Data Processing Addendum
RELATIVITYOS DATA PROCESSING ADDENDUM
Tensyr LLC · Last updated September 22, 2026
This Data Processing Addendum (this "DPA") is incorporated into and forms part of the RelativityOS Terms of Service between Tensyr LLC ("Tensyr") and the customer accepting those terms ("Customer"), and is effective on the effective date of that agreement. For Customers that accepted the Terms of Service before the date above, this DPA is effective on that date and replaces any previously agreed data processing terms. No signature is required; a countersigned copy is available on request to legal@tensyr.com.
Capitalized terms not defined here have the meanings given in the Terms of Service.
Where this DPA conflicts with the Terms of Service, this DPA controls as to the processing of Personal Information. Where it conflicts with the Security Overview, the Security Overview controls as to security measures, incident notification, subprocessor notice and objection, and retention and deletion. This DPA does not restate those terms.
1. Definitions
1.1 "Applicable Privacy Law" means each United States state privacy or consumer data protection statute, and the regulations issued under it, that applies to Customer's use of the Service.
1.2 "Personal Information" means information within Customer Data that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked with an identified or identifiable natural person, and that is subject to Applicable Privacy Law.
1.3 "Sensitive Personal Information" has the meaning given to that term, or to "sensitive data," under Applicable Privacy Law.
1.4 "Consumer Request" means a request by an individual to exercise a right under Applicable Privacy Law, including a right to access, delete, correct, obtain a portable copy of, opt out of the sale or sharing of, or limit the use of that individual's Personal Information.
1.5 "Subprocessor" means a third party engaged by Tensyr to process Personal Information in providing the Service.
2. Roles of the parties
2.1 Allocation. As between the parties, Customer is the controller and business, and Tensyr is the processor, service provider and contractor.
2.2 Customer's responsibilities. Customer determines the purposes and means of the processing. Customer is responsible for the lawfulness of its collection of Personal Information, for providing the notices Applicable Privacy Law requires, for obtaining and maintaining any consent required for Sensitive Personal Information, and for the accuracy and quality of Personal Information it submits.
2.3 Fact-based determination. Whether a party acts as a controller or a processor with respect to a particular processing activity is a fact-based determination that depends on the context. Tensyr, in continuing to adhere to Customer's instructions, remains a processor.
2.4 Aggregated data. Section 7.5 of the Terms of Service governs Tensyr's use of aggregated and de-identified data. Tensyr will not attempt to reidentify such data and will contractually oblige any recipient not to do so.
3. Scope and instructions
3.1 Documented instructions. Tensyr will process Personal Information only on Customer's documented instructions. The Terms of Service, this DPA, the configuration Customer selects, and Customer's use of the features of the Service are Customer's documented instructions. Tensyr will also process Personal Information where required by applicable law, in which case it will inform Customer unless the law prohibits it.
3.2 Nature. The nature of the processing is the hosting, storage, transmission, organization, retrieval, display, backup and deletion of Personal Information, and the delivery of calling, messaging and artificial intelligence features, as necessary to provide, secure and support the Service.
3.3 Purpose. The purpose of the processing is to enable Customer to manage its relationships with its clients and prospective clients and to operate its business through the Service.
3.4 Duration. Processing continues for the Subscription Term and for the period after termination described in Section 14.9 of the Terms of Service and the Security Overview.
3.5 Categories. Annex A describes the categories of individuals and of Personal Information processed.
4. Restrictions on Tensyr's use
Tensyr will not:
(a) sell or share Personal Information, as those terms are defined under Applicable Privacy Law;
(b) retain, use or disclose Personal Information for any purpose other than the business purposes specified in this DPA and the Terms of Service, including for any commercial purpose of its own;
(c) retain, use or disclose Personal Information outside the direct business relationship between Tensyr and Customer;
(d) combine Personal Information received from or on behalf of Customer with personal information received from or on behalf of any other person, except as necessary to perform a business purpose Applicable Privacy Law permits;
(e) use Personal Information to train, fine-tune or improve any artificial intelligence or machine learning model of Tensyr or of any third party, or authorize any Subprocessor to do so; or
(f) process Personal Information in a manner Applicable Privacy Law prohibits to a service provider, contractor or processor.
