Who this notice covers
This notice explains how Trusdem handles personal data when you visit trusdem.com, contact us, use a Trusdem account or interact with our payer and business intelligence services. Trusdem operates from Bulgaria and can be contacted at privacy@trusdem.com. The legal entity responsible for a contracted service is identified in the applicable order form or service agreement.
For website operation, account administration, security, business communications and our own legal obligations, Trusdem acts as a controller. For assessment data submitted by a business customer, Trusdem ordinarily acts as that customer’s processor under a data processing agreement. The customer determines the purpose, lawful basis and permitted use of the assessment. If a contract assigns a different role for a particular activity, that contract controls the allocation of responsibilities.
Data we process
- Business contact data, including name, work email, company, role and correspondence.
- Account and access data, including identity-provider identifiers, membership, role, authentication events and security settings. Trusdem does not receive your Google or GitHub password.
- Service and device data, including IP address, request time, browser or client metadata, API request identifiers, audit records and security events.
- Assessment inputs supplied by a customer, which may include a payer name, IP address, email domain, merchant or website context, transaction context, company name, jurisdiction and registration identifiers.
- Source observations from permitted public or licensed sources, including domain and network records, merchant information, search results, public professional context and official business-register records.
- Assessment outputs, including matched entities, confidence, coverage, source provenance, citations, reasoned findings and review guidance.
Where data comes from
We receive data directly from website visitors, account users and business customers. For an authorised assessment, we may also collect information from official registers, technical internet records, search services, public web pages and other sources listed in the assessment report. We record the source and collection time of material observations.
Customers must submit only data they are authorised to process and must give individuals any notice required by law. Trusdem does not authorise customers to use the service for unrelated surveillance, unlawful discrimination or decisions based solely on protected characteristics.
Purposes and legal bases
- Provide accounts, assessments, reports, support and contracted services: performance of a contract or steps requested before entering a contract.
- Operate, secure, monitor and improve the service; prevent abuse; maintain auditability; and communicate with business contacts: our legitimate interests in providing a reliable B2B service, balanced against the rights of affected individuals.
- Meet tax, accounting, security, data-protection and other legal duties, and respond to lawful authority requests: compliance with legal obligations.
- Run optional website analytics or send communications that legally require permission: consent, which may be withdrawn at any time.
- Process customer assessment data as a processor: the customer’s documented instructions and the lawful basis selected by that customer.
Assessment and automated analysis
Trusdem uses deterministic rules and bounded model-assisted analysis to organise source material, evaluate context and produce explainable findings. Outputs include confidence and coverage so a customer can understand the strength and limits of the available information. Source citations are available in the detailed report.
Trusdem does not make a final credit, payment, employment, insurance or legal decision about an individual and does not instruct customers to rely on an assessment as the sole basis for a decision with legal or similarly significant effects. Customers are responsible for human review, their own policy and any rights that apply to their decision process.
International transfers
Our primary production environment is operated in the European Union. Some service providers or source operators may process data outside the European Economic Area. Where Chapter V of the GDPR applies, we use an adequacy decision, approved contractual safeguards or another lawful transfer mechanism and assess supplementary measures where required. Customers may request the relevant transfer information for their service.
Retention
We keep data only for the applicable purpose and retention schedule. Customer assessment data follows the customer’s contracted retention setting, subject to deletion, legal hold and backup-expiry procedures. Account and audit records are retained while needed for access control, security, dispute resolution and legal obligations. Business correspondence is retained for the relationship and an appropriate legal limitation period. Technical logs are retained for the shortest period reasonably needed for security and operations.
When retention ends, data is deleted, anonymised or placed beyond use until encrypted backups expire. A legal obligation, active dispute or documented legal hold may require longer retention. Customers receive more specific schedules in their service documentation.
Security
We use tenant isolation, role-based access, encryption for sensitive fields, transport encryption, scoped service credentials, audit logging and restricted administrative access. No system can eliminate every risk; we review controls and respond to incidents under documented procedures.
Your rights
Depending on the circumstances, you may request access, correction, erasure, restriction, portability or object to processing based on legitimate interests. Where processing relies on consent, you may withdraw it without affecting earlier lawful processing. You may also ask for information about applicable transfer safeguards.
Email privacy@trusdem.com to exercise a right. We may need information to verify your identity and locate the relevant data. If Trusdem processes the data only for a customer, we will refer the request to that customer or support it as required by our data processing agreement.
You may lodge a complaint with the Bulgarian Commission for Personal Data Protection at cpdp.bg, or with the supervisory authority in your country of residence or work. Contacting us first may allow us to address the concern promptly, but it is not a condition of making a complaint.
Children and changes
Trusdem is a business service and is not directed to children. Customers must not knowingly submit children’s data unless the use is lawful, necessary and expressly agreed with Trusdem.
We may update this notice when our processing or legal obligations change. We will publish the revised date and provide additional notice where a change materially affects how we use personal data.
Contact
Privacy and rights requests: privacy@trusdem.com. Business enquiries: contacts@trusdem.com. Legal notices: legal@trusdem.com.