Data Processing Agreement DPA

Document that governs the conditions under which Tess processes personal data as an operator, on behalf of corporate clients, in compliance with Brazil's General Data Protection Law (LGPD — Law No. 13,709/2018).

Version 02 · Last updated: July 2026 Trust Center Contact the Data Protection Officer (DPO)

This Data Processing Agreement ("DPA") describes the conditions under which Tess Tecnologia LTDA. processes personal data as an operator, on behalf and under the instructions of corporate clients, in the provision of the Tess AI Platform's services.

This is the public reference version. Between Tess and each client, the DPA is in effect as an inseparable annex and addendum to the Services Agreement ("Main Agreement"). Corporate clients who need the formalized document may request it by email at dpo@tess.im.

This DPA does not apply to processing in which Tess acts as an independent controller — registration data, billing, telemetry and security —, which is governed by the Privacy Policy and the Privacy Notice. The current list of sub-processors is published on the Tess Trust Center.

Controller

The corporate client The legal entity identified in the Main Agreement, to whom the decisions regarding the purpose and means of Personal Data processing belong ("CONTROLLER" or "CLIENT").

Operator

TESS TECNOLOGIA LTDA. Registered under Brazilian company registration (CNPJ/MF) No. 60.806.420/0001-91, headquartered at Avenida Oscar Niemeyer, No. 2,000, Bloco 1, Sala 401, Santo Cristo, Rio de Janeiro/RJ, ZIP Code 20220-297, Brazil ("TESS" or "OPERATOR").

Definitions

For the purposes of this Data Processing Agreement ("DPA"), the definitions set out in the LGPD (Law No. 13,709/2018) apply, without prejudice to the following:

  • Personal Data: information related to an identified or identifiable natural person, pursuant to Art. 5, I, of the LGPD.
  • Sensitive Personal Data: data concerning racial or ethnic origin, religious belief, political opinion, health, sex life, or genetic or biometric data, pursuant to Art. 5, II, of the LGPD.
  • Data Subject: the natural person to whom the Personal Data processed under this DPA relates.
  • Controller: the CLIENT, to whom the decisions regarding the processing of Personal Data belong, pursuant to Art. 5, VI, of the LGPD.
  • Operator: TESS, which processes Personal Data on behalf of the Controller, pursuant to Art. 5, VII, of the LGPD.
  • Processing: any operation carried out with Personal Data, pursuant to Art. 5, X, of the LGPD — collection, production, receipt, classification, use, access, reproduction, transmission, distribution, processing, filing, storage, deletion, evaluation, control, modification, communication, transfer, dissemination or extraction.
  • Security Incident: any adverse event, confirmed or suspected, related to a breach of Personal Data security, including unauthorized access, leakage, alteration, or accidental or unlawful loss.
  • Sub-processor: a third party engaged by the Operator to carry out, in whole or in part, Personal Data processing activities on behalf of the Controller.
  • ANPD: Brazil's National Data Protection Authority.
  • Applicable Data Protection Laws: all legislation, regulations and rules applicable to the protection of personal data, including, as applicable, the LGPD, the European Union's General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA) and other related rules.
  • Controller Data: all data, content, files, information, prompts, outputs, logs and metadata submitted, stored, processed or generated in the context of the services, including Personal Data.
  • Affiliate: any entity that controls, is controlled by, or is under common control with, one of the Parties.
  • Data Subject Request: any request made by a Data Subject related to the exercise of their legal data protection rights.
  • Standard Contractual Clauses (SCCs): clauses approved by regulatory authorities to legitimize international data transfers.

Purpose and Object

2.1The purpose of this DPA is to govern the conditions under which the OPERATOR will process Personal Data on behalf of the CONTROLLER, within the scope and for the purposes of performing the Main Agreement, in compliance with Applicable Law.

2.2This DPA is an integral and inseparable part of the Main Agreement, applying to any and all processing of Personal Data carried out by the OPERATOR in connection with the provision of the contracted services.

2.3The purpose of the processing is strictly limited to the performance of the object of the Main Agreement. The OPERATOR may not process Personal Data for any other purpose, whether its own or a third party's, including for training, development, tuning or improvement of artificial intelligence models, algorithms or automated solutions, unless the CONTROLLER has given prior, express and documented authorization.

2.4In the event of a conflict between this DPA and the Main Agreement, with respect to obligations relating to the protection of Personal Data, the provisions of this DPA shall prevail.

Roles of the Parties

3.1The CONTROLLER acts as controller of the Personal Data processed under this DPA, and is responsible for the decisions regarding the purpose and means of the processing.

