Data processing addendum
This Data Processing Addendum (“DPA”) forms part of the agreement between Coherence Limited (HE 490848, 195 Arch. Makariou III, 3030 Limassol, Cyprus) (“Coherence”) and the business that holds a Coherence workspace (the “Customer”), made up of the Terms of Service and, for paid tools, the Licence Terms (together, the “Agreement”). It applies whenever Coherence processes personal data on the Customer's behalf, and needs no separate signature. A countersigned copy is available on request from office@coherenceltd.com.
1. Definitions
“GDPR” means Regulation (EU) 2016/679, and includes the UK GDPR and the Swiss Federal Act on Data Protection where they apply. “Customer Personal Data” means personal data in Customer Data (as defined in the Licence Terms, and including data in any workspace without a paid licence) that Coherence processes on the Customer's behalf. “Controller”, “processor”, “personal data breach”, “data subject” and “processing” have their GDPR meanings. “SCCs” means the standard contractual clauses approved by Commission Implementing Decision (EU) 2021/914.
2. Roles and instructions
2.1 The Customer is the controller (or a processor acting for another controller) of Customer Personal Data, and Coherence is its processor (or subprocessor).
2.2 Coherence processes Customer Personal Data only on the Customer's documented instructions, including with regard to transfers to third countries, unless EU or Member State law requires otherwise; in that case Coherence tells the Customer first, unless that law prohibits it. The Agreement, the Customer's configuration of its workspace (such as the tools it enables and the accounts it connects) and its users' actions in the Service are the Customer's complete instructions. Coherence tells the Customer promptly if it thinks an instruction breaks data protection law.
2.3 The Customer is responsible for having a lawful basis for the processing, for giving data subjects the information the law requires, and for the accuracy of Customer Personal Data.
2.4 The subject matter, duration, nature and purpose of processing, and the types of personal data and categories of data subjects, are set out in Annex 1.
2.5 Customer-directed disclosures. When the Customer, its users or its API keys retrieve Customer Personal Data through the Service, including through the API or an AI client connected over MCP, Coherence discloses that data on the Customer's instruction to the system the Customer chose. Those systems and their providers are not Coherence's subprocessors. From that point the Customer is responsible for the data, including its lawful basis and any transfer outside the European Economic Area. Coherence limits each disclosure to the scopes the Customer set for the key.
3. Coherence's obligations
3.1 Confidentiality. Coherence ensures that everyone it authorises to process Customer Personal Data is bound by confidentiality.
3.2 Security. Coherence implements the technical and organisational measures in Annex 2, which meet Article 32 GDPR. Coherence may update them if the overall level of protection does not fall.
3.3 Subprocessors. The Customer gives Coherence general authorisation to use subprocessors. The current subprocessors are listed on the Subprocessors page (Annex 3). Coherence gives the Customer at least 30 days' notice of a new or replacement subprocessor by updating that page and emailing workspace owners. The Customer may object on reasonable data-protection grounds within that period; the parties will then discuss it in good faith, and if they cannot resolve it the Customer may terminate the affected licences and receive a refund of prepaid fees for the period after termination. Coherence imposes on each subprocessor, by contract, data protection obligations that are at least as protective as this DPA, and remains liable to the Customer for its subprocessors.
3.4 Data subject requests. Taking into account the nature of the processing, Coherence helps the Customer, by appropriate technical and organisational measures, to respond to requests from data subjects exercising their rights. If Coherence receives a request directly, it passes it to the Customer and does not respond itself except to confirm that it has done so.
3.5 Assistance. Coherence helps the Customer meet its obligations under Articles 32 to 36 GDPR (security, breach notification, data protection impact assessments and prior consultation), taking into account the nature of the processing and the information available to Coherence.
3.6 Personal data breaches. Coherence notifies the Customer without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notice includes the information Article 33(3) GDPR requires, as far as it is available, supplemented as more becomes known. Coherence takes reasonable steps to contain the breach and reduce its effects.
3.7 Deletion and return. When the Agreement ends, or when the Customer closes a workspace, Coherence makes Customer Personal Data available for export for 30 days on request and then deletes it within 90 days, including copies, unless EU or Member State law requires storage. Backups are overwritten in the ordinary backup cycle.
