Legal

Data processing agreement

Tessera acts as processor for the content you store. This page summarises the terms of our Article 28 agreement; a signature-ready copy is available on request.

Draft — not yet in force

This document is a working draft published for transparency. It has not completed legal review, is not incorporated into any agreement, and creates no rights or obligations. The definitive version will be published before general availability. For terms you can rely on today, contact legal@PLACEHOLDER_DOMAIN.example.

What the agreement covers

Subject matter & durationArt. 28(3)
Processing of customer content for the purpose of providing distributed object storage, for the duration of the service agreement.
Nature & purposeArt. 28(3)(a)
Storage, retrieval, deletion, integrity verification, and repair of encrypted objects. No other processing occurs — no analysis, no indexing, no derivation.
Processing on instruction onlyArt. 28(3)(a)
We process only on your documented instruction, which for content means your API calls. We notify you if an instruction appears to us to conflict with data protection law.
ConfidentialityArt. 28(3)(b)
Personnel with access are bound by confidentiality obligations that survive the engagement.
Security measuresArt. 32
Client-side encryption before transmission, fragmentation across independent providers with no provider holding a reconstructable portion, integrity verification by Merkle root, signed and expiring request authentication, tenant isolation, encrypted control-plane storage, and continuous repair. Described in full on our security page.
SubprocessorsArt. 28(2), 28(4)
General authorisation with a published list and 30 days notice of additions affecting personal data, with a right to object. Each subprocessor is bound by equivalent obligations.
Data subject rightsArt. 28(3)(e)
We assist you in responding to requests. Because content is encrypted before it reaches us, we cannot locate a data subject within content and will route such requests to you.
Breach notificationArt. 33(2)
Notification to you without undue delay after becoming aware, with the information available at that time and updates as the investigation proceeds.
Audit & informationArt. 28(3)(h)
On request we provide our security documentation, completed CAIQ, and infrastructure audit reports. On-site or third-party audit rights are agreed on the Enterprise tier.
Deletion & returnArt. 28(3)(g)
On termination, content is deleted from the manifest on your instruction or at the end of the agreed export window, and underlying shards cease to be retained as storage contracts lapse.
International transfersCh. V
Standard Contractual Clauses are incorporated where applicable, with a transfer impact assessment available on request.

Obtaining a signed copy

Email privacy@PLACEHOLDER_DOMAIN.example with your legal entity name and address, and we will return a copy for signature. We can execute either our DPA or yours; if yours, expect us to redline anything that asserts capabilities we do not have.