This Data Processing and Security Agreement (“DPSA”) applies if you have entered into the Tencent WorkBuddy Enterprise Service Agreement (“Service Agreement”) for the supply of Tencent WorkBuddy Enterprise (the “Service”) by the entity set out in the Service Agreement (“TCI”, “we”, “us”). The Service is made available by the Tencent Cloud International platform at https://www.tencentcloud.com/. This DPSA governs the processing by TCI, as the processor, of the Customer Personal Data in connection with the Service.
As Tencent WorkBuddy Enterprise is an agentic AI product that does not fall within any standard Tencent Cloud product category, this DPSA is a standalone, product-specific processing agreement and operates in addition to (and, in respect of Tencent WorkBuddy Enterprise, prevails over) the Tencent Cloud International umbrella DPSA and Terms of Service (the “Principal Agreement”) (both of which applies). In the event of any conflict, the order of precedence shall be as follows (from highest to lowest): this DPSA, the Service Agreement, the Tencent Cloud International umbrella DPSA, and Principal Agreement. Please note that this DPSA only applies to the Service. This Privacy Policy does not apply:
(1) where we act as a Controller of Users' personal data. In those cases, please see our separate Privacy Policy here. (2) where you use WorkBuddy's individual version. Please see our separate Privacy Policy here for more information. 1. Definitions
1.1 Terms not defined here have the meaning given in the Principal Agreement or, where applicable, in the relevant Data Protection Laws.
1.2 “Applicable Law” means any of the following, in any jurisdiction, to the extent that it applies to a party:
(a) any statute, directive, order, enactment, regulation, bylaw, ordinance or subordinate legislation in force from time to time;
(b) the common law and the law of equity;
(c) any binding court order, judgment or decree;
(d) any applicable industry code, policy or standard enforceable by law; and
(e) any applicable direction, statement of practice, policy, rule or order that is set out by a competent regulatory authority that is binding on the parties.
1.3 “BYOK” means the bring-your-own-key model under which the Customer selects and supplies the large language model (“LLM”) and associated API keys used with the Service.
1.4 “Customer Content” means the Inputs and Outputs, instant-messaging content exchanged through integrated channels, vector embeddings of Customer content, and the Customer's configuration settings, that are submitted to or generated through the Service.
1.5 “Customer Personal Data” means any personal data contained within the Customer Content that TCI processes on behalf of the Customer under this DPSA, as further described in Annex A.
1.6 “Data Protection Laws” means (a) the General Data Protection Regulation 2016/679 (the “GDPR”); (b) the Privacy and Electronic Communications Directive 2002/58/EC; and (c) any relevant law, statute, declaration, decree, directive, legislative enactment, order, ordinance, regulation, rule or other binding instrument which implements any of the above, or which otherwise relates to data protection, privacy or the use of personal data, in each case, as applicable and in force from time to time, and as amended, consolidated, re-enacted or replaced from time to time.
1.7 “Controller”, “Processor”, “Data Subject”, “Personal Data Breach” and “Sub-processor” have the meanings given under the applicable Data Protection Laws.
1.8 “Controller to Processor Clauses” means (i) in respect of transfers of Personal Data subject to the GDPR, the standard contractual clauses for the transfer of Personal Data to third countries set out in Commission Decision 2021/914 of 4 June 2021, specifically including Module 2 (Controller to Processor); and (ii) in respect of transfers of Personal Data outside any jurisdiction that require such transfer to be effected by a Lawful Export Measure, the lawful form of contract for the transfer of Personal Data to Third Countries from data controllers to data processors approved by the relevant competent authority of such jurisdiction, in each case as in force, amended, updated or replaced from time to time.
1.9 “Inputs” mean User prompts, input content in any manner and form (such as text, voice, or any uploaded files and shared content) and instructions provided in the chat, coding and agentic sessions and related content.
1.10 “Lawful Export Measure” means a method allowing for the lawful transfer of Personal Data from a data exporter to a data importer, as may be stipulated by Data Protection Laws or a Supervisory Authority from time to time, and which may include (depending upon the Applicable Law) transfer terms prescribed by Data Protection Laws, or prior registration, licensing or permission from a Supervisory Authority.
1.11 “Outputs”means the conversation and dialogue records with the Service, responses and actions generated based on your Inputs.
