Data Processing Agreement

Last updated September 10, 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service ("Terms") between Two Trick Pony Enterprise, a Dutch sole proprietorship registered with the Dutch Chamber of Commerce under KvK number 89010701, with its registered address at Lloyd Webberhof 15, Utrecht, the Netherlands ("Truffle", "we", "us"), and the customer using Truffle ("Customer", "you").

This DPA applies where and to the extent that Truffle processes Personal Data on behalf of the Customer in connection with the Truffle services.

If there is a conflict between this DPA and the Terms concerning the processing of Personal Data, this DPA prevails to the extent of that conflict.

1. Definitions

For this DPA:

  • "Personal Data" means personal data as defined by applicable Data Protection Laws.
  • "Processing" means any operation performed on Personal Data, including collection, storage, organisation, retrieval, use, disclosure, transmission, indexing and deletion.
  • "Data Protection Laws" means applicable laws and regulations relating to the protection of Personal Data, including the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR").
  • "Controller", "Processor", "Data Subject" and "Supervisory Authority" have the meanings given to them under the GDPR.
  • "Subprocessor" means a third party engaged by Truffle to process Personal Data on behalf of the Customer.

2. Roles of the parties

For Personal Data processed through the Services on behalf of the Customer:

  • the Customer is the Controller; and
  • Truffle is the Processor.

The Customer remains responsible for determining the purposes and means of processing such Personal Data and for ensuring that its instructions to Truffle comply with applicable Data Protection Laws.

Truffle may process certain information for its own purposes as an independent Controller, including information relating to customer accounts, billing, service administration, security, fraud prevention, product analytics and legal compliance. Such processing is governed by Truffle's Privacy Policy and is outside the scope of this DPA.

3. Subject matter and duration

Truffle will process Personal Data solely in connection with providing, securing, maintaining and supporting the Services.

The duration of processing corresponds to the period during which Truffle provides the Services to the Customer, together with any limited period required to delete or return Personal Data following termination, subject to applicable legal requirements and this DPA.

4. Customer instructions

Truffle will process Personal Data only:

  1. to provide the Services;
  2. on the Customer's documented instructions;
  3. as necessary to comply with applicable law; or
  4. as otherwise expressly permitted by this DPA or the Terms.

The Customer's use of the Services constitutes its instructions to Truffle to process Personal Data as necessary to provide the Services.

If Truffle reasonably believes that an instruction violates applicable Data Protection Laws, Truffle may notify the Customer before carrying out that instruction.

5. Customer responsibilities

The Customer is responsible for:

  • ensuring that it has a lawful basis for processing Personal Data through the Services;
  • providing appropriate notices to Data Subjects where required;
  • obtaining any necessary consents or other legal authorisations;
  • ensuring that its instructions to Truffle are lawful;
  • determining which Personal Data it submits to the Services; and
  • using the Services in accordance with applicable Data Protection Laws and the Terms.

The Customer must not knowingly use the Services to process Personal Data in circumstances where doing so would violate applicable law.

6. Confidentiality

Truffle will ensure that persons authorised to process Personal Data are subject to appropriate confidentiality obligations.

Truffle will not disclose Customer Personal Data to third parties except:

  • as necessary to provide the Services;
  • to approved Subprocessors;
  • where required by law;
  • where necessary to protect the security or integrity of the Services; or
  • with the Customer's documented authorisation.

7. Security

Truffle will implement appropriate technical and organisational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.

Depending on the nature of the Services, these measures may include:

  • access controls and authentication;
  • encryption in transit and, where appropriate, at rest;
  • restricted access to production systems;
  • logging and monitoring;
  • secure credential and secret management;
  • backups and recovery procedures;
  • vulnerability and infrastructure monitoring; and
  • measures designed to maintain the confidentiality, integrity, availability and resilience of the Services.

Truffle may update its security measures from time to time provided that such changes do not materially reduce the overall level of protection provided to Personal Data.

