TRUTHSCAN DATA PROCESSING ADDENDUM
Standard Plans Only • Version 1.1 | Effective September 9, 2026
Who this DPA is for
Customers on TruthScan’s standard plans, being the subscription plans available for purchase online at truthscan.com. Zero Data Retention is available as a plan feature on Business plans and above; see Section 7.
Who it is not for
Enterprise customers. Enterprise engagements are governed by a separately negotiated Data Processing Addendum executed alongside the applicable enterprise agreement. That document applies instead of this one, in full.
This Data Processing Addendum (the "DPA") forms part of, and is incorporated by reference into, the TruthScan Terms of Service or other agreement governing the customer's use of a TruthScan standard plan (the "Agreement"), between the customer identified in the customer's TruthScan account (the "Customer") and Undetectable, Inc., doing business as TruthScan ("TruthScan").
This DPA applies where TruthScan processes personal data on the Customer's behalf in connection with a standard plan. It does not apply to enterprise engagements. Where the Customer and TruthScan have executed a separately negotiated data processing addendum, that addendum governs in full and this DPA does not apply.
In the event of a conflict between this DPA and the Agreement, this DPA prevails with respect to data protection matters, except that the limitation of liability in the Agreement governs liability under this DPA as set out in Section 14.
TruthScan's designated data protection contact is Ben Miller, Chief Information Security Officer, ben@truthscan.com.
1. Acceptance
This DPA takes effect automatically and forms part of the Agreement from the date the Customer first accepts the Agreement or begins using a standard plan, whichever is earlier. No signature is required.
Nothing in this DPA extends to enterprise engagements, and a Customer that later moves to an enterprise agreement will be governed by the data processing addendum executed with that agreement from its effective date.
Customers that require custom data processing terms should contact TruthScan at the contact set out above.
2. Definitions
"Applicable Data Protection Laws" means all data protection and privacy laws applicable to the processing of personal data under this DPA, including the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR where applicable, the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020, together with its implementing regulations ("CCPA"), and other applicable U.S. state privacy laws, including the Virginia Consumer Data Protection Act, the Colorado Privacy Act and the Texas Data Privacy and Security Act (together, "US State Privacy Laws").
"Business Day" means a day other than a Saturday, a Sunday or a federal public holiday in the United States.
"Personal Data" means personal data or personal information, as defined in Applicable Data Protection Laws, that TruthScan processes on the Customer's behalf under the Agreement.
"Security Incident" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Personal Data processed by TruthScan.
"Subprocessor" means any third party engaged by TruthScan to process Personal Data.
"Standard Contractual Clauses" or "SCCs" means the clauses approved by the European Commission in Decision 2021/914.
"Business", "Service Provider", "Sell" and "Share" have the meanings given in the CCPA. Where the CCPA applies, references to Customer include "Business" and references to TruthScan include "Service Provider". Where a US State Privacy Law other than the CCPA applies, references to controller-equivalent and processor-equivalent roles under that law apply correspondingly.
3. Roles of the Parties
The Customer is the controller (or business) in respect of Personal Data it submits to the services. TruthScan is the processor (or service provider) in respect of that Personal Data, except where TruthScan processes aggregated, de-identified or derived data as a controller for its own purposes as permitted under Section 7.
Where retention is enabled on the Customer's account, the model-training processing described in Section 7.1 is carried out by TruthScan as processor, on the Customer's documented instruction as recorded by the retention setting on the Customer's account. The Customer may withdraw that instruction as set out in Section 7.2.
TruthScan processes account, billing and business contact information relating to the Customer and its authorised users, such as names, email addresses and login credentials, as an independent controller for its own purposes, including account administration, billing, security and service communications, in accordance with the TruthScan Privacy Policy. That information is not Personal Data processed on the Customer's behalf under this DPA.
