Teams Data Processing Addendum
How Activated Human LLC handles personal data on behalf of an organization that buys seats on Teams by Activated Human
Last Updated: September 16, 2026
Key Points at a Glance
For names and work emails you give us, you are the controller and we are the processor.
Members' conversations with Teal are handled on the member's instructions, not yours, because you cannot see them.
Every subprocessor is named below, with what it does. You get 15 days to object to a new one.
We notify you of an incident affecting your personal data within 72 hours of confirming it.
1. What this addendum covers
This Data Processing Addendum ("DPA") is part of the Teams Customer Agreement between Activated Human LLC ("we," "our," or "us") and the organization that buys seats on Teams by Activated Human (the "Customer," or "you"). It applies whenever we process personal data for you in running the service. Words defined in the agreement mean the same thing here.
"Personal data," "controller," "processor," "data subject," and "processing" have the meanings given in the data protection law that applies to you, including the GDPR, the UK GDPR, and the Swiss Federal Act on Data Protection where those apply.
2. Who is controller, and of what
Teams has an unusual shape, and the roles follow it. There are two kinds of personal data in the service, and they have different controllers.
2.1 Data you supply: you are the controller
When you set up a team, you give us member names and work email addresses, seat assignments, and the organization profile. For that data you are the controller and we are your processor. We process it only to run the service for you, as Section 3 says. The Team Mirror and the contributions members send upward belong to this category too, once they exist.
2.2 Data members create: we act on the member's instructions
A member's conversations with Teal, and the work profile Teal writes about that member, are private to the member. You cannot access them by design, and the agreement forbids you from trying. Because you have no access to and no say over that data, we do not process it as your processor. We process it on the member's own instructions, under the consumer Privacy Policy the member accepted. That is the honest description of how the product works, and this DPA does not give you any right over that data.
2.3 Your responsibilities
You are responsible for having a lawful basis to give us member names and work emails, for telling members that you have done so, and for making sure the instructions you give us are lawful.
3. How we process your data
- We process your personal data only on your documented instructions. The agreement, each Order, and this DPA are those instructions. If the law requires us to process it some other way, we will tell you first unless the law forbids that.
- We do not sell your personal data, and we do not share it with anyone for their own purposes.
- We do not combine your personal data with data from other customers, from our other products, or from any outside source.
- We do not use your personal data to train models.
- Everyone who works with your personal data on our side is bound by a confidentiality obligation.
- If we think an instruction breaks data protection law, we will tell you.
4. Subprocessors
You authorize us to use the subprocessors below. Each one receives only the data it needs to do its job, and each is bound by a written contract with data protection terms at least as protective as this DPA. We stay responsible to you for their work.
4.1 Model and speech
- Anthropic. Conversation with Teal and Team Mirror synthesis.
- Groq. Voice note transcription.
- OpenAI. Search index embeddings, and transcription fallback when Groq is unavailable.
4.2 Platform
- Auth0. Sign-in.
- Stripe. Payment.
- SendGrid and Klaviyo. Email.
- PostHog. Product analytics. Usage events only, no message content.
- Sentry. Error reports.
- Twilio. WhatsApp delivery, when a member connects WhatsApp.
- Telegram and Discord. Channel delivery, when a member connects one of them.
Everything else runs on infrastructure we operate. Requests are logged on that infrastructure, not sent to a third party.
4.3 Adding a subprocessor
Before we add a subprocessor, we will email the address on your Order. You have 15 days from that email to object in writing, with your reason. If you object, we will work with you in good faith to find a way forward: a different vendor, a configuration that keeps your data away from the new one, or something else that works. If we cannot find one, you may end the affected Order and we will refund prepaid fees for the unused term.
5. Security
We protect your personal data with measures that fit the risk. They include encryption in transit and at rest, secrets held in a secrets manager rather than in code or configuration files, and role-based access so that people and systems can reach only what their job requires. The private reads described in Section 2.2 are enforced in how the product reads and writes data, not left to policy. Our Security page has more detail and is updated as our practices change.
6. Incidents
If we confirm a security incident that affects your personal data, we will notify the email address on your Order within 72 hours of confirming it. The notice will say what we know at the time: what happened, what data is affected, what we have done, and what we recommend you do. We will keep you updated as we learn more, and we will give you the information you need to meet your own notification duties. Notifying you of an incident is not an admission that we were at fault.
