TrustArc Terms and Conditions

TrustArc Privacy Notice

Last updated and effective date: August 12, 2026 


This Privacy and Data Processing Policy ("Notice") reflects TrustArc Inc's ("TrustArc") global privacy practices and standards as of the effective date. TrustArc is a technology-powered privacy solutions company headquartered at 2121 N. California Blvd., Suite 290, Walnut Creek, CA, USA. TrustArc also operates through its subsidiaries: TrustArc Canada Inc. (formerly Nymity Inc.), TRUSTe Europe Ltd. in the UK, TRUSTe Web Services Technologies, Inc. in the Philippines, and TRUSTe LLC in the USA.


Scope of This Notice

This Notice covers our online and offline interactions with you where TrustArc decides how your personal information is processed. For example, when you visit our websites or applications that link to this Notice, when you interact with our marketing or sales teams, when you manage your TrustArc account, or when you contact our support team.


This Notice does not apply to personal information that TrustArc processes on behalf of its customers in connection with providing our software-as-a-service solutions (“solutions”) and services. In those contexts, TrustArc acts as a data processor, service provider, or the equivalent construct under applicable law. Our Data Processing Addendum, customers' instructions, and our customers' own privacy notices govern the collection and use of that data. If you have questions about how a TrustArc customer handles your personal information, please contact that organization directly.


Our online properties may include links to websites and services operated by other (i.e., third-party) companies not under TrustArc's control or direction. If you provide personal information to those sites or services, their privacy policies, not this Notice, apply.


We only use data collected in a third-party context through trustarc.com, truste.com, and truste-svc.net for purposes related to managing consent preferences. We do not use or share such data to enable tracking of particular users or devices by other services.


Privacy is Our Business

At TrustArc we help promote responsible data use and stewardship among businesses and suppliers around the world. Our privacy practices incorporate the following values, which align with global standards including, but not limited to, CCPA, GDPR, OECD, and the EU–US Data Privacy Frameworks:

  • Transparency - We are open about how we collect, use, and share information.
  • Fairness and Trust - We handle your information responsibly and only for the purposes we've explained.
  • Compliance - We comply with applicable laws, regulations, and contractual obligations.
  • Security & Confidentiality - We implement appropriate safeguards to protect your information from unauthorized access.Accountability - We take responsibility for protecting your data and honoring our commitments.

Your Personal Information

What is Personal Information?

Personal information, as defined under applicable law that applies to you, generally means  data that identifies, relates to, or could reasonably be linked with you, such as data used to locate, track, or contact you.


What Personal Information Do We Collect?

We collect personal information in connection with your interactions with us. This may include:

  • IP address
  • Browser/device data
  • Cookie and tracking data
  • Web form submissions
  • Name, job title, email, and company
  • Account credentials and user profile information
  • Platform usage activity and logs
  • Support requests or communications
  • Request type (as submitted to our customers)
  • Metadata (e.g., time, method, IP address)


We do not collect biometric information.


What Categories of Personal Information Do We Collect?

The categories of personal information we collect depend on how you interact with us and use our products and services. You may fall into one of the following data subject categories:


Website Visitors

  • We monitor website visitors to administer our site and to understand how visitors navigate it. This information is used to deliver and maintain website features and functionality, and is processed based on our legitimate interest in ensuring the site operates as intended for visitors.  Specifically, we collect:
    IP address and browser/device data: We automatically receive and log server file information transmitted by your browser when you visit our websites, including IP address, browser type, referring and exit pages, and operating system.
  • Web form submissions: We process information you elect to provide (e.g., by using our Contact Us form) such as your name, email, company, phone number, job function, job title, country, and any comments to respond to your requests or to reach out regarding potential business opportunities. Where we are permitted or have obtained consent to do so, we may send marketing communications to the email address you submit. You can withdraw your consent or opt out at any time using the unsubscribe link in those emails. Note that completing another form after opting out will cancel your opt-out.
  • Cookie and tracking data: We collect personal information through cookies and online trackers, which may include IP address, usernames, email addresses, preferences, behaviors, and browsing activity on our website.


