Tebelis AI
Platform
PricingBlogDocs
Sign inCreate workspace

Tebelis AI — Data Processing Agreement (DPA)

How this DPA applies: it is incorporated by reference into the Terms of Service and forms part of them. It therefore applies automatically to every customer — self-serve (Stripe) and Enterprise alike — without a separate signature. Enterprise customers who require a signed copy may request one; the terms are the same. Where this DPA conflicts with the Terms on data-protection matters, this DPA prevails.

Last updated / Effective date: 7 July 2026

This Data Processing Agreement ("DPA") is between the customer ("Customer", the controller) and Tebelis AI, a French SASU (registered office 173 rue de Courcelles, 75017 Paris; RCS Paris / SIREN 107 153 819) ("Tebelis AI", the processor), and governs the processing of Customer Personal Data in connection with the Tebelis AI platform (the "Service"). Capitalised terms not defined here have the meaning given in the Terms.

1. Definitions

"GDPR" means Regulation (EU) 2016/679, and "UK GDPR" the UK-retained version. "Controller", "Processor", "Data Subject", "Personal Data", "Processing", "Personal Data Breach", and "Supervisory Authority" have the meanings in the GDPR. "Customer Personal Data" means Personal Data within Customer Data that Tebelis AI Processes on the Customer's behalf. "Sub-processor" means a third party engaged by Tebelis AI to Process Customer Personal Data. "SCCs" means the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), and "UK Addendum" the UK International Data Transfer Addendum.

2. Roles and scope

2.1 The Customer is the Controller (or, where the Customer is itself a processor for a third party, the processor) of Customer Personal Data; Tebelis AI is the Processor (or Sub-processor). Each party complies with its obligations under Data Protection Law.

2.2 This DPA applies to Tebelis AI's Processing of Customer Personal Data for the duration of the Terms. Annex I describes the Processing.

2.3 For Personal Data where Tebelis AI acts as an independent controller (account registration, billing, security, and website data described in the Privacy Policy), the Privacy Policy — not this DPA — governs.

3. Processing on instructions

3.1 Tebelis AI Processes Customer Personal Data only on the Customer's documented instructions, including as set out in this DPA and the Terms and as configured by the Customer through the Service. Operating, securing, and supporting the Service in accordance with the Terms constitutes such instructions. This includes diagnosing and correcting faults in the Service, which may require authorised Tebelis AI personnel to review the content of an AI-assistant conversation in order to establish why the assistant behaved incorrectly. Such review is limited to what is necessary to identify and fix the fault, is carried out inside the same EU-region infrastructure and by the same sub-processors already listed in Annex III, and — for the avoidance of doubt — is never used to train any AI or foundation model (see §3.2).

3.2 Tebelis AI will inform the Customer if, in its opinion, an instruction infringes Data Protection Law (without obligation to provide legal advice). Tebelis AI will not Process Customer Personal Data for its own purposes, and will not use Customer Personal Data to train its or any third party's AI/foundation models except on the Customer's documented instruction.

3.3 If Tebelis AI is required by EU or Member-State law to Process beyond the instructions, it will inform the Customer first unless that law prohibits it.

4. Confidentiality

Tebelis AI ensures that personnel authorised to Process Customer Personal Data are bound by confidentiality and are trained on their obligations, and limits access to those who need it to provide the Service (least privilege).

5. Security

Tebelis AI implements appropriate technical and organisational measures under Article 32, as described in Annex II, and may update them provided the level of protection is not materially reduced.

6. Sub-processors

6.1 The Customer gives general authorisation for Tebelis AI to engage Sub-processors to Process Customer Personal Data. The current Sub-processors are listed in Annex III (the public sub-processor list).

6.2 Tebelis AI imposes data-protection obligations on each Sub-processor that are substantially equivalent to those in this DPA, and remains liable for its Sub-processors' performance.

6.3 Tebelis AI will give the Customer prior notice of any new or replacement Sub-processor (by updating the list and/or a notice mechanism the Customer can subscribe to). The Customer may object on reasonable data-protection grounds within 30 days; the parties will work in good faith to resolve it, and if they cannot, the Customer may terminate the affected part of the Service.

7. Data-subject requests

Taking into account the nature of the Processing, Tebelis AI assists the Customer, by appropriate technical and organisational measures and insofar as possible, to respond to Data-Subject requests (access, rectification, erasure, restriction, portability, objection). The Service provides self-serve tools for the Customer to export and erase a person's data (erasure by deletion or by irreversible anonymisation / "tombstoning"). If a Data Subject contacts Tebelis AI directly about Customer Data, Tebelis AI will refer them to the Customer.

8. Assistance, breach notification, DPIAs

8.1 Tebelis AI assists the Customer in ensuring compliance with Articles 32–36 (security, breach notification, and data-protection impact assessments / prior consultation), taking into account the nature of Processing and the information available to Tebelis AI.

