1. The two things this notice keeps apart
This notice is about tokenobserve.com, the marketing website you are reading. Tenhaw LTD is the controller for the small amount of personal data that website processes, and clauses 2 to 12 describe all of it.
It is not a notice about your Token Observe deployment. Token Observe is self-hosted software: it runs inside your network, on infrastructure you control, against your own model-provider accounts using keys you supply. Whatever personal data passes through it is processed by you, under your own controllership, and supplying the software does not make Tenhaw a processor of it — not because a contract says so, but because no copy of it reaches us and there is no vendor-operated component anywhere in the request path. Clauses 13 to 15 set out that position, the narrow arrangements that would change it, and what a deployment actually holds, so that your own data protection officer knows where to look.
If you are completing a supplier assessment, those two halves usually map to different questions on the same form. Answering both from one paragraph is where most vendor notices go wrong, and it is the reason this one is shaped the way it is.