Data Processing Addendum
The Article 28 processing terms, the Standard Contractual Clauses and their annexes, and the HIPAA Business Associate Agreement. It applies automatically wherever Teleon processes personal data on your behalf, no signature required, though a counter-signed copy is yours for the asking.
This document is published for review. Entity registration details and the designated EU and UK representatives are still to be supplied, and appear below as marked placeholders. Until they are filled in, treat this text as a draft rather than as the executed agreement, and ask legal@teleon.ai for the current signed position.
When this addendum applies
This Data Processing Addendum forms part of the Terms of Service or other agreement (the “Agreement”) between Teleon, Inc. (“Teleon”) and the customer (“Customer”). It applies automatically, without separate signature, whenever Teleon processes Personal Data on the Customer’s behalf.
A counter-signed copy is available on request from legal@teleon.ai. Customers who require a negotiated addendum may raise it on an Order Form; this version is the default and is what governs in the absence of one.
It implements Article 28 of the GDPR and the equivalent provisions of the UK GDPR, the Swiss FADP, the CCPA/CPRA, the Virginia CDPA, Colorado CPA, Connecticut CTDPA, the Brazilian LGPD, and other applicable data protection law. Where a term of this addendum conflicts with the Agreement, this addendum prevails on data protection matters.
Roles of the parties
| Data | Customer is | Teleon is |
|---|---|---|
| End-user data flowing through the Customer’s Agents | Controller | Processor |
| End-user data where the Customer is itself a processor for its own clients | Processor | Sub-processor |
| The Customer’s own console user accounts | Controller | Independent controller for security and account administration; processor otherwise |
| Billing and account data | — | Controller |
Teleon processes Customer Personal Data only on the Customer’s documented instructions. The Agreement, this addendum, the configuration the Customer sets in the console, its policies, classifications, retention settings and residency selection, and the Customer’s use of the API together constitute those instructions. Teleon will tell the Customer if an instruction appears to infringe applicable data protection law, and may suspend performance of that instruction until it is resolved.
Teleon will not process Customer Personal Data for its own purposes, will not sell or share it as those terms are defined by the CCPA/CPRA, will not combine it with data from other sources except as necessary to provide the Service, and will not retain, use or disclose it outside the direct business relationship. Teleon certifies that it understands and will comply with these restrictions.
Subject matter, duration, nature and purpose
- Subject matter
- Provision of the Teleon trust layer under the Agreement.
- Duration
- The term of the Agreement, plus the retention and deletion periods in section 9.
- Nature and purpose
- Ingesting audit-event metadata from the Customer’s Agents; enforcing the Customer’s policies at the gateway, sidecar or middleware; classifying and scoring agent behaviour; tokenizing classified fields in the Privacy Vault; generating trust profiles, scores, badges and signed compliance bundles; storing the signed audit ledger; and operating the data-subject request portal on the Customer’s behalf.
- Categories of data subject
- End users of the Customer’s products whose interactions pass through its Agents; the Customer’s personnel who use the console; the Customer’s compliance and security staff handling DSRs; individuals identified in a DSR.
Categories of personal data
| Category | How Teleon holds it | Default retention |
|---|---|---|
| Prompt and response content | SHA-256 hash in the ledger. Plaintext is transmitted to the classifier for evaluation and is not persisted. | n/a, not stored |
| Tool-call arguments | SHA-256 hash; classified fields replaced by a vault token | With the parent entry |
| Direct identifiers (email, account id, name) | Vault token where classified; otherwise as submitted | Until erasure or account closure |
| Decision metadata | Policy identifier, action, severity, reason code | Per the plan’s audit retention |
| Customer personnel account data | Email, name, role, sign-in records | Until account deletion, then 90 days |
| DSR case data | Requester email, verification state, case history | 3 years after completion |
Special categories
Teleon does not process special categories of personal data under Article 9, or criminal-offence data under Article 10, unless the Customer has enabled a Privacy Vault classification for them and, for protected health information, executed the Business Associate Agreement in section 12. Sending such data without doing so is a breach of the Agreement, and Teleon may suspend to contain it.
Teleon’s obligations
- Confidentiality. Personnel authorised to process Customer Personal Data are bound by written confidentiality obligations that survive their engagement, and are granted access only as their role requires.
- Security. Teleon implements the technical and organisational measures in section 8, appropriate to the risk under Article 32.
- Sub-processors. Engaged only under section 5, under a written contract imposing data protection obligations no less protective than these. Teleon remains fully liable for a sub-processor’s performance.
- Assistance with data-subject rights. Section 10.
- Assistance with Articles 32 to 36. Teleon provides the information the Customer reasonably needs for a data protection impact assessment or a prior consultation, taking into account the nature of the processing and what is available to Teleon.
- Deletion or return. Section 9.
- Audit. Section 11.
- Breach notification. Section 7.
