Tandem

Last updated June 24, 2026

Data Processing Addendum

This Data Processing Addendum is a starting point for customer contracts where Tandem processes personal data on behalf of a customer.

These pages are product-specific starting documents, not legal advice. Replace bracketed business details and have counsel review them before selling Tandem or publishing them to customers. Remove this draft banner after legal sign-off.

Roles

For customer workforce data, the customer is the controller and Tandem is the processor. Tandem processes personal data only to provide, secure, support, maintain, and improve the service, and as instructed by the customer or required by law. Tandem may act as an independent controller for its own billing, account administration, support, security, legal, and product communications.

Processing details

  • Subject matter: field workforce management and related operational records.
  • Duration: the subscription term plus deletion, backup, and legal retention periods.
  • Categories of data subjects: customer admins, schedulers, managers, supervisors, workers, contractors, and support contacts.
  • Categories of data: account, workforce, schedule, location, attendance, forms, attachments, safety reports, notification, support, and security data.
  • Special category or sensitive data: customers must not upload healthcare-regulated data or PHI. Accident, absence, certification, or safety records may contain sensitive data and must be configured lawfully by the customer.

Processor obligations

  • Process customer personal data only under documented instructions.
  • Inform the customer if Tandem believes an instruction infringes applicable data protection law.
  • Restrict personnel access to people with a business need.
  • Ensure authorized personnel are bound by confidentiality obligations.
  • Use appropriate technical and organizational security measures.
  • Assist with data subject requests, security incidents, impact assessments, and regulator inquiries where legally required.
  • Delete or return customer personal data at the end of the services, subject to backup and legal retention needs.

Customer obligations

  • Give lawful, documented processing instructions to Tandem.
  • Provide workers and other data subjects with required privacy and monitoring notices.
  • Select and document the lawful basis for workforce monitoring, location tracking, attendance records, forms, and safety workflows.
  • Configure access roles, retention, exports, corrections, and deletion requests in line with customer policies and law.
  • Do not upload prohibited data, including healthcare-regulated records or PHI.

Security measures

  • Tenant-scoped database access controls and row-level security.
  • Role-based access control for admins, schedulers, and workers.
  • Private file storage with signed upload and download URLs.
  • Transport encryption for production web, API, and mobile traffic.
  • Audit and activity records for key workflow events.
  • Service-role secrets kept server-side only.
  • Public legal pages and mobile monitoring disclosure before monitored workflows.
  • Operational monitoring, backup, incident response, and dependency vulnerability management before paid sale.

Subprocessors

Tandem may use subprocessors listed at /subprocessors. Customers should receive notice of material subprocessor changes and an opportunity to object where required by contract or law.

Security incidents

Tandem should notify affected customers without undue delay after becoming aware of a confirmed personal data breach affecting customer personal data. The notice should include known facts, affected data categories, likely consequences, remediation steps, and information reasonably needed for the customer to meet its own notification obligations.

Audit and compliance

Tandem should make reasonable security and compliance information available to customers, including this DPA, the Subprocessor List, security summaries, and responses to proportionate audit questions. Any on-site or invasive audit rights should be controlled by a signed customer agreement to protect other customers and Tandem security.

International transfers

If Tandem transfers personal data outside the UK, EEA, or another protected region, Tandem will use appropriate safeguards such as adequacy decisions, standard contractual clauses, UK addendum terms, or another lawful transfer mechanism.

Deletion and return

On termination or written request, Tandem should delete or return customer personal data unless law or legitimate retention needs require continued storage. Backup copies may remain until overwritten under the backup lifecycle and should be protected from ordinary production access.