Legal

Data Processing Addendum (DPA)

Article 28 GDPR · Last updated: September 28, 2026

This addendum supplements the terms and conditions agreed between the Customer and TRAAKER (the “Provider”) and forms an integral part thereof. It applies whenever the Provider processes personal data on behalf of the Customer in connection with the Platform. It is accepted upon subscription; no separate signature is required. A signed copy is available on request at privacy@traaker.ai.

1. Roles of the parties

The Customer is the controller of the personal data it enters into the Platform or that is collected on its behalf. The Provider acts as processor and processes that data only on the Customer's instructions.

For account, billing and Platform usage data, the Provider acts instead as controller: those processing activities are governed by the privacy policy and not by this addendum.

2. Instructions and limits

The Provider processes the data solely to deliver the Platform, as described in the terms and conditions and configured by the Customer. It uses that data for no other purpose, and in particular:

  • No Customer data is used to train, fine-tune or evaluate any artificial-intelligence model, either by the Provider or by its sub-processors. Model calls are made for inference only, under contractual terms that exclude any reuse of inputs for training purposes.
  • One Customer's data is never used to produce another Customer's results.
  • The Provider informs the Customer if it considers that an instruction infringes the GDPR.

3. Confidentiality

The Provider ensures that persons authorised to process the data are bound by a duty of confidentiality and access it only to the extent necessary to operate and support the Platform.

4. Security measures

The technical and organisational measures implemented under Article 32 GDPR are set out in Annex 2.

5. Sub-processors

The Customer authorises the Provider to engage the sub-processors listed in Annex 3. Each is bound by data-protection obligations equivalent to those set out in this addendum.

The Provider informs the Customer of any addition or replacement of a sub-processor at least 30 days before it takes effect, by email to the account administrator. The Customer may object on reasonable data-protection grounds; failing a solution, it may terminate the subscription without penalty, on a pro-rata basis.

6. Transfers outside the European Union

The Platform is hosted with Amazon Web Services in the us-east-1 region (United States). Data is therefore transferred outside the European Union.

These transfers rely on the European Commission's standard contractual clauses (decision 2021/914), incorporated into the agreements entered into with each relevant sub-processor, supplemented by the technical measures described in Annex 2. Amazon Web Services and Stripe are also certified under the EU-US Data Privacy Framework.

7. Assistance to the Customer

The Provider assists the Customer, to the extent reasonable:

  • in responding to requests from data subjects exercising their rights. To that end the Customer has direct access to the data through the Platform; if a request is addressed directly to the Provider, the Provider forwards it to the Customer without responding to it itself;
  • in carrying out data-protection impact assessments and, where applicable, prior consultation of the supervisory authority;
  • in demonstrating compliance with its obligations, by providing the necessary information on request. The Customer may carry out one documentary audit per contract year, subject to 30 days' notice.

8. Personal data breach

The Provider notifies the Customer of any personal data breach affecting it without undue delay and within 48 hours at the latest after becoming aware of it, by email to the account administrator. The notification states the nature of the breach, the categories and approximate volume of data concerned, the likely consequences and the measures taken or proposed.

9. End of the agreement

At the end of the subscription, data is retained for 12 months to allow reactivation, then automatically deleted. The Customer may request immediate deletion of all of its account data, from the Platform or by email: deletion then takes place within 30 days. Deletion covers the database, stored files, user accounts and search indexes. Invoices and accounting records are retained for 10 years under the statutory retention obligation, under the Provider's own responsibility.

The Customer may export its data before the end of the agreement using the exports available in the Platform. A full extraction can be requested at privacy@traaker.ai.

10. Order of precedence

In the event of a conflict between this addendum and the terms and conditions, this addendum prevails in all matters relating to the processing of personal data.

Annex 1. Description of the processing

Subject matter and nature: measuring and improving a brand's visibility in the answers of generative AI engines. The processing comprises the collection, storage, automated analysis and presentation of public data and of data provided by the Customer.

Duration: that of the subscription, extended by the retention periods set out in Article 9.

Categories of data subjects:

  • the Customer's users authorised to access the Platform;
  • natural persons that the Customer itself designates as tracking targets (for example an executive, a spokesperson or a founder whose visibility the brand wants to measure);
  • natural persons who may be mentioned in public content analysed by the Platform (article authors, citations in AI engine answers).

Categories of data:

  • identification data of the Customer's users: last name, first name, business email address, role, display preferences;
  • connection data: access timestamps, IP address, technical logs;
  • data entered by the Customer describing its brand, market, tracking targets and competitors, including the names, first names and name variants of the natural persons it designates as targets;
  • public content collected: web pages, AI engine answers, citations and sources, which may mention natural persons.

No special categories of data within the meaning of Article 9 GDPR are required by the Platform. The Customer refrains from entering any.

Annex 2. Technical and organisational measures

  • Encryption at rest: all stored data (database, files, vector indexes, message queues) is encrypted by the hosting service.
  • Encryption in transit: all exchanges with the Platform and between its components use TLS.
  • Segregation: each Customer has a logically isolated data space, with its identifier built into the partition key. Every application access is controlled by an authentication token carrying that identifier.
  • Authentication: managed by Amazon Cognito. Passwords are never stored by the Provider; they are hashed by the identity provider and subject to a minimum complexity policy (length, uppercase letter, digit). Federated authentication is available.
  • Least privilege: each execution component has a dedicated role limited to the resources it strictly requires.
  • Secrets: API keys and technical secrets are held in a dedicated secrets manager, never in source code.
  • Environment separation: development and production environments are hosted in separate infrastructure accounts, with no shared data.
  • Perimeter protection: web application firewall in front of public entry points and rate limiting on the programming interface.
  • Logging: execution and access logs retained for 30 days, with alerting on operational anomalies.
  • Deletion: deleting an account is executed as a cascade across every storage medium, including the identity provider and the payment provider.

These measures may evolve; the level of protection will not be reduced during the term of the agreement.

Annex 3. Sub-processors

Sub-processorRolePlace of processing
Amazon Web ServicesHosting, database, storage, authentication, AI model execution (Bedrock), email deliveryUnited States (us-east-1)
StripePayment and invoicingUnited States, Ireland
OpenAIAI engine querying for visibility measurementUnited States
AnthropicAI engine querying for visibility measurementUnited States
GoogleAI engine querying, places dataUnited States
PerplexityAI engine querying for visibility measurementUnited States
SerperAccess to public search resultsUnited States
HubSpotCustomer relationship managementUnited States

The audience-measurement and advertising tools used on the marketing website (Google, Meta, LinkedIn, Microsoft, CookieYes) and the meeting-booking tool (Calendly) play no part in processing the data entrusted by the Customer: they are governed by the privacy policy.

Contact

For any question regarding this addendum: privacy@traaker.ai.