Last updated: 1 October 2026.
This Data Processing Agreement ("DPA") forms part of the Platform Services Agreement between Trialight Ltd ("we") and the Customer ("you"). It applies whenever we process Customer Personal Data.
| Term | Meaning |
|---|---|
| Data Protection Laws | Privacy laws applying to the processing, including the UK General Data Protection Regulation, European Union General Data Protection Regulation, and applicable United States state privacy laws |
| Customer Personal Data | Personal data we process for you as described below |
| Subprocessor | A provider we use to process Customer Personal Data |
1. Roles and instructions
You are the controller and we are your processor for Customer Personal Data. We act as controller for account, billing, security, usage, and public professional data described in our Privacy Policy, and for Trialight Agent interactions you allow us to use to improve Trialight Agent.
We process Customer Personal Data only to provide, secure, support, improve, and end the Service; on your documented instructions; or where law requires, after permitted notice.
We tell you if an instruction appears unlawful. Each party remains responsible for its duties.
2. Processing details
| Item | Detail |
|---|---|
| Subject and duration | The Service term plus return and deletion |
| Nature and purpose | Hosting, storing, securing, supporting, and returning customer workspaces, looking up information you ask Trialight Agent for, and improving Trialight Agent where you allow it |
| Personal data | Searches, instructions, interactions with Trialight Agent, saved workspace content, other personal data you submit to a workspace, and names and job titles Trialight Agent looks up at your request |
| People | People whose personal data you submit to a workspace or ask Trialight Agent to look up |
| Your rights and duties | Give lawful instructions and choose return or deletion; receive information and audit |
| Special-category data | The Service is not designed for it and you must not submit it |
3. Our duties
People authorised to process Customer Personal Data have need-based access and are bound by confidentiality. We maintain appropriate security, keep required records, and tell you if we can no longer comply.
Taking account of the processing and information available to us, we help you with individual rights, security, breach notification, impact assessments, and prior consultation with regulators.
Measures include encryption, restricted production access, managed backups, monitoring, provider checks, and incident response. Updates will not materially reduce protection.
4. Subprocessors
You give general written authority for us to use the providers in our Subprocessors register, including a model provider that receives text a person in your workspace wrote when they use Trialight Agent.
Before a Subprocessor receives Customer Personal Data, we impose equivalent written duties, remain responsible, and give reasonable prior notice of a new direct provider.
You may object on reasonable data-protection grounds. If unresolved, you may close your account and recover unused prepaid credits.
5. Breaches and assistance
We notify your administrator of a breach affecting Customer Personal Data without undue delay, then provide its nature, likely effect, scale, and response as known.
We forward rights requests and respond only on your instruction or where law requires. Unusually burdensome help may be charged at an agreed rate.
6. International transfers
We make restricted transfers only on your instructions and through:
- an adequacy regulation or decision;
- the United Kingdom International Data Transfer Agreement;
- the United Kingdom Addendum to the European Union Standard Contractual Clauses; or
- the European Union Standard Contractual Clauses.
We complete required assessments. If one fails, we replace it or stop the transfer.
7. Return, deletion, and audit
At the end, you may choose return or deletion. We provide a standard export, put remaining data beyond use, delete live data within 90 days, and purge backups within 35 more days, unless law requires retention. Trialight Agent interactions you allowed us to use to improve it are kept as our Privacy Policy describes.
We provide compliance information and allow and contribute to audits or inspections by you or an auditor you appoint. Ordinarily, these start with security material, happen once a year on reasonable notice, and are confidential and at your cost. Regulators and post-breach audits are not limited.
8. Local privacy laws
Equivalent local duties apply. Under United States state privacy law, we act as your service provider or processor. We do not sell, share, combine, or use Customer Personal Data outside the relationship except where law permits.
9. General
This DPA lasts while we process Customer Personal Data. The Agreement's liability limits and England and Wales law apply, except where mandatory law or a transfer instrument differs.
Company and contact
Trialight Ltd is registered in England and Wales under company number 17081917. Its registered office is 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ.
Questions and requests should be sent to privacy@trialight.com.