This Data Processing Agreement ("DPA") forms part of, and is incorporated by reference into, the Tendn App Terms and Conditions and any related agreement between you and us (together, the "Terms of Service") governing your use of the Tendn app. This DPA applies to the extent that we Process Personal Data on your behalf, or otherwise Process Personal Data in connection with the Services, in each case where Data Protection Laws apply.
In this DPA, "we", "us" and "our" means Tendn Ltd (Company No. 17154922), a company registered in England and Wales whose contact email is support@tendn.app ("Tendn"). "You" and "your" means the customer that has entered into the Terms of Service with us. Each of us is a "party" and together we are the "parties".
By accepting the Terms of Service, or by continuing to access or use the Services, you agree to this DPA. If you are entering into this DPA on behalf of an organisation, you confirm you have authority to bind that organisation.
In this DPA, capitalised terms have the meanings given below. Capitalised terms used but not defined in this DPA have the meaning given in the Terms of Service.
| Term | Meaning |
| Controller | has the meaning given in the UK GDPR. |
| Data Protection Laws | all laws and regulations applicable to the Processing of Personal Data under this DPA, including the UK GDPR, the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations 2003, each as amended or replaced from time to time. |
| Data Subject | an identified or identifiable natural person to whom Protected Data relates, being the categories of individual described in Schedule 1. |
| ICO | the Information Commissioner's Office or any successor supervisory authority. |
| International Transfer | a transfer of Protected Data to, or access to Protected Data from, a country or territory outside the United Kingdom. |
| Personal Data | has the meaning given in the UK GDPR. |
| Personal Data Breach | a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Protected Data. |
| Processing | has the meaning given in the UK GDPR, and "Process", "Processes" and "Processed" are construed accordingly. |
| Processor | has the meaning given in the UK GDPR. |
| Protected Data | the Personal Data described in Schedule 1 that is Processed by, or on behalf of, a party under or in connection with the Terms of Service. |
| Restricted Country | a country or territory outside the United Kingdom that is not the subject of an adequacy decision or adequacy regulations recognised under Data Protection Laws. |
| Security Measures | the technical and organisational measures described in Schedule 2, as updated from time to time in accordance with this DPA. |
| Services | the Tendn app and related services made available to you under the Terms of Service. |
| Special Category Data | the categories of Personal Data described in Article 9(1) of the UK GDPR, including health data. |
| Standard Contractual Clauses | where relevant, the standard contractual clauses issued by the European Commission and/or the International Data Transfer Agreement (IDTA) or the International Data Transfer Addendum to the EU SCCs issued by the ICO, in each case as applicable to an International Transfer. |
| Sub-processor | any Processor engaged by us to Process Protected Data in connection with the provision of the Services. |
| UK GDPR | the retained EU law version of Regulation (EU) 2016/679 as it forms part of the law of England and Wales, Scotland and Northern Ireland by virtue of the European Union (Withdrawal) Act 2018. |
2.1 Processing on your behalf
Where you determine the purposes and means of Processing Protected Data and we Process that Protected Data on your behalf in providing the Services, you are the Controller and we act as your Processor. This typically applies to the ultrasound footage, scan-related data that you capture, store and Process using the Services.
2.2 Independent Controller Processing
To the extent that we determine the purposes and means of Processing certain Personal Data for our own purposes (for example, account administration, billing, security, product analytics that do not use your Protected Data, and compliance with our legal obligations), we act as an independent Controller. Our Processing as Controller is described in our published privacy policy and is not governed by this DPA.
2.3 Joint controllership
Where the parties jointly determine the purposes and means of Processing certain Protected Data, they will act as joint Controllers to that extent, and the following applies:
(a) the parties will agree in writing (including in Schedule 1 or a separate arrangement) the essence of their respective responsibilities under Article 26 of the UK GDPR, including their respective roles in providing transparency information to Data Subjects and responding to the exercise of Data Subject rights;
(b) each party will make the essence of that arrangement available to Data Subjects to the extent required by Data Protection Laws; and
(c) unless otherwise agreed, each party is responsible for its own compliance obligations in respect of the Protected Data it Processes as a joint Controller, and will not be liable for the acts or omissions of the other party in that capacity.