Customers and Users (B2B)

  • Name, job title, email, and company name: If you request information about our solutions and services, or partnership opportunities, we process your name, email, phone number, job title, company information, and any comments you provide.
  • Account credentials and user profile information: If you are a licensed or authorized user of our solutions, we process your name, email, username, password, IP address, job title, phone number, company information, actions taken in products and services (such as record creation, changes, approvals, and responses), and support tickets filed on your behalf.
  • Platform usage activity and logs: We may collect technical logs, visit counts, and information about how our solutions are used, excluding your content and data. This information is used only in aggregated and anonymized form to understand customer and market needs, improve our solutions, design new offerings, and inform partnership and business development decisions.


Individuals Using Customer Tools (e.g., DSAR forms and Cookie Consent Manager)

  • Name, email, and request type: When you submit an individual rights request through a form on a company's website that uses TrustArc's Individual Rights Manager, we process the information provided in that form, which may include your name, email, residence, request type, individual type, any comments, and any additional information required to verify your identity, to support the management and fulfillment of your request. All related communications will be managed through our Individual Rights Manager solution. A company may collect sensitive personal information through their customized forms only where expressly permitted by TrustArc.
  • Consent records and connection metadata (e.g., time, method, IP address): If you have given consent through our Cookie Consent Manager (CCM), we process your full IP address at initiation, temporarily, solely to infer your location and serve the correct cookie banner. We then immediately mask the IP address and record your consent choice (opt-in or opt-out), storing it in our CCM application at our data center in Dublin, Ireland, for 13 months. If you are located in India, your consent choice will be stored in Mumbai, India.


General Consumers

This category covers individuals who engage with us in ways not described above, such as respondents to customer assessments or vendors. Depending on the activity, we may collect various categories of personal information. These activities may overlap, for example, a customer might visit our website and share information through multiple channels. If you provide personal information online by filling out a form, attending a webinar, or through cookies or tracking technologies, we will use it only for the purposes described in this notice and in accordance with applicable law.


How Do We Collect Your Personal Information?


Directly from customers and their users

Authorized users or individuals named in our solutions, such as respondents to customer assessments, fall under the control of our customers, for whom TrustArc acts as a service provider. Because we process this data solely on our customers' behalf and instructions, TrustArc cannot grant access to or delete this information without the customer's permission.


When you use the platform and website

We use cookies and other data collection technologies to help you navigate our website and solutions, prevent fraud and abuse, personalize your experience, analyze page visits and feature usage, provide social sharing and video functionality, measure advertising effectiveness, and deliver content from third-party content partners.


From third-party integrations (e.g., SSO, CRM, analytics tools)

We may supplement contact details such as your name, job title, and company with business data from third-party sources such as business intelligence providers and publicly available sources like LinkedIn. We may also receive information about the frequency of your interactions with us online and offline at events, webinars, via email, and on our website. In some cases, information about you may come from colleagues or third-party sources such as ZoomInfo.


On behalf of customers via TrustArc powered  tools (as a processor/sub-processor)

In both scenarios below, TrustArc acts as a processor or sub-processor on the customer's instructions. The customer determines the processing purpose and is responsible for communicating with you directly.


B2B workflows (e.g., vendor assessments, data inventories): When you engage with our solutions as an authorized user or as a non-system user completing a task a customer has sent you, you can direct questions to the customer or to TrustArc.


Consumer-facing solutions (e.g., Individual Rights Manager, Cookie Consent Manager): When you interact with these tools, the customer's basis for processing is typically consent, though you should confirm this with the customer directly.


If a customer has implemented our Consent & Preferences Manager, we process data related to you as directed by that customer to help them manage your consent and preferences. While customers may customize the categories of personal information they collect, we do not recommend the collection of sensitive personal information and do not permit it without prior authorization.


If you click an icon associated with our Ads Interests Manager in an online advertisement, we process information about your interests and use cookies to deliver opt-out tools and measure usage. Our opt-out tool signals to ad companies not to use your browsing behavior for interest-based advertising by setting an opt-out cookie in your browser. Note that clearing your browser cookies will remove these opt-out cookies as well; you will need to re-access the opt-out tool to reset your preferences.


Where is Your Personal Information Stored or Accessed?

Because TrustArc has engineering, product, and support operations in the U.S., Canada, India, and the Philippines, personal information may be accessed from these locations. Most information is hosted at Amazon Web Services (AWS) in the U.S.; however, Cookie Consent Manager and Consent Manager are hosted at AWS in Ireland and India. We offer optional data hosting in Germany for all customers, and in India for customers doing business there. Our remote work environment may also result in employees or contractors accessing data from countries such as Australia, Brazil, Colombia, and the United Kingdom. More information about our sub-processors and affiliates can be found here.

