This DPA is in the review stage for pre-launch. The effective date will be published on the go-live date. Customers requiring a countersigned copy should contact legal@trustvendor.co.

Legal

Data Processing Agreement

Effective date: pending publication

1. Scope and applicability

This Data Processing Agreement ("DPA") supplements the TrustVendor Terms of Service or master subscription agreement between the customer identified in the applicable order form ("Customer", "Controller") and TrustVendor Inc. ("TrustVendor", "Processor"). It governs the Processing of Personal Data by TrustVendor on behalf of the Customer in the course of delivering the TrustVendor platform, the Trust Workspace, and the Vendor Pulse API (the "Services"). In case of any conflict between this DPA and the master agreement with respect to Personal Data, this DPA prevails.

2. Definitions

Capitalised terms not defined in this DPA have the meaning set out in Regulation (EU) 2016/679 ("GDPR"). "Personal Data", "Processing", "Controller", "Processor", "Data Subject", "Sub-processor", and "Supervisory Authority" have the meanings given in the GDPR. "Data Protection Laws" means all applicable laws relating to Personal Data, including the GDPR, the UK GDPR, the California Consumer Privacy Act as amended by the CPRA, and other equivalent laws. "Standard Contractual Clauses" or "SCCs" means the Standard Contractual Clauses approved by the European Commission in Implementing Decision (EU) 2021/914, modules two and three, as applicable.

3. Roles of the parties

Customer is the Controller of Personal Data submitted to or generated in the Trust Workspace and Vendor Pulse API in the course of Customer's use of the Services. TrustVendor acts as a Processor with respect to such Personal Data. Where TrustVendor uses Sub-processors, TrustVendor acts as a Controller in relation to those Sub-processors' obligations toward TrustVendor. Nothing in this DPA restricts TrustVendor's role as an independent Controller for account administration, billing, security, and abuse prevention data.

4. Nature, purpose, subject-matter, and duration of Processing

Nature and purpose: to provide vendor risk intelligence services, including collection of vendor data from public sources, generation of claims and scores, storage of Customer-supplied evidence, delivery of signals and notifications, and hosting of the Trust Workspace and Vendor Pulse API. Subject-matter: Personal Data submitted by Customer or its authorised users in connection with the Services. Duration: for the duration of the master agreement plus any period during which TrustVendor retains Personal Data in accordance with Section 12.

5. Categories of Personal Data and Data Subjects

Categories of Personal Data typically include: identity data (name, business email, job title); usage and log data (IP address, browser metadata, timestamps, session identifiers); communication data submitted through the Services (comments, evidence requests, assessment notes); and Customer-supplied documents that may contain names, contact information, or other identifiers of Customer's personnel, vendors, or third parties. Categories of Data Subjects include Customer's employees, contractors, agents, prospects, and personnel of vendors evaluated by Customer.

6. Customer instructions

TrustVendor will Process Personal Data only on documented instructions from Customer, including with regard to transfers to a third country, unless required to do so by law. Customer's instructions are set out in the master agreement, this DPA, and Customer's configuration and use of the Services. TrustVendor will inform Customer if it believes an instruction infringes Data Protection Laws.

7. Confidentiality

TrustVendor will ensure that persons authorised to Process Personal Data are bound by written confidentiality obligations at least as protective as those in this DPA. TrustVendor limits access to Personal Data to personnel with a strict need to know.

8. Security measures

TrustVendor implements the technical and organisational measures set out in Annex II below to ensure a level of security appropriate to the risk, in accordance with Article 32 of the GDPR. Measures include encryption in transit (TLS 1.2 or higher) and at rest (AES-256), least-privilege identity and access management with mandatory multi-factor authentication for production access, continuous vulnerability management, tenant isolation via Postgres Row Level Security, immutable content-addressed evidence snapshots with sha256 hashing, comprehensive audit logging, and independent third-party security reviews.

9. Sub-processors

Customer provides general authorisation for TrustVendor to engage Sub-processors to Process Personal Data. A current list of Sub-processors is published below and at trustvendor.co/legal/dpa. TrustVendor will notify Customer of any intended addition or replacement of a Sub-processor at least 30 days before the change takes effect. Customer may object on reasonable grounds relating to data protection within that period; TrustVendor and Customer will discuss the objection in good faith and, if it cannot be resolved, Customer may terminate the affected Services with a pro-rated refund of any prepaid fees. TrustVendor imposes on each Sub-processor, by written contract, data-protection obligations substantially equivalent to those in this DPA.

10. Data Subject rights

Taking into account the nature of the Processing, TrustVendor will provide reasonable assistance to Customer, insofar as this is possible, in fulfilling Customer's obligation to respond to Data Subject requests to exercise their rights under the GDPR. Where a Data Subject contacts TrustVendor directly with a request relating to Personal Data Processed on Customer's behalf, TrustVendor will forward the request to Customer without undue delay and will not respond substantively unless authorised by Customer or required by law.

11. Personal data breach

TrustVendor will notify Customer without undue delay after becoming aware of a Personal Data breach affecting Customer's Personal Data, and in any event within 48 hours where feasible. The notification will describe the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, the measures taken or proposed to address the breach, and a designated point of contact. TrustVendor will cooperate with Customer's investigation and any regulatory notifications.

