Legal

Data Processing Addendum

For customers with regulatory or compliance obligations under GDPR, CCPA, HIPAA, or sector-specific frameworks. The architecture below explains why Trekport sits outside most processor relationships, and how to put a counter-signed DPA in place when one is required.

Last updated · May 20, 2026

Trekport’s data processing model

Trekport Studio runs entirely on customer infrastructure. Source database credentials, schemas, table data, and migration output never leave the customer environment. As a consequence, Trekport is not a Data Processor for your migration data under most regulatory frameworks (GDPR Article 28, CCPA, and equivalents).

We are a Data Controller only for the limited information collected through trekport.sh (contact form, download lead capture) and the license-validation traffic from Trekport Studio. The full inventory is documented in our Privacy Policy.

What this means in practice

  • Migration data. No processor agreement is required between you and Trekport for migration data, because we never receive it.
  • Account and license data. We act as Controller and protect this data under the Privacy Policy.
  • Sensitive workloads. Trekport’s architecture is compatible with HIPAA, FedRAMP, PCI-DSS, and air-gapped government deployments. See the Security Policy for the technical controls.

Subprocessors

For website operations and customer communications, we use the following subprocessors. All process data under contractual controls equivalent to our own commitments.

  • Vercel. Website hosting and edge delivery. Processes request metadata and server-rendered responses for trekport.sh.
  • Resend. Transactional email delivery. Processes email addresses and the body of receipt, license, and security notification emails.
  • Cloudflare. Bot protection and DDoS mitigation on website forms. Processes IP addresses and browser fingerprints to score form submissions.
  • PostHog. Privacy-respecting product analytics for the website only. Session replay and autocapture are disabled.
  • Sentry. Error monitoring for the website and, opt-in, for the desktop application. Reports are pre-sanitized to exclude PII and customer database content.

Counter-signed DPA, BAA, and SCCs

Enterprise customers requiring a counter-signed Data Processing Addendum, a Business Associate Agreement under HIPAA, or Standard Contractual Clauses approved by the European Commission can request one. The Trekport team will work with your legal team to put it in place. Most engagements close within one review cycle because there is no migration-data sharing to negotiate over.

Data subject requests

Requests under GDPR, CCPA, or other privacy regulations can be submitted to privacy@trekport.sh. We respond to verified requests within 30 days. Because Trekport does not process migration data, requests typically scope only to website contact records and account or license metadata.