Sub-processors
The Customer gives general written authorisation for Teleon to engage sub-processors. The current list is published at /legal/sub-processors and forms part of this addendum. It is the authoritative list; any other list is superseded by it.
Teleon gives at least 30 days’ notice before a new sub-processor begins processing, and publishes the change on the register the same day. The Customer may object on reasonable data protection grounds within that period, in writing to dpo@teleon.ai. Teleon will use reasonable efforts to offer a configuration avoiding the sub-processor; failing that, the Customer may terminate the affected part of the subscription without penalty and receive a pro-rata refund of prepaid fees.
Amazon Bedrock receives prompt and response content for classification and scoring. It is the only sub-processor that receives payload content, and it processes in us-east-1 for every tenant regardless of the storage residency selected.
Teleon SARL (Tunisia) reaches production under break-glass approval for engineering and support. Tunisia has no EU adequacy decision; section 6 sets out the safeguards.
International transfers
Residency
A Customer on the Business or Enterprise plan may pin storage to eu-west-1 or us-east-1. Residency binds the audit ledger, object storage and key material. It does not bind model-based classification and scoring, which run in us-east-1 for every tenant. Teleon states this rather than allowing “EU residency” to be read as a guarantee it does not give.
Standard Contractual Clauses
Where Teleon transfers Personal Data protected by the GDPR to a country without an adequacy decision, the parties incorporate the Standard Contractual Clauses approved by Commission Implementing Decision (EU) 2021/914 by reference, as follows:
| Situation | Module | Parties |
|---|---|---|
| The Customer is a controller | Module Two (controller to processor) | Customer as data exporter; Teleon as data importer |
| The Customer is itself a processor | Module Three (processor to processor) | Customer as data exporter; Teleon as data importer |
- Clause 7, the docking clause, applies.
- Clause 9(a), option 2 applies: general written authorisation, with a minimum of 30 days’ notice of changes.
- Clause 11(a): the optional independent dispute-resolution language does not apply.
- Clause 13 and Annex I.C: the competent supervisory authority is that of the exporter’s establishment, or where the exporter is not established in the EU, of the Member State in which its Article 27 representative is designated.
- Clause 17: the Clauses are governed by the law of Ireland. Clause 18(b): disputes are heard in the courts of Ireland.
- Annexes I, II and III are set out in sections 13 to 15 of this addendum.
For data protected by the UK GDPR, the parties incorporate the UK International Data Transfer Addendum (version B1.0) to the Standard Contractual Clauses. For Swiss data, the Clauses are read with the Federal Data Protection and Information Commissioner substituted as supervisory authority and references to the GDPR read as references to the FADP.
The Tunisia transfer, specifically
Tunisia is not the subject of a European Commission adequacy decision. Access to EU Personal Data by Teleon SARL is a restricted transfer made under the Standard Contractual Clauses executed between the group entities, supported by a documented transfer impact assessment.
Tunisia is a party to Council of Europe Convention 108 and has a supervisory authority, the Instance Nationale de Protection des Données Personnelles, under Loi organique n° 2004-63 of 27 July 2004. These facts inform the assessment. They are not adequacy and Teleon does not present them as adequacy.
Supplementary measures: no Customer Personal Data is stored on Tunisian infrastructure; access is remote, role-scoped, approved per session, time-boxed and written to the Customer-readable audit ledger; data at rest is encrypted with KMS customer-managed keys held in the storage region; and fields classified for the Privacy Vault present as tokens in a support session rather than as values.
Government access requests
Teleon has received no order under FISA Section 702, no directive under Executive Order 12333, and no national-security demand of any kind as at the effective date of this addendum. If one is received, Teleon will challenge it where there are lawful grounds, disclose only the minimum the order compels, and notify the Customer unless legally prohibited, in which case it will publish the fact in aggregate at the earliest lawful opportunity.
Personal data breach
Teleon notifies the Customer without undue delay and in any event within 72 hours of becoming aware of a Personal Data Breach affecting Customer Personal Data.
The notice describes the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a named contact for coordination. Where the full picture is not available within 72 hours, Teleon sends what it has and supplements it as the investigation develops rather than delaying the first notice.
Teleon assists the Customer in meeting its own notification obligations to supervisory authorities and data subjects. Teleon does not notify the Customer’s data subjects directly unless the Customer instructs it to. Security contact: security@teleon.ai.
