data processing agreement
How we process data on your instructions
Article 28 of the GDPR requires a written contract between a controller and its processor, covering specific points. This document works through them in the order the article sets out, and describes only measures that exist today.
In force since 27 July 2026
in force
These are the Article 28 terms on which Temja processes personal data for a business customer, in force from 27 July 2026. They apply to your subscription without any further step. If your own records need a countersigned copy, or you need it attached to a procurement pack, ask privacy@temja.eu and we will execute one.
Parties and roles
This agreement is for business customers. It exists because an organization that puts its workforce's data into Temja is a controller instructing a processor. A private individual buying for themselves is not: for their own data Temja is the controller, and the privacy notice governs it, not this document.
The controller is the customer organization named on the order. The processor is Anilata AB, Ostgatan 4, 412 75 Gothenburg, Sweden, company registration number 559357-2281, VAT number SE559357228101 — trading as Temja.
This agreement forms part of, and is subordinate to, the terms of service. Where the two conflict on the processing of personal data, this agreement wins.
For its own account, billing, and marketing data Anilata AB is a controller in its own right, not a processor. That processing is described in the privacy notice.
Subject matter and duration
Subject matter: providing the Temja training and evidence service to the controller — hosting the workspace, running lessons, quizzes, attestations and drills, deriving results, and producing the evidence pack.
Duration: from the start of the subscription until it ends, plus the period needed to complete deletion or return under the section below. Instructions that survive termination are limited to those.
Nature and purpose of the processing
The processing is collection, storage, structuring, use, derivation of results, and export, carried out by automated means for one purpose: enabling the controller to train its workforce on the safe use of AI systems and agents, and to evidence that training — for example under Article 4 of the EU AI Act.
The processor does not use the controller's personal data for its own purposes, does not sell it, and does not use it to train models. Processing takes place only on the controller's documented instructions, which are given by this agreement, the terms of service, and the configuration and actions the controller's admins take in the product.
Categories of data subjects
- employees, contractors, and other workers of the controller who are added to a roster as learners;
- managers who review their team's training records;
- administrators and the account owner who configure the workspace and export evidence.
Categories of personal data
Identity and roster
Name, work email address, department, assigned learner role, and the internal account identifier.
Training records
Course enrolment and completion status, the content and lesson version completed against, lesson progress and time in seat, quiz attempts and server-derived scores, attestation text with the typed signature and its hash, drill runs with their outcome and event counts, and certificate serial numbers.
Audit records
An append-only, hash-chained entry for each material event, recording the acting person, the action, and the time.
Technical and security
IP address, device and browser information, request logs, and bot-protection signals.
No special categories of personal data under Article 9 and no criminal-offence data under Article 10 are required by the service, and the controller must not submit any. Free-text fields are limited to what a roster needs.
Processor obligations
The processor:
- processes personal data only on the controller's documented instructions, including on transfers, and tells the controller if it believes an instruction infringes data-protection law;
- ensures that people authorized to process the data are bound by confidentiality;
- maintains the technical and organisational measures set out below, as required by Article 32;
- engages sub-processors only under the conditions in the sub-processor section, and imposes equivalent data-protection obligations on them;
- assists the controller in responding to data-subject requests;
- assists the controller with security, breach notification, impact assessments, and prior consultation under Articles 32 to 36, taking into account the nature of the processing;
- deletes or returns the personal data at the end of the service, as set out below;
- makes available the information needed to demonstrate compliance and submits to audits on the terms below.
Where the processor becomes aware of a personal-data breach affecting the controller's data, it notifies the controller without undue delay, with the information it has, and updates the controller as the investigation proceeds. The processor does not notify a supervisory authority or data subject on the controller's behalf unless instructed to.
Sub-processors
The controller gives general authorization for the sub-processors listed, with their role and region, on the security page. That list is the current one; production onboarding verifies it.
The processor will give the controller thirty days' written notice before adding or replacing a sub-processor, during which the controller may object on reasonable data-protection grounds. If an objection cannot be resolved, the controller may terminate the affected part of the service.
Each sub-processor is engaged under a written contract imposing equivalent obligations, and the processor stays liable to the controller for its sub-processors' performance.
Technical and organisational measures
The measures below are the ones actually enforced today. They are described in more detail, together with what is still a production gate, on the security page.
Tenant isolation and access control
Data-layer rules deny by default. A signed-in session is scoped to one organization and one role; team and learner records are readable only by the person themselves or by a manager or admin entitled to see them, and peers cannot read each other's training rows. Invited or deactivated members cannot read or write tenant data. Organization and membership documents are not client-writable.
