Tracemill Data Processing Addendum
Version: dpa-v1
Effective date: September 12, 2026
1. Scope and instructions
This DPA is incorporated into the Terms between Tracemill, Inc. and Customer. It covers personal information within Customer Data processed on Customer's behalf, including workspace memberships, invitations, roles, customer-specific activity, telemetry and evidence. Customer controls the purposes and lawful instructions; Tracemill acts as processor/service provider, or subprocessor where Customer is authorized to act for another controller. These labels apply as the relevant law provides. Customer is responsible for lawful collection, required notices and instructions; managed-service use still requires authorization under the Terms.
Processing consists of receiving, storing, organizing, transforming, generating, analyzing, retrieving, transmitting, exporting and deleting data to deliver the ordered telemetry/testing service and authorized support/security. Data may include names, usernames, email/IP addresses, device/account identifiers, timestamps and activity details about customer personnel, contractors or others lawfully included in customer-controlled material. Specially regulated data excluded by the Terms is not authorized. Processing lasts through Service provision and permitted retention/deletion.
The Agreement, authorized product settings/operations and other documented lawful instructions govern processing, including disclosures to customer-selected integrations. We process only as instructed or legally required, notify you before legally required contrary processing unless prohibited, and inform you if we believe an instruction infringes applicable privacy law.
Separate cross-workspace identity, business/billing, trial-eligibility and necessary platform-security processing follows the Privacy Notice. Roles follow actual purpose and law; this does not permit moving customer content into independent uses or retention.
2. Protection and use limits
We restrict access to people who need it and are bound by confidentiality and maintain reasonable safeguards appropriate to the data and risk, including access controls, encrypted transport/storage, protected credentials and recovery arrangements. Details of verified measures are available on reasonable request. No certification, dedicated infrastructure, SLA or guaranteed security is represented.
We will not sell or share Customer Personal Data for cross-context behavioral advertising, use it for unrelated commercial purposes, or retain/use/disclose it outside the specified purposes and direct business relationship. We will not combine it with other customer or independently collected personal data except as expressly permitted by applicable law for those specified purposes. The Terms' restrictions on publication and general-purpose AI training continue. We understand and will comply with applicable processor/service-provider restrictions and provide the level of protection they require.
3. Providers and compliance assistance
You generally authorize the providers in the register below, as updated through this Section 3. We bind providers processing on our behalf to appropriate written restrictions, perform reasonable diligence, and remain responsible for their performance of delegated data-protection duties. We will give reasonable advance email notice of intended additions/replacements, allowing sufficient time to raise a documented data-protection objection before the new provider processes affected Customer Personal Data. We will not begin the new processing of your Customer Personal Data while your timely objection remains unresolved. We will work to resolve any such objection; if no reasonable resolution exists, either party may terminate the affected Service by electronic notice under Section 4 before the new processing begins. We will refund unused prepaid fees for that Service within 30 days and release future unprovided commitments for it. Any longer notice or other safeguards required by applicable law control.
We provide information reasonably necessary to demonstrate compliance, assist with applicable individual requests and security/privacy obligations, and permit legally required assessments and audits. Reasonable confidentiality/security coordination protects other customers without obstructing mandatory rights or authority access. We notify you if we can no longer meet applicable processing obligations and permit reasonable steps to stop/remediate unauthorized use. These duties do not depend on a separately purchased support plan.
Requests should identify the relevant Customer where possible; we will seek clarification or forward to the reasonably identifiable Customer and assist within applicable deadlines. We do not independently disclose tenant data to an unverified requester. Customer-selected destinations and AI clients are not our subprocessors merely because Customer requests an integration.
| Provider | Function | Storage, processing and access country |
|---|---|---|
| AWS | Hosting, storage/recovery, authentication and authentication emails, to the extent processing Customer Personal Data | United States |
| Sentry | Operational diagnostics to the extent containing Customer Personal Data | United States |
| Microsoft 365 | Email, including support correspondence and attachments containing Customer Personal Data | United States |
4. Incidents and communications
We notify your privacy contact or account administrator without undue delay after awareness of accidental/unlawful loss, destruction, alteration, unauthorized disclosure of or access to Customer Personal Data in our or our subprocessors' processing. Initial notice will not await complete investigation; we provide available details, likely effects, response measures, a contact and material updates, and reasonably cooperate with your required responses.
All notices, requests, objections and terminations under this DPA may be sent electronically: to support@tracemill.io for Tracemill and your designated privacy contact or administrator for Customer. Notice takes effect when delivered without an automated failure notice. Customer handles its legally required individual/authority notices, without removing our own legal duties.
5. Return, deletion and priority
At your choice we return or delete still-retained Customer Personal Data when processing ends and delete copies unless lawful instructions or a legal storage requirement permit retention. The Retention Schedule supplies ordinary periods; stricter law and lawful earlier deletion instructions prevail. Backups remain protected and outside ordinary use until expiry; required deletions are reapplied before restored data returns to ordinary processing.
You instruct us to keep only minimal identifiers, scope, timestamps and status necessary to enforce/verify deletion, protected against rollback during restoration. We use them only for that purpose and delete or irreversibly anonymize them once all recoverable copies expire and verification is complete, unless limited evidence is legally required longer. This does not extend underlying data deadlines. Processor-held content cannot be kept longer merely by labeling it a log or business record.
This DPA controls personal-data conflicts, survives authorized retention and remains subject to the Terms' lawful liability limits without restricting individual or regulator rights. Provider-register updates follow Section 3 and do not require separate acceptance under the Terms; they do not amend substantive DPA obligations. All other DPA changes follow the Terms' acceptance rules. This US-focused DPA supplies no operative international-transfer clauses: processing requiring safeguards not already in place requires separate review/arrangements before submission. Neither US customer domicile nor this restriction excuses our own legal or onward-transfer obligations.