This Data Processing Addendum (“Addendum”) forms part of the Terms of Service between KMPS Global Corporation, an Ohio corporation doing business as Tejdux (“Processor”, “we”), and the customer that accepted those Terms (“Controller”, “you”).
1.1 This Addendum applies where and to the extent that we process Customer Personal Data on your behalf in providing the Service.
1.2 It is incorporated into the Terms of Service. Where this Addendum conflicts with the Terms on a matter of data protection, this Addendum prevails. Where it conflicts with the Standard Contractual Clauses referred to in Section 13, those Clauses prevail.
1.3 “Customer Personal Data” means personal data contained in your workspace, including Creator Records you import or enter, campaign and content records, and any personal data in files you upload. It does not include your account and login details.
2.1 For Customer Personal Data you are the controller and we are the processor. Where you are yourself acting as a processor for a third party — an agency operating on behalf of a brand, for instance — we are a sub-processor, and you confirm you have the authority to appoint us.
2.2 For your account and login details, website analytics, and billing records, we are the controller and our Privacy Policy applies. The table in Section 1 of that policy sets out which data falls on which side of this line.
2.3 You are responsible for having a lawful basis for the Customer Personal Data you upload, for having obtained it lawfully, and for giving any notices and obtaining any consents your own jurisdiction requires. This mirrors the representations you give under the Terms of Service.
The subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subject are set out in Annex A, as Article 28(3) requires.
4.1 We process Customer Personal Data only on your documented instructions, including as to international transfers, unless required otherwise by law. Where law requires it, we will tell you before processing unless that law forbids the notification.
4.2 Your instructions are: the Terms of Service, this Addendum, your configuration of the Service, and the actions your authorised users take in the product.
4.3 We will tell you if, in our opinion, an instruction infringes data protection law. We may suspend the affected processing until the instruction is withdrawn or amended.
4.4 Where a public authority requests Customer Personal Data, we redirect it to you as the controller. If we are legally compelled to respond directly, we notify you promptly so that you can seek protection from disclosure, unless the law forbids that notification. In every case we assess the request for legal validity, challenge it where it is unlawful or overbroad, disclose only the minimum it compels, and record what we did. Our Government Request Policy sets this out in full.
We ensure that people authorised to process Customer Personal Data are subject to an appropriate duty of confidentiality, and that access is limited to those who need it to provide or support the Service.
6.1 We implement appropriate technical and organisational measures under Article 32. Those measures are described in Annex B.
6.2 We may update them as the Service evolves, provided the level of protection is not materially reduced.
7.1 You give general written authorisation for us to engage sub-processors. Those engaged as at the date of this Addendum are listed in Annex C.
7.2 We will give at least 30 days' notice before adding or replacing a sub-processor, by email to your account's notification address and by updating Annex C.
7.3 You may object on reasonable data protection grounds within that notice period. We will work with you in good faith to find a solution. If none is available, you may terminate the affected part of the Service and receive a pro-rata refund of prepaid fees for the unused term — which is an exception to the no-refunds rule in the Terms.
7.4 We impose data protection obligations on each sub-processor that are no less protective than those in this Addendum, and we remain liable to you for their performance.
8.1 The Service lets you access, correct, export and delete Customer Personal Data directly. For most requests that is the fastest route and needs no involvement from us.
8.2 Where a request cannot be satisfied through the product, we will provide reasonable assistance, taking account of the nature of the processing.
8.3 If a data subject contacts us directly about data in your workspace, we will not respond substantively other than to direct them to you, and we will forward the request to you without undue delay. Where we are legally required to act directly, we will tell you.
Taking account of the nature of processing and the information available to us, we will provide reasonable assistance with your obligations under Articles 32 to 36 — security, breach notification, data protection impact assessments, and prior consultation with a supervisory authority.
10.1 We will notify you without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data.
10.2 The notification will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point — so far as that information is available to us. Where it is not all available at once, we will provide it in phases without further undue delay.
10.3 Notifying you is not an admission of fault or liability.
10.4 You are responsible for notifying supervisory authorities and data subjects where the law requires it, since you hold the relationship with them and the context to assess risk.
