Data Processing Addendum
Version 1.0 · August 10, 2026
This Addendum forms part of the agreement between Tidela and the customer for use of the Tidela service. It sets out how Tidela handles personal data that the customer puts into Tidela. If your organisation needs a signed copy, email security@tidela.ai and we'll send one over — we sign this as written for most customers.
1. Roles
The customer is the controller of the personal data it puts into Tidela — its contacts, its deals, its correspondence. Tidela is the processor, acting on the customer's documented instructions. Using the Tidela service in the ordinary way constitutes those instructions. Where Tidela engages another company to help deliver the service, that company is a subprocessor and Tidela remains responsible for its performance.
2. Subject matter, duration, and scope
Subject matter: provision of the Tidela sales platform, including AI-assisted capture, drafting, and analysis of the customer's own CRM data.
Duration: for the term of the agreement, plus the deletion window in section 9.
Categories of data subject: the customer's employees and authorised users; the customer's own customers, prospects, and business contacts; the customer's partners where the partner portal is used.
Categories of personal data: business contact details (name, work email, phone, employer, job title), records of business communications the customer captures or syncs (email, meeting notes, call notes), CRM activity and pipeline records, and account and authentication data for the customer's users.
Special categories: Tidela is not designed for and should not be used to process special categories of personal data as defined by GDPR Article 9, nor protected health information, payment card data, or government identifiers.
3. Tidela's obligations
Tidela will: process personal data only on the customer's documented instructions, including for international transfers, unless required otherwise by law; ensure that personnel with access to personal data are bound by confidentiality; implement the technical and organisational measures described in section 4; not sell personal data, and not use one customer's data to provide a service to any other customer; and not use customer personal data to train machine-learning models, and permit no subprocessor to do so.
4. Security measures
Tidela maintains technical and organisational measures appropriate to the risk, including: encryption of data in transit and at rest; logical isolation of each customer workspace, with every data access scoped to a single workspace; role-based access control enforced server-side across the application, the API, and the AI layer; single sign-on over SAML 2.0 or OIDC, SCIM provisioning and deprovisioning, and multi-factor authentication available to every customer; encryption of stored credentials and integration secrets at the application layer; an audit log of authentication, permission, configuration, export, and administrative events, exportable by the customer; least-privilege administrative access within Tidela; and secure software development practices including periodic security review. A fuller description is published at tidela.ai/enterprise-security and in Tidela's security review packet.
5. Subprocessors
The customer gives general authorisation for Tidela to engage subprocessors. The current list is published at tidela.ai/legal/subprocessors. Tidela imposes data protection obligations on each subprocessor no less protective than those in this Addendum, and remains liable for their performance. Tidela will give notice of an intended new subprocessor that processes customer records before it begins processing; customers who have asked to be notified receive it by email. If the customer reasonably objects on data protection grounds, the parties will work in good faith to resolve it, and failing that the customer may terminate the affected service.
6. Assistance to the customer
Tidela will assist the customer, taking into account the nature of the processing, in responding to data subject requests to access, correct, delete, restrict, or port personal data. Most such requests can be fulfilled by the customer directly, using Tidela's own search, edit, export, and delete functions. If a request reaches Tidela directly, Tidela will forward it to the customer rather than answer it, unless legally required to do otherwise. Tidela will also provide reasonable assistance with data protection impact assessments and with consultations with a supervisory authority.
7. Personal data breach
Tidela will notify the customer without undue delay, and in any event within 72 hours, of becoming aware of a personal data breach affecting the customer's personal data. The notification will describe what is known: the nature of the breach, the categories and approximate volume of data and data subjects involved, the likely consequences, and the measures taken or proposed. Where the full picture is not yet available, Tidela will notify with what is known and update as the investigation proceeds rather than delay the first notice.
8. Audits and information
Tidela will make available the information reasonably necessary to demonstrate compliance with this Addendum, including its security review packet and written responses to the customer's security questionnaire. Where that is not sufficient for the customer's regulatory obligations, Tidela will accommodate a reasonable audit, no more than once per year absent a breach or a regulator's requirement, on reasonable notice, during business hours, subject to confidentiality, and scoped so as not to compromise other customers' data or the security of the service.
9. Return and deletion
The customer may export its data at any time during the term using Tidela's export functions. On termination, and at the customer's choice, Tidela will return or delete the customer's personal data. Absent a contrary instruction, Tidela will delete customer personal data from live systems within 30 days of termination, and from backups within the ordinary backup rotation thereafter, except where retention is required by law.
10. International transfers
Tidela hosts customer data in the United States. Where the customer transfers personal data subject to European or United Kingdom data protection law, the parties will put in place the applicable Standard Contractual Clauses or UK International Data Transfer Addendum, which are incorporated by reference and, in the event of conflict, take precedence over this Addendum. Tidela's data model supports regional data residency; if residency in a particular jurisdiction is a requirement for your organisation, talk to us before signing rather than after.
11. Order of precedence
In the event of a conflict, the Standard Contractual Clauses prevail over this Addendum, and this Addendum prevails over the rest of the agreement with respect to the processing of personal data.
Contact
Privacy and data protection questions, signature requests, and subprocessor notifications: security@tidela.ai. Tidela is a product of Surf and Sand Consulting, LLC (Florida, United States).
Related: Enterprise Security · Subprocessors · Privacy policy