Tegy Data Processing Addendum

Effective Date: August 6, 2026

This Data Processing Addendum (“DPA”) forms part of the Tegy Terms of Service or another written agreement governing Customer's use of the Service (the “Agreement”) between Customer and MGMJ Innovation Group LLC, the current provider of the Tegy Service (“Tegy”).

Customer enters this DPA when it accepts the Agreement. A separate signature is not required unless the parties agree otherwise. If Customer accepts for an organization, Customer enters this DPA for that organization and its Affiliates permitted to use the Service under the Agreement.

This DPA is designed for processing subject to applicable United States privacy laws. It does not include GDPR, UK GDPR, Swiss, Canadian, or other international terms or cross-border transfer clauses.

1Definitions

Capitalized terms not defined here have the meaning in the Agreement.

“Affiliate” means an entity that controls, is controlled by, or is under common control with a party, where control means ownership or control of more than 50 percent of voting interests or the power to direct management.

“Applicable Data Protection Law” means a United States federal or state law that applies to Tegy's Processing of Customer Personal Data under the Agreement and governs privacy, security, or breach notification. It includes the California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA”), only to the extent applicable. This DPA does not accept or address obligations under a sector-specific law or standard, such as HIPAA, GLBA, FCRA, FERPA, COPPA, PCI DSS, or a law governing classified information, merely because Customer submits covered data. Customer may not submit that data unless a signed agreement expressly authorizes it and addresses the applicable obligations.

“Consumer” means a natural person whose Personal Data is protected by Applicable Data Protection Law. Equivalent terms such as “data subject” have the same meaning for this DPA.

“Customer Personal Data” means Personal Data contained in Customer Content that Tegy Processes on Customer's behalf to provide the Service. Customer Personal Data excludes information for which Tegy determines the purpose and means of Processing as described in Section 4, and excludes information that is deidentified or outside the scope of Applicable Data Protection Law.

“Data Incident” means a confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data in Tegy's or its Subprocessor's possession or control. A Data Incident does not include unsuccessful attempts that do not compromise Customer Personal Data, such as blocked scans, pings, denial-of-service attempts, unsuccessful login attempts, or attacks stopped by security controls.

“Personal Data” means information defined as personal data, personal information, or a comparable term under Applicable Data Protection Law.

“Process” or “Processing” means an operation performed on Personal Data, including collection, access, use, storage, disclosure, transmission, analysis, deletion, or return.

“Subprocessor” means a third party engaged by Tegy to Process Customer Personal Data on Customer's behalf in providing the Service.

Terms such as “business,” “controller,” “contractor,” “processor,” “sell,” “service provider,” and “share” have the meanings provided by the Applicable Data Protection Law that uses them.

2Scope and duration

This DPA applies only to Customer Personal Data Tegy Processes on Customer's behalf under the Agreement. It begins when the Agreement begins and continues while Tegy Processes Customer Personal Data, including during the deletion and backup period after termination.

The subject matter, duration, nature, purpose, categories of Personal Data, and categories of Consumers are described in Appendix A.

3Roles and instructions

3.1Roles

For Customer Personal Data, Customer is the business or controller and Tegy is the service provider, contractor, or processor, as those roles apply. If Customer is itself a processor for another controller, Tegy acts as Customer's subprocessor and Customer represents that it has authority to appoint Tegy.

3.2Documented instructions

Customer instructs Tegy to Process Customer Personal Data:

  • to provide, maintain, secure, support, and troubleshoot the Service;
  • to perform actions, integrations, AI inference, API and MCP requests, and configurations initiated or authorized by Customer;
  • as described in the Agreement, this DPA, and Customer's use of Service controls;
  • to prevent fraud, abuse, security threats, and violations;
  • to comply with applicable law and lawful process; and
  • under another documented instruction Tegy agrees to in writing.

The Agreement, this DPA, Orders, Service configuration, and Customer's authorized use constitute Customer's complete documented instructions. Tegy is not required to follow an instruction that violates law, the Agreement, or the design and permitted scope of the Service. Tegy will notify Customer if it reasonably believes an instruction violates Applicable Data Protection Law, unless prohibited by law.

3.3No expansion by support request

A support ticket or informal request does not amend this DPA or require Tegy to build a feature, change infrastructure, use a specific data location, or accept a regulated category unless Tegy agrees in a signed writing.

