Data Processing Agreement (DPA)
Effective Date: April 15, 2026 Last Updated: August 10, 2026
1. Purpose
This Data Processing Agreement (“DPA”) forms part of the Terms and Conditions between Viral Host Digital LLC (“Processor”) and the Customer (“Controller”) for Pro tier subscriptions. It governs the processing of personal data in accordance with the General Data Protection Regulation (GDPR) (EU) 2016/679.
2. Scope
This DPA applies when the Customer is subject to GDPR and the Customer’s use of Tendril involves processing personal data for which the Customer is the data controller.
Note on the nature of Tendril: Tendril primarily runs on the Customer’s local device. Most personal data processed through Tendril never leaves the Customer’s device. This DPA covers the limited scenarios where personal data is transmitted to Viral Host Digital LLC’s servers (account and subscription records, content-free usage metering, and any bug report or feedback the Customer chooses to submit — including a screenshot, if the Customer attaches one).
3. Definitions
Terms used in this DPA shall have the meanings given in GDPR Article 4:
- Personal Data — any information relating to an identified or identifiable natural person
- Processing — any operation performed on personal data
- Data Subject — an identified or identifiable natural person
- Controller — the entity that determines the purposes and means of processing
- Processor — the entity that processes data on behalf of the controller
- Sub-processor — a third-party processor engaged by the Processor
4. Roles and Responsibilities
4.1 Controller
The Customer is the Controller of any personal data processed through Tendril.
4.2 Processor
Viral Host Digital LLC acts as a Processor only for the limited data transmitted to Viral Host Digital LLC’s servers:
- Account and subscription records (email address, account identifier, subscription tier and billing cycle)
- Licence and activation data, where a licence key is used (licence key, machine identifier, activation timestamps)
- Device records for the devices registered to the account (device identifier, device name, operating system, first-registered and last-seen times)
- Token usage counters (content-free aggregate token counts, used to enforce plan limits)
- Diagnostic, error and aggregate usage information as described in the Privacy Policy
- Bug reports and feedback the Customer chooses to submit through the in-app form, including the description, diagnostic details, and any screenshot the Customer attaches
Each category above is transmitted either to operate the subscription (authentication, plan-limit enforcement, licence validation, device registration) or because the Customer explicitly submitted it. Token counters are reported automatically after each AI request for the purpose of enforcing plan limits; the accompanying model, provider and pipeline-phase values are used to process that request. No prompt, response, code, or project file content is transmitted to Viral Host Digital LLC in any case.
5. Processor Obligations
Viral Host Digital LLC shall:
5.1 Processing Instructions
Process personal data only in accordance with documented instructions from the Controller, including this DPA and the Terms and Conditions. If required by law to process data beyond these instructions, Viral Host Digital LLC shall notify the Controller unless prohibited by law.
5.2 Confidentiality
Ensure that persons authorized to process personal data are bound by confidentiality obligations.
5.3 Security Measures
Implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
- Encryption of data in transit (TLS 1.2+)
- Access controls and authentication for internal systems
- Regular security reviews
- Incident response procedures
5.4 Sub-processors
Engage sub-processors only with the Controller’s prior consent. Current sub-processors:
- AWS (for licensing server infrastructure) — located in us-east-1 (N. Virginia), United States
- Stripe (for payment processing) — located in the United States
Viral Host Digital LLC shall notify the Controller of any intended changes to sub-processors with at least 30 days’ notice.
5.5 Data Subject Rights
Assist the Controller, to the extent possible, in responding to requests from Data Subjects exercising their rights under GDPR (access, rectification, erasure, restriction, portability, objection).
5.6 Breach Notification
Notify the Controller without undue delay (and in any event within 72 hours) after becoming aware of a personal data breach.
5.7 Data Protection Impact Assessment
Assist the Controller with data protection impact assessments and prior consultations with supervisory authorities as required under GDPR Articles 35-36.
5.8 Return or Deletion
Upon termination of service, delete or return all personal data to the Controller within 30 days, unless retention is required by law.
5.9 Audits
Make available to the Controller all information necessary to demonstrate compliance with this DPA and allow for audits conducted by the Controller or an auditor mandated by the Controller, subject to reasonable notice and confidentiality obligations.
6. International Data Transfers
If personal data is transferred outside the European Economic Area (EEA), Viral Host Digital LLC shall ensure appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) approved by the European Commission.
7. Liability
Each party’s liability under this DPA is subject to the limitations of liability set forth in the Terms and Conditions.
8. Term
This DPA remains in effect for the duration of the Terms and Conditions and until all personal data has been returned or deleted in accordance with Section 5.8.
9. Amendments
This DPA may be amended only in writing, signed by both parties (electronic signatures acceptable).
10. Contact
Data Protection Officer: support@viralhostdigital.com
Customer contact for DPA matters: support@viralhostdigital.com
Annex 1: Description of Processing
Categories of Data Subjects:
- Customer’s authorized users (employees, contractors) who install and use Tendril
Categories of Personal Data:
- Account identifiers (email address, account identifier issued by our authentication provider)
- Subscription records (payment-processor customer and subscription identifiers, tier, billing cycle)
- Licence identifiers and activation timestamps, where a licence key is used
- Device records (device identifier, device name, operating system, first-registered and last-seen times)
- Content-free aggregate token counts, and the dates they were recorded
- Diagnostic, error and aggregate usage information
- Bug reports and feedback the Customer submits, including any attached screenshot
Processing Purposes:
- Authenticating the Customer and operating their subscription
- Licence validation and enforcement
- Enforcing plan usage limits
- Operating, securing and improving the Software
- Responding to bug reports and support requests the Customer initiates
- Fraud prevention
Duration of Processing:
- Account records: while the account is active, then deleted within 30 days of account closure
- Subscription records: duration of the subscription plus 3 years for tax and audit purposes
- Token usage counters: retained keyed only on the account identifier, deleted within 30 days of account closure
- Bug reports and feedback: retained while the issue is worked and for support records, deleted on request
- Operational logs: excluded from the above, as described in the Privacy Policy
Annex 2: Technical and Organizational Security Measures
- Encryption: TLS 1.2+ for all data in transit to licensing servers; local API keys encrypted via OS keychain
- Access controls: Multi-factor authentication for internal systems; least-privilege access
- Monitoring: Server logs retained for security monitoring and incident response
- Backup: Regular encrypted backups of licensing database
- Incident response: Documented procedures for identifying, containing, and reporting breaches
- Training: Regular security awareness training for personnel