Preamble
(a) The Parties to this DPA are:
- The Processor: TrustSig OÜ, with registration code 16811982, registered at Vabaduse pst 174b, Tallinn 10917, Estonia ("TrustSig" or the "Processor"). The Processor's contact point for this DPA is the Data Protection Officer, TrustSig OÜ, legal@trustsig.eu; and
- The Controller: the Subscriber identified by its TrustSig account (the "Controller"). The Controller's address, primary administrative contact person, and service-notice email address are those recorded by the Subscriber in the TrustSig dashboard.
Each is a "Party" and together the "Parties".
(b) The Controller accedes to this DPA by accepting the ToS. No physical signature is required for this click-accept form of the DPA.
(c) The Effective Date of this DPA is the Effective Date as defined in the ToS.
(d) The Privacy Notice (https://trustsig.eu/privacy), the ToS and this DPA together form the Agreement between the Parties, consistent with Section 20.1 (Entire Agreement) of the ToS. In the event of any conflict between this DPA and any other part of the Agreement on the processing of personal data on the Controller's behalf, this DPA prevails.
(e) These Clauses apply to the processing of personal data as specified in Annex I.
(f) By accepting the ToS and using the Service, the Controller agrees to this DPA and its Annexes.
Clause 1 – Description of processing(s)
The details of the processing operations, in particular the categories of personal data and the purposes of processing for which the personal data is processed on behalf of the Controller, are specified in Annex I.
Clause 2 – Obligations of the Parties
2.1 Instructions
(a) The Processor shall process personal data only as documented in this DPA, unless required to do so by Union or Member State law to which the Processor is subject. In this case, the Processor shall inform the Controller of that legal requirement before processing, unless the law prohibits this on important grounds of public interest.
(b)The Controller's instructions to TrustSig are: (i) the configuration of the Service made by the Controller in the TrustSig dashboard (including, but not limited to, deployment scope, thresholds, challenge-and-block rules, and the data-retention window); (ii) the use of the Service through the TrustSig API and SDKs; (iii) the ToS, this DPA together with its annexes and any Order Form; and (iv) any further written instructions issued by the Controller to TrustSig through the dashboard, by ticket, or by email to legal@trustsig.eu.
2.2 Purpose limitation
The Processor shall process the personal data only for the specific purpose(s) of the processing, as set out in Annex I, unless it receives further instructions from the Controller.
2.3 Duration of the processing of personal data
Processing by the Processor shall only take place for the duration specified in Annex I.
2.4 Security of processing
(a) The Processor shall at least implement the technical and organisational measures specified in Annex II to ensure the security of the personal data. This includes protecting the data against a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access to the data (personal data breach). In assessing the appropriate level of security, the Parties shall take due account of the state of the art, the costs of implementation, the nature, scope, context and purposes of processing and the risks involved for the data subjects.
(b) The Processor shall grant access to the personal data undergoing processing to members of its personnel only to the extent strictly necessary for implementing, managing and monitoring of the contract. The Processor shall ensure that persons authorised to process the personal data received have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
2.5 Sensitive data
(a)Sensitive data means personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, genetic data or biometric data for the purpose of uniquely identifying a natural person, data concerning health or a person's sex life or sexual orientation, or data relating to criminal convictions and offences ("sensitive data").
(b) The Service is not designed to process such sensitive data. The Controller shall not configure the Service to capture, transmit or store sensitive data. Where sensitive data nevertheless enters the Service inadvertently (for example because such data has been included in a request body that the Controller has elected to forward for inspection), TrustSig will treat that data subject to the same safeguards applied to all Controller personal data, will not single it out for additional use, and will delete it on the standard Controller-configured retention cycle. The Controller remains responsible for ensuring that its use of the Service does not direct sensitive data to TrustSig.
2.6 Documentation and compliance
(a) The Parties shall be able to demonstrate compliance with these Clauses.
(b)The Processor conducts its own audits of the Service aligned with the controls of ISO/IEC 27001:2022 and uses qualified internal or independent auditors. The Controller may not initiate its own on-site or remote audit of TrustSig and is not entitled to inspect TrustSig's internal audit reports as such. For Subscribers other than those on the Free Plan, TrustSig may, in its discretion, make available a written audit summary or certificate at the Controller's reasonable request and subject to a non-disclosure agreement.
