Data Processing Addendum
Draft, not yet in force
This Addendum forms part of the Terms of Service between [LEGAL ENTITY NAME] (the processor) and the customer (the controller), and governs the processing of personal data carried out on the customer's behalf through Trazer.
1. Roles
The customer is the controller of the personal data they enter into their workspace, and decides why and how it is processed. We are the processor, and act only on the customer's documented instructions.
Use of the service constitutes the customer's instruction to process their data for the purpose of providing it. Any other instruction must be agreed in writing.
2. Subject matter and duration
The subject matter is the provision of a promise-to-cash business platform. Processing continues for the term of the agreement, plus the retention window that follows termination.
3. Nature and purpose
We process customer data to store it, make it available to the customer's authorised users, generate documents from it, send and receive email on the customer's behalf, produce analysis and forecasts, and transmit invoices to an accounting system where the customer connects one.
4. Types of personal data
- Contact details of the customer's own clients and prospects, such as name, role, email address and telephone number
- Business records connected to identifiable people: deals, proposals, correspondence, notes and tasks
- Account data for the customer's own users: name, work email address, role and activity records
5. Categories of data subject
- The customer's employees and authorised users
- The customer's clients, prospects and their staff
- Third parties named incidentally in documents or correspondence
6. Our obligations
- Process personal data only on the customer's documented instructions
- Ensure personnel with access are bound by confidentiality
- Implement the technical and organisational measures described in clause 7
- Assist the customer in responding to data subject requests
- Assist with data protection impact assessments where reasonably required
- Notify the customer without undue delay on becoming aware of a personal data breach
- Delete or return personal data on termination, as set out in clause 10
- Make available the information needed to demonstrate compliance with this Addendum
7. Security measures
These are the specific measures in place, rather than a generic assurance:
- Tenant isolation: every record carries the identifier of the workspace that owns it, fixed at creation and immutable thereafter
- Access control enforced at the database layer through row-level security, so it cannot be circumvented from the interface
- Role-based permissions across eight defined roles, granted by invitation only
- Passwordless authentication using one-time codes, so no password store exists
- An append-only audit log written by database triggers rather than by the application
- Per-workspace storage paths, so files cannot be reached across workspaces
- Per-workspace email sending identities, with inbound mail for unrecognised domains rejected rather than routed
- Encryption in transit, and encryption at rest via our infrastructure provider
- Operator tooling that exposes aggregate counts only, never the contents of a workspace
8. Sub-processors
The customer authorises the sub-processors listed on our sub-processors page. Each is engaged under written terms imposing obligations equivalent to those in this Addendum.
We will notify workspace administrators before a new sub-processor begins processing, giving a reasonable opportunity to object. Where an objection cannot be resolved, the customer may terminate the affected service.
9. International transfers
Where personal data is transferred outside the UAE, we rely on the safeguards set out in our agreements with the relevant sub-processor.
[CONFIRM WITH COUNSEL: state the transfer mechanism and the hosting regions precisely. Customers in regulated sectors will require this detail and will not accept a general statement.]
10. Deletion and return
On termination the customer may export their data during the retention window stated in the Terms of Service. After that window, personal data is deleted from active systems, subject to any retention required by law and to routine backup cycles which expire on their own schedule.
11. Breach notification
We will notify the customer without undue delay, and in any event within [NOTIFICATION PERIOD, commonly 72 hours] of becoming aware of a personal data breach affecting their data, providing the information reasonably available at the time and updating it as the position becomes clearer.
12. Audit
We will make available information reasonably necessary to demonstrate compliance. Where a customer requires an on-site audit, it must be agreed in advance, conducted no more than once in any twelve month period except where required by a regulator, and subject to confidentiality.
13. Liability and precedence
[TO BE DRAFTED BY COUNSEL. Set out how liability under this Addendum interacts with the cap in the Terms of Service, and confirm that this Addendum prevails over the Terms in the event of conflict on data protection matters.]
Questions about this document can be sent to us through the contact form, and we will route them to the right place.
Back to all policies