3.2The OPERATOR acts as operator of the Personal Data, carrying out the processing exclusively on behalf of, and in accordance with, the documented instructions of the CONTROLLER, except where Applicable Law imposes a different obligation on the OPERATOR, in which case it must notify the CONTROLLER in advance, unless such notification is prohibited on grounds of substantial public interest.

3.3Should the Parties identify, during contract performance, a scenario of joint controllership or of the OPERATOR acting as an independent controller for its own purposes, such condition must be expressly agreed upon in a specific addendum, with the operator regime provided for in this DPA applying until then.

Description of the Processing

4.1The characteristics of the Personal Data processing subject to this DPA, including categories of data subjects, categories of data, purposes, operations performed, duration, frequency, and systems and environments involved, are described in Annex I, which shall be completed and kept up to date by the OPERATOR, with validation by the CONTROLLER.

4.2Any material change to the scope of the processing described in Annex I must be communicated to the CONTROLLER in advance, and may not be implemented without the corresponding update to this Annex and, where required by Applicable Law, without the CONTROLLER's authorization.

Obligations of the Operator

The OPERATOR undertakes to:

5.1process Personal Data exclusively in accordance with the documented instructions of the CONTROLLER and for the purposes set out in this DPA and in the Main Agreement;

5.2ensure that persons authorized to process Personal Data are subject to a confidentiality commitment, whether contractual or statutory in nature;

5.3adopt the technical and administrative information security measures set out in Annex II, compatible with the nature, scope, size and risk of the processing carried out;

5.4assist the CONTROLLER, to the extent reasonable and technically feasible, in responding to data subject requests and complying with obligations under Applicable Law, including the preparation of impact assessments, when applicable;

5.5notify the CONTROLLER, without undue delay, of any Security Incident that may pose a relevant risk or harm to Data Subjects, pursuant to Clause 11 of this DPA;

5.6not carry out any international transfer of Personal Data without complying with Clause 9 of this DPA;

5.7not subcontract the processing of Personal Data to Sub-processors without complying with Clause 8 of this DPA;

5.8delete or return the Personal Data upon termination of the services, in accordance with the CONTROLLER's instructions and the terms of Clause 14 of this DPA, except where retention is legally or regulatorily required;

5.9make available to the CONTROLLER the information necessary to demonstrate compliance with the obligations set out in this DPA, including, where applicable, evidence of certifications, audit reports or equivalent documentation.

Obligations of the Controller

The CONTROLLER undertakes to:

6.1provide lawful, clear and documented instructions to the OPERATOR regarding the processing of Personal Data;

6.2ensure that it has an adequate legal basis for the processing of Personal Data and for sharing it with the OPERATOR, pursuant to Applicable Law;

6.3respond, to the extent it is responsible, to Data Subject requests related to the exercise of their rights under Applicable Law;

6.4inform the OPERATOR, in a timely manner, of any material change that may impact the processing of Personal Data subject to this DPA.

Technical and Administrative Security Measures

7.1The OPERATOR shall adopt, where applicable to the nature, scope, size and risk of the processing, technical and administrative measures compatible with good information security practices, as detailed in Annex II of this DPA, which distinguishes mandatory minimum controls from additional controls applicable depending on the risk involved.

7.2Certifications, seals, attestations of compliance or audit reports that may be maintained by the OPERATOR (such as ISO 27001, SOC 2 or equivalents) shall be disclosed in Annex II, when available, and may be requested as supplementary evidence of compliance, without prejudice to the adoption of the minimum controls set out in this DPA.

7.3The CONTROLLER may, upon prior and reasonable notice, request additional information about the security measures adopted by the OPERATOR, subject to Clause 12 (Audit and Right of Oversight).

Subcontracting / Sub-processors

8.1The OPERATOR may subcontract Sub-processors for the processing of Personal Data, under a general authorization from the CONTROLLER, hereby expressly granted with respect to the Sub-processors listed in the list published on the TESS Trust Center, provided that: (i) it keeps that list up to date and publicly accessible; (ii) it notifies the CONTROLLER in advance of any addition, replacement or removal of a Sub-processor, with at least 15 (fifteen) calendar days' notice; and (iii) it ensures the CONTROLLER's right to object, in a reasoned manner and in writing, within that period, to the engagement of a given Sub-processor. Upon a reasoned objection, the Parties will negotiate in good faith, for up to 30 (thirty) calendar days, a technically reasonable alternative; if no agreement is reached, the CONTROLLER may terminate, without cost or penalty, the services specifically affected by the objected subcontracting, with the Main Agreement remaining in full force with respect to the other services.

