Data Processing Addendum
Requesting a Copy
The current version of our Data Processing Addendum is available on request. Send an email to [email protected] from the email address associated with your Truestamp account or organization and we will provide the document for your review and signature.
When You Need a DPA
You need a Data Processing Addendum with Truestamp when all of the following are true:
- You use Truestamp on behalf of an organization, not as an individual consumer
- The content you timestamp or the metadata associated with it may contain personal data relating to natural persons other than yourself
- Your organization is the controller of that personal data within the meaning of the EU General Data Protection Regulation (GDPR), the UK GDPR, or an equivalent law
Examples include a law firm timestamping client correspondence, a human-resources platform timestamping employee records, or an auditor recording proof of an external report. In each case, Truestamp processes personal data only on your instructions (the instruction being your submission of an item through the Service), and we act as a processor under Article 28 GDPR.
What the DPA Contains
Our DPA is designed to satisfy Article 28(3) of the GDPR, the corresponding provisions of the UK GDPR, and equivalent processor-contract requirements in other jurisdictions. It contains:
- The subject matter, nature, purpose, and duration of the processing, with data categories and categories of data subjects
- Our obligations as processor, including processing only on your documented instructions, confidentiality commitments for personnel, appropriate technical and organizational security measures (Article 32), and assistance with data subject rights, data protection impact assessments, and breach notifications
- Our subprocessor regime, including a list of current subprocessors and the process by which we notify you of changes and allow you to object
- The European Commission's Standard Contractual Clauses (Commission Implementing Decision 2021/914, Module 2 – controller to processor) for transfers of personal data from the European Economic Area to the United States, with the full Annex content pre-completed for our Service
- The UK International Data Transfer Addendum issued by the UK Information Commissioner's Office, for transfers subject to the UK GDPR
- The Swiss Federal Data Protection and Information Commissioner's recognition of the SCCs, with Swiss-specific amendments, for transfers subject to the Swiss Federal Act on Data Protection
- Our commitments on return or deletion of personal data at the end of the provision of services, and on making available the information necessary to demonstrate compliance
Team Ownership and Controller Roles
Each team on Truestamp selects an ownership model for the items created within it. This selection affects which party is the controller of the personal data that may be contained in those items, and which party is a data contributor whose access ends when their membership ends.
Creator Retains Ownership
Where a team is configured so that creators retain ownership of their items, the creating user is the controller of the personal data contained in those items and the team acts as a collaborative workspace. Truestamp continues to act as processor on behalf of the controller identified by the DPA. When the user leaves the team, items they own follow them to their personal team, and the user remains the controller of that data.
Team Retains Ownership
Where a team is configured so that the team retains ownership, the organization that owns the team (typically the account holder that signs the DPA) is the controller of the personal data contained in every item created in the team. Individual members contribute items to the team as part of their role, but they do not acquire controller rights over the items they author. When a member is removed from or leaves the team, items stay with the team and the departing member loses ongoing access through the Service. The authorship record on each item remains unchanged.
This allocation of roles is the reason we require invitees to a team that retains ownership to acknowledge the ownership clause before their invitation can be accepted. The acknowledgment is recorded alongside the acceptance and is treated as the invitee's informed, documented acceptance of the controller arrangement for that team. There is no accept path that bypasses the acknowledgment. For teams that retain ownership, the controller identified in the DPA is the team's account holder, and instructions to Truestamp as processor are given through that account.
Team administrators can reassign ownership of individual items when responsibilities change. Reassignments are recorded in the audit log. Because the authorship attribute is not part of the cryptographic proof and ownership is separate from authorship, reassignment does not alter the integrity of any existing timestamp or proof.
Current Subprocessors
The subprocessors listed in our Privacy Policy form part of the DPA. A summary for ease of reference:
| Subprocessor | Purpose | Location |
|---|---|---|
| Amazon Web Services, Inc. | Application compute and underlying infrastructure | United States (US East) |
| PlanetScale, Inc. | Managed PostgreSQL database (runs on AWS US East) | United States (US East) |
| Cloudflare, Inc. | DNS, content delivery, DDoS protection, TLS termination, inbound email routing | Global anycast network (US processing) |
| SMTP2GO | Outbound transactional email | United States |
| Google LLC (Google Workspace) | Inbox for our business email addresses and account used to reply to customer correspondence | United States |
| LogSnag LLC (UserJot) | Embedded product feedback widget, public roadmap, and changelog. Receives signed-in user identifiers (ID, email, name, plan tier) and any feedback content the user voluntarily submits | United States |
We update this list in our Privacy Policy when we add, replace, or remove subprocessors, and we notify business customers under DPA of material changes before they take effect.
How to Execute the DPA
To execute a DPA with Truestamp Inc.:
- Email [email protected] from an address associated with your organization and request the DPA. Include the legal name, registered address, and jurisdiction of the entity that will execute it
- We will send you the current version of the DPA (including the pre-completed SCC annexes and subprocessor schedule) for review
- Sign and return the DPA. We will counter-sign and provide a fully executed copy. The DPA takes effect on the date of the last signature
If your procurement process requires specific changes, submit proposed redlines in the same thread. We review all reasonable requests but reserve the right to decline changes that conflict with our infrastructure or other customers' agreements.
Related Documents
Contact
For DPA requests, questions about processing roles, subprocessor changes, or any other data-protection matter, contact:
Truestamp Inc., 16192 Coastal Hwy, Lewes, DE 19958, United States.