Data Processing Addendum
Last changed 20 August 2026
1. Definitions and roles
1.1 In this Addendum: "Customer Personal Data" means personal data contained in Your Content that we process on your behalf; "Data Protection Law" means every law relating to the protection of personal data that applies to a party in respect of the processing, including the New Zealand Privacy Act 2020, the EU General Data Protection Regulation ("GDPR") and the UK GDPR; and "controller", "processor", "personal data", "data subject", "processing", "sub-processor" and "supervisory authority" have the meanings given in the GDPR.
1.2 Other capitalised terms have the meaning given in the Telos Brain Terms of Use, including "Cloud Deployment", "Self-Hosted Deployment", "Metering Data", "Model Provider" and "Model Credentials".
1.3 For Customer Personal Data, you are the controller and we are the processor. Where you are yourself a processor for another controller, we are a sub-processor and you warrant you have authority to appoint us and to give the instructions in this Addendum.
1.3A Who "we" is. This Addendum is between you and Telos NZ Limited, your contracting party under the Terms of Use. Telos NZ Limited is the processor. Other members of the Telos Group, including Telos Limited, Telos IP Ltd and Telos AU Pty Ltd, act as our sub-processors where they process Customer Personal Data, and are listed in Annex 3. Telos NZ Limited remains responsible to you for their acts and omissions under clause 5.5.
1.4 For the personal information described in clauses 2.1, 2.2, 2.3 and 2.5 of the Privacy Policy, including Metering Data, we act as controller. This Addendum does not apply to that processing; the Privacy Policy does.
1.5 Self-Hosted Deployments. Where you operate a Self-Hosted Deployment, Customer Personal Data remains in the environment you control and is not transmitted to us. We are not a processor of that data. In relation to a Self-Hosted Deployment, we process Customer Personal Data only where you send it to us in a support request, and only for so long as is necessary to respond. Accordingly, in relation to a Self-Hosted Deployment:
- clauses 4 (security), 5 (sub-processors), 6 (international transfers), 9 (audit) and 10 (deletion and return) apply only to material you have sent us;
- Annex 2 does not apply, and clause 14.2 and clause B6 of the Terms of Use set out the allocation of security responsibility instead; and
- clause 8 (personal data breach) applies only to a breach affecting systems we control.
1.6 If there is any inconsistency, this Addendum prevails over the Terms of Use in relation to the processing of Customer Personal Data.
2. Scope and instructions
2.1 We will process Customer Personal Data only:
- to provide, maintain, secure and support the Service in accordance with the Terms of Use;
- in accordance with your documented instructions, of which the Terms of Use, this Addendum and your configuration and use of the Service form part, including your selection of a Model Provider and your configuration of Model Credentials; and
- as required by law.
2.2 We will tell you if, in our opinion, an instruction breaches Data Protection Law, and may suspend performance of that instruction until it is withdrawn or amended. We are not obliged to give legal advice on your instructions.
2.3 If we are required by law to process Customer Personal Data other than on your instructions, we will notify you before doing so unless the law prohibits it.
2.4 You are responsible for the lawfulness of the Customer Personal Data you put into the Service and of your instructions, including having a lawful basis, giving any required notice to data subjects (including under information privacy principle 3A of the Privacy Act 2020), and obtaining any required consent.
2.5 Annex 1 sets out the subject matter, duration, nature and purpose of the processing, the categories of data subject and of personal data, and any special categories.
2.6 We will not use Customer Personal Data to train, fine-tune or improve any model, Skill or capability made available to any other customer, in accordance with clause 5.1 of the AI Terms.
3. Confidentiality and personnel
3.1 We will ensure that any person we authorise to process Customer Personal Data is subject to a duty of confidentiality, is trained appropriately, and has access only to the extent necessary for their role.
3.2 We will maintain a record of the categories of personnel with access to Customer Personal Data and will review access rights regularly.
