Last updated: 2026-09-08
This Data Processing Addendum ("DPA") forms part of the Terms of Service between Talea Work AB ("Tiendo", "Processor") and the customer ("Customer", "Controller") and applies where Tiendo processes personal data on the Customer's behalf.
1. Roles
The Customer is the controller of personal data it submits to or generates through the Service, including information about its workers. Tiendo is the processor and acts only on the Customer's documented instructions, which are given through use of the Service and through the Terms of Service.
2. Subject matter and duration
Tiendo processes personal data for the duration of the Customer's subscription and for the limited export and deletion period afterwards described in the Terms.
3. Nature and purpose of processing
Hosting, storing, structuring, translating, transmitting and displaying content the Customer submits, and recording confirmations that a worker has indicated they read and understood a routine.
4. Categories of data subjects
The Customer's personnel, including managers and frontline workers.
5. Types of personal data
Names as entered by the Customer or typed by a worker; preferred reading language; routines assigned and confirmed with date and time; questions submitted through the in-product question feature; and any personal data the Customer chooses to include in the content it creates.
The Service is not designed for special categories of personal data, and the Customer agrees not to submit them.
6. Tiendo's obligations
Tiendo will:
a) process personal data only on the Customer's documented instructions, including for transfers, unless required otherwise by law, in which case it will inform the Customer unless prohibited from doing so; b) ensure persons authorised to process the data are bound by confidentiality; c) implement appropriate technical and organisational security measures, including encryption in transit and at rest, access controls and provider vetting; d) not access customer content except where necessary to provide support at the Customer's request, to maintain the Service, or where legally required; e) not use personal data for its own purposes, and not sell, license, publish or disclose it, and not use it to train artificial intelligence models; f) assist the Customer, taking into account the nature of processing, in responding to data subject requests and in meeting its obligations regarding security, breach notification and impact assessments; g) notify the Customer without undue delay after becoming aware of a personal data breach; h) at the Customer's choice, delete or return personal data at the end of the provision of services, and delete existing copies unless required to retain them by law; i) make available information necessary to demonstrate compliance with this DPA and allow for audits, which may be satisfied by providing relevant documentation.
7. Sub-processors
The Customer gives general authorisation for Tiendo to engage sub-processors. Tiendo imposes data protection obligations on each sub-processor no less protective than this DPA and remains responsible for their performance.
Current sub-processors:
| Sub-processor | Purpose | Processing location |
|---|---|---|
| Stripe | Payment processing | US / EU |
| Supabase | Database and authentication hosting | EU |
| Netlify | Website and application hosting | US / EU |
| Anthropic | AI structuring and translation | US |
| Resend | Service email delivery (sign-in links, billing reminders) | US |
Tiendo will give notice of intended changes to this list. The Customer may object on reasonable data protection grounds, and if the objection cannot be resolved the Customer may terminate the affected part of the Service.
8. International transfers
Where personal data is transferred outside the EEA or UK, the transfer is made under appropriate safeguards, including the European Commission's Standard Contractual Clauses, which are incorporated into this DPA by reference.
9. Customer's obligations
The Customer warrants that it has a lawful basis for the personal data it submits, that it has provided any required notices to its workers, and that its instructions comply with applicable data protection law.
10. Liability
Liability under this DPA is subject to the limitations in the Terms of Service, except where applicable law does not permit that limitation.
11. Conflict
Where this DPA conflicts with the Terms of Service in relation to processing of personal data, this DPA prevails.
Contact: hello@tiendo.co