Tarseek Legal Center
Data Processing Addendum
This Data Processing Addendum (“DPA”) applies when Tarseek processes personal data on behalf of a Customer. Enterprise customers may also execute a signed copy. Self-service Customers who submit personal data through the API are covered by this DPA together with the Terms of Service.
1. Parties
Customer: the Tarseek Customer identified on an order form, account, or DPA signature block. Processor: Tarseek, Inc..
2. Definitions
Terms such as personal data, processing, controller, processor, subprocessor, and data subject have the meanings in applicable data-protection law (including GDPR where it applies). Capitalized terms not defined here follow the Terms.
3. Roles
- Tarseek as controller: account, billing, security, fraud, and website analytics as described in the Privacy Policy.
- Tarseek as processor: Customer Content submitted via the API or other Customer-controlled applications, processed on Customer’s instructions to provide the Service.
4. Processing instructions
Tarseek will process processor-role data only to provide the Service, as documented in the Terms and this DPA, and as required by law. Unlawful instructions may be refused.
5. Subject matter, duration, categories
- Subject matter: providing the Tarseek gateway and related features.
- Duration: the term of the Customer relationship plus deletion/return periods.
- Categories of data: determined by Customer Inputs (which may include personal data in prompts, files, or media).
- Data subjects: determined by Customer (end users, employees, or others whose data Customer submits).
Tarseek does not prescribe that Customers submit personal data; Customers choose their Inputs.
6. Confidentiality
Tarseek will ensure persons authorized to process personal data are bound by confidentiality.
7. Security measures
Tarseek will implement appropriate technical and organizational measures as described in Security & Trust.
8. Subprocessors
Customer authorizes Tarseek to use subprocessors listed on the Subprocessor List, including Model Providers required to fulfill a request. Tarseek will impose data-protection terms on subprocessors and provide notice of material additions.
9. Deletion and return
Upon termination, Tarseek will delete or return processor-role Customer Content from primary systems, except data Tarseek must retain as controller or by law, and except backup lag.
10. Breach notification
Tarseek will notify Customer without undue delay after becoming aware of a personal-data breach affecting processor-role data, and within 72 hours where applicable law requires that timing.
11. Data-subject requests
Taking into account the nature of processing, Tarseek will provide reasonable assistance for Customer to respond to data-subject requests. Tarseek may redirect requesters to Customer when Customer is the controller.
12. Audit rights
Audit rights are limited to relevant certifications, questionnaires, and, for enterprise Customers, on-site or remote audits under confidentiality and reasonable frequency limits.
13. International transfers
Where required, Tarseek uses Standard Contractual Clauses, the UK international data transfer addendum or IDTA, and other lawful transfer tools.
14. Applicable US privacy obligations
Where Tarseek is a “service provider” or “processor” under US state privacy laws, it will not sell or share (as defined) Customer’s processor-role personal data, or use it outside the business purpose of providing the Service, except as permitted by law and this DPA.
Version history
This is the current published version. Prior versions will be retained at stable URLs rather than silently overwritten.
Contact
Questions about this document: hello@tarseek.com. General inquiries: hello@tarseek.com.
