Effective date: 28 May 2026. This DPA forms part of the Terms of Service between Truvyo ("Processor") and Customer ("Controller") for any processing of Personal Data subject to GDPR, UK-GDPR, CCPA, or equivalent.
"Personal Data," "Processing," "Controller," "Processor," "Sub-processor," and "Data Subject" have the meanings given in GDPR Article 4. "Customer Personal Data" means Personal Data within Customer Content.
The Controller is the Customer. The Processor is Truvyo. The Processor processes Customer Personal Data only on documented instructions from the Controller, as reflected in the Service configuration and these Terms.
| Category | Subjects | Purpose |
|---|---|---|
| End-user chat messages (which may contain Personal Data depending on Controller's deployment) | End-users of Controller's website / app | Service delivery — generate the agent reply |
| Conversation metadata: timestamps, agent type, channel, citation IDs | End-users | Operational logs + feedback flywheel |
| Operator account data: email, name, role | Controller's employees / contractors with admin access | Authentication + billing |
Truvyo uses the sub-processors listed at truvyo.ai/subprocessors. Controller authorizes their use. Truvyo will provide at least 30 days' notice of any addition or replacement of a sub-processor; Controller may object on reasonable grounds and, if the parties cannot agree on a remedy, terminate without penalty.
Each sub-processor is bound by terms at least as protective as those in this DPA.
Customer Personal Data is processed in the region designated for the Controller's tenant. For transfers of EEA / UK / Swiss Personal Data to the United States or other third countries, the parties incorporate by reference the European Commission's Standard Contractual Clauses (Decision 2021/914), Module 2 (Controller-to-Processor), with the UK International Data Transfer Addendum where the UK GDPR applies, and the Swiss FDPIC supplementary terms where Swiss law applies.
Truvyo provides Controller with up-to-date documentation describing technical and organizational measures (the Security Overview, Subprocessors page, and on-request SOC 2 Type II report once available). At the Controller's reasonable written request and no more than once per 12-month period, Truvyo will respond to a security questionnaire and, for Enterprise customers under a signed MSA, support an on-site or remote audit with reasonable notice and scope.
The liability provisions of the Terms of Service apply to this DPA. Where data-protection law requires specific liability terms (e.g., Article 82 GDPR), those statutory terms apply in addition.
If there is a conflict, this DPA controls over the Terms of Service for matters related to the processing of Personal Data. SCCs incorporated under Section 6 control over this DPA for the specific transfers they govern.
This DPA is effective upon Customer's acceptance of the Terms of Service. Material updates follow the 30-day notice procedure in the Terms.
Contact: privacy@truvyo.ai · legal@truvyo.ai