← Back to TrailMap

Data Processing Addendum

Draft — not yet in effect

Last updated: [attorney/business to confirm publication date] · Status: DRAFT

This Data Processing Addendum ("DPA") is incorporated into, and forms part of, the Terms of Service (or a separately executed order form/master subscription agreement, as applicable) between Sasquatch Creative TX ("TrailMap," "Processor," or "Service Provider") and the customer identified there ("Customer," "Controller," or "Business"), governing TrailMap's processing of personal data contained within Customer Data on Customer's behalf.

1. Roles of the parties

The parties agree that, with respect to the processing of personal data within Customer Data:

  • Customer is the Controller (or Business) — Customer determines what data it uploads or connects, why, and for what purpose, subject to TrailMap's product functionality.
  • TrailMap is the Processor (or Service Provider) — TrailMap processes that personal data only to provide the Service, on Customer's documented instructions, and not for its own independent purposes (subject to the limited exceptions in Section 3).

This DPA does not apply to TrailMap's processing of Customer's own account and billing contact information as an independent controller — that processing is governed by the Privacy Policy.

2. Subject matter, duration, nature, and purpose of processing

  • Subject matter: TrailMap's provision of the analysis-run pipeline (ingestion, the deterministic engine, the AI narrative layer, dashboards, and exports) applied to Customer Data.
  • Duration: for as long as Customer maintains an active Subscription or account, plus the post-termination period in Section 9.
  • Nature and purpose: normalizing uploaded or connector-synced paid-media performance data into a canonical schema; computing analytics findings deterministically; optionally generating an AI-written narrative from those findings; rendering dashboards and downloadable reports; operating account/team/role/audit-log features; and the security, support, and billing functions necessary to operate the Service.

Categories of Data Subjects, categories of Personal Data, and processing operations are detailed in Annex 1.

3. Processing on instructions

TrailMap will process personal data within Customer Data only on Customer's documented instructions — the Terms of Service and this DPA, Customer's configuration and use of the Service, and any additional written instructions consistent with the Service's documented functionality. If TrailMap believes an instruction infringes Data Protection Law, it will inform Customer promptly. TrailMap will not process personal data within Customer Data for its own purposes, including not using it to train TrailMap's own foundation models, and will not "sell" or "share" it as those terms are defined under the CCPA.

4. Confidentiality

TrailMap ensures that personnel authorized to process personal data within Customer Data are subject to a duty of confidentiality, and limits access to personnel and contractors who need it to provide the Service, consistent with the role-based access control described in Annex 2.

5. Security of processing

Taking into account the state of the art, cost of implementation, and the nature, scope, and purpose of processing, TrailMap implements the technical and organizational measures described in Annex 2. These measures are stated precisely, without overclaiming. Notably: TrailMap does not currently hold a SOC 2 or other third-party security certification (a documented internal roadmap item, not a completed audit), and Annex 2 discloses TrailMap's known architectural limitations alongside its implemented measures.

6. Sub-processors

Customer provides general authorization for TrailMap to engage the Sub-processors listed in Annex 3, to help provide the Service. TrailMap will impose data-protection obligations on each Sub-processor no less protective than this DPA, remain liable to Customer for a Sub-processor's acts and omissions to the same extent TrailMap would be liable performing that processing itself, and give Customer notice of a new Sub-processor or a change to an existing one — by updating this page and, where Customer has provided an email for this purpose, by email — at least [attorney/business to confirm: notice period, e.g. 10–30 days] before the change takes effect, during which Customer may object on reasonable data-protection grounds.

7. Assistance with Data Subject requests

TrailMap will provide reasonable assistance to Customer in responding to a Data Subject's request to exercise their rights under Data Protection Law. In practice, this assistance is anchored by functionality that already exists in the product:

  • A Workspace owner can, from the app's account settings, export a complete JSON snapshot of the Workspace's data on demand (rate-limited, audit-logged), directly satisfying most access/portability requests.
  • A Workspace owner can permanently and irreversibly delete the entire Workspace and all its data, using a type-the-workspace-name confirmation, directly satisfying an erasure request at the Workspace level (subject to the agency-billing-root guard described in the Privacy Policy).
  • For a request that does not come through Customer's own Workspace owner, TrailMap will forward it to Customer and provide reasonable technical assistance.

