Data Processing Addendum (United States)
This Data Processing Addendum (“DPA”) is incorporated into and forms part of the agreement between the Customer and Tenyks Limited (“Tenyks”) under which Tenyks provides the Tenyks Platform and related services, including any pilot agreement, order form or master services agreement that references this DPA (the “Agreement”).
This DPA applies where, and only to the extent that, Tenyks processes Personal Information on behalf of the Customer that is subject to US Data Protection Laws. Where the Customer has operations or data subjects in the European Economic Area or the United Kingdom, the Tenyks Data Processing Addendum (EU and UK) applies to that processing. This DPA takes effect when the Customer enters into the Agreement and does not need to be signed separately. For a signable version of this DPA, please contact your Tenyks sales representative.
Contents
1. Definitions
Capitalised terms not defined in this DPA have the meanings given in the Agreement or, where not defined there, in the applicable US Data Protection Laws. In this DPA:
“Customer” means the entity that has entered into the Agreement with Tenyks. The Customer is the “Business” (or “Controller”) that determines the purposes and means of the processing of Personal Information.
“Tenyks” means Tenyks Limited, a company incorporated in England and Wales, which processes Personal Information on behalf of the Customer as a “Service Provider” (or “Processor”).
“US Data Protection Laws” means the privacy and data protection laws of the United States and its States that apply to the processing of Personal Information under the Agreement, as described in Section 3.
“Personal Information” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household, and that Tenyks processes on behalf of the Customer under the Agreement.
“Biometric Identifier” means a retina or iris scan, fingerprint, voiceprint, or scan of hand or face geometry, and any other identifier defined as a biometric identifier under applicable law, including the Illinois Biometric Information Privacy Act (740 ILCS 14) and the Texas Capture or Use of Biometric Identifier Act (Tex. Bus. & Com. Code § 503.001).
“Deidentified Data” means data that cannot reasonably be used to infer information about, or otherwise be linked to, an identified or identifiable individual, and that meets the deidentification standard of each applicable US Data Protection Law.
“Customer Video Assets” means all raw video files, footage and associated metadata provided by the Customer or captured through the Customer’s systems and processed within the Tenyks Platform.
“AI-Generated Insights” means the metrics, alerts, reports and other outputs generated by the Tenyks Platform from Customer Video Assets.
“Tenyks Platform” means the Tenyks Visual Intelligence software-as-a-service platform for video understanding and analytics.
“Sub-processor” means any third party engaged by Tenyks to process Personal Information on behalf of the Customer.
2. Roles of the parties
The Customer is the controller of, and determines the purposes and means of processing, all Personal Information processed under the Agreement. Tenyks processes Personal Information solely on behalf of the Customer and at its direction.
The Customer is responsible for providing all notices to, and obtaining all consents and authorisations from, individuals required by applicable law in connection with the installation and operation of cameras at its locations, including any notices required of employers in respect of workplace monitoring.
3. Applicable law
This DPA applies to processing governed by the privacy and data protection laws of the United States and its States, including as applicable the California Consumer Privacy Act as amended by the California Privacy Rights Act (Cal. Civ. Code § 1798.100 et seq.) (“CCPA”), the Virginia Consumer Data Protection Act, the Colorado Privacy Act, the Connecticut Data Privacy Act, the Utah Consumer Privacy Act and comparable State statutes then in effect, together with State biometric privacy statutes and State data breach notification laws.
4. Subject matter and duration
Tenyks processes Personal Information solely to deliver the services described in the Agreement, namely the deployment and operation of the Tenyks Platform for the Customer. The duration of processing corresponds to the term of the Agreement, including any agreed extensions, followed by the retention periods in Section 11.
5. Nature and purpose of processing
(a) Nature. Collection, streaming, analysis, storage and dashboard visualisation of video from cameras installed at Customer locations.
(b) Purpose. To provide operational insights and to evaluate service quality, throughput, labour productivity, compliance events, task adherence and efficiency, and to train, fine-tune and evaluate the models used to provide the services to the Customer, as described in the Agreement.
(c) Reporting. Tenyks reports AI-Generated Insights and other analytics derived from Customer Video Assets to the Customer in aggregated form, as totals, averages, rates and trends across locations, time periods or groups of people, and does not attribute them to any identified individual. Event alerts that the Customer configures, and the video clips linked to them, identify the event, location and time and do not name the person involved. This paragraph does not limit how the Tenyks Platform displays data that the Customer provides from its own systems, such as point-of-sale or scheduling data. Aggregation applies to how outputs are reported. It does not limit the processing of Customer Video Assets at frame or image level, including the training, fine-tuning and evaluation described in paragraph (b).
6. Categories of individuals and Personal Information
(a) Individuals: customers, visitors and employees or contractors of the Customer captured in camera footage at the covered locations.
