Trusted Codes

Data Processing Agreement — Business Edition

Version 2026-07-30

In effect from 2026-07-30

This is the permanent address of one version. It will keep showing this exact text.

This English text is the authoritative version of this agreement. Translations into other languages are provided for convenience.

Agreement on the processing of personal data on behalf of a controller, pursuant to Article 28 of Regulation (EU) 2016/679 (“GDPR”).

This agreement applies to the Trusted Codes Business Edition, which runs on Trusted Codes infrastructure. It does not apply to the Enterprise Edition, where the customer operates their own node and the Provider does not process the customer’s user data. A separate, shorter agreement covers that case.

Parties

Controller (“Customer”): the organisation identified in the Trusted Codes account that accepted this agreement, together with the acceptance record described at the end of this document.

Processor (“Provider”): Stefan Sonntag, trading as Trusted Codes
Leonrodstr. 14b, 80634 Munich, Germany
Contact: privacy@trusted.codes

This agreement forms part of, and is subordinate to, the Trusted Codes Terms of Service. It takes effect when the Customer accepts it, and remains in force for as long as the Provider processes personal data on behalf of the Customer.

1. Subject matter and duration

1.1 The Provider processes personal data on behalf of the Customer solely to supply the Trusted Codes Business Edition: a verification service that issues and verifies word-based access codes between identified people, together with the organisation administration, notification and support functions described in the product documentation.

1.2 The duration of the processing corresponds to the duration of the Customer’s subscription, extended by the deletion periods in Section 10.

2. Nature and purpose of the processing

2.1 The Provider processes personal data only to:

  • create and administer user accounts and organisation membership;
  • generate, distribute and verify access codes and related cryptographic material;
  • deliver notifications by electronic mail and push message;
  • provide the administration console, reporting and support;
  • protect the service against fraud and abuse;
  • meet its own legal obligations.

2.2 The Provider does not process the personal data for its own purposes. The Provider does not sell personal data, and does not use it to train machine learning models.

3. Types of personal data

3.1 The following categories may be processed:

CategoryExamplesProtection
Identity dataname, display nameencrypted at rest with a Provider-held key
Contact dataelectronic mail address, telephone numberencrypted at rest with a Provider-held key
Account dataaccount identifier, organisation membership, role, language, statusstored in plain form
Authentication dataauthentication provider identifier, session records, device recordsstored in plain form
Verification dataconnection records, code metadata, verification events, timestampsstored in plain form
Cryptographic materialpublic keys, and secrets encrypted for a specific recipientsee 3.2
Technical dataaddress of origin, device type, application version, diagnostic recordsstored in plain form
Billing databilling address, tax identification number, subscription statestored in plain form; card data never reaches the Provider

3.2 End-to-end encrypted content. Code secrets and the material derived from them are encrypted on the end user’s device for a specific recipient device. The Provider stores that material in encrypted form and cannot read it. The Provider holds no key that can decrypt it.

4. Categories of data subjects

  • the Customer’s members, employees and administrators;
  • the Customer’s verified contacts, being external persons whom the Customer verifies;
  • persons invited by the Customer who have not yet accepted;
  • persons who verify a code issued by the Customer.

5. Instructions of the controller

5.1 The Provider processes personal data only on documented instructions from the Customer. This agreement, the Terms of Service, and the Customer’s use of the product functions constitute those instructions.

5.2 The Provider informs the Customer without delay if, in its opinion, an instruction infringes data protection law. The Provider may suspend the execution of that instruction until the matter is resolved.

5.3 Where the Provider is required by Union or Member State law to process personal data beyond the Customer’s instructions, the Provider informs the Customer of that legal requirement before processing, unless that law forbids the notice on important grounds of public interest.

6. Confidentiality

6.1 The Provider ensures that every person authorised to process the personal data is bound by an obligation of confidentiality, whether by contract or by statute, and that the obligation survives the end of their engagement.

6.2 Access is limited to those persons who need it to supply the service or to meet a legal obligation.

7. Security of processing (Article 32 GDPR)

7.1 The Provider applies the technical and organisational measures described in Annex 1. The Customer has reviewed those measures and considers them appropriate to the risk.

7.2 The Provider may change the measures, provided the level of protection is not reduced.

8. Sub-processors

8.1 The Customer gives general authorisation for the engagement of sub-processors. The current list is Annex 2, which is also published on its own page so that it can be dated and superseded independently of this agreement.