8. Personal data breach notification

TrailMap will notify Customer without undue delay after becoming aware of a Security Incident affecting personal data within Customer Data, providing the information reasonably available at the time and updating it as the investigation progresses.

Attorney/business to confirm: commit to a specific notification window (e.g. "within 72 hours of becoming aware," mirroring GDPR Art. 33(1)) — noting that TrailMap's responsible-disclosure program does not yet have a formal SLA (see docs/SECURITY.md); do not commit to a numeric SLA here until that program matures, or explicitly scope the commitment to Security Incidents affecting Customer Data.

Reports of suspected incidents can be sent to TrailMap at any time at [email protected].

9. Audits

On reasonable prior notice (no more than once per 12-month period, except following a Security Incident or at a supervisory authority's request), TrailMap will make available to Customer the information reasonably necessary to demonstrate compliance with this DPA — which, given that TrailMap does not currently hold an independent third-party security certification, means TrailMap providing this DPA, its internal security documentation, and a written summary of its technical and organizational measures, in lieu of an on-site audit.

10. Return and deletion of data on termination

Before termination takes effect, Customer may export its Workspace's data at any time using the in-app export described in Section 7. Following termination, TrailMap will delete Customer Data within [attorney/business to confirm: retention period, e.g. 30/90 days] of termination, unless Customer has already exercised the in-app deletion capability, or TrailMap is required by law to retain some or all of the data for a longer period. Backups age out per TrailMap's ordinary backup retention cycle rather than being individually purged.

11. International data transfers

Where TrailMap's processing of personal data within Customer Data involves a transfer from the EEA, the UK, or Switzerland to a country that has not received an adequacy decision, the parties agree that such transfer will be governed by the EU Standard Contractual Clauses (Module 2: Controller to Processor), incorporated by reference, and, for transfers from the UK, the UK International Data Transfer Addendum to those Clauses.

Attorney/business to confirm and complete: this DPA currently references the SCCs but does not attach a completed, signed copy — counsel must select the correct SCC module/annex language, complete the parties'/sub-processors'/supervisory-authority annexes based on TrailMap's actual hosting region(s) and sub-processor location(s) (currently marked "location TBD" in Annex 3), and attach the executed SCCs/UK Addendum as an exhibit before use with any EU/UK/Swiss customer.

12. Liability

Each party's liability arising out of or related to this DPA is subject to the limitations of liability set out in the Terms of Service, unless Data Protection Law prohibits limiting liability for that type of claim.

13. Order of precedence

If there is a conflict between this DPA and the Terms of Service regarding the processing of personal data within Customer Data, this DPA controls. If there is a conflict between this DPA and the executed SCCs/UK Addendum (once attached per Section 11), the SCCs/UK Addendum control.

Data protection / DPA questions: [email protected]. Security incidents: [email protected].

Annex 1 — Details of processing

Categories of Data SubjectsCustomer's and its Authorized Users' personnel (team members invited into a Workspace); incidentally, individuals named in ad-campaign metadata a Customer or its team chose, or a lead-gen contact captured in a conversion field an ad platform reports. TrailMap does not intentionally process ad-platform end-consumer/audience data.
Categories of Personal DataAccount data (name, business email, hashed password, role); Customer Data (paid-media performance metrics/metadata, which may incidentally include names inside campaign/creative naming or lead-gen fields); Connector credentials (encrypted OAuth tokens/API keys); usage data (product-usage events, IP addresses in logs).
Special categories of dataNone intentionally collected or required. Customer should not upload or connect data containing special-category personal data (health, biometric, etc.) — the Service is not designed for it.
Processing operationsCollection (upload/connector sync), storage, normalization, deterministic computation, optional AI-narrative generation, display (dashboard), export (JSON/HTML), and deletion.
DurationFor the term of the Terms of Service, plus the post-termination period (Section 10).
FrequencyContinuous, for as long as the Workspace is active.

