tencent cloud

DocumentationTencent Cloud DataBuddyAgreementsTencent Cloud DataBuddy Data Processing and Security Agreement (DPSA)

Tencent Cloud DataBuddy Data Processing and Security Agreement (DPSA)

Download
Focus Mode
Font Size
Last updated: 2026-09-15 09:46:35
AI-Translated & Reviewed
This Data Processing and Security Agreement ("DPSA") forms part of, and is supplemental to, the agreement between the Customer and Tencent Cloud International Pte. Ltd. ("TCI", "we", "us") for the provision of the Tencent Cloud DataBuddy service ("DataBuddy" or the "Service") made available via the Tencent Cloud International platform at https://www.tencentcloud.com/ (the "Principal Agreement"). This DPSA governs the processing by TCI, as the processor, of Customer Personal Data in connection with the Service.

This DPSA applies specifically to Tencent Cloud DataBuddy. Because DataBuddy is an agentic AI product that does not fall within any standard Tencent Cloud product category, this DPSA is a standalone, product-specific processing agreement and operates in addition to (and, in respect of DataBuddy, prevails over) the TCI umbrella DPSA to the extent of any conflict.

Relationship to the umbrella structure: TCI adopts a hybrid model in which an umbrella privacy policy (TCI as controller) and an umbrella DPSA (TCI as processor) cover products generally, supplemented by category-specific documents. As DataBuddy cannot be assigned to a product category, this DPSA – together with the DataBuddy Privacy Policy – constitutes the DataBuddy-specific privacy documents.

1. Definitions

1.1 Terms not defined here have the meaning given in the Principal Agreement or, where applicable, in the relevant Data Protection Laws.
1.2 "Applicable Law" means any of the following, in any jurisdiction, to the extent that it applies to a party:
(a) any statute, directive, order, enactment, regulation, bylaw, ordinance or subordinate legislation in force from time to time;
(b) the common law and the law of equity;
(c) any binding court order, judgment or decree;
(d) any applicable industry code, policy or standard enforceable by law; and
(e) any applicable direction, statement of practice, policy, rule or order that is set out by a competent regulatory authority that is binding on the parties.
1.3 "BYOK" means the bring-your-own-key model under which the Customer selects and supplies the large language model ("LLM") and associated API keys used with the Service.
1.4 "Customer Configuration Information" means the Customer's configuration settings of the LLMs operated under the BYOK model, which are submitted to or generated through the Service.
1.5 "Customer Content" means the prompts, queries, conversation history, uploaded files and documents used for agent context, and AI-generated Outputs, exchanged through integrated channels, vector embeddings of Customer content.
1.6 "Customer Personal Data" means any personal data contained within the Customer Content or Customer Configuration Information that TCI processes on behalf of the Customer under this DPSA, as further described in Annex A.
1.7 "Data Protection Laws" means all data protection and privacy laws applicable to the processing of Customer Personal Data under this DPSA, including in the launch jurisdictions the Singapore Personal Data Protection Act 2012, the Hong Kong Personal Data (Privacy) Ordinance, the Thailand Personal Data Protection Act B.E. 2562, the Indonesia Law No. 27 of 2022 on Personal Data Protection, and the Malaysia Personal Data Protection Act 2010 (as amended in 2024).
1.8 "Controller", "Processor", "Data Subject", "Personal Data Breach" and "Sub-processor" have the meanings given under the applicable Data Protection Laws.
1.9 "Inputs" mean User prompts, code and commands, input content in any manner and form (such as text or any uploaded files and shared content), instructions provided in the chat, coding and agentic sessions and related content.
1.10 "Lawful Export Measure" means a method allowing for the lawful transfer of Personal Data from a data exporter to a data importer, as may be stipulated by Data Protection Laws or a Supervisory Authority from time to time, and which may include (depending upon the Applicable Law) transfer terms prescribed by Data Protection Laws, or prior registration, licensing or permission from a Supervisory Authority.
1.11 "Outputs" means the conversation and dialogue records with the Service, responses and actions generated based on User Inputs.
1.12 "PRC" means the mainland of the People's Republic of China, and for the purposes of this agreement, excluding Hong Kong and Macau Special Administrative Regions and Taiwan region.
1.13 "SCCs" means the standard contractual clauses approved or recognised by the competent Supervisory Authority as the Lawful Export Measure for the international transfer of personal data.
1.14 "Supervisory Authority" refers to a regulatory authority having competent jurisdiction in respect of a Data Protection Law.
1.15 "User" means an administrator or authorised end user of the Customer.

2. Roles of the Parties

2.1 The parties acknowledge that, in respect of Customer Personal Data contained in Customer Content (namely Inputs and Outputs) and Customer Configuration Information, as described in Annex A, the Customer is the Controller and TCI is the Processor acting on the Customer's behalf and on its documented instructions.
2.2 This DPSA does not apply to personal data for which TCI acts as the Controller. TCI's processing of such data as the Controller is described in the DataBuddy Privacy Policy.
2.3 The Customer represents and warrants that it has provided all required notices to and obtained all required consent from its Users or has established other valid lawful basis under the applicable Data Protection Law in respect of the processing of the Customer Personal Data, including transferring the Customer Personal Data to TCI for the processing.

