When a DPA is needed
In hosted services, the customer generally determines the purpose of user and device-data processing, and TrustFlare processes those data on its documented instructions. If the customer is itself a processor, the agreement must address that chain of responsibilities.
Website enquiries and our own business correspondence are separately described in the Privacy policy; they do not become processor activities simply because they are stored by the same provider. A customer-hosted core does not, by itself, give TrustFlare access to its records.
Processing schedule
Before processing begins, the parties need to identify the contracting parties, service, duration, purposes, locations, data categories, affected people and applicable law. The schedule must reflect the actual deployment and agreed support access.
Typical service data include user and device identifiers, public keys, device-security facts, registration events and sign-in decisions for customer employees, contractors or authorized users. The customer determines the enabled checks and must inform its users.
Terms for agreement
The DPA should address documented instructions, authorized personnel and confidentiality, security measures, assistance with privacy requests and incidents, subprocessor authorization, international transfers, audit information, and return or deletion at the end of service.
Where Article 28 GDPR applies, the binding agreement must meet its requirements. The published summary does not substitute for the completed agreement, security schedule or any required transfer mechanism.
Hosting, subprocessors and transfers
The signed schedule should name the actual providers and locations, define subprocessor change notices and objections, and identify any required transfer safeguards. See Service providers and subprocessors. A network provider’s global presence or a self-hosting option does not resolve every transfer question.
Incidents and end of service
Agree incident contacts and the notification process before onboarding. Where TrustFlare is a processor under GDPR, breach notification to the controller is required without undue delay; the controller assesses its own regulatory and individual notifications.
Agree the retention period, export format, deletion process, backup treatment and any legal retention exceptions. A pilot expiry date does not by itself prove that all copies of personal data have been deleted.
Request documents
TrustFlare is an early-stage startup. Information about the operating and contracting party, and documents for customer due diligence, are available on request at legal@trustflare.tech before a paid engagement begins.
Include your deployment model and any procurement requirements so we can provide the relevant documents and identify points that still need agreement.