Relay Data Processing Terms
Effective: July 27, 2026
These Data Processing Terms (“DPT”) form part of the Relay Customer Terms or another written agreement that incorporates them (the “Agreement”) between Tidestone Technologies LLC (“Tidestone”) and Customer.
These DPT apply only to Tidestone's processing of Customer Personal Data on Customer's behalf. They do not apply to Tidestone's independent-controller processing of its own account, billing, security, legal-compliance, support-relationship, or business records, as described in the Privacy Notice. Customer-controlled operational content included in a support request remains Customer Personal Data and is governed by these DPT.
Tidestone's business address is:
Tidestone Technologies LLC
1968 S. Coast Hwy #5307
Laguna Beach, CA 92651
1. Definitions
Capitalized terms not defined here have the meanings given in the Agreement.
- “Account Contact” means the notice contact defined in the Agreement. If the Agreement does not define one, it means the email address associated with the Relay account that executed the Agreement for Customer until Customer designates a replacement in writing.
- “Applicable Data Protection Law” means a privacy, data-protection, or data-security law that applies to the processing of Customer Personal Data under the Agreement.
- “Controller” includes a controller, business, or other entity that determines the purposes and means of processing Personal Data.
- “Customer Personal Data” means Personal Data that Tidestone processes on Customer's behalf in connection with Customer's use of Relay, including Personal Data in Customer Data and Customer-specific operational records generated from that use.
- “Data Subject” means an identified or identifiable person to whom Personal Data relates and includes a consumer where applicable.
- “GDPR” means Regulation (EU) 2016/679.
- “Personal Data” includes personal data, personal information, and similar information protected by Applicable Data Protection Law.
- “Personal Data Breach” means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data processed by Tidestone or a Subprocessor on Tidestone's behalf. It does not include an unsuccessful attempt that does not compromise Customer Personal Data.
- “Processor” includes a processor, service provider, contractor, or other entity that processes Personal Data on behalf of a Controller.
- “Restricted Transfer” means a transfer of Personal Data that requires a transfer mechanism under the GDPR or another Applicable Data Protection Law.
- “Subprocessor” means a third party Tidestone engages to process Customer Personal Data on Customer's behalf.
- “UK GDPR” means the GDPR as it forms part of United Kingdom law.
2. Roles, Scope, and Instructions
2.1 Roles
Customer is a Controller or Processor, as applicable, and Tidestone is Customer's Processor or Subprocessor of Customer Personal Data. Each party will comply with the obligations Applicable Data Protection Law assigns to its role.
If Customer is a Processor, Customer confirms that the relevant Controller has authorized Customer's instructions, Tidestone's appointment as another Processor, and Tidestone's engagement of Subprocessors under these DPT.
Customer is responsible for the lawfulness, fairness, and accuracy of Customer Personal Data and Customer's instructions, including providing required notices and obtaining required rights, permissions, consents, and lawful bases. Customer will not instruct Tidestone to process Customer Personal Data in violation of law.
2.2 Instructions
Tidestone will process Customer Personal Data only:
- on Customer's documented instructions;
- to provide, secure, maintain, troubleshoot, and support Relay;
- to perform the processing described in Appendix 1;
- as required by law, in which case Tidestone will notify Customer before processing unless that law prohibits notice; or
- as otherwise agreed in writing.
The Agreement, Customer's configuration and use of Relay, Customer-directed integrations, support requests, and other written directions are documented instructions. Customer may give additional instructions that are consistent with the Agreement. If an instruction requires material work outside Relay's standard operation, the parties will agree on scope, timing, and reasonable fees before Tidestone performs it.
Tidestone will promptly inform Customer if Tidestone believes an instruction violates Applicable Data Protection Law and may pause the affected processing while the parties resolve the issue.
Where the GDPR applies, the legal-requirement exception above is limited to processing required by European Union or member-state law. Where the UK GDPR applies, it is limited to processing required by United Kingdom law. A third-country government demand is handled under Section 10 and any applicable Standard Contractual Clauses.
