Data Processing Agreement (template).
A single Data Processing Agreement accompanies every TensorPlane contract, built on the GDPR Article 28 mandated-content checklist and the EU Commission's Standard Contractual Clauses. It carries two deployment scopes; Annex 1 selects the one that applies. This is a starting-point template — bracketed placeholders below are shown exactly as they stand in the source.
DRAFT — not legal advice — pending attorney review. These drafts are not execution-ready. They exist to cut attorney time, not to replace review, and must be confirmed by a qualified attorney before anyone relies on them in a signed contract.
How to read this template.
The processing covered differs by deployment mode, so the template carries two scopes rather than two documents:
- Scope A — Vendor-hosted (self-serve): TensorPlane operates the platform on EU infrastructure and, in the course of running reviews, processes customer code and prompts, which may contain personal data. Heavier processor role.
- Scope B — Customer-operated (enterprise): the platform runs on the customer's own infrastructure; customer code and model traffic never transit TensorPlane. TensorPlane processes licensing telemetry only. Narrow processor role.
The distinction is load-bearing: a term correct for Scope A is meaningless for Scope B, where that data never reaches us. The two are not merged.
Parties and roles.
Controller: [CUSTOMER LEGAL ENTITY] (“Customer”), the controller of the personal data processed under the Agreement.
Processor: Blockforo s.r.o., company ID / IČO 21654093 (VAT DIČ CZ21654093), registered seat Rybná 716/24, Staré Město, 110 00 Praha 1, Czech Republic (“TensorPlane”), processing personal data on the Customer's documented instructions. [Attorney: confirm the entity against ARES before execution.]
This DPA forms part of, and is subject to, the Master Services Agreement between the parties. On any conflict about personal-data processing, this DPA prevails. Governing law and jurisdiction follow the Agreement (see the governing-law clause).
Subject matter, duration, nature and purpose.
- Subject matter: processing of personal data necessary to provide the TensorPlane platform and services.
- Duration: the term of the Agreement, plus the deletion/return period in §10.
- Nature and purpose: operating an AI code-review and agent platform, metering entitlements, and billing — as detailed per scope in Annex 1.
Instructions, confidentiality, and security.
§3 — Documented instructions (Art. 28(3)(a)). TensorPlane processes personal data only on the Customer's documented instructions, including on international transfers, unless required by Union or Member State law; in that case it informs the Customer before processing unless the law prohibits it. The Agreement, this DPA, and the Customer's configuration constitute the complete documented instructions. TensorPlane informs the Customer if, in its opinion, an instruction infringes data-protection law.
§4 — Confidentiality (Art. 28(3)(b)). Persons authorised to process the personal data are committed to confidentiality or under an appropriate statutory obligation.
§5 — Security of processing (Art. 28(3)(c) / Art. 32). TensorPlane implements the technical and organisational measures in Annex 2 to ensure a level of security appropriate to the risk.
Sub-processors (Art. 28(2) and (4)).
TensorPlane has the Customer's general authorisation to engage the sub-processors listed in Annex 3. It informs the Customer of any intended addition or replacement at least 30 days in advance [proposed; attorney to confirm], giving the Customer the opportunity to object on reasonable data-protection grounds.
TensorPlane imposes on each sub-processor, by written contract, data-protection obligations no less protective than those in this DPA, and remains fully liable for the sub-processor's performance.
Model providers reached under the Customer's own keys and contracts are the Customer's own controllers/processors, not TensorPlane sub-processors, in both scopes. Annex 1 and Annex 3 state this precisely — it is a defining feature of the product and must not be misdescribed.
Assistance, breach notice, and audits.
§7 — Data-subject rights (Art. 28(3)(e)). Taking into account the nature of the processing, TensorPlane assists the Customer, insofar as possible, in responding to requests to exercise data-subject rights under Chapter III of the GDPR.
§8 — Breach, security, DPIA (Art. 28(3)(f) / Arts. 32–36). TensorPlane notifies the Customer without undue delay and in any event within 48 hours after becoming aware of a personal-data breach affecting the Customer's data [proposed 48h so the Customer retains margin within its own Art. 33 72-hour deadline; attorney to confirm], with the information the Customer needs to meet its Article 33/34 obligations, plus assistance with DPIAs (Art. 35) and prior consultation (Art. 36) where applicable.
§9 — Audits (Art. 28(3)(h)). TensorPlane makes available the information necessary to demonstrate Article 28 compliance, and allows for and contributes to audits, subject to 30 days' prior written notice, no more than once per 12 months (and additionally after a personal-data breach or where a supervisory authority requires it), during business hours, under confidentiality, at the Customer's cost [proposed; attorney to confirm]. Available assurance includes each sub-processor's third-party security assurance reports where offered.
Return or deletion at end of processing (Art. 28(3)(g)).
At the Customer's choice, TensorPlane deletes or returns all personal data after the end of the services, and deletes existing copies unless Union or Member State law requires storage — notably the 10-year Czech retention of financial and tax records (VAT Act 235/2004; AML Act 253/2008), which is exempt from erasure for that period. The deletion/return period for non-retained classes is 30 days [proposed; attorney to confirm].
Today an account-deletion request is accepted — billing shutdown begins and sessions and source-control authority are revoked — but the erasure execution is not represented as automatic completion, because the erasure driver is currently dormant. This must not be described as automatic completion until that driver is activated or a documented interim deletion procedure is in place; otherwise the mechanism would be misdescribed. See Data retention for the acceptance-versus-completion distinction.
