Tended.ai's Data Protection Framework Ensures Secure Handling of Sensitive Customer Information
In today's data-driven landscape, ensuring robust data protection and processing frameworks is crucial, particularly for companies handling sensitive information on behalf of their customers. This technical document outlines Tended.ai's comprehensive approach to data processing governance, security implementation, and compliance requirements. The company's framework addresses various aspects, from fundamental security protocols to handling sensitive data and maintaining compliance during contract termination. Additionally, the document covers technical implementation details, access controls, and the company's approach to audits and security certification. Understanding Tended's data protection measures is essential for both customers and stakeholders to ensure data security and compliance in their collaborative efforts.
Tended.ai processes personal data on behalf of its customers, with specific responsibilities outlined for both parties. The company handles data only for purposes defined in Appendix II of the Data Protection Agreement, with processing duration also specified in this document. All technical and organizational security measures required for data protection are detailed in Appendix III, including comprehensive protection against unauthorized access and breaches.
The company employs a multi-layered security framework that begins with robust user identification protocols, including unique identifiers and prohibition of shared accounts. Access is strictly controlled based on need-to-know principles, with regular reviews of access permissions in place. All security activities are logged for traceability, including user access journals and system activity logs. The company employs continuous security assessments, monitoring for vulnerabilities, and maintaining up-to-date security patches for all systems.
Tended.ai takes physical security seriously, implementing control measures for device encryption and establishing strict physical access controls. The company's technical infrastructure includes robust protection against common cyber threats, with automated detection systems for malicious code and comprehensive code review processes in place. All development occurs in production-only environments, with personal data prohibited from appearing in non-production settings.
The company maintains frequent data backups for high availability, with encryption applied both in transit and at rest. For the transit layer, TLS 1.2 or 1.3 is used alongside HTTPS encryption, while data at rest is protected with AES encryption standards. In the event of contract termination, the company must either delete all personal data at the customer's request or return it, maintaining compliance until completion of these actions.
The company implements multi-factor authentication, including single sign-on (SSO), and follows a need-to-know access principle, regularly reviewing access permissions. All security activities are logged for traceability, including detailed user access journals and comprehensive system activity logs.
Physical security controls include strict device encryption and robust asset management protocols. The technical infrastructure features comprehensive protection against common cyber threats, including automated detection systems for malicious code and rigorous code review processes. All development occurs in production-only environments, with personal data strictly prohibited from non-production settings.
Data availability is maintained through frequent backups encrypted both in transit and at rest. The company uses TLS 1.2 or 1.3 alongside HTTPS encryption for transit security, while data at rest is protected with AES encryption standards. In the event of contract termination, the company must either delete all personal data according to customer request or return it, maintaining compliance until completion of these actions.
Tended.ai implements strict controls for processing sensitive personal data, including genetic information, health records, and criminal conviction data. The company maintains these data types under heightened security protocols and restricted access controls.
According to the Data Protection Agreement, Tended.ai processes sensitive information only for specific purposes outlined in Appendix II, with strict adherence to customer instructions. Processing duration is determined by the contract terms, ensuring data retention aligns with legal and business requirements. The company maintains comprehensive security measures for all personal data, with additional safeguards in place for sensitive information.
Sensitive data handling follows stringent guidelines to prevent unauthorized access. The company employs multi-factor authentication, including single sign-on (SSO), and implements need-to-know access principles with regular reviews of access permissions. All security activities are meticulously logged, including detailed user access journals and comprehensive system activity logs.
The technical infrastructure includes robust protection mechanisms for sensitive information. Tended.ai maintains continuous security assessments, monitoring for vulnerabilities, and applying up-to-date security patches across all systems. The company's development processes occur exclusively in production environments, with strict prohibitions against personal data appearing in non-production settings.
Data protection protocols include frequent backups with encryption both in transit and at rest. The company utilizes TLS 1.2 or 1.3 alongside HTTPS encryption for secure data transmission, while implementing AES encryption standards for data storage. In the event of contract termination, Tended.ai must either delete all personal data according to customer request or return it, maintaining compliance until completion of these actions.
Customer responsibility for ensuring proper data submission is underscored, with Tended.ai taking prompt action to address any customer inquiries regarding data processing. The company permits audits of personal data processing activities by either the customer or an independent auditor, requiring at least 14 business days' notice. Relevant certifications held by Tended.ai may influence audit decisions, ensuring ongoing compliance with data protection standards.
Upon termination of the contract, Tended.ai must delete or return all personal data as per the customer's instructions. The company maintains compliance with data protection standards until the completion of these actions, ensuring all data handling aligns with legal and business requirements.
Customers have the right to conduct audits of processing activities under these clauses, requiring at least 14 business days' notice. Independent auditors may also perform reviews based on relevant certifications held by Tended.ai, which can influence audit decisions. The company responds promptly to customer inquiries about data processing and demonstrates compliance through documented procedures and certifications.
The technical and organizational security framework includes continuous security assessments and monitoring for vulnerabilities. All systems employ security measures certified under ISO 27011 (pending certification) for continuous cybersecurity. The company maintains strict physical access controls and device encryption to protect against unauthorized access, with comprehensive security protocols in place for all data processing activities.
The platform offers three primary pricing tiers: Starter ($99/month), Pro ($495/month), and Custom (special enterprise rates). Each tier includes specific features and support levels.
The Starter Plan enables two users to manage 20 sources, with 100 answers included per month and five project imports. All plans operate with no setup fees, providing basic support through email during business hours. Additional resources are available through a knowledge base and video tutorials. A free trial for the Starter Plan is available without requiring a credit card.
The Pro Plan scales up to five users, managing 100 sources with 1,000 answers included monthly and five project imports. This tier adds business-hour support and SAML Single Sign-On (SSO) capabilities.
All plans offer seamless data source integration, AI-driven response generation, and collaborative tools for team management. Users can import documents in various formats (docx, pdf, excel) and receive fully automated responses to RFP questions.
In the event of contract termination, Tended.ai complies with specific data handling requirements. The company must either delete all personal data at the customer's request or return it, maintaining compliance until completion of these actions. Subprocessor security follows Standard Contractual Clauses with Module Two application, under the governance of the EU supervisory authority in the customer's established Member State, with the governing law and choice of forum determined by that same state.
All technical and organizational security measures are detailed in Appendix III of the Data Protection Agreement. These include robust encryption protocols (HTTPS in transit, TLS 1.2 or 1.3, AES at rest), comprehensive security event logging, and continuous security assessments certified under ISO 27011 (pending certification). The company implements strict physical security controls and device encryption to protect against unauthorized access.