Tejdux

Data Processing Addendum

Version 1.2 · Last updated 11 September 2026

Not yet in force This Addendum is published for review. It takes effect for a customer when it is incorporated into that customer's agreement, either by signature or by the acceptance mechanism described in Section 1.2.

This Data Processing Addendum (“Addendum”) forms part of the Terms of Service between KMPS Global Corporation, an Ohio corporation doing business as Tejdux (“Processor”, “we”), and the customer that accepted those Terms (“Controller”, “you”).

What this document is for. Most of the personal data in a Tejdux workspace is data about creators, which you uploaded. You decided to collect it and you decide what it is for; we hold it and act on your instructions. Article 28(3) of the UK and EU GDPR requires that relationship to be governed by a written contract, and this is that contract. It does not apply to your own account details — for those we are the controller and our Privacy Policy applies in full.

Contents

  1. Scope and order of precedence
  2. Roles of the parties
  3. Subject matter, duration, nature and purpose
  4. Processing on documented instructions
  5. Confidentiality
  6. Security measures
  7. Sub-processors
  8. Assisting with data subject rights
  9. Assisting with your other obligations
  10. Personal data breaches
  11. Deletion and return
  12. Information and audit
  13. International transfers
  14. Liability
  15. Changes to this Addendum
  16. Annex A — Details of processing
  17. Annex B — Technical and organisational measures
  18. Annex C — Sub-processors

1. Scope and order of precedence

1.1 This Addendum applies where and to the extent that we process Customer Personal Data on your behalf in providing the Service.

1.2 It is incorporated into the Terms of Service. Where this Addendum conflicts with the Terms on a matter of data protection, this Addendum prevails. Where it conflicts with the Standard Contractual Clauses referred to in Section 13, those Clauses prevail.

1.3 “Customer Personal Data” means personal data contained in your workspace, including Creator Records you import or enter, campaign and content records, and any personal data in files you upload. It does not include your account and login details.

2. Roles of the parties

2.1 For Customer Personal Data you are the controller and we are the processor. Where you are yourself acting as a processor for a third party — an agency operating on behalf of a brand, for instance — we are a sub-processor, and you confirm you have the authority to appoint us.

2.2 For your account and login details, website analytics, and billing records, we are the controller and our Privacy Policy applies. The table in Section 1 of that policy sets out which data falls on which side of this line.

2.3 You are responsible for having a lawful basis for the Customer Personal Data you upload, for having obtained it lawfully, and for giving any notices and obtaining any consents your own jurisdiction requires. This mirrors the representations you give under the Terms of Service.

3. Subject matter, duration, nature and purpose

The subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subject are set out in Annex A, as Article 28(3) requires.

4. Processing on documented instructions

4.1 We process Customer Personal Data only on your documented instructions, including as to international transfers, unless required otherwise by law. Where law requires it, we will tell you before processing unless that law forbids the notification.

4.2 Your instructions are: the Terms of Service, this Addendum, your configuration of the Service, and the actions your authorised users take in the product.

4.3 We will tell you if, in our opinion, an instruction infringes data protection law. We may suspend the affected processing until the instruction is withdrawn or amended.

4.4 Where a public authority requests Customer Personal Data, we redirect it to you as the controller. If we are legally compelled to respond directly, we notify you promptly so that you can seek protection from disclosure, unless the law forbids that notification. In every case we assess the request for legal validity, challenge it where it is unlawful or overbroad, disclose only the minimum it compels, and record what we did. Our Government Request Policy sets this out in full.

What we do not do with your data. We do not sell it. We do not use it to build profiles for our own purposes. We do not use it to train machine learning models, ours or anyone else's. The one place Customer Personal Data could otherwise reach an AI provider is the spreadsheet import described in Annex C, and that feature deliberately transmits only column headings — never the rows beneath them.

5. Confidentiality

We ensure that people authorised to process Customer Personal Data are subject to an appropriate duty of confidentiality, and that access is limited to those who need it to provide or support the Service.

6. Security measures

6.1 We implement appropriate technical and organisational measures under Article 32. Those measures are described in Annex B.

6.2 We may update them as the Service evolves, provided the level of protection is not materially reduced.

7. Sub-processors

7.1 You give general written authorisation for us to engage sub-processors. Those engaged as at the date of this Addendum are listed in Annex C.

7.2 We will give at least 30 days' notice before adding or replacing a sub-processor, by email to your account's notification address and by updating Annex C.

7.3 You may object on reasonable data protection grounds within that notice period. We will work with you in good faith to find a solution. If none is available, you may terminate the affected part of the Service and receive a pro-rata refund of prepaid fees for the unused term — which is an exception to the no-refunds rule in the Terms.

7.4 We impose data protection obligations on each sub-processor that are no less protective than those in this Addendum, and we remain liable to you for their performance.

8. Assisting with data subject rights

8.1 The Service lets you access, correct, export and delete Customer Personal Data directly. For most requests that is the fastest route and needs no involvement from us.

8.2 Where a request cannot be satisfied through the product, we will provide reasonable assistance, taking account of the nature of the processing.

8.3 If a data subject contacts us directly about data in your workspace, we will not respond substantively other than to direct them to you, and we will forward the request to you without undue delay. Where we are legally required to act directly, we will tell you.

A creator who cannot identify the brand. A creator often does not know which brands hold their details. Where a creator contacts us and cannot identify you, we will identify the relevant workspaces and forward the request. This is described in Section 9 of our Privacy Policy, and it is a commitment to the creator as much as to you.

