Terms and Conditions
Home Terms and Conditions
Last updated: May 2026
Trustif Solutions OÜ
Data Processing Terms (DPA-aligned public summary)
1. Scope and Roles
These terms summarize how personal data is handled when organizations use Trustif services.
In platform operations, the Customer is generally the Controller and Trustif Solutions OÜ is the Processor.
Trustif may also act as an independent Controller for its own billing, support, and security logs.
2. Processing Object and Purpose
Trustif processes personal data to provide and technically maintain the reporting channel service.
Core processed data covers primary user account and technical operation data such as name, email, phone, IP address, sign-in logs, and change logs.
Trustif does not read or use whistleblower report content for its own purposes; report content is processed technically to operate and maintain the service for the Customer.
3. Instructions and Lawfulness
Trustif processes personal data only on documented Customer instructions and under the agreed data processing terms.
The Customer is responsible for legal basis, transparency notices, and lawful collection of personal data uploaded or managed through the service.
4. Subprocessors
Trustif uses subprocessors with equivalent contractual data-protection obligations.
Render - hosting and runtime infrastructure
Resend - transactional email delivery
Cloudflare Turnstile - anti-spam validation for public forms
Trustif will notify Customers before material subprocessor changes and provide the opportunity to object under contract terms.
5. Data Location and Transfers
Customer personal data is intended to be stored in EU/EEA infrastructure.
Trustif’s default processing path is EU/EEA only. If a transfer outside EU/EEA is ever needed, it must be contractually safeguarded and legally compliant before use.
6. Security Measures
Trustif applies appropriate technical and organizational measures, including access control, transmission encryption, logging, and operational safeguards proportionate to risk.
7. Assistance Duties
Taking account of processing nature and available information, Trustif assists Customers with data-subject requests, security assessments, and compliance evidence.
Reasonable additional work requested beyond standard obligations may be chargeable under contract.
8. Personal Data Breach Handling
Parties notify each other without undue delay about personal-data breaches relevant to Customer data.
Trustif provides available incident details, impact assessment, and mitigation measures, and supports Customer obligations toward supervisory authorities.
9. Audit Rights
Customers may perform processor compliance audits through an independent auditor under reasonable notice, confidentiality, and frequency limits agreed in contract.
10. Return or Deletion
At contract end, Trustif returns or deletes Customer personal data (and copies), unless retention is required by law.
11. Priority and Duration
The processing terms form part of the customer service agreement and apply for the period personal data is processed on behalf of the Customer.
12. Governing Law and Contact
Interpretation, notices, and dispute handling follow the service agreement under Estonian law.
See also the Privacy Policy. Contact: Trustif Solutions OÜ, registry code 17079460, Valukoja tn 8/2, Lasnamäe linnaosa, 11415 Tallinn, Harju maakond, Estonia. Email and phone: info@trustif.ee, +372 5624 6020.

