Legal
Data processing terms
Last updated 31 July 2026
Draft, pending legal review. This page describes our intended practice in plain language so you can evaluate the service. It is not the executed agreement. For a signable DPA or the current terms, write to security@triguna.ai.
Roles
For records retrieved through the API, you are the controller and we are the processor. You decide which identifiers to send and why. We assemble and return a record on that instruction, and we do not use retrieved records for our own purposes.
For your account, billing, and request logs, we are the controller. That is covered by the privacy notice.
Scope of processing
| Item | Detail |
|---|---|
| Subject matter | Assembly and return of person and company records. |
| Duration | For the term of your agreement, plus the retention period below. |
| Categories of data | Professional identity, employment history, education, publicly stated skills, and, where you request it, contact details. Company firmographics. |
| Data subjects | People and organizations whose identifiers you send. |
Your instructions
Your instruction is the request you make. We process only what is needed to fulfil it, and we will tell you if an instruction appears to conflict with applicable data protection law rather than carrying it out silently.
Sub-processors
We use sub-processors for hosting, error monitoring, payments, and email. A current list is available on request. We give advance notice before adding one, and you may object on reasonable grounds.
Security measures
- TLS for all API traffic; no unencrypted transport.
- API keys scoped per project and per environment, revocable with immediate effect.
- Per-key credit ceilings, so a compromised key has a bounded blast radius.
- Access to production data limited to staff who need it, with access logged.
- Provenance recorded on every assembled record, making retrieval auditable.
Assistance
We will help you respond to data subject requests, complete security assessments, and investigate incidents. If we become aware of a personal data breach affecting your data, we will notify you without undue delay and with what we know at the time rather than waiting for a complete picture.
Deletion and return
On termination, we delete assembled records associated with your account within 30 days, except where retention is required by law. Request logs are deleted on the schedule in the privacy notice. Records you have already stored in your own systems are yours to manage, and we cannot delete those for you.
International transfers
Where data is transferred outside its region of origin, we rely on the appropriate safeguards for that transfer and will identify them in the executed agreement.
Executing a DPA
For a signable data processing agreement, write to security@triguna.ai.