GDPR
Your data-protection rights under the EU and UK GDPR — and how TRIMS honors them.
01Our GDPR commitment
The General Data Protection Regulation (GDPR) and the UK GDPR give people in the EEA and UK strong rights over their personal data. TRIMS is committed to honoring those rights and to processing personal data lawfully, fairly, and transparently.
This page explains our roles, the data we process, the lawful bases we rely on, how to exercise your rights, and the safeguards we apply to international transfers. It complements our Privacy Policy.
02Controller & processor roles
Your relationship with us determines who is the “controller” (who decides why and how data is processed) and who is the “processor” (who processes on the controller's instructions).
| Scenario | TRIMS acts as |
|---|---|
| Your account & billing data | Controller |
| Click/visitor data for links you create | Processor (you are the controller) |
| Customers & conversion events you send us | Processor |
| Our own product analytics & security | Controller |
03Personal data we process
- Identity & contact — name, email, and profile details.
- Technical — IP address (truncated/hashed after use), device, OS, and browser.
- Location — coarse country/city derived from IP; never precise GPS.
- Usage — clicks, sessions, and feature usage.
- Conversion — customer identifiers and event values you choose to send.
04Lawful bases
We only process personal data where we have a lawful basis under Article 6 GDPR:
| Processing | Lawful basis |
|---|---|
| Delivering the Services you request | Contract (Art. 6(1)(b)) |
| Security, anti-abuse, fraud prevention | Legitimate interests (Art. 6(1)(f)) |
| Product analytics & improvement | Legitimate interests |
| Marketing communications | Consent (Art. 6(1)(a)) |
| Legal, tax & accounting obligations | Legal obligation (Art. 6(1)(c)) |
Where we rely on legitimate interests, we balance them against your rights and freedoms. You can object at any time.
05Your rights & how to exercise them
Under the GDPR you have the right to:
- Access — obtain confirmation and a copy of your personal data.
- Rectification — correct inaccurate or incomplete data.
- Erasure — request deletion (“right to be forgotten”).
- Restriction — limit how we process your data in certain cases.
- Portability — receive your data in a structured, machine-readable format.
- Objection — object to processing based on legitimate interests or to direct marketing.
- Withdraw consent — where processing is based on consent, without affecting prior processing.
- Not be subject to solely automated decisions that produce legal or similarly significant effects.
If you clicked a link and want to exercise rights over that click data, contact the organization that created the link (the controller); as processor we will support them.
06International transfers
Where we transfer personal data outside the EEA, UK, or Switzerland, we use appropriate safeguards, including:
- The European Commission's Standard Contractual Clauses (SCCs).
- The UK International Data Transfer Addendum for UK transfers.
- Transfer impact assessments and supplementary technical measures (encryption, access controls) where needed.
07Subprocessors
We engage a limited set of subprocessors to deliver the Services (hosting/CDN, payment processing, email, and geolocation). Each is bound by data-protection terms consistent with the GDPR.
We maintain a current subprocessor list and provide reasonable prior notice of changes to business customers under a DPA. Request the list at info@trims.app.
08Retention & deletion
We keep personal data only as long as necessary for the purposes it was collected, then delete or anonymize it.
- Account data — for the life of the account plus a limited legal-retention period.
- Analytics — per your plan's retention window.
- Backups — encrypted and purged on a rolling schedule.
On a valid erasure request or account deletion, we remove personal data except where retention is legally required.
09Data Processing Agreement (DPA)
Business customers who act as controllers can enter into our DPA, which incorporates the SCCs and sets out our obligations as processor — including confidentiality, security, subprocessing, assistance with data-subject requests, and breach notification.
10Security measures
We implement appropriate technical and organizational measures under Article 32 GDPR, including encryption in transit and at rest, access controls, audit logging, and continuous monitoring. Details are on our Security page.
11Breach notification
If a personal-data breach is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours where required, and affected individuals or controllers without undue delay.
12DPO & representative
You can reach our data-protection contact at info@trims.app. Where required, we maintain an EU/UK representative for data-protection matters; contact us for their details.
13Complaints
If you believe we have not handled your personal data lawfully, we'd like the chance to resolve it — contact info@trims.app. You also have the right to lodge a complaint with your local supervisory authority (for example, your national data-protection authority in the EEA, or the ICO in the UK).
14Contact
Data-protection enquiries: info@trims.app · info@trims.app.
Questions about this document? Reach us at info@trims.app.