Data Processing Agreement (DPA)

How operational data is handled

Trustline™ works with business systems, operational platforms, and technology environments that may involve the processing of organizational and user-related data.

This Data Processing Agreement outlines the responsibilities, safeguards, and operational expectations associated with information processed in connection with Trustline™ services.
Data Processing Agreement (DPA)

Last Updated: May 27, 2026

Introduction

This Data Processing Agreement (“DPA”) describes how Trustline™ may process, access, store, transmit, or manage information in connection with operational technology services provided to clients.

This DPA is intended to support:

  • operational transparency

  • responsible data handling

  • security-conscious service delivery

  • modern infrastructure and cloud operations

  • regulatory and contractual expectations where applicable

This DPA supplements applicable service agreements, statements of work, onboarding documentation, or related operational contracts entered into between Trustline™ and its clients.


Scope of This Agreement

This DPA applies where Trustline™ processes information on behalf of a client in connection with services such as:

• Managed IT services
• Cloud infrastructure support
• Cybersecurity services
• Monitoring and maintenance
• Backup and disaster recovery
• Vendor coordination
• Technical support services
• Operational systems management

Not all services involve the same level of data access or processing.

The nature of processing may vary depending on:

  • service scope

  • client systems

  • vendor integrations

  • infrastructure requirements

  • operational workflows


Roles and Responsibilities

Client Responsibilities

Clients remain responsible for:

  • determining appropriate data usage

  • maintaining lawful authority over information provided

  • configuring internal policies and permissions

  • managing end-user behavior

  • maintaining appropriate regulatory compliance obligations

Clients are also responsible for maintaining appropriate internal operational and security practices.

Trustline™ Responsibilities

Trustline™ works to:

  • process information only as reasonably necessary for service delivery

  • maintain operational confidentiality

  • implement reasonable security safeguards

  • support operational continuity

  • reduce unnecessary access to information wherever practical

Trustline™ does not assume ownership of client data.


Categories of Information That May Be Processed

Depending on the services provided, Trustline™ may process or access operational information such as:

• User account information
• Business contact information
• Device and infrastructure information
• Authentication and access logs
• Email and communication systems
• Backup and recovery data
• Operational analytics
• Technical support records
• Cloud platform configurations
• Network and systems information

The categories of information processed may vary significantly depending on the client environment and selected services.


Processing Activities

Trustline™ may process information only for operationally necessary purposes related to service delivery.

Processing Activities May Include

• Hosting or cloud administration
• Infrastructure monitoring
• Backup management
• Security monitoring
• User support
• Vendor coordination
• System configuration
• Operational troubleshooting
• Incident response support
• Platform maintenance

Processing activities are generally limited to operational support and technology management purposes.


Confidentiality

Trustline™ recognizes the importance of operational confidentiality and responsible handling of client information.

Personnel and Operational Access

Access to systems or information is generally limited to:

  • authorized personnel

  • operationally necessary access

  • approved service activities

Trustline™ works to maintain reasonable confidentiality expectations across internal operations, vendor coordination, and service delivery workflows.

Additional confidentiality obligations may also exist under separate agreements or non-disclosure arrangements where applicable.


Security Measures

Trustline™ works to maintain reasonable administrative, technical, and operational safeguards designed to help protect client environments and operational information.

Security Measures May Include

• Access controls
• Authentication requirements
• Endpoint protection measures
• Security monitoring
• Vendor management practices
• Backup systems
• Network protections
• Operational logging
• Administrative permission controls
• Infrastructure segmentation where applicable

Security measures may evolve over time as technologies, threats, and operational requirements change.


Shared Security Responsibility

Cybersecurity and operational protection involve shared responsibilities between Trustline™ and its clients.

Clients Remain Responsible For

• Employee awareness and training
• Password management
• Device usage policies
• Internal access permissions
• Regulatory obligations
• Business continuity planning
• End-user conduct
• Internal data governance

Trustline™ Supports Operational Security Through

• Infrastructure management
• Monitoring services
• Security tooling
• Operational recommendations
• Technical support
• Vendor coordination

No environment can be guaranteed completely secure or uninterrupted at all times.


Third-Party Platforms and Subprocessors

Trustline™ may rely on third-party platforms, infrastructure providers, or operational vendors in connection with service delivery.

Examples may include:

• Microsoft
• Google
• Cloud hosting providers
• Backup vendors
• Cybersecurity platforms
• Communication providers
• Infrastructure vendors

Third-Party Operational Reality

Third-party systems may:

  • process information independently

  • operate across multiple geographic regions

  • maintain separate operational policies

  • maintain separate privacy practices

Trustline™ works to select operationally reputable vendors whenever practical but does not control third-party operational environments directly.


International Infrastructure and Data Transfers

Certain systems, cloud providers, vendors, or operational platforms used in connection with Trustline™ services may process or store information across multiple jurisdictions.

By using Trustline™ services, clients acknowledge that information may pass through infrastructure or systems located outside their immediate geographic region.


Incident Response and Security Events

Trustline™ works to maintain operational monitoring and incident response processes appropriate for the services provided.

Security Events May Include

• Unauthorized access attempts
• Malware activity
• Infrastructure disruptions
• Credential compromise
• Vendor-related incidents
• Operational outages

In The Event Of A Significant Incident

Trustline™ may:

  • investigate operationally relevant events

  • coordinate with affected parties where appropriate

  • work with vendors or infrastructure providers

  • implement reasonable mitigation efforts

  • provide reasonable notifications where operationally appropriate or legally required


Data Retention and Deletion

Trustline™ may retain operational records, logs, backups, or service-related information for reasonable business, operational, legal, and security purposes.

Retention Periods May Depend On

• Service requirements
• Security obligations
• Backup schedules
• Regulatory requirements
• Operational continuity needs
• Dispute resolution requirements

Certain information may remain within archival systems, logs, backups, or operational recovery systems for reasonable periods following service changes or termination.


Requests Regarding Information

Where operationally appropriate and legally applicable, Trustline™ may assist clients in responding to certain requests regarding processed information.

Requests May Relate To

• Access requests
• Correction requests
• Deletion requests
• Export requests
• Processing limitations

Certain requests may require:

  • identity verification

  • client authorization

  • operational review

  • legal evaluation


Limitation of Liability

To the extent permitted under applicable law, Trustline™ shall not be responsible for indirect, incidental, consequential, or business interruption damages arising from operational events outside reasonable control.

This May Include

• Cybersecurity incidents
• Vendor failures
• Internet disruptions
• Third-party outages
• Infrastructure failures
• Data loss events
• Operational downtime
• Unauthorized access events

Nothing within this DPA is intended to limit rights or obligations that cannot legally be limited under applicable law.


Changes to This Agreement

Trustline™ may periodically update this DPA to reflect:

• operational changes
• infrastructure updates
• legal requirements
• cybersecurity developments
• vendor or platform changes

Updated versions will be published with a revised effective date.


Related Policies

Additional operational information may also be available within the following pages:

• Privacy Policy
• Terms of Service
• Cookie Policy
• Accessibility Statement


Contact Information

Questions regarding this Data Processing Agreement or operational data handling practices may be directed to:

Trustline™ IT Services
12916 SW 133rd Ct
Miami, FL 33186
United States

Phone: (305) 800-6398
Email: legal@trustlineit.com
Website: https://trustlineit.com