7. Requests from people
People have rights over their personal data: to see it, correct it, delete it, and so on. How we handle a request depends on who controls the data.
- Data you control. If a member or a Customer admin sends us a request about names, work emails, seat assignments, or the organization profile, we forward it to you within a reasonable time and help you respond. We do not answer on your behalf unless you ask us to.
- Data members control. Requests about a member's conversations with Teal, their work profile, or the outputs Teal produced for them go to us directly, and we handle them under the Privacy Policy. We will not forward those to you, because you have no right to that data.
8. Showing you what we do
Once in any 12-month period, you may send us a written security questionnaire and we will answer it, at your cost for any time beyond what a reasonable questionnaire takes. If a data protection authority requires more, or you have a specific reason to believe we are not meeting this DPA, we will agree with you on the scope, timing, and cost of an on-site audit by you or an independent auditor bound by confidentiality. Audits happen during business hours, with reasonable notice, and without disrupting the service.
9. Where processing happens
We process personal data in the United States. Where your personal data is subject to the GDPR, the UK GDPR, or Swiss data protection law, the following applies to its transfer to us and to our subprocessors:
- The EU Standard Contractual Clauses (Commission Decision 2021/914), Module Two (controller to processor), are incorporated into this DPA by reference. You are the data exporter and we are the data importer. Clause 9 uses Option 2, general authorization, with the notice period in Section 4.3. Annexes I and II are filled from Section 4, Section 5, and Section 12 of this DPA. For Clause 17 and Clause 18, the law and courts of Ireland govern. The optional Clause 7 docking clause applies; the optional language in Clause 11(a) does not.
- For UK data, the UK International Data Transfer Addendum to the EU Standard Contractual Clauses (version B1.0) applies with the same information, and its Part 1 tables are completed from the same sections.
- For Swiss data, the Standard Contractual Clauses apply with the adjustments the Swiss Federal Data Protection and Information Commissioner requires.
- Where a subprocessor is certified under the EU-US Data Privacy Framework, the UK Extension to it, or the Swiss-US Data Privacy Framework, we may rely on that certification for the transfer to that subprocessor.
10. When the agreement ends
Deletion at the end of term follows Section 8.3 of the agreement. When your term ends, member seats end with it. Members have 30 days to export their own conversations and work profile. After those 30 days, we delete those member accounts and their data. The Team Mirror and the organization profile, including the member names and work emails you gave us, are deleted at the same time, unless you ask us in writing for an export within the 30 days. Records we are required by law to keep are the exception, and we keep those only as long as the law requires and protect them under this DPA while we do.
11. Order of precedence and changes
If this DPA conflicts with the agreement on how personal data is handled, this DPA wins. If it conflicts with the Standard Contractual Clauses, the Clauses win. We update this DPA the way we update the agreement: by email to the address on your Order, at least 60 days before the change takes effect, except that we may update the subprocessor list under Section 4.3.
12. Schedule: details of processing
Subject matter and purpose
Running Teams by Activated Human for the Customer: setting up and administering a team, giving each member a seat with a private companion, building the Team Mirror, delivering messages over channels a member connects, billing the Customer, and supporting the Customer and its members.
Categories of data subjects
- Members: the people who hold seats on the Customer's team.
- Customer admins: the people who set up the team, manage seats, and handle billing for the Customer.
Categories of personal data processed for the Customer
- Identity and contact data: name, work email address.
- Account and seat data: account identifier, team membership, seat status, role (member or lead).
- Organization profile: what the Customer writes about its team and its mission.
- Contributions members send upward, with or without the member's name, as the member chose.
- The Team Mirror.
- Billing contact and payment details for the Customer admin, held by Stripe.
- Usage events and error reports tied to an account identifier.
Members' conversations with Teal, their work profiles, and the outputs Teal produces for them are not processed for the Customer. See Section 2.2.
Sensitive data
The Customer does not supply sensitive data, and the service does not ask the Customer for any. What a member chooses to write to Teal is the member's own, and is outside this DPA.
Duration
The term of the agreement, plus the 30-day export window in Section 10, plus any period the law requires us to keep specific records.
13. Contact Us
Questions about this DPA, subprocessor objections, and incident correspondence go here:
Legal: [email protected]
Website: https://www.activatedhuman.earth
Activated Human LLC, 2026. All Rights Reserved.