Roles
When a firm uses Tallia, the firm decides what goes into the platform and why. The firm is the controller of the personal data inside its questions and documents - or, if it is handling that data for its own client, the processor. We process that data only on the firm’s instructions, as its processor.
We are a controller in our own right for a narrower set of data: enquiries made through this website, account administration, and our own business records. That processing is covered by our privacy policy, not by the addendum.
Scope and instructions
We do not process customer personal data other than on the firm’s documented instructions, or where applicable law requires it - and where the law requires it and permits us to say so, we tell the firm first. The agreement and the addendum together are the complete expression of those instructions; further instructions bind us only by written amendment signed by both parties.
If we receive an instruction that in our reasonable opinion infringes data protection law, we say so.
What is processed
| Data subjects | Authorised users, and anyone whose personal data the firm or its users put into the platform. |
|---|---|
| Categories of data | Whatever the firm and its users submit. In practice this commonly includes names, email addresses, and telephone numbers. |
| Special category data | Whatever the firm chooses to submit. We apply one uniform standard of security to all data and systems rather than a separate regime for sensitive categories, so a firm submitting special category data should satisfy itself that standard is adequate for its assessment. |
| Nature of processing | Collection, recording, organisation, structuring, storage, consultation, redaction, analysis, use, combination, restriction, erasure, and destruction - as needed to provide the service. |
| Purpose | Providing the service, and enabling the firm to access and use the platform. |
| Duration | The term of the agreement, and the defined period after it set out below. |
We do not use customer data to train AI models. See our AI use policy.
Security measures
We implement and maintain technical, administrative, physical, and organisational measures designed to protect customer personal data against accidental or unlawful destruction, loss, alteration, and unauthorised disclosure or access. Those measures are described on our security page, and in full in our trust centre - which is the source the addendum refers to.
We may update them to reflect our current standards, provided the change does not materially reduce overall security. Our personnel who process customer personal data are screened and bound by written confidentiality obligations.
Data subject requests
The firm is responsible for responding to requests from its own data subjects. We promptly notify the firm of any request we receive, and we do not respond to it ourselves beyond directing the person to the firm, unless the law requires otherwise. Taking into account the nature of the processing, we give the firm the assistance that is reasonably necessary and technically feasible - including for access, deletion, and stopping processing - and we assist with data protection impact assessments and prior consultations where the law requires it.
Breach notification
We notify the firm without undue delay once we confirm a personal data breach affecting its data, and give it the information we hold so it can meet its own reporting obligations - what happened, the categories and approximate numbers involved, the likely consequences, and what we are doing about it. Early information may be incomplete; notifying is not an admission of fault.
As between us, the firm is responsible for its own notifications to regulators, data subjects, and third parties.
Subprocessors
The firm generally authorises us to appoint subprocessors, and authorises those listed in our subprocessor list as at the start of the agreement. We give notice of a proposed new subprocessor by updating that list, so a firm should subscribe to its updates.
A firm may object within ten business days on evidenced, good-faith grounds that the appointment would put it in material and unavoidable breach of data protection law. We will then use reasonable efforts to offer a commercially reasonable alternative; if none is available within thirty days, either party may terminate the affected processing without penalty.
Every subprocessor is under a written contract offering at least equivalent protection to this addendum, and we remain liable for a subprocessor’s breach of it.
International transfers
Tallia runs as separate regional stacks, so a firm’s primary data stays in its region. Where a transfer out of the UK or EEA is nonetheless involved - typically because of a subprocessor - we make it only with a valid Chapter V transfer mechanism in place, such as the EU Standard Contractual Clauses and the UK International Data Transfer Addendum. The subprocessor list states each provider’s location.
Audits
On reasonable request we make available the information needed to demonstrate our compliance with the addendum. Where a firm can evidence that this is not sufficient, we allow and contribute to an audit, subject to at least fourteen days’ notice, an agreed audit plan, confidentiality undertakings, normal business hours, and no more than once a year - except where a regulator or the law requires more. A current third-party report or certification may be provided in place of on-site access.
Return and deletion
For thirty days after the term ends we keep customer data available so the firm can export it using the platform’s own export tools, unless the firm has told us to delete it sooner. After that we return and delete customer personal data in line with the firm’s instructions in the agreement. Where deleting data held in backups is not technically feasible in that timeframe, we put it beyond use and delete it on our normal backup expiry cycle.
Getting a signed copy
The full addendum is provided with the subscription terms at contracting. For a signed copy, the Standard Contractual Clauses, or answers to a data protection questionnaire, email info@tallia.ai.