8. Subprocessors

The Customer authorises Truffle to use third-party service providers that process Personal Data in connection with providing the Services.

Truffle's current Subprocessors may include:

  • Amazon Web Services (AWS) — hosting, compute, storage and database infrastructure.
  • Upstash — caching infrastructure.
  • Qdrant — vector database and similarity-search infrastructure.
  • Anthropic — AI model infrastructure.
  • OpenAI — AI model and embedding infrastructure.
  • PostHog — product analytics.
  • Stripe — payment and subscription infrastructure.

Truffle may maintain the current Subprocessor list separately and update it from time to time.

Truffle will require Subprocessors that process Personal Data to undertake appropriate data protection and confidentiality obligations consistent with the requirements applicable to Truffle.

Truffle remains responsible for its Subprocessors to the extent required by applicable Data Protection Laws.

9. Changes to Subprocessors

Truffle may appoint new Subprocessors or replace existing Subprocessors where reasonably necessary to operate or improve the Services.

Where required by applicable Data Protection Laws, Truffle will provide the Customer with information about material changes to Subprocessors.

If the Customer has a legally valid objection to a new Subprocessor based on data protection grounds, the parties will work in good faith to address the objection.

If the parties cannot reasonably resolve the objection, the Customer may terminate the affected Services in accordance with the Terms.

10. Assistance with Data Subject requests

Taking into account the nature of the processing, Truffle will provide reasonable assistance to the Customer to enable the Customer to respond to requests from Data Subjects exercising their rights under applicable Data Protection Laws.

Where Truffle receives a request directly from a Data Subject relating to Personal Data processed on behalf of the Customer, Truffle will, where legally permitted, direct the Data Subject to the Customer.

Truffle will not independently respond to such requests except where required by law or where otherwise authorised by the Customer.

11. Personal Data breaches

If Truffle becomes aware of a Personal Data breach affecting Personal Data processed on behalf of the Customer, Truffle will notify the Customer without undue delay, where required by applicable Data Protection Laws.

Where reasonably available, the notification will include information necessary for the Customer to assess and respond to the incident, including the nature of the incident and the categories of Personal Data affected.

Truffle will take reasonable measures to investigate, contain and mitigate the effects of a Personal Data breach.

12. Assistance with compliance

Taking into account the nature of the processing and the information available to Truffle, Truffle will provide reasonable assistance to the Customer with:

  • security obligations;
  • Personal Data breach notifications;
  • Data Protection Impact Assessments; and
  • consultations with Supervisory Authorities,

where such assistance is required under applicable Data Protection Laws.

The Customer will reimburse Truffle for reasonable costs incurred in providing assistance that is materially beyond the ordinary scope of the Services, unless otherwise agreed.

13. International transfers

Where Personal Data is transferred outside the European Economic Area ("EEA"), Truffle will ensure that the transfer is carried out using a lawful transfer mechanism under applicable Data Protection Laws.

Depending on the circumstances, this may include:

  • an adequacy decision of the European Commission;
  • the European Commission's Standard Contractual Clauses;
  • another legally recognised transfer mechanism; or
  • another lawful basis permitted under applicable Data Protection Laws.

Truffle may use Subprocessors located outside the EEA where an appropriate legal transfer mechanism is in place.

14. Return and deletion of Personal Data

Following termination of the Services, Truffle will, at the Customer's choice where technically feasible, delete or return Personal Data processed on the Customer's behalf, unless retention is required by applicable law.

The Customer may request deletion of Personal Data relating to a connected source where such functionality is provided by the Services.

Truffle may retain limited copies of Personal Data where necessary for:

  • legal compliance;
  • security;
  • fraud prevention;
  • dispute resolution;
  • enforcing the Terms; or
  • backups maintained as part of normal business continuity procedures.

Personal Data retained solely in backups will be deleted in accordance with Truffle's normal backup lifecycle.

