Privacy Policy
Last updated: 12 July 2026
What we collect
The risk checker runs in your browser. Your answers are not sent to our servers unless you submit a form. When you request the PDF checklist or a consultant introduction, we collect your email address, checker answers, resulting risk tier, company name and system description when provided, and browser user-agent string.
Doc Pack customers submit questionnaire answers and receive generated documents behind an email-verified docs page. Monitoring customers also provide subscription details needed to link a public compliance page to a Doc Pack order.
If you use AI assist, only the field you choose to polish is sent to Groq after explicit consent. Do not include secrets in that field.
How we use it
We use submitted data to send requested checklists, deliver paid Doc Packs, verify access codes, operate Monitoring, answer support requests, prevent abuse, and keep audit records for security and billing integrity. Non-transactional follow-up emails are sent only when you explicitly opt in, and every such email includes an unsubscribe option.
Where it lives
Durable application records, rate limits, and short-lived locks are stored in Postgres. Redis/Upstash is not required for paid self-serve when Postgres is configured. Payments, card details, receipts, tax records, refunds, and chargebacks are handled by Paddle as merchant of record; we never see or store your card number. Plausible provides cookie-free analytics.
Operator details
| Contracting operator | Maximilian Hoffmann |
|---|---|
| Trading name | TrustPacket |
| Legal form / status | Individual operator / sole trader |
| Business registration | Not separately incorporated |
| Business address | 102 Dang Van Bi Street, Thu Duc District, Ho Chi Minh City, Vietnam |
| Contact email | hello@trustpacket.app |
Legal basis by purpose
| Purpose | Data | Legal basis |
|---|---|---|
| Requested checklists and lead emails | Email address, checker answers, company/system details if provided. | Steps taken at your request before a contract, consent for optional follow-up, and legitimate interest in answering inbound requests. |
| Doc Pack delivery | Questionnaire answers, generated document records, access-code hashes, delivery metadata. | Contract performance and legitimate interest in fraud prevention, access control, and audit integrity. |
| Monitoring | Subscription identifiers, linked Doc Pack records, public-page metadata, update history. | Contract performance and legitimate interest in maintaining an accurate subscription-gated service. |
| Payment, tax, refunds, and chargebacks | Buyer email, Paddle customer/transaction/subscription identifiers, invoice metadata. | Contract performance and legal obligations handled by Paddle as merchant of record. |
| Security, rate limits, and abuse prevention | IP/network metadata, user-agent, request metadata, rate-limit counters, audit logs. | Legitimate interest in protecting the service, customers, and paid entitlements. |
| Optional AI assist | Only the single text field you choose to send for wording improvement. | Consent. You can choose not to use AI assist and still complete the questionnaire. |
| Cookie-free analytics | Aggregated page-view and referrer metadata. | Legitimate interest in understanding product usage without cross-site tracking cookies. |
Personal data in your answers
Company names, contact emails, system descriptions, data-source descriptions, incident notes, and uploaded or pasted evidence fields may contain personal data if you include it. Do not include unnecessary personal data, special-category data, passwords, API keys, customer records, or confidential third-party material. If you choose to include personal data because it is necessary to describe your AI system, we process it only for the purposes described here.
Sub-processors
This table reflects the current production deployment profile. We publish provider, region, transfer, backup, and support-access information without exposing secret values, connection strings, or dashboard credentials. If a provider or region changes, this notice is updated.
| Provider / service | Purpose | Data | Primary processing | Transfer / backup / access |
|---|---|---|---|---|
| VercelVercel Inc. - hosting, serverless functions, static asset delivery, edge network. | Hosting, serverless functions, and static asset delivery. | HTTP requests, IP metadata, user-agent, server logs, static assets. | Vercel Functions: iad1 (Washington, D.C., USA). Static assets and CDN responses may be served from Vercel's global edge network. | Vercel DPA/subprocessors and SCCs where restricted transfers apply; traffic may traverse Vercel CDN/edge locations.Static deployment artifacts are replicated under Vercel deployment controls; no TrustPacket document database backup is stored in Vercel.Operator support/admin access may occur from Vietnam with role-limited dashboard access. |
| NeonNeon managed Postgres (via Vercel Storage integration). | Durable application records, rate limits, short-lived locks, customers, orders, subscriptions, leads, access codes, and audit logs. | Customer emails, questionnaire answers, generated document records, payment/subscription identifiers, access-code hashes, audit events, rate-limit counters. | AWS US East (N. Virginia) - Neon region us-east-1. | Neon platform terms/DPA and subprocessors; restricted transfers rely on SCCs where applicable, with TLS in transit and encryption at rest.Neon provider-managed restore/backup data for the database project; no separate TrustPacket backup replica is configured.Operator support/admin access may occur from Vietnam with role-limited dashboard access. |
| ResendResend - transactional email delivery. | Transactional email delivery for checklists, access links, receipts, and admin links. | Email address, email body, access links/codes, delivery metadata. | United States primary processing operations for email delivery. | Resend DPA/subprocessors and EU SCCs for ex-EEA transfers where applicable.Resend-managed delivery logs and metadata under its service settings; no separate TrustPacket email backup is configured.TrustPacket operator access to delivery status in the Resend dashboard. |
| PaddlePaddle - merchant of record for checkout, billing, tax invoices, refunds, and chargebacks. | Payments, subscriptions, receipts, taxes, refunds, and invoices as merchant of record. | Buyer email, billing details, transaction/subscription identifiers, tax and invoice records. Card numbers are handled by Paddle, not TrustPacket. | Paddle merchant-of-record infrastructure and payment subprocessors, including UK, EU, and United States operations as applicable. | Paddle merchant-of-record terms/DPA and SCCs for restricted transfers where applicable.Paddle-retained tax, invoice, and payment records under Paddle legal obligations.TrustPacket can view Paddle transaction/subscription status, not raw card numbers. |
| PlausiblePlausible Analytics - cookie-free web analytics. | Cookie-free product analytics. | Page views, referrers, device/browser aggregates, anonymized analytics metadata. | Germany (EU-owned infrastructure). | EEA processing for visitor analytics; Plausible does not store raw IP addresses or user-agent strings.Plausible-managed analytics retention/backups in Germany/EU infrastructure.TrustPacket operator access to aggregate analytics dashboard. |
| GroqGroq API - optional AI assist provider. | Optional AI assist for polishing a field when the user explicitly consents. | Only the single text field submitted to AI assist; users are instructed not to include secrets. | United States. Retained customer data is stored in GCP buckets in the US; inference customer data is not retained by default. | Explicit user consent for optional AI assist plus Groq DPA/SCCs where applicable; no TrustPacket model training.No TrustPacket backup. Groq may retain limited reliability and abuse-prevention logs up to 30 days unless zero-data-retention terms apply.TrustPacket does not provide Groq with broad account access to customer documents.Only used when AI assist is enabled. |
Retention
- Leads and checker submissions are retained for 90 days by default unless you opt in to ongoing updates.
- Requested access codes expire after 15 minutes; initial delivery codes expire after 24 hours.
- Doc Pack inputs and generated documents are retained for service and support; deletion requests are completed within 72 hours except Paddle tax and invoice records.
- Public compliance pages remain visible during a 30-day grace period after cancellation or pause.
- Retained by Paddle as merchant of record under its legal and tax obligations.
International transfers
TrustPacket is operated from Vietnam and uses the subprocessors listed above. The current production profile includes United States processing for Vercel functions, Neon Postgres, Resend email, Paddle billing, and optional Groq AI assist; Germany/EU processing for Plausible analytics; and operator support access from Vietnam. Where GDPR transfer rules apply, transfers rely on provider data-processing terms, adequacy decisions where available, or appropriate safeguards such as standard contractual clauses where applicable. Optional AI assist is sent only after explicit user consent.
EU representative assessment
TrustPacket is not currently publishing an appointed EU representative. Before materially increasing EU customer volume, we will obtain an assessment from qualified privacy counsel of whether a GDPR Article 27 representative is required for the service scope, customer volume, and processing risk profile. Until any representative is appointed, privacy requests should be sent directly to the contact email below.
Your rights (GDPR)
You can request access to, correction of, deletion of, restriction of, or portability of your personal data, and you can object to processing based on legitimate interests. Where processing is based on consent, you can withdraw consent at any time without affecting prior lawful processing. We complete deletion requests within 72 hours for TrustPacket-controlled records, except Paddle tax and invoice records that Paddle must retain as merchant of record. You also have the right to lodge a complaint with a data protection supervisory authority in the EU/EEA member state where you live, work, or where the alleged infringement occurred. We do not sell your data.
Automated decision-making
TrustPacket does not use automated decision-making with legal or similarly significant effects under GDPR Article 22. The checker produces an informational self-assessment from your answers. Paid entitlement checks are automated access-control steps based on Paddle payment status and do not determine legal rights or compliance status.
Whether data is required
You can use the free checker without submitting personal data. Email delivery, Doc Pack generation, Monitoring activation, support, refunds, and deletion requests require enough information to provide the requested service, verify ownership, and prevent abuse. If you do not provide required information, those features may not work.
Contact
Email hello@trustpacket.app for any privacy question or request.