8.2The OPERATOR remains fully liable to the CONTROLLER for its Sub-processors' compliance with the obligations set out in this DPA, and must contractually impose on them data protection obligations equivalent to those established herein.

8.3The engagement of a Sub-processor for purposes of training artificial intelligence models, or that involves sharing Personal Data for such purpose, shall require the CONTROLLER's prior, express and specific authorization, and the general authorization set out in item 8.1 shall not apply in this case.

List of sub-processors. The complete and current list of Tess's Sub-processors — with purpose, location, categories of data processed and controls applicable to each — is published and kept up to date on the Tess Trust Center. The AI model providers listed there are engaged only when the CONTROLLER or its authorized users select the corresponding model or feature, and under no circumstances is the data used to train models.

International Data Transfer

9.1The CONTROLLER acknowledges that the provision of the services inherently involves, due to its nature and architecture, international transfer of Personal Data, and hereby expressly authorizes transfers to the countries, for the purposes, and to the Sub-processors described in Annex I and in the list of Sub-processors published on the Trust Center, which constitute, for all purposes of this Clause, valid and sufficient prior notice. Transfers to countries or sub-processors not described in Annex I or in that list shall depend on prior notice to the CONTROLLER, in the manner set out in Clause 8.1, and on the adoption of the mechanisms required by Applicable Law, including, where relevant, standard contractual clauses, adequacy decisions or other instruments recognized by the competent authority.

9.2Where required by Applicable Law or necessary for the legitimacy of the international transfer, the Parties will adopt the appropriate contractual, regulatory and technical mechanisms, including standard contractual clauses or other instruments recognized by the ANPD or by a competent foreign authority, as applicable.

9.3In the event of an international transfer of Personal Data, the OPERATOR shall disclose in Annex I and/or in the list of Sub-processors published on the Trust Center, prior to the start of the processing or any material change thereto:

a)the destination countries or international organizations;

b)the categories of Personal Data involved;

c)the purpose of the transfer;

d)the sub-processors involved, if any; and

e)the legal, technical and organizational safeguards adopted, pursuant to Applicable Law.

9.4In the absence of an international data transfer within the scope of the services, this Clause shall have no practical effect, and Annex I shall expressly indicate "not applicable".

Data Subject Rights

10.1The OPERATOR shall assist the CONTROLLER, within a reasonable time, through appropriate technical and organizational measures, in responding to Data Subject requests relating to the exercise of their rights under Applicable Law, such as confirmation of processing, access, correction, anonymization, deletion, portability and information about data sharing.

10.2Should the OPERATOR directly receive a Data Subject request related to Personal Data processed on behalf of the CONTROLLER, it shall forward it to the CONTROLLER within 5 (five) business days, unless a shorter period is necessary for the CONTROLLER to meet an applicable legal or regulatory deadline, refraining from responding directly to the Data Subject, unless otherwise instructed by the CONTROLLER.

Security Incident Notification

11.1The OPERATOR shall notify the CONTROLLER, within 24 (twenty-four) hours of becoming aware, of any Security Incident that may pose a relevant risk or harm to Data Subjects, providing, to the extent possible, information about the nature of the incident, the categories and approximate number of Data Subjects and records affected, the possible consequences, and the measures adopted or proposed to mitigate the risks.

Who the 24-hour deadline applies to. This DPA is entered into with corporate (enterprise) clients as an annex to the Main Agreement, and the 24-hour deadline in Clause 11.1 is a contractual obligation of Tess toward those clients. For other Platform users, incident communication follows the Privacy Notice and the timeframes set out in applicable law, without prejudice to the notifications to the ANPD and to data subjects required by the LGPD.

11.2The OPERATOR shall cooperate with the CONTROLLER to determine the causes of the Security Incident, adopt corrective measures and, where applicable, support any obligations to notify the ANPD and the affected Data Subjects.

11.3The Parties shall designate a specific communication channel for notifying Security Incidents. The OPERATOR's channel is listed in Annex I.

Audit and Right of Oversight

12.1The CONTROLLER may, upon prior written notice of at least 15 (fifteen) calendar days and subject to confidentiality and operational continuity safeguards for the OPERATOR, conduct audits or inspections aimed at verifying compliance with the obligations set out in this DPA, either directly or through an independent third party appointed by it, which may not be a competitor of the OPERATOR and must sign a confidentiality undertaking in the OPERATOR's favor. Audits shall be limited to a maximum frequency of once every 12 (twelve) months, shall be conducted on business days and during business hours, without interrupting the OPERATOR's operations, and shall be at the CONTROLLER's expense. This frequency limitation does not apply in the event of a confirmed Security Incident affecting the CONTROLLER or well-founded evidence of non-compliance with this DPA, in which case the audit may be conducted at any time, upon 5 (five) business days' notice.