4. Security
4.1 For a Cloud Deployment, we will implement and maintain the technical and organisational measures set out in Annex 2, taking into account the state of the art, the cost of implementation, and the nature, scope, context and purposes of processing and the risks to data subjects. Annex 2 is our contractual commitment and is published without any requirement to request access. Supporting evidence, current certifications and audit reports are published on the Telos Limited Trust Centre at https://trust.telosready.com, and access to some of that material may require a request and a confidentiality undertaking.
4.2 We may update those measures, provided we do not materially reduce the overall level of security.
4.3 For a Self-Hosted Deployment, we are responsible for the security of the Software as we deliver it, and you are responsible for the security of the environment in which you run it. Clause 14.2 of the Terms of Use applies.
5. Sub-processors
5.1 You give general authorisation for us to appoint sub-processors, including cloud infrastructure providers and other members of the Telos Group, to process Customer Personal Data in a Cloud Deployment.
5.2 Our current sub-processors are listed in Annex 3 and maintained on the Telos Limited Trust Centre at https://trust.telosready.com. That list is publicly accessible and does not require a request for access.
5.3 Before a new sub-processor begins processing Customer Personal Data, we will update that list and give you at least 30 days' notice. This is the notice period that applies to any change of sub-processor, and it prevails over any shorter or more general statement elsewhere in the Terms of Use or the AI Terms.
5.4 You may object to a new sub-processor on reasonable grounds relating to data protection by notifying us within the notice period. If you do, we will work with you in good faith to find a solution. If we cannot, you may terminate the Terms of Use in respect of the affected part of the Service and clause 10.9 of the Terms of Use applies.
5.5 We will impose on each sub-processor data protection obligations no less protective than those in this Addendum, and remain responsible to you for its performance.
5.6 Model Providers are not our sub-processors. Because you obtain your own account with each Model Provider and configure your own Model Credentials, that Model Provider processes Customer Personal Data under your agreement with it and on your instructions, as your processor (or, where you are yourself a processor, as your sub-processor). It is not our sub-processor and clauses 5.1 to 5.5 do not apply to it. Accordingly:
- you are responsible for putting in place with each Model Provider the data processing terms, security commitments and transfer safeguards that Data Protection Law requires of you, and for satisfying yourself as to its retention and training practices;
- our role is limited to transmitting Customer Personal Data to the Model Provider you have selected, on your instruction, in a Cloud Deployment. In a Self-Hosted Deployment we do not transmit it at all; and
- we will publish in the Documentation the Model Providers the Service supports, and will give you reasonable notice before removing support for one you use. Annex 4 lists the supported Model Providers for information only.
5.7 Telos Group sub-processors. Members of the Telos Group that process Customer Personal Data do so under intra-group data protection terms imposing obligations no less protective than those in this Addendum, together with the standard contractual clauses where a transfer requires them. A change of processing entity within the Telos Group is a change of sub-processor and clause 5.3 applies to it.
6. International transfers
6.1 In a Cloud Deployment, Customer Personal Data is processed in the territories listed in Annex 1.
6.2 Where a transfer is made from New Zealand, we comply with information privacy principle 12 of the Privacy Act 2020. Where a transfer is made from Australia by Telos AU Pty Ltd, we comply with Australian Privacy Principle 8, and section 16 of the Privacy Policy sets out the basis relied on.
6.3 We will carry out and document a transfer risk assessment where Data Protection Law requires it in respect of our own transfers, and will apply supplementary measures where necessary.
6.4 Transfers to Model Providers. A transfer of Customer Personal Data to a Model Provider is made on your instruction, using your credentials, under your agreement with that Model Provider. You are the exporter of that data. You are responsible for the transfer mechanism and any transfer risk assessment it requires. In a Self-Hosted Deployment the transfer is made from your environment and does not involve us at all.
7. Assistance and data subject rights
7.1 The Service provides functionality allowing you to access, correct, export and delete Customer Personal Data yourself. You will use that functionality to respond to a data subject request where you can. In a Self-Hosted Deployment this is the only route available, because we have no access to the data.
7.2 Where you cannot, we will provide reasonable assistance, at your cost where the request is substantial or repeated.
7.3 If we receive a request directly from a data subject relating to Customer Personal Data, we will not respond to it substantively and will refer the data subject to you, and notify you where we can identify you as the relevant customer.
