Data Processing Agreement
In plain terms. For organisations that need a Data Processing Agreement under UK GDPR Article 28, this sets out the roles and commitments. A signed copy is available on request.
Roles
In the context of providing Trackhound to your organisation:
- Your organisation is the Data Controller: you determine what data is uploaded, for what purpose, and how long it is retained.
- Trackhound Limited is the Data Processor: we process personal data only on your documented instructions and for the purpose of providing the service.
Legal basis
This agreement operates under UK GDPR Article 28 and the Data Protection Act 2018. Where EU GDPR applies to the personal data being processed, we comply with its requirements for controller-processor relationships.
Processing commitments
- We process personal data only to the extent necessary to provide the Trackhound service.
- We do not transfer personal data outside the UK or EU without appropriate safeguards. Cloud infrastructure used in processing is specified in our transparency page.
- We maintain appropriate technical and organisational measures to protect personal data against unauthorised access, disclosure, alteration, or destruction.
- Customer email addresses and phone numbers are hashed in memory and never persisted in plain text.
- We will notify you without undue delay if we become aware of a personal data breach affecting your organisation's data.
- We will assist you in responding to data-subject rights requests to the extent technically feasible, including access, rectification, and erasure requests.
Sub-processors
Trackhound uses the following sub-processors. By using the service you authorise processing under these sub-processors.
- Amazon Web Services (EU regions): Database and application hosting, authentication, and AI model inference.
- Cohere: Format recognition and similar-show retrieval.
Contact
DPA requests and data-protection queries: [email protected]