12.2Alternatively, the OPERATOR may provide the CONTROLLER with independent audit reports, certifications or equivalent compliance questionnaires, which the CONTROLLER may accept in full or partial substitution for an on-site audit, at the CONTROLLER's discretion.

12.3The OPERATOR shall grant the CONTROLLER reasonable access to the information strictly necessary to verify compliance with this DPA, safeguarding confidential information belonging to third parties and to other clients of the OPERATOR.

12.4Should non-conformities be identified during an audit, the OPERATOR shall present the CONTROLLER with a corrective action plan within 15 (fifteen) calendar days of receiving the final report, with designated owners and deadlines for each measure.

Confidentiality

13.1The OPERATOR undertakes to maintain confidentiality over all Personal Data and other confidential information to which it has access under this DPA, and may not disclose, assign or use it for any purpose other than that set out in this DPA and in the Main Agreement.

13.2The confidentiality obligations set out in this Clause supplement, without prejudice to, and do not exclude, any specific confidentiality obligations already set out in the Main Agreement.

Term, Retention and Deletion of Data

14.1The OPERATOR's processing of Personal Data shall remain in effect throughout the term of the Main Agreement, automatically ending upon its termination, except where retention is legally or regulatorily required, or necessary for the regular exercise of rights in judicial, administrative or arbitration proceedings.

14.2Upon termination of the services, the OPERATOR shall, in accordance with the CONTROLLER's instructions, return or delete all Personal Data processed under the Main Agreement, including any copies, within the period indicated in Annex I or, in the absence of such indication, within 30 (thirty) days of the end of the services.

14.3Any backup copies containing Personal Data may be deleted according to the OPERATOR's regular backup retention cycle, provided that, during that period, the data remains protected and inaccessible for any purpose other than disaster recovery.

Liability and Indemnification

15.1Each Party shall be liable for the damages it causes to Data Subjects or to the other Party as a result of non-compliance with the obligations set out in Applicable Law or in this DPA, in proportion to its respective involvement in the processing that gave rise to the damage.

15.2Subject to the limit set out in Clause 15.3, the OPERATOR shall indemnify and hold the CONTROLLER harmless from any losses, damages, fines or administrative sanctions imposed by a competent authority that are proven to result from an act or omission of the OPERATOR or its Sub-processors in breach of this DPA or of Applicable Law.

15.3The OPERATOR's aggregate liability arising from or related to this DPA, combined with liability arising from the Main Agreement, is limited to the liability cap set out in the Main Agreement or, in the absence of a specific provision, to the total amount actually paid by the CONTROLLER to the OPERATOR in the 12 (twelve) months preceding the event giving rise to liability. This limitation does not apply, and the breaching Party shall be liable without limitation, in cases of willful misconduct, gross negligence, deliberate breach of confidentiality obligations and other legally non-waivable situations.

15.4Should the Parties adopt a specific liability limit for this DPA, such limit shall be indicated in Annex I or in a dedicated addendum to the Main Agreement.

15.5Neither Party shall be liable to the other for lost profits, loss of revenue, loss of business opportunity or indirect damages, except in legally non-waivable situations and for damages caused directly to Data Subjects.

General Provisions

16.1This DPA binds the Parties and their successors of any kind, and assignment of contractual position is prohibited without the other Party's prior consent, except for an assignment resulting from a corporate transaction that does not materially change the conditions of Personal Data processing.

16.2A Party's tolerance of any breach of an obligation set out in this DPA shall not constitute novation, waiver or amendment of the provisions set out herein.

16.3Should any provision of this DPA be deemed null, invalid or unenforceable, the remaining provisions shall remain in full force and effect, and the Parties shall replace the affected provision with another that, to the greatest extent possible, preserves the Parties' original intent.

16.4This DPA may be updated at any time, by means of a written addendum signed by both Parties, particularly due to changes in Applicable Law or in ANPD guidance.

Governing Jurisdiction

17.1The jurisdiction set out in the Main Agreement shall be elected to settle any disputes arising from this DPA. In the absence of a specific provision in the Main Agreement, the courts of the Capital District of the State of Rio de Janeiro/RJ are elected, with the Parties waiving any other jurisdiction, however privileged it may be.

Annex I — Detailed Description of the Processing

Description of services provided

Access to the Tess AI Platform, a multi-tenant SaaS solution that acts as a multimodal Generative AI orchestrator. The Platform routes the CONTROLLER's requests to third-party models (text/LLM, image, audio, transcription and video) through TESS's adaptive routing technology, without training its own models with the CONTROLLER's data.

