Tahini
Back to home

Legal

Data Processing Addendum

The terms under which Tahini processes personal data on a customer's behalf. This addendum forms part of the agreement between Tahini and the customer.

Effective August 13, 2026

1. Scope and application

This Data Processing Addendum (“DPA”) is entered into between Tahini AI, Inc. (“Tahini”) and the customer identified in the Agreement (“Customer”), and forms part of the master services agreement, subscription agreement, order form, or Terms of Service between them (the “Agreement”).

This DPA applies where and to the extent Tahini processes Personal Data on Customer’s behalf in providing the services. Where this DPA conflicts with the Agreement, this DPA controls as to the processing of Personal Data. Where this DPA conflicts with the Standard Contractual Clauses, the Standard Contractual Clauses control.

2. Definitions

  • Applicable Data Protection Lawmeans all privacy and data protection laws applicable to the processing under this DPA, including the EU General Data Protection Regulation (“GDPR”), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and U.S. state privacy laws including the California Consumer Privacy Act as amended by the CPRA (“CCPA”).
  • Customer Personal Datameans Personal Data contained within Customer Data that Tahini processes on Customer’s behalf.
  • Personal Data, processing, controller, processor, data subject, and personal data breach have the meanings given in Applicable Data Protection Law. As to the CCPA, business, service provider, sell, and share have the meanings given in the CCPA.
  • Standard Contractual Clauses or SCCs means the clauses annexed to European Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
  • Sub-processor means a third party engaged by Tahini to process Customer Personal Data.

3. Roles of the parties

Customer is the controller, and Tahini is the processor, of Customer Personal Data. Where Customer is itself a processor acting for a third party controller, Customer warrants that it has the authority to instruct Tahini as set out in this DPA, and Tahini acts as a sub-processor. For purposes of the CCPA, Customer is the business and Tahini is a service provider.

4. Processing instructions

Tahini will process Customer Personal Data only on Customer’s documented instructions, which comprise the Agreement, this DPA, and Customer’s use of and configuration of the services, unless required to do otherwise by law. Where law requires other processing, Tahini will inform Customer before processing unless the law prohibits that notice.

Tahini will inform Customer if, in its opinion, an instruction infringes Applicable Data Protection Law. Tahini is not responsible for determining whether Customer’s instructions comply with law that applies to Customer.

Restrictions on Tahini’s use. Tahini will not:

  • sell or share Customer Personal Data, as those terms are defined in the CCPA;
  • retain, use, or disclose Customer Personal Data for any purpose other than performing the services, or outside the direct business relationship with Customer, except as permitted by Applicable Data Protection Law;
  • combine Customer Personal Data with personal information received from another source, except as permitted by Applicable Data Protection Law; or
  • use Customer Personal Data to train, fine-tune, or otherwise improve any machine learning or artificial intelligence model, whether Tahini’s or a third party’s.

Tahini certifies that it understands and will comply with these restrictions.

5. Confidentiality

Tahini will ensure that personnel authorized to process Customer Personal Data are bound by appropriate obligations of confidentiality and are granted access only as necessary to perform the services and to maintain and secure them.

6. Security

Tahini will implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing. Those measures are described in Annex II and are summarized on our Security page. Tahini may update its measures, provided the updates do not materially reduce the overall level of protection.

7. Sub-processors

Customer grants Tahini general authorization to engage Sub-processors to provide the services. Tahini will impose on each Sub-processor data protection obligations no less protective than those in this DPA, and remains liable for its Sub-processors’ performance to the same extent it is liable for its own.

A current list of Sub-processors is available on request at hello@usetahini.com. Tahini will give Customer notice before adding or replacing a Sub-processor. Customer may object on reasonable data protection grounds within fifteen (15) days of notice, in which case the parties will work in good faith to find an alternative. If none is reasonably available, Customer may terminate the affected services without penalty, receiving a pro-rata refund of prepaid fees for the terminated portion of the term.

8. Assistance to Customer

Taking into account the nature of the processing and the information available to it, Tahini will provide reasonable assistance to Customer with:

  • responding to requests from data subjects to exercise their rights, including through the functionality of the services. If Tahini receives such a request directly, it will not respond substantively and will promptly forward the request to Customer, unless legally required to respond;
  • data protection impact assessments and prior consultations with supervisory authorities; and
  • demonstrating compliance with Customer’s obligations under Applicable Data Protection Law in respect of the processing.

9. Personal data breach

Tahini will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. The notification will describe, to the extent known, the nature of the breach, the categories and approximate volume of data and data subjects affected, the likely consequences, and the measures taken or proposed. Tahini will provide reasonable cooperation to Customer in investigating and mitigating the breach. Tahini’s notification is not an acknowledgment of fault or liability.

10. Deletion and return

On termination or expiry of the Agreement, Tahini will, at Customer’s election, delete or return Customer Personal Data, and delete existing copies, unless law requires continued storage. Customer may export its data through the services before termination. Data remaining in routine backups will be deleted in accordance with Tahini’s backup cycle and will remain subject to this DPA until deleted.