2.3 Processing Details
Appendix 1 describes the subject matter, duration, nature, purpose, Personal Data, and Data Subjects covered by these DPT.
3. Confidentiality and Personnel
Tidestone will ensure that each person it authorizes to process Customer Personal Data:
- receives access only as needed for that person's duties;
- is bound by an appropriate confidentiality obligation; and
- processes Customer Personal Data only on Tidestone's instructions unless required to do so by law. For processing governed by Article 29 of the GDPR, that exception is limited to European Union or member-state law; for processing governed by the UK GDPR, it is limited to United Kingdom law. A third-country government demand is handled under Section 10 and any applicable Standard Contractual Clauses.
Tidestone remains responsible for its personnel's compliance with these DPT.
4. Security
Tidestone will maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, and unauthorized access. The current service-level measures are described in Appendix 2.
Customer acknowledges that security measures evolve. Tidestone may update them if the update does not materially reduce the overall protection of Customer Personal Data. Customer remains responsible for securely configuring its Relay organization, roles, users, invitations, integrations, contact methods, devices, and Customer-controlled systems.
Relay is not designed for payment-card data, protected health information, government-classified information, or other unsupported regulated or high-risk data identified in the Customer Terms. Customer must not submit that data unless Tidestone agrees in a separate signed writing. Customer may submit a supported credential only through a Relay field specifically designed for that credential.
5. Subprocessors
5.1 General Authorization
Customer gives Tidestone general written authorization to use the providers identified as Tidestone Subprocessors on the current Subprocessor List. Providers listed outside that section are not authorized as Subprocessors by this Section. Tidestone will bind each Subprocessor by a written contract imposing the same data-protection obligations applicable to that Subprocessor's processing under these DPT and Applicable Data Protection Law. Where the GDPR or UK GDPR applies, Tidestone remains fully liable to Customer for the Subprocessor's performance of those obligations. Otherwise, Tidestone remains responsible to the extent required by Applicable Data Protection Law.
5.2 New Subprocessors
Tidestone will update the Subprocessor List and give the Account Contact reasonable advance notice before a new Subprocessor begins processing Customer Personal Data. Customer may object during the notice period on reasonable data-protection grounds through the Company and Contact Notice. Where Applicable Data Protection Law requires an opportunity to object, notice will be early enough to provide a meaningful opportunity before processing begins.
The parties will work in good faith on a reasonable alternative. If none is reasonably available, Tidestone may discontinue the affected optional feature or Customer may terminate the affected Service as its sole remedy for the objection.
An emergency replacement needed to address a security, legal, availability, or provider failure may use a shorter period only to the extent Applicable Data Protection Law and applicable transfer terms permit. If advance notice is impossible, Tidestone will notify Customer without undue delay after engagement, minimize the emergency processing, and provide a prompt practical remedy, including suspension of the affected feature or termination where no lawful alternative exists. Any longer period in executed Standard Contractual Clauses controls.
5.3 Customer-Directed Services
When Customer instructs Tidestone to exchange Customer Personal Data with a Customer-selected service, Customer is responsible for its relationship and lawful instructions to that service. A Customer-selected provider may be Customer's processor or independent controller rather than Tidestone's Subprocessor. Tidestone remains responsible for securely making the exchange as required by the Agreement.
6. Assistance to Customer
6.1 Data Subject Requests
Taking into account the nature of processing, Tidestone will, through appropriate technical and organizational measures insofar as possible, provide reasonable assistance for Customer to respond to a verified request to access, correct, delete, restrict, object to, or export Customer Personal Data, to the extent Customer cannot fulfill the request through Relay and Applicable Data Protection Law requires that assistance.
If Tidestone receives a request that clearly concerns Customer Personal Data, Tidestone will direct the requester to Customer or notify Customer when legally permitted. Tidestone will not independently respond on Customer's behalf unless Customer instructs it or law requires it.
6.2 Compliance Assistance
Taking into account the nature of processing and information available to Tidestone, Tidestone will provide reasonable assistance with:
- security obligations;
- Personal Data Breach notifications;
- data-protection impact assessments; and
- prior consultation with a supervisory authority,
to the extent required by Applicable Data Protection Law for Customer's use of Relay.