3. Scope and Instructions

3.1 TCI shall process Customer Personal Data only: (a) to provide and operate the Service in accordance with the Principal Agreement; (b) on the Customer's documented instructions, which include the Principal Agreement, this DPSA, as well as any instructions provided via the Customer's admin console, including with regard to transfers. TCI shall notify the Customer promptly if it is unable to comply with this DPSA or any documented instructions given by the Customer.
3.2 The subject matter, duration, nature and purpose of the processing, the types of Customer Personal Data, and the categories of Data Subjects are set out in Annex A.
3.3 BYOK and forwarding only: The Customer acknowledges that the Service supports a BYOK model. DataBuddy forwards Inputs and Customer Configuration Information to the Customer-selected LLM providers for inference and returns the Outputs to the User.
3.4 No model training. TCI shall not use Customer Personal Data to train, fine-tune or improve any AI or machine-learning model. The Customer confirms that under the BYOK model, LLM selection and use are determined by the Customer.
3.5 TCI shall inform the Customer if, in its opinion, an instruction infringes applicable Data Protection Laws.

4. Confidentiality

4.1 TCI shall ensure that persons authorised to process Customer Personal Data are subject to appropriate confidentiality obligations and are subject to review, and that access to Customer Personal Data is strictly limited to personnel who require it to provide the Service.

5. Security Measures

5.1 Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, TCI shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk. These measures are set out in Annex B.
5.2 The Customer is responsible for its own configuration and use of the Service, including management of member permissions via the admin console, control of access rights to the Customer Content, selection of LLM providers, MCP connectors, data sources and code repositories, and the security of the API keys it supplies.

6. Sub-processing and Third Parties

6.1 The Customer provides a general authorisation for TCI to engage Sub-processors to support the provision of the Service, including but not limited to those listed in Annex C. TCI shall impose data protection obligations on such Sub-processors that are no less protective than those in this DPSA, by way of data processing agreements and commitment letters, and shall remain liable for their performance.
6.2 Customer-selected third parties. The Customer and its Users may select and authorise third-party LLM providers (via BYOK), MCP connectors, data sources and code repositories. Such third parties act as independent Controllers or independent Processors engaged by the Customer, and process Customer Content and Customer Configuration Information under their own terms and privacy policies. They are not Sub-processors of TCI, and TCI is not responsible for their processing.
6.3 TCI shall inform the Customer of any intended addition or replacement of Sub-processors, giving the Customer the opportunity to object on reasonable data-protection grounds.

7. International Transfers and Remote Access

7.1 Customer Personal Data is stored in Singapore (for account-layer and console-layer information) and the launch regions including Singapore, Hong Kong, Thailand and Indonesia (for workspace-layer information).
7.2 TCI's first-line troubleshooting is provided by its customer support team in Singapore and/or the launch regions. The PRC-based R&D team is engaged only for complex technical issues, and where remote access is necessary, only the limited Customer Personal Data required for troubleshooting is accessed. There is no transfer of Customer Personal Data to the PRC, save for such limited remote access strictly necessary for troubleshooting.
7.3 Where any transfer to or remote access of Customer Personal Data from a third country outside the jurisdiction where the Customer is located occurs, to the extent required by Data Protection Laws and where TCI acts as a data importer, TCI shall ensure that the transfer and onward transfer of Customer Personal Data is carried out using a Lawful Export Measure, including but not limited to reliance on TCI's intra-group data transfer agreement incorporating the applicable SCCs and supported by transfer impact assessments and other appropriate safeguards required under applicable Data Protection Laws.
7.4 To the extent such Lawful Export Measure requires:
(a) a contract imposing appropriate safeguards on the transfer and processing of such Personal Data (which is not otherwise satisfied by this DPSA);
(b) a description of the Processing of Personal Data contemplated under this DPSA; and
(c) a description of technical and organisational measures to be implemented by the data importer,
the parties agree that the description of Processing activities set out in Annex A (Processing Details), and the description of technical and organisational measures set out in Annex B (Technical and Organisational Security Measures), shall apply mutatis mutandis for the benefit of such transfer, and in relation to any onward transfer of the Customer Personal Data by TCI to another person, the other person shall comply with the same importer obligations.

8. Assistance to the Customer

8.1 Taking into account the nature of the processing, TCI shall assist the Customer by taking appropriate technical and organisational measures, insofar as possible, in fulfilling the Customer's obligations to respond to requests from Data Subjects exercising their rights. The Service provides self-service tools: Users may access, copy, correct, delete, deregister or withdraw consent via the user console, and Customer administrators may perform member and configuration management via the admin console.
8.2 TCI shall assist the Customer in ensuring compliance with its security, breach-notification, and, where applicable, data protection impact assessment obligations, taking into account the information available to TCI.

