Skip to content
Self-hosted or hosted: Compare the two

Legal

Data processing agreement

Last updated 26 September 2026

Draft for review. This document has not yet been reviewed by a solicitor and may change before Tenvara is generally available.

This data processing agreement ("DPA") forms part of the terms of service between Tenvara and the customer ("you") and applies where Tenvara hosts a Tenvara instance for you. It sets out the terms required by Article 28 of the UK GDPR and, where it applies, the EU GDPR. It does not apply to self-hosted instances, because Tenvara does not process the data in them.

1. Parties and roles

1.1 The parties

  • Processor: [Company legal name, company number and registered office to be confirmed] ("Tenvara", "we", "us").
  • Controller: the customer named in the Order ("you").

1.2 Roles

For personal data in your hosted instance ("Customer Personal Data"), you are the controller and we are your processor. Where you use Tenvara to provide managed services to your own clients and act as their processor, you are the processor and we are your subprocessor. In that case, you confirm that your instructions to us are authorised by your clients, and references in this DPA to your obligations as controller apply to you as their processor in the same way.

We act as an independent controller only for the account, billing and licensing data described in our privacy notice, which this DPA does not cover.

1.3 Definitions

"Data Protection Law" means the UK GDPR, the Data Protection Act 2018, the Privacy and Electronic Communications Regulations 2003 and, where applicable, the EU GDPR and national laws implementing it. Terms such as "controller", "processor", "data subject", "personal data breach" and "processing" have the meanings given in Data Protection Law. Capitalised terms not defined here have the meaning given in the terms of service.

2. Processing on your instructions

2.1 Documented instructions

We will process Customer Personal Data only on your documented instructions, including with regard to international transfers, unless the law requires otherwise, in which case we will tell you before processing unless the law prohibits it. Your instructions are this DPA, the terms of service, your configuration and use of the Service, and any further written instructions we agree.

2.2 Unlawful instructions

We will tell you promptly if we believe an instruction breaches Data Protection Law. We may suspend the affected processing until you confirm or change the instruction.

2.3 Your responsibilities

You are responsible for the lawfulness of the processing, including having a lawful basis, giving transparency information to data subjects, and having the right to connect the devices, Microsoft 365 tenants and other systems you manage through the Service.

2.4 AI features

Where you enable AI features with your own Anthropic API key, the content sent to Anthropic is transferred on your instruction under your own agreement with Anthropic. Anthropic is not our subprocessor for these features. You choose which features are enabled and which of your clients are excluded.

3. Confidentiality of personnel

We will ensure that everyone we authorise to process Customer Personal Data is bound by a duty of confidentiality, receives appropriate data protection and security training, and has access only to the extent needed for their role.

4. Security

We will implement and maintain the technical and organisational measures in Annex 2, which are designed to ensure a level of security appropriate to the risk, as required by Article 32. We may update these measures over time, provided that the overall level of security is not reduced.

5. Subprocessors

5.1 General authorisation

You give us general authorisation to engage the subprocessors listed in Annex 3. We will impose data protection obligations on each subprocessor by written contract that are no less protective than those in this DPA, and we remain fully liable to you for their performance.

5.2 Changes

We will give you at least 30 days' notice before adding or replacing a subprocessor, by email to your account owner and by updating Annex 3. You may object on reasonable data protection grounds within that period. If you object, we will discuss your concerns in good faith, and if we cannot resolve them, you may terminate the affected part of the Service and receive a pro rata refund of prepaid fees for the unused period.

6. Assistance

6.1 Data subject requests

Taking into account the nature of the processing, we will assist you by appropriate technical and organisational measures in responding to requests from data subjects to exercise their rights. Tenvara lets you find, export, correct and delete records yourself. If we receive a request directly that relates to Customer Personal Data, we will pass it to you without undue delay and will not respond to it except on your instructions.

6.2 Other assistance

We will give you reasonable assistance with data protection impact assessments, prior consultation with supervisory authorities and your security obligations, taking into account the information available to us. We may charge reasonable fees for assistance beyond what the Service and our documentation already provide.