Assistance that requires material work beyond Relay's standard functionality may be subject to reasonable fees unless the need arose from Tidestone's breach of these DPT.
7. Personal Data Breaches
Tidestone will notify Customer without undue delay and within any shorter period required by Applicable Data Protection Law after becoming aware of a Personal Data Breach affecting Customer Personal Data. This does not extend an immediate-notice duty triggered by law. Notification will include information reasonably available to Tidestone about:
- the nature of the breach;
- the categories and approximate numbers of affected Data Subjects and Personal Data records;
- likely consequences;
- measures taken or proposed to address and mitigate the breach; and
- a contact for follow-up.
Tidestone may provide information in phases as it becomes available. Notification is not an admission of fault or liability. Customer is responsible for deciding whether to notify a person, regulator, or other party, except for a notification Tidestone must make directly by law.
Tidestone will take reasonable steps to contain, investigate, mitigate, and remediate a Personal Data Breach within its responsibility and will reasonably cooperate with Customer.
8. Return, Export, and Deletion
During the term, Customer may use available Relay functionality or submit a written request for a reasonable export of Customer Personal Data.
After the services involving processing end, Tidestone will, at Customer's choice, return all Customer Personal Data and delete existing copies, or delete all Customer Personal Data and certify completion, unless storage of specified Customer Personal Data is required by law. For the processor terms required by Article 28(3)(g) of the GDPR, that storage exception is limited to European Union or member-state law; for the corresponding UK GDPR processor terms, it is limited to United Kingdom law. Executed Standard Contractual Clauses or another transfer instrument may separately govern retention required by third-country law and the controls in Sections 10 and 12. If law or an applicable transfer instrument requires storage, Tidestone will identify the requirement when legally permitted, protect the retained data under these DPT and the applicable transfer instrument, process it only for that requirement, and delete it when the required period ends. If Customer does not make a choice after reasonable written notice, Tidestone will delete the Customer Personal Data.
Copies in backups may remain until overwritten through the documented backup lifecycle, provided they remain protected, are put beyond active use, are not used for another purpose, and are deleted or returned if restored. Information Tidestone retains in an independent-controller capacity is governed by the Privacy Notice rather than this Section.
Organization archive is reversible retention and is not a deletion request. Personal-account deletion does not automatically delete Customer-controlled operational history or another user's or organization's data.
9. Information and Audits
Tidestone will make information reasonably necessary to demonstrate compliance with these DPT available to Customer. Tidestone may first satisfy a request through current policies, architecture and security summaries, third-party reports available to Tidestone, written responses, or a remote review.
Customer may conduct or commission one reasonable audit, assessment, or technical and operational test in a 12-month period by giving at least 30 days' notice. The information methods above should be used when they can reasonably satisfy the request. Additional reviews are allowed when required by a regulator, after a material Personal Data Breach affecting Customer Personal Data, or when Customer has credible evidence of material noncompliance. Reviews must:
- be limited to systems and records relevant to Customer Personal Data;
- occur during normal business hours without unreasonably disrupting operations;
- protect other customers, security information, and Tidestone Confidential Information;
- for a formal on-site audit, use an independent qualified auditor who is not Tidestone's competitor and is bound by confidentiality; document, remote, and manual reviews may instead be performed by qualified Customer personnel bound by confidentiality; and
- avoid access to another customer's data or information that would create a security risk.
A penetration test, vulnerability scan, or other active technical test requires a mutually agreed written scope, method, timing, safety controls, and remediation process. Customer must not conduct destructive testing or access another customer's environment.
To the extent Applicable Data Protection Law permits, Customer bears its review costs and Tidestone's reasonable costs for material assistance, unless the review identifies Tidestone's material breach of these DPT. Nothing in this Section requires Tidestone to disclose another customer's information, privileged material, penetration-test details that would create risk, or credentials.