Features: creation and execution of AI agents, templates and automated workflows; knowledge bases with vector indexing (RAG); conversation history and workspaces; integrations and access via REST API (API-first, available from the Business plan); authentication via SSO (Google, Azure AD, Okta) and MFA.

Ancillary services, when contracted: technical support, training, prompt engineering (creation of agents, templates and knowledge bases), allocation of a dedicated specialist, and development/customization of integrations and endpoints.

Role of the Operator

Under Art. 5, VII, of the LGPD, with respect to all Personal Data submitted, generated or stored by the CONTROLLER on the Platform. TESS processes such data exclusively in accordance with the CONTROLLER's documented and lawful instructions.

Independent controllership carve-out: TESS acts as an independent Controller, under its Privacy Policy, exclusively with respect to (i) registration and billing data related to the commercial relationship; and (ii) telemetry, log and security data strictly necessary for operation, protection, fraud prevention and compliance with legal obligations. Such processing does not cover the CONTROLLER's content.

Purpose of the processing

Performance of the object of the Main Agreement, namely: making available, operating, maintaining, monitoring and supporting the Tess AI Platform; receiving and processing prompts, files and content submitted by the CONTROLLER's authorized users to generate responses through AI models (inference); storing history, workspaces, agents and knowledge bases; recording logs for security, auditing, diagnostics and usage-based billing; and providing technical support.

Express prohibition: the CONTROLLER's Personal Data and content are NOT used to train, tune, fine-tune or improve artificial intelligence models, whether TESS's own or third-party models, nor for any purpose of TESS's own, pursuant to Clauses 2.3 and 8.3 of this DPA.

Categories of Data Subjects
  • CONTROLLER's authorized users: employees, administrators and other natural persons to whom the CONTROLLER grants access to the Platform.
  • Third parties of the CONTROLLER: customers, prospects, suppliers, candidates or any other data subjects whose Personal Data the CONTROLLER chooses to enter into prompts, files, knowledge bases or integrations — in which case the categories of data subjects are determined exclusively by the CONTROLLER.
Categories of personal data
  • Registration and account data: name, corporate email, job title, company, user identifier, credentials (stored hashed), roles and permissions.
  • Access and usage data: IP address, date and time of access, browser, operating system, device, authentication and activity logs, credit/token consumption metrics and execution history.
  • CONTROLLER's content: prompts, uploaded files and documents (text, image, audio, video), generated outputs, knowledge bases, embeddings and agent configurations — the content of which is unilaterally defined by the CONTROLLER.
  • Billing data: company name, tax ID (CNPJ), billing data and payment history. Full credit card data is collected and processed directly by the payment processors listed on the Trust Center, and is NOT stored by TESS.
Sensitive personal data involved

Not by default. The Tess AI Platform is not intended, marketed or configured for the processing of Sensitive Personal Data, and TESS does not deliberately request or collect it.

Should the CONTROLLER choose to enter Sensitive Personal Data into prompts, files or knowledge bases, it does so under its exclusive responsibility as Controller, and it is responsible for defining and documenting the applicable legal basis (Art. 11 of the LGPD), and may, if necessary, notify TESS in advance for a joint assessment of additional safeguards for such data.

Processing operations performed

Collection/receipt, access, storage, processing, inference by third-party AI models, transmission, indexing and vectorization (RAG), workflow orchestration, logging, security and performance monitoring, backups, technical support, export/portability and deletion.

Duration of the processing

Throughout the term of the Main Agreement, automatically ending upon its termination, subject to the return and deletion periods set out in Clause 14 and in this Annex I, as well as any legally or regulatorily required retention.

Frequency of the processing

Continuous. Processing occurs automatically and uninterruptedly whenever the CONTROLLER's authorized users use the Platform or its APIs.

Systems and environments involved

Tess AI Platform (web application and REST API), with logically segregated production, staging and development environments. The CONTROLLER's real personal data flows exclusively through production; staging and development environments use anonymized or fictitious data.

The infrastructure runs on public cloud, across two providers:

  • Google Cloud Platform (GCP) — primary provider: operates within a Virtual Private Cloud (VPC), with containers and serverless functions (Cloud Run), managed relational database (Cloud SQL), object storage (Cloud Storage), messaging (Pub/Sub), logging/monitoring and WAF (Cloud Armor).
  • Amazon Web Services (AWS) — secondary provider: compute, storage, networking, database, DNS, CDN, transactional email, backup, monitoring and secrets management services, used in running the application's services.

