← All legal documents
Data Processing Agreement · Version 1.0 · Required document
Published 2026-09-03 · Effective 2026-09-22 · Approved by Hyun Kyu Han, Director on 2026-09-01
Permanent version link: /legal/dpa/1.0

Trine Data Processing Agreement

Document key: trine-dpa Version: 1.0 Status: Published Approved by: Hyun Kyu Han, Director Approved on: 1 September 2026 Published: recorded in the legal registry at publication Effective: 19 days after publication Published at: https://trine.uk/legal/dpa

UK GDPR Article 28(3) requires a written contract containing the terms below. Clauses 3 to 11 and the Annexes exist to satisfy that requirement and should not be trimmed without advice. Annex 2 describes controls that are actually in place; anything not implemented has been stated as such rather than omitted or overstated.

1. Parties and roles

1.1 This Data Processing Agreement ("DPA") forms part of the Agreement between Purinode Ltd (company number 17395630), operator of the Trine platform ("Processor", "we") and the Provider ("Controller", "you").

1.2 In relation to Provider Data, you are the controller and we are the processor.

1.3 In relation to account administration, authentication, billing, support correspondence and platform security telemetry, we act as an independent controller. That processing is described in our Privacy Notice and is outside the scope of clauses 3 to 11.

1.4 "Data Protection Law" means the UK GDPR, the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations 2003, each as amended or replaced.

1.5 Purinode Ltd is registered with the Information Commissioner's Office under registration reference ZC235279. Our privacy lead is Hyun Kyu Han, Director, contactable at [email protected]. We have assessed whether we are required to appoint a statutory Data Protection Officer under Article 37, and our current determination, made using the Information Commissioner's Office screening guidance, is that we are not. That determination is recorded in our governance register and is reviewed at least annually and on any material change in the scale of processing.

2. Duration

2.1 This DPA applies for as long as we process Provider Data, and survives termination of the Agreement until deletion is complete under clause 10.

3. Processing instructions

3.1 We will process Provider Data only on your documented instructions, unless required to do otherwise by law. Where we are so required, we will inform you before processing unless the law prohibits it.

3.2 Your documented instructions comprise: the Agreement, this DPA, your configuration and use of the platform, and any further written instruction you give that we accept.

3.3 We will inform you if, in our opinion, an instruction infringes Data Protection Law.

3.4 We will not sell Provider Data, use it for our own marketing, or disclose it other than as permitted by this DPA.

3.5 We will not use Provider Data to train machine learning models. No AI or transcription service is engaged as a sub-processor at the date of this version. If one is engaged, it will be added to Annex 3 under the notice procedure in clause 7 and will be contractually prohibited from retaining or training on Provider Data.

4. Details of processing

4.1 The subject matter, duration, nature and purpose of processing, the types of personal data and the categories of data subjects are set out in Annex 1.

5. Confidentiality

5.1 We will ensure that persons authorised to process Provider Data are subject to an appropriate duty of confidence, whether contractual or statutory.

5.2 Access to Provider Data by our personnel is limited to those who need it to provide, support or secure the platform, and is logged.

6. Security

6.1 We will implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the nature of the data, which includes special category data and information relating to vulnerable adults.

6.2 The measures in place are described in Annex 2. We may update them, provided the level of protection is not reduced.

7. Sub-processors

7.1 You give general written authorisation for us to engage sub-processors.

7.2 The sub-processors engaged at the date of this DPA are listed in Annex 3.

7.3 We will give at least 30 days' notice before adding or replacing a sub-processor, by email to your registered administrator and by updating Annex 3.

7.4 You may object on reasonable data protection grounds within that notice period. If we cannot resolve your objection, you may terminate the affected subscription without penalty and receive a refund of prepaid fees for the unexpired period.

7.5 We remain liable to you for the acts and omissions of our sub-processors, and will impose on them data protection obligations no less protective than those in this DPA.

8. International transfers

8.1 Provider Data held in the Trine application and its file storage is stored at rest in the United Kingdom (Microsoft Azure, UK South).

8.2 Transactional email sent by the platform is processed in the United States by our email sub-processor. That processing is covered by the transfer mechanism stated in Annex 3 and by a transfer risk assessment we maintain and review.

