Data Processing Addendum (EU and UK)
This Data Processing Addendum (鈥淒PA鈥�) is incorporated into and forms part of the agreement between the Customer and 网曝门 Limited (鈥溚孛赔��) under which 网曝门 provides the 网曝门 Platform and related services, including any pilot agreement, order form or master services agreement that references this DPA (the 鈥淎greement鈥�).
This DPA applies where, and only to the extent that, 网曝门 processes Customer Personal Data that is subject to the EU GDPR or the UK GDPR. Processing subject to United States privacy laws is governed by the 网曝门 Data Processing Addendum (United States). This DPA takes effect when the Customer enters into the Agreement and does not need to be signed separately. For a signable version of this DPA, please contact your 网曝门 sales representative.
Contents
1. Definitions
Capitalised terms not defined in this DPA have the meanings given in the Agreement. 鈥淐ontroller鈥�, 鈥減rocessor鈥�, 鈥渄ata subject鈥�, 鈥減ersonal data鈥�, 鈥減rocessing鈥�, 鈥減ersonal data breach鈥�, 鈥渟upervisory authority鈥�, 鈥渟pecial categories of personal data鈥� and 鈥渂iometric data鈥� have the meanings given in the GDPR. In this DPA:
鈥淐ustomer鈥� means the entity that has entered into the Agreement with 网曝门.
鈥溚孛赔�� means 网曝门 Limited, a company incorporated in England and Wales with its registered office at Eagle Labs, 28 Chesterton Road, Cambridge CB4 3AZ, United Kingdom.
鈥淒ata Protection Laws鈥� means (i) Regulation (EU) 2016/679 (the 鈥淓U GDPR鈥�) and the laws of EEA Member States that supplement it; (ii) the EU GDPR as retained in UK law (the 鈥淯K GDPR鈥�) and the Data Protection Act 2018, each as amended, including by the Data (Use and Access) Act 2025; and (iii) any other law relating to the protection of personal data that applies to the processing of Customer Personal Data under the Agreement.
鈥淐ustomer Personal Data鈥� means personal data that 网曝门 processes on behalf of the Customer under the Agreement.
鈥淓U SCCs鈥� means the standard contractual clauses annexed to Commission Implementing Decision (EU) 2021/914 of 4 June 2021, Module Two (controller to processor).
鈥淯K Addendum鈥� means the International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018, version B1.0, in force from 21 March 2022, as amended from time to time.
鈥淩estricted Transfer鈥� means a transfer of Customer Personal Data that is subject to the EU GDPR to a country outside the EEA without an adequacy decision, or a transfer of Customer Personal Data that is subject to the UK GDPR to a country outside the UK without UK adequacy regulations.
鈥淎nonymised Data鈥� means data that does not relate to an identified or identifiable natural person, taking account of all the means reasonably likely to be used to identify a person, so that it is not personal data under Data Protection Laws.
鈥淐ustomer Video Assets鈥� means all raw video files, footage and associated metadata provided by the Customer or captured through the Customer鈥檚 systems and processed within the 网曝门 Platform.
鈥淎I-Generated Insights鈥� means the metrics, alerts, reports and other outputs generated by the 网曝门 Platform from Customer Video Assets.
鈥溚孛� Platform鈥� means the 网曝门 Visual Intelligence software-as-a-service platform for video understanding and analytics.
鈥淪ub-processor鈥� means any third party engaged by 网曝门 to process Customer Personal Data.
2. Roles and scope
2.1 The Customer is the controller and 网曝门 is the processor of Customer Personal Data. Each party will comply with the obligations that apply to it under Data Protection Laws.
2.2 网曝门 processes Customer Personal Data only on the Customer鈥檚 documented instructions, which include training, fine-tuning and evaluating the models used to provide the services to the Customer. The Agreement and this DPA are the Customer鈥檚 complete instructions at the date of the Agreement; further instructions must be in writing and consistent with the Agreement. 网曝门 will tell the Customer immediately if, in its opinion, an instruction infringes Data Protection Laws.
2.3 The Customer is responsible for:
(a) having a lawful basis for the processing, including any legitimate interests assessment;
(b) providing notices and signage to individuals at its locations as required by Articles 13 and 14 GDPR;
(c) carrying out a data protection impact assessment where required, including for systematic monitoring of publicly accessible areas;
(d) informing or consulting employees and their representatives, including works councils, where national law requires it; and
(e) meeting its own obligations as a deployer under Regulation (EU) 2024/1689 (the 鈥淓U AI Act鈥�) where it applies.
3. Details of processing
This Section also completes Annex I.B of the EU SCCs.
(a) Subject matter: the provision of the 网曝门 Platform and related services under the Agreement.
