This Data Processing Agreement (“DPA”) forms part of, and is incorporated by reference into, the Terms of Service between Overcode, a company incorporated under the laws of the Republic of Serbia, with its registered office at Jovana Cvijića 10, 21101 Novi Sad, Serbia, company registration number 67879724 (“Trailogs”, “we”, “us”, or “our”), and the User or organization entering into the Terms of Service (“Customer”).
This DPA applies where Customer Data submitted to the Service includes Personal Data for which Customer acts as controller (or processor on behalf of a third-party controller) and Trailogs acts as processor, as those terms are defined below.
This DPA should be read together with our Privacy Policy, which describes in more detail the Personal Data Trailogs processes for its own purposes as a controller. Capitalized terms not defined in this DPA have the meaning given to them in the Terms of Service.
1. Definitions
“Applicable Data Protection Law” means all laws and regulations applicable to the processing of Personal Data under this DPA, including, where applicable, the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and the Law on Personal Data Protection of the Republic of Serbia.
“Controller”, “Processor”, “Data Subject”, “Personal Data”, “Processing”, “Personal Data Breach”, and “Sub-processor” have the meanings given in Applicable Data Protection Law.
“Customer Data” has the meaning given in the Terms of Service.
“Security Incident” means a confirmed Personal Data Breach affecting Customer Data processed under this DPA.
“Services” means the Trailogs Service as defined in the Terms of Service.
2. Roles of the Parties
-
As between Trailogs and Customer, Customer is the Controller (or, where Customer processes Personal Data on behalf of a third party, a Processor) of Personal Data contained in Customer Data, and Trailogs is a Processor acting on Customer’s behalf.
-
Trailogs will process Personal Data contained in Customer Data only:
- to provide, secure, and maintain the Service;
- on Customer’s documented instructions, including those given through Customer’s configuration and use of the Service and as set out in this DPA and the Terms of Service;
- as required by Applicable Data Protection Law, in which case Trailogs will, where legally permitted, inform Customer of that legal requirement before processing.
-
Trailogs will promptly notify Customer if, in its opinion, an instruction from Customer infringes Applicable Data Protection Law.
3. Customer’s Responsibilities
-
Customer is responsible for the accuracy, quality, and lawfulness of Customer Data and the means by which it was obtained.
-
Customer represents that it has, and will maintain, all necessary rights, notices, and lawful bases required under Applicable Data Protection Law to submit Personal Data to the Service and to give Trailogs the instructions described in this DPA.
-
Customer is responsible for determining whether the Service, including any Demo Workspace, provides a level of protection appropriate to the Personal Data Customer intends to submit. As described in the Terms of Service, Demo Workspaces are not intended for confidential, highly sensitive, regulated, or production Personal Data.
-
Customer will not submit special categories of Personal Data (as defined under Applicable Data Protection Law) to the Service unless Trailogs has agreed in writing to process that category of data.
4. Personnel
Trailogs will ensure that personnel authorized to process Personal Data under this DPA:
- are subject to a binding duty of confidentiality;
- receive appropriate training on their data-protection responsibilities;
- process Personal Data only to the extent necessary for their role.
5. Security Measures
-
Trailogs will implement and maintain appropriate technical and organizational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing.
-
A description of the measures currently applied by Trailogs is set out in Annex 2 to this DPA. Trailogs may update these measures from time to time, provided that any update does not materially decrease the overall level of protection.
6. Sub-processors
-
Customer authorizes Trailogs to engage the categories of Sub-processors described in Annex 3 to assist in providing the Service.
-
Trailogs will impose data-protection terms on each Sub-processor that are substantially no less protective of Personal Data than those set out in this DPA, and will remain liable for each Sub-processor’s performance of its obligations.
-
Trailogs will make available to Customer, on request, current information about the identity and location of its Sub-processors.
-
If Trailogs adds or replaces a Sub-processor in a way that increases the risk to Customer’s Personal Data, Trailogs will use reasonable efforts to give Customer notice. If Customer reasonably objects to such a change on data-protection grounds, the parties will work in good faith to find a resolution; if no resolution is reached, Customer’s sole remedy is to stop using the affected part of the Service.
