Legal
Data Processing Addendum
Last updated 28 September 2026
This addendum forms part of the Terms of Service. It applies where SaaSili Ltd ("we") processes personal data for a customer ("you") under UK GDPR Article 28. You are the controller and we are the processor.
1.Subject matter and duration
We process personal data to provide Trugap to you, for as long as your account is active and until the data is deleted or returned under section 12.
2.Nature and purpose
Storing, organising, scoring and displaying deal and inspection content, and sending it to an AI model to generate analysis after scoring.
3.Types of personal data
- Business contact details of buyer contacts: names, job titles, employers, business email addresses and phone numbers, and notes about their role in a deal.
- Seller account data: names, email addresses, roles and activity within the workspace.
4.Categories of data subjects
- Your buyer contacts and other people named in deals.
- Your users of Trugap.
5.Your instructions
We process personal data only on your documented instructions, which are these terms and your use of the product. If we think an instruction breaks data protection law, we will tell you.
6.Confidentiality
Everyone we authorise to process the data is bound by a duty of confidentiality.
7.Security
We keep appropriate technical and organisational measures in place, including database-level access rules that keep each workspace's data separate, and role-based access within a workspace. Data is encrypted in transit using TLS and at rest. Access to production data is restricted to authorised personnel, and database access is controlled by row-level security.
8.Sub-processors
You authorise the sub-processors listed in our Privacy Policy. We will give you notice of any new sub-processor before it starts processing your data, and you may object. We put data protection terms in place with each sub-processor and remain responsible for them.
Notice period: 30 days' notice by email, with the right to object.
9.Help with requests
We will help you respond to requests from data subjects exercising their rights, and with security, breach notification, impact assessments and consultation with the ICO, taking into account the nature of the processing.
10.Personal data breaches
We will tell you without undue delay, and in any event within 48 hours of becoming aware of a personal data breach affecting your data, and give you the information you need to meet your own obligations.
11.Audit information
We will make available the information reasonably needed to show we meet Article 28, and allow for reasonable audits on reasonable notice.
12.Deletion or return
When the service ends, at your choice we will return or delete your personal data, unless the law requires us to keep it.
13.International transfers
Where personal data is transferred outside the UK, we rely on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or the UK-US Data Bridge where the recipient is certified under it.