Skip to content
Legal

Data Processing Addendum.

Last updated: 9 August 2026

About this page

This is a plain-language summary of the Trifrost Data Processing Addendum (DPA). The full executed DPA is available for Enterprise customers on request — email cory+trifrost@hawkvelt.id.au.

Roles

You (the customer) are the controller of the personal data you send through the service. Trifrost acts as a processor, processing that data only on your documented instructions — chiefly, routing inference requests to the providers your administrators configure and operating the governance and audit features you enable.

Scope of processing

  • Subject matter — inference request and response data, account identity data, and usage telemetry.
  • Purpose — delivering the gateway, governance, billing, and audit features of the service.
  • Duration — the term of your subscription, plus the deletion window on termination described below.

Sub-processors

Trifrost engages the sub-processors listed at Sub-processors. We remain responsible for their performance and will give notice of changes, with an opportunity to object.

Security measures

  • Encryption in transit and at rest across the service
  • Access controls: SSO via your identity provider, server-side sessions, per-customer RBAC roles
  • Multi-tenant isolation — every customer-scoped read is structurally scoped to the requesting organization
  • A tamper-evident, HMAC-signed audit log of every request and administrative mutation
  • Prompt and response bodies are captured only when your organization explicitly enables a logging policy

Regional processing

Your tenant is pinned to the region you select — AU, APAC, EMEA, UK, or Germany — and we process and store your data in that region. Prompt data leaves the region only to reach the LLM providers your administrators have configured.

Breach notification

We will notify you without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting your data, with the information you need to meet your own obligations.

Audit rights

You may audit our compliance, satisfied in the first instance by our SOC 2 Type II and ISO 27001 reports. Enterprise customers may request additional evidence or an assessment as set out in the full DPA.

Deletion on termination

On termination we make your data available for export, then delete customer data from production systems and backups within the window defined in the full DPA, and certify deletion on request.

Contact

DPA requests and data protection questions: cory+trifrost@hawkvelt.id.au.