Data Processing Agreement

Last updated: July 8, 2026

This agreement forms part of the Terms of Service and applies automatically to every account. You do not need to request or sign a separate copy. Where it conflicts with the Terms on the processing of personal data, this agreement prevails.

1. Parties and roles

You, the account holder, are the controller. TrustPages, operated by Denizhan Koçakgöl, Antalya, Türkiye, is the processor and acts only on your documented instructions. Your instructions are these terms together with your configuration in the dashboard; we will tell you if we believe an instruction infringes the GDPR or other applicable data protection law.

For our own account, billing and security records we act as a controller in our own right — see the Privacy Policy. The vendor pages the Service monitors are published by third parties and are not processed on your behalf.

2. Subject matter, duration, nature and purpose

Subject matter and purpose: monitoring the public pages you configure, recording and classifying changes, publishing the changes you approve to your trust page, and sending change notices to the recipients you specify.

Duration: for as long as your account exists, and thereafter only as described in section 8.

Categories of data subjects: you and your colleagues who hold accounts; people who subscribe to your public trust page; recipients you enter for Article 28(2) notices.

Categories of personal data: email addresses; subscription and delivery status; the record of who approved a change and when. No special categories of data under Article 9 are requested, and the Service is not intended for them.

3. Confidentiality

Anyone we authorise to process this data is bound by an obligation of confidentiality. The Service is currently operated by one person; where that changes, this obligation applies to anyone added.

4. Security measures (Article 32)

All traffic is served over TLS, and the database connection is TLS-only. Authentication is passwordless: a signed, single-use, time-limited magic link, with a session cookie marked HttpOnly and Secure. Every query that reaches account data is scoped by tenant. Login, subscription and public tool endpoints are rate limited. Secrets are held as environment variables, never in the source repository. Payment card data never reaches our systems: Paddle acts as merchant of record and handles it.

We publish a machine-readable monitoring health endpoint so that an interruption to monitoring is externally visible rather than silent.

5. Sub-processors

You give general written authorisation for the sub-processors below. We will announce any addition or replacement by email to the address on your account at least 14 days before it takes effect. You may object on reasonable data protection grounds within that period; if we cannot resolve the objection, you may terminate and receive a pro-rata refund of the unused paid period.

Sub-processor Purpose Location
RenderApplication hostingEU (Frankfurt), company USA
NeonDatabase hostingEU, company USA
ResendTransactional and notification emailUSA
PaddlePayments, as merchant of recordUK/EU
Google (Gemini API)Classifying changes to public vendor pages. Receives excerpts of those public pages, not your personal dataUSA/EU
SentryError monitoringEU

We remain fully liable to you for a sub-processor's performance of its obligations.

6. International transfers

Personal data is stored in the EU. Where a sub-processor above is established outside the EEA or the UK, the transfer relies on the European Commission's Standard Contractual Clauses concluded with that provider (together with the UK Addendum where the UK GDPR applies), or on an adequacy decision where one covers the provider. TrustPages itself is operated from Türkiye, which is not covered by an adequacy decision; that transfer likewise relies on the Standard Contractual Clauses incorporated into this agreement.

7. Assistance, breach notification and audit

We will assist you, taking into account the nature of the processing, in responding to data subject requests, and in meeting your obligations under Articles 32 to 36. Subscribers can unsubscribe themselves from any notice email; for anything else, write to us and we will act within the time you need to meet your own deadline.

We will notify you without undue delay, and in any case within 48 hours of becoming aware, of any personal data breach affecting data processed on your behalf, with the information you need for your own Article 33 notification.

We will make available the information needed to demonstrate compliance with this agreement and will accept an audit or inspection, once per year or after a breach, on 30 days' notice and under confidentiality.

8. Deletion and return

You can export your change history and evidence packs at any time while your account is active. On termination, tell us whether you want the data returned or deleted; if you say nothing, we keep it while the account exists so that your public trust page and history stay online, and delete it on request. Deletion covers backups within 30 days.

9. Contact

Data protection contact: support@usetrustpages.com. We respond within 30 days, and faster where a deadline of yours depends on it.

Last updated: 2 September 2026.