Document key: trine-dpa Version: 1.0 Status: Published Approved by: Hyun Kyu Han, Director Approved on: 1 September 2026 Published: recorded in the legal registry at publication Effective: 19 days after publication Published at: https://trine.uk/legal/dpa
UK GDPR Article 28(3) requires a written contract containing the terms below. Clauses 3 to 11 and the Annexes exist to satisfy that requirement and should not be trimmed without advice. Annex 2 describes controls that are actually in place; anything not implemented has been stated as such rather than omitted or overstated.
1.1 This Data Processing Agreement ("DPA") forms part of the Agreement between Purinode Ltd (company number 17395630), operator of the Trine platform ("Processor", "we") and the Provider ("Controller", "you").
1.2 In relation to Provider Data, you are the controller and we are the processor.
1.3 In relation to account administration, authentication, billing, support correspondence and platform security telemetry, we act as an independent controller. That processing is described in our Privacy Notice and is outside the scope of clauses 3 to 11.
1.4 "Data Protection Law" means the UK GDPR, the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations 2003, each as amended or replaced.
1.5 Purinode Ltd is registered with the Information Commissioner's Office under registration reference ZC235279. Our privacy lead is Hyun Kyu Han, Director, contactable at [email protected]. We have assessed whether we are required to appoint a statutory Data Protection Officer under Article 37, and our current determination, made using the Information Commissioner's Office screening guidance, is that we are not. That determination is recorded in our governance register and is reviewed at least annually and on any material change in the scale of processing.
2.1 This DPA applies for as long as we process Provider Data, and survives termination of the Agreement until deletion is complete under clause 10.
3.1 We will process Provider Data only on your documented instructions, unless required to do otherwise by law. Where we are so required, we will inform you before processing unless the law prohibits it.
3.2 Your documented instructions comprise: the Agreement, this DPA, your configuration and use of the platform, and any further written instruction you give that we accept.
3.3 We will inform you if, in our opinion, an instruction infringes Data Protection Law.
3.4 We will not sell Provider Data, use it for our own marketing, or disclose it other than as permitted by this DPA.
3.5 We will not use Provider Data to train machine learning models. No AI or transcription service is engaged as a sub-processor at the date of this version. If one is engaged, it will be added to Annex 3 under the notice procedure in clause 7 and will be contractually prohibited from retaining or training on Provider Data.
4.1 The subject matter, duration, nature and purpose of processing, the types of personal data and the categories of data subjects are set out in Annex 1.
5.1 We will ensure that persons authorised to process Provider Data are subject to an appropriate duty of confidence, whether contractual or statutory.
5.2 Access to Provider Data by our personnel is limited to those who need it to provide, support or secure the platform, and is logged.
6.1 We will implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the nature of the data, which includes special category data and information relating to vulnerable adults.
6.2 The measures in place are described in Annex 2. We may update them, provided the level of protection is not reduced.
7.1 You give general written authorisation for us to engage sub-processors.
7.2 The sub-processors engaged at the date of this DPA are listed in Annex 3.
7.3 We will give at least 30 days' notice before adding or replacing a sub-processor, by email to your registered administrator and by updating Annex 3.
7.4 You may object on reasonable data protection grounds within that notice period. If we cannot resolve your objection, you may terminate the affected subscription without penalty and receive a refund of prepaid fees for the unexpired period.
7.5 We remain liable to you for the acts and omissions of our sub-processors, and will impose on them data protection obligations no less protective than those in this DPA.
8.1 Provider Data held in the Trine application and its file storage is stored at rest in the United Kingdom (Microsoft Azure, UK South).
8.2 Transactional email sent by the platform is processed in the United States by our email sub-processor. That processing is covered by the transfer mechanism stated in Annex 3 and by a transfer risk assessment we maintain and review.
8.3 Where any sub-processor processes Provider Data outside the UK, we will ensure a valid transfer mechanism is in place, being UK adequacy regulations, the International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses, together with any supplementary measures identified by the transfer risk assessment.
8.4 The location and transfer mechanism applicable to each sub-processor is stated in Annex 3.
9.1 Data subject rights. Taking into account the nature of the processing, we will assist you by appropriate technical and organisational measures in responding to requests to exercise data subject rights. Where a request is made directly to us, we will not respond to it substantively but will refer it to you without undue delay.
