Legal
Data Processing Addendum
Draft processing terms for customer personal data handled by Teev’s hosted control plane.
Draft — not ready for execution1. Parties and scope
This addendum forms part of the agreement between the customer using Teev (“Customer”) and the legal entity operating Teev (“Teev”). It applies where Teev processes personal data on Customer’s behalf to provide the hosted service (“Customer Personal Data”).
It does not govern personal data for which Teev acts independently as controller, such as Teev’s own business contacts, billing, security administration and legal-compliance records; those uses are described in the Privacy notice.
Before execution: insert both parties’ legal identities, addresses, agreement reference, effective date and signature mechanism.
2. Roles and instructions
Customer is controller and Teev is processor for Customer Personal Data covered by this addendum, except where applicable law assigns another role. Teev will process that data only on documented Customer instructions, including the agreement and Customer’s use of the service, unless law requires otherwise. Teev will notify Customer of a conflicting instruction or legal requirement where permitted.
3. Confidentiality and personnel
Teev will limit access to people who need Customer Personal Data to operate, secure or support the service. Those people will be bound by confidentiality duties and receive appropriate security guidance.
4. Security
Teev will maintain appropriate technical and organisational measures proportionate to risk. Current measures include tenant-scoped API authorisation, separate staff authentication with MFA, HTTP-only secure session cookies, TLS-protected transport, encrypted S3 storage, DynamoDB point-in-time recovery, bounded inputs and a control/data-plane separation that keeps source code and credentials customer-side. Further detail appears on the Security page.
5. Subprocessors
Customer gives general authorisation for the subprocessors listed at teev.ai/subprocessors.html. Teev will impose data-protection obligations appropriate to each provider and remain responsible for its obligations under this addendum. Teev will provide advance notice of additions where required, and Customer may object on reasonable data-protection grounds.
6. Assistance
Taking account of the processing and information available, Teev will reasonably assist Customer with data-subject requests, security obligations, breach notifications, impact assessments and regulator consultations. Customer remains responsible for responding to requests and determining whether an assessment or consultation is required.
7. Security incidents
Teev will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data and provide available information needed for Customer’s response. Notification is not an admission of fault. Customer must provide a current security contact.
Before execution: agree any contractual notification deadline, escalation route and incident-content schedule.
8. Return and deletion
At the end of service, Teev will delete or return Customer Personal Data as instructed unless law requires retention. Workspace deletion removes its users, sessions, runs, runners, commands, benchmarks and grants from the control plane; a bounded deletion audit record remains. Source, patches, logs and full artifacts stay in Customer’s environment and remain Customer’s responsibility.
9. Demonstrating compliance
Teev will make information reasonably necessary to demonstrate compliance available to Customer. Subject to confidentiality, security and reasonable scope controls, Teev will support an audit where documentary evidence does not resolve a material concern. Customer bears audit costs unless the audit identifies material non-compliance.
10. International transfers
Customer authorises transfers needed to provide the service only where a lawful transfer mechanism applies. If restricted-transfer clauses are required, the parties will incorporate the applicable UK International Data Transfer Addendum, International Data Transfer Agreement or other approved mechanism.
Before execution: counsel must select the transfer mechanism, complete its tables and confirm each provider’s location and safeguards.
Annex A — processing details
| Subject | Providing account, workspace, scheduling, runner coordination, benchmark metadata, result summaries, support and security functions. |
|---|---|
| Duration | For the service term and limited retention needed for deletion, security, disputes and legal duties. |
| People | Customer users, invited team members, support contacts, repository contributors represented in bounded pull-request metadata. |
| Data | Names, work emails, roles, account identifiers, authentication and session events, repository names, task and pull-request identifiers, bounded contribution facts, result summaries, support messages and technical records. |
| Special-category data | Not intended. Customer must not intentionally submit special-category or criminal-offence data without a written amendment. |
| Frequency | Continuous during account and service use. |
Annex B — customer instructions
Customer instructs Teev to process Customer Personal Data as necessary to provide, secure, monitor and support the service; manage authorised users; coordinate Customer runners; display benchmark and result metadata; and delete data on authorised request. Additional instructions require written agreement.