8.2 The Provider informs the Customer at least 30 days before a new sub-processor begins processing, or before an existing one is replaced. Notice is given by electronic mail to the Customer’s administrative contact and by an update to the published list.

8.3 The Customer may object on reasonable data protection grounds within that period. If the parties cannot resolve the objection, the Customer may terminate the affected subscription, with a refund of the unused prepaid period.

8.4 The Provider imposes on every sub-processor, by contract, data protection obligations no less protective than those in this agreement, and remains fully liable to the Customer for the performance of that sub-processor.

9. Assistance to the controller

9.1 Data subject rights. Taking into account the nature of the processing, the Provider assists the Customer by appropriate technical and organisational measures in fulfilling requests under Chapter III GDPR. The product provides export and deletion functions that allow the Customer to answer most requests without contacting the Provider.

9.2 The Provider forwards to the Customer, without undue delay, any request it receives directly from a data subject relating to the Customer’s data, and does not respond to it itself unless legally required or instructed.

9.3 Personal data breach. The Provider notifies the Customer without undue delay, and in any event within 48 hours of becoming aware of a personal data breach affecting the Customer’s data. The notice describes the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed.

9.4 The Provider assists the Customer with data protection impact assessments and prior consultations under Articles 35 and 36 GDPR, so far as the information is available to the Provider and not available to the Customer.

10. Deletion and return

10.1 On termination, the Customer may export their data using the product’s export function for 30 days.

10.2 After that period, the Provider deletes the personal data within a further 60 days, including from backups in accordance with the backup rotation schedule, unless Union or Member State law requires continued storage.

10.3 Billing records are retained for the statutory retention period under German commercial and tax law.

11. Audit

11.1 The Provider makes available to the Customer all information necessary to demonstrate compliance with Article 28 GDPR.

11.2 The Provider satisfies audit obligations in the first instance by providing documentation, including this agreement, Annex 1, the sub-processor list, and any third-party certification or report it holds.

11.3 Where that documentation is not sufficient, the Customer may carry out an audit, or mandate an independent auditor who is not a competitor of the Provider, subject to: reasonable prior notice of at least 30 days, no more than once per calendar year except after a personal data breach, conduct during normal business hours, no disruption to the service, and a written confidentiality undertaking. The Customer bears its own costs.

12. International transfers

12.1 Some sub-processors are established outside the European Economic Area, as marked in Annex 2.

12.2 For each such transfer the Provider relies on the Standard Contractual Clauses adopted by the European Commission (Decision 2021/914), together with the supplementary measures described in Annex 1. Where the recipient is covered by an adequacy decision, the Provider may rely on that decision instead.

12.3 The Provider selects a European deployment region where the sub-processor offers one.

13. Liability and final provisions

13.1 Liability follows the Terms of Service. Article 82 GDPR remains unaffected.

13.2 Where the Terms of Service and this agreement conflict on the processing of personal data, this agreement prevails.

13.3 The Provider may amend this agreement where required by law or by a change to the service. Material amendments are notified at least 30 days in advance. If the Customer objects, they may terminate the affected subscription with a refund of the unused prepaid period.

13.4 German law applies. The place of jurisdiction is Munich, so far as the law permits a choice.

13.5 If any provision is invalid, the remainder stays in force.

Annex 1 — Technical and organisational measures

Encryption

  • Personal identifying data is encrypted at rest with AES-256 before it is written to the database.
  • Code secrets are encrypted end-to-end for a specific recipient device, using X25519 key agreement and AES-GCM. The Provider cannot decrypt them.
  • The keys that protect data at rest are held by a key custody service operated separately from the database, so access to one system does not yield the other.
  • All traffic in transit is protected by TLS.
  • The mobile application stores local data in an encrypted database.

Access control

  • Row-level security policies in the database restrict access by organisation and by role.
  • Administrative access is limited to named persons and is separated by role, with a distinction between platform administration and node administration.
  • Authentication supports single-use links and third-party identity providers. Biometric confirmation is available for sensitive actions.

Availability and resilience

  • The database is hosted with automated backups and point-in-time recovery.
  • The infrastructure is operated by an established provider with its own resilience measures.

