Data Processing Addendum

Effective 26 August 2026. Last updated 26 August 2026. This Data Processing Addendum forms part of the agreement between Tasirio and its customers and applies wherever Tasirio processes personal data on a customer's behalf.

In short, for a reviewer in a hurry

1. The parties

RoleParty
Controller ("Customer", "you")The customer organisation identified on the order form or other written arrangement with Tasirio.
Processor ("Tasirio", "we")Smartware Holdings, Inc., a Wyoming corporation, doing business as "Tasirio", of 4637 Indian Rock Drive, Fort Worth, TX 76244, United States.

Effective date: 26 August 2026, or the date your subscription starts if later. Governing agreement: the Tasirio Terms of Service together with your order form and any agreement the parties have signed (the "Agreement").

2. Definitions and how this DPA fits with the Agreement

This DPA forms part of the Agreement. If this DPA and the Agreement conflict about the processing of personal data, this DPA prevails. Where the Standard Contractual Clauses apply, they prevail over both to the extent of a conflict. Everything else in the Agreement stands.

This DPA creates no service-level, uptime or availability obligation. See section 17.

If you expect the usual annexes: Annex I (details of processing) is sections 4 and 5. Annex II (technical and organisational measures) is section 8. Annex III (sub-processors) is section 9.

3. Roles of the parties

4. Subject matter, duration, nature and purpose

ItemDetail
Subject matterTasirio's provision of the Tasirio AI-accountability and data-governance service under the Agreement.
DurationFor as long as Tasirio processes personal data for you under the Agreement, then the deletion terms in section 13.
Nature of the processingOutbound, read-only collection of configuration and permission metadata from systems you already operate, using a revocable credential you create. Storage, structuring, analysis and presentation of the results. Onward transmission only to destinations you configure, including the creation and updating of records in a ticketing system you nominate.
PurposeTo show you what your AI assistants and identities can reach, produce findings and remediation steps, and generate evidence exports — for your own security, governance and compliance work.
Type of personal dataSection 5.1.
Categories of data subjectSection 5.2.
FrequencyEvery tenant is placed on a daily automated pass, enabled by default. That pass re-runs analysis over data already held, updates findings and may raise alerts. Re-reading your connected systems on that schedule is a separate setting and is off by default. Unless you enable it, or a person runs a scan, Tasirio reads your systems on request. If you have linked findings to a ticketing system, the daily pass also reads ticket status from that system.

5. What Tasirio actually reads

Written from the connector code, not from a product description. This is the section a security reviewer should check hardest.

5.1 Categories of personal data

CategoryWhat it contains
Directory identity recordsDisplay name, work email or user principal name, account enabled or disabled, internal-or-guest user type, last sign-in timestamp.
Group and role membershipWhich groups a person belongs to, including transitive membership; who owns a group; directory and security roles held; eligibility for privileged roles.
Sharing and access grantsWhich site, drive, folder or item a person or link can reach, and at what level. Item and site names. Never the contents of any item.
Application and consent recordsApp registrations and service principals, their owners, the permissions granted to them, who consented, federated identity trusts.
Policy and app inventoryConditional-access and authorisation policy settings, sensitivity-label catalogue, Teams channel and installed-app inventory, mobile-app-protection policy settings and managed-app inventory. Policy settings and inventories, not device or user records.
Supplier and payment master data (accounts-payable connector only)Supplier name, supplier ID, company and tax or registration number, address, telephone, contact email, and a bank-account identifier. See 5.4.
Network usage records (shadow-AI agent only, if you deploy it)A device IP address and the AI service hostname it resolved, aggregated to device, service and count.
Your Tasirio users and alert recipientsName, work email, role, sign-in records; and for recipients you nominate, name, work email and any mobile number you enter.
FindingsStatements about your configuration naming the affected resource and the accounts implicated — for example "this site is shared with everyone in the organisation", "these accounts hold a privileged role".

5.2 Categories of data subject

5.3 What Tasirio does not read

Tasirio does not read the contents of documents, files, mailboxes, chat or Teams messages, calendar entries, notebooks or attachments. It does not download file bytes.