9. Assisting with your other obligations

Taking account of the nature of processing and the information available to us, we will provide reasonable assistance with your obligations under Articles 32 to 36 — security, breach notification, data protection impact assessments, and prior consultation with a supervisory authority.

10. Personal data breaches

10.1 We will notify you without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data.

10.2 The notification will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point — so far as that information is available to us. Where it is not all available at once, we will provide it in phases without further undue delay.

10.3 Notifying you is not an admission of fault or liability.

10.4 You are responsible for notifying supervisory authorities and data subjects where the law requires it, since you hold the relationship with them and the context to assess risk.

11. Deletion and return

11.1 During your subscription you can export and delete Customer Personal Data through the Service at any time.

11.2 On termination, we delete Customer Personal Data within 30 days, unless you ask in writing within that period for it to be returned first, or law requires us to keep it.

11.3 Automated backups are on a rolling cycle and expire on their own schedule — up to 30 days — after which deleted data no longer exists in them. We also keep a small number of manual database snapshots for disaster recovery. These do not expire on a schedule, so deleted data can persist in them until the snapshot itself is deleted. Until then it is held only in encrypted backups and snapshots in our own AWS account, which the Service does not read.

Two records deliberately survive deletion. Where the law requires us to keep something, we keep it: billing and tax records for the statutory period, and the record that a consent was given or a deletion was performed. The second is not a loophole — the evidence that a deletion was carried out lawfully is precisely what would be needed if anyone later asked whether it was, so destroying it with the account would defeat its purpose. These are retained under a legal-records basis, not under the account-data basis, and are held in a form designed to prove that an event happened rather than to describe a person.

12. Information and audit

12.1 We make available the information necessary to demonstrate compliance with Article 28, and allow for and contribute to audits, including inspections, conducted by you or an auditor you appoint.

12.2 In practice we expect this to be satisfied by our written responses to a security questionnaire and by the information in this Addendum. An on-site or hands-on audit may be requested no more than once in any 12-month period, on 30 days' notice, during business hours, subject to confidentiality, and must not unreasonably disrupt our operations. We may charge our reasonable costs for an audit beyond the first in any 12-month period.

12.3 The frequency limit does not apply where an audit is required by a supervisory authority or follows a personal data breach affecting your data.

13. International transfers

13.1 We and our sub-processors are located in the United States and Customer Personal Data is stored there. See Annex C for each sub-processor's location.

13.2 Where you transfer Customer Personal Data from the UK, the EEA or another region with transfer restrictions, the transfer is made under an appropriate safeguard. Where the EU Standard Contractual Clauses apply, Module Two (controller to processor) is incorporated by reference, with Annex A and Annex B of this Addendum serving as their Annexes I and II. Where the UK regime applies, the UK International Data Transfer Addendum applies to those Clauses.

Read this before relying on Section 13 The Standard Contractual Clauses require choices to be made — governing law, forum, the optional docking clause, and the completion of their own annexes — and those choices are not made here. As at the date above, the Service is sold to customers in the United States only, so no transfer under Chapter V of the GDPR is contemplated. Do not rely on this section for an EEA or UK transfer until it has been completed and reviewed.

14. Liability

Each party's liability under this Addendum is subject to the exclusions and limitations in the Terms of Service. Nothing in this Addendum limits either party's liability to a data subject under Article 82, or any liability that cannot lawfully be limited.

15. Changes to this Addendum

We may update this Addendum where required by a change in law, in the Service, or in our sub-processors. We will give notice by email or in the product before a material change takes effect. The version and date at the top always reflect the current text.

Annex A — Details of processing

ItemDetail
Subject matter Provision of the TejDux influencer-marketing platform.
Duration The term of your subscription, plus the deletion period in Section 11.
Nature and purpose Storing and organising creator records; managing campaigns and content; recording attribution and payments; suggesting spreadsheet column mappings on import; making data available to your authorised users.
Types of personal data Names; social handles and platform; email addresses; campaign participation; fees and payment status; discount codes and affiliate links; notes and correspondence logs; content produced for you; and any other personal data you choose to upload.
Categories of data subject Content creators and influencers; your own personnel who use the Service.
Special category data None. The Terms of Service prohibit uploading special categories of personal data and data relating to minors, and the Service is not designed to hold either.
Frequency Continuous for the duration of the subscription.

Annex B — Technical and organisational measures

The measures below are in place as at the date of this Addendum.

Encryption

Access control

Integrity and auditability

Resilience and recovery

Annex C — Sub-processors

Sub-processorPurposeData involvedLocation
Amazon Web Services, Inc. Hosting, storage, backups, email delivery All Customer Personal Data United States
Stripe, Inc. Subscription payments Your billing contact and payment details — not Customer Personal Data United States
Anthropic, PBC Suggesting spreadsheet column mappings on import; classifying a creator into a content category; drafting campaign brief and landing-page copy For import mapping: column headings and target field names only. Row data is never transmitted.

For classification: a creator’s public social handle, public display name, public follower count, and the text of up to twelve recent public posts. No contact details, no private messages, and nothing the Customer recorded privately (such as a fee or rate).

For drafting: the campaign brief the Customer wrote (goal, audience, offer), plus the named creator’s public social handle and platform name. No follower count, post content or contact details.
United States
Google LLC Business email for support and service correspondence Email addresses and message content you send us United States

Social sign-in providers and the commerce and social platforms you choose to connect are not sub-processors: they receive data because you direct the Service to exchange data with them, and they act as independent controllers under their own terms.

Contact

Questions about this Addendum, or to request a signed copy:

KMPS Global Corporation (d/b/a Tejdux)
[registered office address]
privacy@tejdux.com