer is solely responsible for ensuring its own agreement with the Third-Party LLM Provider satisfies Customer's obligations as Controller, including executing a separate Article 28 data processing agreement directly with that provider where required.

4.4A Scope and Retention of TFALKE's Processing of AI Agent Session Data

TFALKE's infrastructure processes AI Agent Session Data, including the content of messages, commands, and command output (including standard-output and standard-error text), in order to: (a) enforce the single-device restriction described in the Agreement; (b) classify a proposed command and present it for the Accept/Reject confirmation required for High-Risk Commands; (c) relay the request to, and the response from, the Third-Party LLM Provider selected by Customer; and (d) maintain a session record enabling Authorized Users to resume a troubleshooting session. Such content is cached for up to twenty-four (24) hours in TFALKE's short-lived operational data store, and the session record (including messages, commands, and command output) is retained in TFALKE's primary database until deleted by TFALKE at Customer's request or in accordance with Section 8, or automatically pursuant to TFALKE's data retention schedule. Notwithstanding the foregoing, the Accept/Reject decision record (the timestamp, proposed command content, and Accept/Reject decision for each High-Risk Command, as described in the Agreement) is retained for not less than thirty-six (36) months from its creation, or such longer period as required to resolve a pending dispute or claim, regardless of any earlier deletion of the broader session record under this Section 4.4A, as necessary for the establishment, exercise, or defense of legal claims under Article 17(3)(e) GDPR and equivalent provisions of other Data Protection Laws. TFALKE does not use AI Agent Session Data to train or fine-tune TFALKE's own models, and does not manually review AI Agent Session Data except as reasonably necessary to investigate a suspected Acceptable Use Policy violation, security incident, or support request raised by Customer. This processing does not make TFALKE a Processor or Sub-processor of the Third-Party LLM Provider's own, separate processing activities described in this Section 4.4.

5. Cross-Border Data Transfers

5.1 Transfer Mechanism

Customer acknowledges that TFALKE is incorporated in India and that the limited Personal Data described in Annex 1 may be transferred from the European Economic Area, the United Kingdom, Switzerland, or the United States to TFALKE's cloud infrastructure, hosted by TFALKE's Sub-processor on Oracle Cloud Infrastructure, UAE East (Dubai) region, or such other location as TFALKE's Sub-processors may operate from time to time as disclosed in Annex 3. Where such a transfer is subject to GDPR or UK GDPR restrictions on international transfers, the Parties agree that the SCCs (Module Two: Controller to Processor, or Module Three: Processor to Processor, as applicable), attached as Annex 4, are incorporated into and form part of this DPA, with Customer as "data exporter" and TFALKE as "data importer." For transfers subject to UK GDPR, the UK International Data Transfer Addendum to the SCCs is incorporated by reference and applies in place of, or in addition to, the SCCs as required.

5.2 Transfer Impact Assessment

TFALKE will provide Customer with reasonably requested information about TFALKE's data handling practices in India to support Customer's transfer impact assessment, including information about applicable Indian law and TFALKE's technical and organizational security measures (Annex 2).

5.3 US Transfers

Where Personal Data is transferred from the United States, the Parties agree that the CCPA/CPRA service-provider contractual terms in Section 2.1 of this DPA satisfy the requirements of Cal. Civ. Code § 1798.140(ag), and no additional transfer mechanism is required for such transfers absent a specific applicable state law requirement.

6. Security of Processing

6.1 Technical and Organizational Measures

TFALKE will implement and maintain appropriate technical and organizational measures to protect the limited Personal Data it processes against unauthorized or unlawful processing and against accidental loss, destruction, or damage, proportionate to the narrow scope of data described in Annex 1. TFALKE's current measures are set out in Annex 2 and include, at minimum, encryption of Personal Data in transit, role-based access controls limiting internal access to Connection Metadata and Billing Information on a need-to-know basis, logging of administrative access, and regular review of infrastructure security configuration.

