TRIGGERMINT

UK Packaging EPR Compliance Automation

Data Processing Terms

Effective: 29 September 2026

TRIGGERMINT AI CAPITAL LTD
Company Number: 16688139
Registered Office: 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom
Director: Andre Wessels
Email: [email protected]

These Data Processing Terms form part of the TRIGGERMINT Website & Service Terms where TRIGGERMINT processes personal data on behalf of a business customer.

1. Roles and instructions

The customer acts as controller for personal data submitted to the service and TRIGGERMINT acts as processor to the extent it processes that data on the customer's documented instructions. TRIGGERMINT processes the data only to provide, secure, support and maintain the contracted service, unless required otherwise by applicable law.

2. Processing details

The processing may cover account contacts, customer business contacts, uploaded or connected product and transaction records, supporting documents, audit logs and communications. The duration is the period in which the customer uses the service plus any lawful retention period required for security, contractual or legal records.

3. Confidentiality and security

TRIGGERMINT restricts access to authorised personnel and service providers subject to confidentiality obligations. Appropriate technical and organisational measures include authentication and access control, encryption in transit, protected secret storage, audit logging, logical tenant separation, controlled object storage and recovery procedures.

4. Subprocessors

TRIGGERMINT may use subprocessors where reasonably required to provide the service. Current production infrastructure includes Railway for application hosting and object storage, Supabase for authentication and database services, and Stripe for billing and payment processing. Additional subprocessors are added only where required for enabled features and are subject to appropriate contractual and security controls.

5. International transfers

Where personal data is transferred outside the United Kingdom, TRIGGERMINT uses an applicable lawful transfer mechanism and appropriate contractual safeguards where required. The current infrastructure may involve processing outside the UK depending on the service provider and deployment region.

6. Data-subject requests and regulatory assistance

Taking into account the nature of the processing, TRIGGERMINT will provide reasonable assistance to the customer with requests concerning data-subject rights, security obligations and regulatory enquiries relating to the processing performed by TRIGGERMINT.

7. Security incidents

TRIGGERMINT will notify the customer without undue delay after becoming aware of a personal-data breach affecting customer-controlled personal data and will provide information reasonably available to support the customer's legal obligations.

8. Return and deletion

On termination, customer data is deleted or returned in accordance with the service's retention process, except where continued retention is required by law, security requirements or legitimate evidential records. Backup copies are removed in accordance with the applicable backup lifecycle.

9. Audit information

TRIGGERMINT maintains technical and organisational records relevant to the service and will provide information reasonably necessary to demonstrate compliance with these terms. Audit requests must be proportionate, protect other customers and TRIGGERMINT confidential information, and avoid unnecessary disruption.

10. Contact

Data-processing questions may be sent to compliance@{PUBLIC_DOMAIN}.