Data Processing Addendum
The Article 28 GDPR addendum covering personal data we process on behalf of business customers — chiefly review-invitation data.
_Last updated: 3 August 2026_
This Data Processing Addendum ("DPA") forms part of the Business Terms of Service between TrustRating ("Processor", "we") and the business customer ("Controller", "you") whenever, in providing the Service, we process personal data on your behalf and on your instructions. It is written to satisfy Article 28 of the EU General Data Protection Regulation ("GDPR") and equivalent laws (UK GDPR, and analogous frameworks elsewhere). No signature is required: the DPA applies automatically to every business customer whose use of the Service involves processor-processing, and prevails over the Business Terms in case of conflict on data-protection matters.
1. When we act as your processor — and when we don't
Processor (this DPA applies). The clearest case is review invitations: you upload or transmit your customers' contact data (name, email address, order reference, transaction date) so that we send review invitations and reminders on your behalf. There, you are the controller of your customer list; we process it only to run the invitation flow you configured. The same applies to comparable features where you supply personal data of your customers or staff for us to handle on your instructions (for example team-member data you enter to manage seats).
Independent controller (this DPA does not apply). TrustRating is an independent controller — under the Privacy Policy — for: published reviews and reviewer accounts (reviewers are our users, and review content cannot be controlled by the reviewed company, by design); your business users' own accounts on our platform; company profile data we publish; TrustScores and AI assessments; and our own billing, security and legal compliance. A reviewer who happens to be your customer is, on this platform, our user.
The boundary has a purpose worth spelling out: if reviews were processed "on behalf of" the reviewed company, the company could instruct their deletion — and the platform would be worthless. The moment an invitee accepts an invitation and writes a review, the resulting review and the reviewer's account are our controller-domain, governed by the Reviewer Guidelines and beyond the reach of your instructions. Your customer list stays yours; the public record stays public.
2. Details of processing
Subject matter and nature: hosting, transmission and automated handling of invitee data to send review invitations and reminders, track delivery/opens/clicks for your dashboard, suppress unsubscribes, and connect resulting reviews to invitations for verification labelling. Duration: the term of your use of the relevant features, plus the deletion window in Section 9. Purpose: solely to provide the contracted features — never for our own marketing, never for profiling invitees, never for sale. Categories of data subjects: your customers and other individuals whose data you submit. Categories of data: identification and contact data (name, email), transaction references (order id, date, amount context where you include it), and the technical event data generated by the invitation flow (delivery status, opens, clicks, unsubscribes). Special categories: none are required by the Service; you must not submit them.
3. Your obligations as controller
You warrant that: you have a lawful basis to share each invitee's data with us and to have them contacted about a review (including, where required in your jurisdiction, appropriate notice in your own privacy information — a sentence in your privacy policy naming review invitations as a processing purpose is the usual form); the data you submit is accurate and minimised — no data of individuals who were not genuinely your customers, no more fields than the feature needs; you will not submit data of minors under 16 or special-category data; and your instructions to us comply with law. Which lawful basis fits is your call as controller — legitimate interest in post-transaction feedback is the common choice in the EU, consent where your jurisdiction's e-communication rules require it — but having one is not optional, and "we bought the list" is not one. Sending invitations to purchased address lists, or to individuals with no transaction with you, breaches this DPA, the Business Terms of Service and the anti-spam rules of the Acceptable Use Policy.
4. Our obligations as processor
We will: process invitee data only on your documented instructions — given through the Service's configuration and features, which is what "documented instructions" means in a self-service product: every toggle you set, template you choose and list you upload is an instruction, recorded as such — unless EU/Member-State law requires otherwise, in which case we inform you before processing unless that law forbids it; inform you if, in our opinion, an instruction infringes data-protection law; ensure everyone we authorise to process the data is bound by confidentiality; implement the technical and organisational measures in Section 6; assist you, taking into account the nature of processing, with data-subject requests (Section 7), security, breach notification, and — where required — data-protection impact assessments and prior consultation; make available the information reasonably necessary to demonstrate compliance with Article 28 and allow audits under Section 10; and delete or return the data at the end of processing (Section 9).
5. Sub-processors
You authorise us generally to engage sub-processors for hosting/infrastructure, email delivery, monitoring and comparable support functions — the plumbing every online service runs on, engaged so that invitations actually deliver and the platform actually stays up. We: bind every sub-processor by a written contract imposing data-protection obligations no less protective than this DPA; remain fully liable to you for their performance; maintain a current list of sub-processors, available on request through the contact page; and give you advance notice of intended additions or replacements, so you may object on reasonable data-protection grounds. If we cannot resolve a legitimate objection, you may stop using the affected feature and, if the feature was material to your paid plan, terminate it in accordance with the Subscription, Billing & Cancellation Terms.