Separation

  • Data is separated by organisation at the database level.
  • Production, staging and development environments are separate projects with separate credentials.

Logging and monitoring

  • Application events are logged with structured records.
  • Administrative actions on entitlements and organisations are recorded in an audit log.

Deletion

  • Account deletion removes the account, device records, connections, secrets and push tokens through a single controlled procedure.

Supplementary measures for transfers

  • End-to-end encrypted material is unreadable to any sub-processor.
  • Personal identifying data is encrypted before it reaches storage.
  • European deployment regions are selected where offered.

Annex 2 — Sub-processors

This list is also published on its own page at trusted.codes/legal/subprocessors, where it carries its own date and is superseded independently of this agreement.

Current as of 2026-07-30

Core service

Engaged for every customer of the hosted service.

ProviderPurposeLocationData sharedTransfer basis
SupabaseDatabase, authentication, server functions and file storageEuropean Union (Stockholm); operator established in the United StatesAll account, verification and billing data held by the serviceStandard Contractual Clauses (2021/914)
VercelHosting of the web portals and the public websiteUnited States, with European edge regionsRequest metadata: address of origin, user agent, requested pathStandard Contractual Clauses (2021/914)
InfisicalCustody of the keys that protect data at restEuropean UnionEncryption keys only — no personal dataInside the EEA
StripePayment processing and subscription billingIreland and the United StatesBilling name and address, tax identification number, subscription state. Card data never reaches Trusted Codes.Standard Contractual Clauses (2021/914)
ResendDelivery of transactional electronic mailUnited StatesElectronic mail address and message content, decrypted for the moment of sendingStandard Contractual Clauses (2021/914)
ExpoRelay of push notifications to the Apple and Google delivery servicesUnited StatesPush token and notification contentStandard Contractual Clauses (2021/914)
MaxMindFraud scoring and approximate location at sign-inUnited StatesAddress of origin, electronic mail address, device signalsStandard Contractual Clauses (2021/914)
Google (Gemini)Generating the answer of the in-app help assistantUnited StatesThe question asked and the help articles retrieved for itStandard Contractual Clauses (2021/914)
OpenAITurning a help question into a search vector, and indexing the help articlesUnited StatesThe question asked, and the text of the published help articlesStandard Contractual Clauses (2021/914)
MetabaseAnalytics dashboards inside the administration consoleInfrastructure operated by Trusted CodesAggregate figures queried from the service databaseOperated by Trusted Codes

Optional and user-chosen

Engaged only where the end user chooses the feature, or where the component is configured.

ProviderPurposeLocationData sharedTransfer basis
AppleSign-in, where the end user chooses itUnited StatesName and electronic mail address, or the relay address Apple issues insteadStandard Contractual Clauses (2021/914)
GoogleSign-in, where the end user chooses itUnited StatesName and electronic mail addressStandard Contractual Clauses (2021/914)
SentryError monitoring in the mobile applicationEuropean Union (German region)Error reports: stack trace, application version, device modelInside the EEA

Public website only

These handle visitors to trusted.codes, not users of the service.

ProviderPurposeLocationData sharedTransfer basis
Plausible AnalyticsVisitor statistics for the public websiteInfrastructure operated by Trusted CodesPage requested and referrer, with no cookie and no identifierOperated by Trusted Codes
Google (Sheets and Apps Script)Receiving the website contact form and the waiting list formUnited StatesWhat the sender typed into the formStandard Contractual Clauses (2021/914)
SentryError monitoring for the website, where configuredEuropean Union (German region)Error reports: stack trace, browser, pageInside the EEA

Acceptance record

The Provider records, for each acceptance: the accepting user, the organisation, the document identifier and version, the date and time, the address of origin, and the client identification.

The Customer may retrieve the exact version they accepted at any time, at the versioned address shown at the top of this page. The version identifier does not depend on the language read: all six translations of this text are version 2026-07-30.

Where the parties instead conclude a negotiated or signed agreement, the record stores a reference to that document and marks the source as offline.

A negotiated or signed agreement

A customer whose own legal team needs a negotiated or counter-signed document may request one at privacy@trusted.codes. Accepting this standing agreement is not a waiver of that request, and the request does not have to be settled before a subscription is purchased: this standing agreement governs in the meantime, and a negotiated document replaces it from the date both parties sign.