7.4 We will provide you with the information reasonably available to us to assist with a data protection impact assessment or a prior consultation with a supervisory authority, where required and relating to our processing.
7.5 If we receive a legally binding request from a public authority for Customer Personal Data, we will notify you unless prohibited by law, will review the request for validity, and will disclose only the minimum required. In a Self-Hosted Deployment we will tell the authority that we do not hold the data.
8. Personal data breach
8.1 We will notify you without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Customer Personal Data in systems we control. This is the notification period referred to in clause 13.6 of the Terms of Use.
8.2 The notification will describe, to the extent known: the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, the measures taken or proposed, and a contact point. We will provide further information as it becomes available.
8.3 We will take reasonable steps to contain and remediate the breach and will cooperate with you in your own notification obligations. Notifying you is not an admission of fault.
8.4 We cannot detect or notify you of a breach occurring in an environment you control, or in a Model Provider's systems. You are responsible for monitoring those, and for any notification obligation arising from a breach there.
9. Audit
9.1 On reasonable written request, and no more than once in any 12-month period unless required by a supervisory authority or following a personal data breach, we will make available the information reasonably necessary to demonstrate our compliance with this Addendum. Where we hold a current independent certification or audit report, it is identified on the Trust Centre and providing it will ordinarily satisfy this clause. We do not represent that we hold any certification that is not listed there as current and complete.
9.2 Where that information is not sufficient to demonstrate compliance, we will allow an audit by you or an independent auditor appointed by you and reasonably acceptable to us, subject to reasonable notice, confidentiality obligations, and conduct that does not disrupt the Service or compromise the security of other customers' data. You bear the cost unless the audit reveals material non-compliance.
9.3 This clause applies to a Cloud Deployment. There is nothing for you to audit in respect of a Self-Hosted Deployment, because we do not process Customer Personal Data in it.
10. Deletion and return
10.1 In a Cloud Deployment, on termination we will delete Customer Personal Data, and your Model Credentials, in accordance with clause 19.6 of the Terms of Use.
10.2 You may export Customer Personal Data at any time before deletion using the functionality we make available.
10.3 We may retain Customer Personal Data to the extent required by law, and copies may remain in routine backups until overwritten in the ordinary course, in which case this Addendum continues to apply to them.
10.4 On request we will certify deletion in writing.
10.5 In a Self-Hosted Deployment, Customer Personal Data remains in your environment and there is nothing for us to return or delete. Clause 19.7 of the Terms of Use sets out what happens to the Software on termination.
11. General
11.1 Each party's liability under this Addendum is subject to clause 16 of the Terms of Use, except to the extent Data Protection Law does not permit that limitation.
11.2 This Addendum takes effect when you accept the Terms of Use and continues while we process Customer Personal Data.
11.3 We may update this Addendum in accordance with clause 2 of the Terms of Use, provided the update does not reduce the protections it gives you.
11.4 This Addendum is governed by the law stated in clause 21.3 of the Terms of Use, except where the standard contractual clauses require otherwise.
Annex 1 — Details of processing
Applies to Cloud Deployments. In a Self-Hosted Deployment we do not process Customer Personal Data — see clause 1.5.