6. Security
Taking into account the state of the art, costs, and the nature, scope, context and purposes of processing, we implement appropriate measures including: encryption of data in transit; hashed and salted credentials; strict role-based access to production data with audit logging of administrative actions; network protections and rate limiting; segregation between customers' invitee data; a tested backup regime with fixed rotation; vulnerability management and secure development practice; and staff confidentiality obligations. Details of current measures are available on request and are updated as technology evolves — a change never lowers the overall level of protection.
7. Data-subject requests
Invitees exercise rights (access, erasure, objection, and unsubscribing from invitations) sometimes against you and sometimes against us. Where a request reaches us and concerns processor-data, we will not answer on the merits in your place; we will forward it to you promptly and assist with the technical execution (locating, exporting, deleting the record, honouring suppression). Where one person's data sits in both domains — an invitee who became a reviewer — each side handles its own: you answer for the customer record you uploaded, we answer for the review account they created, and neither answer requires the other's permission. Unsubscribes from invitation emails are executed immediately platform-wide as part of the feature itself, and you must not re-upload suppressed addresses.
8. Personal-data breaches
If we become aware of a personal-data breach affecting your invitee data, we will notify you without undue delay, providing — as information becomes available — the nature of the breach, categories and approximate numbers of data subjects and records, likely consequences, measures taken or proposed, and a contact point. Information may arrive in stages: a fast first notice with what is known beats a complete report that arrives after your own 72-hour clock has run out, and we sequence accordingly. We will reasonably cooperate with your own notification duties to authorities and data subjects. Notification is not an admission of fault.
9. Deletion and return
When you stop using an invitation feature, close your business account, or ask us in writing, we delete the invitee data processed on your behalf — and in any case we delete or irreversibly anonymise it after the operational retention window needed for suppression lists, verification labelling and dispute defence. On request made before deletion, we first export the data to you in a common machine-readable format. Copies in encrypted backups are purged on the backup rotation schedule described in the Privacy Policy. Statutory retention duties (for example invoice data under tax law — which is controller-data on our side anyway) are unaffected.
10. Audits
We make available, on request, the information reasonably necessary to demonstrate compliance with this DPA — including summaries of security measures and sub-processor arrangements. Where the law entitles you to more, you (or an independent auditor bound to confidentiality) may audit our compliance no more than once per year, on at least 30 days' notice, during business hours, without access to other customers' data, and at your cost; where a recognised third-party audit report or certification covers the scope, it satisfies the request.
11. International transfers
Where processor-processing involves transfers of personal data out of the EU/EEA or UK to a country without an adequacy decision, we ensure a valid transfer mechanism — the European Commission's Standard Contractual Clauses (module two, controller-to-processor, and module three where sub-processors are involved) with any required supplementary measures, or another mechanism recognised by law. The SCCs are incorporated by reference into this DPA and prevail over it in case of conflict for the transfers they govern.
12. Liability and precedence
Liability under this DPA follows the allocation and caps of the Business Terms of Service, except where data-protection law mandates otherwise (including Article 82 GDPR, under which each party is liable to data subjects for its own share of responsibility). This DPA prevails over the Business Terms on data-protection matters; mandatory law prevails over everything. Questions about this DPA — including sub-processor lists and SCC copies — via the contact page.
13. Term
This DPA takes effect when you first use a feature involving processor-processing and continues until we have deleted or returned all personal data processed on your behalf under Section 9. Obligations that by nature survive — confidentiality, audit support for the processed period, liability for the processing that occurred — survive.
Annex 1 — Description of processing
Data exporter / controller: the business customer identified by its TrustRating business account. Data importer / processor: TrustRating. Data subjects: the controller's customers and other individuals whose personal data the controller submits through the Service's features. Categories of personal data: name and email address; transaction references (order identifier, transaction date, and contextual fields the controller chooses to include); technical event data generated by the invitation flow (delivery, bounce, open, click, unsubscribe events and their timestamps). Special categories: none — submission prohibited. Frequency: continuous, as the controller uses the features. Nature and purpose: hosting, transmission and automated handling to send review invitations and reminders on the controller's behalf, report their outcomes to the controller, honour suppression, and label resulting reviews as verified. Retention: per Section 9. Sub-processing: per Section 5, limited to hosting/infrastructure, email delivery and monitoring functions.
Annex 2 — Technical and organisational measures
The measures currently implemented include, as a binding minimum standard: encryption of personal data in transit (TLS) across all public interfaces; credential protection through salted hashing, with no plaintext password storage anywhere in the system; role-based access control over production systems, on a need-to-know basis, with administrative actions logged in an audit trail; logical separation of each controller's invitee data, so one customer's lists are never visible to another; network-level protections, rate limiting and automated abuse detection on all endpoints; a tiered, tested backup and restore regime with fixed rotation windows so deleted data ages out of backups; vulnerability management as part of the development cycle, with dependency monitoring and prompt patching; a secure development practice in which data-protection impact is considered at design time; staff confidentiality undertakings and access revocation on role change or departure; and an incident-response process connecting detection, containment, assessment and the notification duties of Section 8. An expanded current description is available on request and evolves only upward, per Section 6.