Privacy policy
How we handle the personal data of people who visit the site, write to us and use Trailgun.
Last updated: 4 October 2026
1. In short
We collect the bare minimum. The site uses no cookies, does not track visitors and loads no third-party resources. The documents that firms upload to the platform remain theirs: we process them only to provide the service, on their instructions, in European data centres.
2. Who is the controller
The data controller is [Ragione sociale], registered office [Sede legale], VAT no. [Partita IVA] ("Trailgun", "we"). For any privacy question, write to info@trailgun.ai.
3. What data we process and why
Visiting the site. The server logs technical data for each request (IP address, date and time, page requested, browser type). We need it to run the site, protect it from abuse and fix faults. Legal basis: our legitimate interest in the security of the service (Art. 6(1)(f) GDPR).
Contact. If you write to us, we process your name, your address and what you tell us, to reply and, if you ask, to arrange a presentation. Legal basis: pre-contractual steps at your request and our legitimate interest in replying (Art. 6(1)(b) and (f)).
Platform accounts. For users invited by a firm we process name, email address, firm, role, access logs and usage data (for example the jobs started and their costs). We need it to provide, secure and bill the service. Legal basis: performance of the contract with the firm and our legitimate interest in security (Art. 6(1)(b) and (f)).
Service messages. We send emails and notifications related to the service (invitations, sign-in codes, job alerts). We do not send newsletters or promotional messages without specific consent.
4. Case documents
Case files, filings and documents that firms upload to Trailgun may contain personal data of third parties (clients, counterparties, debtors). For this data the firm is the controller; Trailgun acts as a processor under Art. 28 GDPR, on the basis of a data processing agreement, and processes it only to provide the requested service.
We use artificial intelligence models through professional services that, by contract, do not use customer data to train their models. We do not use firms' documents to train models of our own.
5. Where the data is and who sees it
The platform and its data reside on Amazon Web Services in the Frankfurt region (Germany). Data is kept separate for each firm and encrypted at rest and in transit.
We rely on selected providers, appointed as processors or sub-processors: cloud infrastructure, authentication, email and notification delivery, text recognition and artificial intelligence models. Some of them may process data outside the European Economic Area; in that case the transfer relies on an adequacy decision (such as the EU-US Data Privacy Framework) or on the European Commission’s Standard Contractual Clauses. The current list is available on request and attached to the data processing agreement.
We do not sell personal data and do not share it with third parties for marketing.
6. How long we keep it
Server logs: up to 30 days. Contact emails: as long as needed to handle the request and, if a relationship follows, for its duration. Platform accounts and data: for the duration of the contract with the firm; at the end we delete or return them as the firm instructs, unless the law (for example tax rules) requires longer retention. Backups are overwritten on a rolling basis within 14 days.
7. Cookies
The site uses no cookies and no analytics or profiling tools. The app only uses technical tools that are strictly necessary to sign in (the authentication session stored in the browser), which do not require consent.
8. Your rights
You can ask at any time to access, rectify or erase your data, to restrict processing, for data portability, and object to processing based on legitimate interest (Arts. 15-22 GDPR). Write to info@trailgun.ai: we reply within one month. If your data is in documents uploaded by a firm, we will forward the request to the firm, which is the controller.
You also have the right to lodge a complaint with the Italian Data Protection Authority (garanteprivacy.it) or with the authority of the country where you live or work.
9. Security
We protect data with appropriate technical and organisational measures: encryption, invitation-only access with dedicated authentication, per-firm data separation, least privilege for staff, daily backups and access logs.
10. Changes
If we change this policy we update the date at the top of the page; if the changes are material, we tell platform users before they take effect.