7. International Transfers
-
Trailogs’ primary hosting infrastructure is located in the European Union (Germany). Trailogs is established in Serbia, and Trailogs personnel may access and process Personal Data from Serbia in the course of providing and supporting the Service. Trailogs and its Sub-processors may also process Personal Data in the United States or other countries in which Trailogs or its Sub-processors operate, as further described in Annex 3 and in our Privacy Policy.
-
Where Customer is located in the European Economic Area, the United Kingdom, or Switzerland (or otherwise transfers Personal Data subject to Applicable Data Protection Law restricting transfers outside that territory), Customer (as data exporter) and Trailogs (as data importer) hereby enter into the Standard Contractual Clauses annexed to European Commission Implementing Decision (EU) 2021/914 of 4 June 2021 (“EU SCCs”), Module Two (Controller to Processor), which are incorporated into this DPA by this reference and prevail over any conflicting provision of this DPA to the extent required to satisfy Applicable Data Protection Law. For this purpose:
- Annex I.A and I.B of the EU SCCs are populated with the parties’ identities and the details set out in Annex 1 to this DPA;
- Annex I.C of the EU SCCs designates the supervisory authority of the EU member state in which Customer is established (or, if Customer is not established in an EU member state, the supervisory authority of Ireland) as the competent supervisory authority;
- Annex II of the EU SCCs is populated with the technical and organizational measures set out in Annex 2 to this DPA;
- Annex III of the EU SCCs (authorized Sub-processors) is populated with the Sub-processors listed in Annex 3 to this DPA;
- Clause 17 (governing law) is governed by the laws of Ireland, and Clause 18(b) (choice of forum) designates the courts of Ireland, unless Applicable Data Protection Law requires otherwise for Customer.
-
Where a transfer of Personal Data to a Sub-processor located outside the European Economic Area, the United Kingdom, or Switzerland requires a transfer mechanism under Applicable Data Protection Law (for example, a Sub-processor relying on the EU-US Data Privacy Framework or the EU SCCs in the Processor-to-Processor configuration), Trailogs will ensure that such a mechanism is in place before the transfer occurs.
-
On request, Trailogs will provide Customer with information reasonably necessary to confirm that an appropriate transfer mechanism is in place for a given transfer.
8. Assistance With Data Subject Requests
Taking into account the nature of the processing, Trailogs will provide Customer with reasonable assistance, through appropriate technical and organizational measures available within the Service, to help Customer respond to requests from Data Subjects seeking to exercise their rights under Applicable Data Protection Law. Where a Data Subject contacts Trailogs directly regarding Customer Data, Trailogs will direct the request to Customer without responding to it substantively, unless required to do otherwise by Applicable Data Protection Law.
9. Personal Data Breach Notification
-
Trailogs will notify Customer without undue delay after becoming aware of a Security Incident affecting Customer Data.
-
Such notice will include, to the extent then known, a description of the nature of the incident, the categories and approximate number of Data Subjects and records affected, the likely consequences, and the measures taken or proposed to address the incident. Trailogs may provide this information in phases as it becomes available.
-
Trailogs will take reasonable steps to contain and investigate a Security Incident and to assist Customer in meeting Customer’s own notification obligations under Applicable Data Protection Law.
-
Notification of, or response to, a Security Incident will not be construed as an acknowledgment by Trailogs of fault or liability.
10. Assistance With Compliance Obligations
Taking into account the nature of processing and the information available to Trailogs, Trailogs will provide Customer with reasonable assistance with data-protection impact assessments and prior consultations with supervisory authorities, to the extent required under Applicable Data Protection Law and reasonably related to Trailogs’ processing of Customer Data.
11. Audits and Information
-
On reasonable request, and no more than once per year (except following a Security Incident or where required by a supervisory authority), Trailogs will make available to Customer information reasonably necessary to demonstrate compliance with this DPA, which may take the form of relevant documentation, security summaries, or independent audit reports where available.
-
Any audit will be conducted during normal business hours, with reasonable advance notice, subject to reasonable confidentiality restrictions, and without unreasonably interfering with Trailogs’ business operations or the security of other customers’ data.
12. Deletion or Return of Data
-
On termination or expiry of the Terms of Service, and subject to Section 5 (Demo Workspaces) and Section 7 (Customer Data and Privacy) of the Terms of Service, Trailogs will delete Customer Data within the periods described in our Privacy Policy, unless Applicable Data Protection Law requires continued retention.