8.3 Where any sub-processor processes Provider Data outside the UK, we will ensure a valid transfer mechanism is in place, being UK adequacy regulations, the International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses, together with any supplementary measures identified by the transfer risk assessment.

8.4 The location and transfer mechanism applicable to each sub-processor is stated in Annex 3.

9. Assistance

9.1 Data subject rights. Taking into account the nature of the processing, we will assist you by appropriate technical and organisational measures in responding to requests to exercise data subject rights. Where a request is made directly to us, we will not respond to it substantively but will refer it to you without undue delay.

9.2 Personal data breach. We will notify you of a personal data breach affecting Provider Data without undue delay and, where reasonably practicable, within 24 hours of becoming aware of it. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed. Where full information is not available, we will provide it in phases.

9.3 We will not notify the Information Commissioner or data subjects on your behalf unless you instruct us to do so in writing.

9.4 DPIAs and prior consultation. We will provide reasonable assistance with data protection impact assessments and prior consultation with the ICO, so far as they relate to our processing and taking into account the information available to us.

10. Return and deletion

10.1 On termination, you may obtain an export of Provider Data as described in the Cancellation and Data Export Policy.

10.2 Deletion is currently performed manually by us against a documented procedure rather than by an automated workflow. This does not reduce our obligation to delete.

10.3 After the export window closes, we will delete Provider Data from the active platform within 30 days and will confirm deletion in writing.

10.4 Deleted data persists in backups until those expire on their normal cycle. Point-in-time recovery data is retained for 35 days and database dumps for 30 days, so in normal operation backup copies of deleted data expire within 90 days of deletion. The single most recent database dump is always retained so that recoverability is never lost, and where scheduled backups have stopped running that dump persists beyond 30 days until backups resume. We do not restore deleted Provider Data from backup except in a disaster recovery scenario.

10.5 Where we are required by law to retain any Provider Data, we will inform you what is retained and why, and will continue to protect it under this DPA.

11. Audit

11.1 We will make available to you the information reasonably necessary to demonstrate compliance with Article 28 of the UK GDPR.

11.2 We will allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate, on reasonable notice, no more than once in any 12-month period unless there has been a personal data breach affecting your data or a regulator requires it.

11.3 Audits must be conducted during business hours, must not unreasonably disrupt our operations, and are subject to confidentiality. You will bear your own costs and, where an audit requires more than one working day of our time, our reasonable costs.

11.4 We may satisfy an audit request by providing current security documentation or an independent assessment where that reasonably addresses the scope of the request.

12. Liability

12.1 Liability under this DPA is subject to the limitations in clause 13 of the Terms and Conditions, including the separate cap at clause 13.4, save to the extent those limitations are not permitted by Data Protection Law.


Annex 1 — Details of processing

Subject matter. Provision of the Trine care compliance and operations platform.

Duration. For the term of the Agreement, plus the export and deletion periods in clause 10.

Nature of processing. Collection, recording, organisation, structuring, storage, retrieval, consultation, use, transmission, restriction, erasure and destruction, carried out by automated means within the platform.

Purpose. To enable the Controller to maintain staff and candidate records, recruitment and pre-employment checks, training and supervision records, compliance documents, routine checks, meetings, incidents, complaints, safeguarding matters, risk records and related operational information.

Categories of data subject.

  • Employees, workers, agency and bank staff of the Controller
  • Job applicants and candidates
  • Referees nominated by candidates
  • Residents and service users of the Controller
  • Relatives, representatives and next of kin of residents, where recorded
  • Visiting professionals and contractors, where recorded
  • Complainants and other individuals named in incident, complaint or safeguarding records

Types of personal data.

  • Identity and contact data: name, date of birth, address, telephone, email, photograph
  • Employment data: role, employment dates, contract terms, absence and leave, supervision and appraisal records, disciplinary records
  • Recruitment data: application details, interview records, references, right-to-work documentation
  • Training and qualification data
  • Special category data: health information relating to staff (including fitness to work, occupational health and absence reasons) and to residents (including care needs, conditions, treatment and incidents); where recorded, information revealing racial or ethnic origin or religious belief
  • Criminal offence data: DBS check outcomes and related declarations
  • Records of incidents, accidents, complaints, safeguarding concerns and risk assessments, which may contain information about the health, welfare and behaviour of residents and staff
  • Documents and files uploaded by the Controller, the content of which is determined by the Controller

Special note. The Controller determines what is uploaded. The Processor does not require, and does not ask for, resident-identifiable clinical records beyond what is necessary for the Controller's own record-keeping.


