Trust & Compliance
Last updated: October 4, 2026
This page is for the security, legal and procurement teams reviewing T2D3 Inc. ("T2D3") and the T2D3 Operating System (the "Service"). It gathers what a vendor review usually asks for in one place and links to the binding text in our Privacy Policy and Terms of Service.
At a glance
- Data Processing Agreement — available to every business customer, with the EU Standard Contractual Clauses and the UK Addendum.
- Sub-processors — every provider named, with at least 30 days' notice before a new one is added.
- Breach notification — affected customers and supervisory authorities, within 72 hours where GDPR requires it.
- AI training — your prompts and outputs are never used to train our models or our providers' models.
- Certifications — no SOC 2 report or ISO/IEC 27001 certificate yet; we say so plainly below.
1. Data Processing Agreement (DPA)
Where T2D3 processes personal data on your behalf, we act as your processor and you remain the controller. We sign a Data Processing Agreement with business customers who need one, covering the terms GDPR Article 28 requires: processing only on your documented instructions, confidentiality of personnel, security measures, sub-processor flow-down and notice, assistance with data-subject requests, breach notification, deletion or return of data at the end of the engagement, and audit cooperation.
For transfers from the European Economic Area, the United Kingdom and Switzerland, the DPA incorporates the European Commission's Standard Contractual Clauses (2021) and the UK International Data Transfer Addendum, as described in Section 7 of our Privacy Policy.
To request a DPA for signature, email privacy@t2d3.club with your company's legal name, registered address and the name of the person who will sign.
2. Sub-processors
The current list of sub-processors — who each one is and what it does for the Service — is maintained in Section 4 of our Privacy Policy. Each is bound by a data processing agreement and processes personal data only to perform its function.
We give at least 30 days' advance notice of a new or replacement sub-processor by email or in-app notification, so you can raise an objection before the change takes effect.
3. Security controls
- Encryption in transit (TLS 1.2 or higher) and at rest (AES-256).
- Row-level security enforced in the database, so one organization's records cannot be read through another's session.
- Role-based access and least privilege for our own team, with multi-factor authentication on all administrative and production access.
- Regular security reviews and dependency scanning.
- Logging and monitoring of access to production systems.
The full statement is in Section 10 of our Privacy Policy. We complete security questionnaires on request — send yours to privacy@t2d3.club.
4. Certifications (SOC 2, ISO/IEC 27001)
T2D3 does not currently hold a SOC 2 report or an ISO/IEC 27001 certificate. We would rather tell you that here than have it surface at the end of a review. When an audit is under way we will name the auditor and the expected report date on this page.
Our hosting, database and payment providers publish their own independent security attestations; we can point you to the ones relevant to your review on request.
5. AI processing and the EU AI Act
The Service uses general-purpose AI models from third-party providers to draft and analyze business-to-business marketing work: positioning, personas, content and planning. It is not designed or offered for the high-risk purposes listed in Annex III of the EU AI Act (for example employment decisions about individuals, credit scoring or access to essential services), and it performs none of the practices the Act prohibits.
How we meet the obligations that do apply to us as a deployer of AI:
- Transparency. AI output is presented as a draft, and where it is grounded in your own material the product shows the sources it drew on.
- Human oversight. AI output is a draft for people in your team to review, edit and approve; the product's lock step records that a person accepted it.
- No training on your data. Prompts and outputs are not used to train our models or our providers' models. Providers may keep them for up to 30 days for abuse monitoring; zero-retention arrangements are available on our top-tier plans where the provider supports them. See Section 3 of our Privacy Policy.
This describes how we have assessed the Service under the Act; it is not legal advice for your own obligations.
6. Incident response
If a personal data breach affects your data, we notify you and the relevant supervisory authorities in accordance with applicable law, including within 72 hours where GDPR requires it. The notice describes what happened, the data involved, the likely consequences and the measures taken.
To report a suspected vulnerability or incident, email privacy@t2d3.club.
7. Your data at the end of an engagement
- Return. Before deletion, you can ask for a copy of your organization's data in a structured, machine-readable format.
- Deletion. We delete or anonymize account data and content within 30 days of a deletion request, except records the law requires us to keep (for example tax records for 7 years).
- Backups. Deleted data can remain in encrypted backups for up to 90 days, until normal backup rotation purges it.
- AI providers. Provider-side copies follow the retention described in Section 5 above.
Retention by data category is set out in Section 5 of our Privacy Policy; how to request deletion is on our Delete your account page.
8. Audit logging
Workspace audit logs record administrative and data-handling actions (who did what, and when) for your organization's administrators. Audit logging is deliberately non-blocking: if an entry cannot be written, the action still completes rather than failing. The audit log is therefore a best-effort accountability record, not a guaranteed-complete ledger. Infrastructure-level logging of production systems runs independently of it. See Section 10 of our Privacy Policy.
9. Contact
For DPA requests, security questionnaires and data-protection questions:
T2D3 Inc.
Attn: Privacy
7300 State Highway 121, Suite 300
McKinney, TX 75070
United States of America
Email: privacy@t2d3.club