Data Processing Agreement - Tenaxis
Effective date: 8 June 2026
Version: 1.0
Preamble
This Data Processing Agreement ("DPA") is entered into between:
Controller:
The legal entity or individual ("Customer") that has agreed to the Tenaxis Terms of Service and whose details are set out in the Tenaxis account registration.
Processor:
4ATE90 B.V., trading as Tenaxis, a private limited company incorporated under Dutch law, registered with the Dutch Chamber of Commerce (KvK) under number 87875160, with its registered office at Breda, the Netherlands ("Tenaxis").
This DPA forms part of and supplements the Terms of Service between the Customer and Tenaxis (the "Agreement"). In the event of conflict between this DPA and the Agreement, this DPA shall prevail with respect to the subject matter of data protection.
1. Definitions
In this DPA the following terms have the meanings assigned below. Terms not defined here have the meaning given in the GDPR.
| Term | Meaning |
|---|---|
| GDPR | General Data Protection Regulation (EU) 2016/679 |
| Personal Data | Any information relating to an identified or identifiable natural person as defined in Art. 4(1) GDPR |
| Processing | Any operation or set of operations performed on Personal Data, as defined in Art. 4(2) GDPR |
| Data Subject | The natural person to whom Personal Data relates |
| Sub-processor | Any processor engaged by Tenaxis to process Personal Data on behalf of the Customer |
| Security Incident | Any accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data |
| Supervisory Authority | The Autoriteit Persoonsgegevens (AP) or any other competent data protection authority |
| SCCs | Standard Contractual Clauses adopted by the European Commission for transfers of personal data to third countries |
2. Roles of the Parties
2.1 Customer is the Controller. Customer determines the purposes and means of the Processing of Personal Data.
2.2 Tenaxis is the Processor. Tenaxis processes Personal Data solely on documented instructions from the Customer, as set out in this DPA and the Agreement.
2.3 By accepting the Terms of Service, the Customer provides documented instructions to Tenaxis to process Personal Data as necessary to provide the Service.
3. Subject Matter and Details of Processing
3.1 Purpose
Tenaxis processes Personal Data to provide the Tenaxis Microsoft 365 governance platform and related services as described in the Agreement.
3.2 Nature of Processing
The Service performs the following types of processing:
- Collection and storage of user identity data retrieved via the Microsoft Graph API
- Synchronisation of Microsoft 365 group and site membership
- Risk assessment based on access patterns and site configuration
- Automated notifications and access review workflows
- Audit logging of governance actions
- Reporting and data export
3.3 Categories of Data Subjects
Employees, contractors, guests and visitors of the Customer's organisation whose identities are managed within the Customer's Microsoft 365 environment.
3.4 Categories of Personal Data
| Category | Examples |
|---|---|
| Identity data | Full name (displayName), User Principal Name (UPN), Microsoft user ID |
| Contact data | Work email address |
| Organisational data | Job title (if available), department, group memberships, role within a site |
| Access data | Site permissions, assigned roles (Owner, Member, Visitor), SharePoint permission IDs |
| Account status | accountEnabled, account deletion status (for offboarding workflows) |
| Activity data | Timestamps of sync events, audit log entries of governance actions |
3.5 Special Categories of Data
Tenaxis does not intentionally process special categories of Personal Data (Art. 9 GDPR). Customer shall not upload or submit data falling into these categories via the Service.
3.6 Duration of Processing
Tenaxis processes Personal Data for the duration of the Agreement. Upon termination, Tenaxis will delete or return Personal Data in accordance with Clause 12.
4. Obligations of Tenaxis
Tenaxis shall:
4.1 Process Personal Data only on documented instructions from the Customer, including with regard to transfers of Personal Data to third countries, unless required to do so by EU or Member State law, in which case Tenaxis shall inform the Customer before processing, unless prohibited by law.
4.2 Ensure that persons authorised to process Personal Data are bound by confidentiality obligations or are under an appropriate statutory obligation of confidentiality.
4.3 Implement appropriate technical and organisational measures as required by Art. 32 GDPR (see Clause 7).
4.4 Assist the Customer in ensuring compliance with obligations under Art. 32–36 GDPR (security, breach notification, DPIAs, prior consultation), taking into account the nature of processing and information available to Tenaxis.
4.5 Assist the Customer, to the extent reasonably possible and taking into account the nature of the Processing, with fulfilling Customer's obligations to respond to Data Subject requests under Chapter III GDPR.
4.6 Make available all information necessary to demonstrate compliance with the obligations under Art. 28 GDPR and allow for and contribute to audits conducted by the Customer or a mandated auditor, subject to Clause 10.