1.12 “Supervisory Authority” refers to a regulatory authority having competent jurisdiction in respect of a Data Protection Law.
1.13 “Processor to Processor Clauses” means, as relevant, (i) in respect of transfers of Personal Data subject to the GDPR, the standard contractual clauses for the transfer of Personal Data to third countries set out in Commission Decision 2021/914 of 4 June 2021, specifically including Module 3 (Processor to Processor); and (ii) in respect of transfers of Personal Data outside any jurisdiction that require such transfer to be effected by a Lawful Export Measure, the lawful form of contract for the transfer of Personal Data to Third Countries from data processors to data processors approved by the relevant competent authority of such jurisdiction, in each case as in force, amended, updated or replaced from time to time.
1.14 “User” means an administrator or authorised end user of the Customer.
2. Roles of the Parties
2.1 The parties acknowledge that, in respect of Customer Personal Data contained in Customer Content, the Customer is the Controller and TCI is the Processor acting on the Customer's behalf and on its documented instructions.
2.3 The Customer represents, warrants and undertakes to:
(a) provide all required notices to and obtain all required consents from its Users or has established other valid lawful basis under the applicable Data Protection Law in respect of the processing of Customer Personal Data, including transferring Customer Personal Data to TCI for the processing; and
(b) provide all applicable rights to its Users, including complying with the obligations relating to Article 22 of the GDPR (the right of Users not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her) and equivalent obligations in other jurisdictions.
3. Scope and Instructions
3.1 TCI shall process Customer Personal Data only: (a) to provide and operate the Service in accordance with the Service Agreement and Principal Agreement; (b) on the Customer's documented instructions, which include the Service Agreement and Principal Agreement, this DPSA, as well as any instructions provided via the Customer's admin console, including with regard to transfers. TCI shall notify the Customer promptly if it is unable to comply with this DPSA or any documented instructions given by the Customer.
3.2 The subject matter, duration, nature and purpose of the processing, the types of Customer Personal Data, and the categories of Data Subjects are set out in Annex A.
3.3 BYOK and forwarding only: The Customer acknowledges that the Service supports a BYOK model. In such cases, the Service forwards Customer Content to the selected LLM providers for inference and returns the Outputs to the Users.
3.4 TCI shall inform the Customer if, in its opinion, an instruction infringes applicable Data Protection Laws.
4. Confidentiality
4.1 TCI shall ensure that persons authorised to process Customer Personal Data are subject to appropriate confidentiality obligations and are subject to review, and that access to Customer Personal Data is strictly limited to personnel who require it to provide the Service.
5. Security Measures
5.1 Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, TCI shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk. These measures are set out in Annex B.
5.2 The Customer is responsible for its own configuration and use of the Service, including management of member permissions via the admin console, control of access rights to the Customer Content, selection of LLM providers, Skills and connectors, and the security of the API keys it supplies.
6. Sub-processing and Third Parties
6.1 The Customer provides a general authorisation for TCI to engage Sub-processors to support the provision of the Service, including but not limited to its affiliates and those at Annex C. TCI shall impose data protection obligations on such Sub-processors that are no less protective than those in this DPSA, by way of data processing agreements and commitment letters, and shall remain liable for their performance.
6.2 Customer-selected third parties. The Customer and its Users may select and authorise third-party LLM providers (via BYOK), Skills, MCP connectors, and IM platforms. Such third parties act as independent controllers or independent processors engaged by the Customer, and process Customer Content under their own terms and privacy policies. They are not Sub-processors of TCI, and TCI is not responsible for their processing.
6.3 TCI shall inform the Customer of any intended addition or replacement of Sub-processors, giving the Customer the opportunity to object on reasonable data-protection grounds.
