TraceSpec Data Processing Addendum
Effective date: 29 August 2026 Last updated: 31 August 2026
This Data Processing Addendum (“DPA”) forms part of the TraceSpec Terms of Business between Elyven Ltd, trading as TraceSpec (“TraceSpec”, “we”, “us”, or “our”), and the customer that uses TraceSpec (“Customer”, “you”, or “your”).
This DPA applies where TraceSpec processes Customer Personal Data on behalf of the Customer as a processor.
1. Definitions
In this DPA:
Applicable Data Protection Law means all data protection and privacy laws applicable to the processing of Customer Personal Data, including where applicable the UK GDPR, the Data Protection Act 2018, the EU GDPR, and the Privacy and Electronic Communications Regulations 2003.
Customer Personal Data means personal data contained in Customer Content that TraceSpec processes on behalf of the Customer as a processor in providing the TraceSpec platform.
Controller, processor, personal data, processing, data subject, personal data breach and subprocessor have the meanings given in Applicable Data Protection Law.
Terms means the TraceSpec Terms of Business.
2. Roles of the parties
For Customer Personal Data, the Customer is the controller and TraceSpec is the processor, unless the parties agree otherwise in writing.
For personal data processed by TraceSpec for account administration, billing, security, product improvement, marketing and business operations, TraceSpec acts as a controller as described in the Privacy Policy.
3. Customer instructions
TraceSpec will process Customer Personal Data only:
- to provide, operate, support, secure, troubleshoot, maintain, improve and develop TraceSpec;
- as described in the Terms, this DPA and applicable documentation;
- as instructed by the Customer through use of the platform;
- as necessary to comply with law;
- as otherwise agreed in writing.
The Customer’s documented instructions include this DPA, the Terms, the Customer’s configuration of TraceSpec, and lawful instructions submitted through the platform or support channels.
If TraceSpec believes an instruction infringes Applicable Data Protection Law, TraceSpec will inform the Customer unless prohibited by law.
4. Customer responsibilities
The Customer is responsible for:
- ensuring it has a lawful basis for processing Customer Personal Data;
- providing all required notices to data subjects;
- obtaining any required consents or permissions;
- ensuring Customer Personal Data is accurate, relevant and limited to what is necessary;
- ensuring it has the right to enter, upload and process Customer Personal Data in TraceSpec;
- responding to data subject requests unless TraceSpec is required to assist;
- complying with Applicable Data Protection Law.
TraceSpec is not responsible for determining whether Customer Personal Data is appropriate for the Customer’s project, lawful basis or compliance obligations.
5. Processing details
The subject matter, duration, nature, purpose, categories of data and categories of data subjects are set out in Schedule 1.
6. Confidentiality
TraceSpec will ensure that persons authorised to process Customer Personal Data are subject to appropriate confidentiality obligations.
7. Security measures
TraceSpec will implement appropriate technical and organisational measures designed to protect Customer Personal Data against unauthorised or unlawful processing and against accidental loss, destruction or damage.
Current security measures are summarised in Schedule 2 and our Security Statement.
The Customer acknowledges that no system is completely secure and that security obligations are assessed taking into account the nature of the service, processing risk, available technology, implementation costs and relevant circumstances.
8. Subprocessors
The Customer gives TraceSpec general authorisation to use subprocessors to provide TraceSpec.
Current core subprocessors include:
| Subprocessor | Purpose |
|---|---|
| Vercel | Website/application hosting and deployment infrastructure |
| Supabase | Database and related backend services |
| Stripe | Payment processing, subscription management and billing metadata |
| GitHub | Source code hosting and development workflow |
| Clerk | Sign-up, sign-in, authentication and session management |
| UK2.net / UK-2 Limited / THG | Transactional/service email and support communications |
We maintain a more detailed Data Protection & Processing page, including a subprocessor matrix and indicative processing locations, at https://www.trace-spec.com/legal/data-protection-processing.
TraceSpec will impose data protection obligations on subprocessors that are materially equivalent to those in this DPA, as required by Applicable Data Protection Law.
TraceSpec remains responsible for the performance of its subprocessors’ data-processing obligations to the extent required by Applicable Data Protection Law and the Terms.
9. Changes to subprocessors
TraceSpec may add or replace subprocessors from time to time.
Where required, TraceSpec will provide notice of material subprocessor changes by updating its subprocessor list, notifying account administrators, or using another reasonable method.
The Customer may object to a new subprocessor on reasonable data protection grounds by contacting privacy@trace-spec.com within 14 days of notice. The parties will work in good faith to resolve the objection. If the objection cannot reasonably be resolved, TraceSpec may allow the Customer to terminate the affected service, and the Customer’s sole remedy will be termination of the affected subscription.
10. International transfers
TraceSpec may process Customer Personal Data in the United Kingdom, the EEA and other jurisdictions where TraceSpec or its subprocessors operate.
Where TraceSpec makes a restricted transfer of Customer Personal Data and safeguards are required, TraceSpec will use appropriate safeguards such as:
- adequacy regulations or decisions;
- the UK International Data Transfer Agreement;
- the UK Addendum to the EU Standard Contractual Clauses;
- the EU Standard Contractual Clauses;
- Data Privacy Framework certification where applicable;
- another lawful transfer mechanism under Applicable Data Protection Law.
