Data Processing Agreement

Last updated: 2026-08-20

This Data Processing Agreement ("DPA") forms part of the agreement between 3A Labs LLC trading as Tenet ("Processor") and the customer identified in that agreement ("Controller", "Customer") for the provision of the Tenet age and identity assurance service (the "Service").

Where this DPA and the Terms of Service conflict on the handling of personal data, this DPA governs.

How to execute this. No signature is needed to rely on it: it is incorporated by reference into our Terms of Service, so it binds from the moment you use the Service. If your procurement process requires a countersigned copy, email legal@choosetenet.com and we will return one within two business days.

This DPA follows the structure of the Common Paper Data Processing Agreement (CC BY 4.0), adapted for a service that does not retain what it processes.


1. Definitions

"Personal Data", "Controller", "Processor", "Data Subject", "Processing", and "Supervisory Authority" have the meanings given in the GDPR.

"Data Protection Laws" means all laws applying to the Processing of Personal Data under this DPA, including the EU GDPR, the UK GDPR and Data Protection Act 2018, the California Consumer Privacy Act as amended ("CCPA"), and US state biometric privacy laws including the Illinois Biometric Information Privacy Act ("BIPA"), the Texas Capture or Use of Biometric Identifier Act ("CUBI"), and the Washington My Health My Data Act.

"Customer Personal Data" means Personal Data that Tenet Processes on Customer's behalf under the Agreement.

"Sub-processor" means a third party engaged by Tenet to Process Customer Personal Data.

"Security Incident" means a breach of security leading to accidental or unlawful destruction, loss, alteration, or unauthorised disclosure of or access to Customer Personal Data.


2. Roles

Customer is the Controller. Tenet is the Processor. Customer determines that a verification occurs, who is subject to it, and what threshold applies.

Under the CCPA, Tenet is a Service Provider. Tenet does not sell or share Personal Data, does not retain, use, or disclose it for any purpose other than performing the Service, and does not combine it with data received from anyone else. Tenet certifies that it understands these restrictions and will comply with them.

Tenet acts as an independent Controller only for its own business-contact data (Customer's own staff contact details, billing records) — governed by the Privacy Policy, not by this DPA.


3. Processing

3.1 Instructions

Tenet Processes Customer Personal Data only on Customer's documented instructions, which comprise this DPA, the Agreement, and Customer's configuration and use of the Service.

Tenet will tell Customer if, in its opinion, an instruction infringes Data Protection Laws. Tenet may Process where required by law, and will notify Customer first unless the law prohibits it.

3.2 Confidentiality

Every person authorised to Process Customer Personal Data is bound by written confidentiality obligations that survive the end of their engagement.

3.3 No secondary use — the commitment that matters most here

Tenet will not:

  • retain verification images or biometric data beyond the verification itself (see §4);
  • use Customer Personal Data to train, fine-tune, evaluate, or improve any machine learning model, whether Tenet's own or a third party's;
  • sell, lease, trade, or otherwise profit from biometric identifiers or biometric information;
  • use Customer Personal Data to build a profile of any Data Subject; or
  • disclose Customer Personal Data other than as this DPA permits.

4. Non-retention — Tenet's central undertaking

This clause is the reason enterprise counsel reads this document, so it is stated as an undertaking rather than as a description.

4.1 Images are never persisted

Tenet processes selfies and identity-document images stream-through: in memory, for the duration of the verification, and never written to persistent storage. No verification image is stored, logged, backed up, cached to disk, or retained by Tenet in any form.

This is enforced technically as well as contractually. Tenet's logging layer redacts image payloads at source.

4.2 Document data is discarded at receipt

Where a verification uses a government-issued document, Tenet's document-verification provider returns the full text of the document. Tenet discards all of it on receipt except the fields required for the decision — specifically discarding name, address, document number, and document expiry, which are never written to Tenet's storage.

4.3 What Tenet does retain, and for how long

Tenet retains an append-only decision record per verification, comprising: the method and provider used, the model version, the outcome, the confidence score, the threshold applied, the age threshold requested, a one-way hash of the input, a one-way hash of the subject reference supplied by Customer (never the reference itself, raw or encrypted), the provider's own reference for the decision where one is returned (retained so that a disputed decision can be re-examined by that provider), and — for document-based verifications only — the age derived from the document, as a whole number.

The date of birth is used at decision time and does not survive it. It is needed to cross-check the provider's verdict; what the record retains is the age it implies. A birth date in a seven-year immutable archive is re-identifying data that no erasure request could ever reach.

