Data processing addendum
Last updated 2 October 2026. Part of the Terms of Service; applies automatically, no signature needed.
1. Parties and scope
This addendum is part of the Terms of Service between Sayan Bhattacharya, trading as Triagic ("Triagic") and the Customer. It applies whenever Triagicprocesses personal data on the Customer's behalf in providing the Service ("Customer Personal Data"). For that data, the Customer is the data fiduciary (controller) and Triagic is the data processor. If this addendum and the Terms conflict, this addendum wins for Customer Personal Data.
It is written to meet India's Digital Personal Data Protection Act, 2023 and US state privacy laws, including the CCPA, that apply to the processing.
2. What we process
| Data subjects | The Customer's members, and the Customer's own customers and contacts who submit forms or send email. |
|---|---|
| Data | Names, email addresses and usernames; form submissions, email thread contents and attachments; any personal data in knowledge base documents or playbooks; IP addresses of form submitters (for bot checks); machine hostnames of the Customer's computers. |
| Purpose | Providing the Service: hosting forms and email threads, syncing configuration to the Customer's desktop apps, sending email. |
| Duration | The term of the Customer's account, plus the deletion period in section 8. |
Tickets, investigations and AI prompts processed by the desktop app stay on the Customer's computers and go directly to the Customer's chosen AI provider. Triagic does not receive them, so this addendum does not cover them.
3. Our obligations
Triagic will:
- process Customer Personal Data only on the Customer's documented instructions, which are the Terms, this addendum and the Customer's use of the Service, unless the law requires otherwise (in which case we will tell the Customer first, if the law allows);
- not sell or share it, not use it to train AI models, and not combine it with data from other sources;
- make sure anyone with access to it is bound by confidentiality;
- tell the Customer if we believe an instruction breaks the law.
4. Security
We maintain at least these measures:
- TLS for all traffic; encryption at rest by our database and storage providers.
- AES-256-GCM application-level encryption for stored credentials, API keys and email provider secrets.
- Passwords hashed with argon2id; passkey support; sessions that expire after 12 hours and end on password change.
- Attachments in private storage, served only to signed-in members of the owning organization.
- Organization isolation enforced on every request; an audit log of administrative actions.
- Access to production systems limited to the operator of Triagic.
5. Subprocessors
The Customer authorizes the subprocessors on our subprocessors page. We bind each one to data protection terms at least as protective as this addendum and remain responsible for its performance. We will update that page and email account owners at least 30 days before adding or replacing a subprocessor. The Customer may object on reasonable data protection grounds within that period; if we cannot address the objection, the Customer may cancel and we will refund prepaid fees for the period after cancellation.
6. International transfers
Customer Personal Data is stored in the United States. The Customer agrees to this transfer. We will stop transferring data to any country the Government of India restricts under the DPDP Act.
7. Breaches
We will notify the Customer within 72 hours of becoming aware of a personal data breach affecting Customer Personal Data. The notice will describe what happened, the data and people affected, and the steps we are taking, and we will update it as we learn more. We will help the Customer meet its own obligations to notify the Data Protection Board of India and affected people.
8. Deletion and return
The Customer can delete form submissions, threads and other content in the portal or set automatic retention. When the account ends, or on request to hello@triagic.com, we will delete Customer Personal Data within 30 days, and it leaves database restore history within a further 7 days, unless the law requires us to keep it. Before deletion, the Customer can ask us for a copy of its data.
9. Assistance and audits
We will help the Customer, taking into account the nature of the processing, respond to requests from people exercising their rights, and will pass on any such request we receive directly. On reasonable written request, no more than once a year, we will answer the Customer's security questionnaire and provide the information needed to show we comply with this addendum.
10. Liability
The limitation of liability in the Terms of Service applies to this addendum.