Legal · Data Processing Addendum

Data Processing Addendum

The processor-side commitments, published in full rather than gated behind a sales call. Countersigned copies available on request.

Last updated 24 July 2026 · Effective 24 July 2026

This DPA forms part of the Terms of Service or the Master Services Agreement between you (“Controller” or “Data Fiduciary”) and Turtle Techsai (“Processor”). It applies automatically where we process personal data on your behalf. Need a signed copy for your files? Write to legal@turtleaicoworker.com and we will countersign this document as published.

1. Definitions

“Data Protection Law” means all laws applicable to processing under this DPA, including India’s Digital Personal Data Protection Act, 2023 and rules made under it; Regulation (EU) 2016/679 (“GDPR”); the UK GDPR and Data Protection Act 2018; and applicable US state privacy laws.

“Customer Personal Data” means personal data contained in Customer Data that we process on your behalf. “Controller”, “Processor”, “Data Subject”, “Personal Data Breach” and “Processing” have the meanings given in the GDPR; the corresponding DPDP Act terms Data Fiduciary, Data Processor and Data Principal are read accordingly.

2. Roles

You are the Controller of Customer Personal Data. We are the Processor. You determine the purposes and means; we act only on your documented instructions. Where you are yourself a processor for another controller, we act as sub-processor and your instructions must be consistent with that controller’s.

We are an independent Controller only for the limited account, billing, security and usage data described in our Privacy Policy. That processing is not governed by this DPA.

3. Scope of processing (Annex I)

Subject matterProvision of the Turtle AI Coworker platform
DurationThe term of your agreement, plus the deletion window in clause 10
NatureStorage, retrieval, structuring, transmission, model inference, and execution of actions against systems you connect
PurposeOperating agents, teams and AI employees you configure; retrieval from your knowledge bases; maintaining an audit trail
Types of personal dataDetermined by you. Typically: names, business contact details, employment data, customer records, correspondence, and any personal data contained in documents you upload or systems you connect
Categories of data subjectDetermined by you. Typically: your employees, customers, prospects, candidates, suppliers and end users
Special category dataNot required by the Service. You are responsible for deciding whether to submit it and for having a lawful basis to do so
FrequencyContinuous, for the duration of the agreement

4. Our obligations

We will:

  • Process Customer Personal Data only on your documented instructions, which include your use of the Service and its configuration. Using the platform to run an agent is an instruction.
  • Tell you if we believe an instruction infringes Data Protection Law, and may pause that processing until it is resolved.
  • Ensure everyone authorised to process Customer Personal Data is bound by confidentiality.
  • Implement the technical and organisational measures in clause 6.
  • Assist you, taking into account the nature of processing, with data subject requests, data protection impact assessments, and prior consultation with a supervisory authority.
  • Never sell Customer Personal Data, share it for cross-context behavioural advertising, or use it for any purpose of our own.
  • Never use Customer Personal Data to train, fine-tune or improve machine learning models, and contractually bind every subprocessor to the same restriction. See the AI Addendum.

5. Your obligations

You will:

  • Have a lawful basis for the processing you instruct, and give the notices and obtain the consents Data Protection Law requires.
  • Configure the Service appropriately for the sensitivity of your data — including access roles, PII policies, approval gates and retention periods.
  • Not submit personal data you are not permitted to submit, and not instruct processing that would breach Data Protection Law.
  • Manage your users’ access, and remove access promptly when someone leaves.

6. Security measures (Annex II)

6.1 Encryption

  • TLS for all data in transit.
  • Encryption at rest across all data stores.
  • Integration OAuth tokens and custom-tool credentials additionally encrypted at the application layer, and only ever returned masked.

6.2 Access control

  • Role-based access control across four roles, resolved through a single role × action matrix applied identically on web, mobile and API.
  • Single sign-on via Google and Microsoft OAuth2; TOTP two-factor authentication with hashed backup codes.
  • Short-lived access tokens over rotating refresh tokens, with blacklist-after-rotation.
  • A hard cap on concurrent sessions per user, with sessions enumerable and revocable.
  • Production access limited to personnel who require it.

6.3 Tenancy isolation

Every record carries organisation and workspace scope, and every query is filtered server-side through a central tenancy layer with enforced organisation context. Isolation is not left to application code paths to remember.

6.4 Runtime governance

  • A policy engine evaluates every tool call before it executes; a blocked call is a no-op regardless of what the model decided.
  • Human approval gates for sensitive operations, with single-use approval grants.
  • Per-workspace PII policy — detection and masking, hashing, removal or flagging of emails, phone numbers, identifiers, card numbers, addresses and names.
  • Prompt-injection defences on untrusted content.
  • Budget caps and circuit breakers that halt runaway or misbehaving execution.

