Skip to content
Pricing

Legal

Data Processing Addendum

Effective and last updated: August 28, 2026

This standard Data Processing Addendum ("DPA") forms part of a written agreement under which Trunnion AI, LLC processes personal information for a Haultro business customer. A signed order form or agreement may add or replace terms. This page is not a public offer and does not authorize submission of data outside the approved deployment boundary.

1. Roles and instructions

The customer is the business, controller, or equivalent party for customer personal information; Trunnion AI, LLC acts as service provider, processor, or contractor and processes that information only to provide, secure, support, and maintain the contracted service on documented instructions. We do not sell or share customer personal information, use it for cross-context behavioral advertising, or combine it with information received from another business except as applicable law permits.

2. Scope and sensitive data

The agreement identifies approved users, modules, data categories, purposes, duration, providers, processing location, retention, and deletion. Precise location, voice audio, call transcripts, driver records, and other sensitive or regulated data are prohibited unless the signed scope expressly authorizes them and assigns required notices, consents, access controls, retention, and review responsibilities.

3. Confidentiality and security

Authorized personnel are bound by confidentiality duties. Measures are selected for the scoped risk and may include authenticated routes, tenant and role checks, encryption through deployed providers, signed webhook validation, dependency checks, backups, logging, and incident procedures. Exact implemented controls are documented per release and deployment; this DPA does not convert a roadmap item into a shipped control.

4. Subprocessors

The current public register is at Subprocessors. We impose appropriate data-protection duties on each provider. Customers receive at least 30 days' notice before a new subprocessor begins handling customer personal information and may object on reasonable data-protection grounds. If a reasonable objection cannot be resolved, the customer may terminate the affected service under the agreement.

5. Rights requests

Taking account of the nature of processing, we provide reasonable assistance with verified access, correction, deletion, portability, opt-out, appeal, and regulator requests concerning customer personal information. Direct requests are routed to the customer unless law requires another response.

6. Incidents

We notify affected customers without undue delay after confirming a personal-data breach, provide reasonably available information, mitigate within our control, and cooperate with the customer's legally required response. Notification is not an admission of fault.

7. Return and deletion

On termination or verified instruction, we return or delete customer personal information as the agreement provides, subject to legal holds and required records. Deleted data ages out of backups under the approved deployment schedule and is not used for new processing while retained.

8. Audit information

On reasonable written request and subject to confidentiality, we provide information reasonably necessary to demonstrate compliance for the contracted boundary. Any onsite review must be proportionate, avoid exposure of other customers' data, and follow the agreement.

9. Contact

Request execution or deployment-specific terms at legal@trunnion.ai. Privacy rights may also be submitted through Your Privacy Choices.

Necessary technology is always active because it provides security and remembers this choice.