Tandem Data Processing Addendum Version 2026-09-05-draft.1
Draft for product-owner and UK specialist review. This revision does not authorise paid launch or replace a signed customer agreement.
A binding data processing agreement must identify the customer controller and service-provider processor and state the subject matter, duration, nature and purpose of processing, data types and categories of people. This draft is a review outline, not evidence that those parties have signed such an agreement.
Processing must follow documented controller instructions, including transfer instructions, subject to applicable law. Personnel with access must be subject to confidentiality obligations. The agreement must define appropriate security measures and the process for authorising subprocessors, notifying changes and raising objections.
The processor's obligations must cover assistance with individual rights, security, breach notification, impact assessments and regulatory consultation as applicable. The agreement must also cover return or deletion at the end of service, lawful retention exceptions, compliance information, audits and notification of an unlawful instruction.
The processing schedule, security measures, retention periods, subprocessor register, international transfers and incident contacts require confirmation for the actual service before customer launch. A user's receipt of this notice does not execute a Company data processing agreement or approve subprocessors.