11.1 During your subscription you can export and delete Customer Personal Data through the Service at any time.
11.2 On termination, we delete Customer Personal Data within 30 days, unless you ask in writing within that period for it to be returned first, or law requires us to keep it.
11.3 Automated backups are on a rolling cycle and expire on their own schedule — up to 30 days — after which deleted data no longer exists in them. We also keep a small number of manual database snapshots for disaster recovery. These do not expire on a schedule, so deleted data can persist in them until the snapshot itself is deleted. Until then it is held only in encrypted backups and snapshots in our own AWS account, which the Service does not read.
12.1 We make available the information necessary to demonstrate compliance with Article 28, and allow for and contribute to audits, including inspections, conducted by you or an auditor you appoint.
12.2 In practice we expect this to be satisfied by our written responses to a security questionnaire and by the information in this Addendum. An on-site or hands-on audit may be requested no more than once in any 12-month period, on 30 days' notice, during business hours, subject to confidentiality, and must not unreasonably disrupt our operations. We may charge our reasonable costs for an audit beyond the first in any 12-month period.
12.3 The frequency limit does not apply where an audit is required by a supervisory authority or follows a personal data breach affecting your data.
13.1 We and our sub-processors are located in the United States and Customer Personal Data is stored there. See Annex C for each sub-processor's location.
13.2 Where you transfer Customer Personal Data from the UK, the EEA or another region with transfer restrictions, the transfer is made under an appropriate safeguard. Where the EU Standard Contractual Clauses apply, Module Two (controller to processor) is incorporated by reference, with Annex A and Annex B of this Addendum serving as their Annexes I and II. Where the UK regime applies, the UK International Data Transfer Addendum applies to those Clauses.
Each party's liability under this Addendum is subject to the exclusions and limitations in the Terms of Service. Nothing in this Addendum limits either party's liability to a data subject under Article 82, or any liability that cannot lawfully be limited.
We may update this Addendum where required by a change in law, in the Service, or in our sub-processors. We will give notice by email or in the product before a material change takes effect. The version and date at the top always reflect the current text.
| Item | Detail |
|---|---|
| Subject matter | Provision of the TejDux influencer-marketing platform. |
| Duration | The term of your subscription, plus the deletion period in Section 11. |
| Nature and purpose | Storing and organising creator records; managing campaigns and content; recording attribution and payments; suggesting spreadsheet column mappings on import; making data available to your authorised users. |
| Types of personal data | Names; social handles and platform; email addresses; campaign participation; fees and payment status; discount codes and affiliate links; notes and correspondence logs; content produced for you; and any other personal data you choose to upload. |
| Categories of data subject | Content creators and influencers; your own personnel who use the Service. |
| Special category data | None. The Terms of Service prohibit uploading special categories of personal data and data relating to minors, and the Service is not designed to hold either. |
| Frequency | Continuous for the duration of the subscription. |
The measures below are in place as at the date of this Addendum.
| Sub-processor | Purpose | Data involved | Location |
|---|---|---|---|
| Amazon Web Services, Inc. | Hosting, storage, backups, email delivery | All Customer Personal Data | United States |
| Stripe, Inc. | Subscription payments | Your billing contact and payment details — not Customer Personal Data | United States |
| Anthropic, PBC | Suggesting spreadsheet column mappings on import; classifying a creator into a content category; drafting campaign brief and landing-page copy |
For import mapping: column headings and target field names only. Row data is never
transmitted.
For classification: a creator’s public social handle, public display name, public follower count, and the text of up to twelve recent public posts. No contact details, no private messages, and nothing the Customer recorded privately (such as a fee or rate). For drafting: the campaign brief the Customer wrote (goal, audience, offer), plus the named creator’s public social handle and platform name. No follower count, post content or contact details. |
United States |
| Google LLC | Business email for support and service correspondence | Email addresses and message content you send us | United States |
Social sign-in providers and the commerce and social platforms you choose to connect are not sub-processors: they receive data because you direct the Service to exchange data with them, and they act as independent controllers under their own terms.
Questions about this Addendum, or to request a signed copy:
KMPS Global Corporation (d/b/a Tejdux)
[registered office address]
privacy@tejdux.com