You must be 18+ to use TrimmerOne

    By continuing you confirm you're 18 or older and agree to our Terms and use of cookies. We use essential cookies to run the app; analytics and marketing cookies are optional. See our Privacy Policy. You can change your choice anytime via "Cookie Preferences" in the footer.

    Data Processing Addendum

    Effective: April 2026

    Last reviewed by counsel: pending. This template is provided for transparency and must be executed and reviewed by counsel before relied upon contractually.

    1. Scope and Roles

    This Data Processing Addendum ("DPA") forms part of the agreement between TrimmerOne, Inc. ("Processor") and the customer entity ("Controller") that uses the TrimmerOne service. It governs the Processing of Personal Data as defined under the EU General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA), and other applicable data protection laws.

    2. Definitions

    Capitalized terms (Personal Data, Processing, Controller, Processor, Sub-processor, Data Subject, Supervisory Authority) have the meanings given in the GDPR. Under CCPA/CPRA, TrimmerOne acts as a "Service Provider" with respect to Customer Personal Information.

    3. Subject Matter and Duration

    Subject matter: Provision of the TrimmerOne SaaS platform for cannabis trim-operations management. Duration: For the term of the underlying subscription agreement and any post-termination data retention period required by law.

    4. Nature and Purpose of Processing

    Storage, retrieval, organization, transmission, analysis (including AI-assisted analysis where enabled), backup, and deletion of Customer Personal Data, solely for the purpose of providing, securing, and improving the Service in accordance with Controller's documented instructions.

    5. Categories of Data Subjects and Personal Data

    Data subjects:

    • Controller's authorized users (employees, contractors)
    • Controller's customers, where Controller chooses to upload such data

    Categories of Personal Data:

    • Identifiers (name, email, account credentials, user ID)
    • Professional/employment information (role, assigned location, productivity metrics)
    • Internet/network activity (login timestamps, IP, device/browser)
    • Operational records uploaded by Controller (batch data, photos, notes)

    TrimmerOne does not knowingly process special categories of data under GDPR Article 9 or sensitive personal information under CPRA, except for account credentials.

    6. Processor Obligations

    • Process Personal Data only on documented instructions from Controller
    • Ensure persons authorized to process Personal Data are bound by confidentiality
    • Implement appropriate technical and organizational measures (Section 8)
    • Assist Controller with Data Subject requests, DPIAs, and Supervisory Authority inquiries
    • At Controller's choice, delete or return all Personal Data upon termination
    • Make available information necessary to demonstrate compliance and allow audits (Section 11)

    7. Sub-processors

    Controller authorizes Processor's use of the following Sub-processors:

    • Supabase, Inc. — database, authentication, file storage, edge functions (US/EU regions)
    • Stripe, Inc. — payment processing
    • Resend — transactional email delivery
    • Lovable AI Gateway — AI model access (Google, OpenAI providers)

    Processor will provide at least 30 days' notice before adding or replacing a Sub-processor. Controller may object in writing on reasonable data-protection grounds; if the parties cannot resolve the objection, Controller may terminate the subscription on a pro-rated basis.

    8. Security Measures

    Processor maintains a written information security program that includes:

    • Encryption in transit (TLS 1.2+) and at rest (AES-256)
    • Row-Level Security and tenant isolation in the database
    • Role-based access controls and least-privilege administrative access
    • Centralized logging, monitoring, and intrusion detection
    • Regular vulnerability scanning and dependency management
    • Backup, disaster recovery, and tested restore procedures
    • Personnel security training and confidentiality agreements

    9. International Transfers

    Where Personal Data of EEA, UK, or Swiss data subjects is transferred outside the EEA/UK/CH, the parties incorporate the European Commission's Standard Contractual Clauses (Module 2: Controller to Processor) and the UK International Data Transfer Addendum, as applicable. Processor will implement supplementary measures where required.

    10. Personal Data Breach

    Processor will notify Controller without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data breach affecting Controller's data. The notification will include, to the extent known, the nature of the breach, categories and approximate number of data subjects and records affected, likely consequences, and remedial measures taken or proposed.

    11. Audits

    Processor will make available to Controller, upon reasonable written request and no more than once per 12-month period (except following a Personal Data breach), summaries of independent third-party audits or written responses to a reasonable security questionnaire. On-site audits are limited to Enterprise customers and subject to mutually agreed confidentiality and scope terms.

    12. CCPA / CPRA Service Provider Terms

    Processor will not (a) sell or share Personal Information; (b) retain, use, or disclose Personal Information for any purpose other than the specific business purposes set forth in the Agreement; (c) retain, use, or disclose Personal Information outside of the direct business relationship with Controller; or (d) combine Personal Information received from Controller with Personal Information received from another source, except as permitted by CCPA/CPRA.

    13. Return or Deletion of Data

    Upon termination of the subscription, Processor will, at Controller's election, delete or return all Customer Personal Data within 30 days, subject to retention required by law. Backups containing Personal Data are deleted in the ordinary backup-rotation cycle, not exceeding 90 days.

    14. Liability and Order of Precedence

    The liability provisions of the underlying Master Service Agreement and Terms of Service apply to this DPA. In the event of conflict between this DPA and the underlying agreement with respect to data protection, this DPA controls.

    15. Contact

    Privacy / data protection inquiries: info@trimmerone.com