(c)Notwithstanding the foregoing, TrustSig shall provide the Controller with such additional information as is reasonably necessary to demonstrate compliance with the obligations of this DPA, to the extent required by Article 28(3)(h) of Regulation (EU) 2016/679, and the Parties shall cooperate in good faith with the competent supervisory authority's requests. Free Plan use of the Service is provided on a best-effort, "as-is" basis as set out in the ToS.
2.7 Use of sub-processors
(a) By accepting this DPA the Controller grants TrustSig a standing general written authorisation under Article 28(2) of Regulation (EU) 2016/679 to engage sub-processors and to add, replace or remove sub-processors from time to time.
(b) The agreed list of sub-processors referred to in this sub-clause is the list of sub-processors published in the TrustSig Privacy Notice at https://trustsig.eu/privacy. TrustSig publishes additions to or replacements within that list in the same location. That publication constitutes the written information referred to in this sub-clause and is available to all Controllers regardless of Subscription Plan. In addition, TrustSig maintains a more detailed sub-processor list, which it makes available on request to Subscribers on paid Subscription Plans. Free Plan Subscribers rely on the published list.
(c)The Controller's sole remedy if the Controller does not accept a particular change to the list is to terminate the Subscription in accordance with the ToS. This DPA does not give the Controller a right of veto over a specific sub-processor change, nor a right of objection exercisable against TrustSig in respect of a specific sub-processor.
(d) Where the Processor engages a sub-processor for carrying out specific processing activities, it shall do so by way of a contract which imposes on the sub-processor, in substance, the same data protection obligations as the ones imposed on the data Processor in accordance with these Clauses. The Processor shall ensure that the sub-processor complies with the obligations to which the Processor is subject pursuant to these Clauses and to Regulation (EU) 2016/679.
2.8 International transfers
(a) The Controller agrees that where the Processor engages a sub-processor for carrying out specific processing activities and those processing activities involve a transfer of personal data within the meaning of Chapter V of Regulation (EU) 2016/679, the Processor and the sub-processor can ensure compliance with Chapter V of Regulation (EU) 2016/679 by using standard contractual clauses adopted by the Commission in accordance with Article 46(2) of Regulation (EU) 2016/679, provided the conditions for the use of those standard contractual clauses are met.
(b) Processing of Controller personal data is performed in the European Union region by default, for non-EU sub-processors EU-region data residency is applied where possible. Sub-processor personnel located outside the European Economic Area may access Controller personal data only as strictly necessary to provide support, maintenance or security functions, and only under safeguards adopted in accordance with Chapter V of Regulation (EU) 2016/679 – in particular, standard contractual clauses adopted by the Commission and/or, where applicable, the EU-U.S. Data Privacy Framework.
Clause 3 – Assistance to the Controller
(a) The Processor shall promptly notify the Controller of any request it has received from the data subject. It shall not respond to the request itself, unless authorised to do so by the Controller.
(b)The Processor shall assist the Controller in fulfilling its obligations to respond to data subjects' requests to exercise their rights, taking into account the nature of the processing.
(c) The Processor shall furthermore assist the Controller in ensuring compliance with the following obligations, taking into account the nature of the data processing and the information available to the Processor:
- (1) the obligation to carry out an assessment of the impact of the envisaged processing operations on the protection of personal data (a "data protection impact assessment") where a type of processing is likely to result in a high risk to the rights and freedoms of natural persons;
- (2) the obligation to consult the competent supervisory authority/ies prior to processing where a data protection impact assessment indicates that the processing would result in a high risk in the absence of measures taken by the Controller to mitigate the risk;
- (3) the obligation to ensure that personal data is accurate and up to date, by informing the Controller without delay if the Processor becomes aware that the personal data it is processing is inaccurate or has become outdated.
Clause 4 – Notification of personal data breach
In the event of a personal data breach, the Processor shall cooperate with and assist the Controller for the Controller to comply with its obligations under Articles 33 and 34 Regulation (EU) 2016/679, taking into account the nature of processing and the information available to the Processor.
