Data Processing Agreement
Effective date: 1 July 2025 · Last updated: 1 July 2025
This DPA forms part of the SF Tether Terms of Service.
1. Roles and Scope
SF Tether Ltd ("Processor") acts as a data processor with respect to personal data that the Customer ("Controller") instructs us to process in connection with the Service, including personal data stored in the Token Vault, audit log metadata relating to identifiable individuals, and any personal data contained in API call parameters.
Where SF Tether processes personal data for its own purposes (account management, billing, security), it is an independent data controller. That processing is described in the Privacy Policy.
2. Controller Instructions
SF Tether will process personal data only on documented instructions from the Controller, as set out in this DPA, the Terms of Service, and configuration choices made through the dashboard and API. If we believe any instruction infringes applicable data protection law, we will promptly inform the Controller.
3. Security Measures
SF Tether implements and maintains technical and organisational measures including:
- AES-256 encryption at rest; TLS 1.2+ encryption in transit
- Field-level encryption for Token Vault credentials with separate key management
- Role-based access control with least-privilege enforcement
- Multi-factor authentication for all administrative access
- Immutable audit logging of all credential access
- Regular penetration testing and vulnerability management
- Documented incident response procedure
4. Sub-processors
The following sub-processors are authorised to process personal data on behalf of the Controller:
| Sub-processor | Processing Activity | Location |
|---|---|---|
| Neon, Inc. | Database hosting and storage | EU / US |
| Vercel Inc. | Application hosting, edge compute | EU / US |
| SaaS Factory platform | Authentication, billing, audit logging | UK / EU |
| Temporal Technologies Inc. | Background workflow orchestration | EU / US |
We will provide 30 days' advance notice before adding new sub-processors. You may object to a new sub-processor within 14 days of notice.
5. Data Deletion
Upon termination of the Terms of Service, SF Tether will delete or anonymise all personal data processed under this DPA within 90 days of the termination date. Credentials in the Token Vault will be deleted within 72 hours of account termination. You may request an export of audit logs before deletion.
6. Security Incident Notification
SF Tether will notify the Controller without undue delay, and in any event within 48 hours of becoming aware of a security incident involving personal data processed under this DPA. Notification will include the nature of the incident, affected data categories, likely consequences, and measures taken.
7. Data Subject Rights
SF Tether will assist the Controller in fulfilling data subject rights requests (access, rectification, erasure, portability, restriction, objection) by providing technical tools to search, export, and delete personal data within the Service.
8. International Transfers
Where personal data is transferred outside the UK or EU/EEA, such transfers are made pursuant to UK International Data Transfer Agreements (IDTAs) or EU Standard Contractual Clauses (SCCs), as applicable.
9. Token Vault — Additional Obligations
Credentials in the Token Vault are encrypted at the field level before storage, with encryption keys stored separately from data. SF Tether staff may access decrypted credentials only for documented operational reasons, subject to an additional approval step, and all such accesses are logged.
10. Contact
Data protection enquiries: privacy@sf-tether.saas-factory.ai
Security incident reports: security@sf-tether.saas-factory.ai
The full Data Processing Agreement, including all annexes, is available upon request for enterprise customers. Contact legal@sf-tether.saas-factory.ai.