Data Processing Agreement — Business Edition
Version 2026-07-30
In effect from 2026-07-30
This is the current version. Permanent address of this version
This English text is the authoritative version of this agreement. Translations into other languages are provided for convenience.
Agreement on the processing of personal data on behalf of a controller, pursuant to Article 28 of Regulation (EU) 2016/679 (“GDPR”).
This agreement applies to the Trusted Codes Business Edition, which runs on Trusted Codes infrastructure. It does not apply to the Enterprise Edition, where the customer operates their own node and the Provider does not process the customer’s user data. A separate, shorter agreement covers that case.
Parties
Controller (“Customer”): the organisation identified in the Trusted Codes account that accepted this agreement, together with the acceptance record described at the end of this document.
Processor (“Provider”): Stefan Sonntag, trading as Trusted Codes
Leonrodstr. 14b, 80634 Munich, Germany
Contact: privacy@trusted.codes
This agreement forms part of, and is subordinate to, the Trusted Codes Terms of Service. It takes effect when the Customer accepts it, and remains in force for as long as the Provider processes personal data on behalf of the Customer.
1. Subject matter and duration
1.1 The Provider processes personal data on behalf of the Customer solely to supply the Trusted Codes Business Edition: a verification service that issues and verifies word-based access codes between identified people, together with the organisation administration, notification and support functions described in the product documentation.
1.2 The duration of the processing corresponds to the duration of the Customer’s subscription, extended by the deletion periods in Section 10.
2. Nature and purpose of the processing
2.1 The Provider processes personal data only to:
- create and administer user accounts and organisation membership;
- generate, distribute and verify access codes and related cryptographic material;
- deliver notifications by electronic mail and push message;
- provide the administration console, reporting and support;
- protect the service against fraud and abuse;
- meet its own legal obligations.
2.2 The Provider does not process the personal data for its own purposes. The Provider does not sell personal data, and does not use it to train machine learning models.
3. Types of personal data
3.1 The following categories may be processed:
| Category | Examples | Protection |
|---|---|---|
| Identity data | name, display name | encrypted at rest with a Provider-held key |
| Contact data | electronic mail address, telephone number | encrypted at rest with a Provider-held key |
| Account data | account identifier, organisation membership, role, language, status | stored in plain form |
| Authentication data | authentication provider identifier, session records, device records | stored in plain form |
| Verification data | connection records, code metadata, verification events, timestamps | stored in plain form |
| Cryptographic material | public keys, and secrets encrypted for a specific recipient | see 3.2 |
| Technical data | address of origin, device type, application version, diagnostic records | stored in plain form |
| Billing data | billing address, tax identification number, subscription state | stored in plain form; card data never reaches the Provider |
3.2 End-to-end encrypted content. Code secrets and the material derived from them are encrypted on the end user’s device for a specific recipient device. The Provider stores that material in encrypted form and cannot read it. The Provider holds no key that can decrypt it.
4. Categories of data subjects
- the Customer’s members, employees and administrators;
- the Customer’s verified contacts, being external persons whom the Customer verifies;
- persons invited by the Customer who have not yet accepted;
- persons who verify a code issued by the Customer.
5. Instructions of the controller
5.1 The Provider processes personal data only on documented instructions from the Customer. This agreement, the Terms of Service, and the Customer’s use of the product functions constitute those instructions.
5.2 The Provider informs the Customer without delay if, in its opinion, an instruction infringes data protection law. The Provider may suspend the execution of that instruction until the matter is resolved.
5.3 Where the Provider is required by Union or Member State law to process personal data beyond the Customer’s instructions, the Provider informs the Customer of that legal requirement before processing, unless that law forbids the notice on important grounds of public interest.
6. Confidentiality
6.1 The Provider ensures that every person authorised to process the personal data is bound by an obligation of confidentiality, whether by contract or by statute, and that the obligation survives the end of their engagement.
6.2 Access is limited to those persons who need it to supply the service or to meet a legal obligation.
7. Security of processing (Article 32 GDPR)
7.1 The Provider applies the technical and organisational measures described in Annex 1. The Customer has reviewed those measures and considers them appropriate to the risk.
7.2 The Provider may change the measures, provided the level of protection is not reduced.
8. Sub-processors
8.1 The Customer gives general authorisation for the engagement of sub-processors. The current list is Annex 2, which is also published on its own page so that it can be dated and superseded independently of this agreement.
