Legal
Data Processing Addendum
Data-protection terms for customer organizations using TellTell.
Effective August 26, 2026
1. Scope and order of precedence
This Data Processing Addendum (“DPA”) forms part of the Terms of Use between TellTell LLC (“TellTell”) and the customer organization (“Customer”) whenever TellTell processes Customer Personal Data on Customer's behalf. It applies automatically without a separate signature. If this DPA conflicts with the Terms regarding Customer Personal Data, this DPA controls.
“Customer Personal Data” means personal information contained in Customer Content that TellTell processes as Customer's processor or service provider. “Data Protection Law” means U.S. federal or state privacy law applicable to that processing.
2. Roles, instructions, and purpose limitation
Customer is the controller or business and TellTell is its processor, service provider, or contractor, as those terms are defined by applicable Data Protection Law. TellTell will process Customer Personal Data only to provide, secure, support, and maintain the Service; comply with documented Customer instructions; and meet legal obligations.
TellTell will not sell Customer Personal Data, share it for cross-context behavioral advertising, retain, use, or disclose it outside the direct business relationship with Customer, or combine it with personal information obtained from another source except as permitted by Data Protection Law. TellTell will not use Customer Content to train general-purpose artificial-intelligence models.
Customer is responsible for the lawfulness of its instructions, notices, permissions, and Customer Personal Data. Customer must not submit restricted sensitive data identified in the Terms unless TellTell agrees in writing.
3. Confidentiality and security
TellTell will ensure that personnel authorized to process Customer Personal Data are bound by confidentiality obligations and receive appropriate privacy and security guidance. TellTell will maintain reasonable administrative, technical, and organizational safeguards appropriate to the nature of the data and risk, including access control, least-privilege service identities, encryption in transit, protected cloud storage, logging and monitoring, vulnerability and patch management, backup and recovery controls, and incident-response procedures.
4. Rights and compliance assistance
Taking into account the nature of processing and information available to TellTell, TellTell will reasonably assist Customer with verified requests to access, correct, delete, or export Customer Personal Data and with Customer's privacy impact assessments, consultations, and compliance inquiries when required by applicable law. If TellTell receives a request relating to Customer-controlled data, it may direct the requester to Customer and notify Customer unless prohibited by law.
5. Subprocessors
Customer generally authorizes TellTell to use subprocessors to provide the Service. TellTell will impose data-protection obligations appropriate to the services they perform and remains responsible for its DPA obligations.
Current subprocessors (updated August 26, 2026)
| Provider | Service and processing | Location |
|---|---|---|
| Amazon Web Services, Inc. | Cloud hosting, storage, queues, security services, and email processing and delivery | United States and other provider-documented locations selected for the Service |
| Apple Inc. | Apple sign-in and related identity services | United States and other provider-documented locations |
| Google LLC | Google sign-in and related identity services and website hosting | United States and other provider-documented locations |
| Microsoft Corporation | Microsoft sign-in and related identity services | United States and other provider-documented locations |
| Meta Platforms, Inc. | Facebook Login and related identity services | United States and other provider-documented locations |
| Automattic Inc. (Gravatar) | Optional public profile-image lookup using a one-way SHA-256 representation of a directory person's normalized primary email | United States and other provider-documented locations |
| Stripe, Inc. | Checkout, subscription billing, payment processing, and fraud prevention | United States and other provider-documented locations |
| Crisp IM SAS | Delivery and routing of contact, legal, and customer-support communications submitted through the public contact form or live chat | United States, European Union, and other provider-documented locations |
The personal information processed depends on which Service features a Customer uses. Payment-card details are submitted directly to Stripe and are not stored by TellTell.
Changes to the list
We will update this section before a new subprocessor begins materially processing Customer Personal Data and will provide reasonable notice through the Service or by email when appropriate. A Customer may object on reasonable data-protection grounds by contacting us promptly; the parties will work in good faith on a commercially reasonable resolution.
6. Security incidents and legal demands
TellTell will notify Customer without undue delay after confirming a breach of security that results in accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data (“Security Incident”). Notice will include information reasonably available to help Customer meet applicable obligations. TellTell's notice is not an admission of fault. Unsuccessful attempts that do not compromise Customer Personal Data are not Security Incidents.
If TellTell receives a legally binding demand for Customer Personal Data, it will notify Customer when legally permitted, challenge overbroad demands when reasonably appropriate, and disclose only the information required.
7. Return and deletion
During the subscription, Customer may use available tools or request reasonable assistance to export Customer Personal Data. After termination or account closure, TellTell will delete or de-identify Customer Personal Data under the schedules described in the Privacy Policy and Terms, unless law requires retention. Data may remain in protected backups, provider systems, suppression records, security records, or billing records until the applicable schedule expires and will not be used for another purpose.
8. Verification and audits
On reasonable written request, TellTell will provide information reasonably necessary to demonstrate compliance with this DPA, such as relevant policies, summaries, or independent assessments when available. If that information is insufficient and Data Protection Law requires further verification, Customer may request an audit no more than once annually, or following a confirmed Security Incident. Audits must occur during normal business hours, avoid unreasonable disruption, protect other customers and TellTell confidential information, and be performed by an independent auditor under confidentiality obligations. Customer bears its audit costs unless material noncompliance is found.
9. U.S. state privacy terms
For Customer Personal Data governed by a comprehensive U.S. state privacy law, TellTell will provide the same level of privacy protection required of a processor, service provider, or contractor; notify Customer if it determines it can no longer meet those obligations; and permit Customer to take reasonable and appropriate steps to stop and remediate unauthorized use. TellTell certifies that it understands and will comply with the restrictions in this DPA.
10. Processing details
| Subject matter and duration | Operation of the group-email Service for the subscription term and applicable deletion period. |
|---|---|
| Nature and purpose | Hosting directories and optional account-scoped profile images; authenticating organizers; applying permissions; routing, delivering, and reporting email; support; security; billing administration; and Customer instructions. |
| Data subjects | Customer organizers, users, members, senders, recipients, guardians, support contacts, and other people whose information Customer submits. |
| Data categories | Names, email addresses, optional provider or Gravatar profile images and their one-way lookup identifiers, roles, group relationships, custom fields, account identifiers, configuration, communications, message and delivery metadata, support information, and audit or security events. |
| Sensitive data | Not intended for processing. Customer must follow the restricted-data rule in the Terms. |
11. Contact
DPA inquiries may be sent to legal@telltell.co.
TellTell LLC