9.2 Personal data breach. We will notify you of a personal data breach affecting Provider Data without undue delay and, where reasonably practicable, within 24 hours of becoming aware of it. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed. Where full information is not available, we will provide it in phases.
9.3 We will not notify the Information Commissioner or data subjects on your behalf unless you instruct us to do so in writing.
9.4 DPIAs and prior consultation. We will provide reasonable assistance with data protection impact assessments and prior consultation with the ICO, so far as they relate to our processing and taking into account the information available to us.
10.1 On termination, you may obtain an export of Provider Data as described in the Cancellation and Data Export Policy.
10.2 Deletion is currently performed manually by us against a documented procedure rather than by an automated workflow. This does not reduce our obligation to delete.
10.3 After the export window closes, we will delete Provider Data from the active platform within 30 days and will confirm deletion in writing.
10.4 Deleted data persists in backups until those expire on their normal cycle. Point-in-time recovery data is retained for 35 days and database dumps for 30 days, so in normal operation backup copies of deleted data expire within 90 days of deletion. The single most recent database dump is always retained so that recoverability is never lost, and where scheduled backups have stopped running that dump persists beyond 30 days until backups resume. We do not restore deleted Provider Data from backup except in a disaster recovery scenario.
10.5 Where we are required by law to retain any Provider Data, we will inform you what is retained and why, and will continue to protect it under this DPA.
11.1 We will make available to you the information reasonably necessary to demonstrate compliance with Article 28 of the UK GDPR.
11.2 We will allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate, on reasonable notice, no more than once in any 12-month period unless there has been a personal data breach affecting your data or a regulator requires it.
11.3 Audits must be conducted during business hours, must not unreasonably disrupt our operations, and are subject to confidentiality. You will bear your own costs and, where an audit requires more than one working day of our time, our reasonable costs.
11.4 We may satisfy an audit request by providing current security documentation or an independent assessment where that reasonably addresses the scope of the request.
12.1 Liability under this DPA is subject to the limitations in clause 13 of the Terms and Conditions, including the separate cap at clause 13.4, save to the extent those limitations are not permitted by Data Protection Law.
Subject matter. Provision of the Trine care compliance and operations platform.
Duration. For the term of the Agreement, plus the export and deletion periods in clause 10.
Nature of processing. Collection, recording, organisation, structuring, storage, retrieval, consultation, use, transmission, restriction, erasure and destruction, carried out by automated means within the platform.
Purpose. To enable the Controller to maintain staff and candidate records, recruitment and pre-employment checks, training and supervision records, compliance documents, routine checks, meetings, incidents, complaints, safeguarding matters, risk records and related operational information.
Categories of data subject.
Types of personal data.
Special note. The Controller determines what is uploaded. The Processor does not require, and does not ask for, resident-identifiable clinical records beyond what is necessary for the Controller's own record-keeping.
Certification
Hosting and infrastructure
Encryption
require_secure_transport enabled on the database, so unencrypted database connections are rejectedAccess control
Segregation
File and token handling
Logging and audit
Backup and resilience
Development and change control
Personnel
Incident response
| Sub-processor | Purpose | Location of processing | Transfer mechanism |
|---|---|---|---|
| Microsoft Corporation / Microsoft Ireland Operations Ltd (Microsoft Azure) | Application, database and file storage hosting | United Kingdom (UK South) | Not applicable — UK processing |
| AC PM LLC (Postmark) | Transactional email delivery | United States | EU-U.S. Data Privacy Framework, UK Extension. The UK Addendum to the EU Standard Contractual Clauses applies as an alternative where required, incorporated by reference into Postmark's Data Processing Addendum |
| Stripe Payments Europe Ltd | Payment processing. Engaged only where paid billing is enabled on your account | Global, including the United States. Stripe does not offer UK or EEA data residency | UK International Data Transfer Addendum, incorporated into Stripe's Data Transfers Addendum |
Postmark note. Postmark's Data Processing Addendum is incorporated into its Terms of Service and applies automatically; no separate execution is required. Message content and activity data are stored for 45 days. This is the standard retention period on our plan and cannot currently be reduced. Transactional emails may contain time-limited access links, and a link may remain valid for part of that retention period. Passwords are never sent by email.
Stripe. Stripe acts as an independent controller in respect of payment card data. We do not receive or store full card details.
Not sub-processors. Google Workspace is used for our own business email and identity and does not process Provider Data. No AI or transcription service is engaged.