8.2 The Provider informs the Customer at least 30 days before a new sub-processor begins processing, or before an existing one is replaced. Notice is given by electronic mail to the Customer’s administrative contact and by an update to the published list.
8.3 The Customer may object on reasonable data protection grounds within that period. If the parties cannot resolve the objection, the Customer may terminate the affected subscription, with a refund of the unused prepaid period.
8.4 The Provider imposes on every sub-processor, by contract, data protection obligations no less protective than those in this agreement, and remains fully liable to the Customer for the performance of that sub-processor.
9. Assistance to the controller
9.1 Data subject rights. Taking into account the nature of the processing, the Provider assists the Customer by appropriate technical and organisational measures in fulfilling requests under Chapter III GDPR. The product provides export and deletion functions that allow the Customer to answer most requests without contacting the Provider.
9.2 The Provider forwards to the Customer, without undue delay, any request it receives directly from a data subject relating to the Customer’s data, and does not respond to it itself unless legally required or instructed.
9.3 Personal data breach. The Provider notifies the Customer without undue delay, and in any event within 48 hours of becoming aware of a personal data breach affecting the Customer’s data. The notice describes the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed.
9.4 The Provider assists the Customer with data protection impact assessments and prior consultations under Articles 35 and 36 GDPR, so far as the information is available to the Provider and not available to the Customer.
10. Deletion and return
10.1 On termination, the Customer may export their data using the product’s export function for 30 days.
10.2 After that period, the Provider deletes the personal data within a further 60 days, including from backups in accordance with the backup rotation schedule, unless Union or Member State law requires continued storage.
10.3 Billing records are retained for the statutory retention period under German commercial and tax law.
11. Audit
11.1 The Provider makes available to the Customer all information necessary to demonstrate compliance with Article 28 GDPR.
11.2 The Provider satisfies audit obligations in the first instance by providing documentation, including this agreement, Annex 1, the sub-processor list, and any third-party certification or report it holds.
11.3 Where that documentation is not sufficient, the Customer may carry out an audit, or mandate an independent auditor who is not a competitor of the Provider, subject to: reasonable prior notice of at least 30 days, no more than once per calendar year except after a personal data breach, conduct during normal business hours, no disruption to the service, and a written confidentiality undertaking. The Customer bears its own costs.
12. International transfers
12.1 Some sub-processors are established outside the European Economic Area, as marked in Annex 2.
12.2 For each such transfer the Provider relies on the Standard Contractual Clauses adopted by the European Commission (Decision 2021/914), together with the supplementary measures described in Annex 1. Where the recipient is covered by an adequacy decision, the Provider may rely on that decision instead.
12.3 The Provider selects a European deployment region where the sub-processor offers one.
13. Liability and final provisions
13.1 Liability follows the Terms of Service. Article 82 GDPR remains unaffected.
13.2 Where the Terms of Service and this agreement conflict on the processing of personal data, this agreement prevails.
13.3 The Provider may amend this agreement where required by law or by a change to the service. Material amendments are notified at least 30 days in advance. If the Customer objects, they may terminate the affected subscription with a refund of the unused prepaid period.
13.4 German law applies. The place of jurisdiction is Munich, so far as the law permits a choice.
13.5 If any provision is invalid, the remainder stays in force.
Annex 1 — Technical and organisational measures
Encryption
- Personal identifying data is encrypted at rest with AES-256 before it is written to the database.
- Code secrets are encrypted end-to-end for a specific recipient device, using X25519 key agreement and AES-GCM. The Provider cannot decrypt them.
- The keys that protect data at rest are held by a key custody service operated separately from the database, so access to one system does not yield the other.
- All traffic in transit is protected by TLS.
- The mobile application stores local data in an encrypted database.
Access control
- Row-level security policies in the database restrict access by organisation and by role.
- Administrative access is limited to named persons and is separated by role, with a distinction between platform administration and node administration.
- Authentication supports single-use links and third-party identity providers. Biometric confirmation is available for sensitive actions.
Availability and resilience
- The database is hosted with automated backups and point-in-time recovery.
- The infrastructure is operated by an established provider with its own resilience measures.
Separation
- Data is separated by organisation at the database level.
- Production, staging and development environments are separate projects with separate credentials.