Annex 2 — Technical and organizational measures (TOMs)

Grounded precisely in TrailMap's internal security documentation — no measure below is stated more strongly than that document supports, and this Annex is superseded by it if the two ever diverge.

  • Authentication. Passwords hashed with argon2id; constant-time dummy verification for unknown emails; in-process rate limiting on login/registration.
  • Session security. Random session tokens; only a SHA-256 hash is persisted server-side.
  • Encryption at rest (sensitive secrets). Connector credentials and per-tenant AI-provider keys encrypted with Fernet (AES-128-CBC + HMAC-SHA256); production deployments must configure a real encryption key (an insecure/default key is rejected at boot); key rotation is supported without losing access to already-encrypted data.
  • Encryption in transit. Production deployment guidance requires TLS termination in front of the Service and a Secure-flagged session cookie.
  • Access control. Role-based access control (owner/admin/analyst/viewer) scoped per Workspace; a tenant-scoped, admin-viewable audit log records consequential actions.
  • Administrative-API protection. The operator/admin API is gated by a shared secret compared in constant time.
  • Multi-tenancy isolation. Every data row carries a tenant identifier; a Workspace's analysis and data are isolated from every other Workspace.
  • Secure software development. Every push and pull request runs automated dependency-vulnerability scanning (pip-audit) and static-analysis security scanning (bandit, npm audit) in CI.
  • Data minimization toward the AI layer. The AI narrative layer receives only pre-computed findings and Business Profile context, never raw uploads or Connector credentials; "keyless mode" sends nothing to any AI provider.

Known, honestly-disclosed limitations (stated here, not hidden):

Secrets are currently managed via environment variables, not a dedicated secrets manager/KMS — appropriate for a single-operator or trusted-ops deployment; a managed secrets backend is TrailMap's documented upgrade path. File ingestion is batch, not streaming — bounded by a configurable per-upload size limit. By default, the authentication rate limiter and background connector-sync scheduler are single-node/in-process (the storage layer, including Postgres, is fully multi-worker capable). No SOC 2, ISO 27001, or other third-party security certification is currently held — SOC 2 readiness is a roadmap item.

Annex 3 — Sub-processors

Summary of categories, each with location marked to-be-confirmed pending attorney/ops sign-off. See legal/SUBPROCESSORS.md for the full, source-of-truth version with additional notes.

Sub-processor (role) Purpose Data categories Location
Hosting / infrastructure provider Hosts the TrailMap application, its database, and stored files. All Customer Data; account/authentication data. Location TBD — attorney/ops to confirm.
Commercial LLM provider (vendor-neutral) Generates the AI-written narrative from pre-computed findings and Business Profile context. Not engaged in "keyless mode" or with a self-hosted model endpoint. Derived analytical figures and findings metadata; Business Profile context. Not raw exports or credentials. Location TBD — attorney/ops to confirm.
Stripe Payment processing, subscription billing, and the self-serve Customer Portal. Billing contact info; tokenized payment details; subscription/plan status. Global provider, primarily US-headquartered. Specific region — attorney/ops to confirm.
Email / SMTP provider (operator-configured) Delivers transactional email (password resets, invites, report-ready notices) — only when SMTP is configured. Not engaged by default. Recipient email/name and message content — never Customer Data. Location TBD — depends on the provider actually configured.
Error-monitoring tool (optional; not currently enabled) Would capture application error/exception metadata for debugging, if and when enabled (roadmap item, e.g. Sentry). Technical error metadata; may incidentally include an IP/user identifier. N/A — not currently active.

Consolidated attorney/business checklist

Sub-processor notice period · breach-notification time commitment · audit rights scope · post-termination deletion period · select, complete, and attach the executed SCC module/annexes and UK Addendum · confirm hosting and subprocessor regions · confirm whether a signed hard-copy DPA is needed for enterprise procurement. See legal/DPA.md for the full list with section references.

This page mirrors legal/DPA.md and legal/SUBPROCESSORS.md in the TrailMap repository, which are the authoritative sources and carry every citation to the engineering documentation this draft is grounded in. It is a draft pending attorney review and is not currently in effect.