Complementary components: MongoDB Atlas (NoSQL database); vector database for knowledge bases; Temporal (workflow orchestration); Cloudflare and Google Cloud Armor (CDN, WAF, DDoS mitigation and DNS); Sentry and Google Cloud Logging/Monitoring (observability); and APIs of AI model providers listed on the Trust Center.

All infrastructure is managed as code (Terraform), with no use of removable media, on-premises servers, or external file repositories (Google Drive, OneDrive, Box) for client data. Isolation between clients through logical segregation.

Storage / processing location

United States of America, as the primary storage and processing region, on public cloud infrastructure of Google Cloud Platform (primary provider), Amazon Web Services (secondary provider) and MongoDB Atlas.

Brazil: processing of domestic payments and traffic served by edge network points of presence located in the country. Additionally, for corporate clients that require in-country data residency, TESS can make a fully private environment available, with dedicated storage and processing within Brazil, subject to a specific contract.

Cloudflare operates a multi-regional edge network (processing of traffic, headers and access logs at global points of presence, including Brazil).

AI model providers process prompts and outputs at inference time, mostly in the United States, as listed on the Trust Center.

International data transfer

Yes — bilaterally, between Brazil and the United States.

Brazil → United States flow: data submitted by authorized users in Brazil is transferred for hosting, storage, processing and inference by AI models in the primary region, in the United States.

United States → Brazil flow: generated outputs and stored content return to Brazil whenever accessed or displayed to the CONTROLLER's authorized users, and there is also processing within Brazilian territory for domestic payments and for traffic served by the edge network.

Destination countries: United States of America (primary region) and Brazil, plus the other locations of the sub-processors listed on the Trust Center, including processing on a multi-regional edge network.

Exception — data residency in Brazil: for corporate clients with a fully private environment, specifically contracted to keep storage and processing within Brazilian territory, the international transfer described in this clause does not apply, subject to the conditions agreed in a dedicated addendum.

Categories involved: all categories described in this Annex I.

Purpose: hosting, storage, processing, inference by AI models, security, observability, payments and technical support, strictly for performance of the Main Agreement.

Safeguards adopted (Arts. 33 to 36 of the LGPD): execution of a DPA and Standard Contractual Clauses (SCCs) with each sub-processor; enterprise/commercial API contracts with AI providers, expressly prohibiting the use of data for model training; encryption in transit (TLS 1.2 or higher) and at rest (AES-256); logical segregation per client; least-privilege access control; and verification that sub-processors maintain SOC 2 Type II, ISO/IEC 27001 attestations or equivalents. For CONTROLLERS subject to the GDPR, the European Commission's SCCs may be adopted.

TESS provides reasonable assistance to the CONTROLLER in preparing Transfer Impact Assessments (TIA).

Sub-processors involved

The complete and current list of Sub-processors — with purpose, location, categories of data processed and controls applicable to each — is published and kept up to date on the Tess Trust Center.

TESS will notify the CONTROLLER at least 15 (fifteen) calendar days in advance of any addition, replacement or removal of a Sub-processor, ensuring the right to a reasoned objection, pursuant to Clause 8.

Security incident communication channel

Primary email (monitored): dpo@tess.im

Secondary email: support@tess.im

Operator's privacy point of contact (DPO)

Data Protection Officer (DPO): DPO services are provided on behalf of TESS by Open CyberSecurity, a consultancy specialized in privacy and information security engaged to support compliance with the LGPD/GDPR.

Email: dpo@tess.im

Address: Avenida Oscar Niemeyer, No. 2,000, Bloco 1, Sala 401, Santo Cristo, Rio de Janeiro/RJ, ZIP Code 20220-297.

Deadline for return / deletion after contract termination

Export: Controller Data may be self-exported through the platform, or made available for export in a structured, open and machine-readable format (JSON, CSV or SQL dump), during a 20 (twenty) calendar-day transition period after the end of the contractual relationship, before any deletion.

Deletion: definitive and secure deletion in production environments within 30 (thirty) calendar days of the end of the services, upon issuance of a formal destruction certificate indicating date, scope (production, staging, backups and logs) and methodology used.

Backups: deleted according to TESS's regular backup retention cycle, remaining, until then, encrypted and inaccessible for any purpose other than disaster recovery, pursuant to Clause 14.3.

Residual retention: only for legal or regulatory obligations, the regular exercise of rights, or fraud prevention, always applying data minimization. Security logs are retained for a minimum of 30 (thirty) days.