Frequency, notice, method, confidentiality, and cost restrictions in this Section apply only to the extent consistent with Applicable Data Protection Law and any applicable Standard Contractual Clauses.
10. Government and Legal Requests
Unless law prohibits it, Tidestone will notify Customer before disclosing Customer Personal Data in response to a government or legal demand. Tidestone will review the demand and, where reasonable and legally available, challenge a demand that appears unlawful, overbroad, or inconsistent with the requesting authority's powers. Tidestone will disclose only the Customer Personal Data it reasonably believes must be disclosed. For a Restricted Transfer, the applicable Standard Contractual Clauses and completed transfer assessment control any additional notice, review, challenge, documentation, and suspension duties.
11. U.S. State Privacy Terms
To the extent a U.S. state privacy law applies and Customer discloses Customer Personal Data to Tidestone as a service provider, contractor, or processor, the parties agree that:
- Customer discloses Customer Personal Data to Tidestone only for the limited and specified business purposes listed in Appendix 1, not for use of Relay generally;
- Tidestone will comply with all provisions of the applicable law and regulations assigned to its service-provider, contractor, or processor role;
- Tidestone will not sell or share Customer Personal Data or use it for cross-context behavioral advertising;
- Tidestone will not retain, use, or disclose Customer Personal Data outside the direct business relationship or for a purpose other than the specific business purposes, except as permitted by applicable law;
- Tidestone will not combine Customer Personal Data with Personal Data received from another person or from Tidestone's own interaction with a person except as permitted by applicable law;
- Tidestone will provide the same level of privacy protection required of Customer for the covered processing;
- Tidestone will notify Customer if Tidestone determines it can no longer meet these obligations;
- Customer may take reasonable and appropriate steps to verify compliant use and to stop and remediate unauthorized processing, including through reasonable manual review, assessment, audit, or technical and operational testing;
- Tidestone will provide reasonable assistance with covered consumer requests and, to the extent applicable to the covered processing, Customer's cybersecurity audits, risk assessments, and automated-decisionmaking obligations; and
- each Subprocessor contract covering that Customer Personal Data will impose the requirements applicable to the subprocessing under the relevant state law and regulations.
Tidestone certifies that it understands and will comply with the restrictions in this Section. Customer may monitor Tidestone's compliance through Section 9.
For processing covered by this Section, an additional instruction changes the permitted purposes only through a written amendment that specifically identifies the added limited business purpose.
12. International Transfers
Customer authorizes Tidestone and its Subprocessors to process Customer Personal Data in the United States and the other locations identified in the Subprocessor List. This authorization is a documented processing instruction and does not replace a transfer mechanism required by Applicable Data Protection Law.
If a Restricted Transfer requires the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, Swiss adaptations, or another safeguard, the parties will cooperate in good faith to execute the required terms and complete any legally required assessment. The applicable executed transfer terms control if they conflict with these DPT. Customer must contact Tidestone and receive written confirmation that the required mechanism is in place before submitting Customer Personal Data in a Restricted Transfer. Tidestone may delay the affected processing until then and will not knowingly initiate the Restricted Transfer without the required mechanism.
13. General
These DPT begin when they are validly incorporated into the Agreement and Tidestone first processes Customer Personal Data, and they continue until Tidestone no longer holds Customer Personal Data subject to them.
If these DPT conflict with the Agreement, these DPT control for Customer Personal Data. The applicable Standard Contractual Clauses control over both for a Restricted Transfer. Liability under these DPT is subject to the Agreement's liability terms except to the extent the applicable Standard Contractual Clauses or law prohibit that limitation.
Tidestone may make administrative, clarifying, or legally required updates that do not materially reduce Customer's rights or expand Tidestone's processing. A material adverse change requires Customer's affirmative agreement unless applicable law requires the change, in which case Tidestone will give as much advance notice as legally permitted. Every material revision will have a new effective date. No update applies retroactively to excuse a prior breach.