15. Audit and information

Upon reasonable request, Truffle will make available information reasonably necessary to demonstrate compliance with the obligations applicable to processors under Article 28 of the GDPR.

Where reasonably necessary and legally permitted, this may include relevant security documentation, policies, certifications or summaries of technical and organisational measures.

The Customer may conduct an audit where required by applicable Data Protection Laws, provided that:

  • reasonable prior written notice is given;
  • the audit takes place during normal business hours;
  • the audit does not unreasonably interfere with Truffle's operations or other customers;
  • the Customer does not obtain access to another customer's data;
  • the Customer does not obtain access to Truffle's confidential information unrelated to the audit; and
  • the Customer bears its own audit costs.

Where an independent audit or on-site audit is reasonably necessary, the parties will agree its scope and reasonable conditions in advance.

16. Categories of Personal Data and Data Subjects

Categories of Personal Data

Depending on how the Customer uses Truffle, the Services may process:

  • names;
  • email addresses;
  • usernames and identifiers;
  • organisation or company information;
  • account and membership information;
  • communication and support information;
  • user-generated content;
  • questions and messages submitted to Truffle;
  • content contained in connected repositories, documentation or other sources;
  • technical identifiers and metadata contained in Customer content; and
  • other Personal Data that the Customer chooses to submit through the Services.

Categories of Data Subjects

Data Subjects may include:

  • Customer employees;
  • contractors;
  • users and members;
  • customers and prospective customers;
  • suppliers and business partners; and
  • other individuals whose Personal Data is contained in Customer content.

The Customer is responsible for determining whether the Personal Data it submits to the Services is appropriate for processing through Truffle.

17. Special categories of Personal Data

The Services are not specifically designed to process special categories of Personal Data as defined by Article 9 of the GDPR.

The Customer should not intentionally submit sensitive Personal Data to the Services unless doing so is lawful and appropriate for its intended use of Truffle.

Where the Customer does submit such information, the Customer remains responsible for ensuring that an appropriate legal basis and, where applicable, an Article 9 condition exists.

18. AI services

Truffle may use third-party AI providers to generate answers, summaries, embeddings and other outputs as part of the Services.

Where Customer Personal Data is included in prompts, retrieved context or other inputs sent to an AI provider, such processing is performed as part of providing the Services.

Truffle will use AI providers in accordance with the applicable contractual and data protection arrangements in place for the Services.

Truffle does not use Customer content processed through the Services to train general-purpose AI models, except where the Customer has expressly authorised such use.

Where the Customer uses its own AI provider credentials ("BYOK"), processing by that AI provider may also be subject to the Customer's separate agreement with that provider.

19. No sale of Personal Data

Truffle does not sell Customer Personal Data.

Truffle does not disclose Customer Personal Data to third parties for their independent marketing purposes.

Third-party service providers receive Personal Data only where reasonably necessary to provide the Services or where otherwise permitted by this DPA.

20. Term and termination

This DPA remains in effect for as long as Truffle processes Personal Data on behalf of the Customer.

The termination of the Terms will automatically terminate this DPA, except for provisions that by their nature are intended to survive termination, including provisions concerning confidentiality, security, deletion and legally required retention.

21. Liability

The liability of the parties in connection with this DPA is subject to the limitations and exclusions of liability set out in the Terms, except to the extent that applicable Data Protection Laws prohibit such limitations or require otherwise.

22. Changes to this DPA

Truffle may update this DPA where reasonably necessary to reflect changes to the Services, applicable Data Protection Laws or the Subprocessors used by Truffle.

Where a change materially affects the Customer's rights or obligations, Truffle will provide reasonable notice where required by applicable law.

23. Governing law

This DPA is governed by the laws specified in the Terms.

Any disputes concerning this DPA will be subject to the jurisdiction specified in the Terms.

24. Contact

Questions about this DPA or data processing can be sent to privacy@asktruffle.com.