Legal

Data Processing Agreement

This DPA forms part of your agreement with Thruline and describes how we process personal data on your behalf. We'll countersign on request.

Last updated: July 1, 2026

Roles of the parties

For personal data in customer content, you are the controller and Thruline is the processor. We process that data only on your documented instructions, including as set out in the agreement and this DPA.

Scope of processing

We process personal data to provide the service: hosting, storage, backup, support, and related functions. The subject matter, duration, nature, and purpose are described in the agreement; categories of data and data subjects are those you choose to submit.

Subprocessors

You authorize us to engage subprocessors to support the service. We maintain a current list, impose data-protection terms on each, and remain responsible for their performance. We'll give notice of changes so you can object on reasonable grounds.

Security measures

We implement technical and organizational measures appropriate to the risk, including encryption, access controls, monitoring, and regular testing. Details are in our Security & Trust materials.

International transfers

Where we transfer personal data across borders, we rely on lawful transfer mechanisms such as Standard Contractual Clauses, together with supplementary measures where required.

Data subject requests & deletion

We'll assist you in responding to data subject requests and, on termination, delete or return personal data per your agreement, subject to standard backup cycles and legal retention.

Contact

To request a signed DPA or ask questions, contact privacy@thruline.co.