TrustFlare
ProductDemoPricingRURequest a pilot
All documentsTerms of useAcceptable useRussian personal-data policyPrivacy policy (GDPR/CCPA)Data processing agreementSubprocessorsCookie policySecurityISO 27001 and infrastructureCompliance statements

Legal and compliance

Data processing agreement

Updated: 21 July 2026

This document describes processing by TrustFlare on behalf of the customer. For paid use, the DPA forms part of the agreement; this version describes our standard obligations.

1. Roles

The customer is the controller, or processor, of its users’ data. TrustFlare acts as processor, or subprocessor, and processes data only on documented customer instructions.

For Free, Business and trials, the core runs in TrustFlare cloud: we process device facts, allow/deny decisions and sign-in logs. Under Ultimate, the core is customer-hosted and we have no access to these data. Our processor role covers the cloud core, website and requests.

2. Scope and nature

  • Data subjects: customer employees, contractors and users of protected systems.
  • Data: device identifiers, device and environment facts (OS, version, serial number, public keys), OS username and sign-in metadata (IP, user agent, country), limited to what is needed for a trust decision.
  • Purpose: establishing device and browser trust, registering and confirming devices, and logging access decisions.
  • We do not process special categories of data or create behavioural profiles.

3. Processor obligations

  • Process data only on controller instructions and within the agreement.
  • Ensure confidentiality of people authorized to process data.
  • Apply technical and organizational measures described in Security.
  • Assist the controller with data-subject requests and data-protection impact assessments.
  • Notify breaches without undue delay, as described in the incident-response process.
  • Delete or return data at the controller’s choice when services end.

4. Subprocessors

Subprocessors must have comparable data-protection obligations. See the current list. Changes are notified with an opportunity to object as provided by the agreement.

5. International transfers

The Free, Business and trial cloud core uses Cloudflare infrastructure and a dedicated EU server; the owner provides the exact location on request. Ultimate does not require transfers outside the customer perimeter. Cloud transfers use lawful grounds, including EU Standard Contractual Clauses.

6. Data-subject rights and audits

We assist controllers with access, correction, deletion and other rights, and provide information demonstrating compliance upon reasonable request. Contact [email protected].

© 2026 TrustFlare
BlogLegalPrivacySecurity
Get startedEarly-stage product