Skip to content

Data processing agreement

Last updated 7 August 2026

These are the terms on which we process personal data on your behalf, as article 28 of the GDPR requires. They form part of your agreement with us and take precedence over our terms of use on anything to do with personal data. If you need a signed copy, write to legal@tulina.ai.

Which of us does what

You are the controller. The personal data that reaches Tulina through the tools you connect is yours. You decide what enters, why it is there, and what is done with it. You are responsible for having a lawful basis for it, for telling the people concerned, and for making sure your instructions to us are lawful.

We are the processor. We act on your instructions and for no purpose of our own.

Two things sit outside this agreement, because we are the controller for them and our privacy page covers them instead: the account data of the people who sign in, and what we collect through the tulina.ai website.

What we process for you

Subject matter
Providing the Tulina platform: connecting your tools, keeping context current across them, and carrying out the operations you or the software you authorise ask for.
Duration
For as long as your subscription runs, and then for as long as it takes to return or delete the data under the last section below.
Nature of the processing
Collecting, storing, structuring, retrieving, using, and transmitting personal data to the tools and models you have connected, at your instruction.
Purpose
Only to run the Service for you. We do not process your data for any purpose of our own.
Categories of people
Whoever appears in the systems you connect: your staff, your contacts, your prospects and customers, your suppliers, and — where you use Tulina for recruitment — candidates.
Categories of data
Whatever the connected systems hold: identification and contact details, professional information, the content of messages and documents, and activity records. You decide the scope by choosing what to connect and what to let through.
Special categories
Tulina is not designed for data revealing health, beliefs, or the other special categories under article 9, nor for criminal conviction data. If you connect a system holding it, you do so on your own assessment and remain responsible for the additional safeguards it calls for.

We act only on your instructions

We process your data only on your documented instructions, including where a transfer outside the European Union is concerned. Your instructions are the agreement between us, what you configure in the platform, and what you or your agents ask the Service to do.

If the law obliges us to process your data beyond your instructions, we tell you before doing it, unless that same law forbids us from telling you. If we think an instruction breaches data protection law, we say so.

We do not train or improve any model or agent on your data. Tulina carries no model of its own. The models and agents acting through the Service are yours, or third parties' that you have connected, and what you send to them is governed by your own arrangement with them.

Confidentiality

Everyone we allow near your data is bound by a duty of confidentiality, and access is limited to those who need it to run the Service for you.

Security

We take the measures article 32 requires, judged against the risk. In practice:

Connection credentials and API keys are encrypted with AES-256-GCM in a dedicated vault, with no credential stored in clear anywhere. Traffic is encrypted in transit. The machine serving the platform is isolated, with its own firewall, no private network to anything else, and no colocation with the systems holding credentials. Access inside a workspace follows the roles its administrators set, and organisations can review what has been done in their own workspace through an audit log.

We may change these measures as the Service evolves, provided the level of protection does not drop.

Sub-processors

You give us general authorisation to engage the sub-processors below to process your data.

Otomata
SIREN 106974637, Marseille, France. Operates the backend behind the platform: the encrypted credential vault, the database, and the sign-in service.
Scaleway
France. Compute, managed PostgreSQL, object storage, and secret storage. Everything the platform stores sits here.
Sentry
Error tracking. Receives the name of a failing operation and an opaque user identifier, never your data: IP addresses, cookies, headers and call arguments are excluded by configuration.

We bind each of them by contract to data protection obligations no weaker than these, as article 28(4) requires. Their failure is ours to answer for: we do not hand you off to a sub-processor when something goes wrong. What we owe you for it remains subject to the limits in our terms of use.

We tell you before adding or replacing a sub-processor, and you may object on reasonable data protection grounds. We will work with you to address a reasoned objection.

The tools and models you connect yourself are not our sub-processors. You choose them and your relationship with them is your own.

Where the data sits

We host everything the platform stores inside the European Union — compute, database, object storage, secrets, the credential vault, and the sign-in service — and that is what we commit to here. Today all of it runs in France. Your working data does not leave the Union to be processed by us.

The one exception is error tracking, which reaches a United States provider and receives no personal data of yours by configuration. Where a transfer outside the European Union does occur, it rests on the European Commission's adequacy decision for the EU-US Data Privacy Framework where the provider is certified, and otherwise on the Commission's standard contractual clauses.

Data you send to the tools and models you have connected travels wherever those providers operate. That transfer is yours, made on your instruction.

Requests from the people whose data it is

If someone contacts us directly to exercise a right over data you control, we do not answer for you. We pass the request on without undue delay and leave it to you.

Taking into account the nature of the processing, we help you answer those requests with appropriate technical and organisational measures, including the ability to retrieve, correct, export, and delete what sits in your workspace.

If there is a breach

Once we detect a personal data breach affecting your data, we tell you without undue delay, so that you can meet your own 72-hour deadline to the CNIL.

We tell you what we know: what happened, which categories of data and roughly how many people are affected, the likely consequences, and what we are doing about it. If we cannot establish all of it at once, we send what we have and follow up. Notifying the supervisory authority and the people concerned is yours to do, and we help you do it.

Impact assessments

Where you have to carry out a data protection impact assessment or consult a supervisory authority beforehand, we give you the information about our processing that you reasonably need to do it.

Showing our work

We answer your questions about how we meet these obligations in writing, including a reasonable security questionnaire, and we give you any audit report or certification we hold. That is how this is normally satisfied, and for most customers it is the whole of it.

Where that genuinely leaves a question unanswered, you may inspect: once in any twelve months, on thirty days' written notice, in working hours, without disrupting the Service or coming near another customer's data, and under confidentiality. The auditor must not be one of our competitors, and you bear the cost. A supervisory authority requiring it, or a breach affecting your data, overrides the twelve-month limit and the notice period.

Returning and deleting your data

When the Service ends, we return your data to you or delete it, whichever you choose, and delete the copies we hold. Tell us which within thirty days of the end; after that we delete.

We keep what Union or French law obliges us to keep, for no longer than that obligation lasts, and it stays protected by these terms for as long as we hold it.

You can export what sits in your workspace at any time while the Service is running, and you do not need to wait for the end to ask us to delete something.

Liability and precedence

The limits of liability in our terms of use apply to this agreement too, except where the law does not allow it. This agreement wins over the terms of use on anything to do with personal data, and over any conflicting term in your own purchase documents unless we have signed up to it specifically.

Duration, changes, and law

This agreement runs for as long as we process personal data for you. We may update it to keep it accurate or compliant; for a change that materially reduces your protection we give notice by email before it takes effect. It is governed by French law, and disputes go to the competent courts of Paris.

Contact

Anything about this agreement: legal@tulina.ai. Privacy requests: privacy@tulina.ai. Security and breach reports: security@tulina.ai.

Experience Tulina for 14 days.

By continuing, you agree to our Terms of Use and Privacy policy.