Your organisation decides why personal information is used in its workspace. Tellenze helps you manage that information on your instructions. This draft sets out the proposed rules for that relationship.
This is version 2026-10-10.draft-1 for review. Reading this page, joining the waitlist or opening a workspace does not sign this agreement. The correct parties, their authority, the service agreement and the annexes must be confirmed before it is put into effect.
At a glanceName the people or organisations responsible before agreeing the document.
The customer is the organisation identified in Annex D. In the usual workspace relationship, the customer is the controller: it decides the purposes and essential ways in which personal information is used. The confirmed Tellenze service provider is the processor: it handles that information for the customer under this agreement.
If the customer is itself a processor for another controller, it must have authority to appoint Tellenze and pass on the controller's instructions. The parties will record that processing chain in Annex D. Their actual activities determine their roles; a label in an invoice or this draft does not change them.
João Pedro Marques Morais operates Tellenze. The owner-provided business record displays Xolo Go OÜ - João Pedro Marques Morais, Estonia Partnership, registry code 14717109 and VAT number EE102156920, with Paju tn 1a, 50603 Tartu, Tartu Maakond, Estonia. These are business-record details for review, not a statement that this address is João's personal address, a hosting location or the address of a separate Tellenze company.
Xolo's published terms describe a contractual partnership without its own legal personality and distinguish the professional's work from Xolo's administrative role. The executed service contract and any separate DPA must establish who is bound and in what capacity. This draft does not appoint Xolo as a controller, processor, subprocessor or hosting provider.
For this draft, you and customer mean the confirmed customer; we and Tellenze mean the confirmed service processor. Contact [email protected] about this agreement. Annex D must also identify the authorised instruction, incident and privacy contacts for both parties.
At a glanceThe agreement covers processing for your organisation, with separate roles for other activities.
Customer personal data means information about an identified or identifiable person that we process on your behalf when providing the agreed Tellenze services. It can be in account records, work items, comments, documents, attachments, forms, reviews, integration content or AI requests. Annex A narrows these examples to your actual use.
Processing means using personal data in any way, including receiving, storing, reading, changing, sharing, exporting or deleting it. A personal data breach is a security event that causes accidental or unlawful loss, destruction, change, disclosure or access. A subprocessor is another provider that we appoint to process customer personal data for the service.
This agreement applies only to processing for the customer. Activities carried out for our own separate purposes, such as responding to public website enquiries or managing our business administration, need their own role, legal basis and privacy information. The Privacy notice explains the proposed distinction. A billing or security activity must not be treated as customer processing simply because it relates to the same account.
The service description, enabled features, workspace identifiers and period of service must be recorded in Annex A. A public tool room or a customer-connected provider is not automatically included in the workspace agreement; the parties must identify any additional processing they intend to cover.
At a glanceThe data-processing terms govern the data matters they address.
When executed, this agreement and its completed annexes form part of the service agreement identified in Annex D. If the two conflict on the processing of customer personal data, these data-processing terms take priority for that issue. Other commercial matters stay under the agreed service contract.
Mandatory law and any applicable, properly completed international-transfer standard contractual clauses take priority over conflicting contract terms. Nothing here limits a person's statutory data-protection rights or the powers of a supervisory authority.
The version shown on this website is a review copy. A later website edit does not silently replace an executed agreement or approve a new provider. The parties must keep a record of the version and annexes they actually agree.
At a glanceWe use customer personal data for the agreed service and on documented instructions.
We will process customer personal data only on your documented instructions, including instructions about disclosures and transfers. The completed agreement, agreed service settings and actions by people you authorise can form those instructions within the recorded scope. General requests to improve our business are not permission to reuse workspace personal data for a separate purpose.
You will identify who can give instructions and keep those permissions current. We may verify a person's authority before carrying out an instruction, particularly an export, access change or deletion. Additional requests must be documented so both parties understand the affected information, purpose and action.
If we believe an instruction breaches the GDPR or other applicable EU or Member State data-protection law, we will tell you immediately. We will pause the disputed action and work with you on a lawful instruction. We will also tell you if a requested change needs security or service changes before it can be carried out.
