Privacy Policy | TrustPath Data Protection & Security Standards
Last updated: January 22, 2026
Your privacy is important to us. It is TrustPath's policy to respect your privacy regarding any information we may collect from you across our website, https://trustpath.io. To learn more about how we protect your data and the measures we take for your security, please read our Privacy Policy, writen in German here.
§1 Name and Contact Details of the Controller
This Privacy Policy informs about the processing of personal data on the website of TrustPath.
Controller:
TrustPath UG (haftungsbeschränkt)
Rheinstraße 51,
12161 Berlin
Contact: Contact Form
§1.1 TrustPath's Roles in Data Processing
IMPORTANT: TrustPath processes personal data in different capacities depending on the context. Understanding these roles is crucial for knowing your data protection rights and who to contact regarding your data.
TrustPath operates in the following capacities:
1. As Data Controller (for this website and marketing activities):
- When you visit our website, subscribe to newsletters, or use our contact forms, TrustPath acts as the data controller and determines how your personal data is processed
- Your rights: You can exercise all GDPR rights (access, rectification, deletion, etc.) directly with TrustPath
- Contact: Contact us
2. As Data Processor (for business customer service data):
- When our business customers use our fraud prevention services, TrustPath processes data on their behalf as a data processor
- In this case, the customer is the data controller and determines the purposes and means of processing
- Your rights: If your data is being processed as part of a business customer's use of our services (e.g., identity verification), you should direct your data subject rights requests to that business customer, not to TrustPath
- Example: If a company uses TrustPath to verify your identity during account registration, that company is the controller and TrustPath is the processor
3. As Independent Controller (for fraud prevention database and risk scoring):
- DUAL ROLE NOTICE: In addition to acting as a processor for our customers, TrustPath also acts as an independent data controller when we process and aggregate certain data obtained from various sources for fraud detection and prevention purposes
- This processing serves a substantial public interest and includes:
- Building and maintaining a fraud prevention database by aggregating data from multiple sources
- Using AI/machine learning to identify fraudulent patterns and indicators of illicit activity
- Providing risk scores and alerts to customers based on our independent analysis
- Retaining fraud-related data even after a customer relationship ends, where lawful basis exists
- Legal basis: Legitimate interests (Article 6(1)(f) GDPR) and substantial public interest
- Your rights: You can exercise your GDPR rights, including the right to object (Article 21 GDPR), by contacting us. We will assess your objection and cease processing unless we can demonstrate compelling legitimate grounds that override your interests
- Retention: Data processed in our capacity as independent controller may be retained longer than data processed solely as a processor, as detailed in Section §2.3 below
Why this matters: When TrustPath acts as both processor AND independent controller for the same data, we have dual obligations. Our customers (as controllers) determine how we process data on their behalf, but TrustPath independently determines how we use certain data for fraud prevention purposes. This means:
- Your data may continue to be processed by TrustPath for fraud prevention even after our customer deletes it from their systems
- You may need to exercise certain rights with both the customer (as controller) AND TrustPath (as independent controller)
- Different retention periods may apply depending on the processing purpose
For detailed information about data processing relationships with our business customers, including our dual role as processor and independent controller, please see our Data Processing Agreement.
§2 Scope and Purpose of Personal Data Processing
§2.1 Website Access
When accessing this website, data is automatically sent by the visitor's internet browser to the website's server and stored in a log file. The following data is collected and stored until automatic deletion:
- IP address of the visitor's device
- Date and time of access
- Name and URL of the accessed page
- Website from which the visitor accessed this website (referrer URL)
- Browser and operating system of the device as well as the name of the access provider
Purpose of Processing:
- Fast website connection setup
- User-friendly website operation
- Ensuring system security and stability
- Administrative website optimization
Legal Basis:
Processing is based on Art. 6(1)(f) GDPR (legitimate interest).
Hosting:
The website is hosted by Cloudflare, Inc., 101 Townsend Street, San Francisco, CA 94107, USA. The above-mentioned data is processed under a data processing agreement.
Data Deletion:
The data is deleted after the session ends. Log files remain accessible for up to 24 hours and are permanently deleted within four weeks.
§2.2 Contact Form
Visitors can send messages to the company via an online contact form. A valid email address is required for responding. All other information is voluntary.
- Purpose of Processing: Responding to inquiries
- Legal Basis: Visitor's consent according to Art. 6(1)(a) GDPR
The collected data is deleted once the inquiry is completed, typically within 30 days after the final response.