7. International Transfers
7.1 To the extent TCI Processes Personal Data in a Third Country and it is acting as data importer, TCI shall:
(a) in respect of the Processing of Personal Data in a Third Country that is not subject to the GDPR, and to the extent required by Applicable Data Protection Laws, ensure such transfer is carried out using a Lawful Export Measure. To the extent such Lawful Export Measure requires (a) a contract imposing appropriate safeguards on the transfer and processing of such Personal Data (which is not otherwise satisfied by this DPSA); (b) a description of the Processing of Personal Data contemplated under this DPSA; and (c) a description of technical and organisational measures to be implemented by the data importer, the parties agree that the Controller to Processor Clauses, the description of processing activities set out in Annex A and the description of technical and organisational measures set out in Annex B, shall apply mutatis mutandis for the benefit of such transfer, and in relation to any onward transfer of the Personal Data to another person, the other person shall comply with the same importer obligations, mutatis mutandis;
(b) in respect of the Processing of Personal Data in a Third Country that is subject to the GDPR, comply with the data importer's obligations set out in the Controller to Processor Clauses, which are hereby incorporated into and form part of this DPSA; Customer as Controller will comply with the data exporter's obligations in such Controller to Processor Clauses; and:
(i) for the purposes of Annex I or Part 1 (as relevant) of such Controller to Processor Clauses, the Parties and Processing details set out in Annex A shall apply, and the Start Date is the date in which Customer enters into the Service Agreement, and the signature(s) (in any form) given in connection with the execution of this DPSA by a party and the date(s) of such signature(s) shall apply as the dated signature required from that party;
(ii) if applicable, for the purposes of Part 1 of such Controller to Processor Clauses, the relevant Addendum EU SCCs (as such term is defined in the applicable Controller to Processor Clauses) are the standard contractual clauses for the transfer of Personal Data to third countries set out in Commission Decision 2021/914 of 4 June 2021 (Module 2), as incorporated into this DPSA by virtue of this Clause 7.1;
(iii) for the purposes of Annex II or Part 1 (as relevant) of such Controller to Processor Clauses, the technical and organisational security measures set out in Annex B shall apply; and
(iv) if applicable, for the purposes of: (i) Clause 9 of such Controller to Processor Clauses, Option 2 (“General written authorization”) is deemed to be selected and the notice period shall be 14 days; (ii) Clause 11(a) of such Controller to Processor Clauses, the optional wording in relation to independent dispute resolution is deemed to be omitted; (iii) Clause 13 and Annex I.C, the competent supervisory authority shall be the Dutch Supervisory Authority; (iv) Clause 17, Option 2 is deemed to be selected and the governing law shall be the laws of the Netherlands; (v) Clause 18, the competent courts shall be the competent courts of the Netherlands; (vi) Part 1 of such Controller to Processor Clauses, the Data Processor, as Importer may terminate the Controller to Processor Clauses pursuant to Section 19 of such Controller to Processor Clauses.
8. Assistance to the Customer
8.1 Taking into account the nature of the processing, TCI shall assist the Customer by taking appropriate measures, insofar as possible, in fulfilling the Customer's obligations to respond to requests from Data Subjects exercising their rights. The Service provides self-service tools: enterprise administrators may perform member and configuration management via the admin console.
8.2 TCI shall assist the Customer in ensuring compliance with its security, breach-notification, and, where applicable, data protection impact assessment obligations, taking into account the information available to TCI.
9. Personal Data Breach
9.1 TCI shall notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and shall provide the Customer with sufficient information to enable the Customer to meet any obligations to report or notify the breach under applicable Data Protection Laws.
9.2 TCI maintains early-warning mechanisms and incident response plans, and shall take reasonable steps to mitigate the effects of, and to minimise any damage resulting from, a Personal Data Breach.
10. Modules
10.1 The following Modules shall apply and be incorporated by reference into this DPSA:
11. Retention, Return and Deletion
11.1 On termination of the Service, TCI shall, at the Customer's choice, delete or return Customer Personal Data in TCI's possession, and delete existing copies unless applicable law requires continued storage.
12. Audit
12.1 TCI shall make available to the Customer information reasonably necessary to demonstrate compliance with this DPSA and shall allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer, subject to reasonable notice and frequency, confidentiality obligations, and TCI's security and operational requirements.
13. General
13.1 This DPSA is governed by the law and subject to the jurisdiction specified in the Service Agreement, except to the extent that Data Protection Laws require otherwise.
Jurisdiction-specific Requirements
14. EEA (where the Service is available in your jurisdiction)
14.1 Customer acknowledges and agrees that TCI may, or may appoint an affiliate or third party Sub-Processor (in accordance with clause 6) to Process the Customer's EEA Personal Data in a Third Country, provided that it ensures that such Processing takes place in accordance with the requirements of applicable Data Protection Laws, such as by executing Processor to Processor Clauses, if applicable.
