Stay Compliant 
with Tenon

Tenon is built with compliance top of mind, so you can market confidently
while staying protected.

Confident businessman in glasses smiling with arms crossed in a modern office.

Built-in compliance protection for your brand—
powered by Tenon, built on ServiceNow.

In today’s dynamic regulatory environment, it’s essential to have a platform that evolves with the law. At Tenon, we stay focused on key regulations like TCPA, CCPA, GDPR, CAN-SPAM—so you have the tools and guidance needed to minimize risk with confidence.

More on Trust & Compliance

Learn more about best practices for SMS compliance

Tenon not only complements existing CRM opportunities but expands your reach directly to additional C-suite executives, and their budgets, including CMOs and marketing leaders, broadening your potential client base and deal size.

Marketing work managment

Learn more about best practices for Email compliance

Marketing Automation is a critical component of a comprehensive CRM strategy. Without it, businesses cannot effectively nurture leads, personalize campaigns, or evaluate their success. Together, Tenon and ServiceNow complete the CRM puzzle for our customers.

Learn More
Marketing Automation

Our ServiceNow Build Partnership

At the heart of Tenon is our connection with ServiceNow.

Learn More
Man working at desk

Tenon Compliance FAQs

Data Protection & Privacy Regulations

Is Tenon GDPR compliant?

Yes, Tenon is fully GDPR compliant. We act as a Data Processor under GDPR, processing personal data strictly according to our customers' instructions. Our Data Processing Agreement (DPA) incorporates the 2021 Standard Contractual Clauses for international data transfers. We support all data subject rights including access, rectification, erasure, and portability. Since Tenon operates within your ServiceNow instance, your data benefits from ServiceNow's robust GDPR compliance framework.

How does Tenon handle CCPA compliance?

Tenon supports CCPA compliance by enabling our customers to fulfill California residents' privacy rights. We provide mechanisms for managing access requests, deletion requests, and opt-out preferences directly within the ServiceNow platform. Our DPA includes CCPA-supporting provisions, and we maintain transparency about our sub-processors. Importantly, we do not sell personal information and process data solely as a service provider under CCPA definitions.

How quickly will Tenon notify us of a data breach?

In the unlikely event of a data breach affecting personal data, Tenon commits to notifying affected customers within 72 hours of becoming aware of the incident. Our notification will include the nature of the breach, categories of data affected, measures taken to address the breach, and recommended mitigation steps. Since your data resides within your ServiceNow instance, you also benefit from ServiceNow's enterprise-grade security monitoring and incident response capabilities.

ServiceNow Platform Security & Compliance

How does Tenon leverage ServiceNow's security certifications?

As a native ServiceNow application, Tenon inherently has many of the same security benefits of ServiceNow's extensive compliance certifications, including SOC 2 Type II, ISO 27001, ISO 27018, and FedRAMP authorization. Your Tenon data never leaves your ServiceNow instance without being encrypted at rest and in transit, meaning it's protected by the same security controls, encryption standards, and access management systems that protect your other ServiceNow data.

Where is our data stored when using Tenon?

All Tenon application data remains exclusively within your ServiceNow instance, stored in the data center region you've selected for your ServiceNow deployment. We do not replicate or store your data in any external systems. The only exceptions are when you explicitly configure integrations with authorized sub-processors (like Mailgun for email delivery or Sinch for SMS), where only the minimum necessary data is shared for service delivery. ServiceNow's data residency commitments fully apply to your Tenon data.

Does Tenon have its own SOC 2 or ISO 27001 certification?

While Tenon does not currently hold independent SOC 2 or ISO 27001 certifications, your data resides within your ServiceNow instance which maintains these certifications.  The only exceptions are when you explicitly configure integrations with authorized sub-processors (like Mailgun for email delivery or Sinch for SMS), where only the minimum necessary data is shared for service delivery. This means your data is protected by ServiceNow's certified security controls, though Tenon as an application has not undergone separate certification audits. We maintain our own Information Security Program aligned with industry standards, including encryption, access controls, vulnerability assessments, and security training for all personnel with data access.

Email & SMS Marketing Compliance

How does Tenon ensure CAN-SPAM compliance?

Tenon includes built-in CAN-SPAM compliance features for all email marketing activities. Every marketing email can automatically includes an unsubscribe link, your physical mailing address, and accurate sender information. Opt-out requests are processed immediately, with suppressions applied across all campaigns. Our platform prevents sending to unsubscribed contacts and maintains detailed audit logs of all consent changes. We also ensure proper email header information and prohibit misleading subject lines.

What TCPA compliance features does Tenon offer for SMS marketing?

Tenon provides comprehensive TCPA compliance tools for SMS marketing, including mandatory opt-in capture with timestamp recording, automatic STOP/HELP keyword processing, time-zone aware sending to respect quiet hours (8 AM - 8 PM local time), and complete consent audit trails. We support the latest FCC requirements including processing of additional opt-out keywords (END, CANCEL, UNSUBSCRIBE, QUIT). Our SMS features integrate with Sinch, which maintains its own TCPA compliance standards.

