Version 2
Effective date September 10, 2026
This Data Processing Addendum governs Trampoline's processing of Personal Data in Customer Content under the Trampoline Cloud Services Terms or another agreement that incorporates this Addendum, called the Agreement. It is designed to address processor obligations under Canadian, European, United Kingdom, Swiss, and applicable United States privacy laws.
This Addendum is between the Customer identified in the Agreement and Trampoline AI Inc., 5715 rue Marquette, Montreal, Quebec H2G 2X8, Canada. Privacy questions may be sent to privacy@trampoline.ai. Capitalized terms not defined here have the meanings in the Agreement.
1 Scope and Roles
This Addendum applies when Trampoline processes Personal Data contained in Customer Content on Customer's behalf in connection with the Cloud Services. Customer is the controller or business and Trampoline is the processor or service provider. If Customer acts as a processor for another controller, Trampoline acts as Customer's subprocessor and Customer represents that its instructions are authorized by that controller.
Trampoline acts as an independent controller for Account Data, supplier and billing records, business relationship communications, and security data it determines how to process for its own lawful purposes. Those activities are described in Trampoline's Privacy Policy and are outside this Addendum except where applicable law requires otherwise.
Data Protection Laws means laws applicable to the processing under this Addendum, including the General Data Protection Regulation, United Kingdom GDPR and Data Protection Act, Swiss Federal Act on Data Protection, Canada's Personal Information Protection and Electronic Documents Act, Quebec's Act respecting the protection of personal information in the private sector, and applicable United States state privacy laws.
The processing details required by Article 28 of the GDPR and equivalent laws are set out in Schedule 1. The technical and organizational measures are set out in Schedule 2. Transfer provisions and regional supplements are set out in Schedules 3 and 4.
2 Customer Instructions
Trampoline will process Customer Personal Data only on Customer's documented instructions, including the Agreement, Customer's use and configuration of the Cloud Services, support requests, and other written instructions accepted by Trampoline. Trampoline may process Customer Personal Data where required by law, in which case it will inform Customer before processing unless the law prohibits notice.
Trampoline will notify Customer if, in its reasonable opinion, an instruction infringes Data Protection Laws. Trampoline may suspend the affected processing until the parties resolve the issue. Customer is responsible for the lawfulness, accuracy, quality, and origin of Customer Personal Data; providing required notices; identifying a lawful basis; responding to data subjects; and configuring retention, permissions, tools, and integrations appropriately.
Customer will not provide specially protected data unless the applicable Cloud Service and Order expressly support it and the parties have completed any legally required terms. Customer will not use the Cloud Services for protected health information without a signed business associate agreement, or for payment card data outside a supported tokenized payment flow.
3 Confidentiality and Personnel
Trampoline will ensure that personnel authorized to process Customer Personal Data are subject to contractual or statutory confidentiality obligations, receive appropriate privacy and security training, and access Customer Personal Data only on a need-to-know and least-privilege basis. Trampoline remains responsible for its personnel's compliance with this Addendum.
4 Security
Taking into account the state of the art, implementation cost, the nature, scope, context, and purposes of processing, and the risks to individuals, Trampoline will maintain technical and organizational measures designed to provide a level of security appropriate to the risk. Those measures include the controls in Schedule 2 and may evolve so long as the overall level of protection is not materially reduced.
Customer is responsible for security of its endpoints, accounts, identity provider, credentials supplied to the Cloud Services, Customer Code, connected systems, and configuration. Customer will use available security features, restrict privileges, rotate exposed credentials, and promptly notify Trampoline of suspected unauthorized access.
5 Subprocessors
Customer gives Trampoline general written authorization to engage subprocessors needed to provide the Cloud Services. Trampoline will maintain a current Subprocessor Register identifying each subprocessor's function and relevant processing location. Trampoline will enter written terms requiring each subprocessor to protect Customer Personal Data to a standard no less protective than the applicable obligations in this Addendum. Trampoline remains responsible for a subprocessor's performance to the extent required by Data Protection Laws.