7. Personal data breaches

We will notify you without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data. Our notice will describe, as far as we then know, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. We will provide further information as it becomes available, take reasonable steps to contain and remedy the breach, and support you in meeting your own notification obligations. Our notification is not an admission of fault.

8. Deletion and return

At the end of the Service, you can export Customer Personal Data as set out in section 13 of the terms of service. After the 30-day export period, we will delete Customer Personal Data from the live instance, and it will be removed from our backups within a further 35 days as they expire, unless the law requires us to keep it. We will confirm deletion in writing on request.

9. Audits and information

We will make available all information reasonably necessary to demonstrate compliance with Article 28, including our current security documentation and summaries of independent assessments where available. If this is not enough to demonstrate compliance, or a supervisory authority requires it, you may carry out an audit (or have an independent auditor bound by confidentiality do so) no more than once in any 12 months, on at least 30 days' written notice, during business hours and in a way that does not disrupt our operations or compromise other customers' data. Each party bears its own costs, unless the audit reveals a material breach of this DPA by us.

10. International transfers

We will not transfer Customer Personal Data outside the UK or the European Economic Area, or allow a subprocessor to do so, unless the transfer is protected by an appropriate safeguard under Data Protection Law, as described in Annex 4.

11. Liability and term

Each party's liability under this DPA is subject to the limitations in section 15 of the terms of service. This DPA lasts for as long as we process Customer Personal Data for you. If there is a conflict between this DPA and the terms of service on the processing of personal data, this DPA prevails. This DPA is governed by the law of England and Wales, except where the Standard Contractual Clauses require otherwise.

Annex 1: Details of processing

Item Details
Subject matter Hosting and operating a dedicated Tenvara instance for you
Duration The Subscription Term, plus the 30-day export period and backup expiry in section 8
Nature and purpose Storage, organisation, retrieval, transmission, analysis and deletion of data as needed to provide the Service: professional services automation, remote monitoring and management, remote access, patching and software deployment, backup and restore, Microsoft 365 management, security monitoring and detections, documentation and credential storage, chat, automation, scheduling, reporting and licence sync, and support you request
Frequency Continuous

Categories of data subjects

  • Your staff and contractors who use the Service.
  • Your clients' staff and contacts, including users of the customer portal and chat.
  • End users of devices and Microsoft 365 tenants you manage or protect.
  • Website visitors who use a chat widget you embed.
  • Any other individuals whose personal data is contained in data you back up or store in the Service.

Categories of personal data

  • Identity and contact details: names, job titles, email addresses, phone numbers.
  • Account data: user names, roles, sign-in history, two-factor settings.
  • Ticket, chat, time, scheduling and documentation content, including attachments.
  • Device and inventory data: hostnames, serial numbers, signed-in user names, IP and MAC addresses, installed software, performance metrics.
  • Microsoft 365 directory data: users, groups, licences, mailbox settings, sign-in and audit logs.
  • Security event data: log records from devices, Microsoft 365 and network devices, which may include user names, IP addresses and activity.
  • Remote access session history: who connected to which device, when and for how long.
  • Stored credentials in the vault (always encrypted).
  • Backup content: the contents of backed up files, mailboxes, OneDrive, SharePoint and Teams, which may contain any kind of personal data.

Special category data

We do not intend to process special category data. However, backup content, tickets and documentation may contain it if you or your clients store it there. You are responsible for identifying any such data and any additional safeguards it requires.

