Data Processing Addendum
This Data Processing Addendum ("DPA") forms part of the agreement between Trooth, LLC ("Trooth," "Processor") and the customer ("Customer," "Controller") for use of the Service. It applies where Trooth processes personal data on Customer's behalf that is subject to data-protection laws including the GDPR, UK GDPR, and applicable U.S. state privacy laws.
1. Definitions and roles
Terms such as "controller," "processor," "personal data," "processing," and "data subject" have the meanings in applicable data-protection law. For Customer Data, Customer is the controller (or processor acting for another controller) and Trooth is the processor (or sub-processor). Trooth processes personal data only to provide the Service and on Customer's documented instructions, including as set out in the agreement and this DPA.
2. Processing of personal data
The subject matter, duration, nature and purpose of processing, types of personal data, and categories of data subjects are described in Annex I. Customer represents that it has a lawful basis and all necessary rights and notices/consents to provide the personal data and to instruct the processing.
3. Trooth's obligations
- Process personal data only on Customer's documented instructions, unless required by law (in which case Trooth will inform Customer unless legally prohibited).
- Ensure persons authorized to process personal data are bound by confidentiality.
- Implement appropriate technical and organizational measures (Annex II).
- Assist Customer, taking into account the nature of processing, in responding to data-subject requests and in meeting security, breach-notification, and impact-assessment obligations.
- Not sell personal data or process it for any purpose other than providing the Service.
4. Security
Trooth maintains the security measures described in Annex II, designed to protect personal data against unauthorized or unlawful processing and against accidental loss, destruction, or damage.
5. Sub-processors
Customer authorizes Trooth to engage the sub-processors listed in Annex III and others added in the ordinary course. Trooth will impose data-protection obligations on each sub-processor substantially similar to those in this DPA and remains responsible for their performance. Trooth will give Customer a means to learn of new sub-processors and a reasonable opportunity to object on reasonable data-protection grounds.
6. Data-subject requests
Taking into account the nature of the processing, Trooth will assist Customer by appropriate measures to fulfill Customer's obligation to respond to requests to exercise data-subject rights. If Trooth receives such a request directly, it will, where lawful, direct the data subject to Customer.
7. Personal-data breaches
Trooth will notify Customer without undue delay after becoming aware of a personal-data breach affecting Customer's personal data and will provide information reasonably available to assist Customer in meeting its notification obligations.
8. Deletion and return
On termination of the Service, Trooth will, at Customer's choice, delete or return Customer's personal data within a reasonable period, and delete existing copies unless retention is required by law. Connected-integration credentials are deleted promptly on disconnection.
9. Audits
Trooth will make available information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by Customer or an auditor mandated by Customer, subject to reasonable confidentiality, scheduling, and security conditions. Trooth may satisfy audit requests by providing relevant documentation or third-party reports where available.
10. International transfers
Where Trooth transfers personal data originating in the EEA, UK, or Switzerland to a country without an adequacy decision, the parties incorporate the European Commission's Standard Contractual Clauses (and the UK Addendum / Swiss amendments as applicable), which are deemed completed with the information in the Annexes.
Annex I - Details of processing
- Controller: Customer. Processor: Trooth, LLC.
- Subject matter: provision of the Trooth trust and compliance Service.
- Duration: the term of the agreement plus any legally required retention.
- Nature and purpose: collecting, recording, organizing, storing, analyzing, and displaying observed evidence and related records to provide the Service.
- Types of personal data: business contact details (name, work email, company), account identifiers, usage/log data, and any personal data contained in connected-system signals or uploaded content that Customer chooses to process.
- Categories of data subjects: Customer's authorized users and personnel, and individuals whose data appears in connected systems or uploaded content.
Annex II - Security measures
- Encryption in transit (TLS) and encryption of sensitive stored fields and credentials at rest (AES-256-GCM).
- Least-privilege access controls and authenticated, tenant-isolated access to data.
- Edge isolation and segregation of customer data by tenant.
- Logging, monitoring, and integrity measures, including tamper-evident records.
- Regular backups with retention, and restricted administrative access.
- Secure software-development and change-management practices.
Annex III - Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Cloudflare, Inc. | Hosting, edge compute, storage, CDN | USA / global edge |
| WorkOS, Inc. | Authentication, single sign-on (SSO), and OAuth | USA |
| Neon, Inc. | Managed PostgreSQL database | USA |
| Vercel, Inc. | Web hosting | Multi-region edge |
| Sentry (Functional Software, Inc.) | Application error tracking | USA |
| Nango (only when a customer connects an integration via OAuth) | OAuth authorization broker | USA |
| Resend | Transactional email | USA |
| Amazon Web Services, Inc. | Cloud storage and key management | United States and European Union |
| Google LLC | Business email and document storage | Multi-region |
| Anthropic, PBC | Internal-use generative AI for productivity | United States |
| UptimeRobot | Availability monitoring | Multi-region |
| GitHub, Inc. | Source control, continuous integration, and storage of the nightly database backup | United States |
Revised September 4, 2026: Stripe, Inc. removed from Annex III. Trooth takes no payment and processes no card data, so no payment processor handles personal data on a customer's behalf. No other sub-processor, obligation or safeguard was changed.
Revised September 4, 2026: Expo (650 Industries, Inc.) removed from Annex III. Trooth distributes no mobile application and sends no push notifications, so no such processing occurs.
Adopted for and on behalf of Trooth, LLC by its Founder.