Legal

Trudy Data Processing Addendum

Last updated: 14 August 2026

This Data Processing Addendum (the DPA) forms part of the Trudy Terms of Service (the Terms) between Creator Technologies Ltd, company number 15624338, registered office 124 City Road, London EC1V 2NX (Creator Tech, we, us) and the customer accepting the Terms (the Customer). It applies whenever we process Customer Personal Data on the Customer's behalf, and is agreed by the Customer's acceptance of the Terms, which constitutes a binding written instrument in electronic form for the purposes of Article 28(9) of the Data Protection Legislation.

1. Definitions

Data Protection Legislation means the UK GDPR and the Data Protection Act 2018, Regulation (EU) 2016/679 (EU GDPR), and any legislation implementing or supplementing them, in each case as applicable to a party. Customer Personal Data means personal data that the Customer or its users provide within the service and that we process on the Customer's behalf, as described in Annex A. For clarity, the creator intelligence database (public-source creator profiles and derived scores) is processed by Creator Tech as an independent controller, is outside this DPA, and is described in the privacy policy at trudy.app. Sub-processor means a processor we engage to process Customer Personal Data. SCCs means the standard contractual clauses annexed to Commission Implementing Decision (EU) 2021/914 (module two, controller to processor). UK Addendum means the ICO's international data transfer addendum to the SCCs; IDTA means the ICO's international data transfer agreement. Restricted Transfer means a transfer of personal data restricted under Chapter V of the applicable Data Protection Legislation absent a valid transfer mechanism.

2. Roles and scope

The Customer is the controller of Customer Personal Data and we are its processor. Where the Customer acts as a processor for a third-party controller, we act as sub-processor, the Customer warrants that it has the necessary authorisations, and references to the Customer's instructions include those it passes on from its controller. This DPA applies for the term of the Terms and for as long as we hold Customer Personal Data.

3. Instructions

We process Customer Personal Data only on the Customer's documented instructions, including with regard to any Restricted Transfer, unless required to do otherwise by law to which we are subject; in that case we will inform the Customer of the legal requirement before processing, unless the law prohibits this on important grounds of public interest. The Customer's documented instructions are: this DPA, the Terms, the Customer's configuration and use of the service's features, and any further written instructions agreed between the parties. We will inform the Customer without undue delay if, in our opinion, an instruction infringes the Data Protection Legislation.

Derived Data. The Customer instructs Creator Tech to process Customer Personal Data to create Derived Data, as described in Annex A and in accordance with the Aggregation Standard. That instruction is given by clause 7.9 of the Terms and Conditions and may be withdrawn by the Customer at any time as set out in that clause. Derived Data contains no personal data and is not Customer Personal Data, and this Addendum does not apply to Derived Data once created.

4. Confidentiality

Access to Customer Personal Data is limited to personnel who need it to perform the service. All such personnel are bound by contractual or statutory obligations of confidentiality and receive data protection and security training.

5. Security

We implement and maintain the technical and organisational measures described in Annex B, which satisfy the requirements of Article 32 of the Data Protection Legislation, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing. We may update these measures from time to time, provided the updates do not materially diminish the overall level of protection.

6. Sub-processors

The Customer grants general written authorisation to our engagement of the Sub-processors listed in Annex C. We will give the Customer at least 30 days' prior written notice of any intended addition or replacement of a Sub-processor. The Customer may object within the notice period on reasonable data protection grounds; if the parties cannot resolve the objection, the Customer may terminate the affected services. We impose on every Sub-processor, by written contract, data protection obligations no less protective than those in this DPA, and we remain fully liable to the Customer for the Sub-processor's performance.

7. Data subject requests

We will notify the Customer without undue delay of any request from a data subject relating to Customer Personal Data, will not respond to such a request except on the Customer's documented instructions or where legally required, and will assist the Customer, by appropriate technical and organisational measures and insofar as this is possible, in fulfilling the Customer's obligation to respond to requests under Chapter III of the Data Protection Legislation.

