Skip to content

Trustbird Data Processing Agreement

Version 1.0.0 Effective from 1 October 2026

This Data Processing Agreement (DPA) is Annex 1 to the SaaS Terms of Trustbird B.V. and forms part of the Agreement. It contains the arrangements required by Article 28 of the GDPR. Capitalised terms have the meaning given in Article 1 of the SaaS Terms. Other terms, such as personal data, processing and data subject, have the meaning given in the GDPR. This is a translation of the Dutch text. In the event of any inconsistency, the Dutch version prevails.

Article 1 – Subject matter, roles and order of precedence

1.1 This DPA applies to the processing of personal data in the Customer Data by Trustbird when providing the Service. Annex A describes this processing.

1.2 Customer is the controller and Trustbird is the processor. Customer determines the purposes and means of the processing.

1.3 If Customer invites an adviser as a guest to its Account, that adviser is a User of Customer. Customer remains the controller towards Trustbird. Customer decides which rights the guest has and may withdraw them at any time.

1.4 If Customer uses the Service to process personal data for a client of its own, Customer remains Trustbird's sole counterparty. Customer makes the arrangements with that client that the GDPR requires. Trustbird is then a sub-processor of Customer and this DPA continues to apply unchanged.

1.5 Trustbird is itself the controller for personal data it processes to manage the customer relationship and for invoicing. The privacy statement applies to that processing, not this DPA.

1.6 In the event of a conflict between this DPA and the SaaS Terms, this DPA prevails insofar as the processing of personal data is concerned. Otherwise, the order of precedence in Article 2.3 of the SaaS Terms applies.

Article 2 – Term

2.1 This DPA applies from the moment the Agreement is formed.

2.2 It remains in force for as long as Trustbird processes personal data for Customer. This includes the period after the end of the Agreement, during the export period and until deletion from the backups under Article 13.

Article 3 – Instructions

3.1 Trustbird processes the personal data only on Customer's documented instructions. This also applies to transfers to a country outside the EEA.

3.2 The Agreement and the way Customer uses and configures the Service together constitute the complete documented instruction. This includes the use of the AI Features by Customer's Users.

3.3 The parties agree additional or different instructions in writing. If these require extra work from Trustbird outside the Service, Trustbird may charge a reasonable fee, after informing Customer in advance.

3.4 Trustbird informs Customer immediately if, in its opinion, an instruction infringes the GDPR or other data protection law. Trustbird may suspend carrying out that instruction until Customer has confirmed or changed it.

3.5 Trustbird may process personal data without instruction if required to do so by Union or Dutch law. Trustbird informs Customer of this in advance, unless that law prohibits it. See also Article 12.

3.6 Customer warrants that its instructions and the processing of the personal data in the Service are lawful (Article 10.3 of the SaaS Terms). Customer informs the data subjects where required.

Article 4 – Confidentiality of personnel

4.1 Trustbird only grants access to personal data to those staff members who need it for their work.

4.2 These staff members are bound by a duty of confidentiality, through their employment contract, a confidentiality undertaking or by law. That duty continues after their work for Trustbird ends.

4.3 Trustbird ensures that these staff members are aware of their obligations when handling personal data.

Article 5 – Security

5.1 Trustbird takes appropriate technical and organisational measures to secure the personal data, as required by Article 32 of the GDPR. In doing so, Trustbird takes into account the state of the art, the costs, the nature of the processing and the risks to data subjects.

5.2 The measures are set out in Annex B and in the Security Overview. Article 9 of the SaaS Terms also applies.

5.3 Trustbird may adapt the measures to the state of the art, provided that the level of security does not decrease materially as a result.

5.4 Customer ensures secure use of the Service, as described in Article 9.6 of the SaaS Terms. Customer assesses for itself whether the measures are appropriate for the personal data it processes in the Service.

Article 6 – Sub-processors

6.1 Customer gives Trustbird general authorisation to engage Sub-processors. Annex C lists the Sub-processors at the effective date of this version, with their role, country of establishment and processing location. The current list is available on the Sub-processors page. Customer consents to the Sub-processors on that list when the Agreement is formed.

6.2 Trustbird notifies Customer of a new or replacement Sub-processor at least 30 days in advance, by email to the administrator of the Account.

6.3 Customer may raise a reasoned objection within that period. The parties will then discuss a solution. If they do not find one, Customer may terminate the relevant part of the Service with effect from the date of the change. Trustbird then refunds the prepaid Fees for the period after that date (Article 10.5 of the SaaS Terms).

6.4 Trustbird imposes on each Sub-processor, in writing, at least the same obligations as in this DPA. This applies in particular to appropriate security measures.

