Data processing agreement
Last updated 7 August 2026
These are the terms on which we process personal data on your behalf, as article 28 of the GDPR requires. They form part of your agreement with us and take precedence over our terms of use on anything to do with personal data. If you need a signed copy, write to legal@tulina.ai.
Which of us does what
You are the controller. The personal data that reaches Tulina through the tools you connect is yours. You decide what enters, why it is there, and what is done with it. You are responsible for having a lawful basis for it, for telling the people concerned, and for making sure your instructions to us are lawful.
We are the processor. We act on your instructions and for no purpose of our own.
Two things sit outside this agreement, because we are the controller for them and our privacy page covers them instead: the account data of the people who sign in, and what we collect through the tulina.ai website.
What we process for you
We act only on your instructions
We process your data only on your documented instructions, including where a transfer outside the European Union is concerned. Your instructions are the agreement between us, what you configure in the platform, and what you or your agents ask the Service to do.
If the law obliges us to process your data beyond your instructions, we tell you before doing it, unless that same law forbids us from telling you. If we think an instruction breaches data protection law, we say so.
We do not train or improve any model or agent on your data. Tulina carries no model of its own. The models and agents acting through the Service are yours, or third parties' that you have connected, and what you send to them is governed by your own arrangement with them.
Confidentiality
Everyone we allow near your data is bound by a duty of confidentiality, and access is limited to those who need it to run the Service for you.
Security
We take the measures article 32 requires, judged against the risk. In practice:
Connection credentials and API keys are encrypted with AES-256-GCM in a dedicated vault, with no credential stored in clear anywhere. Traffic is encrypted in transit. The machine serving the platform is isolated, with its own firewall, no private network to anything else, and no colocation with the systems holding credentials. Access inside a workspace follows the roles its administrators set, and organisations can review what has been done in their own workspace through an audit log.
We may change these measures as the Service evolves, provided the level of protection does not drop.
Sub-processors
You give us general authorisation to engage the sub-processors below to process your data.
We bind each of them by contract to data protection obligations no weaker than these, as article 28(4) requires. Their failure is ours to answer for: we do not hand you off to a sub-processor when something goes wrong. What we owe you for it remains subject to the limits in our terms of use.
We tell you before adding or replacing a sub-processor, and you may object on reasonable data protection grounds. We will work with you to address a reasoned objection.
The tools and models you connect yourself are not our sub-processors. You choose them and your relationship with them is your own.
Where the data sits
We host everything the platform stores inside the European Union — compute, database, object storage, secrets, the credential vault, and the sign-in service — and that is what we commit to here. Today all of it runs in France. Your working data does not leave the Union to be processed by us.
The one exception is error tracking, which reaches a United States provider and receives no personal data of yours by configuration. Where a transfer outside the European Union does occur, it rests on the European Commission's adequacy decision for the EU-US Data Privacy Framework where the provider is certified, and otherwise on the Commission's standard contractual clauses.
Data you send to the tools and models you have connected travels wherever those providers operate. That transfer is yours, made on your instruction.
Requests from the people whose data it is
If someone contacts us directly to exercise a right over data you control, we do not answer for you. We pass the request on without undue delay and leave it to you.
Taking into account the nature of the processing, we help you answer those requests with appropriate technical and organisational measures, including the ability to retrieve, correct, export, and delete what sits in your workspace.
If there is a breach
Once we detect a personal data breach affecting your data, we tell you without undue delay, so that you can meet your own 72-hour deadline to the CNIL.
We tell you what we know: what happened, which categories of data and roughly how many people are affected, the likely consequences, and what we are doing about it. If we cannot establish all of it at once, we send what we have and follow up. Notifying the supervisory authority and the people concerned is yours to do, and we help you do it.
Impact assessments
Where you have to carry out a data protection impact assessment or consult a supervisory authority beforehand, we give you the information about our processing that you reasonably need to do it.
Showing our work
We answer your questions about how we meet these obligations in writing, including a reasonable security questionnaire, and we give you any audit report or certification we hold. That is how this is normally satisfied, and for most customers it is the whole of it.
Where that genuinely leaves a question unanswered, you may inspect: once in any twelve months, on thirty days' written notice, in working hours, without disrupting the Service or coming near another customer's data, and under confidentiality. The auditor must not be one of our competitors, and you bear the cost. A supervisory authority requiring it, or a breach affecting your data, overrides the twelve-month limit and the notice period.
Returning and deleting your data
When the Service ends, we return your data to you or delete it, whichever you choose, and delete the copies we hold. Tell us which within thirty days of the end; after that we delete.
We keep what Union or French law obliges us to keep, for no longer than that obligation lasts, and it stays protected by these terms for as long as we hold it.
You can export what sits in your workspace at any time while the Service is running, and you do not need to wait for the end to ask us to delete something.
Liability and precedence
The limits of liability in our terms of use apply to this agreement too, except where the law does not allow it. This agreement wins over the terms of use on anything to do with personal data, and over any conflicting term in your own purchase documents unless we have signed up to it specifically.
Duration, changes, and law
This agreement runs for as long as we process personal data for you. We may update it to keep it accurate or compliant; for a change that materially reduces your protection we give notice by email before it takes effect. It is governed by French law, and disputes go to the competent courts of Paris.
Contact
Anything about this agreement: legal@tulina.ai. Privacy requests: privacy@tulina.ai. Security and breach reports: security@tulina.ai.