(b) Duration: the term of the Agreement, including any agreed extensions, followed by the retention periods in Section 11.
(c) Nature: collection, streaming, analysis, storage and dashboard visualisation of video from cameras installed at Customer locations. Frequency: continuous for the duration of the Agreement.
(d) Purpose: to provide operational insights and to evaluate service quality, throughput, labour productivity, compliance events, task adherence and efficiency and, where enabled by the Customer, aggregated customer sentiment, and to train, fine-tune and evaluate the models used to provide the services to the Customer, as described in the Agreement.
(e) Categories of data subjects: customers and visitors at Customer locations; employees and contractors of the Customer captured in camera footage.
(f) Categories of personal data:
(i) video footage from installed cameras;
(ii) metadata and derived insights, including queue dynamics, dwell times, task adherence and behavioural trends;
(iii) safety and compliance event markers, such as falls and use of personal protective equipment;
(iv) aggregate demographic estimates, where enabled by the Customer; and
(v) aggregated sentiment indicators, where enabled by the Customer, which cannot be attributed to any particular individual.
(g) Special categories of personal data: none intended. See Section 4.
(h) Reporting: 网曝门 reports AI-Generated Insights and other analytics derived from Customer Video Assets to the Customer in aggregated form, as totals, averages, rates and trends across locations, time periods or groups of people, and does not attribute them to any identified individual. Event alerts that the Customer configures, and the video clips linked to them, identify the event, location and time and do not name the person involved. This paragraph does not limit how the 网曝门 Platform displays data that the Customer provides from its own systems, such as point-of-sale or scheduling data. Aggregation applies to how outputs are reported. It does not limit the processing of Customer Video Assets at frame or image level, including the training, fine-tuning and evaluation instructed in Section 2.2.
4. Special category data, biometric data and sentiment
This Section prevails over any inconsistent provision of this DPA or the Agreement, other than the EU SCCs.
(a) 网曝门 does not process biometric data for the purpose of uniquely identifying a natural person, and does not otherwise intend to process special categories of personal data.
(b) The 网曝门 Platform does not perform facial recognition, facial identification, or any scan of face or hand geometry, and does not generate, store or transmit any faceprint, template or other mathematical representation of an individual鈥檚 facial geometry.
(c) Where the Customer enables aggregate demographic estimation, that feature produces only aggregate, non-identifying counts by attribute band. It does not create a persistent identifier for any individual, does not match any individual across visits, and does not retain any representation from which an individual could be identified.
(d) Where the Customer enables sentiment analysis, the 网曝门 Platform produces sentiment indicators only in aggregated form, across groups of people and periods of time. Sentiment outputs cannot be attributed to any particular individual, and the 网曝门 Platform does not create, store or report the emotional state of any identified or identifiable person. The 网曝门 Platform does not categorise individuals on the basis of biometric data to deduce or infer their race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation.
(e) Neither party will enable a feature that would cause the 网曝门 Platform to process special categories of personal data, or biometric data for unique identification, without a prior written amendment to this DPA signed by both parties and a data protection impact assessment.
(f) 网曝门 will notify the Customer in writing at least thirty (30) days before releasing any feature that would change the position in paragraphs (a) to (d).
5. Audio
The 网曝门 Platform does not capture, record, process or store audio. Where a camera at a covered location is capable of capturing audio, the Customer is responsible for disabling audio capture or for complying with any national law that applies to recording audio.
6. 网曝门 obligations
网曝门 shall:
(a) process Customer Personal Data, including any transfer to a third country, only on the Customer鈥檚 documented instructions, unless required to do so by EU, Member State or UK law, in which case 网曝门 will inform the Customer of that legal requirement before processing unless the law prohibits it;
(b) ensure that persons authorised to process Customer Personal Data are bound by appropriate confidentiality obligations;
(c) implement and maintain the technical and organisational measures required by Article 32 GDPR, as documented at the 网曝门 Trust Center (), which form Annex II of the EU SCCs. 网曝门 may update these measures provided the overall level of security is not reduced;
(d) taking into account the nature of the processing, assist the Customer by appropriate technical and organisational measures in responding to requests from data subjects to exercise their rights under Chapter III GDPR, and promptly pass to the Customer any such request it receives directly;
(e) assist the Customer in meeting its obligations under Articles 32 to 36 GDPR, including data protection impact assessments and prior consultation with supervisory authorities, taking into account the nature of the processing and the information available to 网曝门;
(f) notify the Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notice will include, so far as then known, the information listed in Article 33(3) GDPR. 网曝门 will provide further information as it becomes available and take reasonable steps to contain and remedy the breach;
(g) delete or return Customer Personal Data in accordance with Section 11;
(h) make available to the Customer the information necessary to demonstrate compliance with Article 28 GDPR and allow for and contribute to audits in accordance with Section 12;
(i) maintain a record of processing activities carried out on behalf of the Customer as required by Article 30(2) GDPR; and
(j) where permitted by law, promptly notify the Customer of any legally binding request from a public authority for access to Customer Personal Data, and challenge the request where there are reasonable grounds to do so.