6.5 Trustbird remains fully responsible towards Customer for the performance of the obligations of its Sub-processors.

6.6 For the AI Features, Trustbird uses Mistral AI exclusively, through its endpoint hosted in the EU. Mistral AI is a Sub-processor of Trustbird and this article applies in full. Trustbird does not engage any other AI provider and does not fall back on a provider outside the EU in the event of an outage. Customer currently cannot turn off the AI Features or connect its own AI solution.

6.7 Trustbird does not use Customer Data to train AI models. Mistral AI does not use Customer Data for that purpose either: the use of data for model improvement is switched off in Trustbird's account with Mistral. Mistral retains inputs and outputs for at most 30 days, to detect abuse, and deletes them afterwards.

Article 7 – Transfers outside the EEA

7.1 Trustbird hosts and stores the personal data with Laravel Cloud, in the Frankfurt region, Germany (AWS region eu-central-1). The application, database, cache and backups are located in that region (Article 9.2 of the SaaS Terms).

7.2 Trustbird only transfers personal data to a country outside the EEA, or allows a Sub-processor to do so, if one of the following safeguards applies:

  1. an adequacy decision of the European Commission, such as the EU-US Data Privacy Framework for organisations certified under it; or
  2. the standard contractual clauses of the European Commission, following an assessment of the risks of that transfer (transfer risk assessment) and with supplementary measures where needed.

7.3 The provider of Laravel Cloud, Laravel Holdings Inc., is established in the United States. The data remains stored in the Frankfurt region. Insofar as Laravel or an underlying party has access to personal data from a country outside the EEA, this constitutes a transfer and Article 7.2 applies. Laravel Holdings Inc. is certified under the EU-US Data Privacy Framework, so the adequacy decision under Article 7.2(1) applies. Trustbird has a data processing agreement with Laravel.

7.4 Mistral AI processes the data for the AI Features through its endpoint hosted in the EU. Trustbird does not send data to an AI provider outside the EU.

Article 8 – Assistance with data subject rights

8.1 The Service offers Customer functions to view, correct and delete personal data. Customer primarily uses these functions itself to handle requests from data subjects.

8.2 If Customer cannot handle a request with those functions, Trustbird provides reasonable assistance. This concerns requests under Chapter III of the GDPR, such as access, rectification, erasure, restriction, portability and objection.

8.3 If Trustbird itself receives a request from a data subject concerning Customer's personal data, Trustbird refers the data subject to Customer. Trustbird informs Customer of the request without undue delay, if Customer can be identified. Trustbird does not respond to the substance of the request without Customer's instruction.

8.4 Trustbird provides this assistance free of charge. Only for disproportionate requests may Trustbird charge reasonable costs. Trustbird informs Customer of those costs in advance.

Article 9 – Assistance with DPIAs and prior consultation

9.1 Trustbird provides Customer with reasonable assistance with a data protection impact assessment (DPIA) regarding the use of the Service. Trustbird does so by providing the information that Customer reasonably needs and that Trustbird has available.

9.2 Trustbird provides assistance in the same way if Customer must consult the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) or another supervisory authority in advance.

9.3 For this purpose, Trustbird may refer to the Documentation, the Security Overview, Annex A and Annex B. For assistance beyond this that requires more than limited effort, Trustbird may charge reasonable costs, after informing Customer in advance.

Article 10 – Personal data breaches

10.1 Trustbird notifies Customer of a personal data breach without undue delay. It does so no later than 48 hours after Trustbird has discovered the breach.

10.2 Trustbird sends the notification to the contact person Customer has designated for this purpose. If Customer has not designated anyone, Trustbird notifies the administrator of the Account. Customer keeps these contact details up to date.

10.3 The notification contains, insofar as known:

  1. the nature of the breach;
  2. the categories and approximate number of data subjects and personal data records concerned;
  3. a contact point at Trustbird for further information;
  4. the likely consequences of the breach;
  5. the measures Trustbird has taken or proposes to address the breach and mitigate its consequences.

10.4 If not all information is available immediately, Trustbird still makes the notification within the period in Article 10.1. Trustbird supplements the information as soon as it becomes known. Trustbird keeps Customer informed of developments.

10.5 Trustbird immediately takes appropriate measures to end the breach and limit its consequences. Trustbird reasonably cooperates with Customer's investigation and measures.

10.6 Customer decides whether the breach is notified to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens), another supervisory authority or the data subjects. Trustbird assists Customer in this. Trustbird does not itself notify a supervisory authority or data subjects on Customer's behalf.

10.7 Trustbird records breaches, including the facts, the consequences and the measures taken. Customer may request this information for its own documentation obligation.

Article 11 – Audits and information

11.1 Trustbird makes available to Customer all information necessary to demonstrate that Trustbird complies with this DPA and Article 28 of the GDPR.