15. South Korea
15.1 If and to the extent that the Tencent Security Policy is insufficient to meet the applicable requirements under Korean privacy laws and regulations, TCI will take additional measures from time to time to comply with such requirements (as applicable to an overseas transferee of Personal Data), including:
(a) Articles 28 and 63 of the Act on the Promotion of Utilisation of Information and Communications Networks and the Protection of Information (the “ICT Networks Act”);
(b) Articles 15 and 67 of the Enforcement Decree promulgated under the ICT Networks Act;
(c) the Guidelines for Technical and Administrative Measures for the Protection of Personal Information (issued by the Korea Communications Commission);
(d) Article 29 of the Personal Information Protection Act (the “PIPA”);
(e) Article 30 of the Enforcement Decree promulgated under the PIPA; and
(f) the Guidelines for Security Measures for the Safety of Personal Information (issued by the Ministry of Interior and Safety), as the foregoing may be amended and/or supplemented from time to time.
15.2 TCI will:
(a) use the Personal Data only for the purpose of and within the scope of entrusted work;
(b) agree to be subject to the training and supervision by Customer of TCI's handling of the Personal Data; and
(c) agree to be subject to the supervision and audit by relevant regulatory authorities, and by Customer (upon reasonable advance notice and no more than once per calendar year).
15.3 TCI will compensate Customer and any relevant Data Subjects for any and all damages, liabilities, costs and expenses arising out of any breach of TCI's obligations under this DPSA or under Korean data protection laws.
16. Macau
16.1 The appointment of TCI as Processor, as well as the appointment of sub-processors where (and to the extent) permitted in this DPSA, shall be notified by Customer to the local data protection office (GPDP - Gabinete para a Protecção de Dados Pessoais).
16.2 TCI shall have the right to reasonably request Customer provide evidence of compliance with an instruction under the relevant Macau data protection laws.
16.3 Customer shall expressly inform TCI, in writing, in case of processing of sensitive data, as defined in article 7 of the Macau Data Protection Law (Law n. 8/2005), and shall ensure compliance with the particular requirements provided for under Macau data protection law for the processing of such data.
17. Kingdom of Saudi Arabia
17.1 To the extent that TCI Processes Personal Data from KSA in a KSA Third Country and is acting as a data importer, TCI shall comply with the data importer's obligations and Customer shall comply with the data exporter's obligations as set out in the KSA Controller - Processor Transfer Clauses, which are hereby incorporated into and form part of this DPSA, with the Processing details that comprise Appendix 2 to the KSA Controller - Processor Transfer Clauses being those set out in Annex A, and the technical and organisational measures that comprise Appendix 3 to the KSA Controller - Processor Transfer Clauses set out in Annex B.
17.2 For the purposes of the KSA Controller - Processor Transfer Clauses, the following additional provisions will apply:
(a) the parties agree to observe the KSA Controller - Processor Transfer Clauses without modification;
(b) the names and addresses of Customer and TCI will be considered to be incorporated into the KSA Controller - Processor Transfer Clauses and for the purposes of Appendix 1 of the KSA Controller - Processor Transfer Clauses;
(c) Customer is the data exporter and TCI, is the data importer as defined in the KSA Controller - Processor Transfer Clauses; and
(d) each party's signature to this DPSA will be considered a signature to the terms contained in the KSA Controller - Processor Transfer Clauses.
17.3 To the extent TCI Processes Personal Data subject to the PDPL as a Processor, TCI will notify Customer if it is subject to laws outside of KSA which impacts TCI's compliance with the PDPL, and TCI shall not require the prior consent of a Data Subject prior to making mandatory disclosures of Personal Data under applicable KSA laws.
Annex A — Description of Transfers
A. LIST OF PARTIES
Data exporter(s) – Data Controller:
Name: Customer as defined in the Service Agreement
Address: As defined in the Service Agreement
Contact person's name, position and contact details: As defined in the Service Agreement
Role (controller/processor): Controller
Data importer(s) – Data Processor:
Name: TCI as defined in the Service Agreement
Address: As defined in the Service Agreement
Contact person's name, position and contact details: As defined in the Service Agreement
Role (controller/processor): Processor
B. DESCRIPTION OF TRANSFER
Categories of Data Subjects
Customer's Users and any other individuals to whom Customer Personal Data relates.