Technical and organisational measures
These are the measures referred to in Article 32 and reproduced in Annex II. They are Teleon’s current measures and may be updated, provided the level of protection is not reduced.
| Area | Measure |
|---|---|
| Encryption in transit | TLS 1.2 minimum, TLS 1.3 preferred, on every external and inter-service connection. |
| Encryption at rest | AES-256-GCM. Per-region AWS KMS customer-managed keys for audit signing, vault key-encryption keys and object storage. Key material never leaves KMS. |
| Pseudonymisation | Prompt and tool-call content reduced to SHA-256 hashes in the ledger. Classified fields tokenized in the Privacy Vault with per-record data keys, enabling cryptographic erasure. |
| Tenant isolation | Row-level security in the database, enforced below the application, so an application defect cannot cross a tenant boundary. |
| Access control | Role-based, owner, admin, member, viewer. Staff authenticate through self-hosted Zitadel with mandatory MFA. Production access is break-glass: role-scoped, approved per session, time-boxed and audited. |
| Integrity | Every audit entry is signed and hash-chained to its predecessor. Each region’s daily Merkle root is anchored to Bitcoin through four independent OpenTimestamps calendars. |
| Availability and resilience | Multi-AZ managed database with automated backups and point-in-time recovery. Documented disaster-recovery plan with a quarterly restore exercise. |
| Secure development | Static analysis, dependency scanning, container scanning, secret scanning and keyless image signing on every build. Peer review required to merge. |
| Verification | Signed compliance bundles ship with the public keys and an open-source verifier, so a Customer or auditor can verify evidence offline without trusting Teleon’s servers. Key fingerprints are published at trust.teleon.ai. |
| Vendor management | Sub-processors are contracted with data protection terms no less protective than these and are reviewed before engagement. |
| Incident response | Documented plan with defined severities, on-call rotation and post-incident review. Breach notification per section 7. |
Deletion and return
- For 30 days after the Agreement ends, the Customer may export Customer Personal Data through the bundle generator and the API in a documented, machine-readable format.
- After that window, Teleon deletes Customer Personal Data within 90 days.
- Records Teleon is required by law to keep are retained encrypted, are not accessible to operational staff, and are deleted when the obligation lapses. Teleon will state on request what is being kept and why.
- Backups follow their own rotation and are overwritten within 35 days. Data in a backup is not restored to production after a deletion request.
Erasing a vault-held value destroys its data key, making the ciphertext permanently unrecoverable. The ledger entry itself remains: removing it would break the hash chain and invalidate every signature after it, destroying the evidentiary value of the Customer’s entire record. What survives is a hash, a decision, and a signed erasure certificate. That is a record of the erasure, not a copy of the data, and it is the design that lets erasure and tamper-evidence coexist.
Data-subject requests
Teleon operates a data-subject request portal at dsr.teleon.ai/<tenant> on the Customer’s behalf. Access, rectification, erasure, restriction, portability and objection requests are tracked against an SLA clock visible to the Customer in the console.
Where a data subject contacts Teleon directly about data Teleon processes for a Customer, Teleon does not respond substantively. It routes the request to the Customer, identifies the controller to the data subject, and starts the clock on the Customer’s side.
Erasure executed through the portal destroys the relevant vault data key and propagates to every token derived from it. A signed deletion certificate is issued to the data subject and written to the Customer’s audit ledger, so the Customer can later prove the erasure happened.
Teleon assists the Customer in meeting the statutory response deadlines. Assistance included in the subscription covers requests routed through the portal; requests requiring bespoke engineering are quoted separately and are not withheld while the price is agreed.
Audit rights
Teleon makes available the information necessary to demonstrate compliance with Article 28 and allows for and contributes to audits, including inspections, conducted by the Customer or an auditor it mandates.
- In the first instance Teleon satisfies this by providing its security documentation, its answers to a reasonable security questionnaire, and, when available, its SOC 2 Type 2 report and ISO/IEC 27001 certificate. Neither exists today; see section 10 of the Terms of Service. Teleon will not point a Customer at a report that does not exist.
- Where that is genuinely insufficient for the Customer’s regulatory obligation, the Customer may conduct an audit once per twelve months, on 30 days’ written notice, during business hours, under confidentiality, without unreasonable disruption, and at its own cost. A regulator may audit at any time its own powers permit.
- An audit following a Personal Data Breach affecting the Customer is not subject to the annual limit and is at Teleon’s cost.
Requests go to compliance@teleon.ai.
Business Associate Agreement: HIPAA
The Business Associate Agreement takes effect only when executed in writing between the Customer and Teleon, and is available on the Business and Enterprise plans. Until it is executed, no protected health information may be sent to the Service. The text below is the standard form, published so a Customer can review it before asking for it.
Where executed, the Customer is a Covered Entity or Business Associate and Teleon is a Business Associate under 45 CFR Parts 160 and 164. Terms used below have the meanings given in those Parts.
Permitted uses and disclosures
Teleon may use or disclose PHI only to perform the Service, as required by law, or for its own proper management and administration where the disclosure is required by law or Teleon obtains reasonable assurances of confidentiality and notice of any breach. Teleon will not use or disclose PHI in a manner that would violate Subpart E of 45 CFR Part 164 if done by the Covered Entity, and will limit uses and disclosures to the minimum necessary.