Appendix 1 — Processing Description
| Item | Description |
|---|---|
| Subject matter | Operating Relay as an organization-scoped incident-response, on-call, alerting, notification, integration, support, and collaboration service |
| Duration | The Service term plus the period needed for return or deletion and ordinary backup overwrite; longer only when law requires storage as stated in Section 8 |
| Nature of processing | Collection, receipt, recording, organization, structuring, storage, retrieval, consultation, use, transmission, delivery, alignment, combination, restriction, export, return, and deletion, as configured or instructed by Customer |
| Purposes | Providing, securing, maintaining, troubleshooting, and supporting Relay; applying Customer-configured memberships, roles, and organization access; coordinating on-call work and incidents; receiving Signals; delivering alerts and notifications; operating Customer-directed integrations; and preventing misuse |
| Frequency | Continuous or event-driven according to Customer's use, configuration, integrations, schedules, incidents, and delivery choices |
Data Subjects
- Customer's authorized users, administrators, employees, contractors, invitees, and former members;
- responders, on-call participants, notification subscribers, alert recipients, and support participants;
- people identified in Customer Data or Customer-directed integration payloads; and
- Customer's business contacts and representatives.
Categories of Customer Personal Data
- identity and contact data, including names, email addresses, phone numbers, timezones, profile fields, and identifiers;
- organization, membership, role, permission, invitation, team, service, schedule, rotation, on-call, override, and maintenance information;
- incident, Signal, alert, note, tag, status, responder, acknowledgement, resolution, timeline, audit, and source-history information;
- notification preferences, alert policies, subscriptions, quiet hours, readiness, device, push-token, delivery, suppression, and interaction data;
- integration data, including provider identifiers, payloads, OAuth and permission metadata, webhook data, channel and user mappings, and automation results;
- support messages and context Customer submits through Relay.
Sensitive Data
Relay is not intended for the unsupported regulated or high-risk data listed in the Customer Terms, including special-category and criminal-offense personal data protected by Articles 9 or 10 of the GDPR or an analogous law. Customer Personal Data may nevertheless reveal work schedules, availability, phone numbers, security events, system incidents, or other information that warrants careful protection. Customer is responsible for deciding what to submit and for applying appropriate access controls.
Appendix 2 — Technical and Organizational Measures
This Appendix summarizes service-level measures for Relay's production environment. Tidestone will maintain measures appropriate to the risk while these DPT are in effect, subject to Section 4.
Access and Tenant Controls
- organization-scoped data access and explicit authorization checks;
- role- and permission-based controls for administrative and sensitive actions;
- least-privilege service identities and private-network placement for stateful production systems;
- separate production and nonproduction accounts, configuration, credentials, and secrets; and
- revocable sessions, integration credentials, and device registrations where supported.
Encryption and Secrets
- encrypted network transport for public production traffic and supported provider API connections;
- encryption at rest for the production database, backups, cache, block storage, secrets, and supported provider credentials;
- managed key and secret storage; and
- controls intended to protect supported provider credentials in storage, API responses, audit diffs, and client-visible errors.
Availability and Recovery
- deletion-protected production data infrastructure and managed multi-zone data-store capacity;
- database backups and retained recovery snapshots under configured lifecycle controls;
- durable queues and database-owned delivery work for retryable operations; and
- monitoring, alarms, and recovery-oriented deployment controls.
Logging, Monitoring, and Development
- configured retention controls for request diagnostics and selected operational logs;
- request identifiers, safe error causes, and delivery history for investigation;
- automated tests, configuration validation, and controlled deployment artifacts; and
- separation of provider secrets from source control and controls intended to prevent secrets from appearing in customer-visible output.
Data Lifecycle and Incident Handling
- cleanup jobs for selected diagnostic, rate-limit, and dedicated Telnyx communication-ledger records;
- retained operational evidence and the incident-response commitments in Section 7 to support investigation, containment, remediation, and Customer notification after a Personal Data Breach; and
- restrictions on unsupported regulated and high-risk data.
Physical Security
Tidestone relies on its hosting providers for data-center physical and environmental safeguards and maintains reasonable safeguards for Tidestone-controlled endpoints and workspaces.