Data Processing Addendum
Version 2026-10-01. Operated by Teb, an online service operated from Israel by its individual owner; paid purchases are sold and invoiced by Freemius, Inc. as merchant of record.
This Data Processing Addendum (“DPA”) applies when a customer subject to the GDPR, UK GDPR or similar law (“Customer”) uses Teb to process personal data for which the Customer is the controller. It forms part of the Terms of Service. No signature is required; the Customer may request a countersigned copy at support@tebhq.com.
1. Roles and scope
For Handoff content submitted by the Customer or its users, the Customer is the controller and Teb is the processor. For account, billing and usage data, Teb is an independent controller as described in the Privacy Policy.
2. Processing details
- Subject matter: storage and retrieval of conversation Handoffs.
- Duration: the term of the Customer’s use of the Service plus the retention periods in the Privacy Policy.
- Nature and purpose: hosting, encryption, transmission to AI tools the Customer connects.
- Data subjects: the Customer’s users and any persons mentioned in Handoffs.
- Categories: any personal data the Customer’s users include in Handoffs; account identifiers.
3. Processor obligations
Teb will:
- process personal data only on the Customer’s documented instructions, which are the Terms, this DPA and use of the Service’s features, unless required by law (in which case we will inform the Customer unless prohibited);
- ensure persons authorized to process the data are bound by confidentiality;
- implement the technical and organizational measures described on the Security page, including encryption at rest and in transit, access control, logging and backups;
- engage sub-processors only as listed at /legal/subprocessors, under written terms no less protective than this DPA, with 14 days’ notice of changes and a right to object;
- assist the Customer, taking into account the nature of the processing, in responding to data-subject requests and in meeting obligations under GDPR articles 32 to 36;
- notify the Customer without undue delay, and in any case within 48 hours, after becoming aware of a personal-data breach affecting Customer data;
- delete or return all personal data at the end of the Service (the export and delete functions in the dashboard satisfy this), unless law requires retention;
- make available information necessary to demonstrate compliance and allow audits by the Customer or an independent auditor, no more than once a year and on 30 days’ notice, at the Customer’s cost.
4. International transfers
Customer data is stored in the EU. Where sub-processors transfer data outside the EU/UK, the transfer is covered by the EU-U.S. Data Privacy Framework or the Standard Contractual Clauses (Module 3, processor-to-processor) incorporated by reference, with the UK Addendum where applicable.
5. Liability
Liability under this DPA is subject to the limitations in the Terms of Service, except where law provides otherwise.
6. Precedence
In case of conflict between this DPA and the Terms, this DPA prevails for the processing of Customer personal data.