Annex 2: Technical and organisational measures

Area Measures
Tenant isolation Each customer has a dedicated Tenvara instance with its own database. Customer Personal Data is never stored in a database shared with other customers. Backup data is stored in separate repositories per client and source
Encryption in transit All connections to the web application, API, customer portal and agents use TLS. The agent authenticates to the service with its own key pair established at enrolment, and commands sent to agents are digitally signed and checked before they run
Encryption at rest Secrets (vault passwords, two-factor seeds, licence keys, identity provider and integration secrets, API keys) are encrypted individually with AES-256-GCM under keys derived from the instance's application key. Backup repositories are encrypted with per-repository keys. Instance backups and storage volumes are encrypted
Access control Role-based access with per-module permission levels, a separate permission for revealing credentials, and administrator-only settings. Our own staff access to hosted instances is limited to named engineers, for support and operations only, and is logged
Authentication Two-factor authentication (TOTP) which you can require for administrators or everyone, single sign-on with Microsoft Entra ID, Google Workspace, OpenID Connect or SAML, break-glass administrator accounts protected by two-factor authentication, and short-lived access tokens with rotating refresh tokens and reuse detection. Two-factor authentication is mandatory for Tenvara staff
Audit logging An activity log of changes to records, every reveal of a stored credential, every remote access session, script run and Microsoft 365 change (with undo where possible), and administrator approvals for high-risk actions
Availability and resilience Daily encrypted backups of each instance, kept for at least 30 days and stored separately from the primary database, with periodic restore tests. The agent queues data on the device during outages and resends it when the service returns
Application security Code review, automated tests on every change, dependency updates, signed agent releases (code signed and, on macOS, notarised), rate limiting, and protection against common web attacks including cross-site request forgery
Operational security Security patches applied to hosting infrastructure promptly, least-privilege access to infrastructure, monitoring and alerting, and a documented incident response process
Data minimisation AI features are off unless you enable them with your own key, and let you exclude clients and control what leaves the instance. Stored secrets are never returned in full through the API except on an explicit, logged reveal
Personnel Confidentiality obligations, background checks where lawful, and security and data protection training for staff with access to customer data
Deletion Instance data deleted at the end of the Service as set out in section 8, and removed from backups as they expire

Annex 3: Subprocessors

Subprocessor Purpose Data processed Location
[Hosting provider to be confirmed] Hosting of customer instances, databases, backup storage and instance backups All Customer Personal Data [Location to be confirmed]
Cloudflare, Inc. DNS, content delivery and proxying of traffic to hosted instances, protection against attacks Data in transit, including IP addresses and request metadata Global network
Microsoft Corporation Sending email from the Service (notifications, ticket replies where you use Tenvara's mail service rather than your own mailbox) Email content and addresses United Kingdom, European Economic Area and United States
Stripe, Inc. and Stripe Payments Europe, Ltd. Payments and billing for your subscription Billing contact details only, no data from inside your instance United States, Ireland and other locations

Services you connect yourself, such as your own Microsoft 365 tenants, Pax8, Partner Center, Xero, SMS providers, security consoles and Anthropic, are not our subprocessors. Data sent to them is transferred on your instruction under your own agreements with those providers.

Annex 4: International transfers

Transfers from the UK

Where Customer Personal Data is transferred from the UK to a country without UK adequacy regulations, the transfer is made under:

  • the UK Extension to the EU-US Data Privacy Framework, where the recipient in the United States is certified; or
  • the International Data Transfer Addendum to the EU Standard Contractual Clauses issued by the Information Commissioner, or the International Data Transfer Agreement.

Transfers from the European Economic Area

Where you are subject to the EU GDPR and Customer Personal Data is transferred to a country without an adequacy decision, the transfer is made under:

  • the EU-US Data Privacy Framework, where the recipient is certified; or
  • the Standard Contractual Clauses approved by Commission Implementing Decision (EU) 2021/914, Module Two (controller to processor) or Module Three (processor to processor) as appropriate, which are incorporated into this DPA by reference.

Transfers from the European Economic Area to Tenvara in the UK rely on the European Commission's adequacy decision for the United Kingdom.

Standard Contractual Clauses options

Where the Standard Contractual Clauses apply between us: clause 7 (docking) applies; for clause 9, option 2 (general authorisation) applies with the notice period in section 5.2; the optional wording in clause 11 does not apply; for clauses 17 and 18, the law and courts of Ireland apply; Annex I is completed by Annex 1 of this DPA, Annex II by Annex 2 and Annex III by Annex 3. [Solicitor to confirm the governing law and forum elections for the Standard Contractual Clauses.]

Supplementary measures

We carry out transfer risk assessments for each restricted transfer and apply supplementary measures where needed, including encryption in transit and at rest, and challenging any request from a public authority for access to Customer Personal Data that we consider unlawful. We will tell you about any such request unless the law prohibits it.