8.2 Tebelis AI notifies the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, with the information reasonably available to help the Customer meet its own notification duties.

9. Deletion and return

On termination of the Service, Tebelis AI deletes or returns Customer Personal Data per the Customer's choice, subject to the retention described in the Terms and Privacy Policy: a post-termination export window, then deletion/anonymisation, with recoverable (recycle-bin) records purged on their schedule and routine backups expiring on a rolling cycle. Tebelis AI may retain data where required by law (e.g. billing records) and append-only audit/security logs as permitted.

10. Audits

Tebelis AI makes available to the Customer information reasonably necessary to demonstrate compliance with Article 28 and allows for and contributes to audits, including inspections. To minimise disruption, audits are on reasonable prior notice, no more than once per 12 months (unless required by a Supervisory Authority or following a Breach), during business hours, subject to confidentiality, and may be satisfied by Tebelis AI's then-current third-party reports or documentation where available.

11. International transfers

11.1 Tebelis AI Processes Customer Personal Data within the EEA where feasible (see Annex III for hosting region(s)). Where Customer Personal Data is transferred to a country without an adequacy decision, the parties rely on an appropriate safeguard — primarily the EU SCCs (Module Two, controller-to-processor, or Module Three, processor-to-processor, as applicable), and the UK Addendum for UK data — which are incorporated by reference into this DPA and completed with the details in the Annexes.

11.2 For each Sub-processor outside the EEA, the relevant transfer mechanism is identified in Annex III.

12. Liability, term, governing law

12.1 Each party's liability under this DPA is subject to the limitations and exclusions in the Terms.

12.2 This DPA takes effect on the effective date and remains in force for as long as Tebelis AI Processes Customer Personal Data; the obligations survive accordingly.

12.3 This DPA is governed by the laws of France, consistent with the Terms, except where Data Protection Law requires otherwise.

Annex I — Description of the Processing

  • Subject matter: provision of the Tebelis AI platform (forms, records, workflows, projects, people

management, analytics, and AI assistance) to the Customer.

  • Duration: the term of the Terms, plus the retention/deletion periods described above.
  • Nature and purpose: hosting, storage, organisation, retrieval, display, transmission, and

AI-assisted processing of Customer Data to operate the Service on the Customer's instructions.

  • Types of Personal Data: identification and contact details (name, email, role); profile data

(avatar, language); authentication/security data (sessions, IP/device, login events); content the Customer chooses to store in forms, records, attachments (including photos — image EXIF/GPS metadata is stripped on upload), comments, and public-form submissions; and the content of AI-assistant conversations. The Customer controls what categories it enters and must not enter special-category data unless separately agreed (see Terms §8).

  • Categories of Data Subjects: the Customer's authorised users (employees, contractors), the people

recorded in the Customer's forms/records, and respondents to the Customer's public forms.

  • Frequency: continuous, for the duration of the Service.

Annex II — Technical and organisational security measures (Article 32)

  • Tenant isolation between Customer workspaces, enforced at the database with row-level security.
  • Encryption in transit (TLS); encryption at rest of sensitive stored credentials.
  • Access control on least-privilege principles; per-user, per-role, and per-project permissions;

hashed passwords (argon2); session and token-based authentication.

  • Data minimisation on upload: image (EXIF/GPS) metadata stripped from images; AI-conversation

storage replaces images with a placeholder.

  • Auditability: append-only audit logging of significant actions; security events

(authentication failures, lockouts, permission denials) are logged and monitored with alerting.

  • Retention controls: soft-delete with scheduled purge for records; idle-conversation purge; user

erasure via deletion/anonymisation.

  • Resilience: managed cloud infrastructure with backups; logging and monitoring.
  • Sub-processor management under Section 6.

(This annex states measures in force as of the effective date and is kept current.)

Annex III — Sub-processors

The current list of Sub-processors, the service each provides, the categories of data, the hosting region, and the applicable transfer safeguard is maintained on our Sub-processors page, which forms part of this DPA.

Annex IV — SCC signature details

  • Data exporter: the Customer (controller) — identity per the account/Order.
  • Data importer: Tebelis AI (SASU), 173 rue de Courcelles, 75017 Paris, France; SIREN 107 153 819;

represented by its President Alexandre Batzakakis; contact [email protected].

  • Modules: Two (controller→processor) and Three (processor→sub-processor) as applicable.
  • Clause options / docking clause / governing law (France) / supervisory authority (CNIL): to be

completed and, for Enterprise, signed.


Tebelis AI

The agentic platform for field work.

Product
PlatformPricingDocsSee it work
Use cases
Sector use casesSecurityBlog
Get started
Create workspaceSign inContact us
Legal
Terms of ServicePrivacy PolicyData Processing AgreementSub-processorsMentions légales
© 2026 TebelisAI-native records, forms & workflows