Data Processing Agreement
Last updated: August 2026 · GDPR Article 28 compliant
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Tenon ("Processor") and the customer ("Controller") using the Meadowlark platform. This DPA applies where the Controller's use of the platform involves processing personal data subject to GDPR or applicable Canadian privacy law.
1. Definitions
- Controller: The customer organization that determines the purposes and means of processing personal data (i.e., you)
- Processor: Tenon, which processes personal data on behalf of the Controller
- Personal Data: Any information relating to an identified or identifiable natural person
- Processing: Any operation performed on personal data, including collection, storage, use, disclosure, or deletion
- Data Subject: An individual whose personal data is processed
2. Roles and Responsibilities
The Controller determines what personal data is entered into the Meadowlark platform and for what purpose. The Processor (Meadowlark) processes this data solely on the instructions of the Controller, as set out in the Terms of Service and this DPA.
The Processor shall:
- Process personal data only on documented instructions from the Controller
- Ensure that authorized personnel are bound by appropriate confidentiality obligations
- Implement appropriate technical and organizational security measures
- Assist the Controller in responding to data subject requests
- Notify the Controller of any personal data breach without undue delay
- Delete or return all personal data upon termination, at the Controller's option
3. Nature and Purpose of Processing
- Subject matter: Construction project management data, including project, financial, personnel, and communication records
- Duration: For the duration of the subscription agreement
- Nature: Storage, retrieval, display, computation, and transmission of data as part of providing the SaaS platform
- Types of personal data: Contact details, employee records, financial information, communications
- Categories of data subjects: Controller's employees, clients, subcontractors, and vendors
4. Security Measures
The Processor implements the following technical and organizational security measures:
- TLS 1.2+ encryption for all data in transit
- AES-256 encryption for sensitive data at rest
- Role-based access controls (RBAC)
- bcrypt password hashing with minimum cost factor of 10
- JWT authentication with short expiration windows
- Automated daily database backups with 30-day retention
- Network firewall and intrusion detection systems
- Access logging for all data operations
- Regular security vulnerability assessments
5. Sub-Processors
The Processor uses the following approved sub-processors. The Controller hereby provides general authorization for the use of these sub-processors, subject to the conditions below:
DigitalOcean, LLC
- Purpose: Cloud infrastructure and hosting
- Location: United States / Canada
- DPA: DigitalOcean GDPR DPA in place
- Website: digitalocean.com
Stripe, Inc.
- Purpose: Payment processing and subscription management
- Location: United States
- DPA: Stripe Data Processing Agreement in place
- Website: stripe.com
- Note: Stripe processes payment card data directly. Meadowlark never receives or stores raw card data.
Resend, Inc.
- Purpose: Transactional email delivery
- Location: United States
- DPA: Resend Data Processing Agreement in place
- Website: resend.com
PostHog (self-hosted)
- Purpose: Product analytics — page views, feature usage, client-side errors
- Location: Same infrastructure as the rest of the platform (self-hosted instance, not PostHog Inc.'s hosted service)
- DPA: Not applicable — self-hosted; no event data is transmitted to PostHog Inc. or any other third party
- Website: posthog.com
Anthropic, PBC (and/or OpenRouter, Inc.)
- Purpose: Large-language-model processing for Sage, the platform's AI assistant (e.g. task summarization, daily-log drafting, document Q&A)
- Location: United States
- DPA: Anthropic / OpenRouter Data Processing Agreement in place
- Website: anthropic.com / openrouter.ai
- Note: Requests route through OpenRouter by default, with direct Anthropic API access as a fallback. Only data the Controller submits to Sage features is sent; it is not used to train third-party models.
Intuit Inc. (QuickBooks Online)
- Purpose: Accounting sync (invoices, bills, time activity) for Controllers who connect their own QuickBooks Online account
- Location: United States
- DPA: Intuit Data Processing Agreement in place
- Website: intuit.com
- Note: Only engaged where the Controller has explicitly authorized the QuickBooks connection; data flows solely for the connected company's own accounting records.
Cloudflare, Inc.
- Purpose: Inbound email routing for the support@usetenon.com support channel
- Location: United States
- DPA: Cloudflare Data Processing Agreement in place
- Website: cloudflare.com
The Processor will inform the Controller of any intended changes to sub-processors (addition or replacement) and give the Controller the opportunity to object to such changes before they take effect.
6. Data Subject Rights
The Processor shall assist the Controller in fulfilling its obligations to respond to data subject requests. Where a data subject contacts the Processor directly, the Processor will promptly refer the request to the Controller.
The Processor will provide reasonable technical assistance to the Controller to enable the Controller to:
- Provide data subjects access to their personal data
- Correct inaccurate personal data
- Delete personal data (right to erasure)
- Export personal data in a portable format
- Restrict or object to processing
7. Personal Data Breach Notification
In the event of a personal data breach, the Processor will:
- Notify the Controller without undue delay and no later than 72 hours after becoming aware of the breach
- Provide information about the nature of the breach, categories and approximate number of data subjects affected, and categories and approximate number of records concerned
- Describe the likely consequences of the breach
- Describe the measures taken or proposed to address the breach
Breach notifications will be sent to the account owner's registered email address and, if critical, by phone to the contact on file.
8. Audit Rights
Upon reasonable written notice (minimum 30 days), the Controller may conduct an audit of the Processor's data processing activities relevant to this DPA, or request a summary of third-party audit reports. Audits will be conducted at the Controller's expense and in a manner that minimizes disruption to the Processor's operations.
9. Data Return and Deletion
Upon termination of the service agreement, at the Controller's written request, the Processor will:
- Return all personal data to the Controller in JSON or CSV format within 30 days
- Securely delete all personal data from production systems within 90 days
- Provide written confirmation of deletion
- Retain billing records as required by applicable tax law (7 years)
10. Governing Law
This DPA is governed by the laws of the Province of Quebec, Canada. It forms part of and is subject to the Terms of Service between the parties.
11. Contact
For questions about this DPA or data processing practices:
Joe Meadows, Privacy Officer
joe@meadowlarkconstruction.ca