Categories of Personal Data transferred
The content uploaded by Customer, or as notified by Customer to TCI from time to time, such as the following:
|
Inputs and Outputs | We process Inputs and Outputs to provide the Service. |
Billing and Usage Metering Information | We process the following information to provide billing and usage metering statistics to Customer for Customer's own internal management purposes: Metering and quota data, such as account/member identifiers and usage and consumption records Usage information, such as request ID, member ID/name, department, consumption type, and usage time and related information Development efficiency metrics, such as adoption rates, usage counts, and other related information |
Enterprise Organization and Member Management Data | We process the following information to allow Customer to manage its organization and its end users' usage of the Service: End user information, such as member ID, name, login account, department information, status information and member review information User group data, such as user group ID and name, group members, creators Administrator roles information, such as role assignments and administrator information |
Conversation Logs and Audit Logs | We process this information for Customer's audit, security and compliance purposes: Conversation logs, such as session information, input text, model used, requester identity and timestamps Operation/login audit logs, such as operation type, operator, IP address, and timestamps |
Enterprise Knowledge Base Content, Credentials, and Integration Data | We process the following information to provide enterprise AI resource management and third-party integrations: Enterprise knowledge base data, such as uploaded documents/files, content, visibility scope, and file count Credential Management data, such as third-party service credentials Connectors / MCP data, such as connector configuration and authentication tokens IM channel information, such as IM platform user unique identifier and message content sent through IM channels. Configuration information |
Sensitive data transferred (if applicable) and applied restrictions or safeguards that fully take into consideration the nature of the data and the risks involved, such as for instance strict purpose limitation, access restrictions (including access only for staff having followed specialised training), keeping a record of access to the data, restrictions for onward transfers or additional security measures.
The content uploaded by Customer, or as notified by Customer to TCI from time to time
The frequency of the transfer (e.g. whether the data is transferred on a one-off or continuous basis).
Continuous.
Nature of the processing.
TCI will process Customer Personal Data contained in Customer Content in support of the Services performed for Customer.
Purpose(s) of the data transfer and further processing
Transfer and processing necessary to allow TCI to perform the Services and its obligations under the Service Agreement.
The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period
For the duration of the Service Agreement.
C. COMPETENT SUPERVISORY AUTHORITY
Autoriteit Persoonsgegevens (the Netherlands).
Annex B — Technical and Organisational Security Measures
We adopt the following technical and organisational measures in relation to the Service:
Technical Measures
Transfer security: all data is transmitted over HTTPS/TLS encrypted channels.
Storage security: data is stored on TCI within the launch-region data centres, using a multi-tenant network isolation architecture where each enterprise's AI assistant runs on an isolated cloud server instance.
Access control: firewalls, port stealth, access control measures, and security-group (inbound/outbound network rule) configuration.
Four-layer AI defence-in-depth: security auditing, permission control, network isolation, and sensitive-content detection.
AIGC labelling: explicit and implicit labels are added to generated content.
Organisational Measures
Dedicated information-security management systems, processes and teams are established.
Personnel access to information is strictly limited; TCI staff are bound by confidentiality obligations and subject to review.
Regular information-security education and training for relevant TCI personnel.
Early-warning mechanisms and emergency response plans are in place; in the event of a breach, the response plan is activated and reporting/notification obligations are fulfilled per law.
Access Rights Management
Identity authentication via the Tencent Unified Identity platform.
Enterprise administrators manage member permissions and perform operation traceability (management operation logs) via the admin console.
Third-Party Variations
Third-party LLM providers except for those provided in Annex C below act as independent data processors/controllers and handle data per their own privacy policies or Customer's instructions to them.
IM platforms process data per their respective privacy policies.
TCI requires third parties engaged by it to comply with equivalent data-protection requirements via data processing agreements and commitment letters.
Annex C
Approved List of Sub-Contractors
2. All sub-processors listed in the table below:
|
Moonshot AI | Provision of Kimi as an LLM model as part of the Services | Singapore |
JINGSHENG HENGXING TECHNOLOGY PTE. LTD. | Provision of GLM as an LLM model as part of the Services | Singapore |
Tencent Technology (Shenzhen) Co. Ltd | Provide back-end and technical support in the provision of the Services | People's Republic of China |