If EU or Member State law binding on us requires processing outside your instructions, we will tell you about that requirement before the processing, unless the law prohibits notice for important public-interest reasons. We will restrict the processing to what that law requires and document the basis.
At a glanceAccess must be authorised, limited and covered by confidentiality duties.
We will allow access to customer personal data only to people who need it for the agreed work. Before they process it, they must be bound by a confidentiality commitment or an appropriate legal duty of confidentiality. Those duties continue after their access or work ends.
We will give authorised people instructions for handling customer data and review their access when their work or responsibilities change. Administrative or support access must have a defined purpose and must not be used to browse customer content without that purpose.
You control your own members, connected agents, shared links and integration permissions. Access you grant to someone outside your organisation does not make that person our staff or subprocessor. Both parties must protect their credentials and notify the other of a relevant access concern.
At a glanceThe measures must fit the information, the service and the risk to people.
We will implement and maintain appropriate technical and organisational measures for the agreed processing. The assessment must consider the information involved, possible harm to people, current technology and the cost of implementation. It must cover confidentiality, integrity, availability, recovery and regular assessment of the measures.
Annex B records the measures applicable to your service and points to the Security measures page. That page distinguishes application controls observed in the current implementation from operational measures that still need confirmation. Unconfirmed measures must be completed and reviewed before they are relied on in an executed agreement.
We may improve or replace a measure as the service changes, provided the overall protection for the agreed processing is not reduced. We will tell you about a material change that affects your assessment or instructions. A significant change to the processing may require updated annexes.
We will not treat the use of encryption, a provider's certificate or a successful software test as proof that every security risk is covered. You remain responsible for assessing whether the agreed service and measures fit your intended use.
At a glanceOther processors need written approval and a useful opportunity to object to changes.
We will not appoint a subprocessor for customer personal data without your prior specific or general written authorisation. Annex C must record which approach the parties select and the initial providers covered. The provider inventory on this website is a draft discovery record; it is not your authorisation.
If you give general written authorisation, we will notify your agreed contact before adding or replacing a subprocessor. The notice will identify the provider, its task, relevant data, processing and access locations, safeguards and intended start. The agreed procedure must give you enough information and time to raise a data-protection objection before the change affects your data.
We will discuss an objection in good faith and consider a suitable alternative, additional protection or a way to stop the affected processing. We will not treat silence on an incomplete notice as approval. If the parties cannot resolve the issue, the affected processing must not continue through the disputed new provider; the parties will agree how to suspend or end that part of the service under the applicable contract.
For specific authorisation, we will obtain written approval for the proposed appointment before it processes customer personal data. Annex C must record the notice method and any agreed notice or objection period; this draft supplies no assumed number of days.
At a glanceAppointing another provider does not remove our processing obligations.
We will assess whether a proposed subprocessor can provide appropriate protection for its part of the processing. We will bind it through a written contract to the applicable data-protection obligations in this agreement, including instructions, confidentiality, security, assistance and deletion or return.
We remain responsible to you for the subprocessor's performance of those obligations. We will maintain the agreed provider schedule and obtain information needed to support customer oversight, incidents, rights requests and changes in processing.
Where appropriate, we will provide relevant contract or assurance information so you can assess the appointment. Information may be redacted to protect unrelated confidential data, but redaction must not prevent you from understanding the safeguards or exercising the oversight rights in this agreement.
At a glanceRecord where data is stored or accessed and the lawful basis for each relevant transfer.
We will follow your documented transfer instructions and the applicable rules for international transfers. Annex C must record storage, processing and remote-access locations, including relevant onward transfers. A provider's European billing entity or a selectable storage region does not, by itself, establish that all processing stays in the European Economic Area.
Before a transfer that needs a safeguard begins, the parties must identify the exporter, importer, processing roles and valid transfer basis. If standard contractual clauses are used, the correct module, options and annexes must be completed. The transfer assessment and any additional protective measures must match the actual service and access paths.
The European Commission's Article 28 controller–processor clauses in Decision 2021/915 address the processing relationship. They are different from the international-transfer clauses in Decision 2021/914. This custom draft is not either set of standard clauses and does not automatically incorporate or complete them.
We will inform you if an agreed transfer safeguard can no longer be met. The parties will identify a valid alternative or stop the affected transfer. No country, adequacy mechanism, provider certification or account-specific transfer arrangement is assumed from the code or this page.
