This Data Processing Addendum (“DPA”) is between Third Arc Inc. and the Customer that has entered into an Agreement for Trails. It is automatically incorporated into that Agreement when Trails processes Customer Personal Data on Customer's behalf.
1. Scope and precedence
This DPA applies to Trails' Processing of Customer Personal Data as a Processor or Service Provider in connection with the Services. It does not apply where Trails acts as an independent Controller, as described in the Privacy Policy. This DPA remains in effect while Trails Processes Customer Personal Data.
If this DPA conflicts with the Agreement, this DPA controls for the Processing of Customer Personal Data. The Standard Contractual Clauses control over conflicting terms for a Restricted Transfer. Except as modified here, the Agreement remains in effect. The parties enter this DPA by executing an Order that references the Agreement, accepting the online Agreement, or otherwise agreeing in writing.
2. Definitions and roles
“Applicable Data Protection Law” means privacy and data protection law applicable to the Processing, including the GDPR, UK GDPR, UK Data Protection Act 2018, Australian Privacy Act 1988, and U.S. state comprehensive privacy laws. “Customer Personal Data”means Personal Data contained in Customer Content that Trails Processes on Customer's behalf.
“Controller,” “Data Subject,” “Personal Data,” “Process,” “Processor,” and “Supervisory Authority”have the meanings in Applicable Data Protection Law. “Controller” also includes “Business,” “Processor” includes “Service Provider” and “Contractor,” and “Personal Data” includes “Personal Information,” as those terms are used by applicable U.S. state law.
“GDPR” means Regulation (EU) 2016/679.“Restricted Transfer” means a transfer requiring an approved transfer mechanism under the GDPR, UK GDPR, or Swiss data protection law. “Security Incident”means a confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data in Trails' custody or control. Unsuccessful attempts and incidents not affecting Customer Personal Data are not Security Incidents.
Customer is the Controller and Trails is the Processor when Customer determines the purposes and means of Processing. If Customer is itself a Processor for another Controller, Trails is Customer's Subprocessor. Each party will comply with the obligations applicable to its role.
3. Instructions and compliance
Trails will Process Customer Personal Data only on Customer's documented instructions, including to provide, secure, support, and improve the Services; prevent fraud and abuse; comply with the Agreement; and comply with law. The Agreement, Customer's use and configuration of the Services, and written requests consistent with the Agreement constitute documented instructions.
Trails will inform Customer if, in Trails' reasonable opinion, an instruction violates Applicable Data Protection Law, unless law prohibits notice. Trails may suspend the affected Processing until the parties resolve the issue. If law requires Processing beyond Customer's instructions, Trails will inform Customer before Processing unless prohibited by law.
Customer is responsible for the lawfulness, fairness, accuracy, and quality of Customer Personal Data and instructions; providing notices; establishing a lawful basis; honoring Data Subject rights; and configuring the Services appropriately. Customer will not instruct Trails to Process data in violation of law or the Agreement.
Trails will not sell Customer Personal Data, retain, use, or disclose it outside the direct business relationship with Customer or for a commercial purpose other than providing the Services, or combine it with personal data received from another source, except as permitted by Applicable Data Protection Law. Trails will not use Customer Personal Data to train Trails' or a third party's general-purpose AI model without Customer's explicit opt-in instruction.
4. Confidentiality
Trails will ensure that personnel authorized to Process Customer Personal Data are bound by appropriate confidentiality obligations, receive relevant privacy and security training, and access Customer Personal Data only as necessary for their assigned responsibilities.
5. Security
Taking into account the state of the art, implementation cost, nature, scope, context, and purposes of Processing, and risks to individuals, Trails will maintain appropriate technical and organizational measures designed to protect Customer Personal Data. The measures are described in Annex II and include encryption in transit and at rest, access controls, logging and monitoring, secure development, vendor risk management, incident response, and resilience measures.
Customer is responsible for secure account configuration, Authorized User access, strong authentication, endpoint and network security, appropriate redaction, sharing settings, and backups or exports under Customer's control. Trails may update its security measures as technology and risks evolve, provided that the overall security of the Services is not materially diminished.
6. Security incidents
Trails will notify Customer without undue delay after confirming a Security Incident and will provide information reasonably available to help Customer meet applicable notification obligations, including the nature of the incident, affected data and individuals where known, likely consequences, and measures taken or proposed. Information may be provided in phases as the investigation proceeds.
Trails will take reasonable steps to contain, investigate, mitigate, and remediate a Security Incident. Customer is responsible for notices to Data Subjects, regulators, or others unless the parties agree otherwise. Trails' notice or response is not an admission of fault or liability.