On Microsoft 365 — the widest-reaching connector — this is enforced in code. Every request passes a single choke point that pins the HTTP method to GET; refuses any host other than Microsoft Graph; rejects a fixed list of content paths (message, mail folder, calendar, chat, contacts, attachment, photo, thumbnail, version, notebook and raw-value paths); and then requires the remaining path to match an explicit allowlist of permission and inventory endpoints. A request outside that list fails before it is sent. The authentication layer refuses outright any permission whose name matches write, manage, send, delete or full-control patterns, except one you have separately acknowledged under 8.4, and refuses to run a sync if the token it receives carries anything outside the expected read-only set.

Stated so it is not over-read: that allowlist-and-denylist mechanism is the Microsoft 365 connector's. Other connectors reach their vendors through their own read paths and read-only credentials. The commitment not to read content applies to all of them; the structural mechanism does not.

5.4 Two connectors read business record fields, and this is deliberate

5.5 Special categories of personal data

Tasirio does not ask for, and no check requires, special-category data under GDPR Article 9. Directory fields are whatever your systems hold, so a name, job title or group name you have chosen could in principle imply such a category. Tasirio does not classify or use any field on that basis. You warrant that you will not instruct Tasirio to process special-category data, and you will not place such data in fields Tasirio reads.

6. Instructions, and your responsibilities as controller

6.1 Documented instructions

Tasirio processes personal data only on your documented instructions. Your instructions are: this DPA, the Agreement, and what you configure in the Service — which systems you connect, which credential you supply, which permissions you approve, when scans run, and where you send exports, tickets and alerts.

Tasirio will tell you if, in its view, an instruction breaches Data Protection Law. That is a heads-up, not legal advice.

6.2 Your responsibilities

6.3 What Tasirio does not do with your data — and the one carve-out

Tasirio will not process Customer Data for its own purposes, will not sell or share it, and will not use it to train any machine-learning model.

Carve-out, stated rather than assumed. Tasirio derives and retains aggregate, de-identified statistics about finding activity: finding type, connector, severity, and when an issue was first seen and resolved. That record contains no resource name, no description, no account and no user — those columns do not exist in it — and issues are linked over time by a one-way keyed identifier. Tasirio uses it for product analytics, for peer benchmarking (which returns a figure only where the cohort contains at least five organisations other than you), and for aggregate statistics it publishes about the product which never identify a customer. This carve-out is the whole of it; nothing else in the Service produces data Tasirio uses for its own purposes.

6.4 AI processing

The Service offers optional AI features that explain findings and draft remediation steps. Section 9.2 sets out exactly what reaches the model provider, and prompts are redacted before they are sent. Customer content is not used to train any model. That no-training position rests on the model provider's contractual terms, which Tasirio passes through to you; it is not something Tasirio's code can prove.

7. Confidentiality

Tasirio treats Customer Data as confidential. Access to production systems and to Customer Data is limited to named individuals who need it to run or support the Service, and they are bound by confidentiality obligations that survive their engagement.

Tasirio is a small company and does not operate a large staffed operations team. We say so rather than implying otherwise.

8. Security measures — Annex II

Everything in this section exists in code or in the running environment. Where a control has a boundary, the boundary is stated. A measure that is planned is not listed.

8.1 Tenant isolation

8.2 Encryption

8.3 Credentials

8.4 Read-only operation, and where Tasirio does write

8.5 Activity log

8.6 Network and access controls

8.7 Backups and the ability to restore

8.8 Change control

Deployments are manual and versioned. A pre-flight check aborts the deployment on a credential-hygiene violation or a dependency-vulnerability regression. Database changes are versioned migrations. Source is held in a private repository; the sample data committed alongside the code is shape-only — field names, types and count buckets — and an automated check in the build rejects it if it carries identifiers, quoted values or token-shaped strings.

8.9 What Tasirio does not claim

9. Sub-processors — Annex III

You give general authorisation for Tasirio to engage the sub-processors below. The current list is also published at our sub-processors page.