2.4 No diagnostic use
You acknowledge that the Services are provided for educational and training purposes only and not for clinical diagnosis, and you are responsible for ensuring that Protected Data is only submitted to and Processed through the Services for those purposes.
Where we act as your Processor, we will:
(a) Process the Protected Data only on your documented instructions, including as set out in this DPA and the Terms of Service, unless we are required to Process it by law (in which case we will, where legally permitted, inform you of that requirement before Processing);
(b) immediately inform you if, in our opinion, an instruction infringes Data Protection Laws, without any obligation to actively monitor your compliance;
(c) ensure that persons authorised to Process the Protected Data are subject to appropriate obligations of confidentiality;
(d) implement and maintain the Security Measures in accordance with the clause dealing with security;
(e) engage Sub-processors only in accordance with the clause dealing with sub-processors;
(f) assist you, taking into account the nature of the Processing and the information available to us, in responding to requests from Data Subjects and in ensuring your compliance with your obligations under Articles 32 to 36 of the UK GDPR (security, breach notification, data protection impact assessments and prior consultation);
(g) make available to you information reasonably necessary to demonstrate our compliance with this DPA, and allow for and contribute to audits in accordance with the clause dealing with audits; and
(h) on termination, delete or return the Protected Data in accordance with the clause dealing with deletion or return.
Where we act as your Processor, you:
(a) warrant that you have a valid lawful basis under Data Protection Laws for the Processing of Protected Data (and, in respect of Special Category Data, a valid condition under Article 9 of the UK GDPR, which for health data captured through the Services will ordinarily be the explicit consent of the Data Subject);
(b) are responsible for providing all required transparency information and, where applicable, obtaining and maintaining all necessary consents from Data Subjects;
(c) will ensure that your instructions to us comply with Data Protection Laws and that you are entitled to transfer the Protected Data to us so that we may lawfully Process it in accordance with this DPA; and
(d) will not, by any act or omission, cause us or any Sub-processor to be in breach of Data Protection Laws.
(a) The Controller acknowledges that, during its use of the Services, clips captured via the relevant application or device are transmitted to the Processor’s servers for the purpose of processing as contemplated by this DPA. The Processor applies automated recognition technology designed to identify and prevent the transmission or onward processing of content that is not an ultrasound image (for example, any incidental capture of data, including but not limited to Personal Data, which may be on the Controller’s device screen while the Services are operating). However, the Controller acknowledges that this detection may not be accurate in all cases and that incidental non-ultrasound content, such as application transitions, notifications, messages, emails or other content visible on screen during recording, may occasionally be transmitted to the Processor.
(b) The Controller is presented with the captured clips and is required to actively select which clips are saved to the Controller’s library. It is the Controller's responsibility to review the captured clips before saving, and to avoid saving clips containing incidental non-ultrasound content, including any Personal Data visible on the device screen outside the scan region.
(c) Clips that are not selected by the Controller are not retained by the Processor.
(d) Clips saved to the Controller’s library remain subject to the Controller’s retention decisions and may be deleted by the Controller after saving in accordance with the functionality made available by the Processor and the terms of this DPA.
(e) Any Personal Data in the retained clips shall be processed by the Processor in accordance with this DPA.
6.1 General authorisation
You provide general authorisation for us to engage Sub-processors to Process Protected Data, including our cloud hosting and infrastructure providers. Our current Sub-processors are listed in Schedule 3 (or otherwise made available to you on request or via the Services).
6.2 Conditions
Before a Sub-processor Processes Protected Data, we will:
(a) carry out reasonable due diligence to satisfy ourselves that the Sub-processor is capable of providing the level of protection required by this DPA; and
(b) enter into a written agreement with the Sub-processor imposing data protection obligations that are, in substance, no less protective than those in this DPA.
6.3 Changes and objections
We will inform you of any intended addition or replacement of a Sub-processor, giving you a reasonable opportunity to object on reasonable grounds relating to data protection. If you object and we are unable to accommodate your objection, either party may terminate the affected part of the Services in accordance with the Terms of Service. We remain liable to you for the acts and omissions of our Sub-processors to the same extent as we would be liable if performing the services of the Sub-processor directly under this DPA.
