📜 TauOS Data Protection Addendum (DPA)

Sovereign Privacy First Operating System

Document Version: 1.0 Date: August 2025

This Data Protection Addendum ("DPA") forms part of the agreement between Tau LLC ("Processor") and the Customer ("Controller").

1. Purpose

This DPA ensures compliance with global data protection laws (including GDPR) and governs how personal data is processed.

2. Roles

3. Processor Obligations

Tau LLC shall:

  1. Process personal data only on documented instructions from the Controller.
  2. Ensure staff are bound by confidentiality.
  3. Implement technical and organizational measures to protect data.
  4. Assist the Controller in fulfilling obligations under GDPR (e.g., data subject rights, breach notifications).
  5. Delete or return personal data upon termination of services, unless retention is required by law.

4. Sub-processing

5. International Transfers

Data may be transferred outside the user's country, provided that adequate safeguards (e.g., Standard Contractual Clauses) are in place.

6. Security Measures

7. Data Breach

In the event of a personal data breach, Tau LLC will notify the Controller without undue delay and no later than 72 hours.

8. Term

This DPA remains in force for as long as Tau LLC processes personal data on behalf of the Controller.

Signed:

Tau LLC (Processor)

verify@tauos.org

© 2025 Tau Foundation & Tau LLC verify@tauos.org