Data processing addendum
Last updated 26 September 2026. This addendum (DPA) forms part of the agreement between Triad Global, LLC (Triad) and the customer that uses Triad Core (Customer). It applies when Triad processes personal data on Customer's behalf. If it conflicts with the agreement on data protection, this DPA wins. The English text governs.
1. Roles and scope
Customer is the controller (in Korea, the personal information controller; in Israel, the database owner) of the personal data it and its users put into Triad Core (Customer Personal Data). Triad is its processor (entrusted party, holder, service provider). Triad processes Customer Personal Data only to provide, secure and support Triad Core under the agreement and Customer's documented instructions, which are the agreement, this DPA and Customer's use and configuration of the service. Triad tells Customer if it believes an instruction breaks the law.
2. Details of the processing
- Subject matter and duration: hosting and operating Triad Core for the term of the agreement, plus the return and deletion period in section 9.
- Nature and purpose: storage, organisation, retrieval, display, transmission (including email and portal links Customer sends), backup, and, when Customer switches it on, analysis by Triad AI.
- Data subjects: Customer's users, employees and contractors; its customers', suppliers' and other business contacts' staff; signers of documents; people in emails filed or sent through connected mailboxes.
- Categories of data: identification and business contact details; transaction and document records; notes, files, photos and chat; email content and metadata of connected mailboxes; e-signature evidence (typed name, drawn signature, IP, browser, time); account and security logs; and, where the HR module is used, employment, working time, leave, training, pay and national identity numbers.
- Special or sensitive categories: not required by the service. If Customer chooses to store them (for example health information in leave records), Customer is responsible for its legal basis and Triad applies the same security measures.
3. Confidentiality
Triad limits access to Customer Personal Data to personnel and contractors who need it to provide the service and who are bound by confidentiality. Triad staff do not open a workspace except to provide support Customer asked for, to keep the service secure, or when the law requires it.
4. Security
Triad maintains the technical and organisational measures described at /legal/security, including encryption in transit and at rest, logical separation of each customer at the database level, role-based access, an append-only audit trail, backups with point-in-time recovery, and incident response. Triad may improve these measures but will not materially reduce their overall protection during the term.
5. Sub-processors
Customer gives general authorisation for the sub-processors listed at /legal/subprocessors. Triad gives Customer at least 30 days' notice (by email to Customer's administrators or in the service) before adding or replacing a sub-processor that processes Customer Personal Data. Customer may object on reasonable data protection grounds within that period; the parties will discuss a solution in good faith, and if none is found Customer may end the affected part of the service and receive a pro-rata refund of prepaid fees for it. Triad binds each sub-processor to data protection terms no less protective than this DPA and remains responsible for its sub-processors.
6. Help with rights, assessments and authorities
Triad gives Customer tools in the service to access, correct, export and delete Customer Personal Data, and helps Customer, at Customer's reasonable cost for work beyond those tools, to answer data subject requests, carry out data protection impact assessments and consult authorities. Triad forwards to Customer any request it receives from a data subject about Customer Personal Data and does not answer it itself unless Customer asks or the law requires.
7. Personal data breaches
Triad notifies Customer without undue delay, and in any case within 48 hours, after becoming aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Customer Personal Data. The notice describes, as far as then known, what happened, the data and people concerned, likely consequences and the measures taken. Triad takes reasonable steps to contain the breach and helps Customer meet its own notification duties (for example 72 hours to an EU authority, or notice to the Korean PIPC and the people concerned). A notice is not an admission of fault.
8. International transfers
Customer Personal Data is stored in the United States (Google Cloud, us-east4). Customer authorises this transfer.
European Economic Area, United Kingdom and Switzerland: the Standard Contractual Clauses of the European Commission (Decision 2021/914), Module 2 (controller to processor) and, where Customer is itself a processor, Module 3, are incorporated by reference with Annex I taken from section 2 of this DPA, Annex II from /legal/security and Annex III from /legal/subprocessors; clause 7 (docking) applies, clause 9 option 2 (general authorisation, 30 days), clause 11 optional language does not apply, clauses 17 and 18: the law and courts of Ireland. For UK data the UK International Data Transfer Addendum applies, and for Swiss data the Clauses apply with the FDPIC as authority.
Republic of Korea: Customer relies on entrustment and overseas transfer under PIPA Articles 26 and 28-8 and discloses to its data subjects the recipient (Triad Global, LLC and Google LLC), the country (United States), the items, the time and method of transfer, the purpose and the retention period, as set out in the privacy notice. Triad processes Korean personal data only for the entrusted purpose, applies the protective measures of this DPA, accepts Customer's supervision under Article 26(4) through the reports in section 10, and does not further entrust it except to the listed sub-processors.
Israel: Triad complies with the Protection of Privacy Regulations (Data Security) 2017 as a holder, keeps Customer Personal Data only for the agreement's purposes, and returns or deletes it as set out below.
9. Return and deletion
During the term Customer can export its records at any time. Within 30 days after the agreement ends, Triad deletes Customer Personal Data from the live service, after giving Customer the chance to export it during that period; backups roll off within 7 days after that. Triad may keep data the law requires it to keep, protected under this DPA and only for that purpose. On request Triad confirms deletion in writing.
10. Audits
Triad makes available the information reasonably needed to show compliance with this DPA: its security description, answers to a reasonable security questionnaire once a year, and the independent reports of its hosting provider (Google Cloud SOC 2 and ISO 27001). Where these do not answer a regulator's demand or a documented concern after a breach, Customer (or an independent auditor bound by confidentiality) may audit Triad on 30 days' notice, during business hours, at Customer's cost, no more than once a year.
11. Liability and order of precedence
Each party's liability under this DPA is subject to the limits in the agreement, except where the law does not allow a limit. For the Standard Contractual Clauses, the Clauses win over this DPA and the agreement. Otherwise this DPA wins over the agreement on data protection.
12. Contact
Triad privacy contact: office@triadglobal.org, subject "Data protection". Customer names its contact in the agreement or in the service settings.