7. Subprocessors
Customer gives general written authorization for Trails to engage the subprocessors on the Subprocessor List. Trails will impose data protection obligations on each subprocessor that are no less protective in material respects than the obligations applicable to that subprocessor's Processing under this DPA. Trails remains responsible for its subprocessors' performance to the extent required by Applicable Data Protection Law.
Trails will post a new subprocessor at least 15 days before it begins Processing Customer Personal Data when reasonably practicable. Customer may subscribe to updates and object on reasonable data- protection grounds by emailing [email protected] during the notice period. The parties will work in good faith on a commercially reasonable solution. If Trails cannot provide the affected Service without the subprocessor, Trails may terminate the affected feature or Customer may terminate the affected Order as its sole remedy and receive a pro rata refund of prepaid fees for the unused affected period. Urgent security, legal, or continuity needs may require shorter notice.
8. Rights and compliance assistance
Taking into account the nature of Processing and information available to Trails, Trails will provide reasonable assistance for Customer to:
- respond to verified requests to access, correct, delete, restrict, object, or port Customer Personal Data;
- conduct data protection impact assessments and required prior consultations concerning the Services; and
- meet obligations concerning security, breach notification, and records of Processing.
If Trails receives a request concerning Customer Personal Data, Trails will direct the requester to Customer where legally permitted and will not independently respond except on Customer's instruction or as required by law. Customer will reimburse reasonable costs for assistance that is unusually burdensome, legally compelled specifically for Customer, or outside standard Service functionality.
9. Government requests
Trails will review government demands for Customer Personal Data, disclose only data it reasonably believes is legally required, and challenge requests it reasonably believes are unlawful where appropriate. Trails will notify Customer before disclosure unless law prohibits notice or an emergency creates imminent risk of serious harm. If notice is temporarily prohibited, Trails will seek to provide it when the prohibition ends where lawful.
10. Return and deletion
During the term, Customer may retrieve Customer Personal Data using available export functionality. On a verified request following termination, Trails will delete or de-identify Customer Personal Data from active systems within 30 days, unless Applicable Data Protection Law requires retention. Customer should export data before termination.
Customer Personal Data in isolated backups will be overwritten or rendered inaccessible within up to 90 additional days and will remain protected under this DPA. Trails may retain limited data for legal, security, fraud-prevention, accounting, or dispute purposes only for as long as necessary and will isolate it from further Processing except for those purposes.
11. Information and audits
On written request and subject to confidentiality restrictions, Trails will provide information reasonably necessary to demonstrate compliance with this DPA, which may include relevant SOC 2 Type 2 reports, security summaries, questionnaires, and third-party audit materials.
If that information is insufficient to meet a legal audit obligation, Customer may request an audit no more than once per 12-month period, unless a Security Incident or Supervisory Authority requires more. Audits must be conducted by an independent auditor bound by confidentiality, during normal business hours, on at least 30 days' notice, without accessing another customer's data or disrupting the Services. Customer bears its costs and will reimburse Trails' reasonable costs. The parties will use a mutually agreed scope and prefer remote review. Trails may provide a summary rather than information that would compromise security or confidentiality.
12. International transfers
12.1 EEA transfers
For a Restricted Transfer subject to the GDPR, the standard contractual clauses in the European Commission Implementing Decision (EU) 2021/914 of June 4, 2021 (the“EU SCCs”) are incorporated by reference and completed as follows:
- Module Two applies when Customer is a Controller and Trails is a Processor. Module Three applies when Customer is a Processor and Trails is a Subprocessor.
- Clause 7, the optional docking clause, applies. In Clause 9, Option 2 applies with the notice period in Section 7. The optional language in Clause 11 does not apply.
- In Clause 17, Option 1 applies and the laws of Ireland govern. Under Clause 18(b), the courts of Ireland have jurisdiction.
- The competent Supervisory Authority is determined under Clause 13. If Clause 13 does not identify one, the Irish Data Protection Commission is the competent authority.
- Annex I of the EU SCCs is completed by Annex I below, Annex II by Annex II below, and Annex III by the Subprocessor List. By entering the Agreement, the parties are deemed to sign the EU SCCs as of the effective date of this DPA.
12.2 UK transfers
For a Restricted Transfer subject to the UK GDPR, the parties enter the Information Commissioner'sInternational Data Transfer Addendum to the EU SCCs, version B1.0 in force March 21, 2022, completed as described in Annex IV. The mandatory clauses of the UK Addendum are incorporated by reference and prevail for a UK Restricted Transfer.
