Data Processing Agreement

Data Processing Agreement

Last updated: July 22, 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Use (or other similarly titled written or electronic agreement addressing the same subject matter) ("Agreement") between Customer (as defined in the Agreement) and Theneo Inc. under which the Processor provides the Controller with the software and services (the "Services"). The Controller and the Processor are individually referred to as a "Party" and collectively as the "Parties".

The Parties seek to implement this DPA to comply with the requirements of EU GDPR (defined hereunder) in relation to Processor's processing of Personal Data (as defined under the EU GDPR) as part of its obligations under the Agreement. This DPA applies to Processor's processing of Personal Data provided by the Controller as part of Processor's obligations under the Agreement. Except as modified below, the terms of the Agreement remain in full force and effect.

1. Definitions

Terms not otherwise defined herein shall have the meaning given to them in the EU GDPR or the Agreement. The following terms shall have the corresponding meanings assigned to them below:

2. Purpose of this Agreement

This DPA sets out various obligations of the Processor in relation to the Processing of Personal Data and shall be limited to the Processor's obligations under the Agreement. If there is a conflict between the provisions of the Agreement and this DPA, the provisions of this DPA shall prevail solely with respect to the Processing of Personal Data; in all other respects, the provisions of the Agreement (including its limitations of liability and payment terms) shall prevail.

3. Categories of Personal Data and Data Subjects

The Controller authorizes the Processor to process the Personal Data to the extent determined and regulated by the Controller. The current nature of the Personal Data is specified in Annex I to this DPA.

4. Purpose of Processing

The objective of Processing of Personal Data by the Processor shall be limited to the Processor's provision of the Services to the Controller and/or its Client, pursuant to the Agreement.

5. Duration of Processing

The Processor will Process Personal Data for the duration of the Agreement, unless otherwise agreed upon in writing by the Controller.

6. Data Controller's Obligations

  1. 6.1. The Data Controller shall warrant that it has all necessary rights to provide the Personal Data to the Data Processor for the Processing to be performed in relation to the agreed services. To the extent required by Data Privacy Laws, Data Controller is responsible for ensuring that it provides such Personal Data to Data Processor based on an appropriate legal basis allowing lawful processing activities, including any necessary Data Subject consents, and for maintaining a record of such consents. Should such consent be revoked by the Data Subject, the Data Controller is responsible for communicating the fact of such revocation to the Data Processor.
  2. 6.2. The Data Controller shall provide all natural persons from whom it collects Personal Data with the relevant privacy notice.
  3. 6.3. The Data Controller shall request the Data Processor to purge Personal Data when required by the Data Controller or any Data Subject from whom it collects Personal Data, unless the Data Processor is otherwise required to retain the Personal Data by applicable law.
  4. 6.4. The Data Controller shall immediately advise the Data Processor in writing if it receives or learns of any: (a) complaint or allegation indicating a violation of Data Privacy Laws regarding Personal Data; (b) request from one or more individuals seeking to access, correct, or delete Personal Data; (c) inquiry or complaint from one or more individuals relating to the collection, processing, use, or transfer of Personal Data; or (d) regulatory request, search warrant, or other legal, regulatory, administrative, or governmental process seeking Personal Data.

7. Data Processor's Obligations

8. Data Secrecy

9. Audit Rights

10. Mechanism of Data Transfers

Any Data Transfer for the purpose of Processing by the Processor in a country outside the European Economic Area (the "EEA") that has not received an adequacy decision shall take place in accordance with the Standard Contractual Clauses incorporated under Section 1.4 of this DPA, or such other valid transfer mechanism recognized under the EU GDPR or UK GDPR as may apply.

11. Sub-processors

11.1. The Controller acknowledges and agrees that the Processor may engage third-party Sub-processor(s) in connection with the performance of the Services, provided such Sub-processor(s) take technical and organizational measures to ensure the confidentiality of Personal Data shared with them. The current Sub-processors engaged by the Processor and approved by the Controller are listed in Annex III. In accordance with Article 28(4) of the GDPR, the Processor remains liable to the Controller for any failure of a Sub-processor to fulfil its data protection obligations under this DPA in connection with the performance of the Services.

11.2. The Processor will update the Sub-processor list in Annex III as published on its website at least fifteen (15) days before any new Sub-processor begins Processing Personal Data. If the Controller does not object within that period, the new Sub-processor shall be deemed approved. If the Controller has a concern that a Sub-processor's Processing of Personal Data is reasonably likely to cause the Controller to breach its data protection obligations under the GDPR, the Controller may object, and the Parties shall confer in good faith to address such concern.

11.3. AI Service Providers. To provide AI-powered functionality, the Processor may engage one or more AI service providers as authorized Sub-processors. These providers process Personal Data contained in Customer Content solely on the Processor's instructions and only for the purpose of providing the requested Services, subject to contractual confidentiality, security, and data protection obligations. The Processor may add, remove, or replace AI service providers in accordance with Section 11.2; current AI Sub-processors are identified in Annex III. The Processor's agreements with such providers do not permit the use of Customer Content to train publicly available or general-purpose AI models. For clarity, Theneo Inc.'s use of publicly accessible documentation on Theneo to improve its own models is governed by the Agreement and the Privacy Policy.

12. Personal Data Breach Notification

12.1. The Processor shall maintain defined procedures in case of a Personal Data Breach (as defined under the GDPR) and shall without undue delay notify the Controller if it becomes aware of any Personal Data Breach, unless such breach is unlikely to result in a risk to the rights and freedoms of natural persons.

