TensorX
TensorX · IE · Last reviewed: 2026-07-27
Data Protection Contracts
100/100TensorX has a complete Data Processing Agreement under Art. 28 GDPR, automatically incorporated into its terms of service.
jaSource: TensorX DPA (Stand Juli 2026), Vollständiges DPA, automatisch in ToS integriert (Art. 28 DSGVO-konform) (reviewed 2026-07-24)
TensorX applies EU Standard Contractual Clauses for its few non-EU sub-processors; core infrastructure remains EU-only.
jaSource: TensorX DPA, §7a – 2021er EU-SCCs per Verweis integriert für außereuropäische Sub-Prozessoren (Resend, Intercom, Attio); UK-Addendum vorhanden (reviewed 2026-07-24)
TensorX contractually commits to notifying security incidents within 72 hours.
jaSource: TensorX DPA, §4.1 – 72 Stunden vertraglich zugesichert, GDPR Art. 33-konform (reviewed 2026-07-24)
Data Residency & Sovereignty
83/100TensorX contractually processes data only within the EEA/UK unless the customer provides prior written consent to an exception.
jaSource: TensorX DPA, §3.1.5 – Verarbeitung außerhalb EWR/UK nur mit vorheriger schriftlicher Zustimmung des Kunden (reviewed 2026-07-24)
The sub-processor list is fully disclosed and the core infrastructure is EU-only. The two non-EU services on that list (Intercom, Railway) touch only account and support data — billing email, support tickets, usage statistics — per written confirmation on 2026-08-05; no prompts, completions, uploads or output content reach either. The status remains partial because the chain includes services outside the EU and TensorX does not yet document a notice period or a right to object to changes, which is what separates it from the providers rated Yes.
teilweiseSource: Schriftliche Auskunft Anthony (TensorX) 2026-08-05 + Sub-Prozessorenliste tensorx.ai/sub-processors, Intercom und Railway verarbeiten ausschließlich Konto- und Supportdaten (Abrechnungs-E-Mail, Support-Tickets, Nutzungsstatistik); keine Inferenz-Payloads (Prompts, Completions, Uploads, Ausgabeinhalte) (reviewed 2026-08-05)
TensorX is an Irish (EU-based) company.
jaSource: TensorX Terms of Service (Stand März 2026) / DPA, Provider firmiert als TensorX (Irland); EU/EWR-Ansässigkeit gemäß Due-Diligence-Datensatz (reviewed 2026-07-24)
Data Use
100/100TensorX contractually processes requests only in ephemeral enclaves without storage (zero data retention).
jaSource: TensorX DPA §3.2 / ToS §3.3, 5.3, Zero-Retention, Verarbeitung nur in ephemeren Enclaves; Inference-Daten nie gespeichert (reviewed 2026-07-24)
TensorX contractually does not use customer data for model training or fine-tuning.
jaSource: TensorX DPA §3.2 / ToS §3.3, 5.3, Explizit kein Training/Fine-Tuning auf Kundendaten (reviewed 2026-07-24)
No opt-out is needed at TensorX, since training and storage are contractually excluded by default.
jaSource: TensorX DPA, Kein Opt-out nötig, da Zero-Retention und Trainingsverbot vertraglich unbedingt gelten (§3.2) (reviewed 2026-07-24)
Certifications
0/100TensorX is not yet ISO 27001 certified; the certification audit is scheduled for 2026-09-10.
neinSource: Letter of Commitment, Amtivo Ireland (Zertifizierungsstelle), gez. Caroline Plumb, Group CEO — 01_TensorX/TensorX_ISO-27001-Letter-of-Commitment_Amtivo_2026-07-21.pdf, Amtivo bestätigt, dass TensorX Limited die Zertifizierung nach ISO/IEC 27001:2022 beauftragt hat; das Assessment ist für den 10.09.2026 gebucht. Ein Zertifikat liegt nicht vor. (reviewed 2026-07-21)
TensorX currently has no SOC 2 or C5 attestation; SOC 2 Type II is planned but not yet started.
neinSource: TensorX Trust-Center, SOC 2 Type II geplant, Audit noch nicht begonnen; kein C5-Testat vorhanden (reviewed 2026-07-23)
AI Act Readiness
50/100TensorX maintains technical documentation under Art. 53 of the EU AI Act and fulfills the corresponding transparency obligations.
jaSource: TensorX Terms of Service (Stand März 2026), §2.3 – Selbstpositionierung als GPAI-Anbieter, technische Dokumentation gemäß Art. 53 KI-VO (reviewed 2026-03-01)
No verifiable commitment
unbelegtSource: TensorX ToS §2.3 + EU GPAI Code of Practice Signatarliste + schriftliche Auskunft Anthony (TensorX) 2026-08-05, Selbsteinordnung als GPAI-Anbieter laut ToS §2.3; Abwesenheit von der Signatarliste; Widerspruch von TensorX eingeräumt und zur Klärung eskaliert (reviewed 2026-08-05)
Contract Quality & Transparency
67/100TensorX's contract documents (ToS, DPA, AUP, SLA, sub-processor list) are publicly available via its Trust Center.
jaSource: TensorX Terms of Service / Trust-Center (tensorx.ai/trust), Öffentlich zugängliche ToS, DPA, AUP, SLA und Sub-Prozessorenliste (reviewed 2026-07-24)
TensorX publishes an SLA document for its service.
jaSource: TensorX SLA (Trust-Center), Separates SLA-Dokument im Compliance-Dossier vorliegend (abgelegt 2026-07-23) (reviewed 2026-07-23)
The cap of twelve months' fees applies one-sidedly to TensorX only, not to the customer, and carries no elevated exceptions — neither for breaches of confidentiality nor for intellectual property or gross negligence. Only what cannot be waived by law is excluded. Against this stands a one-sided, uncapped indemnification duty on the customer that expressly covers breaches of data protection law.
neinSource: TensorX Terms of Service (Stand März 2026, abgelegt 23.07.2026), §7.1 Ausschluss mittelbarer Schäden; §7.2 Liability Cap — 'TensorX's total cumulative liability to you … shall not exceed the amount you paid to TensorX during the twelve (12) months immediately preceding the event', also einseitig; §7.3 Ausnahmen nur für zwingende Verbraucherrechte, Körperverletzung und Arglist; §8 Indemnification — einseitige Freistellung des Kunden, ausdrücklich einschließlich '(iv) your breach of applicable Data Protection Legislation', ohne Deckel. (reviewed 2026-08-24)
Do you represent TensorX and think something is inaccurate? Write to legal@kontinent.ai. We check every report and correct verified errors with full transparency.
Report error