Data processing terms
Version 1.0. Last updated 2 August 2026.
These terms apply whenever Trueband processes personal data on behalf of a firm. They are written to be redlined, not admired, so anything we cannot promise today is marked as such rather than dressed up.
1. How these terms fit together
These terms form part of the agreement between your firm and Trueband. Where they conflict with the main agreement on the subject of personal data, these terms win. Where they conflict with the standard contractual clauses referenced in section 11, those clauses win. Words like controller, processor, personal data, processing and personal data breach carry the meanings given to them in applicable data protection law.
2. Roles
Your firm is the controller of its clients' personal data. Trueband is the processor and acts only on your firm's documented instructions, which in practice means the credentials you connect and the settings you choose. Using the product is an instruction to process as described in Annex I. If we ever believe an instruction breaks applicable law we will say so rather than quietly comply.
We are the controller of our own business records, such as who at your firm we correspond with. The privacy policy covers that.
3. What we will not do with it
We will not use your firm's client data to train a model, to build a product feature for anyone else, to enrich any other dataset, or for any purpose of our own. There is no analytics layer over it. If we ever want to use aggregate figures to describe how the product performs, we will ask your firm first and take no for an answer.
4. Confidentiality
Everyone with access to your firm's data is bound by a written confidentiality obligation that survives the end of their engagement. Access is granted on need, and removed when the need ends. Trueband is a very small company; the honest version is that the list of people with access is short and we will tell you who is on it if you ask.
5. Security
We maintain the technical and organisational measures in Annex II. Data is encrypted in transit and at rest by the underlying Cloudflare services. Reaching the application requires a signed identity from your firm's own identity provider, checked again by the application on every request against an allowlist your firm controls.
Annex II also lists what is not in place yet. We would rather lose a deal on that list than win one and be found out during due diligence.
6. Sub-processors
Your firm authorises the sub-processors in Annex III. We will give at least 30 days' written notice before adding or replacing one. If your firm reasonably objects on data protection grounds within that period, we will work to offer an alternative, and if we cannot, your firm may terminate the affected part of the service without penalty and receive a refund of anything prepaid and unused.
Every sub-processor is bound by obligations no weaker than these terms, and we remain liable to your firm for what they do.
7. Assisting your firm
If a client of yours exercises a right and you need our help to answer, tell us and we will provide what we hold within 10 business days, sooner where the law requires it. If a client contacts us directly we will not answer on your behalf; we will point them to your firm and let you know it happened.
We will also give your firm reasonable help with data protection impact assessments and with prior consultation, to the extent the information is ours to give.
8. Personal data breaches
If we become aware of a personal data breach affecting your firm's data we will notify you without undue delay and in any case within 48 hours, using the contact your firm gives us. The first notice will say what we know, what we do not know yet, and what we are doing, and we will keep updating it. We will not wait until the picture is complete or flattering.
9. Audit
Your firm may verify our compliance with these terms once in any 12 month period, and more often if a regulator requires it or after a breach affecting your data. In practice that means written answers to a security questionnaire, our documentation, and a call with whoever needs one. We do not have a SOC 2 report to hand you, which is stated plainly on the security page.
10. Deletion and return
On termination your firm may choose deletion or return. We will complete either within 30 days of the request and confirm in writing when it is done. Backups age out on their own cycle, which we will describe if you ask, and nothing is restored from them for any purpose other than recovering the service.
Configurable retention during the term is designed and not yet built. Until it ships, deletion during the term is a request to us rather than a control in the product.
11. International transfers
Processing happens on Cloudflare's network. Drift records are held in Workers KV, which is globally replicated, so data may rest in Cloudflare facilities outside the United States. Where a transfer requires a lawful mechanism, the European Commission's standard contractual clauses and the UK addendum are incorporated by reference, with Trueband as data importer, and Annexes I to III below populate them.
We cannot pin processing to a single region today. If your firm needs that, say so before signing rather than after.
12. Liability
Liability under these terms is governed by the limitations in the main agreement, except where applicable data protection law does not permit that.
Annex I. The processing
- Subject matter: computing portfolio drift and preparing client outreach for advisor review.
- Duration: while your firm's account is active, plus the deletion window in section 10.
- Nature and purpose: reading portfolio data from your firm's existing systems, computing per asset class deviation from a target model, presenting the result to your advisors, and generating an unsent draft email and an optional advisor video.
- Categories of data subject: your firm's advisors, and your firm's advisory clients.
- Categories of personal data: household and account names, account counts and values, holdings by asset class, computed drift, performance figures, a client email address where your firm holds one, advisor recorded video and still frame, and advisor written email text.
- Special category data: none. The product has no field for it.
- Not processed: account numbers, tax identifiers, dates of birth, transaction history.
- Frequency: continuous while a sync schedule is enabled, otherwise on demand.
Annex II. Technical and organisational measures
In place:
- Encryption in transit (TLS) and at rest, provided by the underlying Cloudflare services.
- Identity enforced twice: Cloudflare Access in front of the application, and a signed identity re-checked by the application on every request against a firm-controlled allowlist.
- No infrastructure of ours to log into. Compute is serverless and there is no persistent host with a shell.
- Least privilege against your systems: every call to Orion and Eclipse is a read, bounded by the role your firm grants the credential, revocable by your firm at any time.
- No credential storage for the connection test. Credentials supplied there are used for that request and discarded.
- Client video pages are reachable only by an unguessable per-video link and expose no portfolio data.
- Segregation by construction: the public demo runs on fictional data through code paths that cannot reach a real mailbox or object store.
- Change control through version control, automated tests, and independent review before release.
Not in place yet, and named rather than omitted:
- SOC 2 Type I or II.
- An independent penetration test.
- Per firm credential encryption under a customer managed key.
- Configurable retention and an immutable audit log.
- Archive export to a compliance archiving vendor.
- Regional pinning of stored data.
Annex III. Sub-processors
- Cloudflare, Inc. (United States): compute, key value storage of drift records, object storage of video, access control, and DNS. Global.
That is the entire list. Two other parties are involved and are deliberately not on it. Microsoft receives the draft email, but it is created inside your firm's own Microsoft 365 tenant under your own agreement with Microsoft. Orion and Eclipse are your firm's own systems, which we read from and never write to.
Contact
Questions, objections to a sub-processor, or a request under section 7 go to hello@trueband.app.
See it on fictional households first.
No signup, no call, nothing sends. It runs on fictional households and the buttons in it do not reach a mailbox. Questions it does not answer go to hello@trueband.app.