4. Details of Processing
| Item | Detail |
|---|---|
| Subject matter | Provision of AI content detection services under the Agreement. |
| Duration | The term of the Agreement, plus the retention and deletion periods set out in Section 7. |
| Nature and purpose | The Customer submits content to TruthScan. TruthScan processes that content through its AI detection models and returns detection results, scores and breakdowns to the Customer. |
| Categories of data subjects | Determined by the Customer. Typically, individuals whose images, documents or other content the Customer submits. Account and contact information relating to the Customer's own authorised users is processed by TruthScan as a controller as described in Section 3. |
| Types of Personal Data | Online identifiers, including IP addresses, API authentication tokens and device identifiers. Any further Personal Data contained in content the Customer chooses to submit is determined solely by the Customer. |
| Special categories | TruthScan does not require special or sensitive categories of Personal Data. The Customer is responsible for determining whether the content it submits contains such data and for ensuring it has a lawful basis to submit it. |
| Processing operations | Transmission over HTTPS, automated detection processing, return of results, and retention and model training as determined by the retention setting on the Customer's account under Section 7. |
| Frequency | On demand, initiated by the Customer. Transfers may occur continuously or periodically. |
5. TruthScan's Obligations as Processor
TruthScan shall:
- process Personal Data only on the Customer's documented instructions, including those set out in this DPA and the Agreement, unless required to do otherwise by applicable law, in which case TruthScan will inform the Customer of that requirement unless prohibited from doing so;
- promptly inform the Customer if, in TruthScan's opinion, an instruction from the Customer infringes Applicable Data Protection Laws, without any obligation to carry out a legal review of the Customer's instructions;
- ensure that personnel authorised to access Personal Data are bound by confidentiality obligations;
- implement and maintain the technical and organisational measures set out in Section 12;
- notify the Customer without undue delay after becoming aware of a Security Incident affecting the Customer's Personal Data, providing the information reasonably available to TruthScan about the nature of the incident, the categories and approximate volume of data affected, the likely consequences, and the measures taken or proposed. Where that information is not available at the time of the initial notification, TruthScan may provide it in phases as it becomes available, without undue further delay. Notification of, or response to, a Security Incident is not an acknowledgement by TruthScan of any fault or liability;
- delete Personal Data following termination of the Agreement in accordance with Section 7; and
- make available the information reasonably necessary to demonstrate compliance with this DPA, in accordance with Section 13.
6. Assistance and Data Subject Requests
Taking into account the nature of the processing and the information available to it, TruthScan shall provide reasonable assistance to the Customer to enable the Customer to (a) respond to requests from data subjects exercising their rights under Applicable Data Protection Laws, (b) carry out data protection impact assessments and prior consultations with supervisory authorities, and (c) meet its obligations relating to the security of processing and Security Incident notification. Assistance that goes beyond the features of the services and the materials described in Section 13 is provided at the Customer's reasonable, documented cost, which TruthScan will notify to the Customer before the work is carried out.
Where TruthScan receives a data subject request directly, it shall not respond, other than to confirm receipt or as legally required, and shall forward the request to the Customer without undue delay and at no charge.
7. Data Retention, Storage and Model Training
7.1 Retention-gated training. Data retention is enabled by default on standard plans, and the retention setting on the Customer's account determines whether submitted data may be used for model training. Where retention is enabled, the Customer instructs TruthScan, and grants TruthScan a non-exclusive, worldwide, royalty-free right, to store and retain submitted data and to use, reproduce and process it to operate, develop, train, test, evaluate and improve TruthScan's AI detection models, products and services. Where retention is disabled, submitted data is not retained and is not used for model training, as described in Section 7.3. The parties acknowledge that the retention setting on the Customer's account constitutes the Customer's documented processing instruction for the purposes of Article 28 of the GDPR, and that the Customer may change it as set out in Section 7.2.
7.2 Retention controls and Zero Data Retention. Retention controls are a feature of the Customer's plan. On Business plans and above, the Customer may disable data retention directly in its account settings, and the change takes effect immediately. Enabling Zero Data Retention on an eligible plan is an account configuration made under this DPA; it is not a modification of this DPA and carries no fee. For content types for which the setting is not available in the account, such as video and audio, a Customer on a plan that includes retention controls may request the change in writing to the contact set out above, and TruthScan will apply it within five (5) Business Days of receiving the request. Customers on other standard plans may obtain retention controls by upgrading to a Business plan or above at truthscan.com, or by contacting TruthScan about an enterprise agreement.
