The short version. When your business data sits in TruLens, you are in charge of it and we are not. We only do what you tell us to do with it, we keep it secure, we tell you quickly if anything goes wrong, and we give it back or delete it when you leave. This page is the formal version of that promise, in the form UK data protection law requires.
This summary is for orientation. The clauses below are the agreement.
How this agreement applies
This Data Processing Agreement is entered into between TruLens, company number 17011282, of 4th Floor, Silverstream House, 45 Fitzroy Street, Fitzrovia, London W1T 6EB, and the customer that subscribes to the TruLens for Food platform.
It forms part of our Terms and Conditions and takes effect automatically when you subscribe. You do not need to sign a separate copy, although we will sign one on request if your own procurement process requires it. Where anything in the Terms and Conditions conflicts with this agreement in relation to personal data, this agreement wins.
It is made to satisfy Article 28(3) of the UK GDPR, which requires a written contract between a controller and a processor.
1. Definitions
| Data Protection Law | The UK GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations 2003, each as amended or replaced from time to time. |
| Customer Personal Data | Personal data contained in the data you or your users put into, or generate within, the platform. |
| Controller, Processor, Data Subject, Personal Data, Personal Data Breach, Processing | Have the meanings given to them in Data Protection Law. |
| Sub-processor | Any third party we engage to process Customer Personal Data on our behalf. |
| Terms | The TruLens Terms and Conditions. |
2. Roles and scope
2.1 In relation to Customer Personal Data, you are the Controller and we are the Processor.
2.2 Where you are yourself processing on behalf of somebody else, you confirm you have that party's authority to appoint us and to give the instructions in this agreement.
2.3 We are a Controller in our own right for the personal data we hold about your account contacts and about visitors to our websites, which is not Customer Personal Data. That processing is described in our Privacy Policy and is outside this agreement.
2.4 Each of us will comply with our own obligations under Data Protection Law. You are responsible for making sure you have a lawful basis for the data you put into the platform, and for giving your staff the information they are entitled to about it.
3. Our instructions
3.1 We will process Customer Personal Data only on your documented instructions. Your instructions are: the Terms, this agreement, the configuration choices you make in the platform, and any further written instruction you give us and we accept.
3.2 Using the features of the platform, including reports, integrations, exports and outbound email, constitutes an instruction to process the data required to deliver them.
3.3 We will not sell Customer Personal Data, use it for our own marketing, disclose it to a third party except as this agreement permits, or use it to train artificial intelligence models made available to other customers.
3.4 We may produce aggregated and anonymised statistics from platform usage to operate and improve the service, provided the result cannot identify you, your business or any individual. Once anonymised, that information is no longer personal data.
3.5 If we are required by law to process Customer Personal Data other than on your instructions, we will tell you before doing so unless the law prohibits it.
3.6 If we consider an instruction from you would breach Data Protection Law, we will tell you promptly and may suspend that instruction until it is resolved.
4. Confidentiality of our staff
4.1 We will make sure anyone we authorise to process Customer Personal Data is bound by an appropriate duty of confidentiality, whether contractual or statutory.
4.2 We limit access to those who need it to provide or support the service, and review that access periodically.
5. Security
5.1 We will implement appropriate technical and organisational measures to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access, taking into account the state of the art, the cost of implementation, and the nature, scope, context and purposes of processing as well as the risks involved.
5.2 Our current measures are described in Annex B. We may update them, provided the level of protection is not reduced.
5.3 You are responsible for the parts of security within your control, including who you grant access to, the roles you assign, the strength of credentials your staff use, and removing access when someone leaves.
6. Sub-processors
6.1 You give us general authorisation to appoint Sub-processors. Our current Sub-processors are listed in Annex C.
6.2 Before a new Sub-processor starts processing Customer Personal Data, we will give you at least 30 days' notice by email to your account contact, naming the Sub-processor and describing what it will do.
6.3 You may object on reasonable data protection grounds within that period. If you do, we will work with you in good faith to find a solution, which might be a configuration change or an alternative supplier. If we cannot resolve it, you may end the affected part of the subscription without penalty, and we will refund fees already paid for the period after termination.
6.4 We will impose data protection obligations on each Sub-processor that are equivalent to those in this agreement, and we remain fully liable to you for their performance.
7. Helping you with data subject requests
7.1 The platform gives you the tools to search, correct, export and delete records yourself, which is normally the fastest way to answer a request from one of your staff.
7.2 Taking into account the nature of the processing, we will give you reasonable assistance with requests you cannot handle through those tools.
7.3 If a Data Subject contacts us directly about Customer Personal Data, we will not respond to the substance ourselves. We will tell them to contact you, and pass the request to you without undue delay.
7.4 Assistance is included at no charge unless a request is unusually complex or repetitive, in which case we will agree a reasonable charge with you in advance.
8. Personal data breach
8.1 We will notify you without undue delay, and in any event within 48 hours of becoming aware of a Personal Data Breach affecting Customer Personal Data.
8.2 The notification will describe, as far as we know at the time, the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, the measures we have taken or propose to take, and a contact point for more information. Where we cannot provide everything at once, we will provide it in stages as it becomes available.
8.3 We will take reasonable steps to contain and remedy the breach, and will not make any public statement identifying you without your prior agreement unless we are legally required to.
8.4 Reporting the breach to the Information Commissioner's Office and, where required, to affected individuals is your responsibility as Controller. We will give you the information you reasonably need to do it.