Tensyr certifies that it understands the restrictions in this Section and will comply with them, and will notify Customer promptly if it determines that it can no longer meet its obligations under Applicable Privacy Law.
5. Confidentiality of personnel
Tensyr will ensure that each person it authorizes to process Personal Information is subject to a written obligation of confidentiality that survives the end of their engagement, and will limit access to those personnel who require it.
6. Security
Tensyr has implemented and will maintain technical and organizational measures designed to protect Personal Information, as described in the Security Overview. Customer is responsible for configuring the Service and using the features Tensyr makes available to maintain security appropriate to the Personal Information it submits.
Customer acknowledges that security measures are subject to technical progress and development, and that Tensyr may update them from time to time, provided that no update materially reduces the overall security of the Service during a Subscription Term.
7. Subprocessors
7.1 Authorization. Customer authorizes Tensyr to engage Subprocessors. Section 12 of the Security Overview describes the functions Subprocessors perform, how Customer may obtain their identity, and the notice and objection process applicable to changes.
7.2 Flow-down. Tensyr will engage each Subprocessor under a written contract requiring it to meet obligations with respect to Personal Information no less protective than those Tensyr owes Customer under this DPA. Tensyr remains responsible to Customer for its Subprocessors' performance of those obligations.
8. Assistance with individual rights
8.1 Consumer Requests. Where Tensyr receives a Consumer Request relating to Customer's Account, Tensyr will not respond except to direct the individual to Customer, unless applicable law requires otherwise or Customer instructs otherwise, and will inform Customer without undue delay.
8.2 Enabling Customer to respond. Tensyr will provide Customer with the features, and with reasonable assistance where the features are insufficient, necessary for Customer to respond to a Consumer Request. Customer may access, correct, export and delete Personal Information within its Account through the Service during the Subscription Term.
8.3 Opt-out and limitation instructions. Where Customer instructs Tensyr that an individual has opted out of the sale or sharing of Personal Information, or has directed that the use of Sensitive Personal Information be limited, Tensyr will act on that instruction.
8.4 Assessments. Tensyr will provide Customer, on reasonable request, with the information in its possession that Customer reasonably requires to conduct a data protection assessment where Applicable Privacy Law requires one.
9. Security incidents
Tensyr will notify Customer of a security incident affecting Personal Information, and will provide the information and cooperation described in the Security Overview and in Section 8 of the Terms of Service. The timing, content and method of that notice are governed by those documents. Notice is not an acknowledgment of fault or liability.
10. Sensitive Personal Information
Customer determines what information it submits. Customer acknowledges that the Service is capable of storing Sensitive Personal Information and that Customer is responsible for obtaining any consent Applicable Privacy Law requires before processing it. Section 7.4 of the Terms of Service governs prohibited data.
Tensyr processes Sensitive Personal Information solely on Customer's instructions, solely to store, organize, transmit, display, back up and delete it as part of providing the Service, and not for the purpose of inferring characteristics about any individual. Tensyr does not analyze Sensitive Personal Information to draw inferences about any individual and has no actual knowledge that any particular record contains Sensitive Personal Information unless Customer notifies it.
11. Demonstration of compliance
11.1 Information. Tensyr will make available to Customer the information reasonably necessary to demonstrate its compliance with this DPA.
11.2 How that right is exercised. Customer agrees that it will exercise any audit or assessment right it has under this DPA or Applicable Privacy Law by instructing Tensyr to comply with the measures described in this Section: the annual written control description and technical discussion provided under Section 15 of the Security Overview, and Tensyr's written responses under Section 11.3.