6.5 Audit

Every run and every tool call is recorded with sanitised inputs and outputs, operation type, PII flags, cost and timing, pinned to the immutable configuration version under which it executed. Secrets are redacted before storage. Records are exportable, with configurable retention and legal hold.

6.6 Resilience

  • Encrypted backups retained on a rolling 24 months cycle.
  • Application error and performance monitoring.
  • Deletion cascades across primary and derived stores, with derived stores reconciled within 24 hours.

Stated honestly: we do not currently hold SOC 2 or ISO 27001 certification, and a formal documented incident response plan is in development. We describe the controls we have built, not a certificate we have not earned. Current status is on the trust center.

7. Subprocessors

You give general authorisation for us to engage subprocessors. The current list — all 28 of them, named individually with purpose and location — is published at /legal/subprocessors.

We impose data protection obligations on each subprocessor no less protective than those in this DPA, and remain fully liable to you for their performance.

We give 30 days’ notice before a new subprocessor begins processing Customer Personal Data. You may object on reasonable, documented data-protection grounds within that period; if we cannot offer a reasonable alternative, you may terminate the affected part of the Service and receive a pro-rated refund of prepaid fees for the unused term.

8. Personal Data Breach

We will notify you without undue delay and in any event within 72 hours of becoming aware of a Personal Data Breach affecting Customer Personal Data. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, the measures taken or proposed, and a contact point.

Where we cannot provide all of that at once, we will provide it in phases without undue further delay. We will assist you in meeting your own notification obligations, and we will not delay telling you while we work out how bad it is.

9. Data subject rights

The Service gives you the ability to access, correct, export and delete Customer Personal Data yourself. Where you cannot fulfil a request through the Service, we will provide reasonable assistance at no additional charge for a reasonable volume of requests.

If a data subject contacts us directly about Customer Personal Data, we will not respond substantively — we will redirect them to you and tell you promptly, unless legally required to do otherwise.

10. Return and deletion

You can export Customer Data at any time during the term. On termination, we retain Customer Data for 30 days to allow export, then delete it from live systems. Integration credentials are deleted immediately on disconnection or termination.

Backups are immutable and expire on their own rolling cycle of up to 24 months. Deleted data is not restored to live systems, and is overwritten when the backup expires. We may retain data where a law requires it, for as long as that law requires, and it stays subject to this DPA while we hold it.

11. International transfers

The Service is hosted on Microsoft Azure, East US (Northern Virginia, United States), so processing takes place outside India and outside the EEA.

11.1 EEA and UK

For transfers of personal data from the EEA, the European Commission’s Standard Contractual Clauses (Decision 2021/914) are incorporated into this DPA by reference, with Module Two (Controller to Processor) applying, or Module Three (Processor to Processor) where you act as a processor. Clause 7 (docking) applies; under Clause 9, Option 2 (general written authorisation) applies with a 30-day notice period; the governing law and forum under Clauses 17 and 18 are those of Ireland. Annexes I and II are populated by clauses 3 and 6 of this DPA, and Annex III by the published subprocessor list.

For transfers from the UK, the ICO’s International Data Transfer Addendum is incorporated, with the Standard Contractual Clauses as its Approved Addendum.

11.2 India

Transfers under the DPDP Act are made only to countries not restricted by the Central Government. If a restriction is introduced that affects our hosting, we will tell you and work with you on an alternative.

11.3 Government access

We have received no government or law-enforcement request for Customer Personal Data. Should we receive one, we will challenge it where there are reasonable grounds, disclose only the minimum legally required, and notify you unless legally prohibited from doing so.

12. Audit

On reasonable written notice, not more than once in any twelve-month period, we will make available the information reasonably necessary to demonstrate compliance with this DPA, and respond to a reasonable security questionnaire. Our published completed security questionnaire answers most of it already.

Where you have a regulatory obligation requiring an on-site audit, we will discuss scope, timing and cost in good faith. Audits must not disrupt the Service or compromise another customer’s confidentiality.

13. Liability

Liability under this DPA is subject to the limitations and exclusions in the Terms of Service or the Master Services Agreement, except where Data Protection Law does not permit it.

14. Term and precedence

This DPA applies for as long as we process Customer Personal Data. Where it conflicts with the Terms of Service, this DPA prevails on data protection matters. Where the Standard Contractual Clauses conflict with this DPA, the Clauses prevail.

15. Contact

Data Protection Contact
Turtle Techsai
Nehru Nagar East, Bhilai, CG, India
legal@turtleaicoworker.com

Questions about this document? Write to legal@turtleaicoworker.com.