4Tegy data processed for its own business operations

The parties acknowledge that Tegy may separately determine the purposes and means of Processing the following information, subject to the Privacy Notice and Applicable Data Protection Law:

  • business contact, account, billing, subscription, relationship, and support-administration information collected directly from Customer or Authorized Users;
  • authentication, security, fraud, abuse, and legal-compliance records;
  • Usage Data used to provide, meter, bill, secure, support, analyze, test, benchmark, improve, develop, optimize, and maintain the Service, understand adoption and performance, administer the customer relationship, and communicate with business contacts, to the extent Applicable Data Protection Law permits that role; and
  • data that has been properly aggregated or deidentified.

This Section does not permit Tegy to reclassify the substance of Customer Content as Usage Data, sell or share Customer Personal Data, build unrelated consumer profiles, train shared or general-purpose models on Customer Content without opt-in, or otherwise avoid the restrictions in Section 5.

5Tegy obligations

5.1Purpose limitation

Tegy will Process Customer Personal Data only for the business purposes and instructions stated in this DPA and the Agreement, or as required by law. If law requires other Processing, Tegy will inform Customer before the Processing unless law prohibits notice.

5.2U.S. service-provider and processor restrictions

To the extent required by Applicable Data Protection Law, Tegy will:

  • not sell or share Customer Personal Data;
  • not retain, use, or disclose Customer Personal Data outside the direct business relationship with Customer or for a commercial purpose other than the business purposes specified in the Agreement and this DPA;
  • not combine Customer Personal Data received from Customer with Personal Data received from another person or collected from Tegy's own interaction with a Consumer, except as permitted by Applicable Data Protection Law to perform the specified business purposes;
  • provide the same level of privacy protection for Customer Personal Data required of processors, contractors, or service providers under Applicable Data Protection Law;
  • notify Customer if Tegy determines it can no longer meet an applicable obligation;
  • permit Customer to take reasonable and appropriate steps, as provided in Sections 10 and 11, to help ensure Tegy uses Customer Personal Data consistently with Customer's obligations and to stop and remediate unauthorized use; and
  • comply with applicable obligations imposed on a processor, contractor, or service provider.

Tegy certifies that it understands these restrictions and will comply with them.

5.3Confidentiality

Tegy will require personnel authorized to Process Customer Personal Data to be bound by confidentiality obligations and to access it only as needed for their duties.

5.4No shared-model training

Tegy will not use Customer Personal Data to train shared or general-purpose AI models without Customer's affirmative opt-in. Tegy will use contractual terms, provider controls, routing controls, or a combination designed to prevent AI inference providers from using Customer Personal Data for that training.

5.5Compliance information

On reasonable written request, Tegy will make available information reasonably necessary to demonstrate compliance with this DPA, subject to confidentiality, security, privilege, and the audit limits in Section 11.

6Customer obligations

6.1Compliance and authority

Customer is responsible for:

  • complying with Applicable Data Protection Law in its collection, use, disclosure, instructions, and other Processing of Customer Personal Data;
  • providing all required notices and obtaining all required rights, consents, and authorizations;
  • ensuring its instructions are lawful and within the Service's intended scope;
  • the accuracy, quality, relevance, and legality of Customer Personal Data and the means by which Customer acquired it;
  • responding to Consumers and regulators as the business or controller;
  • configuring permissions, integrations, retention, and security controls appropriately; and
  • ensuring that Customer Personal Data does not include a category prohibited by the AUP or Agreement.

6.2Prohibited regulated data

Customer will not use the Service to Process protected health information, consumer health data subject to a state consumer-health-data law, payment-card data, nonpublic personal information governed by GLBA, consumer-report data governed by FCRA, student education records governed by FERPA, biometric identifiers or templates, children's personal information, government identifiers, classified or controlled-unclassified information, or another specially regulated category unless the parties first sign an agreement expressly covering that category.

6.3Customer security

Customer will protect credentials, endpoints, integrations, user access, and exported data; use reasonable security controls; and promptly notify Tegy of suspected compromise. Tegy is not responsible for a Data Incident caused by Customer, an Authorized User, or a third-party integration outside Tegy's control, but will reasonably cooperate as required by law and the Agreement.

