Legal

GDPR

Your data-protection rights under the EU and UK GDPR — and how TRIMS honors them.

Last updated · July 5, 2026

01Our GDPR commitment

The General Data Protection Regulation (GDPR) and the UK GDPR give people in the EEA and UK strong rights over their personal data. TRIMS is committed to honoring those rights and to processing personal data lawfully, fairly, and transparently.

This page explains our roles, the data we process, the lawful bases we rely on, how to exercise your rights, and the safeguards we apply to international transfers. It complements our Privacy Policy.

02Controller & processor roles

Your relationship with us determines who is the “controller” (who decides why and how data is processed) and who is the “processor” (who processes on the controller's instructions).

ScenarioTRIMS acts as
Your account & billing dataController
Click/visitor data for links you createProcessor (you are the controller)
Customers & conversion events you send usProcessor
Our own product analytics & securityController
For business customers
Where we act as processor, our Data Processing Agreement (DPA) governs the processing. Request it at any time — see the DPA section below.

03Personal data we process

  • Identity & contact — name, email, and profile details.
  • Technical — IP address (truncated/hashed after use), device, OS, and browser.
  • Location — coarse country/city derived from IP; never precise GPS.
  • Usage — clicks, sessions, and feature usage.
  • Conversion — customer identifiers and event values you choose to send.

04Lawful bases

We only process personal data where we have a lawful basis under Article 6 GDPR:

ProcessingLawful basis
Delivering the Services you requestContract (Art. 6(1)(b))
Security, anti-abuse, fraud preventionLegitimate interests (Art. 6(1)(f))
Product analytics & improvementLegitimate interests
Marketing communicationsConsent (Art. 6(1)(a))
Legal, tax & accounting obligationsLegal obligation (Art. 6(1)(c))

Where we rely on legitimate interests, we balance them against your rights and freedoms. You can object at any time.

05Your rights & how to exercise them

Under the GDPR you have the right to:

  • Access — obtain confirmation and a copy of your personal data.
  • Rectification — correct inaccurate or incomplete data.
  • Erasure — request deletion (“right to be forgotten”).
  • Restriction — limit how we process your data in certain cases.
  • Portability — receive your data in a structured, machine-readable format.
  • Objection — object to processing based on legitimate interests or to direct marketing.
  • Withdraw consent — where processing is based on consent, without affecting prior processing.
  • Not be subject to solely automated decisions that produce legal or similarly significant effects.
Self-serve where possible
Account holders can export or delete their data in Settings → Account. For anything else, email info@trims.app. We verify your identity and respond within one month (extendable by two months for complex requests, with notice).

If you clicked a link and want to exercise rights over that click data, contact the organization that created the link (the controller); as processor we will support them.

06International transfers

Where we transfer personal data outside the EEA, UK, or Switzerland, we use appropriate safeguards, including:

  • The European Commission's Standard Contractual Clauses (SCCs).
  • The UK International Data Transfer Addendum for UK transfers.
  • Transfer impact assessments and supplementary technical measures (encryption, access controls) where needed.

07Subprocessors

We engage a limited set of subprocessors to deliver the Services (hosting/CDN, payment processing, email, and geolocation). Each is bound by data-protection terms consistent with the GDPR.

We maintain a current subprocessor list and provide reasonable prior notice of changes to business customers under a DPA. Request the list at info@trims.app.

08Retention & deletion

We keep personal data only as long as necessary for the purposes it was collected, then delete or anonymize it.

  • Account data — for the life of the account plus a limited legal-retention period.
  • Analytics — per your plan's retention window.
  • Backups — encrypted and purged on a rolling schedule.

On a valid erasure request or account deletion, we remove personal data except where retention is legally required.

09Data Processing Agreement (DPA)

Business customers who act as controllers can enter into our DPA, which incorporates the SCCs and sets out our obligations as processor — including confidentiality, security, subprocessing, assistance with data-subject requests, and breach notification.

Request a DPA
Email info@trims.app to receive our DPA for signature.

10Security measures

We implement appropriate technical and organizational measures under Article 32 GDPR, including encryption in transit and at rest, access controls, audit logging, and continuous monitoring. Details are on our Security page.

11Breach notification

If a personal-data breach is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours where required, and affected individuals or controllers without undue delay.

12DPO & representative

You can reach our data-protection contact at info@trims.app. Where required, we maintain an EU/UK representative for data-protection matters; contact us for their details.

13Complaints

If you believe we have not handled your personal data lawfully, we'd like the chance to resolve it — contact info@trims.app. You also have the right to lodge a complaint with your local supervisory authority (for example, your national data-protection authority in the EEA, or the ICO in the UK).

14Contact

Data-protection enquiries: info@trims.app · info@trims.app.

Questions about this document? Reach us at info@trims.app.