Most customers accept this DPA by ticking the checkbox during onboarding. It applies to all personnel and business data you process through Trayd, and sits alongside our Privacy Policy, which covers the data Trayd controls in its own right.
01Interpretation and definitions
In this DPA, the following terms have the meanings set out below. Terms defined in the GDPR and not defined here carry the meaning given to them in the GDPR.
| Term | Meaning |
|---|---|
| Controller | has the meaning given in Article 4(7) GDPR, and refers to the Customer in this DPA. |
| Customer | the business or individual that has accepted the Trayd Terms of Service and is using the Trayd Platform. |
| Data Subject | an identified or identifiable natural person to whom Personal Data relates, including employees, apprentices, and tradespeople employed or engaged by the Customer. |
| GDPR | Regulation (EU) 2016/679 of the European Parliament and of the Council (the General Data Protection Regulation), as given effect in Irish law by the Data Protection Act 2018. |
| Personal Data | has the meaning given in Article 4(1) GDPR. |
| Personal Data Breach | has the meaning given in Article 4(12) GDPR. |
| Personnel Data | Personal Data relating to employees, apprentices, or tradespeople of the Customer that is processed through the Trayd Platform. |
| Platform | the Trayd software application and associated services made available to the Customer under the Terms of Service. |
| Principal Agreement | the Trayd Terms of Service accepted by the Customer at onboarding, as updated from time to time, which governs the commercial relationship between the parties. |
| Processor | has the meaning given in Article 4(8) GDPR, and refers to Trayd in this DPA. |
| Special Category Data | Personal Data revealing health information, including sick leave records, as defined in Article 9 GDPR. |
| Sub-processor | any third-party processor engaged by Trayd to carry out processing activities on behalf of the Customer. |
| Supervisory Authority | the Data Protection Commission of Ireland (DPC), or any successor body. |
02Subject matter and duration
2.1 Trayd processes Personal Data on behalf of the Customer strictly for the purpose of providing the Platform and the services described in the Principal Agreement.
2.2 Processing shall commence on the date the Customer accepts this DPA (or the Terms of Service incorporating it) and shall continue for as long as the Customer has an active account on the Platform, unless terminated earlier in accordance with the Principal Agreement.
2.3 The subject matter, nature, purpose, duration, types of Personal Data, and categories of Data Subjects are set out in Schedule 1 to this DPA.
03Acceptance
3.1 For the majority of Customers, acceptance of this DPA is given by ticking the acceptance checkbox presented during the Trayd onboarding flow. This constitutes a binding agreement between the Customer and Trayd for the purposes of Article 28 GDPR. Trayd records the version of this DPA accepted and the date of acceptance.
3.2 Where a Customer requires a separately executed copy of this DPA (for example, for enterprise procurement purposes), it may be executed by authorised signatories. Contact info@trayd.ie to request a signature copy.
3.3 By accepting this DPA, the Customer confirms that it is authorised to act as Controller in respect of the Personnel Data it provides to Trayd, and that it has a lawful basis for processing that data under the GDPR.
04Obligations of the Controller
4.1 The Customer shall ensure that it has a lawful basis for processing all Personal Data it provides to Trayd and that it has complied with all applicable data protection obligations before instructing Trayd to process that data.
4.2 The Customer shall inform its employees and other Data Subjects of the processing carried out through the Platform, including by reference to a privacy notice that meets the requirements of Articles 13 and 14 GDPR. This includes Personal Data captured incidentally in photographs, voice notes, receipts, or other files uploaded to the Platform (for example, images showing third parties on site, or voice notes mentioning client names).
4.3 The Customer shall ensure that any Personal Data it uploads to the Platform is accurate and, where required, kept up to date.
4.4 Where the Customer instructs Trayd to process Special Category Data (including sick leave records), the Customer confirms that it has identified a valid legal basis under Article 9(2) GDPR for that processing – typically the carrying out of obligations in the field of employment law under Article 9(2)(b), in conjunction with Irish law under the Data Protection Act 2018 – and that this is reflected in its own privacy notice and HR documentation.
