Data Processing Agreement - Traycer AI

Data Processing Agreement

Last Updated

Jan 17, 2025

This Data Processing Agreement (“DPA”) forms part of the Terms of Use (or other similarly titled written or electronic agreement addressing the same subject matter) (“ Agreement”) between Customer (as defined in the Agreement) and “ Traycer AI, Inc.” under which the Processor provides the Controller with the software and services (the “Services”). The Controller and the Processor are individually referred to as a “Party” and collectively as the “Parties”.

The Parties seek to implement this DPA to comply with the requirements of EU GDPR (defined hereunder) in relation to Processor’s processing of Personal Data (as defined under the EU GDPR) as part of its obligations under the Agreement.

This DPA shall apply to Processor’s processing of Personal Data, provided by the Controller as part of Processor’s obligations under the Agreement.

Except as modified below, the terms of the Agreement shall remain in full force and effect.

  1. Definitions

Terms not otherwise defined herein shall have the meaning given to them in the EU GDPR or the Agreement. The following terms shall have the corresponding meanings assigned to them below:

1.1. Data Transfer means a transfer of the Personal Data from the Controller to the Processor, or between two establishments of the Processor, or with a Sub-processor by the Processor.

1.2. EU GDPR means the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46/EC.

1.3. Standard Contractual Clauses means the contractual clauses attached hereto as Schedule 1 pursuant to the European Commission’s Implementing Decision (EU) 2021/914.

1.4. Controller means the natural or legal person, public authority, agency, or other body which determines the purposes and means of the processing of personal data.

1.5. Processor means a natural or legal person, public authority, agency, or other body which processes personal data on behalf of the controller.

1.6. Sub-processor means a processor/sub-contractor appointed by the Processor for the provision of all or parts of the Services and processes the Personal Data as provided by the Controller.

  1. Purpose of this Agreement

This DPA sets out various obligations of the Processor in relation to the Processing of Personal Data and shall be limited to the Processor’s obligations under the Agreement. If there is a conflict between the provisions of the Agreement and this DPA, the provisions of this DPA shall prevail.

  1. Categories of Personal Data and Data Subjects

The Controller authorizes permission to the Processor to process the Personal Data to the extent of which is determined and regulated by the Controller. The current nature of the Personal Data is specified in Annex I to Schedule 1 to this DPA.

  1. Purpose of Processing

The objective of Processing of Personal Data by the Processor shall be limited to the Processor’s provision of the Services to the Controller and/or its Client, pursuant to the Agreement.

  1. Duration of Processing

The Processor will Process Personal Data for the duration of the Agreement, unless otherwise agreed upon in writing by the Controller.

  1. Data Controller’s Obligations

6.1. The Data Controller shall warrant that it has all necessary rights to provide the Personal Data to the Data Processor for the Processing to be performed in relation to the agreed services.

6.2. The Data Controller shall provide all natural persons from whom it collects Personal Data with the relevant privacy notice.

6.3. The Data Controller shall request the Data Processor to purge Personal Data when required by the Data Controller or any Data Subject.

6.4. The Data Controller shall immediately advise the Data Processor in writing if it receives or learns of any:

  1. Data Processor’s Obligations

7.1. The Processor will follow written and documented instructions received from the Controller with respect to the Processing of Personal Data.

7.2. The Processing described in the Agreement shall be considered as Instruction from the Controller.

7.3. At the Data Controller’s request, the Data Processor will provide reasonable assistance to the Data Controller in responding to requests by Data Subjects regarding their rights.

7.4. In relation to the Personal Data, Data Processor shall obtain consent (where necessary) and/or provide notice to the Data Subject in accordance with Data Protection Laws.

7.5. Where shared Personal Data is transferred outside the Data Processor’s territorial boundaries, the transferor shall ensure that the recipient of such data is under contractual obligations to protect such Personal Data to the same or higher standards.

7.6. The processor shall inform the controller if a processing instruction infringes applicable legislation or regulation.

7.7. The Data Processor shall assist the Data Controller in conducting any necessary Data Protection Impact Assessments (DPIAs).

  1. Data Secrecy

8.1. To Process the Personal Data, the Processor will use personnel who are:

8.1.1. Informed of the confidential nature of the Personal Data, and
8.1.2. Perform the Services in accordance with the Agreement.

8.2. The Processor will maintain appropriate technical and organizational measures for protection of the security, confidentiality, and integrity of the Personal Data.

  1. Audit Rights

9.1. Upon Controller’s reasonable request, the Processor will make available to the Controller information necessary to demonstrate compliance with its obligations under the EU GDPR.