4.1 Data breach concerning data processed by the Controller
In the event of a personal data breach concerning data processed by the Controller, the Processor shall assist the Controller:
(a) in notifying the personal data breach to the competent supervisory authority/ies, without undue delay after the Controller has become aware of it, where relevant (unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons);
(b)in obtaining the following information which, pursuant to Article 33(3) Regulation (EU) 2016/679, shall be stated in the Controller's notification, and must at least include:
- (1) the nature of the personal data including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;
- (2) the likely consequences of the personal data breach;
- (3) the measures taken or proposed to be taken by the Controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.
(c) Where, and insofar as, it is not possible to provide all this information at the same time, the initial notification shall contain the information then available and further information shall, as it becomes available, subsequently be provided without undue delay.
(d) In complying, pursuant to Article 34 Regulation (EU) 2016/679, with the obligation to communicate without undue delay the personal data breach to the data subject, when the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons.
4.2 Data breach concerning data processed by the Processor
(a) In the event of a personal data breach concerning data processed by the Processor, the Processor shall notify the Controller without undue delay after the Processor having become aware of the breach. Such notification shall contain, at least:
- (1) a description of the nature of the breach (including, where possible, the categories and approximate number of data subjects and data records concerned);
- (2) the details of a contact point where more information concerning the personal data breach can be obtained;
- (3) its likely consequences and the measures taken or proposed to be taken to address the breach, including to mitigate its possible adverse effects.
(b) Where, and insofar as, it is not possible to provide all this information at the same time, the initial notification shall contain the information then available and further information shall, as it becomes available, subsequently be provided without undue delay.
(c)The Processor is "aware" of a personal data breach once the Processor has a reasonable degree of certainty that a security incident has occurred which has led to personal data being compromised, in line with the awareness threshold set out in EDPB Guidelines 9/2022 on personal-data-breach notification. The time 72 hours within which TrustSig must notify the Controller starts running only from the point at which the Processor has both become aware of, and verified the existence of, the personal data breach.
Clause 5 – Non-compliance with the Clauses and termination
(a) Without prejudice to any provisions of Regulation (EU) 2016/679, in the event that a Party is in breach of its obligations under these Clauses, the other Party may require the processing of personal data to be suspended until the Party in breach complies with these Clauses or the contract is terminated. Each Party shall promptly inform the other Party in case it is unable to comply with these Clauses, for whatever reason.
(b) Either Party shall be entitled to terminate the contract insofar as it concerns the processing of personal data in accordance with these Clauses if:
- (1) the processing of personal data has been suspended pursuant to point (a) and compliance with these Clauses is not restored within a reasonable time and in any event within one month following suspension;
- (2) the other Party is in substantial or persistent breach of these Clauses or of its obligations under Regulation (EU) 2016/679.
(c) Following termination of the contract, the Processor shall, delete all personal data processed on behalf of the Controller, unless Union or Member State law requires storage of the personal data. Until the data is deleted, the Processor shall continue to ensure compliance with these Clauses.
(d)During the term of the Subscription, the retention of Controller personal data on TrustSig's systems is set by the Controller in the TrustSig dashboard within a range of 30 days to 18 months; raw request signals are deleted or irreversibly anonymised at the end of that window. Upon deletion of the Controller's account, the Processor deletes the Controller personal data processed on the Controller's behalf, in line with the standard account-deletion functionality in the TrustSig dashboard and TrustSig's standard backup-rotation cycle. The ending of a Subscription (whether a free or a paid plan), without deletion of the account, does not of itself trigger deletion of Controller personal data beyond the expiry of the configured retention window. The Controller may, in the alternative, instruct the Processor in writing to return the personal data by submitting a written request before initiating the account deletion.
(e) The following categories of data are not Controller personal data processed under this DPA and are not subject to deletion under this sub-clause:
- (1) Account-registration and contractual data – information which TrustSig processes as a data controller for its own purposes of account administration, billing, invoicing and accounting (including invoices and accounting source documents retained for the period prescribed by the Estonian Accounting Act), and which is governed by the TrustSig Privacy Notice rather than by this DPA; and
- (2) Anonymised threat-intelligence data – information that has been irreversibly anonymised so that it does not identify, and cannot reasonably be used to re-identify, any individual, and which therefore falls outside the definition of personal data in Article 4(1) of Regulation (EU) 2016/679 (consistent with Recital 26 thereof). Anonymisation is performed before any further use of the data and is irreversible.
