Last updated: August 28, 2026
This Data Processing Agreement (“DPA”) forms part of the agreement between Trustindex Ltd. (“Trustindex”, “we”, “us” or “Processor”) and the customer identified in the applicable order, subscription, account or other agreement for Trustindex’s services (“Customer”, “you” or “Controller”).
This DPA applies to the extent that Trustindex processes Personal Data on Customer’s behalf in connection with the Trustindex Services.
1. Definitions
For purposes of this DPA:
“Applicable Data Protection Law” means all applicable laws and regulations relating to the protection of Personal Data and privacy, including, where applicable, Regulation (EU) 2016/679 (“GDPR”), the UK GDPR and applicable data protection laws of Switzerland and the United States.
“Customer Personal Data” means Personal Data processed by Trustindex on behalf of Customer in connection with the Services.
“Data Subject” means an identified or identifiable natural person to whom Personal Data relates.
“Personal Data”, “Controller”, “Processor”, “Processing”, “Process”, “Sub-processor” and other relevant terms have the meanings given to them under Applicable Data Protection Law.
“Services” means the Trustindex products and services provided to Customer under the applicable agreement, including, where subscribed to or enabled, review collection, review management, review display widgets, integrations, email campaigns, review invitations, API-based review synchronization, and related functionality.
2. Scope and Role of the Parties
2.1 Processor relationship
The Parties acknowledge that, with respect to Customer Personal Data covered by this DPA, Customer acts as the Controller and Trustindex acts as the Processor.
Trustindex shall process Customer Personal Data only on behalf of and in accordance with Customer’s documented instructions, including those contained in the agreement between the Parties, this DPA, Customer’s configuration and use of the Services, and subsequent documented instructions provided by Customer.
2.2 Trustindex as an independent Controller
This DPA does not apply to Processing for which Trustindex acts as an independent Controller.
For example, Trustindex may process Personal Data as an independent Controller in connection with its own account administration, billing, legal and accounting obligations, security, fraud prevention, website operation, marketing, analytics, customer support, and other purposes described in Trustindex’s Privacy Policy.
The Trustindex Privacy Policy applies to such Processing.
2.3 Customer responsibility
Customer is responsible for determining the purposes and legal basis of its Processing of Customer Personal Data and for ensuring that its collection and disclosure of Customer Personal Data to Trustindex are lawful.
Customer shall provide all necessary notices to Data Subjects and obtain all consents, authorisations, or other legal bases required under Applicable Data Protection Law.
Customer shall not instruct Trustindex to process Personal Data in violation of Applicable Data Protection Law.
3. Details of Processing
The subject matter, nature and purpose of the Processing, the categories of Personal Data, and the categories of Data Subjects are described in Schedule 1 to this DPA.
Trustindex may process Customer Personal Data only for the purposes of providing, maintaining, securing, and supporting the Services and as otherwise instructed by Customer in accordance with this DPA.
4. Trustindex’s Obligations
Trustindex shall:
4.1 Instructions
Process Customer Personal Data only on documented instructions from Customer, unless Trustindex is required to process such Personal Data under applicable Union, Member State, UK, or other applicable law.
Where legally permitted, Trustindex shall inform Customer of such legal requirement before carrying out the relevant Processing.
If Trustindex reasonably believes that an instruction from Customer infringes Applicable Data Protection Law, Trustindex shall inform Customer before carrying out the instruction, unless prohibited by law.
4.2 Confidentiality
Trustindex shall ensure that persons authorised to process Customer Personal Data have committed themselves to confidentiality or are subject to an appropriate statutory obligation of confidentiality.
Access to Customer Personal Data shall be limited to personnel who require access for the performance of their duties and the provision of the Services.
4.3 Security
Trustindex shall implement and maintain appropriate technical and organisational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to such data.
The relevant technical and organisational measures are described in Schedule 2.
Trustindex may modify its technical and organisational measures from time to time, provided that such modifications do not materially reduce the overall level of protection provided to Customer Personal Data.
4.4 Assistance with Data Subject Requests
Taking into account the nature of the Processing, Trustindex shall provide reasonable assistance to Customer, through appropriate technical and organisational measures, to enable Customer to respond to requests from Data Subjects exercising their rights under Applicable Data Protection Law.