How We Use Personal Information

The way we use your personal information depends on how you interact with us and our solutions and services. Where we process personal information, we do so on one or more of the following legal basis: performance of a contract, legitimate interests, compliance with legal obligations, or consent. Where we act as a data processor on behalf of our business customers, we process personal information only as directed by them, in accordance with the legal basis they have identified for such processing. If you are in a jurisdiction that does not recognize legitimate interest as a legal basis, we will obtain your consent prior to processing.


  • We process personal information for the following purposes:
    To provide and support our solutions
  • To authenticate users and manage accounts
  • To respond to customer support inquiries
  • To improve platform performance and usability
  • For security, auditing, and incident prevention
  • For marketing and outreach (with appropriate consent or opt-out rights)
  • For legal and compliance purposes


Some of the information we ask for is required to set up or manage your account or services. Fields marked as required must be completed. If we don't have this information, we may not be able to provide the service you need.

Purpose
Personal Information Processed
Legal Basis
Marketing Communications
Name, phone number, email address, postal address, job title, job function, company name, product interest, and responses to communications. We also track whether, when, and from which IP address and city a marketing communication was viewed, along with company size, financial information, and current or prospective customer status, to manage and improve our outreach.
Legitimate interests to market our solutions and engage existing and prospective customers; to manage and improve our communications.  Consent where required by applicable law. You may opt out or withdraw consent at any time using the unsubscribe link in any email.

General Consumer Surveys
No identifying personal information is collected. Responses are used only in aggregate (e.g., all "Yes" or "No" answers to a question) and cannot be linked back to individuals.
Legitimate interests to understand public views on privacy-related issues and improve our solutions. Because no personal information is collected, individual consent withdrawal is not applicable.
Market & Product Research Surveys
Email address, job title, phone number, company name, job function, state, country, relationship with TrustArc, survey responses, and any comments provided. Surveys may be delivered by us or by a service provider on our behalf. A one-time remuneration (such as a gift card) may be provided in exchange for participation.
Legitimate interests to understand customer needs and improve our solutions. Consent. Participation is voluntary and you may unsubscribe from future survey communications at any time.
Customer Community Participation
Name, contact details, and any information you choose to share through community activities such as online discussions, group meetings, and collaborative engagements.
Consent. Participation requires your consent, which you may withdraw at any time by leaving the activity. Engagement rules apply and vary by the method of engagement.
Webinars & Events
Attendees: Registration details, IP address, technical information, and any comments or feedback provided to the hosting platform (e.g., Zoom).  Featured guests: Name, email address, phone number, company name, job title, image, and voice. By participating as a speaker, you consent to the session being recorded and broadcast publicly on TrustArc’s website and our corporate social media channels for educational and promotional purposes.
Legitimate interests to host, promote, and follow up on events. Follow-up communications are sent to the registered email; you may unsubscribe at any time. Consent for guest participation and recording.
Recorded Calls  & Video Conferences

Name, email address, job title, image, and voice, used for training, customer relationship management, and providing recordings to customers upon request (e.g., a recording of a product demo).
Consent. Recording only proceeds with your consent. Notice of the intent to record is provided before any call begins.
Business Intent Signals
Company- and organizational-level interest signals, received from third-party providers, based on interactions with content across third-party websites. These signals indicate interest in certain topics, products, or services and are not used to identify individuals. Appropriate safeguards are applied throughout this process.
Legitimate interests to prioritize outreach, personalize communications, and improve our marketing efforts. You have the right to opt out of or object to this processing at any time, either by contacting us or using the unsubscribe link in our emails.
Contract Execution & Delivery
Name, email address, postal address, company name, billing information (purchase order numbers, bank wire details, credit card information), company size, company financial information, signature, communication content, and feedback. Note: We do not make automated decisions about you that would result in legal or other significant effects.
Performance of a contract that is necessary to enter into and fulfill agreements, process payments, and administer services.
Customer Relationship Management & Subscription Renewal
Interaction records, product usage data, communication history, company size, company financial information, and current or prospective customer status. We analyze online and offline interactions to better understand your needs, improve engagement, and determine when you may be ready to make a purchase or renew a subscription.
Performance of a contract to fulfill our contractual obligations and renew subscription-based solutions.  Legitimate interests  to improve engagement and retain customers.
Using Our Solutions (as customer or authorized user)
Business information relating to your organization, including practices, policies, processes, and supporting documentation, stored and used solely to deliver the solutions your organization has contracted us to provide.
Performance of a contract in accordance with the terms of your agreement with TrustArc.
Customer- Directed Processing (TrustArc as data processor)
Contact information and identifiers input by TrustArc customers through our platform (e.g., to send a Nymity Reference or other materials). TrustArc acts solely as a data processor on the instructions of the customer.
As directed by our customers where the customer is the data controller and is responsible for the lawful basis for processing. Please refer to the relevant customer's privacy notice for details.
Website Operations & Privacy Requests
Cookie preferences, IP address, device type, browser information, and details submitted through our Individual Rights Manager. When you engage with our Cookie Consent Manager or submit a privacy rights request, TrustArc acts as the data controller and is directly accountable for honoring your preferences and requests.
Legitimate interests to operate, secure, and improve our website. Consent where required by applicable law, for the processing of non-essential cookies and for handling rights requests submitted by individuals.
Support Requests & Account Management
Account details, authentication information, support communications, and issue details, used to provision and manage accounts, provide customer service, deliver assurance programs and seals, resolve disputes, send platform alerts, and help customers build and demonstrate their privacy programs.
Performance of a contract to deliver and administer contracted solutions and services.  Legitimate interests to improve our support and resolve issues effectively.