Trampoline will give at least 15 days' advance notice before a new subprocessor begins processing Customer Personal Data, except where an urgent change is reasonably necessary for security, availability, or legal compliance. Customer may object during the notice period on reasonable data-protection grounds. The parties will work in good faith to resolve the concern, including through configuration or a commercially reasonable alternative. If no resolution is reasonably available, either party may terminate the affected Cloud Service, and Trampoline will refund prepaid fees for the unused terminated period.
A model provider, connector, or other service selected and contracted directly by Customer, including through Customer-supplied credentials, is not Trampoline's subprocessor to the extent it processes data under Customer's agreement and independent instructions. Trampoline will make the configured transfer, but Customer is responsible for the provider's terms and settings.
6 Data Subject Requests
Taking into account the nature of processing, Trampoline will provide reasonable assistance through available product features and technical measures so Customer can respond to requests to access, correct, delete, restrict, object, or port Customer Personal Data. If Trampoline receives a request relating to Customer Personal Data, it will refer the requester to Customer and will not respond substantively unless Customer instructs it or law requires it.
Customer is responsible for verifying requesters, deciding whether a request is valid, and communicating with data subjects and authorities. Assistance that requires material work beyond standard functionality may be charged at agreed professional services rates where permitted by law.
7 Personal Data Breaches
Trampoline will notify Customer without undue delay and no later than 48 hours after confirming a Personal Data Breach affecting Customer Personal Data. A Personal Data Breach means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data under Trampoline's control.
To the extent information is available, notice will describe the nature of the breach, affected data and individuals, likely consequences, mitigation taken or proposed, and a contact for follow-up. Trampoline may provide information in phases, will take reasonable steps to contain and remediate the breach, and will reasonably assist Customer with legally required notifications and investigations. Notice is not an admission of fault or liability.
Customer is responsible for notifying authorities, individuals, and third parties unless law assigns that duty to Trampoline. Trampoline is not required to report unsuccessful attempts or events that do not compromise the security of Customer Personal Data.
8 Compliance Assistance
Taking into account the nature of processing and information available to Trampoline, Trampoline will reasonably assist Customer with security obligations, breach assessments, data protection impact assessments, transfer assessments, and prior consultation with authorities. Customer will provide the information needed to scope the request. Material assistance beyond standard documentation and product functionality may be charged where permitted by law.
9 Audits and Information
Trampoline will make available information reasonably necessary to demonstrate compliance, which may include security summaries, certifications, independent audit reports, penetration-test summaries, and completed questionnaires, subject to confidentiality and security restrictions.
If that information is insufficient, Customer may conduct one audit per 12-month period on at least 30 days' notice, during normal business hours, and in a manner that minimizes disruption and protects other customers. Additional audits may be conducted following a confirmed Personal Data Breach, a material compliance concern, or a regulator's request. The auditor must be independent, qualified, not a Trampoline competitor, and bound by confidentiality. Customer bears its audit costs unless the audit identifies material noncompliance by Trampoline.
10 Return and Deletion
During the Agreement term, Customer may retrieve or delete Customer Personal Data using available features. On Customer's written request or within 30 days after termination or expiration of the affected Cloud Service, Trampoline will return or delete Customer Personal Data, at Customer's choice, unless law requires retention. Customer must request return before the deletion period expires.
Customer Personal Data in encrypted backups will be isolated from ordinary use and deleted or overwritten in the normal backup cycle. Until deletion, retained data remains protected by the Agreement and will be processed only for recovery, security, or legal compliance. Trampoline may retain de-identified information that no longer identifies Customer or an individual and cannot reasonably be reidentified.
11 Government and Legal Requests
Unless prohibited by law, Trampoline will notify Customer of a legally binding demand for Customer Personal Data before disclosure and will refer the requester to Customer where reasonable. Trampoline will review the validity and scope of the demand, challenge unlawful or overbroad demands where there are reasonable grounds, and disclose only data it is legally required to provide.