Where Trustindex receives a Data Subject request relating to Customer Personal Data, Trustindex shall, where legally permitted, notify Customer without undue delay and shall not respond to the request except as necessary to confirm receipt, identify the requester, as otherwise instructed by Customer, or as required by law.
4.5 Assistance with Compliance Obligations
Taking into account the nature of the Processing and the information available to Trustindex, Trustindex shall provide reasonable assistance to Customer in relation to:
a. security obligations under Applicable Data Protection Law;
b. notification of Personal Data breaches;
c. data protection impact assessments; and
d. consultations with supervisory authorities.
Where such assistance requires substantial additional work beyond the standard Services, Trustindex may charge reasonable fees where permitted by the applicable agreement.
4.6 Personal Data Breaches
Trustindex shall notify Customer without undue delay after becoming aware of a confirmed Personal Data breach affecting Customer Personal Data.
To the extent reasonably available, the notification shall include information concerning:
a. the nature of the breach;
b. the categories and approximate number of Data Subjects affected;
c. the categories and approximate number of Personal Data records affected;
d. the likely consequences of the breach; and
e. measures taken or proposed to address and mitigate the breach.
Trustindex shall provide reasonable cooperation and updates as information becomes available.
4.7 Government and Law-Enforcement Requests
Where legally permitted, Trustindex shall notify Customer of any legally binding request from a governmental, regulatory, or law-enforcement authority requiring disclosure of Customer Personal Data.
Where legally permitted and appropriate, Trustindex shall take reasonable steps to limit the disclosure to the Personal Data legally required to be disclosed.
5. Sub-processors
5.1 General Authorisation
Customer provides Trustindex with general authorisation to engage Sub-processors in connection with the provision of the Services.
Trustindex currently uses the following Sub-processors, as applicable to the Services:
- Amazon Web Services, Inc. – Hosting and infrastructure services; processing locations may include the European Economic Area and the United States.
- Google Ireland Limited – Google-related APIs, integrations, and related services.
- The Rocket Science Group LLC d/b/a Mailchimp – Email delivery and related email campaign services.
- Twilio Inc. – SMS and related communications services.
The actual Sub-processors used may depend on the Services and functionality used by Customer.
5.2 Changes to Sub-processors
Trustindex may add or replace Sub-processors from time to time.
Trustindex shall provide Customer with prior notice of material changes to its Sub-processors by email or through another appropriate notification mechanism.
Customer may object to the appointment of a new Sub-processor on reasonable data protection grounds by notifying Trustindex within 15 days of receiving notice.
The Parties shall work in good faith to resolve any valid objection. If no reasonable solution can be agreed, Customer may terminate the affected Services in accordance with the applicable agreement.
5.3 Sub-processor Obligations
Trustindex shall enter into a written agreement with each Sub-processor requiring the Sub-processor to comply with data protection obligations appropriate to the services it performs and substantially equivalent to the obligations applicable to Trustindex under this DPA.
Trustindex shall remain responsible for the performance of its Sub-processors to the extent required by Applicable Data Protection Law.
6. International Data Transfers
Where Trustindex transfers Customer Personal Data outside the European Economic Area, the United Kingdom, or Switzerland, Trustindex shall ensure that the transfer is carried out in accordance with Applicable Data Protection Law.
Where required, the Parties shall rely on an applicable adequacy decision, the European Commission’s Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914, the UK International Data Transfer Addendum, or another legally valid transfer mechanism.
Where the Standard Contractual Clauses are required, the relevant module shall apply according to the roles of the Parties and the nature of the transfer.
The Parties agree that the Standard Contractual Clauses may be incorporated into this DPA by reference where applicable.
7. Deletion and Return of Customer Personal Data
Upon termination or expiry of the Services, Trustindex shall, at Customer’s choice and taking into account the technical functionality of the Services:
a. delete Customer Personal Data; or
b. return Customer Personal Data to Customer,
unless applicable law requires Trustindex to retain certain Personal Data.
Where Trustindex is required by law to retain Personal Data, Trustindex shall continue to protect such Personal Data and shall process it only to the extent required by that legal obligation.
Backup copies may remain for a limited period in accordance with Trustindex’s normal backup and disaster-recovery procedures, provided such data is securely isolated and not actively processed except where required for security, disaster recovery, or legal purposes.
8. Audits and Compliance Information
Trustindex shall make available to Customer information reasonably necessary to demonstrate compliance with the obligations applicable to processors under Article 28 of the GDPR and equivalent Applicable Data Protection Law.
