Skip to content
In development

Tenvey is not running yet. Every number on this site comes from one example website, not from a live service. What that means

Tenvey

Legal

Data processing agreement

Tenvey processes personal data on your instructions when it monitors your websites. This document sets out what that covers, who else is involved, and what we are obliged to do.

Last updated 12 August 2026

Tenvey is a demo product and this document is a template, not legal advice. No live service is processing anyone's data behind it — read it as an example of how a website monitoring product would describe its obligations, and have a lawyer write the version you publish.

1. The two roles

You are the controller. You decide which websites are monitored, which paths are excluded and who in your organisation sees the results. Tenvey is the processor and acts on your instructions.

For the data Tenvey needs to run its own business — your account, your invoices, the logs of your visits to the dashboard — Tenvey is itself the controller, and the privacy policy governs that. This agreement forms part of the terms of service and applies from the day your account is created.

2. Subject matter, duration and purpose

  • Subject matter — continuous monitoring of the websites you add, and the storage of what those checks return.
  • Duration — the term of your subscription, plus the retention periods in the privacy policy.
  • Nature of the processing — fetching public pages, recording responses and headers, storing snapshots, deriving issues, sending alerts, and giving you access to all of it.
  • Purpose — telling you what is wrong with your website and what to do about it. Nothing else.

3. Whose data, and what kind

Two groups, and they are very different in character.

  • Your team — the people you invite. Name, work email address, hashed credentials, role, IP address and timestamps in server logs, and the actions they take in the dashboard.
  • People whose data appears on your public pages — staff named on a team page, an author byline, a comment left under an article. Tenvey stores an HTML snapshot and a screenshot of each checked page, so whatever is published there is captured as part of the page.

Tenvey does not ask for special categories of personal data under Article 9 and has no use for them. If pages within the scope you set publish such data, that is your instruction and your assessment to make — exclude those paths in the site's settings if you would rather they were never fetched. Excluded paths are not requested at all.

4. Instructions

Tenvey processes personal data only on your documented instructions: the sites and paths you configure, the alerts you set up, this agreement and the terms of service. Where the law obliges us to process data otherwise, we tell you before we do, unless the same law forbids that.

If we believe an instruction breaches the GDPR or another data protection law, we say so and may pause that part of the processing until it is resolved. We will not quietly comply.

5. Confidentiality

Everyone at Tenvey with access to your data is bound by confidentiality obligations that survive the end of their engagement, and access is granted per role and on need. Your data is never used to build features for other customers.

6. Security measures

These are the measures in place at the date above. They may be improved, never weakened.

  • TLS 1.3 in transit; AES-256 at rest for databases, snapshots and backups.
  • Multi-factor authentication for every staff account, single sign-on with hardware keys for production.
  • Role-based access on least privilege; every production access is tied to a named ticket and logged, and logs are retained for 12 months.
  • Workspace isolation enforced in the data layer, so a query cannot cross from one customer to another.
  • Encrypted daily backups with restores tested quarterly; a documented recovery objective of four hours.
  • Dependency and vulnerability scanning on every build, plus an annual penetration test by an outside firm. The most recent report summary is available under NDA.
  • A written incident response procedure with named owners and a rehearsal twice a year.

7. Subprocessors

You give general authorisation for the subprocessors below. Each has a written agreement with the same obligations we owe you, and Tenvey remains fully liable for their performance.

  • Cloud hosting and storage — Frankfurt, EU. Databases, snapshots, backups and the application itself.
  • Regional check runners — Frankfurt, Washington and Singapore. They send requests to your sites and return the timing, headers and response body to EU storage. They keep nothing.
  • Transactional email — EU. Alerts, reports and account email.
  • Payment processing — EU and United States. Billing details only; no monitoring data.
  • Error tracking — EU. Stack traces and request metadata, with bodies and headers scrubbed before they leave the application.

We announce a new or replacement subprocessor at least 30 days before it starts processing, by email to account owners. You may object in writing within those 30 days on reasonable data protection grounds; if we cannot offer an alternative, you may terminate the affected part of the service and receive a refund for the unused period.

8. Requests from data subjects

The dashboard lets you find, export and delete what belongs to a site or a person, so most requests need no involvement from us. If someone contacts Tenvey directly about data we hold for you, we do not answer on your behalf: we tell them we are the processor and forward the request to you without undue delay. Where you still need help, we assist you, and we charge for it only if the effort is substantial and we agree it with you in advance.

9. Personal data breaches

We notify you without undue delay and no later than 48 hours after becoming aware of a breach affecting your data — early enough for your own 72-hour deadline to be met. The notification describes what happened, which categories of data and roughly how many records are affected, the likely consequences, what we have already done and what we recommend you do. If the facts are still incomplete we send what we have and follow up rather than wait.

10. Assessments and prior consultation

We give you the information you reasonably need for a data protection impact assessment or a consultation with a supervisory authority, to the extent it concerns the processing described here and is not available to you already.

11. Audits

We keep records of processing and make them available to you, along with our current security documentation and the latest penetration test summary. That normally answers an audit. Beyond it, you may audit once in any 12-month period — or after a breach — on 30 days' written notice, at your cost, under NDA, without access to other customers' data, and at times that do not put the service at risk.

12. Deletion and return

When the subscription ends you can export everything for 30 days. After that, or immediately if you ask, we delete your data from production within 24 hours; encrypted backups expire within 35 days. We keep only what the law requires us to keep, such as invoices, and that stays under the same protection until it too expires.

13. Transfers outside the EU

Storage is in the European Union. Two of the check regions — Washington and Singapore — sit outside it, as does part of the payment processing. Those transfers use the European Commission's 2021 standard contractual clauses, module three where the recipient is a processor, together with a transfer impact assessment for each provider and the UK addendum where UK data is involved. Supplementary measures include encryption in transit, retention of nothing at the runner, and a published policy of challenging any government access request we are permitted to challenge.

14. Order of precedence

If this agreement conflicts with the terms of service, this agreement wins for anything concerning personal data. If it conflicts with the standard contractual clauses, the clauses win.

Contact

Tenvey is not required to appoint a data protection officer, but privacy@tenvey.com reaches the person responsible for this agreement. General enquiries: the contact page. See also the privacy policy and the terms of service.