7Subprocessors

7.1General authorization

Customer generally authorizes Tegy to engage Subprocessors to provide the Service. Tegy maintains a current list at tegy.io/subprocessors identifying each Subprocessor's name, service, and primary processing location.

7.2Subprocessor terms and responsibility

Tegy will impose written data-protection and confidentiality obligations on a Subprocessor that are appropriate to the services and no less protective in material respects than Tegy's relevant obligations under this DPA. Tegy remains responsible for the Subprocessor's performance of those obligations to the extent required by the Agreement or Applicable Data Protection Law.

7.3Changes and objections

Tegy will provide at least 15 days' notice of a new Subprocessor that will materially Process Customer Personal Data, by updating the list and using an email, in-product, or subscription notice mechanism. Tegy may use a shorter period when necessary to address an emergency, security risk, provider discontinuation, or legal requirement and will provide notice as soon as reasonably practicable.

Customer may object during the notice period on reasonable, documented data-protection grounds. The parties will attempt a commercially reasonable resolution. If Tegy cannot provide a reasonable alternative without material burden, Customer's sole remedy is to stop using the affected feature or terminate the affected paid Service before the Subprocessor begins material Processing. That termination does not entitle Customer to a refund except for prepaid fees covering the unused period of a Service Customer cannot reasonably use because of the objected-to Subprocessor.

8Security

8.1Safeguards

Taking into account the nature of the Service and Customer Personal Data, reasonably foreseeable risks, the state of generally available safeguards, and implementation cost, Tegy will maintain reasonable administrative, technical, and organizational measures designed to protect Customer Personal Data from unauthorized access, use, alteration, disclosure, or destruction. Appendix B describes the baseline measures.

8.2Changes

Tegy may update safeguards as technology and the Service change, provided the overall protection of Customer Personal Data is not materially reduced during a paid subscription period.

8.3Shared responsibility

The safeguards protect components controlled by Tegy. Customer is responsible for its devices, networks, identity provider, credentials, Authorized Users, permissions, connected services, configurations, exports, and actions taken through Customer's accounts.

9Data Incidents

9.1Notice

Tegy will notify Customer without undue delay after confirming a Data Incident affecting Customer Personal Data, unless Applicable Data Protection Law prohibits notice. Notice will be sent to Customer's account or security contact and may be delivered in phases as information becomes available.

9.2Information and cooperation

To the extent reasonably available, notice will describe the nature of the Data Incident, categories of affected information, known or likely consequences, measures taken or planned, and a contact for follow-up. Tegy will take reasonable steps to contain, investigate, and mitigate the Data Incident and will reasonably assist Customer with legally required notifications.

9.3Responsibility for notices

Customer is responsible for determining whether to notify Consumers, customers, regulators, or others, unless law directly requires Tegy to notify them. Tegy's notice or cooperation is not an admission of fault or liability. Customer will coordinate public statements with Tegy where they identify Tegy, except to the extent law prohibits coordination.

10Consumer requests and compliance assistance

10.1Requests received by Tegy

If Tegy receives a request from a Consumer concerning Customer Personal Data and can reasonably identify Customer, Tegy will direct the Consumer to Customer or notify Customer, unless law requires Tegy to respond directly. Tegy will not independently respond on Customer's behalf without authorization, except to confirm that the request was referred or as required by law.

10.2Assistance

Taking into account the nature of Processing and information available, Tegy will provide reasonable assistance through Service functionality or other commercially reasonable means so Customer can respond to verified requests to access, correct, delete, or obtain Customer Personal Data and meet applicable security, assessment, consultation, and breach obligations.

Assistance beyond standard Service functionality may be subject to Tegy's reasonable fees based on time and cost, unless the assistance is required because Tegy breached this DPA.

11Assessments, information, and audits

11.1Documentation first

No more than once in a 12-month period, Customer may request then-current documentation reasonably sufficient to evaluate Tegy's compliance with this DPA, such as a security overview, relevant policies, questionnaire response, independent assessment or certification if available, and summary of material findings. Tegy may redact information unrelated to Customer, protected by privilege, confidential to another party, or likely to create security risk.