(b) Personal Information: (i) video footage from installed cameras; (ii) metadata and derived insights, including queue dynamics, dwell times, task adherence and behavioural trends; (iii) safety and compliance event markers; (iv) aggregate demographic estimates, where enabled by the Customer; and (v) aggregated sentiment indicators, where enabled by the Customer, which are produced only in aggregated form and cannot be attributed to any particular individual.
7. Biometric restriction
This Section controls over any inconsistent provision of this DPA or the Agreement.
(a) Tenyks does not collect, capture, purchase, receive through trade, or otherwise obtain any Biometric Identifier or biometric information from Customer Video Assets.
(b) The Tenyks Platform does not perform facial recognition, facial identification, or any scan of face or hand geometry, and does not generate, store or transmit any faceprint, template or other mathematical representation of an individual’s facial geometry.
(c) Where the Customer enables aggregate demographic estimation, that feature produces only aggregate, non-identifying counts by attribute band. It does not create a persistent identifier for any individual, does not match any individual across visits, and does not retain any representation from which an individual could be identified.
(d) Tenyks will not enable, and the Customer will not request, any feature that would cause the Tenyks Platform to collect a Biometric Identifier without a prior written amendment to this DPA executed by both parties and a compliance assessment addressing the written notice, written release and retention schedule requirements of applicable State biometric law.
(e) Tenyks will notify the Customer in writing at least thirty (30) days before releasing any feature that would change the position in paragraphs (a) to (c).
8. Audio
The Tenyks Platform does not capture, record, process or store audio. Where a camera at a covered location is capable of capturing audio, the Customer is responsible for disabling audio capture or for obtaining all consents required under applicable Federal and State wiretapping and eavesdropping laws, including two-party consent statutes.
9. Tenyks obligations and restrictions
Tenyks shall:
(a) process Personal Information only for the business purposes specified in this DPA and the Agreement, and only on documented instructions from the Customer;
(b) not sell or share Personal Information, as those terms are defined under applicable US Data Protection Laws;
(c) not retain, use or disclose Personal Information outside the direct business relationship between the parties, or for any commercial purpose other than the business purposes specified, except as permitted by Section 10;
(d) not combine Personal Information received from the Customer with personal information received from, or on behalf of, any other person, except as permitted by applicable law for a service provider;
(e) comply with the obligations that apply to it under US Data Protection Laws and provide the same level of privacy protection as those laws require of the Customer;
(f) ensure that personnel authorised to process Personal Information are bound by appropriate confidentiality obligations;
(g) implement and maintain reasonable technical, physical and administrative safeguards appropriate to the nature of the Personal Information, consistent with the measures documented at the Tenyks Trust Center (https://trust.tenyks.ai/);
(h) provide reasonable assistance to the Customer in responding to verifiable consumer requests to know, delete, correct, or opt out;
(i) notify the Customer without undue delay, and in any event within seventy-two (72) hours, upon becoming aware of a breach of security leading to unauthorised access to or acquisition of Personal Information, and provide the information reasonably necessary for the Customer to meet its obligations under State breach notification laws;
(j) notify the Customer promptly if it determines that it can no longer meet its obligations under US Data Protection Laws; and
(k) grant the Customer the right, on notice, to take reasonable and appropriate steps to stop and remediate unauthorised use of Personal Information.
Tenyks certifies that it understands the restrictions in this Section and will comply with them.
10. Deidentified data and model training
Tenyks may retain and use Deidentified Data derived from Customer Video Assets to operate, maintain and improve the Tenyks Platform, including model training, validation and benchmarking, provided that Tenyks:
(a) takes reasonable measures to ensure the data cannot be associated with any individual, household or the Customer;
(b) publicly commits to maintain and use the data in deidentified form and not to attempt to reidentify it, except for the limited purpose of testing the effectiveness of its deidentification measures;
(c) contractually obliges any recipient to the same restrictions; and
(d) does not disclose any Customer Video Assets, any Personal Information, or any AI-Generated Insight specific to the Customer, to any third party.
Tenyks may also use Personal Information that has not been deidentified to build and improve the quality of the Tenyks Platform, including by training, fine-tuning and evaluating the models used to provide the services to the Customer under Section 5(b), provided that Tenyks does not use that Personal Information to perform services on behalf of any other person or to build profiles of individuals, and does not disclose it to any other customer.
“Model Assets” means the models, model weights and parameters, and other improvements to the Tenyks Platform that result from training, fine-tuning or evaluation under Section 5(b) or this Section, excluding any stored copy of Customer Video Assets or Personal Information. Model Assets are owned by Tenyks and are not Personal Information, Customer Video Assets or AI-Generated Insights. Tenyks is not required to delete, retrain or modify any Model Asset on termination or expiry of the Agreement or in response to a request to delete Personal Information. Tenyks will maintain reasonable technical measures designed to prevent any Model Asset from being used to identify an individual or to reproduce Personal Information or Customer Video Assets, and will not use any Model Asset for those purposes.