9.2. The Controller shall bear the expense of such an audit.

  1. Mechanism of Data Transfers

Any Data Transfer for the purpose of Processing by the Processor in a country outside the European Economic Area (the “ EEA”) shall only take place in compliance as detailed in Schedule 1.

  1. Sub-processors

11.1. The Controller acknowledges and agrees that the Processor may engage third-party Sub-processors in connection with the performance of the Services.

11.2. If the Controller has concerns about the Sub-processor(s), the Controller may object to Processor’s use of such Sub-processor and the Processor and Controller shall confer in good faith to address such concern.

  1. Personal Data Breach Notification

12.1. The Processor shall maintain defined procedures in case of a Personal Data Breach.

12.2. The Processor shall provide the Controller with all reasonable assistance to comply with the notification of Personal Data Breach to Supervisory Authority and/or the Data Subject.

12.3. Processor’s notification of or response to a Personal Data Breach under this DPA will not be construed as an acknowledgement by Processor of fault.

  1. Return and Deletion of Personal Data

13.1. The Processor shall, from the end of the Agreement, return to the Controller all the Personal Data, or if the Controller so instructs, the Processor shall delete the Personal Data.

13.2. The Processor shall delete Personal Data including all copies of it as soon as reasonably practicable following the end of the Agreement.

  1. Technical and Organizational Measures

The Processor will take appropriate technical and organizational measures against the unauthorized or unlawful processing of Personal Data and against the accidental loss or destruction of, or damage to, Personal Data.

SCHEDULE 1 ANNEX I
A. LIST OF PARTIES

Data exporter(s):

| Name | Customer (As set forth in the relevant Order Form). | | Address | As set forth in the relevant Order Form. | | Contact person’s name, position, and contact details | As set forth in the relevant Order Form. | | Activities relevant to the data transferred under these Clauses | Recipient of the Services provided by Traycer AI, Inc. in accordance with the Agreement. | | Signature and date | Signature and date are set out in the Agreement. | | Role Controller/ Processor | Controller |

Data importer(s):

| Name | Traycer AI, Inc. | | Address | 376 La Casa Via, Walnut Creek, California, 94598 | | Contact person’s name, position, and contact details | Hardik Shingala, DPO, hardik@traycer.ai | | Activities relevant to the data transferred under these Clauses | Provision of the Services to the Customer in accordance with the Agreement. | | Signature and date | Signature and date are set out in the Agreement. | | Role Controller/ Processor | Processor. | | Our EU-GDPR representative according to Art. 27 of the GDPR is | Rickert Rechtsanwaltsgesellschaft mbH, Colmantstraße 15, 53115 Bonn, Germany, art-27-rep-traycer@rickert.law |

B. DESCRIPTION OF TRANSFER

| Categories of data subjects whose personal data is transferred | Customer’s authorized users of the Services. | | Categories of personal data transferred | Name, Email, Image, GitHub User ID, Username | | Sensitive data transferred (if applicable) and applied restrictions or safeguards | No sensitive data collected. | | The frequency of the transfer | Continuous basis | | Nature of the processing | The nature of the processing is more fully described in the Agreement. | Purpose(s) of the data transfer and further processing | The purpose of the transfer is to facilitate the performance of the Services. | | The period for which the personal data will be retained | The period for which the Customer Personal Data will be retained is more fully described in the Agreement. |

C. COMPETENT SUPERVISORY AUTHORITY

| Data exporter is established in an EEA country. The competent supervisory authority is | As determined by application of Clause 13 of the EU SCCs. |

ANNEX II TECHNICAL AND ORGANISATIONAL MEASURES INCLUDING TECHNICAL AND ORGANISATIONAL MEASURES TO ENSURE THE SECURITY OF THE DATA

Description of the technical and organisational security measures implemented by Traycer AI, Inc. as the data processor/data importer to ensure an appropriate level of security.

ANNEX III LIST OF SUB-PROCESSORS

The controller has authorized the use of the following sub-processors:

Name of Sub-Processor Description of Processing Location of Other Processor
Google Cloud Service Hosting the Production Environment USA
Google Workspace Email services USA
GitHub Code version control USA
Supabase Database and Authentication Provider USA
Stripe Invoicing and Payment solution USA
Anthropic LLM Provider USA
OpenAI LLM Provider USA
Microsoft Azure OpenAI LLM Provider USA
PineCone LLM Provider USA
VoyageAI LLM Provider USA
AWS Bedrock LLM Provider USA
LangSmith Product Analytics USA
PostHog Product Analytics USA
Intercom Customer Service USA

Your coding agents are fast. We keep them on track.

Join thousands of developers already experiencing a better way to build software with AI.



Download for Linux](https://github.com/traycerai/traycer/releases/latest/download/traycer-desktop-linux-x86_64.AppImage)