4.7 Inform the Customer immediately if an instruction infringes the GDPR or other applicable data protection law.
5. Obligations of the Customer
Customer shall:
5.1 Ensure it has a valid legal basis under the GDPR for each Processing activity performed via the Service and, where required, has provided notice to and obtained consent from the relevant Data Subjects.
5.2 Ensure it has authority to connect its Microsoft 365 tenant to the Service and that the OAuth2 delegated and application permissions granted are lawful and appropriately consented.
5.3 Not instruct Tenaxis to process Special Categories of Personal Data.
5.4 Notify Tenaxis promptly of any changes to applicable law that affect the Processing.
6. Sub-processors
6.1 Current Sub-processors
Customer grants Tenaxis a general written authorisation to engage Sub-processors. Tenaxis's current list of Sub-processors is:
| Sub-processor | Country of incorporation | Data processing location | Safeguard | Purpose |
|---|---|---|---|---|
| Vercel, Inc. | USA | EEA (Frankfurt, aws-eu-central-1) | SCCs | Web application hosting |
| Railway Corp. | USA | EEA (EU region) | SCCs | Worker / background job hosting |
| Neon, Inc. | USA | EEA (Azure Germany West Central) | SCCs | PostgreSQL database hosting |
| Redis Cloud provider | USA / EEA | EEA | SCCs (if USA) | Job queue (BullMQ / Redis) |
| Resend, Inc. | USA | USA | SCCs | Transactional email delivery |
| ImprovMX | USA | USA | SCCs | Inbound email forwarding |
| Stripe, Inc. | USA | USA / EEA | SCCs | Payment processing (billing data only) |
| Microsoft Corporation | USA / EEA | USA / EEA | SCCs + adequacy decision | Authentication (OAuth2/OIDC) and integration with the Customer's Microsoft 365 environment; Microsoft acts as an independent controller or separate processor for its own M365 services under the Microsoft Product Terms |
6.2 Changes to Sub-processors
Tenaxis will provide the Customer with at least 30 days' prior written notice (via email or in-app notification) before adding or replacing any Sub-processor that processes Personal Data. If the Customer objects on legitimate grounds relating to data protection within the notice period, the parties shall negotiate in good faith. If no resolution is reached, either party may terminate the Agreement on written notice.
6.3 Sub-processor Obligations
Tenaxis shall impose data protection obligations on Sub-processors that are equivalent to those set out in this DPA, by contract or other legal act. Tenaxis remains liable to the Customer for any failure by a Sub-processor to fulfil its data protection obligations.
7. Security Measures
Tenaxis implements and maintains the following technical and organisational measures:
7.1 Access Control
- Role-based access control within the Service
- Multi-factor authentication available for admin accounts via Microsoft SSO
- Least-privilege principle applied to internal systems
7.2 Encryption
- All data in transit encrypted using TLS 1.2 or higher
- Personal data at rest encrypted using industry-accepted encryption standards (minimum AES-256 or equivalent, depending on the infrastructure layer)
- OAuth2 refresh tokens encrypted with AES-256-GCM before storage
7.3 Authentication and Session Management
- Session tokens signed with HMAC-SHA256 (HS256)
- Short-lived JWT tokens with tenant and user binding
- Secure, HTTP-only cookies with
SameSite=Strict
7.4 Infrastructure
- Hosted on cloud infrastructure with logical separation between customer tenants
- Automated backups with point-in-time recovery
- Network-level access controls
7.5 Monitoring and Incident Response
- Continuous security monitoring and anomaly detection
- Defined incident response procedure (see Clause 8)
- Audit logging of administrative actions
7.6 Software Development
- Dependency vulnerability scanning
- Code review process before production deployment
- No special categories of personal data handled in development environments
Tenaxis may update these measures over time, provided that updated measures do not materially reduce the overall level of protection.
8. Personal Data Breach Notification
8.1 Tenaxis shall notify the Customer without undue delay and, where feasible, within 24 hours of becoming aware of a Security Incident involving Personal Data processed on behalf of the Customer, so that the Customer has adequate time to fulfil its own statutory notification obligation to the Supervisory Authority within 72 hours.
8.2 The notification shall include, to the extent then known:
- A description of the nature of the Security Incident
- The categories and approximate number of Data Subjects concerned
- The categories and approximate number of Personal Data records concerned
- Likely consequences of the Security Incident
- Measures taken or proposed to address the Security Incident
8.3 Tenaxis shall provide further information as it becomes available. The notification does not imply admission of fault or liability.
