Data Processing Addendum

Last updated: 5 October 2026

This Data Processing Addendum ("DPA") forms part of the Terms of Service (or any order form) between the customer ("Controller") and Khandaker Saifuzzaman, trading as TrustDyne ("TrustDyne", "Processor"). It applies where TrustDyne processes personal data on the customer's behalf through the Service, and reflects Article 28 of UK GDPR and, where it applies, EU GDPR. If it conflicts with the Terms on data protection, this DPA prevails.

1. Subject matter and details

ItemDetail
Subject matter and natureHosting, analysing and reporting on Customer Content through the Service
PurposeProviding the Service to the Controller, including security scanning, SBOM and vulnerability analysis, AI-assisted remediation, compliance mapping, monitoring and support
DurationThe term of the agreement, plus the deletion periods in section 9
Types of personal dataWhatever is contained in Customer Content: typically developer and employee names, emails and usernames found in code, configuration, logs and cloud metadata, plus account details of the Controller's users
Data subjectsThe Controller's staff, contractors and users, and any individuals whose data appears in the scanned material
Special category dataNot intended. The Controller must not submit it.

2. Processing on instructions

TrustDyne will process personal data only on the Controller's documented instructions, which are the Terms, this DPA and the Controller's use of the Service's features, unless the law requires otherwise. TrustDyne will tell the Controller if an instruction appears to infringe data protection law.

3. Confidentiality

TrustDyne makes sure that people authorised to process the data are under a duty of confidentiality and that access is limited to those who need it.

4. Security

TrustDyne applies appropriate technical and organisational measures, including those on the Security and Trust page: encryption at rest and in transit, access control with least privilege, isolated and ephemeral processing, audit logging, and deletion of uploaded files after analysis.

5. Sub-processors

The Controller gives general authorisation for the sub-processors on the Sub-processors page. TrustDyne will give at least 30 days' notice by email or on that page before adding or replacing one. The Controller can object on reasonable data protection grounds within that period. If the parties cannot resolve the objection, the Controller can cancel the affected Service. TrustDyne remains responsible for its sub-processors and binds them to data protection terms no less protective than this DPA.

6. International transfers

The Service runs in the AWS US East (N. Virginia) region. Transfers of personal data from the UK or EEA to the United States rely on the UK Extension to the EU-US Data Privacy Framework for certified sub-processors, or on another safeguard permitted by UK GDPR or EU GDPR, such as standard contractual clauses with the UK addendum.

7. Assisting the Controller

TrustDyne will, taking account of the nature of the processing and the information it has, help the Controller (a) respond to requests from data subjects, (b) meet its security, breach notification and impact assessment duties, and (c) consult regulators. TrustDyne can charge reasonable costs for assistance that goes beyond using the Service's own features.

8. Personal data breaches

TrustDyne will notify the Controller without undue delay after becoming aware of a personal data breach affecting Customer Content and, where it can, within 72 hours. The notice will describe what is known about the breach, its likely consequences and the steps taken, and TrustDyne will provide further information as it becomes available.

9. Deletion and return

Uploaded files are deleted when analysis finishes. Reports, findings and SBOMs are deleted automatically 12 months after creation, and earlier if the Controller deletes them. On termination, TrustDyne will, at the Controller's choice, return or delete the remaining personal data within 90 days, unless the law requires it to keep a copy. Copies in backups are deleted when the backups expire, within 90 days.

10. Audit

TrustDyne will provide the information reasonably needed to show compliance with this DPA, and will allow audits by the Controller or its appointed auditor on reasonable notice, no more than once a year unless a breach or regulator requires otherwise, during business hours and subject to confidentiality. TrustDyne can meet a request first by supplying relevant documentation or independent reports.

11. Controller responsibilities

The Controller confirms it has a lawful basis for the processing and for the instructions it gives, has told data subjects as required, and will not submit content it is not entitled to submit.

12. Liability and law

Each party's liability under this DPA is subject to the limits in the Terms. This DPA is governed by the law of England and Wales. Questions: legal@trustdyne.com.