Logging and monitoring
- Application events are logged with structured records.
- Administrative actions on entitlements and organisations are recorded in an audit log.
Deletion
- Account deletion removes the account, device records, connections, secrets and push tokens through a single controlled procedure.
Supplementary measures for transfers
- End-to-end encrypted material is unreadable to any sub-processor.
- Personal identifying data is encrypted before it reaches storage.
- European deployment regions are selected where offered.
Annex 2 — Sub-processors
This list is also published on its own page at trusted.codes/legal/subprocessors, where it carries its own date and is superseded independently of this agreement.
Current as of 2026-07-30
Core service
Engaged for every customer of the hosted service.
| Provider | Purpose | Location | Data shared | Transfer basis |
|---|---|---|---|---|
| Supabase | Database, authentication, server functions and file storage | European Union (Stockholm); operator established in the United States | All account, verification and billing data held by the service | Standard Contractual Clauses (2021/914) |
| Vercel | Hosting of the web portals and the public website | United States, with European edge regions | Request metadata: address of origin, user agent, requested path | Standard Contractual Clauses (2021/914) |
| Infisical | Custody of the keys that protect data at rest | European Union | Encryption keys only — no personal data | Inside the EEA |
| Stripe | Payment processing and subscription billing | Ireland and the United States | Billing name and address, tax identification number, subscription state. Card data never reaches Trusted Codes. | Standard Contractual Clauses (2021/914) |
| Resend | Delivery of transactional electronic mail | United States | Electronic mail address and message content, decrypted for the moment of sending | Standard Contractual Clauses (2021/914) |
| Expo | Relay of push notifications to the Apple and Google delivery services | United States | Push token and notification content | Standard Contractual Clauses (2021/914) |
| MaxMind | Fraud scoring and approximate location at sign-in | United States | Address of origin, electronic mail address, device signals | Standard Contractual Clauses (2021/914) |
| Google (Gemini) | Generating the answer of the in-app help assistant | United States | The question asked and the help articles retrieved for it | Standard Contractual Clauses (2021/914) |
| OpenAI | Turning a help question into a search vector, and indexing the help articles | United States | The question asked, and the text of the published help articles | Standard Contractual Clauses (2021/914) |
| Metabase | Analytics dashboards inside the administration console | Infrastructure operated by Trusted Codes | Aggregate figures queried from the service database | Operated by Trusted Codes |
Optional and user-chosen
Engaged only where the end user chooses the feature, or where the component is configured.
| Provider | Purpose | Location | Data shared | Transfer basis |
|---|---|---|---|---|
| Apple | Sign-in, where the end user chooses it | United States | Name and electronic mail address, or the relay address Apple issues instead | Standard Contractual Clauses (2021/914) |
| Sign-in, where the end user chooses it | United States | Name and electronic mail address | Standard Contractual Clauses (2021/914) | |
| Sentry | Error monitoring in the mobile application | European Union (German region) | Error reports: stack trace, application version, device model | Inside the EEA |
Public website only
These handle visitors to trusted.codes, not users of the service.
| Provider | Purpose | Location | Data shared | Transfer basis |
|---|---|---|---|---|
| Plausible Analytics | Visitor statistics for the public website | Infrastructure operated by Trusted Codes | Page requested and referrer, with no cookie and no identifier | Operated by Trusted Codes |
| Google (Sheets and Apps Script) | Receiving the website contact form and the waiting list form | United States | What the sender typed into the form | Standard Contractual Clauses (2021/914) |
| Sentry | Error monitoring for the website, where configured | European Union (German region) | Error reports: stack trace, browser, page | Inside the EEA |
Acceptance record
The Provider records, for each acceptance: the accepting user, the organisation, the document identifier and version, the date and time, the address of origin, and the client identification.
The Customer may retrieve the exact version they accepted at any time, at the versioned address shown at the top of this page. The version identifier does not depend on the language read: all six translations of this text are version 2026-07-30.
Where the parties instead conclude a negotiated or signed agreement, the record stores a reference to that document and marks the source as offline.
A negotiated or signed agreement
A customer whose own legal team needs a negotiated or counter-signed document may request one at privacy@trusted.codes. Accepting this standing agreement is not a waiver of that request, and the request does not have to be settled before a subscription is purchased: this standing agreement governs in the meantime, and a negotiated document replaces it from the date both parties sign.