“Training Data” means individual frames, short clips and associated annotations that Tenyks selects from Customer Video Assets and adds to a curated dataset for the training, fine-tuning, validation or evaluation of models under Section 5(b), excluding continuous or bulk recordings. Tenyks may retain Training Data during and after the term of the Agreement for as long as it is reasonably necessary and proportionate for those purposes, and will review its Training Data at least once a year and delete items it no longer needs. Training Data that has not been deidentified remains Personal Information and this DPA continues to apply to it. Tenyks will:
(a) store Training Data encrypted and restrict access to personnel and Sub-processors who need it for those purposes;
(b) apply blurring or similar measures to faces and other identifiers where this does not materially reduce the usefulness of the data for training or evaluation;
(c) not use Training Data for any other purpose or disclose it to any other customer; and
(d) delete specific items of Training Data when the Customer directs it to do so in order to respond to a consumer’s deletion request, without any obligation to delete, retrain or modify Model Assets.
11. Retention, deletion and return
Tenyks retains Customer Video Assets in accordance with the Agreement, and in any event no longer than ninety (90) days of continuous footage unless required for active analysis. Training Data is not continuous footage and is retained under Section 10.
On termination or expiry of the Agreement, or on the Customer’s written request, Tenyks shall delete or return all Personal Information in its possession within thirty (30) days, except for Deidentified Data, Training Data and Model Assets retained under Section 10, and any Personal Information that applicable law requires it to retain. Certification of deletion will be provided on request.
12. Sub-processors
Tenyks may engage Sub-processors to process Personal Information, each bound by written terms incorporating protections no less protective than this DPA. A current list of Sub-processors is maintained at the Tenyks Trust Center (https://trust.tenyks.ai/).
Tenyks shall give the Customer at least ten (10) days’ notice of any intended addition or replacement of a Sub-processor, by updating that list and notifying any email address the Customer has registered for notifications. The Customer may object on reasonable grounds within that period, in which case the parties will discuss the objection in good faith.
13. Location of processing and cross-border transfer
The Customer acknowledges that Tenyks is established in the United Kingdom and that Personal Information will be transferred to and processed in the United Kingdom and in the United States by the Sub-processors identified under Section 12.
Tenyks shall maintain safeguards for such transfers no less protective than those required of it under UK data protection law, and shall not transfer Personal Information to any jurisdiction other than the United Kingdom, the United States or the European Economic Area without the Customer’s prior written consent.
14. Employee and contractor data
(a) The Customer acknowledges that footage of its employees, contractors and applicants constitutes personal information about those individuals under the CCPA, the employment exemption to which expired on 1 January 2023. Where the Customer has personnel in California, it is responsible for providing the notice at collection required of an employer.
(b) Certain States, including Connecticut, New York and Delaware, require employers to give written notice to employees before engaging in electronic monitoring. The Customer is responsible for providing any such notice and for maintaining any workplace monitoring policy required in the jurisdictions in which it operates.
(c) Tenyks will assist the Customer on reasonable request in meeting the obligations in this Section.
15. Audit
The Customer may, on reasonable prior written notice and no more than once in any twelve-month period, assess Tenyks’ compliance with this DPA through a written questionnaire, review of Tenyks’ then-current security documentation and third-party audit reports, or, where those are insufficient to address a specific identified concern, an on-site assessment conducted during business hours, subject to confidentiality obligations and minimal disruption.
16. Governing law
This DPA is governed by the law that governs the Agreement. Where the Agreement does not specify a governing law, this DPA is governed by the laws of the State of Delaware, without giving effect to principles of conflicts of law.
17. Precedence
In the event of a conflict between this DPA and the Agreement in respect of the processing of Personal Information, this DPA prevails. Section 7 prevails over any inconsistent provision of either document.
18. Versions and updates
This is version 1.0 of this DPA. The version in effect on the date the Customer enters into the Agreement (or, for a renewal or new order, the date of that renewal or order) applies to the Customer for the term of that Agreement or order.
Tenyks may publish updated versions of this DPA. An updated version applies to an existing Customer only when the Customer renews or places a new order, or agrees to it in writing, except where a change is required by law or does not reduce the protection given to Personal Information, in which case Tenyks will give the Customer at least thirty (30) days’ notice before it takes effect. Previous versions are available on request and are listed in the Tenyks Legal Center.
19. Execution and contact
This DPA forms part of the Agreement and is binding on the parties without a separate signature. For a signable version of this DPA, please contact your Tenyks sales representative.
Questions about this DPA can be sent to Tenyks Limited, Eagle Labs, 28 Chesterton Road, Cambridge CB4 3AZ, United Kingdom, or by email to legal@tenyks.ai.
Version history
- Version 1.0 (October 1, 2026): first publicly available published version.






