Legal
Data Processing Addendum — Consulting
Last updated: 6 May 2026
This Data Processing Addendum ("DPA") applies only when the Statement of Work for a consulting engagement says Traject AI will process personal data on the client's behalf — for example, during a build phase where Traject AI runs a system that handles end-user data before handover, or in a managed-pilot arrangement.
For one-off advisory engagements (architecture reviews, training sessions, code audits) where no personal data is processed by Traject AI, this DPA does not apply.
For the SaaS product's DPA (covering the AI agent marketplace where Traject AI is always the processor), see traject-ai.in/legal/dpa.
1. Roles
Where Traject AI processes personal data on behalf of the client under an SOW, the client is the controller and Traject AI is a processor. Traject AI will only process personal data on the client's documented instructions (the SOW + any subsequent written direction).
2. Categories of data
The categories and subjects of personal data are defined per engagement in the SOW. Typical categories: end-customer contact details (name, email, phone), conversation transcripts, booking records.
3. Sub-processors
The engagement's SOW lists the cloud + AI sub-processors used (typically a subset of: Google Cloud, Google Vertex AI, Cloudflare, the client's own messaging or calendar providers). Material changes are notified in writing with at least 30 days' notice; the client may object before the change takes effect.
4. Security
- Encryption in transit (TLS 1.2+) and at rest where supported by the chosen platform.
- Access on a least-privilege basis. Single engagement-scoped service accounts; no shared credentials across clients.
- Per-engagement Google Cloud project where feasible, so isolation is at the platform tenancy layer.
- Incident response: written notice within 72 hours of confirmed material breach.
5. Data subject rights
Traject AI will reasonably assist the client in responding to data subject access, correction, or deletion requests within the engagement scope.
6. Audit
On reasonable notice (and not more than once per year except after a material incident), the client may request a written summary of relevant security controls. Physical or third-party audits are scoped per the SOW.
7. Return / deletion on termination
On engagement end, Traject AI will return or delete personal data per the SOW within 30 days, except where retention is required by law.
8. Contact
Privacy questions: consulting@traject-ai.in
Related: Consulting privacy · Consulting terms.