Legal
Data Processing Addendum
This Data Processing Addendum (DPA) describes how TrustDesk processes personal data on behalf of its customers and forms part of the agreement between TrustDesk and the customer.
Last updated: July 23, 2026
1. Overview and scope
This DPA applies where TrustDesk processes personal data contained in customer content on behalf of a customer in connection with the service. It supplements our Terms of Service and Privacy Policy.
2. Roles of the parties
The customer is the data controller (or, where applicable, a processor acting on behalf of its own controllers) and determines the purposes and means of processing.
TrustDesk is the data processor and processes personal data only on the customer’s documented instructions, including as set out in the agreement and this DPA.
3. Details of processing
Subject matter and duration: provision of the TrustDesk service for the term of the agreement.
Nature and purpose: hosting, storing, and processing customer content to operate the Trust Center, compliance, and evidence-management features.
Types of personal data and data subjects: as determined by the customer through its use of the service, typically including the customer’s personnel, contacts, and other individuals whose data is included in uploaded content.
4. Processor obligations
TrustDesk will process personal data only on documented instructions; ensure personnel are bound by confidentiality; implement appropriate technical and organizational security measures; and assist the customer, taking into account the nature of processing, with data subject requests and with security, breach, and impact-assessment obligations.
5. Sub-processors
The customer authorizes TrustDesk to engage vetted sub-processors — such as cloud hosting, email delivery, analytics, and file-sharing providers — under written terms that impose data protection obligations equivalent to those in this DPA.
TrustDesk maintains a current list of sub-processors, available on request and through our Trust Center, and will provide a mechanism to notify customers of changes so they may object on reasonable grounds.
6. International data transfers
Where processing involves the transfer of personal data across borders, TrustDesk relies on appropriate safeguards, including the EU Standard Contractual Clauses and the UK International Data Transfer Addendum, as applicable.
7. Security measures
TrustDesk implements measures appropriate to the risk, including encryption in transit and at rest, role-based access control and multi-factor authentication, network segmentation, logging and monitoring, and regular testing. Further detail is on our Information Security & Trust page.
8. Personal data breach notification
TrustDesk will notify the customer without undue delay after becoming aware of a personal data breach affecting the customer’s personal data, and will provide information reasonably necessary for the customer to meet its own notification obligations.
9. Data subject requests and assistance
Taking into account the nature of the processing, TrustDesk will assist the customer by appropriate technical and organizational measures in responding to requests from data subjects to exercise their rights.
10. Return and deletion of data
Upon termination or expiry of the agreement, TrustDesk will, at the customer’s choice, return or delete customer personal data, except where retention is required by law.
11. Audits
TrustDesk will make available information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, subject to reasonable confidentiality and security safeguards.
12. Contact us
To request a signed copy of this DPA or the current sub-processor list, contact privacy@trustdesk.com.