These terms are being finalized and may be updated.

Legal

Data Processing Agreement

Last updated: October 2, 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service between the customer ("Controller") and Trinitis ("Processor"). It applies where Trinitis processes personal data on the customer's behalf in providing the service.

1. Subject matter and purpose

Trinitis processes customer metadata to discover the customer's data estate, read existing grants, draft and store policies, write approved policies into the customer's platforms, and maintain an audit trail. Trinitis processes personal data only on the customer's documented instructions, which are these terms and the customer's configuration of the service.

2. Categories of data

Trinitis processes metadata only:

  • Schema, table and column names, and tags
  • Existing grants, and policies drafted and approved in Trinitis
  • Group and role membership — which may include names or identifiers of the customer's users and service principals
  • Query history for the audit trail, with real data values stripped — which may include the identity of the user or principal that ran a query
  • Account information for the customer's Trinitis users (name, work email)

Trinitis does not store customer data values and does not sample column contents.

3. Access to customer platforms

On Snowflake, Databricks, Redshift and PostgreSQL, column discovery requires the SELECT privilege, because those platforms offer no metadata-only alternative. Trinitis reads only schema and column metadata and stores no row values, but the credential is capable of reading data and the customer should evaluate it on that basis. On BigQuery, roles/bigquery.metadataViewer exposes column metadata with data reads denied.

4. Processor obligations

  • Process personal data only on the customer's documented instructions.
  • Ensure personnel with access are bound by confidentiality.
  • Implement the security measures in section 5.
  • Assist the customer, taking into account the nature of processing, in responding to data-subject requests.
  • Notify the customer without undue delay after becoming aware of a personal data breach affecting customer data.
  • Delete customer data at the end of the service on the schedule in section 7.

5. Security measures

  • Hosting in the United States — AWS us-east-1 (N. Virginia).
  • Encryption at rest with AES-256 via AWS KMS, including database storage.
  • Encryption in transit with TLS 1.2+.
  • Platform credentials stored in AWS Secrets Manager, encrypted with AWS KMS.
  • No proxy in the customer's query path; customer data values are not stored.

6. Subprocessors

The customer authorizes Trinitis to use the following subprocessors:

SubprocessorPurposeLocation
Amazon Web ServicesApplication hosting, database, credential storageUnited States (us-east-1)
VercelMarketing site hostingUnited States
Auth0AuthenticationUnited States
Google WorkspaceEmail and calendar/schedulingUnited States

Trinitis will update this list before engaging a new subprocessor and remains responsible for its subprocessors' performance.

7. Retention and deletion

  • Configuration and metadata: life of the account; deleted within 30 days of termination.
  • Audit and access-intelligence events (values stripped): rolling 12-month window from event date; not deleted at termination; purged at the end of the window.
  • Credentials: deleted at account offboarding, with AWS's 7-day recovery window. While a connection exists or is archived, its credential is retained for audit attribution.
  • Backups: automated database backups retained for 7 days; deleted data ages out within that window.

Policies already enforced in the customer's platforms continue to work after termination.

8. International transfers

Customer data is processed in the United States. Where a transfer mechanism is required by law, the parties will rely on an appropriate mechanism agreed in the order form.

9. Audits

A SOC 2 Type I audit is in progress. Until a report is available, Trinitis will respond to reasonable written security questionnaires from the customer. Current status is on our Trust page.

10. Contact