Data Processing Addendum
Version 2026-10-05
- 1. Definitions
- 2. Roles and scope
- 3. Our obligations
- 4. Subprocessors
- 5. Security
- 6. Personal data breaches
- 7. International transfers
- 8. Deletion and return
- 9. Audits
- 10. Liability and term
- 11. Language
- Annex 1: details of processing
- Annex 2: technical and organisational measures
This Data Processing Addendum ("DPA") forms part of the Terms of Service (or other written agreement) between [Legal entity name, e.g. PT ... / ... Pty Ltd] ("Processor", "we") and the customer organisation that accepts it ("Customer", "you"). It applies when we process Customer Personal Data on your behalf. If this DPA conflicts with the Terms, this DPA prevails for personal data.
1. Definitions
"Data Protection Law" means all laws that apply to the processing, including the EU GDPR, the UK GDPR and Data Protection Act 2018, Indonesian Law No. 27 of 2022 on Personal Data Protection ("UU PDP"), and the Australian Privacy Act 1988. "Customer Personal Data" means personal data in Customer Data that we process for you. "Controller", "processor", "data subject", "personal data breach" and "processing" have the meanings in Data Protection Law (for UU PDP, "Pengendali Data Pribadi" and "Prosesor Data Pribadi"). "Subprocessor" means a third party we engage to process Customer Personal Data.
2. Roles and scope
- You are the controller (or a processor acting for your own controller) and we are your processor of Customer Personal Data.
- Details of the processing are in Annex 1.
- You are responsible for the lawfulness of the instructions you give and for having a lawful basis, and any notices or consents required, for the data your phones show and your Flows capture, including personal data of people who are not your users.
- This DPA does not cover data we process as an independent controller (account, billing, security and telemetry data) or anonymised data that no longer identifies anyone, including the Screen Graph described in How we improve the product. Those are covered by the Privacy Policy.
3. Our obligations
We will:
- process Customer Personal Data only on your documented instructions, which are the Terms, this DPA, and your configuration and use of the Service, unless the law requires otherwise (in which case we will tell you first unless the law forbids it);
- tell you if we believe an instruction breaks Data Protection Law;
- ensure that everyone who processes it is bound by confidentiality;
- implement the technical and organisational measures in Annex 2;
- help you, taking into account the nature of the processing, to respond to data subject requests, and pass to you any request we receive about your data without responding to it ourselves except to redirect;
- help you with data protection impact assessments, prior consultations, and breach notifications, to the extent the information is available to us;
- delete or return Customer Personal Data at the end of the Service as described in section 8;
- make available the information needed to show compliance with this DPA and allow audits as described in section 9.
4. Subprocessors
- You give us general authorisation to engage Subprocessors. The current list is on Subprocessors.
- We will give you at least 30 days' notice of a new Subprocessor (by email to subscribers of that page and to your owner). You may object on reasonable data-protection grounds within that period. We will try to resolve the objection; if we cannot, you may terminate the affected part of the Service and receive a refund of prepaid fees for the unused period.
- We impose data-protection terms on each Subprocessor that are at least as protective as this DPA and remain responsible for their performance.
- Services you choose to connect, such as your AI provider (for example Anthropic under your own key or login), webhook destinations and export targets, are not our Subprocessors; they act under your own agreement with them.
5. Security
We implement and maintain the measures in Annex 2 and may update them as long as the overall level of protection is not reduced.
6. Personal data breaches
We will notify you without undue delay, and in any case within 48 hours after becoming aware of a personal data breach affecting Customer Personal Data, with the information you need to meet your own obligations (including the 72-hour notification under GDPR and the 3 x 24-hour notification under UU PDP Art. 46). We will update you as we learn more, take reasonable steps to contain the breach, and record it. Notifying you is not an admission of fault.
