Skip to content
Trailgun
ITEN Log in

GDPR compliance

How Trailgun protects the personal data firms entrust to it, in line with Regulation (EU) 2016/679.

Last updated: 4 October 2026

  • Data hosted in Europe, on Amazon Web Services in Frankfurt.
  • A data processing agreement (Art. 28) with every firm.
  • Data kept separate for each firm, encrypted at rest and in transit.
  • No model training on customers' documents.
  • Data deleted or returned at the end of the relationship.

1. Clear roles

For case documents the controller is the firm, which decides what data to upload and for what purpose. Trailgun is a processor under Art. 28 GDPR: it processes data only on the firm’s documented instructions and only to provide the requested service. For account data (name, email, role, access logs) Trailgun is the controller, as described in the privacy policy.

2. The data processing agreement

With every firm we sign a data processing agreement covering: subject matter and duration, the firm’s instructions, confidentiality of anyone with access, security measures, authorisation of sub-processors, assistance with data subject rights and impact assessments, breach notification, deletion or return of data, and audits by the firm.

3. Where the data is

The platform, databases and documents reside on Amazon Web Services in the Frankfurt region (Germany). When a provider processes data outside the European Economic Area, as may happen for artificial intelligence models, the transfer relies on an adequacy decision (such as the EU-US Data Privacy Framework) or on the European Commission’s Standard Contractual Clauses.

4. Security of processing

The measures required by Art. 32 are part of the architecture, not an add-on: encrypted disks and storage, always-encrypted connections, invitation-only access with dedicated authentication, data separated by firm and, within a firm, configurable visibility for each client (whole firm, creator only, selected people).

There is no direct access to the servers: administration goes through a managed, logged channel. Service credentials live in an encrypted store, never in the code. Daily backups kept for 14 days; technical logs kept for up to 30 days.

5. Data minimisation and purpose limitation

We process only the documents the firm uploads, only for the job the firm starts. Data is not used to profile people, for marketing, or to train artificial intelligence models, whether ours or our providers’.

6. Sub-processors

We rely on a small number of selected providers (cloud infrastructure, authentication, email and notification delivery, text recognition, artificial intelligence models), bound to the same data protection obligations by contracts compliant with Art. 28(4). The current list is attached to the data processing agreement and firms are informed of changes.

7. Data subject rights

We help the firm answer data subject requests (access, rectification, erasure, restriction, portability, objection). If a request reaches us directly and concerns data controlled by the firm, we forward it to the firm without delay.

8. Personal data breaches

In case of a personal data breach we inform the firm without undue delay, with the information it needs to assess it and, where required, notify the supervisory authority and data subjects under Arts. 33 and 34.

9. Impact assessments

We provide the firm with the technical and organisational documentation it needs for its data protection impact assessment (Art. 35) and any prior consultation.

10. End of the relationship

At the end of the contract, on the firm’s instructions, we delete the data or return it in a usable format, unless the law requires retention. Backups are overwritten on a rolling basis within 14 days.

11. Contact

For any data protection question, to receive the data processing agreement or the list of sub-processors: info@trailgun.ai.