12.3 Swiss transfers
For a Restricted Transfer subject to Swiss data protection law, the EU SCCs apply with references to the GDPR understood to include the Swiss Federal Act on Data Protection, “Member State” interpreted to include Switzerland, and the competent authority and courts determined under Swiss law. Data Subjects in Switzerland may enforce their rights in Switzerland.
12.4 Transfer cooperation
If a transfer mechanism is invalidated or a Supervisory Authority requires additional safeguards, the parties will work in good faith to implement a lawful alternative. Trails will provide information reasonably necessary for Customer's transfer assessment, subject to confidentiality and security restrictions.
13. Liability
Each party's liability arising out of this DPA is subject to the exclusions and limitations in the Agreement, and liability under this DPA and the Agreement is aggregated. Nothing limits a Data Subject's rights under the EU SCCs or liability that Applicable Data Protection Law does not permit the parties to limit.
Annex I: Processing details
A. Parties
Data exporter:Customer and, where applicable, its affiliates that use the Services. The exporter's contact details and activities are stated in the Order and Customer's Trails account. The exporter is a Controller or Processor as described in Section 2.
Data importer: Third Arc Inc. dba Trails, 2501 30th Ave., San Francisco, CA 94116, United States; [email protected]. The importer provides the Services and acts as a Processor or Subprocessor.
B. Description of transfer and Processing
| Data Subjects | Authorized Users; Customer's employees, contractors, customers, prospects, suppliers, and partners; viewers and recipients of Customer Content; and individuals whose information appears in screenshots, recordings, video, audio, transcripts, guides, pages, support requests, or other Customer Content. |
|---|---|
| Personal Data | Identity and business contact data; account, role, permission, authentication, and SSO data; device, IP, usage, and log data; screenshots, recordings, video, audio, voice samples, transcripts, text, URLs, clicks, prompts, Inputs, Outputs, translations, generated media, branding, files, and other data Customer submits or captures; support and communications data. |
| Sensitive data | Account credentials; voice samples and recordings; and other sensitive or regulated data Customer chooses and is authorized to submit. Protected health information is permitted only under an executed Business Associate Agreement. Safeguards include encryption, access restriction, confidentiality, logging, redaction tools, and contractual purpose limitations. |
| Frequency | Continuous or as initiated by Customer during the Agreement. |
| Nature and purpose | Collection, recording, organization, hosting, storage, retrieval, adaptation, redaction, transcription, analysis, AI generation, translation, narration, rendering, search, transmission, sharing, support, security, backup, deletion, and other Processing necessary to provide and protect the Services under Customer's instructions. |
| Duration | The Agreement plus the deletion periods described in Section 10, unless law requires longer retention. |
| Subprocessor Processing | The subject matter, nature, and duration necessary for each purpose stated on the Subprocessor List. |
Annex II: Security measures
Trails' security program includes measures appropriate to the Services and risk, including:
- encryption of Customer data in transit using modern transport encryption and at rest using industry-standard encryption;
- role-based and least-privilege access, authentication controls, periodic access review, SSO and multi-factor capabilities where applicable, and prompt access revocation;
- logical tenant separation, per-guide permissions, password-protected sharing, and on-device redaction tools;
- logging, monitoring, alerting, vulnerability management, malware and abuse defenses, and protected audit evidence;
- secure software-development practices, code review, change control, dependency and vulnerability assessment, and production access restrictions;
- incident-response, escalation, investigation, notification, and remediation procedures tested and updated periodically;
- backups, resilience, disaster recovery, service monitoring, and business-continuity measures appropriate to service risk;
- personnel confidentiality commitments, security and privacy training, and disciplinary processes;
- risk-based vendor diligence, written data-protection terms, and ongoing oversight of material subprocessors; and
- independent assessment through a SOC 2 Type 2 program and periodic review of the effectiveness of safeguards.
Annex III: Subprocessors
The current subprocessors, subject matter and nature of Processing, and principal processing locations are listed attrails.so/subprocessors and are incorporated into this DPA.
Annex IV: UK Addendum
The UK Addendum tables are completed as follows:
- Table 1: The parties and key contacts are those in Annex I.A. The start date is the effective date of this DPA or the date the exporter becomes bound by it, whichever is later.
- Table 2: The Approved EU SCCs are the EU SCCs incorporated in Section 12.1, including the selected module, clauses, and options stated there.
- Table 3: The Appendix Information is in Annex I, Annex II, and the Subprocessor List.
- Table 4: The Data Importer may end the UK Addendum as provided in Section 19 of its mandatory clauses if the Approved Addendum changes.
By entering the Agreement, each party agrees to be bound by the UK Addendum and is deemed to sign it.