Legal · Data Processing Addendum

Data Processing Addendum.

Effective date: 28 May 2026. This DPA forms part of the Terms of Service between Truvyo ("Processor") and Customer ("Controller") for any processing of Personal Data subject to GDPR, UK-GDPR, CCPA, or equivalent.

1. Definitions

"Personal Data," "Processing," "Controller," "Processor," "Sub-processor," and "Data Subject" have the meanings given in GDPR Article 4. "Customer Personal Data" means Personal Data within Customer Content.

2. Roles & scope

The Controller is the Customer. The Processor is Truvyo. The Processor processes Customer Personal Data only on documented instructions from the Controller, as reflected in the Service configuration and these Terms.

3. Categories of Personal Data & Data Subjects

CategorySubjectsPurpose
End-user chat messages (which may contain Personal Data depending on Controller's deployment)End-users of Controller's website / appService delivery — generate the agent reply
Conversation metadata: timestamps, agent type, channel, citation IDsEnd-usersOperational logs + feedback flywheel
Operator account data: email, name, roleController's employees / contractors with admin accessAuthentication + billing

4. Processor obligations

5. Sub-processors

Truvyo uses the sub-processors listed at truvyo.ai/subprocessors. Controller authorizes their use. Truvyo will provide at least 30 days' notice of any addition or replacement of a sub-processor; Controller may object on reasonable grounds and, if the parties cannot agree on a remedy, terminate without penalty.

Each sub-processor is bound by terms at least as protective as those in this DPA.

6. International transfers

Customer Personal Data is processed in the region designated for the Controller's tenant. For transfers of EEA / UK / Swiss Personal Data to the United States or other third countries, the parties incorporate by reference the European Commission's Standard Contractual Clauses (Decision 2021/914), Module 2 (Controller-to-Processor), with the UK International Data Transfer Addendum where the UK GDPR applies, and the Swiss FDPIC supplementary terms where Swiss law applies.

7. Audit

Truvyo provides Controller with up-to-date documentation describing technical and organizational measures (the Security Overview, Subprocessors page, and on-request SOC 2 Type II report once available). At the Controller's reasonable written request and no more than once per 12-month period, Truvyo will respond to a security questionnaire and, for Enterprise customers under a signed MSA, support an on-site or remote audit with reasonable notice and scope.

8. Liability

The liability provisions of the Terms of Service apply to this DPA. Where data-protection law requires specific liability terms (e.g., Article 82 GDPR), those statutory terms apply in addition.

9. Order of precedence

If there is a conflict, this DPA controls over the Terms of Service for matters related to the processing of Personal Data. SCCs incorporated under Section 6 control over this DPA for the specific transfers they govern.

10. Effective date & modification

This DPA is effective upon Customer's acceptance of the Terms of Service. Material updates follow the 30-day notice procedure in the Terms.

Contact: privacy@truvyo.ai · legal@truvyo.ai