This DPA forms part of your agreement with Thruline and describes how we process personal data on your behalf. We'll countersign on request.
For personal data in customer content, you are the controller and Thruline is the processor. We process that data only on your documented instructions, including as set out in the agreement and this DPA.
We process personal data to provide the service: hosting, storage, backup, support, and related functions. The subject matter, duration, nature, and purpose are described in the agreement; categories of data and data subjects are those you choose to submit.
You authorize us to engage subprocessors to support the service. We maintain a current list, impose data-protection terms on each, and remain responsible for their performance. We'll give notice of changes so you can object on reasonable grounds.
We implement technical and organizational measures appropriate to the risk, including encryption, access controls, monitoring, and regular testing. Details are in our Security & Trust materials.
Where we transfer personal data across borders, we rely on lawful transfer mechanisms such as Standard Contractual Clauses, together with supplementary measures where required.
We'll assist you in responding to data subject requests and, on termination, delete or return personal data per your agreement, subject to standard backup cycles and legal retention.
To request a signed DPA or ask questions, contact privacy@thruline.co.