LEGAL

Data processing agreement

How Trivena processes customer data as a processor: what we do with it, who else touches it, how it is protected, and what happens when the relationship ends. This page summarises the terms we sign.

Effective 1 July 2026

1. Roles

For the business data inside a Trivena Cloud Site, the customer is the controller and Trivena is the processor. The customer decides what data is stored and for what purpose; we process it on the customer's instructions in order to run the Service.

For our own website, enquiries, and account administration we act as controller. That is described in the privacy policy.

2. Our obligations as processor

  • Process customer data only on the customer's documented instructions and to provide the Service.
  • Keep it confidential, and bind the personnel who can access it to confidentiality.
  • Apply appropriate technical and organisational security measures, described in section 5.
  • Assist the customer with data subject requests and with security and impact assessments, on reasonable request.
  • Notify the customer without undue delay on becoming aware of a personal data breach affecting their data.
  • Delete or return customer data at the end of the relationship, subject to legal retention requirements.
  • Make available the information needed to demonstrate compliance with these obligations.

3. Details of processing

Subject matter
Hosting and operating the customer's Trivena Cloud Site and the applications installed in it, and providing support for that Site.
Duration
The term of the customer's agreement, plus the limited period needed for export and deletion after it ends.
Nature and purpose
Storage, hosting, processing, backup, and transmission of customer data as required to deliver the Service and support it on request.
Categories of data
Whatever the customer chooses to put into its Site. Typically contact details of business contacts, employee records, transaction data, and support correspondence.
Categories of data subjects
The customer's users, employees, customers, suppliers, and other business contacts.
Instructions
The customer's documented instructions are given through the agreement, this DPA, and their use of the Service's configuration options.

4. Subprocessors

We use a limited set of subprocessors to deliver the Service, covering infrastructure and hosting, transactional email delivery, and AI providers for specific capabilities. Each is engaged under a written contract with data protection obligations no less protective than these.

A current subprocessor list is available on request. We notify customers of intended changes to that list so they have an opportunity to object on reasonable data protection grounds.

5. Security measures

  • Tenant isolation: each customer runs in a separate Site with its own database, and requests resolve to a single Site before business logic runs.
  • Access control: the platform's permission system governs record, row, and field access, and applies identically to the UI, the API, and Trivena AI.
  • Encryption in transit: all traffic to Sites is served over HTTPS with automatically renewed certificates and HSTS enabled.
  • Operational access: administrative access to infrastructure is restricted to the personnel who operate Trivena Cloud, over authenticated channels.
  • Backups: automated on a schedule, with restoration performed by Trivena.
  • Monitoring: continuous monitoring of the control plane, workers, proxies, and database hosts, published at status.trivena.tech.
  • Patching: platform, application, and infrastructure updates applied as part of running the Service.
  • Environment separation: test and staging Sites are separate tenants, so evaluating a change does not touch production data.

Our security page describes these measures in more depth.

6. Trivena AI

AI capabilities operate within a single Site and in the context of the requesting user's permissions. Customer data is used to answer that customer's requests, and not to train models shared across customers. Where an external AI provider processes a request, it does so as a subprocessor under contract. An enterprise option for customers to use their own AI provider or keys is planned.

7. International transfers

Trivena is operated from the Netherlands and we prefer subprocessors within the European Economic Area. Where a transfer outside the EEA is necessary, we rely on an appropriate transfer mechanism such as the European Commission's standard contractual clauses, together with any additional measures required.

8. Data subject requests

Requests from data subjects should be directed to the customer as controller. Where a request reaches us directly, we forward it rather than acting on it, and we assist the customer in responding, including by making the relevant records available or exportable from their Site.

9. Breach notification

If we become aware of a personal data breach affecting customer data, we notify the customer's administrative contact without undue delay, with the information available at that point: what happened, which data is affected as far as we know, what we are doing about it, and what we recommend the customer does. Updates follow as the investigation progresses.

10. Audit and information

On reasonable request we provide the information a customer needs to assess our compliance with this DPA, including descriptions of our architecture, security measures, and subprocessors. Enterprise agreements can include further audit arrangements.

11. Return and deletion

Customer data remains exportable over the REST API and in standard formats throughout the term. After termination we make it available for export for a defined period, then delete it from active systems and, on the expiry of the backup cycle, from backups, unless law requires longer retention.

12. Getting a signed DPA

This page is a summary so you can evaluate our terms before asking for paperwork. For a signed DPA covering your specific processing, including standard contractual clauses where relevant, contact us and tell us which entity is contracting.

Questions

To request a signed data processing agreement or our subprocessor list, contact cloud@tynktech.nl