Trivo

Data Processing Agreement

Last updated: 2026-09-28

This Data Processing Agreement ("DPA") forms part of the agreement between you (the "Customer") and Haven Media Development AB, 556823-7753, Parkallén 5, 183 41 Täby, Sweden ("Trivo", "we", "us") for use of the Trivo service (the "Service"). It applies whenever we process personal data on the Customer's behalf and reflects our obligations under Article 28 of the General Data Protection Regulation (GDPR) and applicable Swedish data protection law.

For the personal data of the Customer's team members processed through the Service, the Customer is the controller and Trivo is the processor. Where we act as controller for our own account and billing data, our Privacy Policy applies instead. In the event of a conflict, this DPA prevails over the general Terms & Conditions on data-protection matters.

1. Definitions

Terms used but not defined here have the meaning given to them in the GDPR.

  • Controller, processor, sub-processor, data subject, personal data, processing and personal data breach have the meanings set out in the GDPR.
  • Customer Personal Data means the personal data we process on the Customer's behalf under the agreement, as described in Section 2.
  • Data Protection Laws means the GDPR and all applicable national laws implementing or supplementing it, including Swedish data protection law.
  • Standard Contractual Clauses (SCCs) means the clauses adopted by the European Commission for transfers of personal data to third countries.

2. Scope & Details of Processing

We process Customer Personal Data only to provide the Service. The details required by Article 28(3) GDPR are:

Subject matter & nature

Hosting, storage, and processing of team pulse check-ins, comments, and the generation of AI-assisted insight reports for team managers.

Purpose

To deliver the Service to the Customer in accordance with the agreement and the Customer's documented instructions.

Duration

For the term of the Customer's subscription, followed by deletion in accordance with Section 9.

Categories of data subjects

The Customer's team members and other authorised users of the Customer's account.

Categories of personal data

Name, work email address, hashed password; team check-in ratings (morale, quality, flow) and free-text comments; and technical data such as IP address and session identifiers. We do not require and ask the Customer not to submit special categories of personal data.

3. The Customer's Obligations

  • The Customer determines the purposes and means of processing Customer Personal Data and must comply with Data Protection Laws in its role as controller.
  • The Customer must ensure it has a valid legal basis and has provided any required notices to, or obtained any required consents from, its team members before their data is submitted to the Service.
  • The Customer's instructions to us must be lawful. The Customer is responsible for the accuracy and lawfulness of the data it submits.

4. Our Obligations as Processor

We will:

  • Process Customer Personal Data only on the Customer's documented instructions, including the agreement and use of the Service, unless required to do otherwise by law (in which case we will inform the Customer unless the law prohibits it).
  • Not sell Customer Personal Data or use it for our own purposes. We use only aggregated, anonymised data to operate and improve the Service.
  • Ensure that persons authorised to process Customer Personal Data are bound by confidentiality.
  • Implement the technical and organisational measures described in Section 6.
  • Assist the Customer as described in Section 8, and make available the information necessary to demonstrate compliance with Article 28 GDPR.

5. Confidentiality & Personnel

Access to Customer Personal Data is limited to personnel who need it to provide, support, or maintain the Service. All such personnel are bound by written confidentiality obligations and receive appropriate guidance on their data-protection responsibilities.

6. Security Measures

Taking into account the state of the art and the risks of processing, we apply appropriate technical and organisational measures, including:

  • Encryption of data in transit (TLS).
  • Hashed password storage.
  • Role- and team-scoped access controls, so users only see data for teams they belong to.
  • Application-level error monitoring and logging.
  • Data minimisation before AI sub-processing: emails and personal names are automatically redacted from free-text comments and chat messages before they are sent to our AI sub-processor, so that identifying details are removed as far as reasonably possible.
  • Presentation of comments to team leaders without the author's name shown alongside the response.

We regularly review and, where appropriate, improve these measures. This section describes the measures in place at the date above and may be updated as the Service evolves.

7. Sub-processors

The Customer authorises us to engage the sub-processors listed below to process Customer Personal Data. Each is bound by data-protection obligations no less protective than those in this DPA.

Sub-processor Purpose Location
Supabase Database hosting & storage of check-in and account data EU (Stockholm, Sweden)
Loopia Application hosting, infrastructure & transactional email Sweden
Anthropic (can be subject to change) AI-generated team insights (from redacted comment text) USA (DPF / SCCs)
Sentry Error monitoring USA (DPF / SCCs)

Our AI sub-processor is contractually prohibited from using Customer Personal Data to train its foundational models.

Stripe (payment processing) and Google Analytics (website analytics) process data for which we act as controller; they are described in our Privacy Policy rather than as sub-processors under this DPA.

We will give the Customer at least 30 days' notice before adding or replacing a sub-processor. If the Customer has a reasonable, data-protection-based objection, it may raise it within that period and we will work in good faith to resolve it; if we cannot, the Customer may terminate the affected part of the Service.

8. Assistance to the Customer

Taking into account the nature of the processing, we will provide reasonable assistance to help the Customer:

  • Respond to requests from data subjects exercising their rights (access, rectification, erasure, restriction, portability, and objection), including through functionality available in the Service.
  • Meet its obligations regarding security, breach notification, data protection impact assessments, and prior consultation with a supervisory authority.

Where the assistance requested goes materially beyond the functionality of the Service, we may charge a reasonable fee, notified in advance.

9. Return & Deletion of Data

On termination of the Service, we will delete Customer Personal Data within 90 days, and on request will return it in a structured, machine-readable format before deletion, unless Data Protection Laws require continued retention. Billing records are retained for 7 years to comply with Swedish accounting law (Bokföringslagen), as set out in our Privacy Policy.

10. Personal Data Breaches

We will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and provide the information reasonably available to help the Customer meet its own notification obligations, together with the measures we have taken or propose to take.

11. Audits

On reasonable prior written notice (normally at least 30 days) and no more than once per year, except where required by a supervisory authority, we will make available the information necessary to demonstrate compliance with this DPA and allow for and contribute to audits, including inspections, conducted by the Customer or an independent auditor it mandates. Audits are conducted during business hours, must not unreasonably disrupt our operations, and are subject to confidentiality.

12. International Transfers

Where a sub-processor processes Customer Personal Data outside the EEA (currently our AI and error-monitoring sub-processors in the USA), the transfer is safeguarded under the EU–US Data Privacy Framework (DPF) where the relevant sub-processor is certified under it; otherwise it is governed by Standard Contractual Clauses adopted by the European Commission, together with appropriate supplementary measures where required.

13. Liability

Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the agreement. Liability towards data subjects and supervisory authorities is governed by Articles 82 and 83 GDPR.

14. Term

This DPA takes effect when the Customer accepts the agreement or first uses the Service and remains in force for as long as we process Customer Personal Data. Provisions that by their nature should survive termination (including confidentiality, deletion, and liability) continue to apply.

15. Governing Law

This DPA is governed by Swedish law and by the GDPR. The Customer may lodge a complaint with the Swedish supervisory authority, Integritetsskyddsmyndigheten (IMY), at www.imy.se.

16. Contact

For any questions about this DPA or to exercise data-protection rights, please contact:

Haven Media Development AB

Parkallén 5

183 41 Täby

Sweden

Email: privacy@trivolab.com