12 International Transfers
Trampoline will not transfer Customer Personal Data across borders except as needed to provide the Cloud Services, as configured by Customer, or as otherwise instructed. Trampoline will use a lawful transfer mechanism where required and will conduct or support assessments required by Data Protection Laws. Customer acknowledges that remote access from another country can constitute a transfer.
Where the European Commission Standard Contractual Clauses are required, they are incorporated as described in Schedule 3. Where United Kingdom restricted transfers are involved, the United Kingdom International Data Transfer Addendum applies. For Swiss transfers, references in the Standard Contractual Clauses will be interpreted to include the Swiss Federal Act on Data Protection and the competent Swiss authority.
13 General
If this Addendum conflicts with the Agreement on processing of Customer Personal Data, this Addendum controls. The liability limitations and governing law in the Agreement apply except where the Standard Contractual Clauses or mandatory law require otherwise. This Addendum continues for as long as Trampoline processes Customer Personal Data.
Trampoline may update this Addendum to reflect changes in law or the Cloud Services. Material adverse changes will follow the change provisions in the Agreement. No change will reduce protections required by Data Protection Laws.
Schedule 1 Processing Details
Subject matter. Hosting, retrieving, transforming, analyzing, transmitting, and otherwise processing Customer Personal Data through the Cloud Services and Customer-configured Workflows.
Duration. The term of the affected Cloud Services plus the return, deletion, backup, and legal-retention periods described in this Addendum.
Nature and purpose. Collection from Customer-authorized sources; storage; organization; extraction; structuring; retrieval; consultation; model inference; generation; classification; reconciliation; validation; monitoring; transmission to Customer-authorized destinations; support; security; and deletion, solely to provide and protect the Cloud Services and follow Customer's instructions.
Frequency. Continuous, scheduled, event-driven, or on-demand, as determined by Customer's use and configuration.
Categories of data subjects. Authorized Users; Customer personnel, applicants, contractors, clients, prospects, suppliers, advisers, and counterparties; and other individuals whose information Customer lawfully includes in documents, data sources, systems, or Workflows.
Categories of Personal Data. Business identity and contact information; account and authentication metadata; employment and professional information; correspondence; commercial and transaction information; document and file content; system identifiers; device, network, audit, and usage data; and other Personal Data selected by Customer.
Sensitive data. None is required for ordinary use. Special-category, highly sensitive, regulated, or criminal-offence data may be processed only when Customer is authorized to provide it and the applicable service, Order, and required supplemental agreement expressly support it.
Customer instructions. The Agreement, Orders, Customer's configuration and use of the Cloud Services, and written instructions accepted by Trampoline.
Retention. Customer-configured retention during the term; deletion or return on request or within 30 days after the affected service ends; and later deletion from isolated backups through the normal backup cycle, unless law requires retention.
Schedule 2 Technical and Organizational Measures
Control area | Measures |
Governance and risk | Documented security and privacy responsibilities; periodic risk review; policies covering access, incidents, vendors, retention, and secure development; confidentiality obligations and workforce training. |
Identity and access | Role-based access controls; least privilege; controlled provisioning and revocation; multi-factor authentication for privileged and administrative access; periodic review of elevated permissions. |
Encryption and secrets | Encryption in transit using current transport security and encryption at rest using industry-standard cloud controls; managed handling of service credentials and secrets; rotation or revocation when compromise is suspected. |
Tenant isolation | Logical segregation using tenant identifiers, scoped authorization, and service-layer controls designed to prevent one customer from accessing another customer's data. |
Infrastructure security | Use of established cloud providers; hardened configuration; restricted production access; network and service controls; patching and vulnerability management proportionate to risk. |
Secure development | Code review; dependency and vulnerability checks; change control; separation of production from development and test; testing before deployment; no routine use of live Customer Personal Data in non-production environments. |
Logging and monitoring | Logging of relevant authentication, administrative, security, error, and execution events; centralized monitoring and alerting; access to logs restricted according to role; retention based on security, legal, and minimization needs. |
Incident response | Documented detection, triage, containment, investigation, communication, recovery, and post-incident review processes; designated response roles; periodic exercises and lessons-learned updates. |
Availability and recovery | Managed backups where appropriate; recovery procedures; redundancy and capacity controls proportionate to the service; periodic testing of material recovery processes. |
Data lifecycle | Customer-configurable retention where available; deletion tools; scheduled cleanup of temporary data; deletion or isolation after termination; documented handling of backups and legal holds. |
Vendor management | Risk-based diligence before engaging subprocessors; written data-protection terms; security and privacy review; transfer safeguards where required; periodic reassessment. |
Testing and evaluation | Periodic vulnerability assessment and security testing based on risk; remediation tracking; review of material safeguards; controlled testing of agentic Workflows before production. |
Schedule 3 European Transfers
The standard contractual clauses issued under European Commission Implementing Decision (EU) 2021/914, called the SCCs, are incorporated when a transfer of Customer Personal Data is not otherwise protected by an adequacy decision or another valid mechanism.