Annex I – Description of the Processing
Categories of data subjects whose personal data is processed
Visitors ("End Users") to the Controller's website, application or other digital property that is protected by the Service.
Categories of personal data processed
TrustSig's two services process different categories of data.
Bot protection (TrustSig Web) processes the following signals. TrustSig has no practical means or additional context to link these signals to an identified natural person. TrustSig therefore treats them as not personal data under the GDPR.
| Category | Examples |
|---|---|
| Network identifiers | IP address (source IP) of the End User's connection, stored as a hash |
| Approximate location | Geolocation derived from the source IP (typically to country / region level) |
| Connection metadata | User-agent string and other HTTP request headers |
| Device characteristics | Device-fingerprint signals (for example browser, operating system, screen and language attributes) |
| Behavioural signals | Patterns of interaction with the protected resource (for example navigation, timing, input cadence) |
| Trust signals | Computed risk scores assigned to the request by the Service, and the corresponding disposition (allow, challenge or block) |
Fraud prevention (TrustSig Pro) processes the signals above and, only where the Controller chooses to share it, the following personal data:
| Category | Examples |
|---|---|
| Account identifiers (shared at the Controller's option) | E-mail address, username, name, phone number |
The Controller shall not transmit, and TrustSig does not request government identifier, financial account, content of communications or other detailed personal data as part of the processing carried out under this DPA, except where such data is contained in HTTP request fields that the Controller chooses to forward to the Service.
Sensitive data processed (if applicable) and applied restrictions or safeguards
No sensitive data within the meaning of Articles 9 and 10 of Regulation (EU) 2016/679 is intentionally processed under this DPA. The Controller shall not configure the Service to capture sensitive data. Where sensitive data is nevertheless transmitted to the Service inadvertently, TrustSig applies the same security measures as to all Controller personal data, does not single it out for additional use, and deletes it on the standard Controller-configured retention cycle.
Nature of the processing
- Real-time signal collection – collection of End User signals from each request to the Controller's protected resource.
- Server-side enrichment – enrichment of those signals with TrustSig's own historical threat-intelligence data.
- Trust/risk scoring – computation of real-time trust/risk scores.
- Request handling – allowing, challenging or blocking the request in accordance with the Controller's configuration.
- Storage – storage of raw request signals during the Controller-configured retention window.
- Security reporting – generation of security reports made available to the Controller through the dashboard and API.
- Anonymisation for onward use – irreversible anonymisation of indicators of compromise and related threat intelligence signals upon expiry of the retention window, for onward threat-intelligence use by TrustSig.
Purpose(s) for which the personal data is processed on behalf of the Controller
Protection of the Controller's website, application or other digital property against malicious, fraudulent and automated activity – including, but not limited to, bots, fake-account creation, credential stuffing, scraping, scalping, denial-of-service traffic, vulnerability probing, fraud, and similar threats – by means of real-time analysis of End User signals, computation of a trust / risk score, and a disposition decision in accordance with the Controller's configuration.
Duration of the processing
For the term of the Subscription as defined in the ToS, plus the data-retention window configured by the Controller in the TrustSig dashboard (between 30 days and 18 months), after which raw request signals are either deleted or irreversibly anonymised. Account-registration and contractual data processed by TrustSig as a controller in its own right (see Clause 5, deletion specification) is retained under the periods set out in the TrustSig Privacy Notice and is outside the scope of this DPA.
For processing by sub-processors, also specify subject matter, nature and duration of the processing
The subject matter, nature and duration of processing by each sub-processor is set out by reference in the TrustSig Privacy Notice. In summary: infrastructure and edge-network sub-processors provide hosting and content-delivery functions for the Service in the EU region for the duration of the Subscription and the applicable retention window.
Annex II – Technical and Organisational Measures
This Annex describes the technical and organisational measures implemented by TrustSig in respect of the processing carried out on behalf of the Controller under this DPA. They are reviewed at least annually and updated from time to time. Updates shall not result in a material reduction of the security of the Service.
