This addendum is available on request for business customers who require a data processing agreement covering personal data we process on their behalf.
Last updated: July 10, 2026 · Effective: July 10, 2026
This Data Processing Addendum (“DPA”) is available on request and forms part of the agreement between you (the “Controller”) and TryReport (“TryReport”, operated from Ukraine, the “Processor”) for use of the Service. It applies where we process personal data on your behalf as a processor. Where we determine the purposes and means of processing (for example, our own account and billing data), we act as an independent controller under our Privacy Policy.
We maintain appropriate technical and organisational measures, including encryption of data in transit, access controls and least-privilege permissions, secure authentication, logging and monitoring, and use of vetted sub-processors under contract.
You authorise us to engage the sub-processors listed below. We impose data-protection obligations on each sub-processor consistent with this DPA and remain responsible for their performance. We will give notice of changes to this list so you can object on reasonable grounds.
| Sub-processor | Purpose | Location |
|---|---|---|
| Clerk | Authentication & user account management | United States |
| Neon (PostgreSQL) | Primary application database hosting | United States |
| Google (Gemini API) | AI model processing of user-submitted content | United States |
| Google Analytics | Usage analytics (loads only after cookie consent) | United States |
| Resend | Transactional & notification email delivery | United States |
| DataForSEO | SEO keyword and market data enrichment | United States |
| Paddle | Payment processing & subscription billing as merchant of record (we never receive or store full payment credentials) | United Kingdom |
| Private virtual server (self-managed) | Application hosting and background job queue (Redis) | European Union |
On reasonable prior written notice, and no more than once per year (unless required by a supervisory authority), we will make available information necessary to demonstrate compliance with this DPA and cooperate with audits, subject to confidentiality and to protecting other customers’ data.
We are operated from Ukraine, and personal data processed under this DPA is processed in Ukraine, the United States, and the European Union. We take reasonable technical and organisational measures to protect personal data wherever it is processed. If you require specific contractual transfer terms, contact us and we will accommodate reasonable requests.
We will notify you without undue delay after becoming aware of a personal data breach affecting your data, and provide information reasonably available to help you meet your notification obligations.
On termination of the Service, we will delete or return your personal data at your choice, except where retention is required by law. Backups are deleted in the ordinary course of our retention cycle.
To request a signed copy of this DPA or ask a question, email [email protected].
This document is provided for transparency and is not legal advice. If you have questions, contact us at [email protected].