International transfers, liability, and precedence.
§11 — International transfers. Where personal data is transferred outside the EEA, the transfer is made under an appropriate Article 46 safeguard (Standard Contractual Clauses) or an adequacy decision. Scope A (vendor-hosted) asserts EU data residency, so intra-EEA processing is the design intent; any exception is listed in Annex 1 with its transfer mechanism. Onward transfers arise mainly from our operational suppliers — Stripe (billing), GitHub (vendor-hosted source control), and Cloudflare (transactional email) — each under the EU-US Data Privacy Framework where certified, otherwise EU Standard Contractual Clauses. [Attorney to confirm the basis per route.]
§12 — Liability, term, and precedence. Governed by the Agreement. [Cross-reference the Agreement's liability cap and term clauses; confirm no conflict with this DPA's §10 survival.]
Description of processing (select the applicable scope).
Scope A — Vendor-hosted (self-serve)
- Data subjects: the Customer's developers and end users whose personal data may appear in code, prompts, or repository content submitted for review; the Customer's administrators and billing contacts.
- Types of personal data: any personal data in Customer code, prompts, commit metadata, and repository content processed during review (Customer-determined; special categories arise only if the Customer's own content contains them —
[TODO: customer-dependent]); account identifiers, SSO identity, and billing contacts. - Nature / purpose: executing AI code review on EU-operated infrastructure in isolated, short-lived, credential-free sandboxes; metering; billing. Model calls use the Customer's own keys — those providers are the Customer's controllers/processors, not TensorPlane sub-processors.
- Retention: validated findings 30 days and review-history 90 days after the attempt; content-free security-audit events 365 days; content-free financial records 10 years (Czech VAT/AML); legal holds for the obligation's duration.
Scope B — Customer-operated (enterprise)
- Data subjects: the Customer's administrators, team members, and users referenced in licensing telemetry.
- Types of personal data — licensing telemetry only: customer code and model traffic never transit TensorPlane. The telemetry kinds are sign-in (SSO), entitlement and configuration refresh, heartbeats, revocation acknowledgements, signed usage records. Signed usage records are dimensioned by organisation, team, user, repository, project, model, provider, skill, task type, time, and include aggregate token counts used for attribution and licensing, never for billing.
- Nature / purpose: licensing, entitlement enforcement, and usage attribution for a platform the Customer operates on its own infrastructure.
- Residency: wherever the Customer deploys — the Customer's choice.
These two inventories are the single source of truth in the commercial model and are rendered from there; if the schema changes, this annex and that file change together.
Technical and organisational measures (Art. 32).
The following measures are implemented and tested — nothing aspirational is listed:
- Tenant isolation: forced PostgreSQL row-level security with a per-organisation policy, a transaction-bound tenant context, and a restricted application database role. Cross-tenant read/write and missing-context tests enforce it.
- Credential custody at rest: provider credentials are sealed before storage with AES-256-GCM under KMS-wrapped data-encryption keys; readback exposes only masked metadata.
- Access control: console access is authenticated with server-validated sessions and a WebAuthn second factor, with secure cookies, exact-origin and CSRF protection, and request-rate controls; tenant permissions cannot authorise staff operations.
- Audit: covered security-sensitive operations are recorded as redacted, append-only events that the application role cannot update or delete.
- Encryption in transit (stated subset): the production public API uses TLS ≥1.2; tenant-scoped HTTP egress requires HTTPS with certificate verification; the network-accessible custody seam requires mutual TLS.
Not claimed (not implemented, only partial, or gated — kept out of this Annex until shipped and verified): completed data erasure (execution gated — see §10); customer data export / portability (built as a core, not yet reachable); universal at-rest or universal in-transit encryption; continuously hash-linked or externally-witnessed audit; sandbox / guest isolation; backup / RPO-RTO guarantees. [Attorney + engineering to confirm this list against the deployed configuration before execution.]
Authorised sub-processors.
| Sub-processor | Purpose | Location | Safeguard |
|---|---|---|---|
| OVH SAS (France; parent OVH Groupe SAS) | Hosting of the vendor-hosted platform, control-plane data, and the data-export object store | EU (Gravelines / GRA) | Intra-EEA; Standard Contractual Clauses where a service transfers outside the EEA |
| Stripe Payments Europe, Limited (Ireland) | Payment processing and billing of our fees; also an independent controller for payment, fraud, and regulatory purposes | Ireland / US | Data Privacy Framework, then EU Standard Contractual Clauses (Data Transfers Addendum) |
| GitHub, Inc. (US; EU under Irish law) | Source-control integration (vendor-hosted mode only): repository content, identity, installation metadata, webhook payloads | US | Data Privacy Framework and/or EU Standard Contractual Clauses |
| Cloudflare | Transactional email (operator email Worker on Cloudflare Workers, delivered via Cloudflare Email Sending): recipient and sender addresses and message content | US | Data Privacy Framework, then EU Standard Contractual Clauses |
Not sub-processors: model providers reached under the Customer's own keys and contracts, whose calls travel under those keys. This is stated explicitly so the list is not read as conceding a data path the product does not have. See the customer-facing sub-processor list.
Questions about these documents?
These pages are the published rendering of our internal drafts and will change as attorney review completes. If your legal or procurement team needs a specific point clarified, contact us.