How are unsubscribe requests processed?

Unsubscribe requests are processed immediately upon receipt. For email, clicking the unsubscribe link and confirming on the respective page instantly updates the contact's subscription status in your ServiceNow instance, preventing any further marketing emails. For SMS, STOP keywords are processed automatically by our SMS provider (Sinch) and synchronized back to ServiceNow in real-time. All unsubscribe actions are logged with timestamps and source information for compliance auditing. Re-subscription requires explicit opt-in consent from the contact.

Consent Management

1How does Tenon capture and store consent?

Tenon captures consent through multiple channels including web forms, landing pages, API integrations, and manual entry. Each consent record includes the timestamp and specific purpose data. Consent data is stored directly in your ServiceNow instance with full audit trails. We support granular consent for different communication types (email, SMS) and purposes (marketing, transactional), allowing contacts to customize their preferences rather than requiring all-or-nothing consent.

Does Tenon support double opt-in?

Yes, Tenon fully supports double opt-in (confirmed opt-in) workflows. When enabled, new subscribers receive an automatic confirmation email requiring them to verify their subscription before receiving marketing communications. This feature is particularly important for compliance in countries like Germany where double opt-in is effectively required. The confirmation process includes customizable emails and detailed tracking of both the initial sign-up and confirmation timestamps.

Data Processing & Sub-processors

Which sub-processors does Tenon use and why?

Tenon uses a limited number of carefully vetted sub-processors:

  • BeeFree: Email template design and editing (receives template data only, no personal data)
  • Mailgun: Email delivery services (processes email addresses, message consent, and personalization data)
  • Sinch: SMS delivery services (processes phone numbers, message consent, and personalization data)
  • AWS: Landing page and MMS image hosting infrastructure (stores landing pages and MMS images)

All sub-processors are contractually required to maintain GDPR compliance and implement appropriate security measures. We provide 10 days advance notice of any sub-processor changes through our trust page.

Can we object to new sub-processors?

Yes, customers have the right to object to new sub-processors on reasonable data protection grounds. We provide at least 10 days advance notice of any additions or replacements to our sub-processor list via our trust page (tenonhq.com/trust). If you object, we'll work with you to address your concerns or provide alternative solutions.

Security Measures & Access Control

What security measures does Tenon implement?

Tenon implements comprehensive security measures including:

  • Encryption: All data encrypted in transit (TLS 1.2+) and at rest
  • Access Controls: Role-based access with principle of least privilege, multi-factor authentication support
  • Security Monitoring: Regular vulnerability assessments and security updates
  • Personnel Security: Background checks, confidentiality agreements, and annual security training for all staff
  • Development Security: Secure coding practices, code reviews, and security testing in our SDLC

Since Tenon runs within ServiceNow, you also benefit from ServiceNow's additional security layers including DDoS protection, intrusion detection, and 24/7 security operations center monitoring.

How does Tenon handle role-based access control?

Tenon leverages ServiceNow's robust role-based access control (RBAC) system, allowing granular permission management. Administrators can create custom roles defining access to specific features, data fields, and actions. For example, marketing managers might have full campaign creation rights while analysts have read-only access to performance data. Field-level security enables hiding sensitive information from certain roles. All access is logged and auditable, with regular access reviews recommended as part of security governance.

Data Portability & Retention

How can we export data from Tenon?

Tenon provides multiple data export options to support portability requirements. Since all data resides in your ServiceNow instance, you can use ServiceNow's native export capabilities including CSV downloads, Excel exports, and API access. Exports can be scheduled, filtered, and formatted to meet various compliance and operational needs. All export activities are logged for audit purposes.

What are Tenon's data retention policies?

Tenon does not impose its own data retention periods – you maintain full control over retention within your ServiceNow instance. We provide tools to implement automated retention policies including scheduled deletion of inactive contacts, automatic purging of old campaign data, and consent expiration management. Upon contract termination, we assist with data export or deletion as requested.

Customer Responsibilities

What are your responsibilities as the Data Controller?

As the Data Controller, you are responsible for:

  • Legal Basis: Determining and documenting the lawful basis for processing personal data
  • Consent: Obtaining valid consent where required and maintaining proof of consent
  • Privacy Notices: Providing transparent privacy notices to data subjects
  • Data Minimization: Collecting only necessary data for stated purposes
  • Accuracy: Ensuring personal data remains accurate and up-to-date
  • Security: Implementing appropriate access controls within your ServiceNow instance
  • Training: Ensuring your team understands compliance requirements
  • Vendor Management: Reviewing and approving our DPA and sub-processor list
  • And more: Tenon is not your legal team, and you are responsible for understanding your commitments and responsibilities as a Data Controller

We provide tools and features to support these obligations, but ultimate compliance responsibility remains with you as the Controller. Our support team is available to provide guidance on using Tenon's features for compliance purposes.

Connect Marketing to ServiceNow

Get your personalized Tenon tour.

Request a Demo

Two team members smiling while having a conversation with other marketers in their team