8. Assistance

Taking into account the nature of the processing and the information available to us, we will assist the Customer in ensuring compliance with its obligations under Articles 32 to 36 of the Data Protection Legislation, including security, breach notification, data protection impact assessments and prior consultation. This assistance is provided at no additional charge unless requests are manifestly unfounded or excessive.

9. Personal data breach

We will notify the Customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notification will include, insofar as available and if necessary in phases, the information described in Article 33(3) of the Data Protection Legislation, and we will reasonably cooperate with the Customer's own notification obligations. Notification is not an acknowledgement of fault or liability.

10. Deletion and return

On expiry or termination of the Terms, at the Customer's election we will return Customer Personal Data in a structured, commonly used and machine-readable format and/or delete it, in each case within 30 days, save to the extent that applicable law requires continued storage. Data is removed from active systems within that period and from backups in the ordinary backup rotation. We will certify deletion on written request. This clause does not apply to Derived Data, which contains no personal data.

11. Audit and information

We will make available to the Customer all information necessary to demonstrate compliance with Article 28 of the Data Protection Legislation, including an annual written summary of our security measures, and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer. Unless a supervisory authority requires otherwise or an audit follows a personal data breach, audits are limited to once in any 12-month period, on at least 30 days' written notice, during business hours, without unreasonable disruption, subject to confidentiality, and at the Customer's cost.

12. International transfers

Customer Personal Data is hosted in Google Cloud regions in the EU and UK or, for customers on a dedicated United States deployment agreed in their order, on AWS in the United States, as set out in Annex C. We will not make a Restricted Transfer of Customer Personal Data except with a valid transfer mechanism under Chapter V. Where a Restricted Transfer arises between the Customer and Creator Tech, the SCCs and, in respect of transfers subject to the UK GDPR, the UK Addendum (or, at the parties' election, the IDTA) are incorporated into this DPA by reference and completed with the details in Annexes A to C; should an adequacy decision on which a transfer relies cease to apply, these clauses apply automatically to that transfer.

13. Liability, precedence and general

The liability of each party under this DPA is subject to the exclusions and limitations in the Terms. In case of conflict, this DPA prevails over the Terms with respect to the processing of Customer Personal Data, and the SCCs, UK Addendum or IDTA prevail over this DPA. We may update this DPA on notice, provided updates do not materially diminish the protections it provides. This DPA is governed by the law governing the Terms, with the same jurisdiction provisions.

Annex A. Description of processing

Subject matter and duration: provision of the Trudy service for the term of the Terms plus the wind-down period in clause 10. Nature and purpose: hosting, storage and administration of customer workspace data; storage and matching of customer-supplied lists against the creator intelligence database; presentation of results within the Customer's workspace; access management; support and troubleshooting; creation of Derived Data, being aggregated and anonymised data and statistics, from Customer Personal Data in accordance with clause 7.9 of the Terms and Conditions and the Aggregation Standard. Categories of data subjects: the Customer's personnel and authorised users; individuals appearing in customer-supplied lists (for example a customer's own ambassadors or creators). Categories of personal data: name, work contact details, role and authentication data of users; names, handles and contact references in customer-supplied lists. Special category data: none; the Customer must not submit special category data to the service. Frequency: continuous. For clarity, customer-submitted personal data is not processed through Creator Tech's large language model pipeline.

Annex B. Technical and organisational measures

Encryption in transit (TLS 1.2 or higher) and at rest (AES-256); role-based access control on a need-to-know basis; logging of access to systems processing personal data; two-factor authentication; personnel confidentiality undertakings and security and data protection training; documented incident response; review of security controls at least annually; the measures summarised in the written security summary available on request.

Annex C. Sub-processors and locations

Google Cloud (Google Ireland Limited / Google LLC): cloud hosting and storage, EU and UK regions. Amazon Web Services: cloud hosting for dedicated United States deployments only, United States; transfers safeguarded under the EU-US Data Privacy Framework (including its UK Extension) where certified, or the SCCs with the UK Addendum. For clarity, Creator Tech's large language model provider is not a Sub-processor of Customer Personal Data. Notice of changes to this list is given per clause 6 to the Customer's account email.