The Customer authorises TraceSpec to make such transfers as necessary to provide TraceSpec, subject to this DPA.
11. Data subject requests
Taking into account the nature of the processing, TraceSpec will provide reasonable assistance to the Customer in responding to data subject requests relating to Customer Personal Data, where the Customer cannot reasonably fulfil the request without TraceSpec’s assistance.
If a data subject contacts TraceSpec directly about Customer Personal Data, TraceSpec may refer the request to the Customer unless required by law to respond otherwise.
12. Assistance with compliance
Taking into account the nature of the processing and information available to TraceSpec, TraceSpec will provide reasonable assistance with Customer obligations relating to security, breach notification, data protection impact assessments and prior consultation, where required by Applicable Data Protection Law.
Assistance beyond standard support may be subject to reasonable fees unless the assistance is required due to TraceSpec’s breach of this DPA.
13. Personal data breaches
TraceSpec will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data.
The notification will include information reasonably available to TraceSpec to help the Customer meet its legal obligations. TraceSpec may provide information in phases as it becomes available.
TraceSpec’s notification of a breach is not an admission of fault or liability.
14. Deletion and return
On termination or expiry of the relevant service, TraceSpec will delete or anonymise Customer Personal Data in accordance with the Terms, the Privacy Policy, account settings, technical capabilities, backup cycles and legal requirements.
Where export functionality is available, the Customer is responsible for exporting Customer Content before termination or account closure.
Customer Personal Data may remain in backups until the relevant backup cycle expires, provided it remains protected and is not actively processed except for backup, disaster recovery, security, legal or compliance purposes.
TraceSpec may retain Customer Personal Data where required by law or where necessary to establish, exercise or defend legal claims, maintain security, resolve disputes or comply with accounting, audit or regulatory obligations.
15. Audit and information rights
TraceSpec will make available information reasonably necessary to demonstrate compliance with this DPA, taking into account the nature of the service and processing.
For self-serve subscriptions, this will usually be provided through documentation, written responses, security summaries, third-party certifications where available, and policy materials.
On-site audits are not included for self-serve subscriptions unless required by Applicable Data Protection Law and agreed in advance. Any audit must be conducted during normal business hours, on reasonable notice, without disrupting TraceSpec’s business, and subject to confidentiality, security and scope controls.
TraceSpec may charge reasonable fees for audit assistance unless the audit is required due to TraceSpec’s breach of this DPA.
16. Liability
Liability under this DPA is subject to the limitations and exclusions in the Terms, unless prohibited by Applicable Data Protection Law.
17. Conflict
If there is a conflict between this DPA and the Terms in relation to processing of Customer Personal Data as processor, this DPA takes precedence.
18. Contact
For data protection matters, contact:
TraceSpec / Elyven Ltd Email: privacy@trace-spec.com
Schedule 1 — Processing details
Subject matter
Processing of Customer Personal Data submitted to, stored in or generated through TraceSpec by or on behalf of the Customer.
Duration
For the duration of the Customer’s subscription or use of TraceSpec, and thereafter as required for deletion, backup expiry, legal retention, dispute resolution, security, audit and compliance purposes.
Nature and purpose of processing
- Hosting Customer Content;
- providing TraceSpec platform functionality;
- generating calculations, candidate rankings, warnings, reports and exports;
- account/workspace administration;
- support and troubleshooting;
- security monitoring and access logging;
- backup and disaster recovery;
- product maintenance and improvement;
- compliance with law and enforcement of terms.
Categories of data subjects
Customer Personal Data may relate to:
- Customer users and administrators;
- employees, contractors or representatives of the Customer;
- Customer clients, project contacts or stakeholders;
- individuals named in project data, line lists, files, reports or support communications.
Categories of personal data
Customer Personal Data may include:
- names;
- business email addresses;
- business phone numbers;
- job titles or roles;
- company or organisation names;
- project references containing personal identifiers;
- user IDs and account metadata;
- support content;
- other personal data included by the Customer in Customer Content.
Special category data
TraceSpec is not designed to process special category data or criminal offence data. The Customer must not enter or upload such data unless expressly agreed in writing and supported by an appropriate lawful basis and safeguards.
Schedule 2 — Security measures
TraceSpec’s technical and organisational measures may include:
- hosting with reputable cloud infrastructure providers;
- database and backend services provided by Supabase;
- application hosting and deployment through Vercel;
- payment processing through Stripe;
- encrypted transmission using HTTPS/TLS;
- access controls for staff and administrative systems;
- authentication and session controls;
- role-based or permission-based access where available;
- logging and monitoring for security, troubleshooting and audit purposes;
- backup and disaster recovery processes;
- least-privilege access principles where practicable;
- confidentiality obligations for personnel with access to systems or Customer data;
- use of development workflows and source control through GitHub;
- review of security issues and vulnerabilities as part of product maintenance;
- incident response procedures appropriate to the stage and scale of the business;
- restrictions on support access to Customer Content except where needed to provide support, troubleshoot, secure or improve the service.
Security measures may evolve over time as TraceSpec develops.