1. Controller and processor
TrustFlare is controller of website visitor and lead-form data. For customer user data processed through the service, TrustFlare acts as processor on customer instructions under the DPA.
In self-hosted deployments, end-user data remain in customer infrastructure and TrustFlare does not receive them.
2. Data and lawful grounds (Article 6 GDPR)
- Lead-form data (name, contact, company, message): consent and/or steps before a contract taken at your request, Articles 6(1)(a) and (b).
- Anonymized visit analytics: legitimate interest in improving the website, Article 6(1)(f). We do not use cross-site advertising tracking.
- Processor data: processed on documented instructions from the customer-controller.
3. Your rights (Articles 15–22 GDPR)
You may access, correct or erase data; restrict processing; request portability; object to processing; and withdraw consent.
Use the DSAR form on the Privacy page or email [email protected]. We respond within one month. You may also complain to a supervisory authority.
4. International transfers
For transfers outside the EEA, we use lawful mechanisms, including EU Standard Contractual Clauses, and additional safeguards. Self-hosted deployments generally do not require international transfers.
5. California rights (CCPA/CPRA)
- Know what personal data are collected and obtain a copy.
- Request deletion and correction.
- Opt out of the sale or sharing of data. We do not sell personal data.
6. Retention and security
We retain data only as long as needed for the purposes and protect them with technical and organizational measures. See our Subprocessors.
7. Contact and compliance statement
Privacy enquiries and rights requests: [email protected]. Representative/DPO contact details are available on request.
TrustFlare declares that it processes personal data in accordance with GDPR, including lawful grounds, minimization, subject rights and Articles 33–34 breach notifications. See Compliance statements.