Data Processing Agreement
Effective date: May 6, 2026
Teros AI, S.L. · NIF B-88787445 · Calle Jacinto Camarero 8, entreplanta, 28019 Madrid, Spain
This Data Processing Agreement ("DPA") forms part of the Terms of Service or other written or electronic agreement (the "Agreement") between Teros AI, S.L., with VAT/NIF B-88787445 and registered office at Calle Jacinto Camarero 8, entreplanta, 28019 Madrid, Spain ("Teros", "Processor") and the entity or individual subscribing to the Services ("Customer", "Controller").
This DPA reflects the parties' agreement with regard to the processing of Customer Personal Data by Teros as a Data Processor on behalf of the Customer in connection with the Teros AI Operating System services.
Definitions
"Customer Personal Data" means any personal data processed by Teros on behalf of the Customer pursuant to the Agreement.
"Data Protection Laws" means all applicable worldwide legislation relating to data protection and privacy, including the European General Data Protection Regulation (Regulation (EU) 2016/679) ("GDPR"), the UK GDPR, and the California Consumer Privacy Act ("CCPA").
"Sub-processor" means any third party appointed by Teros to process Customer Personal Data.
Roles and Responsibilities
- 2.1. Role of the Parties:
- The parties acknowledge and agree that with regard to the processing of Customer Personal Data, Customer is the Data Controller and Teros is the Data Processor.
- 2.2. Customer's Obligations:
- Customer shall ensure that its instructions comply with Data Protection Laws. Customer is solely responsible for the accuracy, quality, and legality of Customer Personal Data and the means by which Customer acquired such data. Customer is also responsible for managing the permissions and scopes granted to Teros AI agents via OAuth or API keys for third-party integrations (e.g., Gmail, Notion, GitHub).
- 2.3. Teros' Obligations:
- Teros shall process Customer Personal Data only on documented instructions from the Customer, unless required to do so by applicable law. The Agreement, this DPA, and the Customer's use of the Services (including prompts given to AI agents) constitute the Customer's complete and final documented instructions.
Confidentiality and Security
- 3.1. Confidentiality:
- Teros shall ensure that its personnel authorized to process Customer Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
- 3.2. Security Measures:
- Teros shall implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. These measures include encryption in transit and at rest, access controls, and secure authentication mechanisms.
Sub-processors and Third-Party LLMs
- 4.1. General Authorization:
- Customer provides general authorization for Teros to engage Sub-processors to process Customer Personal Data. Current Sub-processors include cloud infrastructure providers (e.g., AWS, GCP) and third-party Large Language Model (LLM) providers (e.g., OpenAI, Anthropic, Google).
- 4.2. LLM Providers:
- Teros acts as an orchestrator. When AI agents execute tasks, relevant Customer Personal Data may be transmitted to LLM providers via API. Teros ensures that its enterprise agreements with these LLM providers prohibit the use of Customer Personal Data for training their foundational models.
- 4.3. Changes to Sub-processors:
- Teros will notify Customer of any intended changes concerning the addition or replacement of Sub-processors. Customer may object to such changes on reasonable data protection grounds within 15 days of the notification.
Data Subject Rights and Assistance
- 5.1. Data Subject Requests:
- Teros shall, to the extent legally permitted, promptly notify Customer if it receives a request from a Data Subject to exercise their rights under Data Protection Laws. Teros shall not respond to such requests directly without Customer's prior authorization, except to direct the Data Subject to the Customer.
- 5.2. Assistance:
- Teros shall provide reasonable assistance to Customer, at Customer's expense, to fulfill its obligations to respond to Data Subject requests and to conduct Data Protection Impact Assessments (DPIAs), taking into account the nature of the processing and the information available to Teros.
Personal Data Breaches
Teros shall notify Customer without undue delay (and in any event within 72 hours) after becoming aware of a personal data breach affecting Customer Personal Data. Teros shall provide Customer with sufficient information to allow Customer to meet any obligations to report or inform Data Subjects of the personal data breach under Data Protection Laws.
International Data Transfers
Teros may process Customer Personal Data globally as necessary to provide the Services. If Teros transfers Customer Personal Data originating from the EEA, the UK, or Switzerland to a country not recognized as providing an adequate level of protection, Teros shall ensure that such transfer is governed by a valid transfer mechanism, such as the EU-US Data Privacy Framework or the Standard Contractual Clauses (SCCs) approved by the European Commission.
Deletion or Return of Data
Upon termination or expiration of the Agreement, Teros shall, at the choice of the Customer, delete or return all Customer Personal Data to the Customer, and delete existing copies unless applicable law requires storage of the personal data.
Annex 1: Details of Processing
- Subject matter:
- The provision of the Teros AI Operating System and autonomous agent services.
- Duration:
- The term of the Agreement.
- Nature and purpose:
- To provide the Services, including executing automated workflows, interacting with integrated third-party tools, and generating AI responses based on Customer prompts.
- Types of personal data:
- Any personal data contained in the inputs provided by the Customer or accessed by the AI agents via authorized integrations (e.g., names, emails, messages, documents, code).
- Categories of data subjects:
- Customer's employees, contractors, clients, prospects, and any other individuals whose data is processed via the authorized integrations.
Related documents