Retention: seven years, in storage configured for write-once, read-many immutability.

4.4 The immutability consequence, disclosed rather than buried

Decision records are held in object storage under a compliance-mode retention lock. Neither Tenet nor Customer can alter or delete them before their retention period expires — this is a property of the storage, not a policy choice, and it is what makes the record admissible.

Consequence for erasure requests: Tenet cannot delete a decision record in response to a Data Subject request, a Customer instruction, or termination. Tenet relies on the exemptions for Processing necessary to comply with a legal obligation and to establish, exercise, or defend legal claims. Customer must reflect this in its own privacy notice.

4.5 Warranty of non-retention

Tenet warrants that it does not retain identifying information used to verify age beyond what §4.3 specifies. Customer may rely on this warranty in responding to a regulator, including in jurisdictions that impose penalties for retaining verification data.

Tenet will, on reasonable request and no more than once a year, provide a written statement confirming this warranty remains accurate.


5. Biometric data — allocation of BIPA and CUBI obligations

Generic DPAs do not cover this, and it carries the largest statutory exposure of anything in this document. It is therefore allocated expressly.

5.1 Customer's obligations

Where a Data Subject may be located in Illinois, Texas, Washington, or another state with a biometric privacy statute, Customer is responsible for ensuring that the notice and consent required by that statute is obtained before biometric Processing begins.

Tenet provides a consent interface within the hosted flow as a means of obtaining it. Customer remains the party legally obliged to ensure it is adequate for its use case and must not disable, bypass, or modify it.

5.2 Tenet's obligations

Tenet will:

  • publish a written policy with a retention schedule and destruction guidelines for biometric identifiers and biometric information, as BIPA § 15(a) requires — currently at Privacy Policy § 4;
  • present the notice and obtain the release contemplated by BIPA § 15(b) through its hosted flow;
  • not sell, lease, trade, or otherwise profit from biometric data (BIPA § 15(c));
  • not disclose biometric data except to the Sub-processors in Exhibit B performing the analysis, and only for that purpose (BIPA § 15(d));
  • destroy biometric identifiers and biometric information on completion of the verification (BIPA § 15(a)); and
  • maintain the security standard in §7.

5.3 Indemnity

Tenet indemnifies Customer against claims under BIPA § 15(c) or § 15(d), or their state equivalents, arising from Tenet's own sale, profit from, or unauthorised disclosure of biometric data.

Customer indemnifies Tenet against claims under BIPA § 15(b), or its state equivalents, arising from Customer's failure to ensure adequate notice and consent, or from Customer's disabling or modification of the consent interface Tenet provides.

Both indemnities are subject to the liability cap in Terms § B10.


6. Sub-processors

6.1 Authorisation

Customer gives general authorisation for Tenet to engage the Sub-processors in Exhibit B.

6.2 Changes

Tenet will give at least three days' notice before adding or replacing a Sub-processor, by updating its Security page and emailing every active Customer at the address given during onboarding. There is no list to subscribe to and nothing to opt into: if you are a Customer, you are notified.

Customer may object on reasonable data-protection grounds within that period. The parties will work in good faith to resolve it; failing that, Customer may terminate the affected Service without penalty and receive a pro-rata refund of prepaid fees.

6.3 Liability

Tenet imposes data-protection obligations on each Sub-processor no less protective than those in this DPA.


7. Security

Tenet implements and maintains appropriate technical and organisational measures, described in Exhibit C and, in current detail, on the Security page.

Tenet may update these measures, provided it does not materially reduce their overall protection.


8. Security incidents

Tenet will notify Customer without undue delay and in any event within 48 hours of becoming aware of a Security Incident affecting Customer Personal Data.

The notification will describe the nature of the incident, the categories and approximate number of Data Subjects and records affected, the likely consequences, the measures taken or proposed, and a contact point — to the extent known, with further information following as the investigation proceeds.

Tenet will cooperate reasonably with Customer's own notification obligations. Tenet will not notify a Supervisory Authority or Data Subject on Customer's behalf without Customer's prior written instruction, except where Tenet is independently required to.


9. Data subject rights

Tenet will, to the extent Customer cannot do so itself through the Service, provide reasonable assistance to Customer in responding to Data Subject requests.

If Tenet receives a request directly, it will not respond on the merits (other than to acknowledge and redirect) and will forward it to Customer without undue delay.

Where the request concerns a decision record, Tenet will explain the limit in §4.4 rather than decline without reason.


10. Data protection impact assessments

Tenet will provide reasonable assistance with Customer's data protection impact assessments and prior consultations with Supervisory Authorities, so far as they relate to Tenet's Processing and Customer cannot obtain the information itself.


