DATA PROCESSING AGREEMENT (DPA)
Effective Date: June 15, 2026
1. INTRODUCTION AND DEFINITIONS
This Data Processing Agreement ("DPA") supplements and forms an integral part of the Terms and Conditions for Businesses (the "Agreement") between you (the "Business" or "Controller") and TrustRating.ai ("TrustRating", "we", "our", or "us", acting as the "Processor"). This DPA governs the processing of personal data provided by you to us in connection with our trust intelligence, rating, and review invitation services.
- "Applicable Data Protection Law" means all relevant data protection and privacy laws applicable to our processing of Relevant Data, including the General Data Protection Regulation (GDPR), the UK GDPR, and the California Consumer Privacy Act (CCPA), each as amended.
- "Relevant Data" means the personal data described in the Annex below, which is processed by TrustRating on your behalf under the Agreement.
- "Personal Data", "Special Categories of Data", "Controller", "Processor", "Data Subject", and "Processing" shall have the meanings ascribed to them under Applicable Data Protection Law.
2. RELATIONSHIP AND SCOPE
- Roles: You acknowledge that you are the Data Controller and TrustRating is the Data Processor regarding the Relevant Data.
- Duration: This DPA remains active for as long as the main Agreement is in effect, or for as long as TrustRating retains or processes Relevant Data on your behalf—whichever period is longer.
3. PROCESSING INSTRUCTIONS
- Purpose Limitations: TrustRating will process Relevant Data strictly in accordance with your documented instructions and solely for the operational purposes described in the Annex below (the "Purpose"). We will not process Relevant Data for any other purpose unless legally compelled by applicable judicial or regulatory authorities, in which case we will notify you unless prohibited by law.
- Compliance Checks: If TrustRating believes an instruction from you violates Applicable Data Protection Law, we will inform you immediately.
4. INTERNATIONAL DATA TRANSFERS
TrustRating will not transfer Relevant Data outside of the European Economic Area (EEA), the UK, or your local jurisdiction unless we have implemented legally recognized transfer mechanisms to safeguard the data. These measures include transferring to countries deemed adequate by relevant authorities or utilizing approved Standard Contractual Clauses (SCCs).
5. COMPLIANCE AND PROHIBITED DATA
You represent and warrant that you possess all necessary rights, permissions, and explicit consumer consents required under Applicable Data Protection Law to disclose the Relevant Data to TrustRating for processing. You agree not to upload, copy us on, or disclose any Special Categories of Data or protected health information unless explicitly agreed upon in writing.
6. CONFIDENTIALITY
TrustRating ensures that all personnel, employees, and authorized agents permitted to handle or process the Relevant Data are bound by strict contractual or statutory obligations of confidentiality.
7. SECURITY PRACTICES
TrustRating implements and maintains rigorous technical and organizational security measures designed to protect Relevant Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. These measures are regularly reviewed and updated to align with modern industry standards and structural risks.
8. AUDIT RIGHTS
- Independent Inspection: You may, at your own expense, appoint an independent, non-competitor expert to audit TrustRating’s compliance with this DPA and evaluate our technical security measures.
- Notice and NDA: You must provide TrustRating with at least 14 days' prior written notice of an audit. The appointed expert must sign a customary non-disclosure agreement before receiving access to our facilities or systems. All audit findings must be shared with TrustRating and kept strictly confidential.
9. REGULATORY AND SECURITY INCIDENTS
- Authority Requests: TrustRating will notify you in writing without undue delay of any legally binding disclosure requests received from data protection authorities regarding your Relevant Data, unless expressly prohibited by law.
- Data Breaches: In the event of a confirmed security incident resulting in the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of Relevant Data, TrustRating will notify you in writing without undue delay after becoming aware of the facts, enabling you to fulfill your data breach notification obligations.
10. COOPERATION AND DATA SUBJECT RIGHTS
- Data Subject Requests: TrustRating will promptly assist you, through appropriate technical solutions, in responding to requests from individuals exercising their rights under Applicable Data Protection Law (such as access, correction, or deletion requests).
- Handling Protocols: If we receive a request directly from your consumer, we will redirect the individual to submit their request to you as the primary Controller.
- Impact Assessments: TrustRating will provide reasonable cooperation and information to assist you with conducting data protection impact assessments (DPIAs) where required.
11. SUB-PROCESSORS
- Authorization: You grant TrustRating a general authorization to engage third-party sub-processors to fulfill the Purpose. We impose data protection obligations on each sub-processor that are at least as restrictive as those contained in this DPA.
- Notification & Objection: TrustRating will maintain an updated list of sub-processors. We will notify you of any intended additions or replacements. You may object to a new sub-processor on reasonable, objective data protection grounds within 14 days. If a mutual resolution cannot be reached, you may terminate your subscription by giving us 14 days' written notice.
- Liability: TrustRating remains fully liable to you for the performance of our sub-processors' obligations.
12. DELETION OR RETURN OF DATA
Upon termination of the Agreement, or upon your earlier written request, TrustRating will securely delete, anonymize, or return all Relevant Data in our possession, unless applicable statutory laws or regulatory compliance frameworks require the continued storage of certain records.
13. LEGAL EFFECT
This DPA is legally binding upon your acceptance of the TrustRating.ai Terms and Conditions or upon using our review invitation mechanisms. In the event of any direct conflict or inconsistency between the main Agreement and this DPA regarding data processing issues, the provisions of this DPA shall prevail.
ANNEX: DETAILS OF PROCESSING
Purposes of Processing
TrustRating processes Relevant Data as necessary to provide, manage, and optimize our trust intelligence platform services on your behalf. This includes facilitating our automated and human-reviewed review invitation workflows, managing business verification metrics, generating analytical trust reports, and operating native TrustRating widgets on your connected digital properties.
Categories of Data Subjects
Your verified consumers, customers, and website platform visitors.
Categories of Personal Data ("Relevant Data")
-First and last name.
-Electronic email address.
-Transactional reference numbers (such as order IDs, booking references, or invoice codes).
-IP address, device metadata, and interaction history captured via deployed website widgets.
Additional informational fields explicitly collected from reviewers via custom verification parameters.
Special Categories of Personal Data
TrustRating.ai does not intentionally solicit, collect, or process Special Categories of Personal Data. However, if you choose to utilize automated email feed options that copy us on unredacted customer order confirmations, such data may be processed incidentally. You are encouraged to filter out sensitive personal categories prior to routing data to our platform.