9. Impact assessments and prior consultation
9.1 Taking into account the nature of processing and the information available to us, we will give you reasonable assistance with any data protection impact assessment you carry out, and with any prior consultation with the Information Commissioner's Office that follows from it.
10. Information and audit
10.1 We will make available the information reasonably necessary to demonstrate compliance with Article 28 of the UK GDPR.
10.2 You may audit that compliance no more than once in any twelve month period, on at least 30 days' written notice, during business hours, in a way that does not disrupt the service, and subject to confidentiality. You may audit more frequently following a Personal Data Breach affecting your data or a specific instruction from a regulator.
10.3 We may satisfy an audit request by providing a written response to a reasonable security questionnaire, or documentation covering our controls, where that gives you the assurance you need.
10.4 You will bear your own costs of an audit, and our reasonable costs where an audit goes beyond a written response.
11. International transfers
11.1 Customer Personal Data in the platform is hosted in the United Kingdom.
11.2 We will not transfer Customer Personal Data outside the UK unless an appropriate safeguard under Data Protection Law is in place, such as an adequacy regulation, the International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses, together with a transfer risk assessment where required.
11.3 Where a Sub-processor provides support from outside the UK, that access is covered by the same safeguards, and is noted in Annex C.
12. Return and deletion
12.1 You may export your data at any time during the subscription and for 30 days after it ends, using the export features in the platform. If you need help doing so, ask us before that period ends.
12.2 After that period we will, at your choice, delete or return Customer Personal Data and delete existing copies, within 90 days.
12.3 Two exceptions apply. Copies held in encrypted backups taken for disaster recovery are deleted as those backups cycle out on their normal rotation rather than on demand, and remain protected by this agreement until they do. Operational and security logs may be retained for up to 12 months. We may also retain anything Data Protection Law or other law requires us to keep, and will keep it only for that purpose.
12.4 We will confirm deletion in writing on request.
13. Liability
13.1 Each party's liability under or in connection with this agreement is subject to the limits and exclusions in the Terms, and those limits apply to the agreement as a whole rather than separately to this document.
13.2 Nothing in this agreement affects the rights a Data Subject has directly against either party under Data Protection Law.
14. Duration and general
14.1 This agreement takes effect when your subscription starts and continues for as long as we process Customer Personal Data, including any period after the subscription ends until deletion is complete under clause 12.
14.2 We may update this agreement where Data Protection Law changes or where the platform changes, provided the update does not reduce your protections. We will give account contacts at least 30 days' notice of any material change.
14.3 This agreement is governed by the laws of England and Wales, and the courts of England and Wales have exclusive jurisdiction, matching the Terms.
Annex A: Details of the processing
| Item | Detail |
|---|---|
| Subject matter | Providing the TruLens for Food platform to the customer. |
| Duration | The subscription term, plus the export and deletion periods in clause 12. |
| Nature and purpose | Hosting, storage, structuring, retrieval, analysis and transmission of customer data in order to deliver inventory, recipe costing, production, waste, wholesale, sales reconciliation and reporting functionality, and to send operational messages the customer configures. |
| Types of personal data | Names and work contact details of the customer's staff and operators; user account identifiers and roles; records of actions taken in the platform and the user who took them; names and work contact details of the customer's suppliers and wholesale clients; account and billing contact details. |
| Special category data | None. The platform is not designed for it and customers are instructed not to upload it. |
| Payment card data | None. TruLens is not a payment processor and does not store card numbers. |
| Categories of data subject | The customer's staff, operators and authorised users; contacts at the customer's suppliers and wholesale clients. |
| Frequency | Continuous for the duration of the subscription. |
Annex B: Technical and organisational security measures
| Area | Measure |
|---|---|
| Encryption in transit | All traffic to the platform is encrypted using TLS. Plain HTTP connections are redirected. |
| Encryption at rest | Managed storage and database volumes are encrypted at rest. |
| Tenant isolation | Each customer's data is held in its own database schema rather than mixed into shared tables, so queries are scoped to a single customer by design. |
| Access control | Role based access control within each account, so users only reach the functions their role permits. |
| Authentication | Managed identity provider handling credentials, password policy and session management. Multi-factor authentication is required for administrative access. |
| Administrative access | Access to production systems is limited to personnel who need it, and is reviewed periodically. |
| Audit logging | Significant actions are recorded with the acting user and timestamp, giving a traceable history of changes. |
| Backups | Regular automated backups, encrypted, retained on a rolling cycle for disaster recovery. |
| Network | Databases are not publicly exposed. Administrative access is via secured channels only. |
| Change management | Changes are reviewed and tested before release, with database migrations applied under controlled procedure. |
| Segregation of environments | Development and testing are carried out on separate environments from production. |
| Certification | We do not currently hold ISO 27001, SOC 2 or PCI DSS certification and make no such claim. |
Annex C: Current sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Amazon Web Services EMEA SARL | Hosting, compute, database, file storage, user authentication and outbound service email | United Kingdom |
| Payment provider | Taking subscription payments. Receives billing contact details. Card data is handled entirely on their systems and never reaches TruLens | To be confirmed |
| Business email and document provider | Correspondence and support. May incidentally hold Customer Personal Data included in a support request | To be confirmed |
To be notified of changes to this list, email hello@trulens.co.uk and ask to be added to sub-processor notifications.
TruLens, company number 17011282, 4th Floor, Silverstream House, 45 Fitzroy Street, Fitzrovia, London W1T 6EB. Version 1.0, effective 9 August 2026. Previous versions are available on request.