TRUSTe Dispute Resolution
Name, email address, country, and complaint details (including TRUSTe certification complaints and trademark misuse reports). Additional information is optional. We will not share your identity with the subject of the complaint without your consent. If you reside in a country with cross-border transfer rules, you must consent to your information being sent to the United States or other countries where we have offices and process personal information for dispute resolution purposes, such as Canada and the Philippines. Without this consent, we cannot process your information or register your complaint.
Consent. Submission constitutes consent to processing and, where applicable, cross-border transfer. Without consent, we cannot register or process your complaint. Compliance with legal obligations to maintain required records for our certification and dispute resolution programs.
Record-Keeping & Legal Compliance
Business records, communication records, and any personal information necessary to meet legal, financial, regulatory, or reporting obligations, or to enforce our rights and agreements.
Compliance with legal obligations. We retain information as required by law.  Legitimate interests to enforce our rights and agreements and to maintain records necessary for our business operations.


We do not utilize the data we collect to make automated decisions that would result in legal or other similarly significant effects for you or your business.


Where processing is based on consent, you may withdraw consent at any time using the unsubscribe link in our emails or by contacting us through our Individual Rights form.


Cookies and Online Tracking Technologies

We use two types of browser cookies: session cookies, which expire when you close your browser, and persistent cookies, which remain on your device until they expire or you delete them.


We group cookies and other online tracking technologies on our site into three categories, all manageable through our Cookie Consent Manager. You can update your online tracking preferences at any time by clicking the Cookie Preferences link in the footer of our webpages.


  • Required cookies: Necessary for core site functionality, including security and bot detection (Google reCAPTCHA, BotDetect Captcha), accessibility compliance, font rendering, tag management, and managing your cookie consent preferences through TrustArc's consent platform.
  • Functional cookies: Support site performance and enhanced functionality, including analytics and performance monitoring (Google Analytics, New Relic), content delivery, video playback (Vimeo), live chat support (LiveChat), embedded content such as presentations and data visualizations, job listing integrations, and visitor intelligence tools.
  • Advertising cookies: Used by advertising and marketing platforms to deliver relevant ads, track campaign performance, and identify returning visitors. These may be set by ad networks (Google Advertising Products, Xandr, LiveIntent), social media platforms (LinkedIn, X, Reddit), and marketing automation tools (Marketo), as well as sales intelligence services to help us identify and engage with potential customers.


Global Privacy Control (GPC)

The Global Privacy Control (GPC) signal is another way to communicate your tracking preferences. To use GPC, download a supported browser or extension at globalprivacycontrol.org. Note that GPC must be enabled separately for each browser or extension you use.


If you clear your browser history, any opt-out cookies we have set will also be removed. You will need to revisit the Cookie Consent Manager to re-establish your preferences.


Cross-browser and cross-device recognition

We do not connect your browser or device to other personal information unless you provide it directly. However, some of our customers may recognize you across browsers or devices based on information they have collected, and may direct us to store an identifier (such as an IP address) within their Cookie Consent Manager instance. Please visit those customers' websites or contact them directly to learn more about their data practices.

