Legal
Data Processing Agreement
Our processing of personal data on your behalf under Article 28 of the GDPR. It applies automatically when you accept our Terms of Service; nothing needs to be requested or signed for you to be covered by it.
Last updated 30 August 2026
How this document is built
Rather than bespoke wording, the operative clauses are the European Commission’s Standard Contractual Clauses for controller-to-processor processing (Decision 2021/915), incorporated by reference and unmodified. Transfers outside the EEA rely on Decision 2021/914, Module Two.
Those texts are adopted by the Commission and presumed adequate, so the operative wording is the Commission’s rather than our paraphrase of it. What follows is the information the Clauses require us to specify: who processes what, why, for how long, and with which safeguards. If your legal team prefers to paper this on your own template instead, tell us and we will sign a reasonable one.
1.Roles
You are the controller. You decide what documents to upload and which questionnaires to answer. FillTrust is the processor, acting only on your instructions. Using the service is the instruction; anything beyond it requires your agreement in writing.
2.Subject matter and duration
We process your data to extract questions from security questionnaires, generate answers from the documents you provide, and store both so you can review, reuse and export them. Processing lasts as long as your account exists. When you delete your account we delete the data, as described under deletion and return.
3.Categories of data subject and personal data
FillTrust is designed around corporate documentation, not personal data. In normal use the personal data we process is limited to:
- Your users: name, email address, hashed password, and, if enabled, an encrypted two-factor secret.
- Colleagues you involve: the email address of anyone you ask to answer a question, and the answer they write.
- Incidental content: any personal data that happens to appear inside a document you upload, such as a named security officer in a policy.
We do not ask for special-category data under Article 9, and the service is not intended for it. Please do not upload it.
4.Sub-processors
You give general authorisation for the sub-processors below. We will publish any addition on this page and at /legal/subprocessors at least 30 days before it starts processing, so you can object.
| Sub-processor | Purpose | Location |
|---|---|---|
| Google Cloud Platform | Application hosting and document storage | europe-west9 (Paris) |
| Neon | Managed PostgreSQL database | AWS eu-central-1 (Frankfurt) |
| Google (Gemini API) | Generating questionnaire answers | United States |
| Anthropic | Fallback answer generation (configurable, not currently in use) | United States |
| OpenAI | Text embeddings for retrieval | United States |
| Stripe | Payment processing | United States |
| Resend | Transactional email | United States |
| Google Analytics | Counting visits to public pages, for visitors who consent | United States (EU-US Data Privacy Framework) |
| Cloudflare | DNS, CDN and DDoS protection | Global edge network |
5.International transfers
Your documents are stored in the EU: object storage in Paris, database in Frankfurt. To answer a question we send the question text and the specific passages retrieved from your documents to Google and OpenAI in the United States. We do not send whole documents.
Those transfers rely on the Commission’s Standard Contractual Clauses (Decision 2021/914, Module Two). Each provider states that data submitted through their paid APIs is not used to train their models.
Anthropic remains listed as a subprocessor and may receive the same question text and passages if we switch the answering model back. It is not in use today. We would rather name a recipient that is currently idle than have you discover one that was not listed.
If EU-only processing is a hard requirement for you, tell us before uploading anything. Today we cannot offer it.
6.Security
The technical and organisational measures we apply under Article 32:
Encryption in transit
TLS on every connection, including between our own services.
Encryption at rest
Google Cloud default encryption for object storage and database. TOTP secrets additionally encrypted with AES-256-GCM at the application layer.
Tenant isolation
Every request derives its tenant from the authenticated session server-side. No endpoint accepts a customer identifier from the browser; a request for another tenant's record returns 404.
Access control
Password authentication with optional TOTP two-factor. Authentication endpoints rate limited. The processing backend is not reachable from the public internet.
Least privilege
Service accounts hold only the specific secret and storage permissions they use.
Logging and audit
Every change to an answer is recorded append-only with actor and timestamp. Application errors raise alerts.
Resilience
Object storage is versioned; the managed database provides point-in-time recovery.
Deletion
Account deletion removes all stored documents and generated questionnaires, and aborts rather than partially applying if any part cannot be completed.
Everyone with access to production is bound by confidentiality. We will notify you without undue delay, and in any event within 48 hours, of any breach affecting your data, with what we know and what we are doing about it.
We are not currently SOC 2 or ISO 27001 certified and do not claim to be. See our security overview.
7.Deletion and return
You can export your data at any time from the product. Deleting your account removes every uploaded document, generated questionnaire and stored answer, and cancels billing. If any part of that cannot be completed the deletion is aborted and reported to you rather than partially applied.
Backups roll off within 30 days. We keep no copy after that except where law requires it.
8.Assistance and audit
We will help you respond to data subject requests and to your obligations under Articles 32 to 36, taking into account the nature of the processing and the information available to us. We will make available the information needed to demonstrate compliance with Article 28, and will accept a reasonable audit, in practice, answering a security questionnaire, which we are unusually well placed to do.
Signature and countersignature. This agreement takes effect without a signature. If your procurement process requires a countersigned copy, or you need it executed on your own paper, write to legal@filltrust.com and we will return one.
See also our Terms of Service, Privacy Policy, sub-processor list and security overview.