6.2 Personal Data Breach Notification

TFALKE will notify Customer without undue delay, and in any event within seventy-two (72) hours of becoming aware, of any confirmed Personal Data breach affecting Customer's Personal Data, providing the information reasonably necessary for Customer to meet its own notification obligations under Data Protection Laws, and will take reasonable steps to mitigate the effects and minimize any damage resulting from the breach.

6.3 Assistance with Data Subject Rights

Taking into account the nature of the processing, TFALKE will provide reasonable technical and organizational assistance to Customer, insofar as possible, to enable Customer to respond to requests from data subjects exercising their rights under Data Protection Laws, and to comply with Customer's obligations regarding security, breach notification, data protection impact assessments, and consultation with supervisory authorities, in each case limited to the Personal Data actually processed by TFALKE under Annex 1.

7. Audits and Compliance Verification

7.1 Written Questionnaire in Lieu of On-Site Audit

In light of the multi-tenant nature of TFALKE's SaaS infrastructure, the narrow scope of Personal Data processed (Annex 1), and the need to protect the confidentiality and security of other customers' environments, Customer's audit rights under Article 28(3)(h) GDPR are exercised as follows:

  • Customer may, no more than once in any twelve (12)-month period (or more frequently if required following a confirmed Personal Data breach affecting Customer, or by a supervisory authority), submit a written information security and compliance questionnaire to TFALKE, covering TFALKE's technical and organizational measures, Sub-processor management, and compliance with this DPA;
  • TFALKE will respond to such questionnaire within thirty (30) days and will make available, on a confidential basis, any current third-party security certification, audit report, or penetration test summary that TFALKE has commissioned and holds at the time of the request; and
  • in lieu of, and not in addition to, physical or on-site inspection, TFALKE will provide such documentary evidence, screen-shared demonstrations, or remote interviews with relevant TFALKE personnel as are reasonably necessary to allow Customer to verify TFALKE's compliance with this DPA.

7.2 No On-Site or Physical Audit Right

Customer agrees that on-site or physical audits of TFALKE's infrastructure, data centers, or offices are not available under this DPA, whether conducted by Customer directly or through a third-party auditor, except where a supervisory authority with binding legal authority over TFALKE compels such access, in which case TFALKE will cooperate to the extent legally required. Notwithstanding the foregoing, where Customer is subject to a legal or regulatory requirement mandating on-site or third-party audit rights over its processors (including, without limitation, financial services regulation applicable to Customer), the Parties will discuss in good faith reasonable accommodations to meet that requirement, subject to appropriate confidentiality and security protections for TFALKE's multi-tenant infrastructure and other customers.

7.3 Costs

Each Party bears its own costs in connection with the questionnaire process described in Section 7.1, except that TFALKE may charge a reasonable fee for questionnaire responses or documentation requests exceeding one instance per twelve (12)-month period.

8. Return and Deletion of Personal Data

On termination or expiry of the Agreement, TFALKE will, at Customer's election, delete or return all Personal Data processed under this DPA, and delete existing copies, within a commercially reasonable period, unless applicable law requires TFALKE to retain some or all of the Personal Data, in which case TFALKE will continue to protect it in accordance with this DPA for as long as it is retained.

9. Liability

Each Party's liability arising out of or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Agreement, including the Limitation of Liability and Indemnification sections of the Master Services Agreement, which are incorporated into this DPA by reference. Nothing in this DPA expands TFALKE's liability beyond that set out in the Agreement.

10. Order of Precedence and Governing Law

This DPA is governed by the same governing law and dispute resolution provisions as the Agreement (India-seated arbitration, as set out in the Agreement), except that, to the extent required by Data Protection Laws, the SCCs in Annex 4 are governed by the law of the EU Member State specified therein and are enforceable independently of the arbitration clause with respect to data subject and supervisory authority rights, as required under the SCCs' own terms.