TrustArc's AI-enabled Features

TrustArc offers optional AI-enabled features within its solutions. We won't process or transmit your data to any AI technology unless you actively use one of these features, and you'll receive appropriate notice before any AI processing occurs, including an in-product notice at the point of engagement where AI features interact directly with users, consistent with applicable AI transparency requirements. Data you submit when using an AI-enabled feature (queries, inputs, uploaded content) is used solely to provide the requested functionality under your Agreement with TrustArc. We don't use your data for AI model training or improvement: AI services within TrustArc solutions are opted out of LLM training by default and process data only to generate responses for authenticated users within the TrustArc environment.


To ensure platform performance and fair access, TrustArc monitors usage of AI-enabled features, including query volumes, token consumption, and API usage. This monitoring is for operational purposes only and doesn't profile individual users. If your usage materially exceeds reasonable thresholds, TrustArc may throttle or temporarily suspend your access under your Agreement. During any such suspension, your data continues to be protected in accordance with TrustArc's Data Processing Addendum. Any such suspension doesn't affect your right to request cessation of AI-related processing or to request deletion or return of your data.


AI-enabled features are supported by vetted third-party AI service providers, listed in TrustArc's Terms of Use for Artificial Intelligence Features. These providers operate under contractual obligations covering confidentiality, data protection, and security as set out in TrustArc's Data Processing Addendum. We don't sell your data or disclose it for purposes unrelated to delivering our solutions. Where a change in AI service provider materially affects your data processing, TrustArc will provide at least 30 days' advance notice.


AI-generated outputs may contain errors. You're responsible for reviewing and validating results before reliance, and shouldn't use AI outputs for decision-making without appropriate human oversight. We recommend avoiding submission of sensitive or proprietary information unless appropriate safeguards are in place. You may discontinue use of any AI-enabled feature at any time; upon request, TrustArc will promptly cease related data processing and handle deletion or return requests consistent with our contractual commitments. In the event of a security incident involving AI-related processing, we'll notify you consistent with our legal and contractual obligations. All data subject rights described in the Your Rights section apply equally to personal data processed through AI-enabled features. To submit a request, use our Individual Rights Manager form.

Your Choices Around the Use and Disclosure of Your Personal Information

Where we use your personal information for a purpose materially different from the one for which it was originally collected, or disclose it to a new third party not described in this Notice, we will notify you and provide an opportunity to opt out before doing so. To opt out, contact us as described in the Contact Us section below or use our Individual Rights form.

Your Rights

Individuals may have rights under applicable privacy and data protection laws regarding the personal information we process about them. To submit a request or exercise any such rights, you may use our Individual Rights Manager form, by emailing privacy@trustarc.com, or by contacting us via telephone. We do not usually charge a fee to handle your request. We will respond within the timeframe required by applicable law and may extend this period where permitted, for example if your request is complex or you have submitted multiple requests. We will honor your requests as permitted by law. In some situations we may be unable to fully comply, in which case we will explain our reasons and advise you of any applicable options.


Individual Rights


Information / Right to Know You have the right to request confirmation of whether we process your personal information and to receive details about it — including the categories we hold, the sources, the business or commercial purpose for collection or sale, the categories of third parties with whom we've shared it, and whether we collect sensitive information or inferences.


Access You have the right to access the personal information we process about you and to receive a copy of it. Depending on your residency, you may request access free of charge, twice per year, to information collected in the last 12 months — or for a longer period, provided it was collected on or after January 1, 2022.


Correction You have the right to request correction of inaccurate, outdated, or incomplete personal information. TrustArc will notify processors to whom the information has been disclosed of any updates, unless doing so is impossible or involves disproportionate effort.


Deletion You have the right to request deletion of the personal information we have collected from or obtained about you. We typically retain personal information for the minimum period necessary to fulfill the purposes outlined in this Notice, unless a longer retention period is required or permitted by law. Please note that in many situations we must retain all or a portion of your information to: comply with legal obligations; resolve disputes; enforce our agreements; protect against fraudulent, deceptive, or illegal activity; or for other business purposes aligned with the delivery of our contracted solutions and services. Where we have not collected identifying information, we may be unable to locate and remove your specific data.


TrustArc will notify processors to whom the information has been disclosed of any deletion, unless doing so is impossible or involves disproportionate effort.


Restriction You have the right to temporarily or permanently limit our processing of some or all of your personal information, where applicable.