7. International transfers
We host the Service in [Railway region, e.g. US West / EU West / Singapore]. We may transfer Customer Personal Data to countries outside the one it was collected in only with a lawful transfer mechanism. Where the EU GDPR applies and there is no adequacy decision, the EU Standard Contractual Clauses (Module 2, controller to processor; or Module 3 where you are a processor) are incorporated by reference, with the UK International Data Transfer Addendum where the UK GDPR applies. For Indonesia, we will ensure the recipient country has an equal or higher level of protection, or apply adequate and binding safeguards, as UU PDP Art. 56 requires. For Australia, we take reasonable steps under APP 8. [Counsel: SCC clause choices: Clause 7 docking, Clause 9(a) option 2, Clause 11 optional language omitted, Clause 17 governing law, Clause 18 forum.]
8. Deletion and return
During the subscription you can export and delete your data in the studio. Captures and recordings are deleted automatically at the end of your plan's retention window. When the Service ends, you can export your data for 30 days; after that we delete Customer Personal Data, and remove it from backups within 35 days, unless the law requires us to keep it.
9. Audits
On request we will provide information reasonably needed to demonstrate compliance, such as summaries of our security practices and third-party reports when available. If that is not enough, or a regulator requires it, you may audit our compliance once a year with at least 30 days' notice, during business hours, under confidentiality, at your cost, in a way that does not compromise other customers' data. Your organisation's audit log, which records any action our staff took on your organisation, is available to your owners and admins at any time.
10. Liability and term
Each party's liability under this DPA is subject to the limitations in the Terms, except where Data Protection Law does not allow it. This DPA lasts as long as we process Customer Personal Data.
11. Language
This DPA is available in English and Indonesian. If the Customer is an Indonesian party, the Indonesian version prevails to the extent of any inconsistency; otherwise the English version prevails.
Annex 1: details of processing
| Subject matter | Providing the Tether Service: remote control and automation of mobile phones (currently Android phones) the Customer owns or is authorised to use, and keeping what their screens show as data. |
| Duration | The subscription term plus the export and deletion periods in section 8. |
| Nature and purpose | Hosting, storage, transmission (including through the relay), display, extraction into sheets, export, webhook delivery, recording (if enabled), backup, security monitoring and support. |
| Categories of data subjects | The Customer's users; and any person whose information appears on the Customer's phone screens, such as the Customer's own contacts, correspondents, customers, followers and account holders. |
| Categories of personal data | Whatever appears on screen when a capture or recording is taken: names, usernames, profile images, messages, comments, contact details, account information, and other content in the apps the Customer automates. Also run logs and the extracted rows in sheets. |
| Special categories | Not intended. The Customer must not configure Flows to capture special-category or children's data unless it has a lawful basis that covers it. Screens may incidentally show it. |
| Frequency | Continuous while phones are connected and Flows run. |
| Retention | Per plan, as in the Privacy Policy section 6, or as configured. |
Annex 2: technical and organisational measures
- Access control: organisation roles (owner, admin, member, viewer); recordings visible only to roles with explicit permission; platform support staff cannot view captures or recordings; staff access to customer organisations is recorded in the customer's audit log.
- Audit: append-only, hash-chained audit log of sign-ins, membership and role changes, pairing, live-control sessions (counts only, never keystrokes), runs, exports, settings changes and staff actions, exportable by the customer.
- Encryption: TLS in transit between browser, studio, relay and agent; secrets and AI API keys encrypted at rest; per-organisation keys for recordings [planned].
- Agent security: agent tokens bound to one agent, revocable, and rotated on revoke; pairing codes are short-lived.
- Data minimisation: short default retention; recordings off by default and opt-in per organisation and per Flow; password and secure fields masked in recordings; screens marked secure by the app are captured black.
- Outbound data: webhooks only to public HTTPS hosts, signed and without redirects.
- Resilience: backups with restricted access, deleted on the backup cycle.
- People: confidentiality obligations; least-privilege access; security training.
- Incident response: documented process with customer notification as in section 6.
- Vulnerability management: dependency updates, security review of changes, reporting address [email protected].