Annex 1 - Details of Processing

Subject MatterProvision of the RTEM Service, including connectivity, availability monitoring, and account/billing administration for Customer's enrolled Endpoints.
DurationFor the term of the Agreement, plus any post-termination retention period described in Section 8 and TFALKE's data retention schedule.
Nature and Purpose of ProcessingMaintaining live Endpoint connectivity; account provisioning and security; subscription billing and payment administration. Excludes analytics, profiling, and content-level processing of Endpoint payloads.
Categories of Data SubjectsCustomer's administrators and Authorized Users who create or access the account; individuals associated with billing contacts; and, incidentally, any other individual whose Personal Data may appear within AI Agent command output (e.g., a username or file path referenced in standard-output or standard-error text).
Types of Personal DataAccount Creation Details (name, business email, authentication credentials); Billing Information (billing name, business address, payment instrument token); Connection Metadata (device identifier, IP address, connection timestamp, agent heartbeat status, agent version); AI Agent Session Data (natural-language messages submitted by Authorized Users, the AI Agent's responses, commands issued, and command output, including terminal standard-output and standard-error text, which may incidentally contain Personal Data appearing in that output, such as usernames or file paths). Excludes special category data and Endpoint file contents not incidentally captured in AI Agent Session Data.
Special Category DataNone. TFALKE's processing under this DPA does not include special category data as defined under Article 9 GDPR.

Annex 2 - Technical and Organizational Security Measures

  • Encryption of Personal Data in transit using industry-standard protocols (e.g., TLS 1.2+).
  • Role-based access controls restricting internal access to Connection Metadata and Billing Information to personnel with a defined operational need.
  • Logging and monitoring of administrative access to production systems handling Personal Data.
  • Segregation of Customer environments within TFALKE's multi-tenant architecture.
  • Vendor security review process for Sub-processors prior to onboarding.
  • Documented incident response procedure, including the 72-hour breach notification commitment in Section 6.2.
  • Periodic review of access permissions and revocation of access for departed personnel.

Annex 3 - Sub-processor List

A current, complete Sub-processor list is maintained at TFALKE's Trust & Privacy portal and is made available to Customer on request, consistent with Section 4.2. As of the effective date of this DPA, TFALKE's Sub-processors are limited to categories necessary to deliver the narrow processing described in Annex 1, such as:

CategoryPurposeLocation
Cloud infrastructure / hosting providerHosting of Connection Metadata and account systemsOracle Cloud Infrastructure - UAE East (Dubai) region
Payment processorProcessing of Billing Information and payment transactionsPaddle.com Market Ltd (Paddle), United Kingdom

Note: per Section 4.4, any Third-Party LLM Provider connected by Customer under the BYOK model is NOT included on this list, as it is not a Sub-processor of TFALKE.

Annex 4 - Standard Contractual Clauses

The Parties agree that the European Commission's Standard Contractual Clauses (Module Two: Controller to Processor), as set out in the Annex to Commission Implementing Decision (EU) 2021/914, are incorporated into this DPA by reference, with the following selections:

  • Clause 7 (Docking Clause): Not used.
  • Clause 9 (Sub-processors): Option 2 (General Written Authorization), with the notice period specified in Section 4.2 of this DPA.
  • Clause 11(a) (Redress): The optional language is not used.
  • Clause 13 / Annex I.C (Competent Supervisory Authority): The German Federal Commissioner for Data Protection and Freedom of Information (BfDI), or the competent Land (state) data protection authority corresponding to Customer's EU establishment, where applicable.
  • Clause 17 (Governing Law): The laws of the Federal Republic of Germany.
  • Clause 18 (Choice of Forum and Jurisdiction): The courts of the Federal Republic of Germany.

For transfers subject to UK GDPR, the UK Information Commissioner's Office International Data Transfer Addendum to the EU SCCs applies in place of, or alongside, the above, as required. Annexes I, II, and III to the SCCs are deemed populated by reference to Annexes 1, 2, and 3 of this DPA respectively.

Contact

For DPA or data processing inquiries:

[email protected]