9.1 Part A — may process Customer Data

Sub-processorPurposeWhat it receivesLocation
Microsoft Azure (Microsoft Corporation)All hosting — compute, database, key vault, evidence storage, application logsEverything Tasirio holds: connector settings, permission metadata, findings, evidence packs, the activity log, the credential vault. Finding detail is encrypted by the application before it is written.United States (East US 2)
Brevo (Sendinblue SAS)Transactional email and text messagesRecipient names and addresses; alert digests containing finding severity, title and the affected resource name; report headlines and share links. A text message carries a headline only — never a resource name or finding title. No evidence pack is ever attached to an email.European Union
Microsoft Azure OpenAIOptional in-product AI features: explaining findings and drafting remediation stepsSee 9.2. Prompts are redacted before they are sent. Runs on Tasirio’s own Azure OpenAI resource in East US 2, within the same Azure subscription as the rest of the service. Microsoft does not use content submitted to Azure OpenAI to train its models.United States (East US 2)

9.2 What reaches the AI model, precisely

This DPA names the provider, not the model version. A model name written into a contract is a hand-typed copy of a deployed value with no mechanism to stay true.

9.3 Part B — process only Tasirio's own business records, never Customer Data

ProviderPurposeWhat it receivesLocation
Intuit (QuickBooks Online)Invoicing — Tasirio's own business recordsYour legal name, billing email and address, payment terms, and invoice line descriptions which name the connectors you have licensed. That last item tells Intuit which of your systems Tasirio is connected to, which is why it is disclosed here rather than left implicit — it is a system inventory, and a security reviewer will treat it as one.United States
hCaptcha (Intuition Machines, Inc.)Bot protection on Tasirio's public formsThe challenge token and the website visitor's IP address. Website visitors to tasirio.com only — nothing from your Tasirio account and no Customer Data.United States

9.4 Part C — not sub-processors

9.5 Sub-processor obligations, notice and objection

10. International transfers

All Customer Data at rest is held in Microsoft Azure, East US 2, in the United States. Tasirio operates a single region and offers no other data-residency option. There is no EU, UK or Canadian hosting.

Two qualifications, stated because a reviewer will find them anyway:

Transfer mechanism. Where you are established in the EEA, the UK or Switzerland, or are otherwise subject to a law restricting transfers, the parties incorporate the European Commission's Standard Contractual Clauses (Decision 2021/914), Module Two (controller to processor), with the annexes populated by sections 5, 8 and 9 of this DPA. The options are selected as follows:

Tasirio is not certified under the EU–US Data Privacy Framework and does not rely on it.

Tasirio will tell you if it receives a legally binding request from a public authority for Customer Data, unless legally prohibited, and will challenge over-broad requests.

11. Helping you answer data-subject requests

Tasirio has no direct relationship with the people whose data it processes for you. If a request reaches Tasirio it will be redirected to you and not answered directly.

Tasirio will help you by, on your documented instruction: searching for what is held about an identified person; exporting it; and correcting or deleting it, subject to section 13. Tasirio will respond within 10 business days, and faster where your own statutory deadline requires it. This assistance is included in the fees you already pay; there is no separate charge for it.

One practical point: nearly everything Tasirio holds about a person is a copy of what your own directory says. Correcting it at source and running a new scan is usually the fastest fix.

12. Personal data breach

If Tasirio becomes aware of a personal data breach affecting Customer Data in Tasirio's systems, it will notify you without undue delay, and in any event no later than 72 hours after becoming aware.

The notice will describe what Tasirio knows at the time: the nature of the breach, the categories and approximate number of data subjects and records affected if known, the likely consequences, the measures taken or proposed, and a contact point. Tasirio will not delay the first notice to complete its investigation and will send updates as facts are established. A notification is not an acknowledgement of fault or liability.

You remain responsible for notifying regulators and data subjects. Tasirio will provide the information you reasonably need to do so. Section 20 of the Agreement covers security incidents that do not involve personal data.

For clarity: a finding about your own environment — an over-shared site, an over-privileged account — is the Service working as intended. It is not a breach of Tasirio's systems and does not trigger this section.

13. Retention, deletion and return

Retention is not one number, and a single figure would be contradicted by three parts of the system. It is stated per data type.