1. Information security governance and risk management
TrustSig operates an information security management system (ISMS) aligned with ISO/IEC 27001:2022 (Annex A controls). Information security roles and responsibilities are documented. An information security policy is in force and reviewed at least annually. An information security risk-assessment and treatment process is in place. The effectiveness of the controls is reviewed at least annually by management.
2. Data minimisation, retention and deletion
Only the minimum signals necessary to compute a trust/risk score and produce security reports are collected from each request. Retention of raw request signals is controlled by the Controller through the TrustSig dashboard, configurable between 30 days and 18 months. Automatic deletion takes place at the expiry of the configured retention window. Upon deletion of the Controller's account, secure deletion of Controller personal data is performed in line with the standard account-deletion mechanism and the standard backup-rotation cycle.
3. Anonymisation and pseudonymisation
Threat-intelligence indicators and related signals are irreversibly anonymised before any further use by TrustSig, so that they do not identify, and cannot reasonably be used to re-identify, any individual. Anonymisation is performed using techniques feasible to specific use cases, such as identifier removal, masking, hashing, or generalisation. The resulting data falls outside the definition of personal data and is used to maintain and improve detection of malicious activity. TrustSig undertakes not to attempt to re-identify any individual from anonymised data. No pseudonymisation takes place.
4. Security in transit and at rest
Personal data in transit to and from the Service is protected by Transport Layer Security secure versions with modern cipher suites for both the application programming interface and the administrative dashboard. Personal data at rest is encrypted using AES-256. Cryptographic keys and secrets are stored in a vault and managed in accordance with key-management controls.
5. Personal data breach handling and continuity
TrustSig operates an incident response process covering detection, triage, containment, eradication, recovery, post-incident review and notification. Personal data breach notification to the Controller is provided as set out in Clause 4. Incident records are retained for at least 10 years from closure. Business continuity and disaster recovery procedures are in place and tested periodically.
6. Access management
Access to systems processing Controller personal data is controlled by role-based access control on the principle of least privilege. Multi-factor authentication is mandatory for all TrustSig personnel with access to Controller personal data. Access rights are reviewed periodically. Joiners, movers and leavers are processed promptly. Access is revoked without undue delay upon a personnel change that removes the need to access Controller personal data.
7. Physical security
Processing of Controller personal data is performed in third-party data centres operated by TrustSig's infrastructure sub-processors and on the global edge network. Physical security at those facilities (including perimeter control, access management to data-centre floors, environmental controls, and decommissioning of media) is provided by those sub-processors. Their compliance is maintained through their own security certifications, which include ISO/IEC 27001 and SOC 2 as published by the respective providers. TrustSig personnel perform processing of Controller personal data from controlled environments and do not process Controller personal data in unsecured public locations.
8. Data quality
Inputs to the Service are validated, and the outputs of the scoring engine are subject to ongoing measurement and quality testing, in support of the accuracy principle. Defects identified through quality testing are tracked and remediated.
9. Event logging and monitoring
TrustSig maintains audit logs of administrative actions and security-relevant events on systems processing Controller personal data. A continuous security monitoring and alerting capability is in place. Alerts on privileged actions are reviewed by the security team. Operational and security logs are retained for 3 years.
10. Data portability
Controller personal data processed by the Service can be acquired by the Controller through a written request to TrustSig. Machine-readable data formats are used (JSON, CSV).
11. Continuity and change management
Backup and restore practices are in place. An internal change management process is applied for controlled Service modifications and updates.
12. Personnel
All TrustSig personnel with access to Controller personal data are bound by written confidentiality undertakings or are under an appropriate statutory obligation of confidentiality by law. TrustSig provides security awareness training to its non-security personnel. Background checks are carried out where lawful.
13. Sub-processor security
Each prospective sub-processor is subjected to a security and data protection assessment before being engaged. TrustSig engages only sub-processors that demonstrate robust information security and data protection practices.
14. Verification of measures
TrustSig performs internal assessments and reviews the effectiveness of the measures at least annually. Where TrustSig issues an attestation, certification or audit summary covering the Service, it may make that summary available to the Controller as set out in the audit-rights specification under Clause 2.6 above.
Contact
Questions about this DPA, or about the processing of personal data by TrustSig, may be addressed to the TrustSig Data Protection Officer at legal@trustsig.eu.