- Module Two applies where Customer is a controller and Trampoline is a processor.
- Module Three applies where Customer is a processor and Trampoline is a subprocessor.
- Clause 7 docking applies. Clause 9 uses Option 2 general written authorization with the 15-day notice period in this Addendum.
- In Clause 11, the optional independent dispute-resolution language does not apply.
- For Clauses 17 and 18, Irish law and the courts of Ireland apply unless the exporter is established in an EEA member state and the parties select that member state's law and courts in an Order.
- Annex I is completed by the parties and contact details in the Agreement, the roles in this Addendum, the processing details in Schedule 1, and the subprocessor information in the Subprocessor Register. The competent supervisory authority is determined under Clause 13.
- Annex II is completed by Schedule 2. Annex III is completed by the Subprocessor Register.
For United Kingdom restricted transfers, the then-current mandatory United Kingdom International Data Transfer Addendum issued by the Information Commissioner's Office is incorporated, with the information in this Addendum completing its tables. Neither party may vary the SCCs or United Kingdom Addendum in a manner that conflicts with their mandatory text.
The parties will reasonably cooperate on transfer impact assessments and supplementary measures. If a transfer mechanism becomes invalid, they will work promptly to implement a valid replacement. If none is reasonably available, Trampoline may suspend the affected transfer and Customer may terminate the affected Cloud Service.
Schedule 4 United States Privacy Terms
To the extent a United States state privacy law applies and Trampoline acts as a processor, contractor, or service provider, Trampoline will process Personal Data only for the limited and specified purposes in the Agreement; will not sell or share it for cross-context behavioral advertising; will not retain, use, or disclose it outside the direct business relationship or permitted business purposes; and will not combine it with personal information received from another person except as permitted by law.
Trampoline will provide the same level of privacy protection required of a service provider or processor, notify Customer if it can no longer meet an applicable obligation, permit Customer to take reasonable steps to stop and remediate unauthorized use, flow applicable restrictions to subprocessors, and provide reasonable assistance with consumer requests and required assessments.
Schedule 5 Canada Privacy Terms
Where Canadian privacy law applies, Trampoline will protect Customer Personal Data using contractual, administrative, technical, and physical safeguards appropriate to its sensitivity; limit processing to the purposes and instructions in the Agreement; ensure personnel and subprocessors remain subject to confidentiality; and notify Customer if Trampoline can no longer meet an applicable obligation.
For processing subject to Quebec privacy law, Trampoline will use Customer Personal Data only to perform the Agreement, refrain from keeping it after the processing purpose and applicable retention period end, promptly notify Customer of an unauthorized access, use, or disclosure, and allow Customer to verify compliance through the information and audit rights in this Addendum. Trampoline will provide information reasonably needed for Customer's privacy impact assessment of processing outside Quebec.
Trampoline will reasonably assist Customer with access and correction requests, breach assessment and recordkeeping, and return or deletion. Customer remains responsible for establishing authority and consent or another lawful basis, providing required notices, and deciding whether its collection, use, disclosure, and cross-border processing comply with Canadian law.