Data Processing Addendum (DPA)
Effective date: 2026-07-07 (draft) · Version: 0.9
This DPA forms part of the agreement between the Customer ("Controller") and TXR Enterprises LLC, a Wyoming, United States limited liability company ("CINTA", "Processor") for the CINTA platform (the "Service"). It applies where CINTA processes personal data on the Customer's behalf under Ley 1581 de 2012 (Colombia), GDPR/UK-GDPR, and other applicable data-protection laws.
Draft v0.9 — pending review by licensed counsel before production use. Review with counsel; attach as an addendum to the master agreement. Pair with the live Subprocessors list and the Privacy Policy.
1. Roles
The Customer is the Controller; CINTA is the Processor acting on the Customer's documented instructions. For CINTA's own account/billing data, CINTA is an independent controller (see Privacy Policy).
2. Scope & subject matter
Subject matter: processing necessary to provide the Service.
Duration: the term of the agreement plus the retention period in §8.
Nature & purpose: hosting, AI inference (hybrid local/cloud routing), automation execution, memory, integrations, billing/metering, support.
Data types: account identifiers, content the Customer submits, connected- account data, usage/telemetry.
Data subjects: the Customer's authorized users and the individuals represented in the Customer's content.
3. Processor obligations
CINTA will: (a) process only on documented instructions; (b) ensure personnel are bound by confidentiality; (c) implement the security measures in §6; (d) assist the Controller with data-subject requests and DPIAs to the extent reasonable; (e) make available information needed to demonstrate compliance.
4. Subprocessors
The Controller authorizes CINTA to engage the subprocessors listed in Subprocessors. CINTA imposes data-protection terms on each no less protective than this DPA and remains responsible for their performance. CINTA will give notice of new subprocessors with a reasonable window to object.
5. International transfers
Where personal data is transferred across borders, CINTA relies on appropriate safeguards (e.g. Standard Contractual Clauses). EU data-residency is available for eligible plans on request.
6. Security measures (Annex II)
Encryption in transit (TLS) and at rest for sensitive secrets (OAuth tokens via AES-256-GCM).
Tenant isolation by
workspace_idat the application layer + database row-level security as a second layer.Access control (least privilege), authenticated APIs, secret rotation, per-identity rate-limiting.
Audit logging of security and billing events; owner-access auditing.
Backups and recoverability of the canonical datastore.
7. Personal-data breach
CINTA will notify the Controller without undue delay after becoming aware of a personal-data breach affecting the Customer's data, with information then available to help the Controller meet its notification duties.
8. Deletion & return
On termination, CINTA will delete or return the Customer's personal data within 30 days, except where retention is legally required. The Customer may export data at any time via the platform DSR/export path.
9. Audits
CINTA will respond to reasonable audit requests, including via third-party reports/attestations where available, subject to confidentiality and without compromising other customers' security.
10. Liability
Liability under this DPA is subject to the limitations in the master agreement / Terms of Service.
Annex I — Parties & processing
Controller: the customer entity identified in the applicable order form · Processor: TXR Enterprises LLC. Processing details as described in §2.
Annex II — Security measures
As described in §6.
Annex III — Subprocessors
See the live list: Subprocessors.
Draft v0.9 — pending review by licensed counsel before production use. Last updated: 2026-07-07 (draft).
