Data Processing Addendum

This addendum is available on request for business customers who require a data processing agreement covering personal data we process on their behalf.

Last updated: July 10, 2026 · Effective: July 10, 2026

1. Scope and roles

This Data Processing Addendum (“DPA”) is available on request and forms part of the agreement between you (the “Controller”) and TryReport (“TryReport”, operated from Ukraine, the “Processor”) for use of the Service. It applies where we process personal data on your behalf as a processor. Where we determine the purposes and means of processing (for example, our own account and billing data), we act as an independent controller under our Privacy Policy.

2. Processing details

  • Subject matter: provision of the TryReport research and intelligence Service.
  • Duration: for the term of your use of the Service and any wind-down period.
  • Nature and purpose: hosting, processing, and generating outputs from the content you submit, including via AI models.
  • Types of data: account identifiers, contact details, and any personal data contained in content you submit.
  • Data subjects: your authorised users and any individuals referenced in your content.

3. Our obligations as processor

  • Process personal data only on your documented instructions;
  • Ensure persons authorised to process data are bound by confidentiality;
  • Implement the security measures described in Section 4;
  • Assist you, taking into account the nature of processing, with data-subject requests and your obligations under Articles 32–36 GDPR;
  • Delete or return personal data at the end of the engagement (Section 7);
  • Make available information necessary to demonstrate compliance and allow for audits (Section 6).

4. Security measures (Art. 32)

We maintain appropriate technical and organisational measures, including encryption of data in transit, access controls and least-privilege permissions, secure authentication, logging and monitoring, and use of vetted sub-processors under contract.

5. Sub-processors

You authorise us to engage the sub-processors listed below. We impose data-protection obligations on each sub-processor consistent with this DPA and remain responsible for their performance. We will give notice of changes to this list so you can object on reasonable grounds.

Sub-processorPurposeLocation
ClerkAuthentication & user account managementUnited States
Neon (PostgreSQL)Primary application database hostingUnited States
Google (Gemini API)AI model processing of user-submitted contentUnited States
Google AnalyticsUsage analytics (loads only after cookie consent)United States
ResendTransactional & notification email deliveryUnited States
DataForSEOSEO keyword and market data enrichmentUnited States
PaddlePayment processing & subscription billing as merchant of record (we never receive or store full payment credentials)United Kingdom
Private virtual server (self-managed)Application hosting and background job queue (Redis)European Union

6. Audits

On reasonable prior written notice, and no more than once per year (unless required by a supervisory authority), we will make available information necessary to demonstrate compliance with this DPA and cooperate with audits, subject to confidentiality and to protecting other customers’ data.

7. Where data is processed

We are operated from Ukraine, and personal data processed under this DPA is processed in Ukraine, the United States, and the European Union. We take reasonable technical and organisational measures to protect personal data wherever it is processed. If you require specific contractual transfer terms, contact us and we will accommodate reasonable requests.

8. Personal data breaches

We will notify you without undue delay after becoming aware of a personal data breach affecting your data, and provide information reasonably available to help you meet your notification obligations.

9. Deletion and return of data

On termination of the Service, we will delete or return your personal data at your choice, except where retention is required by law. Backups are deleted in the ordinary course of our retention cycle.

10. Contact

To request a signed copy of this DPA or ask a question, email [email protected].

This document is provided for transparency and is not legal advice. If you have questions, contact us at [email protected].