11.2 To this end, Trustbird provides on request:

  1. relevant certificates, once Trustbird holds them. Trustbird is currently not ISO 27001 certified and does not commit to certification;
  2. the summary of the latest penetration test by an independent party, if one has been carried out. No penetration test has been carried out yet;
  3. once a year, free of charge, a completed reasonable security questionnaire.

11.3 Customer may have an audit carried out at Trustbird if a supervisory authority requires this of Customer, or if the information under Article 11.2 is demonstrably insufficient. The following applies:

  1. the audit takes place no more than once a year, unless a supervisory authority requires more frequent audits;
  2. the audit is carried out by an independent expert bound by a duty of confidentiality;
  3. Customer announces the audit in writing in advance and the parties agree on the scope, timing and duration;
  4. the audit disrupts Trustbird's operations and its services to other customers as little as possible, and gives no access to data of other customers;
  5. Customer bears the costs of the audit, including those of the expert.

11.4 The results of an audit and all information under this article are confidential (Article 12 of the SaaS Terms). Customer uses them only to verify compliance. Customer may share them with a supervisory authority that requests them.

11.5 If an audit shows that Trustbird does not comply with this DPA, Trustbird remedies this within a reasonable period at its own expense.

Article 12 – Requests from authorities

12.1 If a government authority requests Trustbird to disclose Customer's personal data, Trustbird only does so if legally required (Article 10.7 of the SaaS Terms).

12.2 Trustbird assesses whether the request is lawful. Where possible, Trustbird refers the authority to Customer.

12.3 Trustbird informs Customer of the request in advance, unless the law prohibits this. Trustbird discloses no more personal data than strictly necessary.

Article 13 – End: return and deletion

13.1 After the end of the Agreement, Customer has 30 days to retrieve the Customer Data (the export period). During that period, the Account is only accessible for viewing data (Article 16.5 of the SaaS Terms). The Service has no export function of its own. At Customer's request, Trustbird delivers the Customer Data within 30 days of the request, in CSV or JSON. If Customer makes that request during the export period, the deletion under Article 13.2 waits until delivery.

13.2 After the export period, Trustbird permanently deletes the personal data from the Service. The personal data is deleted from the backups no later than 90 days after the end of the Agreement.

13.3 Trustbird ensures that its Sub-processors also delete the personal data.

13.4 Trustbird confirms the deletion in writing at Customer's request.

13.5 Trustbird only retains personal data for longer if Union or Dutch law requires it. Trustbird then uses that data only for that legal purpose and continues to comply with this DPA for it.

13.6 For switching to another provider, Article 16 of the SaaS Terms applies.

Article 14 – Liability

14.1 Article 14 of the SaaS Terms applies to the liability of the parties under this DPA.

14.2 For damage caused by a breach of this DPA, the higher cap in Article 14.2 of the SaaS Terms applies. That cap is twice the Annual Fees, with a minimum of EUR 50,000 and a maximum of EUR 500,000 per calendar year.

14.3 Article 14.6 of the SaaS Terms applies to fines imposed by a supervisory authority.

14.4 These limitations do not affect liability towards data subjects under Article 82 of the GDPR. Between themselves, the parties allocate the damage in accordance with this DPA and Article 14 of the SaaS Terms.

Article 15 – Final provisions

15.1 Trustbird may amend this DPA in accordance with Article 18 of the SaaS Terms. An amendment does not reduce the level of protection of the personal data.

15.2 Obligations that by their nature are intended to continue after the end of this DPA, such as confidentiality, remain in force.

15.3 This DPA is governed by Dutch law. Disputes are handled in accordance with Article 20 of the SaaS Terms, by the District Court of Gelderland.

15.4 Customer can send questions about this DPA to support@trustbird.com. Customer reports security incidents and suspected misuse to support@trustbird.com.

Annex A – Description of the processing

Item Description
Subject matter Providing the Service: an integrated information security management system (ISMS) as an online service, including support and AI Features.
Nature of the processing Storing, organising, consulting, editing, analysing, backing up and deleting Customer Data. Sending transactional email to Users. For AI Features: sending data to Mistral AI to generate Output.
Purpose Providing, supporting and securing the Service under the Agreement, and complying with legal obligations (Article 10.1 of the SaaS Terms).
Categories of data subjects Employees and contact persons of Customer; Users, including guests; employees of suppliers and business relations recorded by Customer; data subjects in incident and risk registers.
Categories of personal data Name; business contact details; job title; login credentials and logs, such as IP addresses and activity in the Service; the audit trail of changes (who, when, which record, old and new value); content entered by Customer, such as incident descriptions, risk assessments and audit findings.
Special categories Not intended. The Service is not designed for special categories of personal data or criminal offence data. Customer only processes such data if necessary and after its own risk assessment (Article 10.3 of the SaaS Terms).
Frequency Continuous, for as long as Customer uses the Service.
Retention period For the duration of the Agreement. Then a 30-day export period, followed by deletion. From backups no later than 90 days after the end of the Agreement (Article 13). The backup provides continuous restoration to an earlier point in time (point-in-time recovery), with a retention period of 14 days.
Location Hosting and storage with Laravel Cloud, Frankfurt region, Germany (AWS region eu-central-1). The application, database, cache and backups are located in that region. AI Features: Mistral AI, through its endpoint hosted in the EU. See also Article 7 and Annex C.
Sub-processors See Annex C and the Sub-processors page.