At a glanceYou decide how to answer rights requests; we help with the processing we perform.
Taking account of the processing and the tools available, we will help you respond to requests to access, correct, delete, restrict or obtain personal data, and to other applicable data-subject rights. The assistance may include locating information, providing an agreed export or carrying out a documented correction or deletion.
If a person sends us a request about data we process for you, we will pass it to your agreed contact without undue delay and may direct the person to you. We will not decide the request or disclose customer personal data without your instructions, unless law requires it.
You are responsible for checking the requester's identity, deciding the applicable rights and exceptions, and meeting the legal response deadline. We will provide the information and practical assistance needed for our part. Both parties should share only the personal information needed to handle the request securely.
At a glanceWe will notify you without undue delay after becoming aware of a breach affecting your data.
We will notify your agreed incident contact without undue delay after becoming aware of a personal data breach affecting customer personal data. We will not wait for a complete investigation before giving the first notice. The processor's duty to notify you is separate from your duty to assess notification to authorities and affected people.
As information becomes available, we will explain what happened, the relevant data and people, approximate numbers where known, likely consequences, containment or recovery steps, and a contact for further information. We will distinguish confirmed facts from what remains under investigation and provide further information in phases without undue further delay.
We will take appropriate steps to contain the breach, reduce harm, preserve relevant evidence and address its cause. We will cooperate with your investigation and provide information needed for your risk assessment and any required notification. We will document the event and the relevant response actions.
You decide notifications about customer processing to authorities and people unless a legal requirement directs otherwise. Annex D must contain working incident contacts and escalation arrangements. This draft does not promise a fixed hourly response cap or treat the GDPR controller notification period as a processor notification allowance.
At a glanceWe will provide relevant help with security, impact assessments and consultations.
Taking account of the processing and the information available to us, we will help you with your duties under GDPR Articles 32 to 36. This includes relevant security information, breach assistance, data protection impact assessments and prior consultation with a supervisory authority where required.
You decide whether your intended use needs an impact assessment and carry it out before the processing where law requires it. Tell us about processing that changes the risk, such as sensitive records, monitoring or important decisions about individuals, so the parties can assess the service and measures before that use starts.
We will cooperate with competent supervisory authorities as required by law. Each party remains responsible for its own statutory duties; the agreement does not transfer all of one party's legal responsibilities to the other.
At a glanceYou need enough evidence to check how your information is handled.
We will make available the information necessary to demonstrate our compliance with the applicable Article 28 obligations. We will allow and contribute to audits, including inspections, by you or an auditor you appoint. Provider information or a questionnaire may help an assessment but does not automatically replace a necessary inspection.
The parties will agree a practical scope and arrangements for an audit, with safeguards for systems, staff, other customers' information and confidential material. Routine scheduling and confidentiality arrangements must not block required oversight or an urgent assessment following a breach, credible concern or regulator request.
You and your auditor will limit access and use of information to the assessment and protect what you receive. We will respond to relevant findings and work with you on corrective action. Any separately agreed audit costs or logistics must not remove rights or delay legally required cooperation.
At a glanceA request from an authority needs a lawful basis and a controlled response.
If we receive a request from an authority for customer personal data, we will assess its legal basis, scope and whether disclosure is required. Where legally permitted, we will tell your agreed contact before disclosure and provide relevant information so you can understand the request or seek a remedy.
We will seek clarification of an unclear or excessive request and challenge an unlawful demand where legally available and appropriate. Any required disclosure will be limited to the information the law requires. We will document the request, our assessment and what was disclosed, subject to lawful restrictions.
A foreign authority's order is not automatically a lawful international-transfer basis. We will apply the relevant transfer rules and agreed safeguards. If notice is prohibited, we will respect the prohibition and seek permission to inform you when possible.
At a glanceChoose what happens at the end and agree how active systems and backups are handled.
At the end of the services that involve processing, we will, at your choice, return or delete customer personal data and delete existing copies, unless EU or Member State law requires storage. We will follow documented instructions for earlier deletion during the service where applicable. Archiving a work item or disconnecting an app is not an instruction or technical proof that every stored copy has been erased.
