Legal

Data Processing Agreement

This Data Processing Agreement ("DPA") forms part of the contract between the Customer (acting as controller) and {COMPANY_NAME}, trading as TrivoCloud (acting as processor), and governs the processing of personal data on the controller's behalf when the controller runs workloads on the TrivoCloud service.

Last updated: 8 September 2026 · Controller: {COMPANY_NAME}, {ADDRESS} · bok@cloudservicedroid.site

1. Subject-matter and duration

Subject-matter: processing of personal data uploaded to or generated by workloads that the controller runs on the TrivoCloud service.

Duration: this DPA applies for as long as the controller has an active TrivoCloud service and until the deletion or return of the personal data as described below.

2. Nature, purpose and categories

Nature and purpose: hosting, storing, transmitting and otherwise processing personal data solely as required to provide the service.

Categories of data subjects and personal data: determined by the controller. TrivoCloud does not inspect the content of customer workloads and cannot enumerate the categories on the controller's behalf.

3. Processing on documented instructions

TrivoCloud processes the personal data only on the controller's documented instructions, including with regard to transfers of personal data to a third country, unless required to do so by Union or Member State law. In such a case, TrivoCloud informs the controller of that legal requirement before processing, unless the law prohibits such information on important grounds of public interest.

4. Confidentiality

TrivoCloud ensures that persons authorised to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

5. Security of processing

TrivoCloud implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including: encryption of data in transit, encryption of backups at rest, network segregation between the management plane and customer workloads, multi-factor authentication for administrative access, hardened baseline images, and audit logging of privileged actions.

6. Sub-processors

The controller grants TrivoCloud general authorisation to engage sub-processors, subject to a written contract that imposes the same data-protection obligations as those set out in this DPA.

TrivoCloud maintains a current list of sub-processors and provides at least 30 days' notice by email of the addition or replacement of a sub-processor. The controller may object on reasonable data-protection grounds; if the objection cannot be resolved, the controller may terminate the affected service without penalty.

7. Assistance with data-subject rights

Taking into account the nature of the processing, TrivoCloud assists the controller by appropriate technical and organisational measures, insofar as this is possible, in fulfilling the controller's obligation to respond to requests for exercising data-subject rights under Chapter III GDPR.

8. Personal data breach notification

TrivoCloud notifies the controller without undue delay after becoming aware of a personal data breach affecting the controller's data, and provides all information reasonably necessary to enable the controller to meet its own notification obligations under Articles 33 and 34 GDPR.

9. Data protection impact assessments

TrivoCloud provides reasonable assistance to the controller with data protection impact assessments and prior consultations with supervisory authorities, taking into account the nature of the processing and the information available to TrivoCloud.

10. Return and deletion

At the choice of the controller, TrivoCloud deletes or returns all the personal data after the end of the provision of services relating to processing, and deletes existing copies unless Union or Member State law requires storage of the personal data.

11. Audits

TrivoCloud makes available to the controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR and this DPA, and allows for and contributes to audits, including inspections, conducted by the controller or another auditor mandated by the controller, subject to reasonable notice, confidentiality undertakings and the operational constraints of a shared hosting environment.

12. International transfers

Where TrivoCloud transfers personal data to a country outside the European Economic Area that is not the subject of an adequacy decision, the transfer relies on the European Commission's Standard Contractual Clauses (Decision 2021/914), which are incorporated into this DPA by reference.