DataWhat happensWhen
Findings, remediation records, scan history, permission metadata, your tenant and user recordsRetained for the life of the Agreement, then deleted. Exception: if you are on the one-time Assessment engagement, scan history and findings are deleted automatically 183 days (about six months) after each scan date, during the engagement, by a scheduled sweep. That sweep runs only for Assessment customers; subscription customers' data is not swept.Within 30 days of termination or of your written request; Assessment scan history at 183 days from each scan
Connector credentialsDeleted from the key vault. The vault keeps a recoverable soft-deleted copy for 90 days, then purges it. Under bring-your-own-vault there is nothing for Tasirio to delete — you revoke Tasirio's access. In every case you can revoke the credential in your own system immediately, without Tasirio.Within 30 days; vault soft-delete window 90 days
Evidence packsHeld under a 365-day write-once (WORM) retention policy. While the policy stands they cannot be deleted or overwritten by Tasirio or by anyone else. The policy is in an unlocked state, which means Tasirio retains the ability to lift it where the law requires erasure — so erasure is not impossible, but it is not automatic either.365 days from creation
The activity logCannot be edited or purged during the term — the database refuses the operation, and deleting entries would break the tamper-evidence that is the point of it. It is deleted together with your tenant record on termination, by the database's own cascade.Life of the Agreement, then deleted with the tenant
Aggregate product statistics (section 6.3)Retained. Contains a finding type, severity, connector, date and an opaque non-reversible key — no names, no resource, no account, and no column exists for one. On deletion of your tenant the tenant reference is set to null and the per-tenant key material is destroyed, leaving rows that cannot be attributed to you.Indefinite, unattributable after deletion
BackupsDeleted data may persist in a point-in-time backup until it ages out. Backups are restored only for disaster recovery.Up to 35 days
Billing and tax recordsRetained as required by law. Tasirio's own controller data, not Customer Data.As required by applicable law

Return. While your account is active you can export your data yourself — findings and exposure reports as CSV, evidence manifests as JSON, and evidence packs. On written request Tasirio will provide a final export within 30 days, in the formats the Service supports at that time.

14. Audit and information rights

Tasirio holds no third-party audit report. This section states what it can actually do rather than a clause it would breach on first use.

Standing rights, at no charge:

On-site or third-party audit: where the information above is genuinely insufficient to demonstrate compliance, an on-site audit is available by agreement between the parties, no more than once in any twelve-month period, on 30 days' written notice, under NDA, during business hours, scoped to systems that process your data, and conducted so as not to disrupt the Service or expose another customer's data. The audit is at your cost, including Tasirio's reasonable costs of supporting it. Penetration testing of production requires separate written agreement and a scope both parties sign. Nothing in this section limits an audit right that Data Protection Law makes mandatory.

15. Impact assessments

Tasirio will give you the information reasonably available to it to help with a data protection impact assessment or a prior consultation with a supervisory authority, to the extent the assessment concerns Tasirio's processing. Sections 5, 8 and 9 are designed to be usable directly in one.

16. California and other US state privacy laws

Where the California Consumer Privacy Act as amended applies, Tasirio acts as a service provider and you are the business. Tasirio: (a) processes personal information only to perform the Service under the Agreement and for no other purpose; (b) will not sell or share personal information as those terms are defined; (c) will not retain, use or disclose personal information outside the direct business relationship or for a commercial purpose other than performing the Service; (d) will not combine personal information received from you with personal information received from another source, except as permitted; and (e) will comply with the applicable obligations and provide the same level of privacy protection the Act requires. Tasirio will notify you if it determines it can no longer meet these obligations. You may take reasonable steps to stop and remediate unauthorised use.

Where the Virginia, Colorado, Connecticut, Texas or other US state privacy laws apply, Tasirio acts as a processor on your documented instructions and gives the equivalent commitments: it processes personal data only for the purposes you specify, maintains the confidentiality obligations in section 7 and the security measures in section 8, engages sub-processors only under section 9.5, assists with data-subject requests under section 11, deletes or returns personal data under section 13, and makes available the information needed to demonstrate compliance under section 14.

17. What this DPA does not promise

18. General

Questions

Privacy and data-protection questions: privacy@tasirio.com. Security: security@tasirio.com.

Related: Privacy Policy · Terms of Service · Data Processing Addendum · Sub-processors · Security & Trust