11. Audits

Tenet will make available the information reasonably necessary to demonstrate compliance with this DPA.

Customer may audit once in any 12-month period, on 30 days' written notice, during business hours, without unreasonably disrupting Tenet's operations, and subject to confidentiality. Customer bears its own costs.

Tenet may satisfy an audit request by providing a current third-party audit report or security questionnaire response where one exists and reasonably addresses the request. No third-party audit report exists today. The paragraph above describes a mechanism that becomes available if one ever does; it is not a claim that one is available now. What we do and do not hold is published on the Security page under What we do not yet have.

A Supervisory Authority may audit to the extent Data Protection Laws require.


12. International transfers

Tenet Processes Customer Personal Data in the United States. Application services, databases, and the audit archive are all held there.

One onward transfer is worth naming rather than leaving to be discovered: the fallback age-estimation provider (Exhibit B) is established in the United Kingdom, so where that fallback is used, a facial image transits to the UK for the duration of the estimate and is not retained.

Where Customer Personal Data originating in the EEA, UK, or Switzerland is transferred to a country without an adequacy decision, the transfer is governed by:

  • the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module Two (Controller to Processor), incorporated by reference and completed per Exhibit A, with Clause 7 (docking) included, Clause 9 option 2 (general authorisation, 30 days), Clause 11 optional redress language omitted, Clause 17 governed by Irish law, and Clause 18 venue in Ireland;
  • for UK transfers, the UK International Data Transfer Addendum (version B1.0), with Tables 1–3 completed by reference to Exhibit A and Table 4 "neither party";
  • for Swiss transfers, the EU SCCs with references read as the Swiss FADP and the Swiss Federal Data Protection and Information Commissioner as supervisory authority.

Tenet will notify Customer if it becomes unable to comply and will assist with supplementary measures where required.

These transfer mechanisms apply only where Tenet has confirmed to Customer in writing that it accepts Customer as an EEA, UK or Swiss Controller. Tenet's launch jurisdiction is the United States only. The mechanism is set out in full above so that a European buyer can read what it would be rather than read its absence as a gap — but the SCCs carry obligations well beyond signature, and Tenet does not assume them by accident.


13. Deletion and return

On termination, Tenet will delete or return Customer Personal Data within 90 days at Customer's election, and delete existing copies — except the immutable decision records in §4.4 and anything Tenet must retain by law.

Tenet will certify deletion in writing on request.


14. General

This DPA is governed by the law and venue in the Agreement, except where the SCCs specify otherwise. It takes effect on the earlier of the Agreement's effective date and Customer's first use of the Service, and continues while Tenet Processes Customer Personal Data. If a provision is invalid, the rest survives.


Exhibit A — Details of Processing

Data exporter: Customer, as identified in the Agreement. Contact and role per the Agreement.

Data importer: 3A Labs LLC trading as Tenet, 5900 Balcones Drive, STE 100, Austin, TX 78731, United States. Contact: privacy@choosetenet.com. Role: Processor.

Subject matter: Provision of age and identity assurance.

Duration: The term of the Agreement, plus the retention periods in §4.

Nature and purpose: Determining whether a Data Subject meets an age or identity threshold set by Customer, and returning that determination to Customer. Includes transient biometric analysis, transient document analysis, and creation of an immutable decision record.

Categories of Data Subject: Individuals whom Customer directs to the Service — typically Customer's end users, customers, or applicants.

Categories of Personal Data:

CategoryRetained?
Facial images (selfies)No — transient only
Identity document imagesNo — transient only
Facial geometry / biometric analysisNo — transient only
Name, address, document number, expiryNo — discarded at receipt
Date of birthNo — used at decision time, not retained
Age derived from the document, as a whole number (document verifications only)Yes — 7 years
Verification outcome, confidence, threshold, method, model versionYes — 7 years
One-way hash of verification inputYes — 7 years
Provider's own reference for the decision, where the provider returns oneYes — 7 years
One-way hash of the Customer-supplied subject referenceYes — 7 years
Whether the Data Subject agreed or declined the biometric noticeYes — 7 years
Which version of the notice the Data Subject was shownYes — 7 years
A fingerprint of the exact notice text shownYes — 7 years
Which checks the notice coveredYes — 7 years
End-user email or phone (only where the Data Subject asks for a credential)Yes — 30 days, encrypted

On the consent record. Where a verification analyses facial geometry, Illinois BIPA § 15(b) requires a written release before collection begins. Tenet obtains one and records it: the decision, the version and fingerprint of the notice the Data Subject actually read, which checks that notice covered, and when they answered. A decline is recorded, not omitted — "asked and declined" and "never asked" are different facts, and only the record of the first is evidence of anything.

