Techneth EOOD  •  Tryneth Privacy Policy & DPA

PRIVACY POLICY

Including Data Processing Addendum for the Tryneth Platform

About this Policy. This Privacy Policy explains how Techneth EOOD (“Techneth”, “we”, “us”) collects, uses, and protects personal data in connection with the Tryneth platform (the “Service”). It should be read with our Terms and Conditions. Capitalised terms not defined here have the meaning given in the Terms. This Policy is designed to comply with the EU General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”) and applicable Bulgarian data-protection law.

1. Who We Are and Our Role

1.1 Controller. Techneth EOOD is a limited liability company incorporated in the Republic of Bulgaria, with registered office at ul. “Perla” 26, Zapad, Mladost, 9000 Varna, Bulgaria, and company registration (UIC) number 208663227. For questions about this Policy or your data, contact us at privacy@techneth.com.

1.2 Two roles. We act in two distinct capacities:

  • As a controller for personal data we determine the purposes of, principally data about our direct business customers, their account owners and Users, billing contacts, website visitors, and prospects.
  • As a processor for personal data that our customers process through the Service about their own end-clients, leads, contacts, and meeting participants (“End-Client Data”). For that data, our customer is the controller and we process it on the customer’s instructions. The Data Processing Addendum in Part B governs this relationship.

1.3 Data Protection contact. We have appointed [a Data Protection Officer / a privacy contact] reachable at privacy@tryneth.com. If we are required to appoint an EU representative or DPO under the GDPR, details will be published here.

PART A: HOW WE USE DATA AS CONTROLLER

2. Personal Data We Collect

We collect the following categories of personal data when you register for, use, or interact with the Service or our website:

CategoryExamplesSource
Account and identityName, business email, role, company name, account credentialsYou / your organisation
BillingBilling contact, plan, transaction records (no full card data)You / payment processor
Usage and technicalLog data, device and browser data, IP address, pages visited, actions, Spark ledger, cookiesAutomated collection
Support and commsMessages, enquiries, feedback you send usYou
MarketingContact details of prospects, engagement with our communicationsYou / lawful sources

3. How and Why We Use It (Purposes and Lawful Bases)

As controller, we process personal data on the following lawful bases under Article 6 GDPR:

PurposeLawful basisNotes
Provide, operate, and secure the ServiceContract (Art. 6(1)(b))Necessary to deliver what you signed up for
Billing, fraud prevention, and account managementContract / Legal obligation (Art. 6(1)(b),(c))Includes tax and accounting duties
Improve, develop, and secure the Service, including AI Features, using aggregated or de-identified and account/usage dataLegitimate interests (Art. 6(1)(f))See Section 4; balanced against your rights
Customer support and communicationsContract / Legitimate interestsResponding to you
Direct marketing to business contactsLegitimate interests / Consent where requiredOpt-out always available
Compliance with law and defending legal claimsLegal obligation / Legitimate interestsAs required

4. Service Improvement and AI Training

4.1 We use data to operate, secure, analyse, and improve the Service, including to train, fine-tune, and evaluate the AI Features. We do this only using (a) data that has been aggregated or de-identified so that it no longer identifies any individual, and (b) account-level and usage data about how the Service is configured and used.

4.2 End-Client Data is excluded from training. We do not use our customers’ End-Client Data (including leads, contacts, meeting recordings, transcripts, and inbound messages) to train or fine-tune our AI models, unless the relevant customer expressly opts in and confirms it has the necessary consents and legal basis. Absent that opt-in, End-Client Data is processed solely to provide the Service, as set out in Part B.

4.3 We do not sell personal data. We do not sell personal data and do not share it with third parties for their own independent marketing purposes. Where we use third-party AI model providers, they process data on our behalf under contractual confidentiality and data-protection commitments and are not permitted to use it for their own purposes.

4.4 Your right to object. Where we rely on legitimate interests, you may object at any time (see Section 9). We will stop unless we have compelling legitimate grounds that override your rights, or need to process for legal claims.

5. Automated Processing and AI Output

5.1 The Service uses AI to generate and analyse content. This supports human decision-making; it is not used by us to make decisions producing legal or similarly significant effects on individuals without human involvement. Where a customer configures automated workflows, that customer is responsible for the lawfulness of those workflows.

5.2 AI Output may be inaccurate. We are not responsible for how customers use AI Output; responsibility for reviewing and using Output rests with the customer under the Terms.

6. Cookies and Tracking

6.1 We and our providers use cookies and similar technologies for authentication, security, preferences, and analytics. Strictly necessary cookies are used to operate the Service; non-essential cookies are used only with your consent where required. You can manage preferences through your browser or any cookie controls we provide.

7. Sharing and Sub-Processors

7.1 We share personal data only as needed to run the Service and our business, with: (a) service providers and Sub-Processors who process on our behalf (for AI models, payment processing, hosting and content delivery, email delivery, analytics, video-meeting infrastructure, and similar functions); (b) professional advisers; (c) authorities where legally required; and (d) a successor in a reorganisation, merger, or sale of assets, subject to this Policy.

7.2 Sub-Processor Register. A current list of Sub-Processors that process personal data, identified by name, is maintained in our Sub-Processor Register, available on request or as published in-product. Each Sub-Processor is bound by data-protection terms consistent with the GDPR.

8. International Transfers

8.1 Some Sub-Processors may process personal data outside the European Economic Area. Where they do, we ensure an appropriate safeguard under Chapter V GDPR is in place, such as an adequacy decision or the European Commission’s Standard Contractual Clauses, together with supplementary measures where needed. Details are available on request.

9. Your Rights

Subject to the GDPR, you have the right to: access your personal data; rectify inaccurate data; erase data; restrict or object to processing; data portability; and withdraw consent where processing is based on consent, without affecting prior processing. Where we process End-Client Data as processor, requests should be directed to the relevant customer (the controller); we will assist that customer as required.

