Legal
Data Processing Addendum
Last updated: August 19, 2026
Status and execution
This public text is the standard Trytracegrid DPA framework. It becomes binding only when executed by the customer and Ahmed Refaat Abdelzaher as operator of Trytracegrid. The private execution process requires legal names, valid service addresses, signing authority, and contact details. Request execution at support@trytracegrid.com.
Roles and instructions
The customer is controller and Trytracegrid is processor for personal data submitted through customer workspaces, except where each party acts as an independent controller under law. Trytracegrid processes data only to provide, secure, support, and improve the contracted service, follow documented instructions, or comply with law.
Processing details
Subject: marketing measurement audits, connected-system evidence, approvals, and support. Duration: subscription term plus deletion and backup periods. Data subjects: customer personnel, end users represented in technical event data, and business contacts. Data categories: identifiers, online and device data, campaign and event data, account metadata, communications, and audit evidence. Customers must not submit unnecessary special-category, payment-card, health, biometric, or government-identifier data.
Confidentiality and security
Personnel and contractors authorized to process customer data are bound by confidentiality. Trytracegrid maintains measures appropriate to the service risk, including tenant isolation, access control, encryption of credentials, session controls, logging, rate limits, secure headers, backup management, and controlled change workflows.
Subprocessors
The customer authorizes the subprocessors in the current Subprocessor List. Trytracegrid remains responsible for required contractual obligations and will publish material changes in advance where reasonably possible. The executed DPA will specify the customer's reasonable objection process.
International transfers
Where required, the parties will execute applicable transfer safeguards, including recognized standard contractual clauses and relevant supplementary measures. Trytracegrid does not make an EU-only residency promise unless expressly documented for the customer deployment.
Data-subject requests
Taking account of the processing, Trytracegrid will provide reasonable assistance for access, correction, deletion, restriction, portability, objection, and consent-withdrawal requests. The customer remains responsible for evaluating and responding to requests as controller.
Security incidents
Trytracegrid will notify the customer without undue delay after becoming aware of a personal-data breach affecting customer data and will provide available information about nature, scope, likely consequences, containment, and remediation. Notification is not an admission of fault.
Deletion and return
During the term, the customer may export available data. On verified deletion or termination instruction, active data is deleted promptly and residual encrypted backups are targeted for purge within 30 days, unless retention is required by law or necessary for security and dispute preservation.
Assistance and audits
Trytracegrid will provide available security and processing information reasonably needed for compliance. Audits must protect other customers and system security, use existing reports first, occur no more than annually unless required after a breach or by a regulator, and be subject to reasonable confidentiality, scope, scheduling, and cost terms in the executed agreement.
Liability and precedence
The Terms of Service liability limits apply to this DPA unless prohibited by applicable data-protection law. If this DPA conflicts with the Terms on personal-data processing, this DPA controls.