11.2Additional audit

If the documentation is not reasonably sufficient to meet a specific requirement of Applicable Data Protection Law, Customer may request an additional audit by an independent, qualified auditor acceptable to Tegy. The audit must:

  • be limited to Customer Personal Data and Tegy's obligations under this DPA;
  • occur no more than once in a 12-month period unless required by a regulator or following a material Data Incident;
  • follow at least 30 days' written notice;
  • occur during normal business hours without disrupting operations;
  • avoid access to source code, vulnerability details, other customers' data, privileged material, or information whose disclosure would create security risk;
  • comply with Tegy's security and confidentiality requirements; and
  • be conducted at Customer's expense, including Tegy's reasonable internal costs, unless the audit identifies a material uncured breach by Tegy.

Customer will provide Tegy a copy of the audit report. The report and underlying information are Tegy's Confidential Information. Tegy may satisfy an on-site audit request with a recent independent third-party report where legally sufficient.

11.3Remediation

If an audit identifies a verified material failure to comply, Tegy will take commercially reasonable corrective action. Customer's monitoring and remediation rights under Applicable Data Protection Law are exercised through this Section and Section 5.2.

12Return and deletion

12.1During the term

Customer may access, export, or delete Customer Personal Data using available Service controls. Customer is responsible for exporting information it needs before account closure or termination.

12.2After termination or request

On Customer's verified written request or termination of the affected Service, Tegy will delete Customer Personal Data from active systems within 30 days and direct applicable Subprocessors to delete it under their contractual deletion procedures, unless Customer requests an available return or export before deletion or law requires retention.

Customer Personal Data may remain in encrypted, access-restricted backups for up to 90 additional days and will be deleted or overwritten through the normal backup cycle. During that period, Tegy will not restore the data to active use except for disaster recovery, security, or legal necessity; if restored, it remains subject to this DPA and will be deleted again under the cycle.

12.3Exceptions

Tegy may retain Customer Personal Data to the extent required by law, court order, legal hold, security investigation, or defense of a claim. Tegy will isolate and protect retained information and Process it only for the reason requiring retention. This Section does not require deletion of information that is not Personal Data, Service Data lawfully retained under Section 4, or properly deidentified and aggregated information.

13Government and legal requests

Unless prohibited by law, Tegy will notify Customer of a binding request from a government authority for Customer Personal Data and will reasonably attempt to direct the authority to Customer. If Tegy must respond, it will disclose only the information legally required and, at Customer's expense, provide reasonable cooperation for Customer to seek protection.

14Liability and indemnity

Each party's liability arising from this DPA, including for a Data Incident, is subject to the exclusions, caps, procedures, and other liability terms in the Agreement. Customer's obligations concerning unlawful Customer Personal Data, instructions, regulated data, and third-party claims remain subject to the Customer indemnity in the Agreement. Nothing limits liability that applicable law prohibits the parties from limiting.

15Conflict, changes, and termination

15.1Conflict

This DPA controls over the Agreement only for conflicting terms concerning Processing of Customer Personal Data. It does not expand the Service, fees, warranties, or remedies except for the limited termination and refund rights expressly stated in Sections 7.3 and 15.2.

15.2Changes

Tegy may update this DPA to reflect changes in law or the Service. Tegy will provide reasonable advance notice of a material reduction in Customer's contractual data-protection rights during a paid period, except where an earlier change is required by law or needed to address security or abuse. If Customer reasonably objects to such a reduction, Customer may terminate the affected paid Service before the change takes effect and receive a pro rata refund of prepaid unused fees for that Service.

15.3Survival

The confidentiality, security, deletion, liability, and other provisions that by their nature apply while Tegy retains Customer Personal Data survive termination.

Appendix AProcessing details

A.1 Subject matter

Processing Customer Personal Data submitted, accessed, generated, or exchanged through the Service to provide Tegy's business productivity, content generation, analysis, integration, API, MCP, collaboration, storage, support, security, and related functions.

A.2 Duration

For the Agreement term and the deletion and backup period described in Section 12, subject to legal, security, and claim holds.

A.3 Nature and operations

Collection, receipt, access, organization, hosting, storage, retrieval, transmission, transformation, analysis, inference, generation, display, support, troubleshooting, security monitoring, export, return, deletion, and other operations initiated by Customer or necessary to provide the Service.

