Data Processing Addendum.
Last updated: 9 August 2026
About this page
This is a plain-language summary of the Trifrost Data Processing Addendum (DPA). The full executed DPA is available for Enterprise customers on request — email cory+trifrost@hawkvelt.id.au.
Roles
You (the customer) are the controller of the personal data you send through the service. Trifrost acts as a processor, processing that data only on your documented instructions — chiefly, routing inference requests to the providers your administrators configure and operating the governance and audit features you enable.
Scope of processing
- Subject matter — inference request and response data, account identity data, and usage telemetry.
- Purpose — delivering the gateway, governance, billing, and audit features of the service.
- Duration — the term of your subscription, plus the deletion window on termination described below.
Sub-processors
Trifrost engages the sub-processors listed at Sub-processors. We remain responsible for their performance and will give notice of changes, with an opportunity to object.
Security measures
- Encryption in transit and at rest across the service
- Access controls: SSO via your identity provider, server-side sessions, per-customer RBAC roles
- Multi-tenant isolation — every customer-scoped read is structurally scoped to the requesting organization
- A tamper-evident, HMAC-signed audit log of every request and administrative mutation
- Prompt and response bodies are captured only when your organization explicitly enables a logging policy
Regional processing
Your tenant is pinned to the region you select — AU, APAC, EMEA, UK, or Germany — and we process and store your data in that region. Prompt data leaves the region only to reach the LLM providers your administrators have configured.
Breach notification
We will notify you without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting your data, with the information you need to meet your own obligations.
Audit rights
You may audit our compliance, satisfied in the first instance by our SOC 2 Type II and ISO 27001 reports. Enterprise customers may request additional evidence or an assessment as set out in the full DPA.
Deletion on termination
On termination we make your data available for export, then delete customer data from production systems and backups within the window defined in the full DPA, and certify deletion on request.
Contact
DPA requests and data protection questions: cory+trifrost@hawkvelt.id.au.