Annex 2 — Technical and organisational measures

Certification

  • Purinode Ltd holds Cyber Essentials certification, scoped to the whole organisation, certificate number 6fcde322-bedf-487a-839b-e6977a72f9ed, certified 1 September 2026 and valid until 1 September 2027. Certification body: Delta Cyber Security, under the IASME Consortium

Hosting and infrastructure

  • Application, database and file storage hosted on Microsoft Azure, UK South region
  • Data at rest for the application and its file storage remains in the United Kingdom

Encryption

  • TLS 1.2 or above enforced at the edge
  • require_secure_transport enabled on the database, so unencrypted database connections are rejected
  • Azure platform-managed encryption at rest for disks and storage accounts, with a minimum TLS version of 1.2 enforced on storage
  • We do not currently use customer-managed keys and do not apply application-level field encryption. Encryption at rest is single-layer and platform-managed

Access control

  • Role-based access enforced server-side; tenant scope resolved from membership rather than from client-supplied identifiers
  • Job-title-derived access levels with delegated additional permissions
  • Two-factor authentication is available to users on an opt-in basis. It is not currently enforced
  • Administrative access to production is limited to named individuals

Segregation

  • Logical tenant separation with server-side scope checks on every request
  • Cross-company and cross-care-home access denied by default and covered by regression tests

File and token handling

  • Path containment enforced on uploaded files
  • Authenticated access required for private documents
  • Candidate portal access uses scoped, time-limited tokens stored as SHA-256 hashes at rest. Candidate links have a default lifetime of 30 days, configurable by the provider between 1 and 90 days, and are automatically extended where necessary so that a link remains valid until the onboarding deadline it relates to. Links can be revoked and reissued by the provider
  • Password reset links and account set-up and invitation links expire after 72 hours. Certain administratively initiated resets use a 60-minute link. All such links are single use and are superseded when a new link is issued. Requests do not disclose whether an account exists

Logging and audit

  • Append-only audit log of material actions
  • Secrets, tokens, payment data and document contents excluded from logs
  • Audit records retained as set out in the Data Retention Policy

Backup and resilience

  • Daily database dump at 05:00 UTC, retained for 30 days
  • Point-in-time recovery retained for 35 days
  • Restore procedure last proven on 6 June 2026

Development and change control

  • Code review before merge
  • Automated regression suites covering access scope, billing and compliance behaviour
  • Separation of development and production environments; production data not used in development

Personnel

  • Confidentiality obligations for all personnel with access to Provider Data
  • Data protection awareness training is completed annually by the director, using Information Commissioner's Office materials, and is recorded with its date in our governance register. Any further personnel must complete it before being granted access to Provider Data

Incident response

  • Documented breach identification, escalation and notification process supporting the commitment in clause 9.2

Annex 3 — Sub-processors

Sub-processorPurposeLocation of processingTransfer mechanism
Microsoft Corporation / Microsoft Ireland Operations Ltd (Microsoft Azure)Application, database and file storage hostingUnited Kingdom (UK South)Not applicable — UK processing
AC PM LLC (Postmark)Transactional email deliveryUnited StatesEU-U.S. Data Privacy Framework, UK Extension. The UK Addendum to the EU Standard Contractual Clauses applies as an alternative where required, incorporated by reference into Postmark's Data Processing Addendum
Stripe Payments Europe LtdPayment processing. Engaged only where paid billing is enabled on your accountGlobal, including the United States. Stripe does not offer UK or EEA data residencyUK International Data Transfer Addendum, incorporated into Stripe's Data Transfers Addendum

Postmark note. Postmark's Data Processing Addendum is incorporated into its Terms of Service and applies automatically; no separate execution is required. Message content and activity data are stored for 45 days. This is the standard retention period on our plan and cannot currently be reduced. Transactional emails may contain time-limited access links, and a link may remain valid for part of that retention period. Passwords are never sent by email.

Stripe. Stripe acts as an independent controller in respect of payment card data. We do not receive or store full card details.

Not sub-processors. Google Workspace is used for our own business email and identity and does not process Provider Data. No AI or transcription service is engaged.