Safeguards
Teleon implements the administrative, physical and technical safeguards required by the Security Rule at 45 CFR Part 164 Subpart C, including those in section 8 above, and complies with the Security Rule with respect to electronic PHI.
Reporting
Teleon reports to the Customer any use or disclosure of PHI not permitted by this section, any Security Incident of which it becomes aware, and any Breach of Unsecured PHI, without unreasonable delay and in any event within 30 calendar days of discovery, and within 72 hours where the incident is also a Personal Data Breach under section 7. Reports include the information required by 45 CFR 164.410(c).
Subcontractors
Teleon ensures that any subcontractor that creates, receives, maintains or transmits PHI on its behalf agrees in writing to restrictions and conditions at least as restrictive as those that apply to Teleon.
Individual rights
Teleon makes PHI in a Designated Record Set available to the Customer as necessary for the Customer to meet its obligations under 45 CFR 164.524 (access), 164.526 (amendment) and 164.528 (accounting of disclosures), and makes its internal practices, books and records available to the Secretary of Health and Human Services for determining compliance.
Termination
On termination, Teleon returns or destroys all PHI it still holds and retains no copies, to the extent feasible. Where return or destruction is infeasible, the hash-chained ledger being the clear case, Teleon extends the protections of this section to that PHI and limits further uses and disclosures to the purposes that make return or destruction infeasible, for as long as it is retained. The Customer may terminate the Agreement if Teleon breaches a material term of this section and fails to cure within 30 days.
Annex I: parties, processing, supervisory authority
A. List of parties
| Role | Party | Activities | Contact |
|---|---|---|---|
| Data exporter | The Customer identified in the Agreement | Operating AI agents whose activity is governed and recorded by the Service | The account’s administrative and privacy contacts |
| Data importer | Teleon, Inc., «TODO: Delaware registered office address» | Providing the Teleon trust layer as described in section 3 | dpo@teleon.ai |
The exporter’s signature and date are those of the Agreement; the importer’s are those of this addendum as published, or of the counter-signed copy where one is issued.
B. Description of transfer
- Data subjects
- As set out in section 3.
- Categories of personal data
- As set out in section 3.
- Sensitive data
- Only where the Customer has enabled a Privacy Vault classification for it, and for PHI only where the Business Associate Agreement in section 12 has been executed. Restrictions: tokenization at the boundary, encryption with per-record data keys, access confined to audited detokenization calls.
- Frequency
- Continuous, for the duration of the Agreement.
- Nature and purpose
- As set out in section 3.
- Retention
- As set out in section 9 and in the retention schedule in the Privacy Policy.
- Sub-processor transfers
- As published at /legal/sub-processors, for the duration of their engagement.
C. Competent supervisory authority
The supervisory authority of the Member State in which the data exporter is established. Where the exporter is not established in the EEA but is subject to the GDPR under Article 3(2), the supervisory authority of the Member State in which its Article 27 representative is designated.
Annex II: technical and organisational measures
The measures set out in section 8 constitute Annex II to the Standard Contractual Clauses and are incorporated here by reference. They apply to transfers to sub-processors as well as to Teleon.
Annex III: sub-processors
The register published at /legal/sub-processors constitutes Annex III and is incorporated here by reference. The Customer has authorised the sub-processors listed there under Clause 9(a), option 2, with 30 days’ notice of changes.
Liability, order of precedence, and contact
Liability under this addendum is subject to the limitations in the Agreement, except where applicable data protection law does not permit it to be limited, in particular a data subject’s right to compensation under Article 82, and the liability provisions of the Standard Contractual Clauses, which are not limited by the Agreement.
Where a conflict arises, the order of precedence is: the Standard Contractual Clauses first, then this addendum, then the Agreement.
This addendum is governed by the law that governs the Agreement, except that the Standard Contractual Clauses are governed by the law of Ireland as stated in section 6, and except where mandatory data protection law requires otherwise.
- Data protection
- dpo@teleon.ai
- Contracts and counter-signature
- legal@teleon.ai
- Compliance evidence and audits
- compliance@teleon.ai
- Security and breach
- security@teleon.ai
- Data importer
- Teleon, Inc., «TODO: Delaware registered office address»
- Group sub-processor
- Teleon SARL, «TODO: Tunisian registered office address»
| Version | Effective | What changed |
|---|---|---|
| 2.0 | 2026-08-30 | Rewritten for Teleon, Inc. (Delaware) as data importer, replacing a French entity. Added the Tunisia transfer analysis and supplementary measures, explicit SCC module and clause selections, Annexes I to III, the CCPA service-provider certification, the government-access statement, and the full HIPAA Business Associate Agreement text. Corrected the audit clause to stop citing a SOC 2 report that does not exist. |
| 1.0 | 2026-07-26 | Initial addendum, maintained internally and never published. |