12. Return and deletion

Upon termination of the master agreement or on Customer's written request, TrustVendor will, at Customer's option, return or delete all Personal Data Processed on Customer's behalf within 30 days, subject to legal-hold obligations and backup retention cycles (encrypted backups are retained for up to 90 days on a rolling basis and are not restored except for disaster recovery). Immutable, content-addressed public evidence artifacts collected from public sources are retained indefinitely as part of the Vendor Graph audit trail; these do not contain Customer Personal Data.

13. Audit

TrustVendor makes available to Customer information necessary to demonstrate compliance with this DPA, including summary reports from its most recent independent security audit (SOC 2 Type II or equivalent). At Customer's request, and no more than once per 12-month period (except after a Personal Data breach or as required by a Supervisory Authority), TrustVendor will cooperate with Customer's reasonable audit, which will be conducted at Customer's expense, on 30 days' notice, during normal business hours, and subject to appropriate confidentiality obligations.

14. International transfers

Where TrustVendor Processes Personal Data of Data Subjects located in the European Economic Area, United Kingdom, or Switzerland outside those jurisdictions, the parties agree that: (a) the EU Standard Contractual Clauses (module 2 or 3 as applicable) are incorporated by reference into this DPA; (b) for UK transfers, the UK International Data Transfer Addendum (IDTA) applies; and (c) for Swiss transfers, references to the GDPR are read as references to the FADP as applicable. TrustVendor will implement supplementary measures as described in the Security Annex where required by Schrems II considerations.

15. California, Colorado, Virginia, and other US state laws

To the extent TrustVendor Processes Personal Information subject to the California Consumer Privacy Act, as amended, TrustVendor is a "Service Provider" and will not sell or share Personal Information, will not retain, use, or disclose Personal Information outside the direct business relationship or for purposes other than the specific business purpose of providing the Services. Equivalent obligations apply for other US state privacy laws (Colorado, Virginia, Connecticut, Utah, and others as enacted).

16. Liability

The liability of the parties under or in connection with this DPA is subject to the exclusions and limitations of liability set out in the master agreement. Nothing in this DPA excludes or limits liability that cannot be excluded or limited under Data Protection Laws.

17. Term and precedence

This DPA is effective from the effective date of the master agreement and continues for as long as TrustVendor Processes Personal Data on Customer's behalf. In the event of a conflict between this DPA and the master agreement with respect to Personal Data, this DPA prevails. In the event of a conflict between this DPA and the SCCs, the SCCs prevail.

Annex I — Sub-processors

Current list of Sub-processors used to deliver the Services. TrustVendor will provide at least 30 days\' notice of any material change to this list via email to notice contacts and by updating this page.

Sub-processor Purpose Location
Amazon Web Services (AWS) Primary infrastructure — compute, storage, managed Postgres, S3-compatible blob storage United States, European Union
Cloudflare CDN, DDoS protection, edge functions for the marketing site, WAF Global edge
Redpanda Data Managed Kafka-compatible event streaming backbone United States
Redis Cloud Ephemeral caching, rate limiting, leader election, idempotency keys United States, European Union
Resend Transactional and notification email delivery United States
Anthropic AI claim extraction for tier-2 and tier-3 evidence extraction United States
OpenAI AI claim extraction for tier-1 extraction and vector embeddings United States
Stripe Subscription billing and payment processing United States, Ireland
Vercel Static hosting of documentation and marketing surfaces Global edge
Datadog Operational observability — metrics, traces, and logs United States, European Union

Annex II — Technical and organisational measures

Summary of the technical and organisational measures implemented under Article 32 of the GDPR. Additional detail is available on request under NDA.

Encryption

TLS 1.2+ for all data in transit; AES-256 for data at rest in Postgres and blob storage; sha256 hashing of every evidence artifact.

Access control

Least-privilege IAM roles, mandatory multi-factor authentication on all production access, no shared credentials, per-tenant Row Level Security in Postgres enforced by the tenant middleware.

Tenant isolation

Customer data segregated by tenant_id; per-request app.tenant_id context set on each database connection; belt-and-braces isolation via RLS policies and query-builder guards.

Network security

Private VPC subnets for application workloads; ingress only via load balancers with WAF; egress restricted to allowlisted endpoints; Cloudflare DDoS and rate-limit protections on the public surface.

Vulnerability management

Continuous dependency scanning, weekly patch cycle for infrastructure, annual third-party penetration test, and a coordinated disclosure programme published at trustvendor.co/security.

Personnel

Background checks on personnel with production access; annual security and privacy training; documented onboarding and offboarding checklists including credential revocation.

Monitoring and logging

Structured audit logging of authentication events, tenant context switches, evidence access, and administrative actions; log retention for a minimum of 12 months; alerts on anomalous access patterns.

Business continuity

Automated database backups with point-in-time recovery; documented incident response runbook; annual disaster-recovery tabletop exercise; primary and secondary infrastructure regions.

Data minimisation

Only data necessary for the Services is collected; ephemeral logs are retained for the shortest period necessary; sensitive fields are hashed or tokenised where practical.

For a countersigned copy of this DPA, the Standard Contractual Clauses, or the UK Addendum, contact legal@trustvendor.co.

Report a security concern: security@trustvendor.co. Coordinated disclosure: trustvendor.co/security.