| Item | Detail |
|---|---|
| Subject matter | Provision of Telos Brain as a Cloud Deployment under the Terms of Use. |
| Duration | The term of the Terms of Use, plus the retention period in clause 19.6 of those Terms. |
| Nature and purpose | Hosting, storage, indexing, embedding, retrieval, structuring and AI processing of Your Content in order to provide the Service, including transmission to the Model Provider selected by the customer, using the customer's own credentials, to generate AI Outputs. |
| Categories of data subject | Customer personnel; the customer's clients and contacts; any individual referred to in content the customer puts into its Brain. The customer determines this. |
| Categories of personal data | Identification and contact details; employment and role information; correspondence and business records; any personal data contained in documents, messages and records the customer uploads or connects. |
| Special categories | The Service is not intended for special category data. See clauses 2.2 and 2.3 of the Acceptable Use Policy. |
| Frequency of transfer | Continuous, for the duration of the Terms of Use. |
| Sub-processors | As listed in Annex 3 and on the Trust Centre at https://trust.telosready.com. Includes Telos Group entities. |
| Model Providers | Selected by the customer. Not sub-processors — see clause 5.6. Listed for information in Annex 4. |
Annex 2 — Technical and organisational measures
Applies to Cloud Deployments only. To be completed by engineering and verified before publication. Each line must describe a control that is actually implemented — this Annex is a contractual commitment and is the first thing a security reviewer will test. Delete any heading you cannot substantiate. This Annex must remain publicly available and must not be moved behind a Trust Centre access request: it is incorporated into the contract and customers must be able to read it before they accept. Supporting evidence may be gated; the commitment may not.
| Area | Measure |
|---|---|
| Access control | Management API and admin UI authenticate via Clerk (JWT from Authorization: Bearer or Clerk session cookie). Organisation API keys (tbk_…) authenticate non-interactive clients as the organisation. Execution API authenticates with a per-brain API key. Roles are Admin and Member; mutating Management API routes require Admin ([RequireRole(Admin)]). Platform Super Admin is a separate Clerk publicMetadata flag, checked live via the Clerk Backend API; Hangfire (/hangfire) is Super Admin–only in staging and production. Organisation membership can be invited, accepted, and removed (soft-delete). |
| Encryption | In transit: customer traffic to the Cloud Service terminates on Azure Container Apps TLS (Azure-managed certificates for go.telosbrain.com / mcp.telosbrain.com). At rest (application secrets): customer LLM and tool secrets in BrainEnvironmentVariables, connector tokens, organisation integration keys, and caller JWTs are encrypted with AES-256-GCM (12-byte random nonce, 16-byte tag). The 256-bit key is supplied as Encryption__Key (environment variable; not stored with the ciphertext). At rest (database): customer data is stored in Azure SQL Database (platform encryption as provided by Microsoft for that service). |
| Model credential handling | Customer provider keys (ANTHROPIC_API_KEY, OPENAI_API_KEY, XAI_API_KEY, VOYAGE_API_KEY, and other .env values) are uploaded by an organisation Admin (POST /brains/{instance}/environment-variables or brain deploy) and encrypted before persist. They are scoped to one brain. They are decrypted only at call time (run, embedding, or tool injection). The plaintext key is not returned on API responses (upload returns 204). Logs record the variable name and brain id, not the value. Schema / tool YAML holds a name reference (secret:), not the key. TELOS_* CLI credentials are never uploaded. Keys overwrite on redeploy. Soft-deleting the brain is the documented way to retire a brain. |
| Segregation | Logical multi-tenant isolation on shared Azure compute and a shared Azure SQL database — not dedicated compute per customer. Storage: every brain is keyed by BrainId and belongs to one OrganisationId. Management API lookups are organisation-scoped (wrong org → not found). Execution API sets CurrentBrainId from the brain API key; EF global query filters restrict brain-owned rows to that id. Compute: all tenants share the Container App. Model context: a run uses that brain's workflows, tools, memory, and that brain's decrypted provider key only. This is application-level isolation, not a separate VPC per customer. |
| Logging and monitoring | Application logs and request telemetry are sent to Azure Monitor / Application Insights when APPLICATIONINSIGHTS_CONNECTION_STRING is set on the Container App. Conversant logs use a correlation id and tool/status metadata; they are written not to log prompt bodies or API keys. Workflow prompts and messages are stored as product data in the database (WorkflowMessages) for the customer's own brain, not as a separate ops log. |
| Backup and recovery | Databases are Azure SQL Database (TelosBrainStagingDb / TelosBrainProdDb), which includes Microsoft's platform-automated backups. |
| Secure development | Source is on GitLab. CI (build-test on merge requests; publish → ACR → Azure Container Apps on main / production) separates staging and production apps and databases. Secrets for cloud deploy are GitLab CI/CD variables and Container App environment variables (not committed). Hangfire and Super Admin surfaces are not open in production. Container images: ACR for cloud, Docker Hub for brain start; no image signing / cosign. |
| Physical security | Inherited from Microsoft Azure (Container Apps, Azure SQL, ACR, Monitor). Telos does not operate the datacentre. |
Annex 3 — Sub-processors
To be completed by engineering. This list must be complete and current, and must reconcile with the Trust Centre list referenced in clause 5.2, with clause 2.5 of the AI Terms, and with clause 7.2 of the Privacy Policy. Telos Group entities that process customer content ARE sub-processors and must be listed. Model Providers must NOT be listed here — they are not sub-processors. List them in Annex 4 instead.