12.2. Taking into account the nature of the Processing and the information available to the Processor, the Processor shall provide the Controller with reasonable assistance to comply with notification obligations to the Supervisory Authority and/or Data Subjects, to identify the cause of the breach, and to take commercially reasonable steps to mitigate and remedy it. Where a Personal Data Breach did not result from the Processor's breach of this DPA, the Processor may charge reasonable fees for such assistance.

12.3. The Processor's notification of or response to a Personal Data Breach under this DPA will not be construed as an acknowledgement of any fault or liability.

13. Return and Deletion of Personal Data

13.1. Upon termination or expiry of the Agreement, or upon cessation of the Processor's Services under the Agreement, the Controller may request the return and/or deletion of the Personal Data. Following receipt of such request, the Processor shall return the Personal Data in a commonly used format (or the current stored format, at the Controller's discretion) and/or delete the Personal Data from its active systems within thirty (30) days of the request at the latest, unless and to the extent retention is required by applicable law. Personal Data remaining in encrypted backups following such deletion is isolated from any further Processing and is deleted in the ordinary course of the Processor's rolling backup cycle.

13.2. Absent such a request, the Processor shall delete Personal Data in accordance with its standard data retention practices following the end of the Agreement, and in any event shall not retain Personal Data longer than permitted under applicable law.

14. Technical and Organizational Measures

Having regard to the state of technological development and the cost of implementation, the Processor will take appropriate technical and organizational measures against the unauthorized or unlawful processing of Personal Data and against accidental loss, destruction, or damage, appropriate to (a) the harm that might result and (b) the nature of the data to be protected, including the measures stated in Annex II.

15. Liability

Each Party's liability, taken together in the aggregate, arising out of or relating to this DPA and the Standard Contractual Clauses where applicable, whether in contract, tort, or under any other theory of liability, is subject to the limitations and exclusions of liability set forth in the Agreement, and any reference in such provisions to the liability of a Party means the aggregate liability of that Party under the Agreement and this DPA together. Nothing in this Section limits either Party's liability to Data Subjects under the Standard Contractual Clauses or restricts any rights of Data Subjects under applicable data protection law.

ANNEX I

A. List of Parties

Data exporter: Customer — name, address, contact person, and signature/date as set forth in the relevant Order Form or account registration. Activities: recipient of the Services provided by Theneo Inc. in accordance with the Agreement. Role: Controller.

Data importer: Theneo Inc., 7511 Greenwood Ave North, Seattle, WA 98103, United States. Contact: Privacy Contact, hello@theneo.io. Activities: provision of the Services to the Customer in accordance with the Agreement. Role: Processor.

B. Description of Transfer

Categories of data subjects whose personal data is transferred: Customer's authorized users of the Services (workspace members, including Admins, Editors, Guests, and Billing Managers). Documentation-portal readers: individuals who access documentation or developer hubs published by the Customer, where the Customer has enabled reader accounts, access controls, or similar features involving the collection of such individuals' details.

Categories of personal data transferred:

C. Competent Supervisory Authority

The competent supervisory authority shall be determined in accordance with Clause 13 of the Standard Contractual Clauses, based on the location and supervisory authority of the data exporter (Customer).

ANNEX II

Technical and Organisational Measures

Description of the technical and organisational measures implemented by Theneo Inc. as data processor/data importer to ensure an appropriate level of security, taking into account the nature, scope, context, and purposes of the processing and the risks to natural persons.

ANNEX III

List of Sub-processors

The Controller has authorized the use of the following Sub-processors. Each processes Personal Data only for the purpose described and only to the extent necessary to provide the Services.

Sub-Processor Purpose of Processing Privacy Policy
Amazon Web Services (AWS) Cloud infrastructure, hosting, and file storage (including S3) aws.amazon.com/privacy
MongoDB Atlas Managed database hosting mongodb.com/legal/privacy
Google Authentication (Google OAuth) and website analytics (Google Analytics / Tag Manager) policies.google.com/privacy
OpenAI AI Provider openai.com/policies/privacy-policy
Anthropic AI Provider anthropic.com/legal/privacy
Stripe Payment processing (customer and subscription identifiers; full payment data is processed by Stripe directly) stripe.com/privacy
GitHub Repository synchronization and OAuth sign-in docs.github.com — Privacy Statement
Atlassian (Jira) Support and bug tracking, including "Report a Problem" submissions and attachments atlassian.com/legal/privacy-policy
Typeform Migration request form submissions typeform.com/privacy-policy
Slack Customer support and collaboration channels slack.com — Privacy Policy
Pylon Customer support platform (support conversations and contact details) usepylon.com/privacy
Rocketlane Customer onboarding and implementation management (customer user contact details, onboarding tasks and activity) rocketlane.com/privacy-policy
Hotjar In-product and website session analytics and user activity tracking (session recordings, user feedback) hotjar.com/legal/policies/privacy
Mandrill (Mailchimp Transactional) Transactional and service email delivery to customers and users (verification, invitations, notifications) mailchimp.com/legal/privacy

Scope of Annex III. Annex III lists only third parties that Process Customer Personal Data on the Controller's behalf in the provision of the Services. Tools used by Theneo Inc. solely for its own internal business operations (including CRM, marketing, accounting, and compliance functions) are not Sub-processors; where such tools process personal data, Theneo Inc. acts as controller, as described in its Privacy Policy.