We will implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of Processing, as well as the risk to Data Subjects. Those measures are described in Schedule 2 and include, as a minimum:
(a) encryption of Protected Data in transit and, where appropriate, at rest;
(b) measures to ensure the ongoing confidentiality, integrity, availability and resilience of Processing systems;
(c) access controls limiting access to Protected Data to authorised personnel on a need-to-know basis;
(d) the ability to restore the availability of and access to Protected Data in a timely manner following an incident; and
(e) a process for regularly testing, assessing and evaluating the effectiveness of the Security Measures.
We may update the Security Measures from time to time provided that the updated measures do not materially reduce the overall level of security.
We will notify you without undue delay after becoming aware of a Personal Data Breach affecting Protected Data we Process on your behalf. Our notification will, to the extent then available, describe the nature of the breach, the likely consequences, and the measures taken or proposed to address it. We will provide reasonable co-operation and assistance to enable you to comply with your notification obligations to the ICO and to affected Data Subjects. Nothing in this clause requires us to notify you of unsuccessful attempts or immaterial incidents that do not compromise the security of Protected Data.
If we receive a request from a Data Subject to exercise their rights under Data Protection Laws in respect of Protected Data we Process on your behalf, we will, unless legally prohibited, promptly notify you and not respond to the request except on your documented instructions or as required by law. Taking into account the nature of the Processing, we will provide reasonable assistance, by appropriate technical and organisational measures, to enable you to respond to such requests.
We will make available to you, on reasonable written request, information reasonably necessary to demonstrate our compliance with this DPA, and will allow for and contribute to audits, including inspections, conducted by you or an auditor mandated by you, subject to the following:
(a) audits may be conducted no more than once in any twelve-month period, unless required by the ICO or following a Personal Data Breach;
(b) you will give at least thirty days' prior written notice, conduct the audit during our normal business hours, and not unreasonably disrupt our operations;
(c) you (and your auditor) will comply with our reasonable security and confidentiality requirements and will not access data relating to any other customer; and
(d) we may satisfy an audit request by providing relevant third-party certifications, audit reports or summaries where these reasonably demonstrate our compliance.
We will not carry out an International Transfer of Protected Data to a Restricted Country unless an appropriate safeguard or lawful transfer mechanism is in place. Where such a transfer occurs:
(a) we will put in place, and require any relevant Sub-processor to enter into, the Standard Contractual Clauses (including the IDTA or the UK Addendum to the EU SCCs, as applicable) or rely on another valid transfer mechanism under Data Protection Laws;
(b) we will carry out any transfer risk assessment required by Data Protection Laws and implement any supplementary measures reasonably necessary; and
(c) the recipient countries or territories, the relevant Sub-processors and the applicable transfer mechanism are set out in Schedule 3 (or otherwise notified to you).
You authorise us to enter into the applicable Standard Contractual Clauses with Sub-processors on your behalf where reasonably required to give effect to this clause.
On termination or expiry of the Terms of Service, or otherwise on your written request, we will, at your choice, delete or return to you all Protected Data we Process on your behalf and delete existing copies, unless retention is required by law. We may retain Protected Data to the extent, and for the period, required by law, and this DPA will continue to apply to such retained Protected Data. Deletion of Protected Data from live systems does not require deletion from routine backups until those backups are overwritten in the ordinary course, provided the Protected Data remains protected and is not restored to active use.
The liability of each party arising out of or in connection with this DPA is subject to, and counts towards, the exclusions, limitations and aggregate caps on liability set out in the Terms of Service, and this DPA does not increase or create any additional caps on liability.
Without limiting the above and to the maximum extent permitted by law, our total aggregate liability to you arising out of or in connection with this DPA (whether in contract, tort, including negligence, breach of statutory duty or otherwise) is limited to the amount set out in the Terms of Service. Nothing in this DPA limits or excludes either party's liability where it cannot lawfully be limited or excluded, including for compensation payable to a Data Subject under Data Protection Laws to the extent attributable to that party's breach.