| Sub-processor | Purpose | Location | Data accessed |
|---|---|---|---|
| Telos Limited | Group security operations, governance, support escalation | New Zealand | Customer content and account data as required to operate and support the service (brains, inbox, workflows, files, logs). |
| Telos AU Pty Ltd | Australian sales, support and delivery | Australia | Same as Telos NZ Limited, limited to what is required to operate the service. |
| Telos IP Ltd | Intellectual Property holding and licensing | New Zealand | Same as Telos NZ Limited, limited to what is required to operate the service. |
| Microsoft Corporation (Microsoft Azure) | Hosting of the production and staging applications, Azure SQL Database, container registry, and Azure Monitor / Application Insights. | Australia (Azure geo; confirm the exact region in the telos-brain subscription) | All customer content stored or processed by the service: application database, hosted files, request logs, exceptions, and operational telemetry. |
| Stripe | Payment processing | United States (global infrastructure) | Billing contact and transaction data — controller data, not Customer Personal Data |
| Clerk, Inc. | Authentication and user / organisation management for the admin application and Management API. | United States | Account identity data: name, email, organisation membership, session tokens, and Clerk public metadata (e.g. Super Admin). Not brain memory, inbox bodies, or workflow run content. |
| ActiveCampaign, LLC (Postmark) | Outbound transactional email (organisation invites) and inbound email-to-brain (inbox.telosbrain.com). | United States | Invite emails: recipient address and invite link. Inbound mail (when email-to-brain is enabled): sender/recipient addresses, subject, body, and attachments (attachments are transcribed and not retained as files). |
| Google LLC (Google Workspace) | Support and operational email used by Telos staff. | United States (Google global infrastructure) | Personal data and customer content that a customer or Telos staff include in support or operational email. |
Annex 4 — Supported Model Providers (not sub-processors)
For information only. Each customer contracts directly with the Model Provider it selects, using its own credentials. These are not our sub-processors — see clause 5.6 — and we give no commitment about their data practices. Customers should verify each provider's current data usage terms themselves. Keep this list aligned with the Documentation.
| Model Provider | Used for | Customer responsibilities |
|---|---|---|
| Anthropic, PBC | LLM inference (default provider). Also file/image transcription and Anthropic-native web search / web fetch when those tools are enabled. | Credential: ANTHROPIC_API_KEY. Own account and credentials; own data processing terms; own transfer mechanism; verify retention and training position. |
| OpenAI, Inc. | LLM inference (openai/… models). Also embeddings when the brain embedding-model is a text-embedding-… model, and file/image transcription. | Credential: OPENAI_API_KEY. Own account and credentials; own data processing terms; own transfer mechanism; verify retention and training position. |
| xAI Corp. | LLM inference (Grok / xai/… models). | Credential: XAI_API_KEY. Own account and credentials; own data processing terms; own transfer mechanism; verify retention and training position. |
| Voyage AI, Inc. | LLM embeddings. Default when embedding-model is omitted (voyage-3-lite). | Credential: VOYAGE_API_KEY. Own account and credentials; own data processing terms; own transfer mechanism; verify retention and training position. |
| ElevenLabs, Inc. | Optional conversational / voice agents. Workflows with deployment-type: elevenlabs_conversational_ai are deployed to the customer's ElevenLabs account via an elevenlabs connector. | Own account and credentials; own data processing terms; own transfer mechanism; verify retention and training position. |