Annex B – Technical and organisational measures

Trustbird takes at least the following measures. The Security Overview provides more detail.

  1. Information security policy: an information security management system (ISMS) in accordance with ISO/IEC 27001. Trustbird is currently not certified.
  2. Encryption: all traffic runs over TLS (HTTPS enforced, with HSTS). The database is encrypted at rest with AES-256. The keys are held in AWS KMS and are rotated. Backups are encrypted.
  3. Authentication: sign-in with email address and password, with a verified email address. Sign-in attempts are rate limited. Password reset works through a one-time, time-limited link. A session expires after 120 minutes of inactivity. Multi-factor authentication is mandatory for every User, with an authenticator app (with single-use recovery codes) or a code by email. Single sign-on is not available.
  4. Access control: within an Account, each User has exactly one role. A guest can read and comment; Customer can enable editing per section. A guest cannot invite Users, see billing or delete the Account. The Service has no function that lets Trustbird staff view a Customer Account. Access to the hosting environment and the database is limited to the staff who operate the Service, on a need-to-know basis (least privilege).
  5. Customer separation: all customers are stored in one shared database. The data of different customers is logically separated. That separation is enforced at database level, with row level security in Postgres.
  6. Backups and recovery: continuous backup with restoration to any point in time within the 14-day retention period (point-in-time recovery). The backups are encrypted and located in the Frankfurt region. Restoration is tested at least once a year.
  7. Hosting: with Laravel Cloud, on Amazon Web Services infrastructure, in the Frankfurt region, Germany. The database is Laravel Serverless Postgres, provided by Neon, in the same region. Laravel Cloud, AWS and Neon each hold an ISO/IEC 27001 certificate and a SOC 2 Type 2 report.
  8. Vulnerabilities and testing: a coordinated vulnerability disclosure policy (Vulnerability disclosure). No penetration test has been carried out yet.
  9. Secure development: every change goes through a pull request and is only merged once the automated tests, static analysis and a scan for leaked secrets pass. Dependencies are checked daily for known vulnerabilities, and the code for unsafe patterns (static application security testing).
  10. Logging and monitoring: every creation, change and deletion of Customer Data is recorded: who, when, which record, old and new value. Customer can view this audit trail per Account, read-only. In addition, Laravel Cloud keeps application and access logs, which are retained for at most 30 days.
  11. Incident response: a procedure for identifying, handling and reporting security incidents, with notification to Customer within 48 hours of discovery (Article 10).
  12. Personnel: a duty of confidentiality for all staff with access to Customer Data (Article 4).
  13. Sub-processors: assessment of Sub-processors in advance and written agreements with at least the same obligations as this DPA.
  14. AI Features: Mistral AI exclusively, through its endpoint hosted in the EU, without fallback to a provider outside the EU. AI assists and people decide: an AI Feature does not publish policy, accept risks, mark a requirement as met or draw an audit conclusion. For each AI assessment, the model, the prompt version, the input and the time are recorded.

Annex C – Sub-processors

At the effective date of this version, Trustbird engages the following Sub-processors. Trustbird notifies changes under Article 6.2 and records them on the Sub-processors page.

Sub-processor Role Country of establishment Processing location
Laravel Holdings Inc. (Laravel Cloud) Hosting of application, database, cache and backups United States Frankfurt, Germany
Mistral AI SAS AI Features France EU (endpoint hosted in the EU)
Lettermint B.V. Transactional email to Users the Netherlands European Union

Laravel Cloud itself uses two underlying parties, which process the data in the Frankfurt region:

Underlying party Role Country of establishment Processing location
Amazon Web Services EMEA SARL Infrastructure underlying Laravel Cloud Luxembourg Frankfurt, Germany
Neon, LLC (part of Databricks, Inc.) Database (Laravel Serverless Postgres) United States Frankfurt, Germany

Mollie and Google are not Sub-processors of Customer Data. The Sub-processors page explains why.