Data Processing Addendum

Our Data Processing Addendum (DPA) governs the processing of personal data by Truestamp Inc. when we act as a processor on behalf of a business customer acting as a controller.
Last updated: September 8, 2026

English is the governing language

This document is published in English. The English text is authoritative and governs in the event of any conflict or question of interpretation.

Requesting a Copy

The current version of our Data Processing Addendum is available on request. Send an email to [email protected] from the email address associated with your Truestamp account or organization and we will provide the document for your review and signature.

When You Need a DPA

You need a Data Processing Addendum with Truestamp when all of the following are true:

  • You use Truestamp on behalf of an organization, not as an individual consumer
  • The content you timestamp or the metadata associated with it may contain personal data relating to natural persons other than yourself
  • Your organization is the controller of that personal data within the meaning of the EU General Data Protection Regulation (GDPR), the UK GDPR, or an equivalent law

Examples include a law firm timestamping client correspondence, a human-resources platform timestamping employee records, or an auditor recording proof of an external report. In each case, Truestamp processes personal data only on your instructions (the instruction being your submission of an item through the Service), and we act as a processor under Article 28 GDPR.

What the DPA Contains

Our DPA is designed to satisfy Article 28(3) of the GDPR, the corresponding provisions of the UK GDPR, and equivalent processor-contract requirements in other jurisdictions. It contains:

  • The subject matter, nature, purpose, and duration of the processing, with data categories and categories of data subjects
  • Our obligations as processor, including processing only on your documented instructions, confidentiality commitments for personnel, appropriate technical and organizational security measures (Article 32), and assistance with data subject rights, data protection impact assessments, and breach notifications
  • Our subprocessor regime, including a list of current subprocessors and the process by which we notify you of changes and allow you to object
  • The European Commission's Standard Contractual Clauses (Commission Implementing Decision 2021/914, Module 2 – controller to processor) for transfers of personal data from the European Economic Area to the United States, with the full Annex content pre-completed for our Service
  • The UK International Data Transfer Addendum issued by the UK Information Commissioner's Office, for transfers subject to the UK GDPR
  • The Swiss Federal Data Protection and Information Commissioner's recognition of the SCCs, with Swiss-specific amendments, for transfers subject to the Swiss Federal Act on Data Protection
  • Our commitments on return or deletion of personal data at the end of the provision of services, and on making available the information necessary to demonstrate compliance

Team Ownership and Controller Roles

Each team on Truestamp selects an ownership model for the items created within it. This selection affects which party is the controller of the personal data that may be contained in those items, and which party is a data contributor whose access ends when their membership ends.

Creator Retains Ownership

Where a team is configured so that creators retain ownership of their items, the creating user is the controller of the personal data contained in those items and the team acts as a collaborative workspace. Truestamp continues to act as processor on behalf of the controller identified by the DPA. When the user leaves the team, items they own follow them to their personal team, and the user remains the controller of that data.

Team Retains Ownership

Where a team is configured so that the team retains ownership, the organization that owns the team (typically the account holder that signs the DPA) is the controller of the personal data contained in every item created in the team. Individual members contribute items to the team as part of their role, but they do not acquire controller rights over the items they author. When a member is removed from or leaves the team, items stay with the team and the departing member loses ongoing access through the Service. The authorship record on each item remains unchanged.

This allocation of roles is the reason we require invitees to a team that retains ownership to acknowledge the ownership clause before their invitation can be accepted. The acknowledgment is recorded alongside the acceptance and is treated as the invitee's informed, documented acceptance of the controller arrangement for that team. There is no accept path that bypasses the acknowledgment. For teams that retain ownership, the controller identified in the DPA is the team's account holder, and instructions to Truestamp as processor are given through that account.

Team administrators can reassign ownership of individual items when responsibilities change. Reassignments are recorded in the audit log. Because the authorship attribute is not part of the cryptographic proof and ownership is separate from authorship, reassignment does not alter the integrity of any existing timestamp or proof.

Current Subprocessors

The subprocessors listed in our Privacy Policy form part of the DPA. A summary for ease of reference:

Subprocessor Purpose Location
Amazon Web Services, Inc. Application compute and underlying infrastructure United States
PlanetScale, Inc. Managed PostgreSQL database United States
Cloudflare, Inc. DNS, content delivery, DDoS protection, TLS termination, inbound email routing United States company; traffic in transit processed on its global edge network
SMTP2GO (Sand Dune Mail Limited) Outbound transactional email New Zealand company; global email delivery infrastructure
OpenRouter, Inc. AI assistant responses, conversation titles, and documentation search for signed-in users. Receives assistant conversation content and, for signed-in users, item or account data the assistant retrieves to answer a question; for documentation search, query text and excerpts of our own documentation. Routes requests to the AI model providers OpenRouter publishes for each purpose, which can change. Documentation searches by signed-out visitors are processed on our own servers. Not used by OpenRouter for model training; not stored by OpenRouter unless logging is enabled, which it is not; per-request metadata such as token counts is stored. Every request is sent with data collection set to deny, which limits routing to providers OpenRouter records as not collecting user data; assistant and title requests are also sent with zero-data-retention routing, which limits them to endpoints OpenRouter records as not retaining prompts or responses for any period United States
Google LLC (Google Workspace) Inbox for our business email addresses and account used to reply to customer correspondence United States
LogSnag LLC (UserJot) Embedded product feedback widget, public roadmap, and changelog. Receives signed-in user identifiers (ID, email, name, plan tier) and any feedback content the user voluntarily submits United States

We update this list in our Privacy Policy when we add, replace, or remove subprocessors, and we notify business customers under DPA of material changes before they take effect. In addition, where item claims include geographic coordinates, those coordinates alone (with no account or item identifiers) are sent to the OpenStreetMap Foundation's public Nominatim service to render place names, as described in our Privacy Policy.

How to Execute the DPA

To execute a DPA with Truestamp Inc.:

  1. Email [email protected] from an address associated with your organization and request the DPA. Include the legal name, registered address, and jurisdiction of the entity that will execute it
  2. We will send you the current version of the DPA (including the pre-completed SCC annexes and subprocessor schedule) for review
  3. Sign and return the DPA. We will counter-sign and provide a fully executed copy. The DPA takes effect on the date of the last signature

If your procurement process requires specific changes, submit proposed redlines in the same thread. We review all reasonable requests but reserve the right to decline changes that conflict with our infrastructure or other customers' agreements.

Related Documents

Language

This page and the Data Processing Addendum it describes are published in English. The English text is the authoritative version and governs in the event of any conflict or question of interpretation. Translated content elsewhere on this site is provided for convenience and does not modify the DPA.

Contact

For DPA requests, questions about processing roles, subprocessor changes, or any other data-protection matter, contact:

Truestamp Inc., 2810 N Church St Ste 82200, Wilmington, DE 19802-4447, United States.