7.3 Effect of disabling retention. Where retention is disabled, TruthScan will cease retaining newly submitted data. Submitted content and all associated artifacts, including previews, heatmaps and analysis results, are held only transiently on the API server for the purpose of completing the detection and are automatically purged, and are not used to train, develop, evaluate or improve any model. As a consequence, neither the submission history view nor the heatmap overlay will be available in the Customer's dashboard for the period during which retention is disabled, although aggregate usage metrics remain accessible at all times.
7.4 Disabling applies prospectively. Disabling retention applies to data submitted after the change takes effect. It does not require the deletion of, and does not affect TruthScan's rights in, any data already incorporated into trained models, model parameters, training artifacts, or any aggregated, de-identified or derived data, all of which TruthScan may continue to use and retain. To the extent such aggregated, de-identified or derived data no longer constitutes Personal Data under Applicable Data Protection Laws, it is not subject to the deletion obligations of this DPA.
7.5 Usage and billing records. TruthScan retains aggregated, anonymised usage logs and billing records for invoicing, security and compliance purposes. These do not contain the substantive content of submissions.
7.6 Deletion on termination. Following termination of the Agreement, TruthScan will delete or return retained Personal Data within thirty (30) Business Days of the Customer's written request, except for the data described in Section 7.4 and Section 7.5, and except where retention is required by applicable law. Where the Customer does not make such a request, TruthScan will delete retained Personal Data within ninety (90) Business Days of termination of the Agreement, subject to the same exceptions.
8. Subprocessors
The Customer provides a general authorisation for TruthScan to engage Subprocessors. TruthScan maintains an up-to-date list of its Subprocessors, including their names, locations and processing activities, at https://trust.truthscan.com/subprocessors, and will update that list at least five (5) Business Days before a new Subprocessor first processes Personal Data. The Customer may opt in to receive email notice of changes to that list using the method TruthScan makes available for that purpose, including any invitation TruthScan sends to the Customer's account contact. Email notice is sent only to Customers that have opted in, and TruthScan will send it at least five (5) Business Days before the new Subprocessor first processes Personal Data. A Customer that has not opted in agrees that publication of the change on that page constitutes notice for the purposes of this DPA and the Standard Contractual Clauses. Where a Subprocessor must be replaced urgently for security or service continuity reasons, TruthScan may engage the replacement immediately, and will update the list and notify opted-in Customers as soon as reasonably practicable thereafter.
Where the Customer objects to a Subprocessor on reasonable data protection grounds and the parties cannot resolve the objection within a reasonable period, the Customer may, as its sole and exclusive remedy, terminate the affected portion of the services.
TruthScan imposes on each Subprocessor, by written contract, data protection obligations no less protective than those in this DPA and consistent with Article 28 of the GDPR. Each Subprocessor may retain Personal Data only to the extent and for the duration necessary to perform its function. For hosting and infrastructure Subprocessors, that function includes storage of retained data in accordance with the Customer's retention election under Section 7; all other Subprocessors are engaged on a no-storage, no-retention basis. TruthScan remains responsible for its Subprocessors' performance of their data protection obligations, subject to Section 14.
9. Customer Warranties and Indemnity
The Customer represents and warrants that, in respect of all data it submits to TruthScan:
- it has a valid legal basis under Applicable Data Protection Laws to submit the data and to authorise the processing, storage and, where retention is enabled, model-training use described in this DPA;
- it has provided all notices and obtained all consents, permissions and authorisations required for that processing;
- it is lawfully entitled to submit the data, and its submission and processing do not infringe the rights of any third party or violate any applicable law, including any biometric privacy law such as the Illinois Biometric Information Privacy Act and comparable laws; and
- its instructions to TruthScan comply with Applicable Data Protection Laws.
The Customer shall defend, indemnify and hold harmless TruthScan and its affiliates from and against any third-party claim, and any resulting liabilities, damages, fines, penalties and reasonable costs, including reasonable attorneys' fees, arising out of the Customer's breach of the warranties in this Section 9 or out of content the Customer submits to the services, including any claim under a biometric privacy law. This obligation applies in addition to any indemnification provisions of the Agreement.