8.4 Notifications shall be sent to the email address associated with the Customer's Tenaxis account. Customer is responsible for keeping this address up to date.
9. Data Subject Rights
9.1 Tenaxis provides Customer with tools to assist in fulfilling Data Subject requests (e.g. access, rectification, erasure, portability) to the extent technically feasible via the Service.
9.2 Tenaxis shall, upon Customer's written request, assist in fulfilling Data Subject rights that cannot be exercised through the Service itself, at a reasonable charge if the assistance requires significant effort.
9.3 If a Data Subject contacts Tenaxis directly, Tenaxis shall redirect the Data Subject to the Customer and shall not respond to the request without Customer's instruction, except where required by law.
10. Audits and Inspections
10.1 Tenaxis shall make available to the Customer, on request, all information necessary to demonstrate compliance with this DPA.
10.2 Tenaxis may satisfy audit rights by providing a current ISO 27001 certificate, SOC 2 Type II report, or equivalent third-party audit report, where available.
10.3 Where the Customer requires an audit beyond document review, such audit shall be:
- Conducted at the Customer's expense
- Limited to business hours with at least 30 days' prior written notice
- Conducted in a manner that does not disrupt Tenaxis's operations
- Conducted no more than once per calendar year, unless a Security Incident justifies an additional audit
10.4 Customer shall keep confidential all information obtained during audits.
11. International Data Transfers
11.1 Tenaxis will not transfer Personal Data outside the EEA without ensuring adequate safeguards.
11.2 Where Personal Data is transferred to Sub-processors in third countries, Tenaxis relies on:
- An adequacy decision by the European Commission; or
- Standard Contractual Clauses (SCCs) as adopted by the European Commission.
11.3 Tenaxis will inform the Customer of any intended cross-border transfers and the safeguard mechanism used.
12. Deletion and Return of Data
12.1 Upon termination or expiry of the Agreement, Tenaxis shall, at the Customer's written choice:
- Delete all Personal Data processed on behalf of the Customer; or
- Return a copy of Personal Data in a machine-readable format (CSV or JSON).
12.2 The Customer may exercise this right within 30 days of termination. After this period, Tenaxis will delete all Personal Data within 90 days of termination, unless longer retention is required by applicable law.
12.3 Tenaxis shall certify deletion in writing upon request.
13. Liability and Indemnification
13.1 Each party shall be liable to the other for direct losses arising from a breach of this DPA in accordance with the limitations set out in the Agreement.
13.2 If a third party (including a Data Subject or Supervisory Authority) holds Tenaxis liable for a Processing activity that is the Customer's responsibility, Customer shall indemnify Tenaxis for any losses, fines, penalties and legal costs arising from that claim.
13.3 If a third party holds Customer liable for a Processing activity that is Tenaxis's responsibility as Processor, Tenaxis shall indemnify Customer for any losses, fines, penalties and legal costs arising from that claim.
14. Term and Termination
14.1 This DPA commences on the date the Customer accepts the Terms of Service and remains in force for as long as Tenaxis processes Personal Data on behalf of the Customer.
14.2 This DPA terminates automatically upon termination or expiry of the Agreement, subject to the data deletion obligations in Clause 12.
15. General
15.1 Order of precedence. In the event of conflict between this DPA and the Agreement, this DPA prevails with respect to data protection.
15.2 Governing law. This DPA is governed by Dutch law. Any disputes shall be submitted to the competent court in the district where Tenaxis has its registered office.
15.3 Amendments. Tenaxis may update this DPA to reflect changes in law or guidance from Supervisory Authorities, with 30 days' notice to the Customer.
15.4 Severability. If any provision of this DPA is held invalid, the remaining provisions continue in full force.
Annex A - Details of Processing (Summary)
| Field | Detail |
|---|---|
| Controller | Customer (name and details as per Tenaxis account) |
| Processor | 4ATE90 B.V., trading as Tenaxis |
| Purpose | Provide Microsoft 365 governance platform services |
| Nature | Collection, storage, synchronisation, risk analysis, reporting, notification |
| Data subjects | Employees, contractors, guests and visitors in Customer's M365 environment |
| Personal data categories | Identity, contact, organisational, access, account status, activity data |
| Special categories | None |
| Processing duration | Duration of Agreement + 90 days |
| Location of processing | EEA (primary); sub-processors may process in USA under SCCs |
Contact
Processor - Data Protection Contact:
4ATE90 B.V., trading as Tenaxis
Breda, Netherlands
The Netherlands
KvK: 87875160
Email: privacy@tenaxis.nl