14.1 Relationship with the Terms of Service
This DPA supplements the Terms of Service. In the event of a conflict between this DPA and the Terms of Service in relation to the Processing of Protected Data, this DPA prevails to the extent of the conflict. Where this DPA is incorporated by reference into online terms and conditions, acceptance of those terms constitutes acceptance of this DPA.
14.2 Changes to this DPA
We may update this DPA from time to time to reflect changes in Data Protection Laws, our Sub-processors or the Services. We will make the current version available on our website, and your continued use of the Services after any change takes effect constitutes acceptance of the updated DPA, except where a change materially reduces your protections, in which case we will provide reasonable prior notice.
14.3 Notices
Notices under this DPA must be given in writing and may be sent by email to support@tendn.app (for us) and to the email address associated with your account (for you).
14.4 Severance
If any provision of this DPA is or becomes invalid, illegal or unenforceable, it will be deemed modified to the minimum extent necessary to make it valid, and if such modification is not possible, the relevant provision will be deemed deleted, without affecting the remainder of this DPA.
14.5 Governing law and jurisdiction
This DPA and any dispute or claim arising out of or in connection with it are governed by the laws of England and Wales, and the parties submit to the exclusive jurisdiction of the courts of England and Wales.
This Schedule sets out the details of the Processing of Protected Data as required by Article 28(3) of the UK GDPR.
| Subject matter of Processing | Provision of the Tendn AI-powered ultrasound coaching Services for educational and training purposes. |
| Duration of Processing | For the term of the Terms of Service, plus any retention period required by law or agreed under the deletion or return clause. |
| Nature and purpose of Processing | Storage, hosting, organisation, analysis and processing of ultrasound footage and related data to provide real-time feedback, coaching, a footage library and related features. |
| Categories of Data Subject | Individuals who are scanned using the Services, including colleagues, and family or friends on whom trainees practise. |
| Categories of Personal Data | Scan-related data; any Personal Data which is on your device’s screen during the screen record, and ultrasound footage and imagery captured through the Services. |
| Special Category Data | Where health data (Article 9 UK GDPR), including ultrasound imagery and associated clinical information from which an individual is identifiable, is Processed, it is Processed on the basis of explicit consent obtained by you. |
We implement and maintain the following technical and organisational Security Measures, which we may update from time to time provided the overall level of security is not materially reduced:
(a) encryption of Protected Data in transit and, where appropriate, at rest;
(b) role-based access controls, authentication and least-privilege access to Protected Data;
(c) network security, firewalls and logging and monitoring of access to Processing systems;
(d) secure development practices, patch management and vulnerability management;
(e) backup, business continuity and disaster recovery arrangements;
(f) staff confidentiality obligations and data protection training;
(g) TLS encryption in transit; encryption at rest (Google Cloud default AES-256);
(h) per-user access scoping enforced by Firebase security rules;
(i) automated cropping of captured frames to the tissue image region, removing surrounding interface/screen content, before storage or analysis; UK-region processing; and
(j) MFA on all administrative accounts.
Our approved Sub-processors, the Processing they carry out, the locations in which Protected Data is Processed, and the applicable transfer mechanism are as follows:
| Google Cloud / Firebase (Google Ireland Ltd). | Processing: Authentication, database and storage of account data and Scan Data. |
| Location(s): europe-west2 (London, UK). | |
| Transfer mechanism (if outside UK): Irish company (within EU) subject to an adequacy decision, and all data is stored within the UK. | |
| Anthropic PBC | Processing: AI processing of user-entered text only (in-app assistant queries, reflection notes). No Scan Data or imagery is sent. |
| Location(s): United States. | |
| Transfer mechanism (if outside UK): UK Addendum / IDTA via Anthropic's DPA. | |
| Stripe Payments UK Ltd. | Processing: payment processing when subscriptions launch (controller-side; no Scan Data). |
| Location(s): UK/EU (US parent). | |
| Transfer mechanism (if outside UK): Stripe DPA including UK Addendum. |