Data Processing Addendum
Last updated: 5 October 2026
This Data Processing Addendum ("DPA") forms part of the Terms of Service (or any order form) between the customer ("Controller") and Khandaker Saifuzzaman, trading as TrustDyne ("TrustDyne", "Processor"). It applies where TrustDyne processes personal data on the customer's behalf through the Service, and reflects Article 28 of UK GDPR and, where it applies, EU GDPR. If it conflicts with the Terms on data protection, this DPA prevails.
1. Subject matter and details
| Item | Detail |
|---|---|
| Subject matter and nature | Hosting, analysing and reporting on Customer Content through the Service |
| Purpose | Providing the Service to the Controller, including security scanning, SBOM and vulnerability analysis, AI-assisted remediation, compliance mapping, monitoring and support |
| Duration | The term of the agreement, plus the deletion periods in section 9 |
| Types of personal data | Whatever is contained in Customer Content: typically developer and employee names, emails and usernames found in code, configuration, logs and cloud metadata, plus account details of the Controller's users |
| Data subjects | The Controller's staff, contractors and users, and any individuals whose data appears in the scanned material |
| Special category data | Not intended. The Controller must not submit it. |
2. Processing on instructions
TrustDyne will process personal data only on the Controller's documented instructions, which are the Terms, this DPA and the Controller's use of the Service's features, unless the law requires otherwise. TrustDyne will tell the Controller if an instruction appears to infringe data protection law.
3. Confidentiality
TrustDyne makes sure that people authorised to process the data are under a duty of confidentiality and that access is limited to those who need it.
4. Security
TrustDyne applies appropriate technical and organisational measures, including those on the Security and Trust page: encryption at rest and in transit, access control with least privilege, isolated and ephemeral processing, audit logging, and deletion of uploaded files after analysis.
5. Sub-processors
The Controller gives general authorisation for the sub-processors on the Sub-processors page. TrustDyne will give at least 30 days' notice by email or on that page before adding or replacing one. The Controller can object on reasonable data protection grounds within that period. If the parties cannot resolve the objection, the Controller can cancel the affected Service. TrustDyne remains responsible for its sub-processors and binds them to data protection terms no less protective than this DPA.
6. International transfers
The Service runs in the AWS US East (N. Virginia) region. Transfers of personal data from the UK or EEA to the United States rely on the UK Extension to the EU-US Data Privacy Framework for certified sub-processors, or on another safeguard permitted by UK GDPR or EU GDPR, such as standard contractual clauses with the UK addendum.
7. Assisting the Controller
TrustDyne will, taking account of the nature of the processing and the information it has, help the Controller (a) respond to requests from data subjects, (b) meet its security, breach notification and impact assessment duties, and (c) consult regulators. TrustDyne can charge reasonable costs for assistance that goes beyond using the Service's own features.
8. Personal data breaches
TrustDyne will notify the Controller without undue delay after becoming aware of a personal data breach affecting Customer Content and, where it can, within 72 hours. The notice will describe what is known about the breach, its likely consequences and the steps taken, and TrustDyne will provide further information as it becomes available.
9. Deletion and return
Uploaded files are deleted when analysis finishes. Reports, findings and SBOMs are deleted automatically 12 months after creation, and earlier if the Controller deletes them. On termination, TrustDyne will, at the Controller's choice, return or delete the remaining personal data within 90 days, unless the law requires it to keep a copy. Copies in backups are deleted when the backups expire, within 90 days.
10. Audit
TrustDyne will provide the information reasonably needed to show compliance with this DPA, and will allow audits by the Controller or its appointed auditor on reasonable notice, no more than once a year unless a breach or regulator requires otherwise, during business hours and subject to confidentiality. TrustDyne can meet a request first by supplying relevant documentation or independent reports.
11. Controller responsibilities
The Controller confirms it has a lawful basis for the processing and for the instructions it gives, has told data subjects as required, and will not submit content it is not entitled to submit.
12. Liability and law
Each party's liability under this DPA is subject to the limits in the Terms. This DPA is governed by the law of England and Wales. Questions: legal@trustdyne.com.
TrustDyne