§2.3 Customer Data Processing (Business Services)
For business customers using TrustPath's fraud prevention services, different data retention periods apply:
- Service Data: Personal data processed through our fraud prevention services is retained for one (1) year from the completion of the relevant query, unless otherwise configured by the customer
- Custom Retention: Business customers can configure custom data retention periods within the TrustPath platform according to their legal requirements
- Testing Data: Data processed during service testing is deleted within 30 days after completion of the testing period
For detailed information about data processing for business services, please refer to our Data Processing Agreement.
§3 Data Sharing
Personal data is only shared with third parties if:
- Consent: Art. 6(1)(a) GDPR
- Legal Claim: Art. 6(1)(f) GDPR
- Legal Obligation: Art. 6(1)(c) GDPR
- Contract Performance: Art. 6(1)(b) GDPR
No sharing occurs in any other cases.
§4 Cookies
This website uses cookies to enable essential functionality and, with your consent, to analyze website usage. For detailed information about what cookies we use, their purposes, retention periods, and how to manage your preferences, please see our Cookie Policy.
Legal Basis:
- Necessary cookies: Art. 6(1)(b) GDPR (contract performance) and Art. 6(1)(f) GDPR (legitimate interest)
- Analytics cookies: Art. 6(1)(a) GDPR (consent)
§5 Website Analytics Services
This website uses Google Analytics 4, a web analytics service provided by Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland). Analytics are managed through Google Tag Manager with Consent Mode v2 and are only activated with your explicit consent.
For detailed information about analytics cookies, data collection, retention periods, IP anonymization, and how to opt-out, please see our Cookie Policy.
Legal Basis:
Art. 6(1)(a) GDPR (consent).
Data Transfer:
Data may be transferred to Google servers in the USA under Standard Contractual Clauses (SCCs) in accordance with Art. 46 GDPR.
§6 Personal Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, TrustPath will:
- Notify the relevant supervisory authority (Berliner Beauftragte für Datenschutz und Informationsfreiheit) without undue delay and, where feasible, within 72 hours of becoming aware of the breach, in accordance with Art. 33 GDPR
- Where the breach is likely to result in a high risk to your rights and freedoms, notify affected data subjects without undue delay in accordance with Art. 34 GDPR
- Provide information about the nature of the breach, likely consequences, and measures taken or proposed to address the breach
- Document all personal data breaches and make this documentation available to the supervisory authority upon request
If you believe your personal data has been compromised, please contact us immediately using our contact form.
§7 Data Protection Officer
Due to the nature and scope of our data processing activities, TrustPath UG is not required to appoint a Data Protection Officer under Art. 37 GDPR. For all data protection inquiries, please use our contact form.
§8 Rights of the Data Subject
You have the following rights:
- Information (Art. 15 GDPR): About your stored data.
- Rectification (Art. 16 GDPR): Have incorrect data corrected.
- Deletion (Art. 17 GDPR): Have data deleted where no legal retention obligation exists.
- Restriction (Art. 18 GDPR): Have processing restricted.
- Data Portability (Art. 20 GDPR): Request transfer to another controller.
- Withdrawal (Art. 7(3) GDPR): Withdraw consent.
- Complaint (Art. 77 GDPR): File a complaint with a supervisory authority.
Supervisory Authority:
Berliner Beauftragte für Datenschutz und Informationsfreiheit
Friedrichstraße 219
10969 Berlin, Germany
Phone: +49 30 13889-0
Email: mailbox@datenschutz-berlin.de
Website: https://www.datenschutz-berlin.de
§9 Right to Object
You can object to the processing of your data at any time (Art. 21 GDPR), particularly regarding direct marketing. To exercise this right, please use our contact form.
§10 Data Security
This website uses SSL (Secure Socket Layer) with up to 256-bit encryption. Technical and organizational security measures protect your data from unauthorized access and manipulation.
§11 United States Data Protection Rights
This section applies to residents of California, Virginia, Colorado, Utah, and other U.S. states with applicable privacy laws.
§11.1 Scope of U.S. Privacy Laws
TrustPath complies with the following U.S. state privacy laws where applicable:
- California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA)
- Virginia Consumer Data Protection Act (VCDPA)
- Colorado Privacy Act (CPA)
- Utah Consumer Privacy Act (UCPA)
- Other applicable state privacy laws
Important: This section applies to our marketing website only. If you are a business customer using our fraud prevention API services, data processing is governed by our Data Processing Agreement and Terms of Service.
§11.2 Categories of Personal Information We Collect
For U.S. residents visiting our marketing website, we collect the following categories of personal information:
| Category | Examples | Collected |
|---|---|---|
| Identifiers | Email address, IP address, device identifiers | Yes |
| Internet or Network Activity | Browsing history on our site, interaction with our website | Yes |
| Geolocation Data | General location derived from IP address | Yes |
| Commercial Information | Inquiry details, service interest information | Yes (if you contact us) |
| Professional Information | Company name, job title (if voluntarily provided) | Yes (if you contact us) |
| Inferences | Preferences and interests derived from website activity | Yes (analytics only) |
We do NOT collect:
- Sensitive personal information (racial origin, health data, biometric data, precise geolocation)
- Social security numbers, driver's license numbers, or government ID numbers
- Financial account information
- Contents of communications (except inquiries you send us via contact form)
§11.3 Business Purposes for Collection
We collect and use personal information for the following business purposes:
- Website operation and security: Providing and maintaining website functionality, ensuring security and preventing fraud
- Communication: Responding to inquiries and providing customer support
- Analytics: Understanding how visitors use our website to improve user experience (with consent)
- Marketing: Sending marketing communications (with consent)
- Legal compliance: Complying with legal obligations and enforcing our terms
§11.4 Categories of Third Parties We Share With
We share personal information with the following categories of third parties:
| Third Party Category | Purpose | Personal Information Shared |
|---|---|---|
| Hosting Providers (Cloudflare) | Website hosting and CDN services | IP address, website activity data |
| Analytics Providers (Google Analytics) | Website analytics (only with consent) | IP address (anonymized), browsing behavior |
| Service Providers | IT services, security, and technical support | As necessary for service provision |
We do NOT:
- Sell your personal information
- Share your personal information for cross-context behavioral advertising
- Process sensitive personal information without your consent
§11.5 Data Retention
- Website logs: Deleted within 4 weeks
- Contact form inquiries: Deleted within 30 days after inquiry completion
- Analytics cookies: Retained for up to 14 months (only with consent)
For business customer data retention, see our Data Processing Agreement.
§11.6 Your U.S. Privacy Rights
If you are a U.S. resident, you have the following rights:
Right to Know (Access):
- Request disclosure of personal information we collect, use, disclose, and sell
- Request specific pieces of personal information we hold about you
Right to Delete:
- Request deletion of personal information we collected from you (subject to legal exceptions)
Right to Correct:
- Request correction of inaccurate personal information
Right to Opt-Out:
- Opt-out of the sale or sharing of personal information (note: we do not sell personal information)
- Opt-out of targeted advertising
Right to Limit Use of Sensitive Personal Information:
- Not applicable - we do not collect or process sensitive personal information
Right to Non-Discrimination:
- We will not discriminate against you for exercising your privacy rights
Right to Data Portability:
- Request a copy of your personal information in a portable format (where technically feasible)
§11.7 How to Exercise Your Rights
To exercise any of these rights:
- Submit a request: Use our contact form and specify which right you wish to exercise
- Verify your identity: We may request additional information to verify your identity
- Response timeline: We will respond within 45 days (extendable by 45 days if necessary)
You may also designate an authorized agent to make a request on your behalf. The authorized agent must provide proof of authorization.
§11.8 California-Specific "Do Not Sell My Personal Information"
We do not sell personal information. TrustPath has not sold personal information in the preceding 12 months and does not sell personal information.
If our practices change, we will update this Privacy Policy and provide California residents with a clear "Do Not Sell My Personal Information" link.
§11.9 California "Shine the Light" Law
California Civil Code Section 1798.83 permits California residents to request information about disclosure of personal information to third parties for direct marketing purposes. We do not share personal information with third parties for their direct marketing purposes.
§11.10 Business Customer Data Processing
Important: If you are an end user whose data is being processed by one of our business customers (e.g., a company using TrustPath's fraud prevention API to verify your identity):
- The business customer is the data controller, not TrustPath
- You should exercise your rights directly with that business
- TrustPath acts as a service provider/processor on behalf of the business customer
- Refer to the business customer's privacy policy for information about your rights
For details about TrustPath's role as a service provider, see our Data Processing Agreement.
§12 Current Status and Changes
Changes due to new legal requirements or website developments will be updated here.
For our German-language privacy policy (Datenschutzerklärung), please visit: https://trustpath.io/de/legal/datenschutz