That record is subject to the same immutability as a decision record, and therefore to the same consequence: like the records in §4.4, it cannot be deleted on request. A consent record that could be erased would defeat its own purpose, since its value is precisely that it cannot be revised after the fact. It contains no image and no biometric identifier.

Special categories: Biometric data for the purpose of uniquely identifying a natural person, and data concerning a Data Subject's age. Processed transiently only; never retained. Safeguards: stream-through processing, no persistence, encryption in transit and at rest, least-privilege access, purpose limitation, immediate destruction on completion.

Frequency: Continuous, on Customer's instruction.

Retention: Per §4.3 and the table above.

Sub-processor processing: Per Exhibit B.

Competent Supervisory Authority (SCCs): determined by the Controller's establishment or its Article 27 representative, and named for a specific Controller at the point Tenet accepts one under § 12.


Exhibit B — Sub-processors

Current as of 2026-08-20. The live list is maintained at Security.

Sub-processorPurposeLocationReceives biometric data?
Hetzner Online GmbHApplication and database hostingUnited States (Hillsboro, Oregon)No
Amazon Web Services, Inc.Immutable audit archive (S3 Object Lock)United States (us-east-1)No
Cloudflare, Inc.DNS; edge DDoS and WAF protection where enabledUnited States / global edgeIn transit only
Google LLCBusiness email (Google Workspace) — the mailboxes these documents publish and everything written to themUnited StatesNo
Stripe, Inc.Customer invoicing and payment — business contact and billing details onlyUnited StatesNo
Modal Labs, Inc.Hosting for Tenet's own age-estimation modelUnited StatesYes — transient
Yoti LtdThird-party facial age estimation (fallback)United KingdomYes — transient
ID AnalyzerIdentity document verification and face matchingUnited StatesYes — transient

On the two age-estimation providers. Tenet routes age estimation to its own Modal-hosted model by default and to Yoti as a fallback. Both may therefore receive a selfie. Tenet does not claim that facial images never leave its own infrastructure, because that would not be true.

On invoicing. Stripe is listed above and is not yet processing anything: it is the decided billing mechanism and no Customer has been invoiced. What it will receive is the business contact and billing detail needed to raise an invoice — never Customer Personal Data from a verification.

On business email. Mail sent to the addresses these documents publish is received and answered in Google Workspace, so Google processes whatever a person chooses to write to us — including, if you send one that way, the contents of a rights request. It is listed for that reason and no other; it touches no part of the verification pipeline.

On messaging to verifying users. No email or SMS provider appears above for messages to people being verified, because none is live: the retargeting messaging adapter is a development stub that writes to a log and sends nothing to anyone. A provider is added to this table in the same change that makes it live, rather than afterwards.


Exhibit C — Technical and organisational measures

Summarised here for contractual completeness; described in operational detail on the Security page, which is the current source of truth.

Access control. Least-privilege. Multi-factor authentication on all administrative access. No shared accounts. Access reviewed on personnel change.

Encryption. TLS 1.2+ in transit, enforced by HSTS. Encryption at rest for all databases and object storage. Application-layer AES-256-GCM encryption for opaque subject references and end-user contact details, with keys held outside the database.

Pseudonymisation and minimisation. Verification inputs reduced to a one-way hash. The subject reference carried into the immutable record is a keyed pseudonym (HMAC), so holding that record does not let anyone test a guess at the reference behind it. Subject references held for an in-flight verification are encrypted at the application layer. Document text discarded at receipt.

Segregation. Logical tenant separation on every query path. Service-to-service authentication between internal components.

Integrity. Decision records are append-only, enforced at the database layer by triggers that reject UPDATE and DELETE, and exported to write-once object storage.

Availability. Infrastructure defined as code and reproducible from version control. Both databases are backed up daily to object storage on a 30-day retention — deliberately not under an immutability lock, because an unalterable seven-year copy of every audit row is a liability rather than a control. The deployment is a single host with no redundancy.

Logging. Structured logs with a redaction layer that strips images, credentials, tokens, and authorisation headers at source.

Vulnerability management. Automated dependency scanning and secret scanning on every change. Security-relevant changes require review.

Personnel. Everyone with access is bound by written confidentiality obligations that survive the end of their engagement. Background checks are not performed at current headcount.

Incident response. Documented process; 48-hour customer notification commitment per §8.