Specific liability limit for this DPA

Defined between the Parties in the Main Agreement or in a dedicated addendum. In the absence of a specific agreement, the liability limit set out in the Main Agreement applies, except in cases of willful misconduct, gross negligence and other legally non-waivable exceptions set out in Clause 15.3.

Use of data to train AI models

Prohibited. No data entered into the Platform is used for machine learning, training, tuning or improvement of the base models, whether proprietary or third-party. Data travels strictly for inference of the contracted session.

TESS's contracts with AI model providers are entered into under an enterprise/commercial API model, with clauses prohibiting the use of data to improve the provider's own services and, where available, zero data retention.

TESS does not sell, license, assign, monetize, combine or enrich the Controller Data with data from other clients or from its own sources.

AI models and routing

The Platform does not have a proprietary model trained by TESS. Requests are routed to third-party models according to the user's choice or the Platform's adaptive routing. The providers actually engaged are listed on the Trust Center, and are engaged only when the CONTROLLER selects the corresponding model or feature.

Automated decisions: the Platform is a support tool and does not, on its own, make decisions with legal effects on Data Subjects. Any use of the outputs for such purposes is the CONTROLLER's exclusive decision and responsibility, and it is the CONTROLLER's responsibility to ensure human review pursuant to Art. 20 of the LGPD.

Controller's documented instructions

The following constitute documented instructions from the CONTROLLER: (i) the Main Agreement; (ii) this DPA and its Annexes; (iii) the settings, permissions and parameters defined by the CONTROLLER on the Platform; and (iv) additional instructions formalized in writing between the Parties.

TESS will promptly notify the CONTROLLER if it understands that a given instruction violates Applicable Law.

Assistance to data subjects, DPIA and RoPA

Data Subject Requests (DSAR): TESS provides assistance to the CONTROLLER within no more than 5 (five) business days, and does not respond directly to Data Subjects without the CONTROLLER's prior authorization, except where legally required otherwise (Clause 10).

DPIA: TESS provides reasonable assistance in preparing Data Protection Impact Assessments, risk assessments and any consultations with the ANPD, providing technical and organizational information about the processing.

RoPA: TESS maintains a record of processing operations carried out on behalf of the CONTROLLER, making it available upon request and NDA.

Service level and continuity

Contracted availability: 99% (ninety-nine percent), except for scheduled maintenance communicated at least 8 (eight) hours in advance and force majeure events.

Support: remote via chat and email, with a response by the next business day (9 a.m. to 6 p.m.), pursuant to the Main Agreement.

Third-party dependency: in the event of unavailability of AI model provider APIs, the corresponding feature may be temporarily suspended or routed to an alternative provider.

Annex II — Minimum Required Security Measures

The OPERATOR shall adopt, at a minimum, the mandatory minimum controls listed below. The additional controls shall be adopted whenever the processing involves access to critical systems, large volumes of data, Sensitive Personal Data or information technology services, as applicable, as indicated by the OPERATOR and validated by the CONTROLLER.

Mandatory minimum controls (applicable to every Operator)

  • Individualized access to systems, with sharing of credentials prohibited;
  • Use of strong passwords and, where technically available, multi-factor authentication (MFA);
  • Access control based on the principle of least privilege necessary to perform the activities;
  • Contractual confidentiality commitment and guidance for individuals with access to Personal Data;
  • Maintenance of up-to-date devices, operating systems and software;
  • Adoption of protection mechanisms against malicious software and unauthorized access;
  • Notification of Security Incidents to the CONTROLLER within 24 (twenty-four) hours of becoming aware;
  • Secure disposal or return of Personal Data upon termination of the processing, pursuant to Clause 14;
  • Appropriate management of Sub-processors, where applicable, pursuant to Clause 8.

Additional controls (depending on risk, criticality and applicability)

  • Encryption of Personal Data in transit and at rest;
  • Generation, retention and monitoring of system access and usage logs;
  • Periodic security testing, vulnerability scanning and patch management;
  • Use of threat detection and response solutions (EDR/SIEM or equivalent);
  • Business Continuity Plan (BCP) and Disaster Recovery Plan (DRP), with defined RTO and RPO;
  • Recognized certifications (e.g., ISO/IEC 27001, SOC 2 or equivalent), when available;
  • Independent information security audits;
  • Periodic access reviews and timely deactivation of unused access.

