Last updated: 2026-09-28
This Data Processing Agreement ("DPA") forms part of the agreement between you (the "Customer") and Haven Media Development AB, 556823-7753, Parkallén 5, 183 41 Täby, Sweden ("Trivo", "we", "us") for use of the Trivo service (the "Service"). It applies whenever we process personal data on the Customer's behalf and reflects our obligations under Article 28 of the General Data Protection Regulation (GDPR) and applicable Swedish data protection law.
For the personal data of the Customer's team members processed through the Service, the Customer is the controller and Trivo is the processor. Where we act as controller for our own account and billing data, our Privacy Policy applies instead. In the event of a conflict, this DPA prevails over the general Terms & Conditions on data-protection matters.
Terms used but not defined here have the meaning given to them in the GDPR.
We process Customer Personal Data only to provide the Service. The details required by Article 28(3) GDPR are:
Subject matter & nature
Hosting, storage, and processing of team pulse check-ins, comments, and the generation of AI-assisted insight reports for team managers.
Purpose
To deliver the Service to the Customer in accordance with the agreement and the Customer's documented instructions.
Duration
For the term of the Customer's subscription, followed by deletion in accordance with Section 9.
Categories of data subjects
The Customer's team members and other authorised users of the Customer's account.
Categories of personal data
Name, work email address, hashed password; team check-in ratings (morale, quality, flow) and free-text comments; and technical data such as IP address and session identifiers. We do not require and ask the Customer not to submit special categories of personal data.
We will:
Access to Customer Personal Data is limited to personnel who need it to provide, support, or maintain the Service. All such personnel are bound by written confidentiality obligations and receive appropriate guidance on their data-protection responsibilities.
Taking into account the state of the art and the risks of processing, we apply appropriate technical and organisational measures, including:
We regularly review and, where appropriate, improve these measures. This section describes the measures in place at the date above and may be updated as the Service evolves.
The Customer authorises us to engage the sub-processors listed below to process Customer Personal Data. Each is bound by data-protection obligations no less protective than those in this DPA.
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase | Database hosting & storage of check-in and account data | EU (Stockholm, Sweden) |
| Loopia | Application hosting, infrastructure & transactional email | Sweden |
| Anthropic (can be subject to change) | AI-generated team insights (from redacted comment text) | USA (DPF / SCCs) |
| Sentry | Error monitoring | USA (DPF / SCCs) |
Our AI sub-processor is contractually prohibited from using Customer Personal Data to train its foundational models.
Stripe (payment processing) and Google Analytics (website analytics) process data for which we act as controller; they are described in our Privacy Policy rather than as sub-processors under this DPA.
We will give the Customer at least 30 days' notice before adding or replacing a sub-processor. If the Customer has a reasonable, data-protection-based objection, it may raise it within that period and we will work in good faith to resolve it; if we cannot, the Customer may terminate the affected part of the Service.
Taking into account the nature of the processing, we will provide reasonable assistance to help the Customer:
Where the assistance requested goes materially beyond the functionality of the Service, we may charge a reasonable fee, notified in advance.
On termination of the Service, we will delete Customer Personal Data within 90 days, and on request will return it in a structured, machine-readable format before deletion, unless Data Protection Laws require continued retention. Billing records are retained for 7 years to comply with Swedish accounting law (Bokföringslagen), as set out in our Privacy Policy.
We will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and provide the information reasonably available to help the Customer meet its own notification obligations, together with the measures we have taken or propose to take.
On reasonable prior written notice (normally at least 30 days) and no more than once per year, except where required by a supervisory authority, we will make available the information necessary to demonstrate compliance with this DPA and allow for and contribute to audits, including inspections, conducted by the Customer or an independent auditor it mandates. Audits are conducted during business hours, must not unreasonably disrupt our operations, and are subject to confidentiality.
Where a sub-processor processes Customer Personal Data outside the EEA (currently our AI and error-monitoring sub-processors in the USA), the transfer is safeguarded under the EU–US Data Privacy Framework (DPF) where the relevant sub-processor is certified under it; otherwise it is governed by Standard Contractual Clauses adopted by the European Commission, together with appropriate supplementary measures where required.
Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the agreement. Liability towards data subjects and supervisory authorities is governed by Articles 82 and 83 GDPR.
This DPA takes effect when the Customer accepts the agreement or first uses the Service and remains in force for as long as we process Customer Personal Data. Provisions that by their nature should survive termination (including confidentiality, deletion, and liability) continue to apply.
This DPA is governed by Swedish law and by the GDPR. The Customer may lodge a complaint with the Swedish supervisory authority, Integritetsskyddsmyndigheten (IMY), at www.imy.se.
For any questions about this DPA or to exercise data-protection rights, please contact: