Last updated: March 5, 2026
GDPR Article 28 compliant. This DPA is incorporated into the Terms of Service and governs the processing of personal data by Truncus on behalf of customers.
Need a countersigned DPA?
Enterprise customers requiring a wet-signature or countersigned DPA for procurement purposes can request one at no charge.
Contact legal@truncus.coData Controller
The Customer — the company or individual subscribing to Truncus and determining the purposes and means of email processing.
Data Processor
Van Moose BV, registered in Amsterdam, Netherlands (KvK: 97411698), operating Truncus.
Van Moose BV processes personal data on behalf of the Controller for the sole purpose of transactional email delivery via the Truncus platform. Processing occurs only on documented Controller instructions (email send requests via the Truncus API).
This DPA is in effect for the duration of the Controller's Truncus subscription. All personal data is deleted or returned within 30 days of account termination, except where retention is required by law.
Processing activities include:
End users of the Controller's application or service who receive transactional emails triggered by their interactions with the Controller's platform.
The Controller represents and warrants that:
Van Moose BV commits to:
The Controller consents to the use of the following sub-processors. Van Moose BV will notify the Controller of any intended changes to this list, providing an opportunity to object.
| Sub-processor | Purpose | Location |
|---|---|---|
| Amazon Web Services (SES) | Email delivery infrastructure (primary) | EU (eu-west-1, Ireland) |
| Scaleway (Transactional Email) | EU failover email delivery | EU (fr-par, France) |
| Clerk | Authentication services | United States (SCCs apply) |
| Stripe | Payment processing | United States (SCCs apply) |
| Vercel | Application hosting | United States / EU edge (SCCs apply) |
| Supabase | Database hosting | EU (eu-central-1, Frankfurt) |
| Cloudflare | CDN, DNS, and inbound email routing | United States / global edge (SCCs apply) |
| Sentry | Application error monitoring (error traces only; no email content or recipient data) | EU (Frankfurt) data region; US parent (SCCs apply) |
| Upstash (Redis) | Rate-limit counters, circuit-breaker state. Holds API-key identifiers, sending-domain names and integer counters only — no email content, no recipient addresses, no IP addresses. | EU (Frankfurt); US-incorporated (SCCs apply) |
| SignalLayer (Van Moose) | First-party product analytics. Receives page views and CTA clicks from site visitors, and domain-setup events from signed-in users which include the sending-domain name. No email content, no recipient addresses. | EU; operated by Van Moose (Netherlands) |
| Telegram | Internal operational alerting. Receives alerts for Van Moose’s OWN sending domains only — customer domain names are excluded at the call site and route to email instead. No Controller personal data. | Non-EU (SCCs apply); no Controller data transferred |
Where personal data is transferred outside the European Economic Area (EEA) — specifically via Clerk, Stripe, Vercel, Cloudflare, Sentry, and Upstash — such transfers are governed by Standard Contractual Clauses (SCCs) adopted by the European Commission. Several of these are US-incorporated companies operating EU regions, and are therefore reachable under the US CLOUD Act even where the data itself rests in the EU; we state this plainly rather than describing EU regions as sovereignty. Email delivery (AWS SES eu-west-1 Ireland; Scaleway TEM fr-par France) is processed within the EU and does not constitute an international transfer.
Email content — message bodies, subjects, attachments and recipient addresses — is processed by three sub-processors only: AWS SES (eu-west-1), Scaleway TEM (fr-par) and Supabase (eu-central-1). No other entry in the table above receives email content or recipient addresses.
Technical and organizational measures include:
The Controller is responsible for handling data subject rights requests (access, rectification, erasure, restriction, portability, objection). Truncus will assist the Controller with such requests within 72 hours of written notice at legal@truncus.co.
In the event of a personal data breach affecting Controller data, Van Moose BV will notify the Controller within 72 hours of becoming aware, providing sufficient detail to fulfill the Controller's own notification obligations under GDPR Article 33.
This DPA is governed by the laws of the Netherlands and the General Data Protection Regulation (GDPR). Disputes shall be submitted to the courts of Amsterdam, Netherlands.
Questions or countersigned DPA requests