05Obligations of the Processor
5.1 Trayd shall process Personal Data only on the documented instructions of the Customer, including the instructions set out in this DPA and the Principal Agreement, except where required to do so by EU or Irish law, in which case Trayd shall inform the Customer of that requirement before processing, unless prohibited from doing so by law.
5.2 Trayd shall ensure that persons authorised to process the Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
5.3 Trayd shall implement and maintain appropriate technical and organisational measures to protect the Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures are described in Schedule 2.
5.4 Trayd shall not engage any Sub-processor without the authorisation of the Customer, given in accordance with Section 6.
5.5 Trayd shall assist the Customer in fulfilling its obligations to respond to requests from Data Subjects exercising their rights under Chapter III GDPR, taking into account the nature of the processing and the information available to Trayd.
5.6 Trayd shall notify the Customer of any Personal Data Breach affecting the Customer's data in accordance with Section 10.
5.7 Trayd shall, at the Customer's choice, delete or return all Personal Data to the Customer after the end of the provision of services, and delete existing copies, in accordance with Section 12, unless EU or Irish law requires storage of the Personal Data.
5.8 Trayd shall make available to the Customer all information reasonably necessary to demonstrate compliance with the obligations set out in Article 28 GDPR and this DPA, in the first instance through documentation, summaries of security measures, and third-party certifications or reports where available.
5.9 Where the information provided under Section 5.8 is not sufficient, Trayd shall allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer, provided that:
- audits take place no more than once in any 12-month period, except following a Personal Data Breach affecting the Customer's data or where required by the Supervisory Authority;
- the Customer gives at least 30 days' written notice;
- audits are conducted during normal business hours, do not unreasonably disrupt Trayd's operations, and are subject to appropriate confidentiality obligations;
- the Customer bears its own costs; and
- no audit gives access to data relating to any other customer of Trayd.
06Sub-processors
6.1 The Customer provides general authorisation for Trayd to engage the Sub-processors listed in Schedule 3. Trayd shall inform the Customer of any intended addition or replacement of a Sub-processor at least 30 days before it takes effect, by email to the address registered to the Customer's account or by notice in the Platform.
6.2 The Customer may object to a new Sub-processor on reasonable data protection grounds by notifying Trayd in writing within the notice period. The parties shall then work together in good faith to address the objection. If it cannot be resolved, the Customer may terminate its account and this DPA, and Section 12 shall apply.
6.3 Where Trayd engages a Sub-processor, Trayd shall impose data protection obligations on that Sub-processor equivalent to those set out in this DPA, by way of a written contract.
6.4 Trayd remains fully liable to the Customer for the performance of each Sub-processor's obligations.
07Assistance to the Controller
7.1 Trayd shall assist the Customer, insofar as reasonably possible, in fulfilling the Customer's obligations under Articles 32 to 36 GDPR (security, breach notification, data protection impact assessments, and prior consultation), taking into account the nature of processing and the information available to Trayd.
7.2 To the extent the Customer is required to carry out a Data Protection Impact Assessment (DPIA) in connection with the Platform, Trayd shall cooperate reasonably with the Customer in carrying out that assessment.
7.3 Trayd shall, promptly upon request, provide the Customer with such information as is reasonably required to enable the Customer to comply with requests from the Supervisory Authority.
08Security
8.1 Trayd shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, having regard to the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risk to the rights and freedoms of natural persons.
8.2 These measures include, at minimum, those described in Schedule 2 to this DPA.
8.3 Trayd shall regularly review and update its security measures and shall take steps to ensure that any person acting under Trayd's authority who has access to Personal Data processes it only on the instructions of Trayd, unless required to do so by applicable law.
8.4 All primary Platform data is stored on infrastructure located within the European Economic Area. At the date of this DPA, Trayd uses Supabase (EU-West region, Ireland) for its database, authentication, and file storage. The limited processing that takes place outside the EEA is set out in Section 11 and Schedule 3.
09Data Subject rights
9.1 As between the parties, the Customer is responsible for responding to requests from Data Subjects exercising their rights under Chapter III GDPR (including rights of access, rectification, erasure, restriction, portability, and objection).
9.2 If Trayd receives a request directly from a Data Subject, Trayd shall promptly forward it to the Customer and shall not respond to the Data Subject directly except on the Customer's instructions or as required by applicable law.