7. Anonymised data and model training
The Customer instructs 网曝门 to create Anonymised Data from Customer Video Assets. 网曝门 may use Anonymised Data to operate, maintain and improve the 网曝门 Platform, including model training, validation and benchmarking, provided that 网曝门:
(a) applies anonymisation techniques appropriate to video data and to the state of the art, and reviews them periodically;
(b) does not attempt to re-identify any individual or the Customer from Anonymised Data, except to test the effectiveness of its anonymisation measures;
(c) contractually obliges any recipient of Anonymised Data to the same restrictions; and
(d) does not disclose any Customer Video Assets, any Customer Personal Data, or any AI-Generated Insight specific to the Customer, to any third party.
Customer Personal Data that has not been anonymised in accordance with this Section is used to train, fine-tune and evaluate models only as instructed in Section 2.2, and is not disclosed to any other customer.
鈥淢odel Assets鈥� means the models, model weights and parameters, and other improvements to the 网曝门 Platform that result from training, fine-tuning or evaluation under Section 2.2 or this Section, excluding any stored copy of Customer Video Assets or Customer Personal Data. Model Assets are owned by 网曝门. The parties agree that Model Assets are not Customer Personal Data, Customer Video Assets or AI-Generated Insights, and 网曝门 is not required to delete, retrain or modify any Model Asset on termination or expiry of the Agreement or in response to a data subject request. 网曝门 will maintain technical and organisational measures designed to prevent personal data from being extracted from or reproduced by any Model Asset, and will not use any Model Asset to identify an individual. If a supervisory authority or court determines that a Model Asset contains Customer Personal Data, 网曝门 will take reasonable steps to remedy this, which may include filtering, fine-tuning or retraining, at its own cost.
鈥淭raining Data鈥� means individual frames, short clips and associated annotations that 网曝门 selects from Customer Video Assets and adds to a curated dataset for the training, fine-tuning, validation or evaluation of models as instructed in Section 2.2, excluding continuous or bulk recordings. The Customer instructs 网曝门 to retain Training Data during the term of the Agreement and for up to thirty-six (36) months after its termination or expiry, for as long as it is necessary for those purposes. 网曝门 will review its Training Data at least once a year and delete items it no longer needs. Training Data that has not been anonymised remains Customer Personal Data and this DPA continues to apply to it. 网曝门 will:
(a) store Training Data encrypted and restrict access to personnel and Sub-processors who need it for those purposes;
(b) apply blurring or similar measures to faces and other identifiers where this does not materially reduce the usefulness of the data for training or evaluation;
(c) not use Training Data for any other purpose or disclose it to any other customer; and
(d) delete specific items of Training Data on the Customer鈥檚 instruction where needed to respond to a data subject request, without any obligation to delete, retrain or modify Model Assets.
8. Sub-processors
8.1 The Customer gives 网曝门 general written authorisation to engage Sub-processors. The current list of Sub-processors is maintained at the 网曝门 Trust Center () and forms Annex III of the EU SCCs.
8.2 网曝门 will give the Customer at least ten (10) days鈥� notice of any intended addition or replacement of a Sub-processor, by updating that list and notifying any email address the Customer has registered for notifications. The Customer may object on reasonable grounds within that period, in which case the parties will discuss the objection in good faith.
8.3 网曝门 will impose on each Sub-processor, by written contract, data protection obligations no less protective than those in this DPA, in particular providing sufficient guarantees to implement appropriate technical and organisational measures. 网曝门 remains fully liable to the Customer for the performance of each Sub-processor鈥檚 obligations.
9. International transfers
9.1 网曝门 is established in the United Kingdom. Transfers of Customer Personal Data from the EEA to 网曝门 in the United Kingdom rely on the adequacy decision adopted by the European Commission under Article 45 EU GDPR in respect of the United Kingdom, as renewed on 19 December 2025, for as long as it remains in force.
9.2 If that adequacy decision is repealed, suspended, expires or is otherwise no longer valid, the EU SCCs, completed as set out in Section 10, will apply automatically to transfers from the Customer (as data exporter) to 网曝门 (as data importer) from the date the decision ceases to apply.
9.3 网曝门 will not make, or permit a Sub-processor to make, a Restricted Transfer of Customer Personal Data unless the transfer is covered by:
(a) an adequacy decision or UK adequacy regulations, including the EU-US Data Privacy Framework and its UK Extension where the recipient is certified; or
(b) the EU SCCs, the UK Addendum or the UK International Data Transfer Agreement, together with a transfer risk assessment and any supplementary measures it identifies as necessary.
