Institutional Counterparties

    Data Processing Addendum

    As of 15 June 2026

    This page summarises the standard TIAKI Data Processing Addendum("DPA") made available to institutional counterparties (controllers) who engage TIAKI AB ("TIAKI") as a processor in connection with the Platform. The DPA forms part of the master commercial agreement and is executed on request. The executable PDF is issued under NDA via investors@tiaki.ai.

    1. Scope & Roles

    TIAKI processes personal data on documented instructions from the controller, solely to provide the Platform. Controller-to-controller marketing data is governed by our Privacy Policy, not this DPA.

    2. GDPR Art. 28 Mandatory Terms

    • Subject-matter, duration, nature, purpose, and categories of data and data subjects are recorded in an Order Form Annex.
    • Confidentiality undertakings bind all TIAKI personnel with access to personal data.
    • Technical and organisational measures meet GDPR Art. 32 (see §5).
    • Assistance with data-subject rights, DPIAs, breach notifications, and supervisory inquiries is provided.
    • On termination, personal data is deleted or returned at controller election.
    • Audit rights are available subject to reasonable notice and confidentiality controls.

    3. International Transfers

    Where personal data is transferred outside the EEA or UK, the EU Standard Contractual Clauses (Commission Decision 2021/914) and the UK International Data Transfer Addendum are incorporated by reference, with supplementary measures consistent with the EDPB Recommendations 01/2020.

    4. Sub-Processors

    TIAKI uses a controlled set of sub-processors providing cloud infrastructure (EU region), AI inference, identity, communications, payments, and support. A current sub-processor list is provided as Annex II of the DPA on signature, and updated changes are notified with a 30-day objection window.

    5. Security Measures (Art. 32)

    • Pseudonymisation of sensitive identifiers at ingress (SHA-256), separation of identity and risk data.
    • Row-level security on every public table; least-privilege role model via has_role() security-definer pattern.
    • Encryption in transit (TLS 1.2+) and at rest; secret material held in a managed vault; no service-role exposure to the browser.
    • Immutable audit logging, hash-chained provenance, and Patent Sentinel log.
    • Backup, restore, ICT-resilience and incident-response procedures aligned to DORA Art. 6–17 and ISO 27001:2022 Annex A.

    6. Personal-Data Breach Notification

    TIAKI notifies the controller without undue delay and in any event within 48 hours of becoming aware of a personal-data breach, and provides the information required for the controller to comply with GDPR Art. 33 and 34.

    7. Audit & Evidence

    Controllers may rely on TIAKI's most recent compliance evidence pack (architecture documentation, RLS posture, sub-processor list, ICT-resilience attestations, and — once achieved — SOC 2 and ISO 27001:2022 reports). On-site audits may be arranged once per 12-month period subject to reasonable notice.

    8. Liability

    Liability for breach of the DPA is governed by the limits stated in the master commercial agreement, subject to applicable mandatory law.

    9. Request the Executable DPA

    Email investors@tiaki.ai with your legal entity name, jurisdiction, intended use case, and procurement contact. We respond within five business days.