9.3 Trayd shall provide functionality within the Platform to support the Customer's ability to meet Data Subject requests, including the ability to export, amend, or delete Personnel Data held within the Platform.
10Personal Data Breach
10.1 Trayd shall notify the Customer without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data Breach affecting the Customer's data. Notification shall be provided to the email address registered to the Customer's account.
10.2 The notification shall include, to the extent information is available:
- a description of the nature of the Personal Data Breach including, where possible, the categories and approximate number of Data Subjects concerned and the categories and approximate number of Personal Data records concerned;
- the name and contact details of Trayd's data protection contact;
- a description of the likely consequences of the breach; and
- a description of the measures taken or proposed to address the breach and mitigate its possible adverse effects.
10.3 Where it is not possible to provide all information in the initial notification, Trayd shall provide it in phases without undue further delay.
10.4 The Customer is responsible for assessing whether the breach must be reported to the Supervisory Authority under Article 33 GDPR or communicated to Data Subjects under Article 34 GDPR.
10.5 Trayd shall cooperate with the Customer in investigating any breach and in preparing any notifications required under Articles 33 and 34 GDPR.
11International transfers
11.1 Trayd shall not transfer Personal Data outside the European Economic Area (EEA) unless:
- the transfer is to a country that benefits from an adequacy decision by the European Commission;
- the transfer is subject to appropriate safeguards under Article 46 GDPR (such as Standard Contractual Clauses); or
- an exception under Article 49 GDPR applies.
11.2 At the date of this DPA, the only transfers of Personal Data outside the EEA are those set out in Schedule 3:
- the processing by Anthropic, PBC in the United States of content submitted to the Platform's AI assistant and of receipt images uploaded for data capture, under the European Commission's Standard Contractual Clauses; and
- limited payment data processed by Stripe affiliates in the United States under Stripe's approved transfer mechanisms, including the EU–US Data Privacy Framework and Standard Contractual Clauses.
Special Category Data is not included in either transfer.
11.3 Trayd shall notify the Customer, in accordance with Section 6, before any new Sub-processor transfer outside the EEA takes effect, together with the transfer mechanism relied upon.
12Deletion and return of data
12.1 Upon termination or expiry of the Principal Agreement, or on the Customer's earlier request, Trayd shall delete or return all Personal Data processed on behalf of the Customer, including copies held by Sub-processors, unless EU or Irish law requires continued storage. Deletion shall be completed within 90 days of termination.
12.2 The Customer may, within 30 days of account closure, request an export of its data in a machine-readable format. After this period, Trayd may proceed to deletion without further notice, subject to any legal retention obligations.
12.3 On the Customer's request, Trayd shall confirm in writing once deletion has been completed.
12.4 Trayd may retain aggregated, anonymised data that cannot be used to identify any individual; such data is not Personal Data and is not subject to the deletion obligations in this Section.
13Liability
13.1 Each party's liability under or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Principal Agreement.
13.2 Nothing in this DPA limits or excludes either party's liability for: (a) death or personal injury caused by negligence; (b) fraud or fraudulent misrepresentation; or (c) any liability that cannot be limited or excluded by applicable law.
13.3 As between the parties, where a Data Subject suffers damage as a result of an infringement of the GDPR, the parties shall be liable to the extent of their responsibility for the damage, in accordance with Article 82 GDPR.
14General
14.1 If there is a conflict between this DPA and the Principal Agreement on the processing of Personal Data, this DPA prevails.
14.2 This DPA is governed by the laws of Ireland, and the courts of Ireland have exclusive jurisdiction, unless the Principal Agreement expressly states otherwise.
14.3 Trayd may update this DPA from time to time where necessary to reflect changes in applicable law or changes to its Sub-processors. Trayd shall give the Customer reasonable notice of material changes by email or in the Platform, and the version number and date at the top of this DPA will be updated.
14.4 This DPA, together with the Principal Agreement and the Schedules to this DPA, constitutes the entire agreement between the parties in respect of the processing of Personal Data.
14.5 If any provision of this DPA is held to be invalid or unenforceable, the remaining provisions shall continue in full force and effect.