The parties must agree an export format, a way to deliver it securely, the time allowed to retrieve it, and the deletion schedule in Annex B. The schedule must address active databases, private files, histories, queues, logs where relevant, backup copies and subprocessors. This draft does not imply that a complete workspace export or immediate backup erasure is already available as a product feature.
Backup copies awaiting agreed expiry or a lawful hold must be protected, restricted from ordinary use and removed under the recorded schedule when retention ends. If a backup is restored, completed deletion instructions must be reapplied. The operational process and maximum periods must be confirmed; a backup setting or retention target is not evidence that this happens.
Where law requires continued storage, we will identify the relevant basis and retained categories, inform you where permitted, isolate the data and limit its use to that requirement. A general preference to keep records is not a legal hold. Once the requirement ends, the data must be deleted under the agreed process.
We will provide confirmation of the actions completed and explain any lawfully retained categories. Information that you or your recipients already exported or sent to a separately controlled provider is subject to that recipient's responsibilities; we will still carry out our obligations for copies under our control and with our subprocessors.
At a glanceChoose lawful uses, keep permissions current and tell us what protection you need.
You have the right to give lawful documented instructions, obtain the information and assistance set out here, oversee processing and choose return or deletion at the end. You are responsible for the purposes of customer processing, the lawful basis, required notices and the information you choose to put in Tellenze.
You must ensure that your instructions and sharing choices are authorised. If you process data for someone else, obtain their required permission for Tellenze, its approved subprocessors and relevant transfers. Keep your instruction and incident contacts current and tell us promptly about relevant misuse or compromised access.
Use only the information needed for your work. Review member and agent access, published reviews, public form settings, sharing links and connected accounts. Do not include passwords, secret keys or unnecessary sensitive information in work content or AI requests.
Before using special-category information, criminal-offence information or another high-risk data set, agree the scope and appropriate safeguards in Annex A. Record any applicable conditions and extra protections. The standard workspace examples do not establish suitability for medical, criminal or other sensitive processing.
When enabling AI or an external integration, assess its purpose, recipients and terms and inform affected people where required. Human review and an access check are useful controls; they do not establish a lawful basis or settle an impact assessment on their own.
At a glanceChanges need a record, and affected processing must stop when it cannot lawfully continue.
The parties will keep the annexes current when processing, features, recipients or material safeguards change. Changes to the agreement require a written record accepted by authorised representatives. Electronic records may be used when they provide a binding, retained agreement; viewing a draft supplies no such record.
If we cannot comply with an applicable obligation in this agreement, we will tell you promptly, explain the affected processing and discuss a remedy. Processing that cannot lawfully continue must be suspended or ended. The parties will coordinate return, deletion and any legal retention under section 15.
Ending or suspending processing does not remove confidentiality, assistance, lawful retention or deletion duties that still apply. Service termination, commercial consequences and dispute terms must be aligned with the actual service agreement; no unconfirmed liability cap, fee or contract period is added here.
At a glanceThese service examples must be narrowed and completed for the customer's actual workspace.
Complete this annex with the customer. The descriptions below show the processing the product can support, not permission to process every category for every customer. Record the workspaces and enabled features, any exclusions, expected scale and any additional conditions.
Built-in AI, email powerups and other integrations add processing only when enabled and used under the applicable instructions. Public website enquiries and independent public-tool use need a separate assessment if they are intended to form part of this agreement. Durable public-tool statistics are separate from the temporary rooms and should not be confused with workspace data.