Controls actually adopted by Tess

Minimum controls actually adopted

All mandatory minimum controls are adopted by TESS, as detailed below:

  1. Individualized access: unique identifiers per user across all systems, with contractual and technical prohibition on sharing credentials.
  2. Passwords and MFA: the Platform requires a password with a minimum of 8 characters (uppercase, lowercase and number); multi-factor authentication (2FA/MFA) enabled for all TESS employees and for privileged access; support for SSO (Google, Azure AD, Okta), OAuth and OTP.
  3. Least privilege: role-based access control (RBAC), with a formal grant workflow, approval by a designated approver and dual approval for privileged access.
  4. Confidentiality: Code of Conduct and confidentiality clauses/terms signed by all employees; background checks upon hiring; security and privacy training during onboarding and on an ongoing basis.
  5. Updates: infrastructure 100% managed as code in the cloud (Terraform); patches monitored monthly, tested in staging and deployed via automation, with a hotfix protocol for critical emergencies.
  6. Protection against malicious software and unauthorized access: WAF (Cloudflare and Google Cloud Armor) with protection against the OWASP Top 10, SQLi and XSS; Super Bot Fight Mode; firewalls, IPS and VPN; internal network segmented within a VPC; rate limiting and input validation on the APIs.
  7. Incident notification to the CONTROLLER within 24 (twenty-four) hours of becoming aware, pursuant to Clause 11 and the Incident Response Plan.
  8. Secure disposal/return upon termination of the processing, pursuant to Clause 14.
  9. Sub-processor management formalized, with third-party risk assessment, DPA or equivalent terms, and data protection obligations equivalent to those of this DPA (Clause 8).
Additional controls actually adopted

Applicable and actually adopted:

  • Encryption: data in transit with TLS 1.2 or higher (HTTPS) and at rest with AES-256; use of RSA and AES; key management performed by the cloud provider under TESS's administration. Customer-managed keys (BYOK/CMEK) are not supported.
  • Logs: generation, centralization and monitoring of access and usage logs, with a minimum retention of 30 (thirty) days and access restricted to administrators; monitoring of privileged access and detection of anomalous behavior and configuration failures.
  • Vulnerability management: systemic scans twice a week; SLA for fixing critical vulnerabilities within 15 days, high within 30 days, and medium within 45 days; automated code review, dependency analysis and vulnerability remediation before promotion to production (UAT).
  • Detection and response: multi-layered cloud protection (WAF, Cloud Armor, network scans and logical VPC protections) and continuous observability (Sentry, Cloud Monitoring).
  • BCP/DRP: daily, encrypted backups, with the type (full, incremental or hybrid) defined by asset criticality, and restore tests conducted within the same annual cycle. RTO and RPO defined according to technical and commercial feasibility.
  • Independent security testing: pentests and adversarial Red Team exercises conducted by specialized partners, at least annually, with additional execution upon each significant launch of a new function or service.
  • Access review: periodic review at least annually; revocation of credentials, API tokens and integration keys within 48 (forty-eight) hours of termination or role change.
  • Governance: Information Security and Privacy Committee; appointed DPO; security and privacy policies published on the Trust Center and reviewed annually; formal risk management program with a risk register; whistleblowing channel via the DPO's email, with a non-retaliation policy.
  • Environment segregation: production, staging and development logically segregated; real client personal data is not used in non-production environments (only anonymized data).
Current certifications / seals

TESS is in the process of SOC 2 certification, expected to be completed in Q3 2026. Once issued, the report will be accessible directly on the Trust Center under NDA.

Sub-processors: the infrastructure and AI model providers listed on the Trust Center maintain SOC 2 Type II, ISO/IEC 27001 and/or PCI DSS attestations. The respective reports may be made available as supplementary evidence, upon request and NDA, subject to the providers' contractual restrictions.

Supplementary evidence available to the CONTROLLER upon request and NDA: pentest and Red Team exercise reports on the Tess AI Platform; security and privacy policies published on the Trust Center.

Date of last audit / security assessment

Annual review of security and privacy policies: April 2026.

Pentest and Red Team exercise by an independent partner: at least annually — last cycle in July 2026.

SOC 2 program: in progress, expected to be completed in Q3 2026.

Reportable security incidents in the last 12 months: 4 infrastructure incidents, as published on the Tess status page.

Contact and Data Protection Officer

Tess Tecnologia LTDA.

Operator Tess Tecnologia LTDA. — CNPJ 60.806.420/0001-91
Address Avenida Oscar Niemeyer, 2000, Bloco 1, Sala 401, Santo Cristo, Rio de Janeiro, RJ, 20220-297, Brazil
Data Protection Officer (DPO) DPO services are provided on behalf of Tess by Open CyberSecurity, a consultancy specialized in privacy and information security, engaged to support compliance with the LGPD/GDPR.
Incidents and DPA dpo@tess.im · support@tess.im
Sub-processors and evidence Trust Center · Status page