11. Audits

Tahini will make available to Customer the information reasonably necessary to demonstrate compliance with this DPA, including by responding to reasonable security questionnaires and providing any third-party audit reports or certifications it holds. Where Applicable Data Protection Law entitles Customer to conduct an audit beyond that information, the parties will agree in advance on reasonable scope, timing, and duration. Audits will occur no more than once in any twelve (12) month period, except following a personal data breach or where required by a supervisory authority, must be conducted during business hours with reasonable prior notice, must not unreasonably interfere with Tahini’s operations, and are subject to confidentiality obligations. Customer bears the cost of any such audit.

12. International transfers

Tahini processes Customer Personal Data in the United States and may process it in other countries where it or its Sub-processors operate.

Where Customer Personal Data protected by the GDPR is transferred to a country not subject to an adequacy decision, the SCCs are incorporated into this DPA by reference and apply as follows: Module Two (controller-to-processor) applies where Customer is a controller, and Module Three (processor-to-processor) applies where Customer is a processor; the optional docking clause in Clause 7 applies; in Clause 9, Option 2 (general written authorization) applies with the notice period in Section 7 of this DPA; in Clause 11, the optional independent dispute resolution language does not apply; in Clause 17, the clauses are governed by the law of Ireland; in Clause 18(b), disputes are resolved before the courts of Ireland; and Annexes I and II of the SCCs are populated by Annexes I and II of this DPA.

Transfers of Personal Data protected by UK law are subject to the UK International Data Transfer Addendum to the SCCs, and transfers of Personal Data protected by Swiss law are subject to the SCCs as amended to refer to the Swiss Federal Data Protection and Information Commissioner and Swiss law.

13. Liability

Each party’s liability arising out of or related to this DPA is subject to the exclusions and limitations of liability set out in the Agreement. Nothing in this DPA limits liability that cannot be limited under Applicable Data Protection Law, including a data subject’s rights under the SCCs.

14. Term, governing law, and general

This DPA takes effect on the effective date of the Agreement and continues until Tahini has ceased all processing of Customer Personal Data. Except as stated in Section 12 for the SCCs, this DPA is governed by the law and venue specified in the Agreement. If any provision is held invalid, the remainder stays in effect.

Annex I — Details of processing

Parties. Data exporter: Customer, the entity identified in the Agreement, acting as controller (or as processor where it processes on behalf of a third party). Data importer: Tahini AI, Inc., San Francisco, California, United States, acting as processor, contact hello@usetahini.com.

Subject matter and nature of processing.Provision of Tahini’s financial and operational software, including hosting and storage of Customer Data; automated extraction, categorization, reconciliation, matching, and analysis of documents and records; generation of reports and analytics; user authentication and access management; and support, maintenance, and security of the services.

Purpose. To provide, secure, and support the services for Customer under the Agreement.

Duration. For the term of the Agreement, plus the period until deletion or return under Section 10.

Categories of data subjects.Customer’s personnel and authorized users; Customer’s suppliers, vendors, and their personnel; Customer’s trading partners and retail customers and their personnel; and, where Customer connects a commerce platform, Customer’s own end customers.

Categories of Personal Data. Identification and contact data such as name, business email address, business telephone number, and postal or shipping address; employment data such as job title, role, and approval authority; account data such as user identifiers, organization membership, and role assignments; transactional data such as order, invoice, purchase order, payment, and remittance records associated with an identified or identifiable person; correspondence and free-text notes submitted to the services; and technical data such as IP address and log records.

Special categories of data. The services are not intended for special categories of Personal Data as defined in Article 9 GDPR, and Customer agrees not to submit them.

Frequency of transfer. Continuous, for the duration of the Agreement.

Competent supervisory authority.Determined in accordance with Clause 13 of the SCCs, based on Customer’s place of establishment or its EU representative.

Annex II — Technical and organizational measures

Tahini maintains measures including, at a minimum, those described below and on our Security page:

  • Tenant isolation.Each customer’s data is logically segregated by organization, enforced at the database layer rather than by application code alone.
  • Encryption. Encryption of data in transit using TLS; encryption of data at rest; and additional application-layer encryption of integration credentials and third-party secrets using AES-256-GCM with keys held outside the database.
  • Access control. Role-based access within each customer organization; access by invitation only; server-side session management; and separation of internal administrative functions from the customer product, with authorization verified against current records on each request so that revocation is immediate.
  • Document storage. Uploaded documents held in private object storage with no public URLs, released only through short-lived signed links issued after an ownership check.
  • Integration security. Standard authorization flows with least-privilege scopes and cryptographic verification of platform callbacks before credentials are accepted.
  • Restrictions on AI processing.Customer Personal Data is not used to train, fine-tune, or improve any model, and Tahini’s agreements with model providers prohibit such use.
  • Infrastructure. Services run on managed cloud infrastructure, with the provider responsible for physical security, network security, and platform patching.
  • Incident response. Procedures for identifying, investigating, containing, and notifying personal data breaches in accordance with Section 9.

Annex III — Sub-processors

Tahini engages Sub-processors in the following categories: cloud hosting and application delivery; database, authentication, and file storage; AI model processing; and transactional email. A current list naming each Sub-processor, its role, and its processing location is available on request at hello@usetahini.com, and will be provided to Customer on execution of this DPA.

How to execute this DPA

Customers who require a countersigned copy can request one at hello@usetahini.com. Please include the legal entity name, the signatory’s name and title, and any EU or UK representative details you need reflected in Annex I.