9.1 How to exercise. Contact us at privacy@techneth.com. We respond within the time limits set by the GDPR (generally one month). You may also lodge a complaint with the Bulgarian Commission for Personal Data Protection (Komisia za zashtita na lichnite danni) or with the supervisory authority of your habitual residence.

10. Data Retention and Security

10.1 Retention. We keep personal data only as long as necessary for the purposes described, to provide the Service, to comply with legal, tax, and accounting obligations, and to defend legal claims. On termination, Customer Data is available for export for a limited period, after which it is deleted or de-identified in accordance with our retention practices, unless retention is legally required.

10.2 Security. We apply appropriate technical and organisational measures, including encryption of data in transit (TLS 1.2 or higher), role-based access controls, tenant isolation, short-lived access tokens, and secure payment handling through a PCI-DSS-compliant payment processor so that no full card data is stored by us. No system is completely secure; we cannot guarantee absolute security.

11. Children

The Service is a business tool not directed at children and is not intended for anyone under the age at which they can validly consent under applicable law. We do not knowingly collect data from children.

12. Changes to this Policy

We may update this Policy from time to time. Material changes will be notified through the Service or by email. The effective date at the top shows when it was last updated.

PART B: DATA PROCESSING ADDENDUM (ARTICLE 28 GDPR)

Scope. This Data Processing Addendum (“DPA”) forms part of the Agreement between Techneth EOOD (“Processor”) and the Customer (“Controller”) and applies where Techneth processes End-Client Data and other personal data on the Controller’s behalf. It reflects the requirements of Article 28 GDPR. In case of conflict on data-protection matters, this DPA prevails over the Terms.

13. Roles and Instructions

13.1 The Controller determines the purposes and means of processing End-Client Data; the Processor processes it only on the Controller’s documented instructions, including the Agreement and use of the Service, unless required by EU or Member-State law (in which case the Processor informs the Controller unless prohibited).

13.2 The Controller warrants that its instructions and the processing are lawful, that it has a valid lawful basis, and that it has given all required notices and obtained all required consents from data subjects, including meeting participants for recording and transcription.

13.3 The Processor will inform the Controller if, in its opinion, an instruction infringes the GDPR or other data-protection law.

14. Subject-Matter and Details of Processing

ElementDetail
Subject-matterProvision of the Tryneth platform to the Controller
DurationFor the term of the Agreement plus any limited export/retention period
Nature and purposeHosting, storage, transmission, generation, transcription, analysis, and processing of data to deliver the Service
Types of personal dataContact and identity data, lead and CRM data, communications and DM content, meeting audio/video/transcripts, usage data
Categories of data subjectsThe Controller’s end-clients, leads, contacts, meeting participants, and personnel

15. Processor Obligations

The Processor will:

  • process personal data only on documented instructions, including for international transfers;
  • ensure persons authorised to process are bound by confidentiality;
  • implement appropriate technical and organisational security measures under Article 32 GDPR, as summarised in Section 10.2 and further described on request;
  • respect the conditions for engaging Sub-Processors in Section 16;
  • assist the Controller, taking into account the nature of processing, in responding to data-subject rights requests;
  • assist the Controller with its obligations under Articles 32 to 36 GDPR (security, breach notification, impact assessments, prior consultation), taking into account the information available to the Processor;
  • at the Controller’s choice, delete or return personal data at the end of provision of services, and delete existing copies unless legally required to retain them; and
  • make available information necessary to demonstrate compliance with Article 28, and allow for and contribute to audits as described in Section 17.

16. Sub-Processors

16.1 General authorisation. The Controller gives general authorisation for the Processor to engage Sub-Processors listed in the Sub-Processor Register. The Processor imposes data-protection obligations on each Sub-Processor no less protective than those in this DPA and remains liable for their performance.

16.2 Changes. The Processor will give notice of intended additions or replacements of Sub-Processors, giving the Controller the opportunity to object on reasonable data-protection grounds. If an objection cannot be resolved, the Controller may terminate the affected part of the Service as its sole remedy.

17. Audits

17.1 The Processor will make available information reasonably necessary to demonstrate compliance and will allow audits by the Controller or a mandated auditor, no more than once per year (unless required by a supervisory authority or after a personal-data breach), on reasonable prior notice, during business hours, subject to confidentiality, and in a manner that does not compromise other customers’ data or security. The Processor may satisfy audit requests by providing existing reports or certifications where available.

18. Personal-Data Breach

18.1 The Processor will notify the Controller without undue delay after becoming aware of a personal-data breach affecting the Controller’s data, with the information reasonably available to enable the Controller to meet its own notification obligations. The Controller is responsible for notifying supervisory authorities and data subjects where required.

19. International Transfers (Processor)

19.1 Where the Processor or a Sub-Processor transfers the Controller’s personal data outside the EEA, the transfer is made under an appropriate Chapter V GDPR safeguard, such as an adequacy decision or the Standard Contractual Clauses, which the parties agree are incorporated by reference where applicable, with the Processor (or Sub-Processor) as data importer and the Controller as data exporter.

20. Liability under this DPA

20.1 The liability of each party under or in connection with this DPA is subject to the limitations and exclusions of liability in the Terms. Nothing in this DPA limits any liability that cannot be limited under the GDPR or mandatory law, including a data subject’s rights.

21. Order of Precedence and Governing Law

21.1 This DPA is governed by the same law and jurisdiction as the Terms (the laws of the Republic of Bulgaria), except where the GDPR or mandatory law requires otherwise. On data-protection matters, this DPA prevails over conflicting provisions of the Terms; on all other matters, the Terms prevail.

Confidential  •  Version 1.0