Telluris
Data processing agreement
Legal information and terms for the Telluris private beta.
1. Purpose and roles
This agreement supplements the contract between TELLURIS SAS and the customer for personal data processed on its behalf. The customer acts as controller, or as an authorised processor for its own principal; Telluris acts as processor or subprocessor. Telluris’s own processing is described in the privacy policy.
The agreement applies during service provision and the agreed return or deletion operations. It must be accepted with completed annexes before personal data are entrusted to Telluris on the customer’s behalf.
2. Processing description — annex to complete
The service includes hosting, organising, consulting, modifying, authorised sharing, returning and deleting data within well and drilling dossiers.
Expected categories include professional identities and contact details, roles, contributions and personal data in uploaded documents. Individuals may include customer employees, contractors and contacts. Before signature, the customer must specify the actual categories, purposes, volumes, duration and any special categories; this indicative list does not authorise all categories by default.
3. Instructions and confidentiality
Telluris processes data only on documented customer instructions, including for transfers, unless legally required otherwise. In that case it informs the customer before processing unless legally prohibited. Telluris immediately informs the customer if an instruction appears to breach data protection rules.
Telluris ensures authorised persons are bound by confidentiality and access only data needed for their tasks. This agreement does not authorise reuse for unspecified independent purposes.
4. Security — annex to validate
Telluris implements technical and organisational measures appropriate to risk under GDPR Article 32. The security annex must describe access controls, communication confidentiality, permission and incident management, backups, restoration and deletion.
The reviewed configuration includes private administration access, encrypted PostgreSQL connections with certificate verification and application permissions by organisation and dossier. Verification of the actual deployment, backups and restoration tests remains to be recorded; this draft does not certify a standard or service level.
5. Subprocessors
The customer authorises the subprocessors listed in the accepted annex for the activities described there. Telluris imposes equivalent data protection obligations and remains responsible to the customer for performance of their processing obligations.
Before adding or replacing a subprocessor, Telluris gives written notice and sufficient time for a reasoned objection before the new processing. The notice period and resolution procedure must be specified in the annex before signature.
The inventory to classify includes Scaleway, Resend, Sentry, Geoapify, Google Workspace and operational providers according to actual access. PostHog must be classified separately according to Telluris’s own purposes. The technical list in the privacy policy is not, by itself, subprocessing authorisation.
6. Assistance and personal data breaches
Taking account of the nature of processing and available information, Telluris assists with data subject requests and security, notification, impact assessment and prior consultation obligations. Requests received concerning customer data are forwarded to the customer.
Telluris notifies the customer of a personal data breach without undue delay after becoming aware of it. Notice provides available information about the breach, affected individuals and data, likely consequences, measures taken or proposed and a follow-up contact, supplemented as information becomes available. The customer’s emergency contact must be included in the annex.
7. International transfers
Transfers outside the European Economic Area must comply with documented instructions and GDPR Chapter V. The annex must identify countries, recipients, applicable mechanisms and necessary supplementary safeguards. A European endpoint alone does not establish the absence of transfers.
Using Resend requires reviewing its stated US storage. Contractual safeguards and their applicability to Telluris’s account must be verified before signature; no unverified safeguard is deemed established by this draft.
8. End of service and verification
At the end of service, at the customer’s choice, Telluris returns or deletes personal data and deletes copies unless retention is legally required. The annex specifies formats, deadlines, backup handling and deletion confirmation.
Telluris provides information needed to demonstrate compliance, allows audits and inspections by the customer or its appointed auditor and contributes to them. Practical arrangements protect security and other customers’ confidentiality without preventing the GDPR’s audit rights.