Server-derived, immutable evidence
Evidence and audit writes go through a trusted command layer that verifies the identity token, validates a strict schema, applies rate limits and bot-protection checks, enforces the active role, and de-duplicates on a command identifier. The server derives scores, timestamps, certificates, hashes, and audit entries; clients send raw inputs only. Enrolments, progress, quiz attempts, attestations, drill runs, and the audit log are not client-writable.
Integrity of the audit log
Each material event is hash-chained with SHA-256 over the previous hash and the canonical entry, from a fixed genesis, with the organization identifier bound into the hash so an entry cannot be replayed into another tenant. The chain is signed with versioned HMAC-SHA-256 key material held in a managed secret store. Verification anchors the genesis, checks contiguous sequence numbers and signatures, and is reported inside the evidence pack.
Encryption and secrets
Data is encrypted in transit with TLS and at rest by the hosting provider. Credentials and API keys live in a managed secret store, never in the source repository and never in the browser bundle. The audit-signing key is never bound to the public marketing service.
Operator access and separation
Platform-operator access requires both a custom identity claim and a server-side email allowlist; customer roles never grant it. Support access into a tenant, where enabled, is time-boxed, read-only, reason-bound, visible, and audited.
Fail-closed configuration
The production runtime refuses to start with demo project identifiers, emulator hosts, or demo signing keys, a readiness probe reports misconfiguration without exposing secret values, and security headers are resolved from the runtime profile so the production policy cannot be pinned to a demo one.
Redaction in the export
The evidence pack redacts learners' free-text interaction answers, and reports its own limitations in writing inside the pack.
Stated limits, so the controller can assess them: the audit chain is signed with a symmetric key held by the processor and is not independently anchored, so it does not prove anything against the key holder. Tenant-admin multi-factor authentication, single sign-on, and SCIM do not exist today; an Enterprise engagement can add an identity-provider integration against agreed acceptance tests. Automated retention and erasure lifecycle jobs are not shipped; erasure is handled case by case.
Assisting with data-subject requests
The product itself gives the controller's admins the access, correction, and export they need for most requests, including the canonical evidence export.
Where a data subject contacts the processor directly, the processor does not answer on the controller's behalf: it tells the person to contact their organization and forwards the request to the controller without undue delay. For anything the admin surfaces cannot do, the controller can ask privacy@temja.eu for assistance.
Erasure has a hard edge worth naming. The audit log is append-only so that a completed training cannot be silently altered, and the controller may itself need to keep the evidence to meet a legal obligation or to defend a claim, which Article 17(3) permits. Erasure therefore removes or de-identifies profile data while preserving the integrity of the record, and the processor will state in writing what was retained and why.
Deletion and return
The controller can export the canonical evidence pack at any time during the subscription, which is the return mechanism.
After the service ends, the processor deletes the controller's personal data within thirty days of a written request, except where storage is required by law, and confirms the deletion in writing. Retention beyond that is agreed per contract and per sector requirement; there is no automated retention lifecycle today, so a deletion request is executed and confirmed by a human.
Audit rights
The processor makes available the information needed to demonstrate compliance with this agreement: this document, the security page, the sub-processor list, and written answers to the controller's questionnaire.
Beyond that, the controller may audit on these terms: Schedule 2 (Audit): not more than once in any twelve-month period except after a personal data breach or where a supervisory authority requires it, on thirty days' written notice, during business hours, without access to other customers' data, subject to confidentiality, and at the controller's own cost unless the audit finds material non-compliance. Temja holds no third-party security certification and publishes no audit report, so any assurance beyond written answers has to be arranged between the two parties.
International transfers
Application data — authentication, learner records, drill logs, and the audit chain — is hosted in the European Union. Outbound transactional email routes through the EU.
Some providers on the sub-processor list operate partly outside the EU: inbound mail is handled from Switzerland, which has an adequacy decision, and the payment provider may process billing data outside the EU under its own transfer safeguards. Learner training records are not exported outside the EU by the processor.
The mechanism relied on for each sub-processor — an adequacy decision, the EU standard contractual clauses, or the fact that no transfer occurs — is set out below. This table is the transfer annex; it is not a promise of one.
| Sub-processor | Transfer basis |
|---|---|
| Firebase / Google Cloud | No transfer for stored data — the project is pinned to europe-west. Any support access from outside the EEA is covered by the standard contractual clauses in Google's Cloud Data Processing Addendum. |
| Resend | No third-country transfer — sending is handled from the EU region. |
| Migadu | European Commission adequacy decision for Switzerland — no additional Article 46 safeguard is required. |
| Stripe | Contracted through Stripe's EU entity. Onward transfer of billing data to its US affiliate relies on the standard contractual clauses in Stripe's own data processing agreement. No learner training record is sent to Stripe. |
Contact
Data-protection contact: privacy@temja.eu. Commercial contact: hello@temja.eu. Company identification is on the imprint.