Legal
Data Processing Addendum
Last updated: 2026-09-03
1. Roles
You are the Controller. Assegai Analytics is the Processor when handling personal data on your behalf via Trident Protect.
2. Subject-matter & duration
Processing occurs for the duration of your subscription and any wind-down period required to return or delete personal data.
3. Nature & purpose
To provide the Trident Protect platform and any managed DPO services you have contracted.
4. Types of personal data
- User account data (name, email, role).
- Records, evidence, and documents you upload.
- Data subject records associated with your compliance workflows (e.g. DSARs, breach incidents).
5. Data subject categories
Your staff, customers, and any other data subjects reflected in the records you maintain in Trident.
6. Processor obligations
- Process only on documented instructions.
- Ensure personnel are bound by confidentiality.
- Implement appropriate technical and organisational measures.
7. Sub-processors
- Supabase — database, auth, storage.
- Stripe — payments.
- Resend — transactional email.
- Sentry — error monitoring.
8. International transfers
Placeholder — transfer mechanisms pending legal review.
9. Security measures
- Row-level security enforced in Postgres for every tenant table.
- Encryption in transit; encryption at rest via Supabase.
- Least-privilege access and full audit logging.
10. Assistance to controller
We assist with DSARs, DPIAs, and breach notifications through the platform and, where contracted, our DPO service.
11. Deletion & return
On termination, we return or delete personal data on your written instruction, subject to legal retention obligations.
12. Audit
We make information reasonably necessary to demonstrate compliance available on request.
13. Contact
Email dposervices@assegai.africa.
Questions? Email trident@assegai.africa.