| Required detail | Proposed service description | Customer-specific completion |
|---|---|---|
| Subject matter | Providing the agreed Tellenze workspace and authorised supporting features. | Identify service agreement, customer, workspace identifiers and enabled features. |
| Duration | During the agreed service and the limited return, deletion or lawful-retention process that follows. | Record start, service period, end instructions and maximum residual-copy periods in Annex B. |
| Nature of processing | Receipt, storage, organisation, retrieval, access, editing, sharing on instruction, transmission to approved providers, export and deletion. | State which operations and integrations are authorised and any restrictions. |
| Purpose | Support the customer's work planning, collaboration, knowledge, intake, review and instructed assistance. | Describe the customer's purposes and whether it acts for another controller. |
| Personal data | Names, email addresses, user and role identifiers; work and document content; comments, files, form responses and review content; activity records; enabled integration and AI request content. | List actual data categories and exclude categories the service is not agreed to process. |
| People concerned | Customer members and invited collaborators; customers, suppliers or other people mentioned in work; form respondents, reviewers and email recipients where relevant. | Identify the actual groups, including any children or vulnerable people if expressly agreed. |
| Sensitive or high-risk data | Not established as part of the standard examples. | Record any expressly accepted categories, lawful conditions, safeguards and risk assessment before use. |
| Customer rights and duties | Documented instructions, oversight, assistance and end-of-service choice; lawful use, notices, data minimisation and control of access. | Record instruction contacts, controller authority, feature restrictions and any additional agreed duties. |
At a glanceComplete the practical arrangements and attach the agreed security version.
Use the Security measures page as the starting point for the technical and organisational measures. Attach or retain its agreed version with the executed agreement. Confirm which application controls and operational measures are in place for the specific deployment.
The following fields are required review inputs. An empty or pending field is not a contractual assurance. The parties must resolve material gaps before processing begins under this agreement.
| Area | Details to complete |
|---|---|
| Access and confidentiality | Authorised service personnel, support access purpose and approval, confidentiality commitments, access reviews and evidence retained. |
| Technical protection | Applicable workspace boundaries, private-file controls, encryption coverage, key custody, transport protection, monitoring and vulnerability management. |
| Recovery and resilience | Actual backup coverage, frequency, locations, encryption and access; independent recovery of keys; tested restoration and agreed recovery objectives, if any. |
| Retention during service | Periods and purposes for work content, history, operational records, logs, queues, attachments and relevant provider copies. |
| Return and deletion | Export scope and format, secure delivery, retrieval window, active-system deletion, subprocessor deletion and confirmation procedure. |
| Backups and legal holds | Maximum residual-copy periods, restricted use, hold basis and review, final erasure, and reapplication of deletions after restoration. |
| Assessment and incidents | Security review arrangements, testing evidence, breach escalation contacts and the agreed method for progress updates. |
At a glanceComplete the provider schedule from verified agreements and actual processing paths.
The Subprocessors and providers page is an owner-confirmation inventory. It identifies application paths and the information still needed; it is not a complete or approved schedule. The executed annex must name each authorised subprocessor's legal entity, service, relevant data, countries for storage and access, and applicable safeguards.
Record specific or general written authorisation, how change notices are sent and the agreed objection procedure. Keep customer-appointed integrations and providers acting for their own purposes distinct from our subprocessors. Record the service-specific role where one provider has more than one role.
For relevant international transfers, attach the valid basis, completed transfer clauses where needed, transfer assessment and additional measures. Record upstream authorisation when the customer is a processor. This annex must be complete for the actual service before execution.
At a glanceThe execution record is completed outside this preview and kept by both parties.
Both parties must review and complete this record, the processing annexes and the linked service contract. There is no signature, acceptance control or automatic execution on this page. Contact [email protected] to arrange the review.
| Record | Required information |
|---|---|
| Customer | Full legal name, address, registration details where relevant, controller or processor role, and upstream controller authority if applicable. |
| Service processor | Exact contracting person or persons, role in operating Tellenze, address for the agreement and any representation or signatory authority. Review the Xolo Go service framework separately. |
| Contacts | Authorised instruction and privacy contacts for both parties, breach contact and escalation method. Tellenze draft contact: [email protected]. |
| Contract and annexes | Service agreement reference, workspaces, DPA version, completed Annexes A to C and any applicable transfer documents. |
| Execution | Effective date, authorised signatories or other valid acceptance record, their capacities, and a copy retained by each party. |
Sources used for this document
Read the original guidance and provider terms for more detail.
- GDPR: processing duties, security, breaches and transfers
- European Commission: Article 28 controller–processor clauses, Decision 2021/915
- European Commission: international-transfer clauses, Decision 2021/914
- European Commission: explanation of the two sets of standard clauses
- Xolo: general service-contract framework
- Xolo: the legal status of a Go partnership
- Xolo: separate agreement of NDA and DPA responsibilities
A question about this document?
Email [email protected] or contact Tellenze. For workspace personal data, start with your workspace administrator.