Draft — prepared for review by counsel. Bracketed items require confirmation. Not yet final.
Data Processing Agreement
Last updated: July 27, 2026 (draft)
Parties & Incorporation
This Data Processing Agreement (“DPA”) forms part of the Terms of Service (the “Agreement”) between Triples Global LLC, a California limited liability company (“tethr”, the “Processor”) and the customer identified in the Agreement or the signature block below (“Customer”, the “Controller”). It governs tethr’s processing of personal data contained in Customer Data (“Customer Personal Data”) and takes effect when Customer accepts the Agreement or the parties sign below, whichever is earlier. If this DPA conflicts with the Agreement, this DPA controls with respect to the processing of Customer Personal Data.
1. Definitions
“Data Protection Laws” means all laws applicable to the processing of Customer Personal Data, including (as applicable) the EU General Data Protection Regulation 2016/679 (“GDPR”), the UK GDPR, and US state privacy laws such as the California Consumer Privacy Act as amended (“CCPA”). “Controller”, “processor”, “data subject”, “personal data”, “personal data breach”, and “processing” have the meanings given in the GDPR; “service provider”, “sell”, and “share” have the meanings given in the CCPA.
2. Scope & Roles
Customer is the controller of Customer Personal Data (or a processor acting for another controller, in which case Customer warrants it is authorized to instruct tethr). tethr is Customer’s processor. The subject matter, duration, nature and purpose of the processing, and the categories of personal data and data subjects are described in Annex 1.
3. Processing Instructions
tethr will process Customer Personal Data only on Customer’s documented instructions — which consist of the Agreement, this DPA, and Customer’s and its users’ use of the Service’s features — unless required to do otherwise by law (in which case tethr will inform Customer unless legally prohibited). tethr will promptly inform Customer if, in its opinion, an instruction infringes Data Protection Laws. tethr will not sell or share Customer Personal Data, retain or use it except to provide the Service, or combine it with data from other sources except as permitted for service providers under the CCPA.
4. Confidentiality
tethr ensures that all persons it authorizes to process Customer Personal Data are bound by contractual or statutory obligations of confidentiality.
5. Security
tethr implements and maintains the technical and organizational measures described in Annex 2, and will not materially decrease the overall security of the Service during the term. Taking into account the state of the art and the nature of the data, these measures are designed to ensure a level of security appropriate to the risk, including protection against unauthorized access, loss, and disclosure.
6. Sub-processors
Customer generally authorizes tethr to engage the sub-processors listed in Annex 3. tethr will (a) impose data-protection obligations on each sub-processor no less protective than those in this DPA, (b) remain liable for its sub-processors’ performance, and (c) give Customer at least 30 days’ notice (by email to workspace administrators or through the Service) before adding or replacing a sub-processor. Customer may object on reasonable data-protection grounds within that notice period; if the parties cannot resolve the objection, Customer may terminate the affected Service and tethr will refund any prepaid unused fees.
7. Data Subject Requests
The Service provides self-serve tools that help Customer respond to data-subject requests directly (search, correction of records, full workspace export, and deletion). Taking into account the nature of the processing, tethr will assist Customer with reasonable technical and organizational measures to fulfil requests to exercise data-subject rights. If a data subject contacts tethr directly about Customer Personal Data, tethr will forward the request to Customer without responding on the merits, except to direct the data subject to Customer.
8. Personal Data Breach
tethr will notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notification will describe, to the extent known, the nature of the breach, the categories and approximate numbers of data subjects and records concerned, the likely consequences, and the measures taken or proposed. tethr will cooperate with Customer and take reasonable steps to mitigate the breach. tethr’s notification is not an admission of fault.
9. Assistance
Taking into account the nature of the processing and the information available to it, tethr will provide reasonable assistance with Customer’s data-protection impact assessments and prior consultations with supervisory authorities, where required by Data Protection Laws.
10. Deletion & Return of Data
During the term, Customer can export Customer Data as a machine-readable archive and can permanently delete individual records or its entire workspace self-serve. Upon termination of the Agreement, tethr will, at Customer’s choice, make Customer Data available for export for at least 30 days and then delete Customer Personal Data within 30 days, including by cascading deletion of all workspace records, except where retention is required by law. Residual copies in encrypted backups are purged on a short rolling cycle. On request, tethr will confirm deletion in writing.
11. Audits
tethr will make available to Customer information reasonably necessary to demonstrate compliance with this DPA, including summaries of security measures and, when available, third-party audit reports or certifications. No more than once per year, and on at least 30 days’ notice, Customer may conduct (directly or through an independent auditor bound by confidentiality) an audit limited in scope to tethr’s compliance with this DPA, during business hours, without disrupting operations, and at Customer’s expense. Information obtained is Confidential Information under the Agreement.