S1Schedule 1 – Details of processing
Subject matter of processing
The provision of the Trayd Platform, being a job management, HR, invoicing, fleet, and scheduling application for Irish trades businesses.
Nature of processing
Collection, storage, retrieval, organisation, structuring, use, disclosure by transmission, and deletion of Personal Data relating to the Customer's workforce and business operations.
Purpose of processing
To enable the Customer to: log and manage jobs; generate invoices; manage employee leave, sick leave, certifications, and on-call rotas; track fleet compliance; generate accounting exports; and use the Platform's built-in AI assistant for product support and to capture details from uploaded receipts.
Duration of processing
For the duration of the Customer's active account, and for such further period as is required under applicable law or until deletion is completed under Section 12.
Types of Personal Data
- Employee names, job titles, and contact details
- Work schedules, timesheets, attendance records, and site check-ins (including location captured at check-in)
- Sick leave records (Special Category Data – health information under Article 9 GDPR)
- Certification records (e.g. Safe Pass, RGI, RECI, CSCS)
- Job notes, voice recordings, and photographs uploaded through the Platform, which may contain incidental Personal Data
- Receipt images, expense records, and materials data
- Van and fleet records linked to named employees
- On-call rota assignments
Categories of Data Subjects
- Employees, apprentices, and tradespeople employed or engaged by the Customer
- The Customer (where an individual sole trader)
- Incidentally, third parties mentioned in job notes, photographs, or invoices
S2Schedule 2 – Technical and organisational measures
The following measures are implemented by Trayd as at the date of this DPA and are subject to regular review and update.
| Measure | Implementation |
|---|---|
| Data encryption at rest | All data stored in Supabase EU-West is encrypted at rest using AES-256. |
| Data encryption in transit | All data in transit is encrypted using TLS 1.2 or higher. |
| Access controls | Row-Level Security (RLS) enforced at the database layer. Role-based access control (Owner, Tradesperson, Apprentice) enforced at the application layer. |
| Authentication | Supabase Auth used for user authentication. Multi-factor authentication available. |
| Data residency | All primary data stored in the Supabase EU-West (Ireland) region within the EEA. |
| Sub-processor contracts | Written data processing terms in place with all Sub-processors listed in Schedule 3. |
| Incident response | Internal procedure for identifying, reporting, and managing Personal Data Breaches, with notification to the Customer per Section 10. |
| Employee confidentiality | All persons with access to Personal Data are subject to confidentiality obligations. |
| Pseudonymisation | Where feasible, analytics and logging systems use pseudonymised identifiers rather than direct personal identifiers. |
| Backup and recovery | Automated database backups managed by Supabase. Point-in-time recovery available. |
S3Schedule 3 – Approved Sub-processors
The following Sub-processors are approved as at the date of this DPA. Trayd will notify Customers of changes in accordance with Section 6.
| Sub-processor | Purpose | Location | Transfer mechanism |
|---|---|---|---|
| Supabase Inc. | Primary database, authentication, and file storage for all Platform data | EU-West (Ireland) | Processed in the EEA – no transfer |
| Anthropic, PBC | AI assistant (product support chatbot) and extraction of details from receipt images uploaded to the Platform (Claude API) | United States | EU Standard Contractual Clauses |
| Stripe Payments Europe, Ltd. | Subscription payments and, where the Customer uses them, invoicing and payment collection features | Ireland / EU, with limited transfers to Stripe affiliates in the United States | EU–US Data Privacy Framework and Standard Contractual Clauses |
AI processing
Content submitted to the AI assistant and receipt images sent to Anthropic are used solely to provide those features and are not used to train AI models. Special Category Data (including sick leave records) is not sent to Anthropic.
Usage and diagnostic data
Trayd separately uses Google Ireland Limited (Firebase Analytics and Crashlytics) to process app usage and diagnostic data. Trayd acts as controller of that data in its own right, as described in the Trayd Privacy Policy; it is not Personnel Data processed on the Customer's behalf and Google is therefore not a Sub-processor under this DPA.
15Contact
Questions about this DPA, Sub-processor notices, or requests for a signed copy:
Trayd data protection contactEmail is the quickest way to reach us.
info@trayd.ie