By continuing you confirm you're 18 or older and agree to our Terms and use of cookies. We use essential cookies to run the app; analytics and marketing cookies are optional. See our Privacy Policy. You can change your choice anytime via "Cookie Preferences" in the footer.
Effective: April 2026
Last reviewed by counsel: pending. This template is provided for transparency and must be executed and reviewed by counsel before relied upon contractually.
This Data Processing Addendum ("DPA") forms part of the agreement between TrimmerOne, Inc. ("Processor") and the customer entity ("Controller") that uses the TrimmerOne service. It governs the Processing of Personal Data as defined under the EU General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA), and other applicable data protection laws.
Capitalized terms (Personal Data, Processing, Controller, Processor, Sub-processor, Data Subject, Supervisory Authority) have the meanings given in the GDPR. Under CCPA/CPRA, TrimmerOne acts as a "Service Provider" with respect to Customer Personal Information.
Subject matter: Provision of the TrimmerOne SaaS platform for cannabis trim-operations management. Duration: For the term of the underlying subscription agreement and any post-termination data retention period required by law.
Storage, retrieval, organization, transmission, analysis (including AI-assisted analysis where enabled), backup, and deletion of Customer Personal Data, solely for the purpose of providing, securing, and improving the Service in accordance with Controller's documented instructions.
Data subjects:
Categories of Personal Data:
TrimmerOne does not knowingly process special categories of data under GDPR Article 9 or sensitive personal information under CPRA, except for account credentials.
Controller authorizes Processor's use of the following Sub-processors:
Processor will provide at least 30 days' notice before adding or replacing a Sub-processor. Controller may object in writing on reasonable data-protection grounds; if the parties cannot resolve the objection, Controller may terminate the subscription on a pro-rated basis.
Processor maintains a written information security program that includes:
Where Personal Data of EEA, UK, or Swiss data subjects is transferred outside the EEA/UK/CH, the parties incorporate the European Commission's Standard Contractual Clauses (Module 2: Controller to Processor) and the UK International Data Transfer Addendum, as applicable. Processor will implement supplementary measures where required.
Processor will notify Controller without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data breach affecting Controller's data. The notification will include, to the extent known, the nature of the breach, categories and approximate number of data subjects and records affected, likely consequences, and remedial measures taken or proposed.
Processor will make available to Controller, upon reasonable written request and no more than once per 12-month period (except following a Personal Data breach), summaries of independent third-party audits or written responses to a reasonable security questionnaire. On-site audits are limited to Enterprise customers and subject to mutually agreed confidentiality and scope terms.
Processor will not (a) sell or share Personal Information; (b) retain, use, or disclose Personal Information for any purpose other than the specific business purposes set forth in the Agreement; (c) retain, use, or disclose Personal Information outside of the direct business relationship with Controller; or (d) combine Personal Information received from Controller with Personal Information received from another source, except as permitted by CCPA/CPRA.
Upon termination of the subscription, Processor will, at Controller's election, delete or return all Customer Personal Data within 30 days, subject to retention required by law. Backups containing Personal Data are deleted in the ordinary backup-rotation cycle, not exceeding 90 days.
The liability provisions of the underlying Master Service Agreement and Terms of Service apply to this DPA. In the event of conflict between this DPA and the underlying agreement with respect to data protection, this DPA controls.
Privacy / data protection inquiries: info@trimmerone.com