10. CCPA and US State Privacy Law Terms
To the extent TruthScan processes personal information subject to the CCPA on the Customer's behalf, TruthScan acts as a Service Provider and the Customer acts as a Business. TruthScan shall not (a) Sell or Share personal information; (b) retain, use or disclose personal information for any purpose, including any commercial purpose, other than the business purposes specified in this DPA and the Agreement, or as otherwise permitted by the CCPA; (c) retain, use or disclose personal information outside the direct business relationship between the parties; or (d) combine personal information received from the Customer with personal information received from or on behalf of another person or entity, or collected from TruthScan's own interactions with consumers, except as permitted by the CCPA.
The business purposes for which TruthScan processes personal information are providing the services described in Section 4 and, where retention is enabled on the Customer's account, the retention and model-improvement processing described in Section 7. That model-improvement processing is an internal use by TruthScan to build and improve the quality of the services it provides, carried out within the direct business relationship between the parties, as permitted by the CCPA and its implementing regulations. It does not involve building or modifying household or consumer profiles for use in providing services to another business, and does not involve correcting or augmenting data acquired from another source. The Customer may restrict that processing by disabling retention as set out in Section 7.2.
TruthScan shall comply with the obligations applicable to Service Providers under the CCPA and shall provide the same level of privacy protection as the CCPA requires of Businesses. TruthScan certifies that it understands the restrictions in this Section 10 and will comply with them. The Customer may take reasonable and appropriate steps to help ensure that TruthScan uses personal information in a manner consistent with the Customer's obligations under the CCPA, which the Customer may satisfy by reviewing the materials described in Section 13, and, upon reasonable written notice, may take reasonable and appropriate steps to stop and remediate any unauthorised use of personal information. If TruthScan determines it can no longer comply with its obligations under the CCPA, it shall notify the Customer promptly. TruthScan shall cooperate in good faith with the Customer in responding to verifiable consumer requests, provided that such cooperation does not impose unreasonable burdens on TruthScan's operations or require access to data beyond what TruthScan maintains in the ordinary course of business. TruthScan engages Subprocessors in accordance with Section 8, on written terms that impose obligations consistent with this Section 10.
To the extent a US State Privacy Law other than the CCPA applies to Personal Data processed under this DPA, TruthScan will process that Personal Data as a processor or service provider under that law on terms materially equivalent to those in this Section 10.
11. International Data Transfers
The Standard Contractual Clauses apply only to the extent the GDPR or UK GDPR applies to a transfer of Personal Data. Where processing involves only personal information subject to the CCPA or another US State Privacy Law, no transfer mechanism under this Section is required.
Standard plans are hosted in the United States. TruthScan provides the services using secure, cloud-hosted infrastructure located in the United States that employs industry-standard logical isolation between tenants. TruthScan's authorised technical personnel, who may be located outside the EEA and the United Kingdom, may access the infrastructure on a strictly limited, role-based and logged basis solely for system maintenance, incident response, security patching and operational support, and are bound by confidentiality obligations.
To the extent processing by TruthScan involves a transfer of Personal Data outside the EEA or the United Kingdom, that transfer is covered by the Standard Contractual Clauses (Module Two: Controller to Processor, with the Customer as data exporter and TruthScan as data importer), which are incorporated into this DPA by reference, or by another applicable transfer mechanism ensuring an equivalent level of protection. For the purposes of the Standard Contractual Clauses:
- Clause 7, the optional docking clause, applies;
- in Clause 9, Option 2 (general written authorisation) applies, the period for prior notice of changes to Subprocessors is five (5) Business Days, and notice is given in the manner set out in Section 8;
- in Clause 11, the optional language does not apply;
- in Clause 13, the competent supervisory authority is determined in accordance with Section 15;
- in Clause 17, the Standard Contractual Clauses are governed by the laws of Ireland;
- in Clause 18, disputes arising from the Standard Contractual Clauses are resolved by the courts of Ireland;
- Annex I is populated by the parties' details as recorded in the Customer's TruthScan account and in this DPA, together with the details of processing in Section 4; Annex II is populated by the measures in Section 12; and Annex III is populated by the Subprocessor list referenced in Section 8; and
- the audit and Subprocessor provisions of this DPA apply, except to the extent the Standard Contractual Clauses require otherwise.
Where the UK GDPR applies to a transfer, the UK International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the Information Commissioner (version B1.0, in force from 21 March 2022) (the "UK Addendum") is incorporated into this DPA. For the purposes of the UK Addendum, Tables 1 to 3 are completed by the information set out in this DPA and the selections above, and for Table 4 either party may end the UK Addendum as set out in Section 19 of the UK Addendum.
