Data processing agreement
Effective and last updated: 27 August 2026
This public DPA describes Trakium’s baseline processor commitments. It becomes binding when incorporated into an executed order form or signed by the customer and the Trakium contracting entity identified in that order form.
1. Scope and roles
The customer is the controller and Trakium is the processor of personal data processed through the service, except where Trakium acts as controller for its own account administration, security, billing, and direct business communications. This DPA applies for the service term and until processor-held customer personal data is returned or deleted.
2. Processing details
- Subject matter: providing workforce intelligence, attendance, desktop activity evidence, screenshots, alerts, search, reporting, and support.
- People: customer employees, contractors, users, administrators, and other authorised workforce participants.
- Data: identifiers, employment and role context, attendance and shift data, devices, application and website context, active and idle time, screenshots, searchable text context, alerts, reports, audit events, and support information.
- Purpose: the customer’s documented workforce visibility, attendance, client evidence, operational review, coaching, security, or compliance purpose.
3. Documented instructions
Trakium will process personal data only on the customer’s documented instructions, including the agreement and product configuration, unless law requires otherwise. If legally permitted, Trakium will tell the customer before processing required by law. Trakium will inform the customer if an instruction appears to violate applicable data protection law.
4. Confidentiality and access
Personnel and service providers authorised to process customer personal data are subject to confidentiality obligations and receive access only as needed for their duties. Trakium will maintain role, authentication, and organisation-scoping controls appropriate to the service.
5. Security
Trakium will maintain technical and organisational measures appropriate to the deployment and risk, including access controls, revocable sessions, tenant scoping, protected object access, audit logging, vulnerability and change management, backups where contracted, and incident procedures. The executed security schedule describes the production deployment and shared responsibilities.
6. Subprocessors
The customer authorises subprocessors needed for public-site delivery, communications, cloud infrastructure, storage, security, and configured AI services. The applicable schedule lists material product subprocessors. Trakium will impose data-protection duties that provide substantially equivalent protection and remains responsible for its subprocessors under the agreement.
- Cloudflare: DNS, public-site delivery, security, forms, email routing, and connectivity services.
- Google Gemini services: configured AI-assisted classification and summarisation using the data flow described in the product and security materials.
- The production hosting provider named in the executed deployment schedule.
7. International transfers
Where restricted personal data is transferred internationally, the parties will use an applicable adequacy decision, standard contractual clauses, recognised addendum, or another lawful mechanism identified in the schedule. The customer authorises transfers inherent in the approved subprocessors and deployment.
8. Individual rights
Taking into account the nature of processing, Trakium will provide reasonable assistance for access, correction, deletion, restriction, objection, and portability requests. If Trakium receives a request relating to customer-controlled workforce data, it will direct the person to the customer unless legally prohibited.
9. Breach and incident response
Trakium will notify the customer without undue delay after becoming aware of a confirmed personal-data breach affecting customer data and will provide available information reasonably required for the customer’s legal assessment, notification, containment, and remediation.
10. Assessments, regulators, and audits
Trakium will provide information reasonably necessary to demonstrate compliance with processor obligations and assist with relevant impact assessments or regulator consultations. Audit scope, confidentiality, frequency, cost, and security are handled under the customer agreement.
11. Return and deletion
At termination, Trakium will return or delete customer personal data according to the agreement and deployment schedule, except information that law requires to be retained. Backup copies will age out under the documented backup cycle and remain protected until deletion.
12. Order of precedence
This DPA supplements the customer agreement. If they conflict on personal-data processing, this DPA controls. An executed, deployment-specific DPA schedule controls over this public baseline for the details it expressly completes or changes.
Contact
Questions about this document or Trakium’s data practices can be sent to info@trakiumai.com.