9.4 网曝门 will not transfer Customer Personal Data to any jurisdiction other than the United Kingdom, the EEA or the United States without the Customer鈥檚 prior written consent.
10. Standard contractual clauses
Where the EU SCCs apply under this DPA, they are incorporated by reference and completed as follows:
(a) Module Two applies;
(b) the optional docking clause in Clause 7 applies;
(c) in Clause 9, Option 2 applies and the notice period is the one in Section 8.2;
(d) the optional language in Clause 11 does not apply;
(e) in Clause 13, the competent supervisory authority is the one determined under Clause 13(a);
(f) in Clause 17, Option 1 applies and the EU SCCs are governed by the law of the Republic of Bulgaria;
(g) in Clause 18(b), disputes are resolved before the courts of Sofia, Bulgaria; and
(h) Annex I is completed by the details of the parties in the Agreement and by Section 3, Annex II by the measures documented at the 网曝门 Trust Center, and Annex III by the Sub-processor list at the 网曝门 Trust Center.
Where a Restricted Transfer is subject to the UK GDPR, the UK Addendum applies. Tables 1 to 3 are completed with the information in this Section and Section 3, and for Table 4 neither party may end the UK Addendum under its Section 19. If there is a conflict between this DPA and the EU SCCs or the UK Addendum, the EU SCCs or the UK Addendum prevail.
11. Retention, deletion and return
网曝门 retains Customer Video Assets in accordance with the Agreement, and in any event no longer than ninety (90) days of continuous footage unless required for active analysis or a shorter period is configured by the Customer. Training Data is not continuous footage and is retained under Section 7.
On termination or expiry of the Agreement, or on the Customer鈥檚 written request, 网曝门 shall, at the Customer鈥檚 choice, delete or return all Customer Personal Data within thirty (30) days, except for Anonymised Data, Training Data and Model Assets under Section 7, and any Customer Personal Data that EU, Member State or UK law requires 网曝门 to keep, which 网曝门 will protect and process only for that purpose. Certification of deletion will be provided on request.
12. Audit
12.1 网曝门 will make available on request its current security documentation, completed security questionnaires and any third-party audit reports or certifications it holds, through the 网曝门 Trust Center or otherwise, subject to confidentiality.
12.2 Where that information is not sufficient to demonstrate compliance with this DPA, where a supervisory authority requires it, or following a personal data breach affecting Customer Personal Data, the Customer or an independent auditor bound by confidentiality may carry out an inspection on at least thirty (30) days鈥� written notice, during business hours and with minimal disruption. Except in the case of a supervisory authority request or a personal data breach, the Customer may exercise this right no more than once in any twelve-month period. Each party bears its own costs unless the audit reveals a material breach of this DPA by 网曝门.
13. Liability
Each party鈥檚 liability under or in connection with this DPA is subject to the limitations and exclusions of liability in the Agreement, except to the extent that applicable law does not permit them. Nothing in this DPA limits the rights of data subjects under the EU SCCs or Data Protection Laws.
14. Governing law
This DPA is governed by the law that governs the Agreement, except that the EU SCCs and the UK Addendum are governed as set out in Section 10, and except where Data Protection Laws require otherwise.
15. Precedence
In the event of a conflict, the following order of precedence applies:
(a) the EU SCCs and the UK Addendum, where they apply;
(b) Section 4 of this DPA;
(c) the rest of this DPA; and
(d) the Agreement.
16. Versions and updates
This is version 1.0 of this DPA. The version in effect on the date the Customer enters into the Agreement (or, for a renewal or new order, the date of that renewal or order) applies to the Customer for the term of that Agreement or order.
网曝门 may publish updated versions of this DPA. An updated version applies to an existing Customer only when the Customer renews or places a new order, or agrees to it in writing, except where a change is required by Data Protection Laws or does not reduce the protection given to Customer Personal Data, in which case 网曝门 will give the Customer at least thirty (30) days鈥� notice before it takes effect. Previous versions are listed in the 网曝门 Legal Center and are available on request.
17. Execution and contact
This DPA forms part of the Agreement and is binding on the parties without a separate signature. For a signable version of this DPA, please contact your 网曝门 sales representative.
Questions about this DPA can be sent to 网曝门 Limited, Eagle Labs, 28 Chesterton Road, Cambridge CB4 3AZ, United Kingdom, or by email to legal@tenyks.ai.
EU representative under Article 27 GDPR: Diana Koleva, Head of Legal (diana.koleva@tenyks.ai).
Version history
- Version 1.0 (October 1, 2026): first publicly available published version.