-
Because Demo Workspaces are provided for evaluation only, Customer Data in a Demo Workspace may be deleted earlier, including without notice, as described in the Terms of Service. Customer is responsible for exporting or retaining any Customer Data it wishes to keep.
-
Deletion from active systems may not immediately remove Customer Data from encrypted backups, which will be deleted in the ordinary course in accordance with Trailogs’ backup-retention cycle.
13. Liability
Each party’s liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service. Nothing in this DPA is intended to expand either party’s liability beyond what is set out in the Terms of Service, except to the extent such limitation would be prohibited by Applicable Data Protection Law.
14. Term
This DPA takes effect on the date Customer first agrees to the Terms of Service and remains in effect for as long as Trailogs processes Personal Data on Customer’s behalf under the Terms of Service.
15. Governing Law and Jurisdiction
This DPA is governed by the laws of the Republic of Serbia, excluding its conflict-of-laws rules. Subject to any mandatory rights available to Customer under Applicable Data Protection Law, the competent courts in Novi Sad, Serbia will have exclusive jurisdiction over any dispute arising from this DPA. This Section does not apply to the EU SCCs incorporated under Section 7, which are governed by their own governing-law and jurisdiction clauses as specified in Section 7.2.
16. Contact
For questions about this Data Processing Agreement, contact:
Email: support@trailogs.com
Annex 1 — Details of Processing
| Subject matter | Trailogs’ provision of the Service to Customer under the Terms of Service. |
| Duration | For the term of the Terms of Service, plus any retention period described in Section 12 of this DPA. |
| Nature and purpose of processing | Hosting, storing, organizing, retrieving, and displaying Customer Data submitted to the Service; generating embeddings and AI-generated responses from Customer Data; securing, monitoring, and troubleshooting the Service; and any other processing reasonably necessary to provide the functionality Customer configures or requests. |
| Categories of Personal Data | Names or other identifiers of people referenced in logs, subjects, comments, or other Customer Data; workspace member names and email addresses; and any other Personal Data Customer chooses to include in Customer Data. |
| Categories of Data Subjects | Customer’s workspace members and, where included in Customer Data at Customer’s discretion, Customer’s employees, contractors, customers, or other individuals referenced in logs or related content. |
| Frequency of processing | Continuous, for as long as the Service is used. |
| Location(s) of processing | Primary hosting infrastructure: European Union (Germany). Administrative access by Trailogs personnel: Serbia. Additional processing by Sub-processors as described in Annex 3. |
Annex 2 — Technical and Organizational Security Measures
Trailogs applies technical and organizational measures designed to protect Customer Data, including:
- encryption of data in transit using HTTPS/TLS;
- authentication controls and access management for Accounts and administrative systems;
- storage of passwords in hashed form;
- restricted, role-based administrative access to production systems;
- secure management of environment variables, credentials, and secrets;
- database and infrastructure-level security controls, including network segmentation where applicable;
- logging and monitoring of application and infrastructure activity;
- regular backups and documented recovery procedures;
- periodic review of service-provider and Sub-processor access;
- ongoing application of software and dependency security updates;
- internal procedures for identifying, investigating, and responding to Security Incidents.
These measures may be updated from time to time consistent with Section 5 of this DPA.
Annex 3 — Sub-processors
| Sub-processor | Location | Purpose |
|---|---|---|
| Hetzner Online GmbH | Falkenstein, Germany (European Union) | Primary application hosting, databases, storage, networking, content delivery, backups, logging, and monitoring. |
| AI providers | European Union / United States (varies by provider) | Generating text embeddings, semantic retrieval, and generating AI responses within AI Features. |
| Communication and support providers | European Union / United States (varies by provider) | Transactional email, Account verification, and support communications. |
| Analytics and error-monitoring providers | European Union / United States (varies by provider), where enabled | Diagnosing errors and understanding Service performance and reliability. |
Current information about the specific providers within the “AI providers”, “Communication and support providers”, and “Analytics and error-monitoring providers” categories is available on request at support@trailogs.com. Trailogs will provide notice of a new or replacement Sub-processor as described in Section 6.4 of this DPA.