The third-party beneficiary rights and the complaint and forum rights granted to data subjects under the Standard Contractual Clauses, the UK Addendum and Applicable Data Protection Laws are preserved and are not limited by any third-party-beneficiary or dispute-resolution provision of the Agreement.
12. Technical and Organisational Measures
Pursuant to Article 32 of the GDPR, TruthScan implements technical and organisational measures as data importer that include, at a minimum, measures materially consistent with the following.
Encryption
- Only secure channels and protocols are permitted for inbound network connections (TLS 1.2 or higher).
- Cryptographic methods protect data in transit and at rest. Certificates and keys are securely managed.
Confidentiality: physical and logical access controls
- Access rights are granted through a documented request and approval flow, limited to personnel who require them, and reviewed periodically.
- Access attempts, successful and failed, are logged and monitored. Inactive accounts are disabled or removed in a timely manner.
Integrity, availability and resilience
- Error and event logs are produced and monitored, and are protected against unauthorised access and tampering.
- Authentication secrets, including passwords, OAuth 2 clients and tokens, are securely managed.
Certifications
- ISO/IEC 27001
- SOC 2 Type II
13. Security Commitments and Documentation
TruthScan shall maintain the technical and organisational measures set out in Section 12 throughout the term of the Agreement and shall not materially diminish the overall level of protection during that term. TruthScan shall maintain its SOC 2 Type II and ISO/IEC 27001 certifications, or substantially equivalent certifications, throughout the term. TruthScan conducts regular vulnerability scanning and periodic penetration testing of the systems used to provide the services, and remediates identified material vulnerabilities on a risk-prioritised basis.
The Customer may satisfy any audit or inspection right under Applicable Data Protection Laws by reviewing TruthScan's then-current SOC 2 Type II report, ISO/IEC 27001 certificate and the information published at https://trust.truthscan.com. TruthScan will provide those materials on reasonable written request, no more than once in any twelve (12) month period, subject to confidentiality obligations. Nothing in this Section limits an audit right that cannot be limited under the SCCs where they apply. On-site audits are not available under a standard plan. They are available to enterprise customers under a separately negotiated agreement.
14. Liability
Each party's liability arising out of or related to this DPA, the processing of Personal Data and any Security Incident is subject to, and counts toward, the limitations and exclusions of liability set out in the Agreement. This DPA does not increase those limitations.
To the maximum extent permitted by law, neither party will be liable for any indirect, incidental, special, consequential, exemplary or punitive damages, or for loss of profits, revenue, goodwill or anticipated savings, arising out of or related to this DPA, even if advised of the possibility of such damages.
These exclusions and limitations do not limit (a) either party's liability for its own wilful misconduct or fraud, (b) the Customer's indemnification obligations under Section 9, or (c) liability that cannot be limited under applicable law.
Each party shall bear any administrative fines or regulatory penalties imposed on it, to the extent those fines or penalties arise from that party's own breach of this DPA or of Applicable Data Protection Laws.
16. Governing Law
This DPA is governed by and construed in accordance with the laws of the State of Delaware, without regard to its conflict-of-laws principles, consistent with the governing law provision of the Agreement. The Standard Contractual Clauses are governed by the laws of Ireland, and disputes arising under them are subject to the courts of Ireland, as set out in Section 11. Nothing in the dispute-resolution provisions of the Agreement limits the right of a data subject or supervisory authority to pursue any remedy or lodge any complaint in the forum required by the SCCs, the UK Addendum or Applicable Data Protection Laws.
17. Changes to this DPA
TruthScan may update this DPA from time to time, including to reflect changes in Applicable Data Protection Laws, its Subprocessors or its security measures. Where a change materially reduces the protections afforded to the Customer, TruthScan will provide at least thirty (30) Business Days' notice before it takes effect, by email to the Customer's account contact or by notice within the services. If the Customer objects to such a change on reasonable data protection grounds before it takes effect, the Customer may terminate the affected services by written notice to TruthScan, effective no later than the date the change takes effect. The current version is always published at https://trust.truthscan.com. This Section applies to the standard-plan DPA only. Enterprise addenda are amended by agreement between the parties.