9. Personal Data Breach

9.1 TCI shall notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and shall provide the Customer with sufficient information to enable the Customer to meet any obligations to report or notify the breach under applicable Data Protection Laws.
9.2 TCI maintains early-warning mechanisms and incident response plans, and shall take reasonable steps to mitigate the effects of, and to minimise any damage resulting from, a Personal Data Breach.

10. Retention, Return and Deletion

10.1 Within one month upon termination of the Service or the Customer's account or upon request by the Customer, TCI shall, at the Customer's choice, delete or return Customer Personal Data in TCI's possession, and delete existing copies unless applicable law requires continued storage.

11. Audit

11.1 TCI shall make available to the Customer information reasonably necessary to demonstrate compliance with this DPSA and shall allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer, subject to reasonable notice and frequency, confidentiality obligations, and TCI's security and operational requirements.

12. General

12.1 In the event of any conflict between this DPSA and the Principal Agreement or the umbrella DPSA in relation to the processing of Customer Personal Data for DataBuddy, this DPSA prevails.
12.2 This DPSA is governed by the law and subject to the jurisdiction specified in the Principal Agreement, except to the extent that Data Protection Laws require otherwise.

Annex A – Description of Processing

Subject matter and duration

Processing of Customer Personal Data contained in Customer Content and Customer Configuration Information for the purpose of providing the Tencent Cloud DataBuddy, for the duration of the Principal Agreement.

Nature and purpose of processing

To operate and provide the Service to the Customer and its Users on the Customer's instructions, including to manage the Customer's accounts, to provide the AI feature and other features of the Service, to enable the Customer to connect its own data sources and to process the Customer's business data ingested from Tencent Cloud Data Lake (TCLake), including exporting such data to destinations designated solely by the Customer, to maintain a tamper-evident record of security-relevant and governance-relevant operations performed within the Customer's workspace.

Categories of Data Subjects

The Customer's Users and any other individuals to whom the Customer Personal Data relates.

Types of Customer Personal Data

Inputs and Outputs: User prompts to DataBuddy AI features and LLM-generated results, including those exchanged via the in-product Kimi LLM and any third-party LLMs selected by the Customer.
Third-party LLM configuration and usage information: conversation logs, agent-generated long-term memory, RAG context, tool-call records, embeddings, workspace content artefacts produced through AI interaction, and Customer-configured model endpoint credentials.
Customer data source connection and credentials: data source connection configuration, data source credentials, connection operation records, ingested Customer business data, data egress configuration and records.
Customer model development and AI gateway information: experiments and run records, training and evaluation datasets, model artefacts and registry entries, inference endpoint configuration and records, and AI gateway records.
Code repository integration information: repository binding configuration, repository access credentials, cloned repository content, and contribution and push records.
Customer audit logs: common audit event attributes, authentication and session events, data access and processing events, data movement events, governance and configuration change events, and feature invocation metadata.
Other configuration information: external tool and connector configuration, agent configuration, model selection configuration, permission and delegation configuration, user preferences, and configuration change history.

Storage location

Account-layer and console-layer information is stored in Singapore. Workspace-layer information is stored within the launch region selected by Customer, including Singapore, Hong Kong, Thailand and/or Indonesia.

Annex B – Technical and Organisational Security Measures

DataBuddy adopts the following technical and organisational measures:

I. Technical Measures

Transfer security: all data is transmitted over HTTPS/TLS encrypted channels.
Storage security: data is stored on TCI infrastructure within the launch-region data centres, using a multi-tenant network isolation architecture where each Customer's AI assistant runs on an isolated cloud server instance.
Access control: firewalls, port stealth, access control measures, and security-group (inbound/outbound network rule) configuration.
Four-layer AI defence-in-depth: security auditing, permission control, network isolation, and sensitive-content detection.
AIGC labelling: explicit and implicit labels are added to generated content.

II. Organisational Measures

Dedicated information-security management systems, processes and teams are established.
Personnel access to information is strictly limited; TCI staff are bound by confidentiality obligations and subject to review.
Regular information-security education and training for relevant TCI personnel.
Early-warning mechanisms and emergency response plans are in place; in the event of a breach, the response plan is activated and reporting/notification obligations are fulfilled per law.

III. Access Rights Management

Identity authentication via the Tencent CAM.
Customer administrators manage member permissions and perform operation traceability (management operation logs) via the admin console.

IV. Third-Party Variations

Third-party LLM providers act as independent data processors/controllers and handle data per their own privacy policies or the Customer's instructions to them.
TCI requires third parties engaged by it to comply with equivalent data-protection requirements via data processing agreements and commitment letters.

Annex C – Approved List of Sub-processors

1. All Sub-processors listed on the Third Party Information Page, in the applicable launch regions.
2. All Sub-processors listed in the table below:
Entity
Purpose of Data Processing Activity
Processing location
Moonshot AI
Provision of Kimi LLM as the in-product LLM of the Service
Singapore


Help and Support

Was this page helpful?

Help us improve! Rate your documentation experience in 5 mins.

Feedback