3.8 Records, information and audits. Coherence keeps records of processing under Article 30(2) GDPR. It makes available to the Customer all information needed to demonstrate compliance with Article 28 GDPR, including answers to reasonable security questionnaires and its subprocessors' audit reports where available. It allows for and contributes to audits, including inspections, by the Customer or an independent auditor it mandates who is bound by confidentiality, on at least 30 days' notice, during business hours, no more than once a year unless a breach or a supervisory authority requires it, and at the Customer's cost.
4. International transfers
4.1 Coherence is established in the European Union (Cyprus). Coherence may transfer Customer Personal Data outside the European Economic Area only in line with Chapter V GDPR.
4.2 Transfers to subprocessors. Where a subprocessor processes Customer Personal Data in a country without an adequacy decision, Coherence relies on the subprocessor's certification under the EU–US Data Privacy Framework where available, and in every case has entered into the SCCs (Module 3, processor to processor) with that subprocessor, supplemented by the UK International Data Transfer Addendum and Swiss amendments where relevant.
4.3 Customers outside the EEA. Where the Customer is located in a country without an adequacy decision and Coherence returns or makes available Customer Personal Data to it, the SCCs Module 4 (processor to controller) are incorporated into this DPA by reference, with Coherence as data exporter and the Customer as data importer, and the options set out in Section 4.4.
4.4 SCC options. Where the SCCs apply under this DPA: the optional docking clause (Clause 7) applies; in Clause 9, option 2 (general authorisation) applies with the notice period in Section 3.3; the optional language in Clause 11 does not apply; the governing law (Clause 17) and courts (Clause 18) are those of the Republic of Cyprus; and Annexes I and II of the SCCs are completed by Annexes 1 and 2 of this DPA. If the SCCs conflict with this DPA, the SCCs prevail.
5. Liability and precedence
Each party's liability under this DPA is subject to the limits in the Agreement, except where the GDPR or the SCCs do not allow them. If this DPA conflicts with the rest of the Agreement on the processing of personal data, this DPA prevails. This DPA lasts as long as Coherence processes Customer Personal Data.
Annex 1: Details of processing
Parties. Data exporter: the Customer (controller). Data importer / processor: Coherence Limited, 195 Arch. Makariou III, 3030 Limassol, Cyprus, contact office@coherenceltd.com.
Subject matter and purpose. Providing the Coherence workspace and the tools the Customer enables, including drafting creator briefs, answering questions, analysing content performance, and finding, matching and filing receipts, as described in the Licence Terms and the tool schedules.
Nature of processing. Collection through the Service and connected accounts, storage, organisation, retrieval, analysis by software and AI models, transmission on the Customer's instruction, and deletion.
Duration. For the term of the Agreement and the deletion period in Section 3.7.
Frequency. Continuous.
Categories of data subjects. The Customer's workspace members; the Customer's employees, contractors and business contacts; senders and recipients of emails in connected mailboxes; merchants and counterparties in connected bank accounts; people named in content the Customer submits.
Types of personal data. Names, email addresses and other contact details; workspace roles and activity; content of briefs, questions and other submissions; emails matching receipt and invoice searches, their attachments and message details (sender, recipient, subject, date); expense details (merchant, amount, date, card or account reference). The Service is not designed for special categories of personal data or data about criminal convictions, and the Customer should not submit them.
Retention. As in Section 3.7 and the Privacy Policy.
Transfers to subprocessors. As listed in Annex 3, for the purposes stated there.
Annex 2: Technical and organisational measures
- Encryption. TLS for data in transit. Data at rest encrypted by our database provider; access tokens and keys for connected accounts additionally encrypted with AES-256-GCM before storage. API keys stored only as hashes.
- Workspace isolation. Each workspace's data is separated in the database by row-level security policies, tested automatically before each release.
- Access control. Least-privilege roles within workspaces; financial tools limited to owners and admins; production access limited to authorised Coherence personnel.
- Authentication. Passwordless one-time sign-in codes or links; expiring, revocable API keys.
- AI processing. AI model requests are made through Vercel AI Gateway with zero data retention; providers do not keep or train on the content.
- Records. Append-only audit, usage and acceptance records.
- Resilience. Managed database and hosting on infrastructure providers that hold SOC 2 Type II reports.
- Development. Changes go through pull requests with automated application and database security tests before deployment to production.
- Incidents. A written procedure to contain, assess, record and notify personal data breaches, and a register of breaches (Article 33(5) GDPR).
- Minimisation. Tools collect only the data needed for the features enabled; for mailboxes, only messages matching receipt and invoice searches.
- Subprocessors. Assessed before use and bound by data protection terms.
Annex 3: Subprocessors
See the Subprocessors page.