11.3 Written responses. At Customer's written request, Tensyr will provide written responses, on a confidential basis, to reasonable requests for information necessary to confirm its compliance with this DPA. Customer will not exercise this right more than once in any twelve-month period unless it has reasonable grounds to suspect non-compliance or Applicable Privacy Law requires otherwise.
11.4 Limits. No right under this Section entitles Customer or any person acting for Customer to access Tensyr's facilities or systems, to conduct security or penetration testing against the Service, to access any data relating to another customer, or to require Tensyr to act in breach of a confidentiality obligation owed to a third party. Tensyr may decline a request made by or through a person that develops, operates or markets a product or service competitive with the Service. Information Tensyr provides under this Section is Tensyr's Confidential Information.
11.5 Relationship to other rights. This Section applies only to the extent the Terms of Service and the Security Overview do not otherwise provide Customer with rights meeting the requirements of Applicable Privacy Law.
11.6 Cost. Tensyr bears its own costs of complying with Sections 11.1 to 11.3. Where a request requires disproportionate time, resources or access from Tensyr or a Subprocessor, Tensyr may charge Customer for the additional time and costs reasonably incurred at its then-current rates.
12. Return and deletion
12.1 During the Subscription Term. Customer may access, export, correct and delete Personal Information within its Account through the features of the Service.
12.2 On termination. On termination, Tensyr will delete or, at Customer's direction and within the window described in Section 14.9 of the Terms of Service, return Personal Information. The mechanics and schedule are governed by the Terms of Service and the Security Overview.
12.3 Carve-outs. Sections 12.1 and 12.2 do not apply to Personal Information that Tensyr is required to retain by applicable law, that is subject to a legal hold or a pending or threatened claim, or that is held in the acceptance records described in Section 7 of the Security Overview. Tensyr will maintain the confidentiality of any Personal Information so retained and will not further process it except as required by applicable law.
12.4 Backups. Sections 12.1 and 12.2 do not apply to Personal Information archived on backup systems, which Tensyr and its Subprocessors will securely isolate and protect from further processing until deleted in accordance with the backup rotation then in effect.
13. Liability
Each party's liability arising out of or related to this DPA is subject to the exclusions and limitations in Section 13 of the Terms of Service. Claims under this DPA and under the Terms of Service are aggregated for the purpose of that Section and do not create separate caps.
14. Term and changes
This DPA continues until Tensyr has completed the deletion or return of Personal Information under Section 12. Sections 4, 5, 11, 12 and 13 survive.
Tensyr may update this DPA on notice, in accordance with Section 16.2 of the Terms of Service, provided that no update materially reduces Tensyr's obligations with respect to Personal Information during a Subscription Term. Prior versions remain available in the archive.
15. Contact
Questions concerning this DPA: legal@tensyr.com
Annex A — Description of processing
Categories of individuals. Customer's clients and prospective clients; individuals those clients designate; Customer's Users; and Customer's own personnel and contractors.
Categories of Personal Information.
- Identifiers: name, postal address, email address, telephone number, date of birth, and account identifiers.
- Professional information: employer, occupation, and any professional credential Customer records.
- Commercial information: records of the products or services Customer offers, quotes, transactions and related details.
- Communications: the contents and metadata of calls, recordings, voicemails, text messages, emails and notes recorded by Users.
- Internet and device information: IP address, device and browser information, and activity within the Service.
- Government identifiers, where Customer collects them.
- Health-related information, where a User records it.
Sensitive categories. Health-related information, government identification numbers, and the contents of communications, in each case to the extent Applicable Privacy Law treats them as sensitive.
Frequency. Continuous, for the duration of the Subscription Term.
Nature, purpose and duration. As described in Sections 3.2, 3.3 and 3.4.
Annex B — Subprocessors
Section 12 of the Security Overview describes the functions Subprocessors perform, how Customer may obtain their identity, and the notice and objection process applicable to changes.