Skip to content
Request evaluation
PricingRequest evaluation

Legal

Data Processing Addendum

Effective and last updated: August 27, 2026

This standard Data Processing Addendum ("DPA") forms part of a written agreement under which Trunnion AI, LLC processes personal information for a business customer. A signed order form or agreement may add or replace terms. This page is not a public offer and does not authorize submission of data outside the approved product and deployment boundary.

1. Roles and instructions

The customer is the business, controller, or equivalent party for customer personal information; Trunnion AI, LLC acts as service provider, processor, or contractor and processes that information only to provide, secure, support, and improve the contracted service on documented instructions. We do not sell or share customer personal information, use it for cross-context behavioral advertising, or combine it with information received from another business except as permitted by applicable US privacy law.

2. Scope and purpose

The agreement identifies the approved users, tools, data categories, data subjects, purpose, duration, providers, processing location, retention, output use, and professional-review requirements. Classified, CUI, export-controlled, protected-class, highly sensitive, or regulated information is prohibited unless the signed scope expressly authorizes it and identifies the required controls.

3. Confidentiality and security

Authorized personnel are bound by confidentiality duties. Administrative, technical, and organizational measures are selected for the scoped risk and may include authenticated routes, server-side ownership and team checks, encryption in transit and at rest through the deployed providers, signed webhook validation, vulnerability and dependency checks, backup and recovery, logging, and incident procedures. The exact implemented controls are documented per release and deployment; this DPA does not convert a roadmap item into a shipped control.

4. Subprocessors

The current public register is at Subprocessors. We impose data-protection duties appropriate to each provider's service. Where the agreement provides advance notice, customers receive at least 30 days' notice of a new subprocessor and may object on reasonable data-protection grounds under that agreement. Hosted model providers, retention, training exclusion, and processing location must be identified in the signed scope before production use.

5. Rights requests and legal compliance

Taking account of the nature of processing, we provide reasonable assistance with verified access, correction, deletion, portability, opt-out, appeal, and regulator requests that concern customer personal information. If we receive a request directly, we route it to the customer unless law requires another response. Each party is responsible for its own legal basis, notices, instructions, and legally required assessments.

6. Incidents

We notify the customer of a confirmed security incident affecting customer personal information without undue delay and within any shorter period stated in the signed agreement or applicable law. Notice includes known nature, affected data and people, likely consequences, containment, remediation, and a contact for follow-up, with updates as facts develop. A notification is not an admission of fault.

7. Return and deletion

At the end of the service, customer personal information is returned or deleted as the agreement requires, subject to legal holds and limited backup expiry. The signed scope states export format, deletion window, backup window, and any records retained to meet legal, security, billing, or dispute obligations.

8. Information and audit support

We provide information reasonably necessary to demonstrate the obligations applicable to the contracted processing, subject to confidentiality, security, privilege, tenant isolation, and proportionality. Independent reports are provided only if actually held and in scope. Where further review is justified, the parties coordinate a questionnaire, evidence review, or audit that avoids exposing other customers or restricted systems.

9. Contact

Request execution of this DPA or deployment-specific terms through contact@viceroynm.com. Privacy rights may also be submitted through Your Privacy Choices.

Necessary technology is always active because it provides security and remembers this choice.