12. International Transfers
Customer Personal Data is processed in the United States (Annex 3). To the extent the processing involves a transfer of personal data from the EEA, UK, or Switzerland to a country without an adequacy decision, the parties incorporate by reference the European Commission’s Standard Contractual Clauses (Decision (EU) 2021/914), Module Two (controller to processor), completed with the details in the Annexes, with Customer as data exporter and tethr as data importer [counsel: confirm module selection, optional clauses, and the UK International Data Transfer Addendum / Swiss amendments as applicable].
13. Liability & Order of Precedence
Each party’s liability under this DPA is subject to the limitations of liability in the Agreement. This DPA supersedes any prior data-processing terms between the parties for the Service.
Annex 1 — Details of Processing
- Subject matter: provision of the tethr HR platform to Customer.
- Duration: the term of the Agreement, plus the deletion/return period in Section 10.
- Nature and purpose: hosting, storage, retrieval, display, transmission, analysis (including AI-assisted features invoked by Customer’s users), and deletion of Customer Data as needed to provide the Service’s features: person directory and org chart, performance targets and reviews, surveys, recognition, recruiting, document storage, notifications, and an embedded AI assistant.
- Categories of data subjects: Customer’s current and former people and contractors; Customer’s workspace users; job candidates who apply to Customer’s postings.
- Categories of personal data: identification and contact data (name, email, phone, address); employment data (title, department, manager, employment dates and status); compensation and offer data; performance data (targets, reviews, ratings, feedback); recognition messages; survey responses; recruiting data (résumés/CVs and their parsed contents, interview feedback); uploaded documents; emergency-contact details.
- Special categories: only if and to the extent Customer chooses to store them (for example, health-related records or information revealed in free-text fields and documents). Customer is responsible for ensuring a lawful basis for any special-category data it submits.
Annex 2 — Technical & Organizational Measures
- Encryption: TLS for all data in transit; encryption at rest for the database and file storage (managed by the providers in Annex 3).
- Tenant isolation: every workspace record carries a tenant identifier and every database query is scoped to the requesting workspace; cross-tenant access is treated as a defect of the highest severity and tested for.
- Access control: role-based access within each workspace (Owner, HR, Manager, Person), with server-side enforcement of feature-level permissions and of anti-privilege-escalation rules for invitations.
- AI data minimization: where the assistant retrieves workspace data to answer a question, a server-side filter strips compensation, government identifiers, medical information, personal contact details and credentials before that content is sent to an AI provider. Features that process content the user supplies directly — résumé parsing, document summarisation, roster import, job drafting — transmit that content as given. AI usage is rate-limited and metered per workspace.
- Survey anonymity: responses to surveys marked anonymous are stored without respondent identity, using a keyed one-way hash solely for duplicate prevention.
- Auditability: administrative and data-changing actions are recorded in a per-workspace audit log.
- Backups & recovery: the database host maintains point-in-time recovery for the production database, and the production branch is protected against deletion.
- Data portability & deletion: self-serve full-workspace export (machine-readable) and self-serve permanent workspace deletion with cascading removal of all workspace records.
- Operational security: production secrets are stored in the hosting platform’s encrypted configuration and are write-only once set, so they cannot be read back out. Changes are made through version control, and automated type, unit, end-to-end and dependency-vulnerability checks are run against a change before it is deployed.
Annex 3 — Authorized Sub-processors
| Provider | Purpose | Location |
|---|---|---|
| Vercel | Application hosting, and the AI Gateway through which all assistant and parsing requests are routed to model providers | United States |
| Neon | Postgres database hosting (all workspace data) | United States |
| Clerk | Authentication and user management | United States |
| Cloudflare | Document and file storage (R2) | United States |
| Anthropic | AI model provider, reached via the Vercel AI Gateway (assistant, résumé parsing, roster import, document summaries, job drafting) | United States |
| Voyage AI | Text embeddings for document search | United States |
| Resend | Transactional email (invites, notifications) | United States |
| Upstash | Redis used for rate limiting and short-lived subscription-status caching (processes user identifiers and IP addresses) | United States |
If Customer connects an optional integration (for example an e-signature provider for offer letters), that provider processes data at Customer’s direction and is not a tethr sub-processor.
Signatures
This DPA may be executed electronically or, where accepted as part of the Agreement, applies without signature.
tethr — Triples Global LLC
Signature:
Name:
Title:
Date:
Customer
Signature:
Name:
Title:
Date: