Data Processing Addendum

Last updated September 11, 2026

TRICORN DATA PROCESSING ADDENDUM

Effective Date: September 11, 2026

The Tricorn Data Processing Addendum ("DPA") applies where Customer Data includes personal information subject to the GDPR, the UK GDPR, the Swiss FADP, PIPEDA or Quebec's Law 25, the Australian Privacy Act 1988, Brazil's LGPD, the CCPA/CPRA or similar United States state privacy laws, or similar laws, as described in Section 14.5 of the Tricorn Platform Terms of Service.

Requesting the DPA

The DPA is available on request. Email legal@gotricorn.com from the email address associated with your Customer account and state the Customer organization name. We will send the current DPA, including the EU Standard Contractual Clauses, the UK International Data Transfer Addendum and the Swiss adaptations where required for transfers, for signature.

What the DPA covers

  • The roles of the parties: Tricorn acts as processor of personal data contained in Customer Data and as controller of account, billing, and usage data, as described in Section 2 of the Privacy Policy.
  • Processing only on Customer's documented instructions, and the confidentiality, security, and personnel obligations that apply to Tricorn.
  • Subprocessors: the current list, the notice period for changes, and how to object, as published at /legal/subprocessors.
  • Assistance with data-subject requests, impact assessments, and regulator inquiries.
  • Security Incident notification without undue delay and no later than 72 hours after Tricorn determines that a Security Incident affecting Customer Data has occurred.
  • International transfer mechanisms.
  • Return and deletion of Customer Data at the end of the Services, consistent with Section 24 of the Terms of Service.

Questions

Privacy questions go to privacy@gotricorn.com. Contract questions go to legal@gotricorn.com.

Tricorn LLC, 18426 Livingston Ave, Suite 2, Lutz, Florida 33559, United States.