Tendril
Tendril
Home How It Works Features Pricing Compare How-To Download Security For Developers For PMs
Download Free
FOUNDING First 200 seats only

Lock in $19/mo $29/mo for life. Parallel agents, cross-project KG, audit pipeline.

Claim a founding seat

Data Processing Agreement (DPA)

Effective Date: April 15, 2026 Last Updated: August 10, 2026

1. Purpose

This Data Processing Agreement (“DPA”) forms part of the Terms and Conditions between Viral Host Digital LLC (“Processor”) and the Customer (“Controller”) for Pro tier subscriptions. It governs the processing of personal data in accordance with the General Data Protection Regulation (GDPR) (EU) 2016/679.

2. Scope

This DPA applies when the Customer is subject to GDPR and the Customer’s use of Tendril involves processing personal data for which the Customer is the data controller.

Note on the nature of Tendril: Tendril primarily runs on the Customer’s local device. Most personal data processed through Tendril never leaves the Customer’s device. This DPA covers the limited scenarios where personal data is transmitted to Viral Host Digital LLC’s servers (account and subscription records, content-free usage metering, and any bug report or feedback the Customer chooses to submit — including a screenshot, if the Customer attaches one).

3. Definitions

Terms used in this DPA shall have the meanings given in GDPR Article 4:

  • Personal Data — any information relating to an identified or identifiable natural person
  • Processing — any operation performed on personal data
  • Data Subject — an identified or identifiable natural person
  • Controller — the entity that determines the purposes and means of processing
  • Processor — the entity that processes data on behalf of the controller
  • Sub-processor — a third-party processor engaged by the Processor

4. Roles and Responsibilities

4.1 Controller

The Customer is the Controller of any personal data processed through Tendril.

4.2 Processor

Viral Host Digital LLC acts as a Processor only for the limited data transmitted to Viral Host Digital LLC’s servers:

  • Account and subscription records (email address, account identifier, subscription tier and billing cycle)
  • Licence and activation data, where a licence key is used (licence key, machine identifier, activation timestamps)
  • Device records for the devices registered to the account (device identifier, device name, operating system, first-registered and last-seen times)
  • Token usage counters (content-free aggregate token counts, used to enforce plan limits)
  • Diagnostic, error and aggregate usage information as described in the Privacy Policy
  • Bug reports and feedback the Customer chooses to submit through the in-app form, including the description, diagnostic details, and any screenshot the Customer attaches

Each category above is transmitted either to operate the subscription (authentication, plan-limit enforcement, licence validation, device registration) or because the Customer explicitly submitted it. Token counters are reported automatically after each AI request for the purpose of enforcing plan limits; the accompanying model, provider and pipeline-phase values are used to process that request. No prompt, response, code, or project file content is transmitted to Viral Host Digital LLC in any case.

5. Processor Obligations

Viral Host Digital LLC shall:

5.1 Processing Instructions

Process personal data only in accordance with documented instructions from the Controller, including this DPA and the Terms and Conditions. If required by law to process data beyond these instructions, Viral Host Digital LLC shall notify the Controller unless prohibited by law.

5.2 Confidentiality

Ensure that persons authorized to process personal data are bound by confidentiality obligations.

5.3 Security Measures

Implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:

  • Encryption of data in transit (TLS 1.2+)
  • Access controls and authentication for internal systems
  • Regular security reviews
  • Incident response procedures

5.4 Sub-processors

Engage sub-processors only with the Controller’s prior consent. Current sub-processors:

  • AWS (for licensing server infrastructure) — located in us-east-1 (N. Virginia), United States
  • Stripe (for payment processing) — located in the United States

Viral Host Digital LLC shall notify the Controller of any intended changes to sub-processors with at least 30 days’ notice.

5.5 Data Subject Rights

Assist the Controller, to the extent possible, in responding to requests from Data Subjects exercising their rights under GDPR (access, rectification, erasure, restriction, portability, objection).

5.6 Breach Notification

Notify the Controller without undue delay (and in any event within 72 hours) after becoming aware of a personal data breach.

5.7 Data Protection Impact Assessment

Assist the Controller with data protection impact assessments and prior consultations with supervisory authorities as required under GDPR Articles 35-36.

5.8 Return or Deletion

Upon termination of service, delete or return all personal data to the Controller within 30 days, unless retention is required by law.

5.9 Audits

Make available to the Controller all information necessary to demonstrate compliance with this DPA and allow for audits conducted by the Controller or an auditor mandated by the Controller, subject to reasonable notice and confidentiality obligations.

6. International Data Transfers

If personal data is transferred outside the European Economic Area (EEA), Viral Host Digital LLC shall ensure appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) approved by the European Commission.

7. Liability

Each party’s liability under this DPA is subject to the limitations of liability set forth in the Terms and Conditions.

8. Term

This DPA remains in effect for the duration of the Terms and Conditions and until all personal data has been returned or deleted in accordance with Section 5.8.

9. Amendments

This DPA may be amended only in writing, signed by both parties (electronic signatures acceptable).

10. Contact

Data Protection Officer: support@viralhostdigital.com

Customer contact for DPA matters: support@viralhostdigital.com


Annex 1: Description of Processing

Categories of Data Subjects:

  • Customer’s authorized users (employees, contractors) who install and use Tendril

Categories of Personal Data:

  • Account identifiers (email address, account identifier issued by our authentication provider)
  • Subscription records (payment-processor customer and subscription identifiers, tier, billing cycle)
  • Licence identifiers and activation timestamps, where a licence key is used
  • Device records (device identifier, device name, operating system, first-registered and last-seen times)
  • Content-free aggregate token counts, and the dates they were recorded
  • Diagnostic, error and aggregate usage information
  • Bug reports and feedback the Customer submits, including any attached screenshot

Processing Purposes:

  • Authenticating the Customer and operating their subscription
  • Licence validation and enforcement
  • Enforcing plan usage limits
  • Operating, securing and improving the Software
  • Responding to bug reports and support requests the Customer initiates
  • Fraud prevention

Duration of Processing:

  • Account records: while the account is active, then deleted within 30 days of account closure
  • Subscription records: duration of the subscription plus 3 years for tax and audit purposes
  • Token usage counters: retained keyed only on the account identifier, deleted within 30 days of account closure
  • Bug reports and feedback: retained while the issue is worked and for support records, deleted on request
  • Operational logs: excluded from the above, as described in the Privacy Policy

Annex 2: Technical and Organizational Security Measures

  • Encryption: TLS 1.2+ for all data in transit to licensing servers; local API keys encrypted via OS keychain
  • Access controls: Multi-factor authentication for internal systems; least-privilege access
  • Monitoring: Server logs retained for security monitoring and incident response
  • Backup: Regular encrypted backups of licensing database
  • Incident response: Documented procedures for identifying, containing, and reporting breaches
  • Training: Regular security awareness training for personnel
Tendril

Agent-first IDE. Local-first by design. Bring your own API key.

An app by Viral Host Digital

© 2026 Viral Host Digital LLC · Puerto Rico, USA
All rights reserved. Tendril™ is a trademark of Viral Host Digital LLC.

Product

Home Get Tendril Pricing Download Security How it works

Learn

How-to guides Compare For developers For PMs

Legal

Privacy Policy Terms & Conditions EULA Data Processing

Support

support@viralhostdigital.com viralhostdigital.com
Home Features Pricing Download Security