Back to home

Data Processing Agreement (summary)

Last updated: 24 July 2026

This summary applies where TrustRespond.ai processes personal data on a customer's documented instructions. A signed order form or DPA may add project-specific terms and takes precedence where it expressly differs.

1. Roles and subject matter

The customer is controller and TrustRespond.ai is processor for personal data contained in documents, questionnaires and generated results. Processing supports questionnaire preparation, source matching, review and export for the contract term.

2. Instructions and confidentiality

Data is processed only to provide, secure and support the agreed service or comply with law. Authorised persons are bound by confidentiality. Customer content is not used by TrustRespond.ai to train its own public model.

3. Current subprocessors

ProviderFunctionCurrent location/configuration
VercelApplication hosting and functionsFrankfurt (fra1)
SupabaseDatabase, authentication and storageFrankfurt (eu-central-1)
Google Gemini APIAI inference using Gemini 2.5 FlashProvider-managed processing
Zoho MailTransactional emailProvider-managed processing

Material changes to subprocessors will be communicated as required by the executed customer agreement.

4. Technical and organisational measures

Measures include HTTPS transport, authenticated access, workspace-scoped application access, restricted administrative access, environment-managed secrets, review-based deployments and incident handling. Current limitations, including the absence of a separate automated application backup, are disclosed in the Security Overview.

5. Retention, return and deletion

Uploaded documents and generated results are retained for 90 days unless deleted earlier or agreed otherwise. On a valid instruction or termination, data is deleted or returned where technically available, subject to statutory retention duties. Customers should keep authoritative copies because no customer-restorable backup commitment currently applies.

6. Personal data breaches

TrustRespond.ai will notify the affected controller without undue delay after becoming aware of a qualifying personal data breach and provide available information needed for the controller's assessment and notification duties.

7. Assistance and audits

Taking into account the nature of processing, TrustRespond.ai assists with data-subject requests, security assessments and supervisory obligations. Reasonable compliance information is made available; audit scope and cost are agreed contractually.

8. International transfers

Where processing outside the EEA requires safeguards, the parties rely on applicable adequacy decisions or Standard Contractual Clauses and supplementary measures. EU regional hosting alone is not represented as eliminating every transfer.

9. Contact

info@trustrespond.ai