Data processing agreement
Effective date: 2 October 2026
This data processing agreement (“DPA”) is part of the terms of service between Teyo Labs GmbH (“Partnex”, the processor) and the Customer (the controller). It applies whenever Partnex processes personal data contained in Customer Content on the Customer’s behalf. It meets the requirements of Art. 28 of the EU General Data Protection Regulation (GDPR) and Art. 9 of the Swiss Federal Act on Data Protection (FADP). Words defined in the terms of service have the same meaning here.
No signature is needed: the DPA takes effect when the Customer accepts the terms of service. Customers who need a countersigned copy can request one at privacy@teyolabs.com.
1. Roles and instructions
1.1 The Customer is the controller of personal data in Customer Content, and Partnex is its processor.
1.2 Partnex processes that data only on the Customer’s documented instructions. The terms of service, this DPA, and the Customer’s use and configuration of the Service (for example running a deliverable, looking up contacts, forwarding an email, or inviting a teammate) are the Customer’s instructions. Partnex will tell the Customer if it believes an instruction breaks data protection law.
1.3 The Customer is responsible for the lawfulness of the data it puts into the Service and of its instructions, including having a lawful basis for processing the data of the people it researches and contacts, and for informing them where the law requires.
2. Confidentiality
Partnex ensures that everyone authorised to process the personal data is bound by confidentiality and processes it only as needed to provide the Service.
3. Security
Partnex implements the technical and organisational measures in Annex 2 and keeps them appropriate to the risk. Partnex may update them, provided the overall level of protection does not decrease.
4. Subprocessors
4.1 The Customer gives general authorisation for Partnex to use subprocessors. The current list is on the subprocessors page.
4.2 Partnex will announce a new or replacement subprocessor on that page and by email to the Customer’s account owner at least 30 days before it starts processing Customer personal data. The Customer may object on reasonable data protection grounds within that period. If the parties cannot resolve the objection, the Customer may terminate the affected subscription and receive a pro-rata refund of prepaid fees for the remaining period.
4.3 Partnex imposes data protection obligations on each subprocessor that are no less protective than this DPA, and remains responsible for its subprocessors’ performance.
5. International transfers
Customer personal data is hosted in the European Union. Where a subprocessor processes it in a country without an adequacy decision recognised by Switzerland or the EU, the transfer is based on the EU Standard Contractual Clauses (Module 3, processor to processor), with the amendments required by the FADP, or on the subprocessor’s certification under the EU-US and Swiss-US Data Privacy Frameworks.
6. Assistance
6.1 Requests from individuals. Partnex will forward to the Customer any request it receives from an individual about Customer personal data, and will not answer it itself except to refer the individual to the Customer. The Service lets the Customer access, correct, export and delete its data; where that is not enough, Partnex will help as reasonably needed.
6.2 Other obligations. Partnex will provide reasonable help with data protection impact assessments and consultations with authorities, as far as they concern the Service.
7. Personal data breaches
Partnex will notify the Customer without undue delay, and where possible within 48 hours, after becoming aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer personal data. The notice will describe what is known about the breach, its likely consequences, and the measures taken, and will be updated as more becomes known.
8. Return and deletion
The Customer can export its data from the Service at any time. When an account is deleted, Partnex deletes its Customer personal data from the live system immediately and from backups as they expire, within 30 days, unless the law requires Partnex to keep it.
9. Audits
Partnex will make available the information reasonably needed to demonstrate compliance with this DPA, including answers to security questionnaires. If that is not sufficient, the Customer may, at its own cost and with at least 30 days’ notice, have an independent auditor bound by confidentiality inspect the relevant processing once per year, during business hours and without disrupting the Service or exposing other customers’ data.
10. Liability and precedence
Liability under this DPA is governed by the terms of service. If this DPA conflicts with the terms of service on the processing of personal data, this DPA prevails. If the Standard Contractual Clauses apply, they prevail over both.
Annex 1: Details of the processing
| Subject matter | Providing the Partnex Service to the Customer. |
| Duration | As long as the Customer has an account, plus the deletion period in section 8. |
| Nature and purpose | Hosting, storing, organising, analysing and transmitting Customer Content to research, plan and carry out business partnerships, including generating deliverables with AI, looking up business contact details at the Customer’s request, receiving emails the Customer forwards, and sending emails the Customer chooses to send. |
| Categories of individuals | The Customer’s Users; the Customer’s employees named in its content (for example stakeholders); people at the Customer’s prospective and actual partners (contacts); senders and recipients of emails the Customer forwards or sends. |
| Categories of personal data | Names; job titles and employers; business email addresses, phone numbers and LinkedIn profiles; the content of business correspondence and conversation records; notes about business relationships; account and usage data of Users. |
| Special categories | None intended. The Customer must not put special categories of personal data into the Service. |
Annex 2: Technical and organisational measures
Hosting and data location
- The application and its database are hosted in a data centre in the European Union.
- All connections to the Service are encrypted with TLS.
Access control
- Passwords are stored only as bcrypt hashes. Session tokens and API keys are stored only as hashes and can be revoked.
- Changing or resetting a password ends all other sessions.
- Every request that reads or changes a workspace is checked against the requesting account’s access rights; one customer’s data is never reachable from another customer’s account. These checks are covered by automated tests.
- Team roles limit what each User can do. Viewers can read but not change anything.
- Production access is limited to the Partnex staff who need it.
AI processing
- AI tasks run in a sandbox that can read only the workspace of the task being performed and cannot reach the rest of the system or other customers’ data.
- The AI cannot delete Customer Content and has no general file-writing tool; it saves results only through controlled interfaces that check them.
- Contact details are only stored when a data provider actually supplied them; details the AI cannot trace to a source are discarded.
- Content from forwarded emails is treated as data, never as instructions, and the assistant that reads incoming email has no access to the web.
Integrity and availability
- Changes to records are versioned and checked for conflicts; documents keep a full version history.
- Actions in a workspace are recorded in an action log.
- The database and documents are backed up nightly, and backups are kept for 30 days.
- Requests are rate limited to protect the Service from abuse.
Organisation
- Staff are bound by confidentiality.
- Subprocessors are selected for their security practices and bound by data processing agreements.
- Security incidents are handled under section 7.
Annex 3: Subprocessors
See the subprocessors page.