A.4 Business purposes

  • provide and administer the Service and Customer-requested features;
  • authenticate and authorize users;
  • host, retrieve, transform, analyze, and generate Customer Content and outputs;
  • operate integrations, APIs, MCP tools, and AI inference;
  • provide support and troubleshoot customer-reported problems;
  • maintain reliability, security, abuse prevention, and legal compliance; and
  • delete or return Customer Personal Data.

A.5 Categories of Consumers

Depending on Customer's use, Consumers may include:

  • Customer's and its affiliates' employees, contractors, applicants, representatives, customers, prospects, suppliers, and business contacts;
  • Authorized Users and workspace administrators;
  • participants in communications, documents, meetings, calls, and connected systems; and
  • other individuals whose information Customer lawfully submits.

A.6 Categories of Personal Data

Depending on Customer's use, Customer Personal Data may include:

  • names, business contact details, roles, company and professional information;
  • account, user, workspace, and online identifiers;
  • messages, correspondence, notes, documents, files, images, audio, transcripts, and collaboration content;
  • business, project, customer-relationship, sales, operational, and workflow information;
  • integration and connected-system records;
  • prompts, instructions, retrieved context, model inputs, and outputs;
  • connection credentials, access tokens, authentication data, and related metadata submitted through designated credential or secrets mechanisms, to the extent they constitute Personal Data; and
  • metadata associated with those categories.

A.7 Restricted categories

The Service is not designed for the specially regulated or high-risk categories prohibited by the Agreement and AUP. Customer must not submit them without a signed written addendum.

A.8 Frequency

Continuous or intermittent, as initiated by Customer and its Authorized Users during the Agreement term.

Appendix BBaseline security measures

Tegy will maintain a security program proportionate to the nature and scope of the Service, the Customer Personal Data, and reasonably foreseeable risk. The baseline measures are:

B.1 Governance and personnel

  • assigned responsibility for security and incident response;
  • confidentiality obligations for personnel and contractors with access;
  • security awareness appropriate to role;
  • prompt removal or adjustment of access when roles change; and
  • periodic review of material security risks and safeguards.

B.2 Identity and access

  • unique workforce accounts for systems that store or can access Customer Personal Data;
  • least-privilege and role-based access to production systems and Customer Content;
  • multi-factor authentication for privileged workforce access and central administrative accounts;
  • credential and secret-management controls; and
  • periodic review of privileged access.

B.3 Transmission and storage

  • encryption of Customer Personal Data in transit over public networks using current industry-standard transport encryption;
  • encryption at rest for primary production databases, object storage, and backups;
  • logical separation of customer workspaces through application and access controls; and
  • restrictions against placing raw credentials or prohibited Customer Content in analytics.

B.4 Application and infrastructure

  • controlled production changes and code review appropriate to risk;
  • separation of development and production environments, with production Customer Personal Data excluded from development by default;
  • dependency and vulnerability management;
  • logging and monitoring for material authentication, administrative, error, and security events;
  • protection against common web-application and infrastructure threats;
  • environment, network, cloud, and provider controls appropriate to the architecture; and
  • remediation of verified material vulnerabilities based on severity and exploitability.

B.5 Data handling

  • product analytics designed around approved metadata rather than Customer Content;
  • masking or exclusion of Customer Content and secrets from designated replay and telemetry surfaces;
  • restrictions on workforce access to Customer Content;
  • retention and deletion controls aligned to the Agreement and Tegy's internal retention schedule; and
  • safeguards for exports, backups, and disposal.

B.6 Vendors and AI providers

  • risk-based review of material Subprocessors;
  • written confidentiality, security, and data-processing terms appropriate to their service;
  • a maintained Subprocessor inventory;
  • AI-provider configuration or contractual controls designed to prevent shared-model training on Customer Content absent opt-in; and
  • review of provider data practices when changing models, endpoints, or tools.

B.7 Resilience and response

  • backups appropriate to the Service and periodic restore testing;
  • an incident-response process covering investigation, containment, remediation, documentation, and notification;
  • escalation paths for suspected compromise; and
  • reasonable business-continuity and recovery planning.

These measures do not represent SOC 2 certification, a particular audit outcome, perfect security, or compliance with a regulated-data framework unless a separate signed agreement expressly says so.