Customer may, on reasonable prior written notice and no more than once per twelve-month period, request reasonable documentation relating to Trustindex’s compliance with this DPA, including relevant security documentation, policies, or third-party audit reports, where available.
Where legally required or where a material Personal Data breach has occurred, Customer may request an additional audit, subject to reasonable confidentiality, security, and operational requirements.
Any audit shall:
a. take place during normal business hours;
b. be conducted in a manner that does not unreasonably disrupt Trustindex’s business or security;
c. protect the confidentiality of Trustindex’s information and the information of other customers; and
d. be conducted by Customer or an appropriately qualified independent auditor who is not a competitor of Trustindex.
Customer shall bear its own audit costs unless otherwise required by Applicable Data Protection Law.
9. Customer Obligations
Customer shall:
a. provide lawful and documented instructions to Trustindex;
b. ensure it has a valid legal basis for its Processing of Customer Personal Data;
c. provide all legally required privacy notices to Data Subjects;
d. ensure that the Customer Personal Data supplied to Trustindex is accurate and obtained lawfully;
e. ensure that its use of the Services complies with Applicable Data Protection Law; and
f. not knowingly instruct Trustindex to process Special Categories of Personal Data or other highly sensitive data unless expressly agreed by the Parties and appropriate safeguards have been established.
10. Special Categories of Personal Data
The Services are not intended for the Processing of Special Categories of Personal Data as defined by Article 9 of the GDPR.
Customer shall not intentionally provide Trustindex with Special Categories of Personal Data unless such Processing is expressly supported by the relevant Service and agreed in writing between the Parties.
Where Customer nevertheless provides such data to Trustindex without prior written agreement, Customer remains responsible for ensuring that a lawful basis and appropriate condition for Processing under Applicable Data Protection Law exists.
11. CCPA and Other U.S. Privacy Laws
To the extent Applicable Data Protection Law includes the California Consumer Privacy Act, as amended (“CCPA”), or similar U.S. privacy laws, Trustindex shall process Customer Personal Data solely for the permitted business purposes of providing the Services and shall not sell Customer Personal Data or use such data for purposes inconsistent with the Services and this DPA.
Trustindex shall provide the level of privacy protection required of a service provider or processor under Applicable Data Protection Law, to the extent applicable.
12. Priority
In the event of any conflict between this DPA and another agreement between the Parties concerning the Processing of Customer Personal Data, this DPA shall prevail solely with respect to the subject matter of data protection and Processing, unless the Parties expressly agree otherwise in writing.
13. Term and Termination
This DPA shall remain in effect for as long as Trustindex processes Customer Personal Data on behalf of Customer.
The obligations concerning confidentiality, security, deletion, return, audits, and any other provisions which by their nature should survive termination shall survive termination to the extent applicable.
14. Governing Law
Unless otherwise required by Applicable Data Protection Law, this DPA shall be governed by the laws specified in the applicable agreement between the Parties.
Where no governing law is specified in the applicable agreement, this DPA shall be governed by the laws of Hungary.
15. Contact
Questions concerning this DPA may be directed to:
Trustindex Ltd.
Hungary, 2724 Ujlengyel, Nyari Pal utca 15.
Email: support@trustindex.io
SCHEDULE 1 — DETAILS OF PROCESSING
1. Subject Matter
The subject matter of the Processing is the processing of Personal Data by Trustindex on behalf of Customer in connection with the provision of the Trustindex Services.
Depending on the Services subscribed to or used by Customer, Processing may include review collection, review invitation campaigns, review management, review synchronization from connected platforms, review display, integrations, and related functionality.
Customer Personal Data may be provided directly by Customer, collected through Customer-configured Services, or received from third-party platforms or integrations connected by Customer or at Customer’s instruction.
2. Duration
Trustindex shall process Customer Personal Data for the duration of Customer’s use of the relevant Services and in accordance with the deletion and retention provisions set out in this DPA.
Following termination or expiry of the Services, Customer Personal Data shall be deleted or returned in accordance with Section 7 of this DPA, except where retention is required by applicable law.
3. Nature and Purposes of Processing
Depending on the Services used by Customer, Trustindex may carry out the following Processing activities:
- collection and storage of Personal Data provided by or on behalf of Customer;
- sending review invitations and other review-related communications on behalf of Customer;
- collecting, storing, managing, and displaying reviews and ratings;
- importing and synchronizing reviews and related information from third-party platforms connected by Customer;
- enabling Customer to view and manage reviews through the Trustindex dashboard;
- enabling Customer to publish or display reviews through Trustindex widgets and other Services;
- providing integrations and API-based functionality;
- providing technical support and troubleshooting in connection with Customer Personal Data;
- maintaining, securing, monitoring, and operating the Services on behalf of Customer and in accordance with Customer’s instructions;
- performing backups and disaster recovery; and
- carrying out other Processing necessary to provide the Services in accordance with Customer’s documented instructions.
4. Categories of Data Subjects
Depending on the Services used, Customer Personal Data may relate to the following categories of Data Subjects:
- Customer’s customers and prospective customers;
- individuals who receive review invitations from Customer;
- individuals who submit reviews or other feedback;
- individuals whose reviews or related information are imported from third-party platforms;
- Customer’s employees, representatives, and other authorised users of the Services; and
- other individuals whose Personal Data is submitted to the Services by or on behalf of Customer.
5. Categories of Personal Data
Depending on the Services used, Customer Personal Data may include:
- first and last name;
- email address;
- telephone number, where provided;
- postal or other address information, where provided;
- customer, purchase, transaction, or order information provided by Customer;
- review content and ratings;
- review submission dates and related timestamps;
- reviewer identifiers and publicly available profile information;
- photographs, videos, or other media submitted as part of a review;
- business or website information;
- Customer account or user identifiers;
- information associated with connected third-party platforms;
- platform, Page, review, or business identifiers;
- authentication and integration information, including API credentials or tokens where required to provide the relevant integration;
- IP address and other technical information where included in Customer-provided data; and
- other Personal Data contained in information submitted to or processed through the Services by or on behalf of Customer.
6. Special Categories of Personal Data
The Services are not intended for the Processing of Special Categories of Personal Data as defined under Article 9 of the GDPR.
Customer shall not intentionally submit Special Categories of Personal Data to the Services unless the relevant Processing is expressly supported by the applicable Service and the Parties have agreed on the appropriate safeguards.
7. Processing Operations
The Processing operations may include, as applicable:
- collection;
- recording;
- organisation;
- storage;
- structuring;
- adaptation or alteration;
- retrieval;
- consultation;
- use;
- transmission;
- disclosure where necessary to provide the Services;
- alignment or combination;
- restriction;
- deletion; and
- destruction.
The Processing shall be carried out only to the extent necessary to provide the Services and in accordance with Customer’s documented instructions and this DPA.
SCHEDULE 2 — TECHNICAL AND ORGANISATIONAL SECURITY MEASURES
Trustindex shall maintain technical and organisational measures appropriate to the risks associated with the Processing.
Such measures shall include, as appropriate:
1. Access Control
Access to Customer Personal Data shall be limited to authorised personnel with a legitimate business need.
2. Authentication
Trustindex shall implement appropriate authentication and access-control mechanisms for systems used to process Customer Personal Data.
3. Confidentiality
Personnel authorised to access Customer Personal Data shall be subject to confidentiality obligations.
4. Data Transmission Security
Trustindex shall use appropriate security measures to protect Customer Personal Data during transmission over public or otherwise untrusted networks.
5. Data Storage Security
Trustindex shall implement appropriate measures to protect Customer Personal Data stored in its systems against unauthorised access, alteration, loss, or destruction.
6. Backup and Recovery
Trustindex shall maintain appropriate backup and recovery procedures designed to restore availability and access to Customer Personal Data following a technical or physical incident.
7. Incident Management
Trustindex shall maintain procedures for detecting, assessing, responding to, and mitigating security incidents and Personal Data breaches.
8. Availability and Resilience
Trustindex shall maintain reasonable measures designed to ensure the ongoing availability, integrity, and resilience of systems used to provide the Services.
9. Testing and Review
Trustindex shall periodically assess and review the effectiveness of its technical and organisational security measures and update them where appropriate.
10. Physical Security
Trustindex shall rely on appropriate physical and environmental security measures at facilities used to process Customer Personal Data, including those implemented by relevant infrastructure providers.
11. Sub-processor Security
Trustindex shall require applicable Sub-processors to implement appropriate security measures consistent with the nature of the services provided.