Portability You have the right to request that your personal information be transferred to you or a third party in a format that is easily understandable and, to the extent technically feasible, in a structured, commonly used, machine-readable format — where we process data based on your consent or a contract with you.


Consent Withdrawal Where we rely on your consent to process your personal information, you have the right to decline or withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing that occurred before the withdrawal.


Opt-Out / Right to Object You have the right to opt out of the processing of your personal information. Where you do so, we will stop processing unless we have compelling legitimate grounds or another valid legal basis. You may also opt out of our use of your personal information that we have made available or disclosed to third parties for advertising purposes.


Right to Opt Out of Sale or Sharing We may "sell" or "share", as defined under applicable laws, the following categories of personal information by making them available to third parties using online tracking technologies: device information and other unique identifiers, internet or network activity, geolocation data, and IP address and browser information. Categories of third parties include advertisers and marketing partners, data analytics providers, and social media networks.


You may opt out by submitting the Do Not Sell or Share My Personal Information form, using the "Do Not Sell or Share My Personal Information" link at the bottom of our website, or by emailing privacy@trustarc.com or calling 1-866-I-OPT-OUT (467-8688), service code 751.


If you do not provide the information needed to identify you, we may not be able to process your request. Information you provide for this purpose will not be used, disclosed, or retained for any other purpose.


We support the Global Privacy Control (GPC) opt-out signal. If you have enabled GPC in a supported browser or extension, we will treat it as a valid opt-out request under applicable privacy laws. GPC must be enabled separately for each browser or extension. California residents will receive confirmation on our website when their GPC opt-out has been processed.


If you would like us to link your browser to your account when submitting an opt-out or GPC signal, and you have not yet opted out, we recommend submitting your request via the Do Not Sell or Share My Personal Information link above.


Right of Nondiscrimination We do not discriminate against individuals who exercise any of the rights described in this Notice.


How to Exercise Your Rights


Identity Verification To process certain requests, we will need to verify your identity. Depending on the request type, we may ask for your name, email address, residence, request type, and any comments you provide. We may request additional details as needed for verification. We do not solicit sensitive personal information and seek to collect only the minimum necessary to verify your identity.


Authorized Agent You may designate an authorized agent to submit a request on your behalf. To do so, you must: (1) provide the agent with written and signed permission to act on your behalf; and (2) verify your own identity directly with us. Some jurisdictions require specific methods for authenticating agents; we may deny a request from an agent that does not submit proof of authorization.


If you have been designated as an authorized agent for another individual, you must make the appropriate selection when submitting the Request Form.


Responding to Requests We will respond within the timeframe permitted by applicable law. We may charge a reasonable fee for multiple requests within the same 12-month period, where permitted by law. If we deny your request, or any portion of it, we will inform you of the reason for the denial and provide information about any available options, including the right to appeal our decision where applicable.


Appealing a Decision If you wish to appeal a response to an Individual Rights Request, please contact us at privacy@trustarc.com or in writing at:


TrustArc Inc | 2121 N. California Blvd., Suite 290, Walnut Creek, CA 94596, USA | Attn: IRM Appeals


When you submit an individual rights request, we will use your information to respond and to verify your identity. We will respond by email in most cases. If you wish to withdraw your request, you may do so via that email.

Note: TrustArc processes certain personal information solely on behalf of our business customers, who act as the data controllers. In these cases, we act as a data processor and handle your information according to the customer's instructions. To exercise your privacy rights regarding that information, please contact the relevant business customer directly.


Additional Information for U.S. Residents

This Privacy Notice is designed to comply with applicable privacy and data protection laws globally, including U.S. state consumer privacy laws. We have adopted a single, unified Notice that addresses the core disclosure requirements common to all applicable laws and regulations. Where a specific law or jurisdiction imposes additional or distinct requirements, those are addressed within the relevant sections of this Notice.

How We Share Personal Information

TrustArc is a B2B company that sells software solutions to other businesses. You may interact with our solutions because your company has purchased them or because you work with a company that does business with our customers. In most cases, the information involved is business rather than personal information, but we do not control what information our customers enter about you.


At TrustArc, we only disclose personal information in the ways described in this Notice. We do not sell personal information in exchange for monetary or other valuable consideration. Some privacy laws, however, define "sale" or "sharing" more broadly to include disclosures made for commercial purposes such as targeted advertising and cross-context behavioral advertising, regardless of whether money changes hands.


Under that broader definition, in the past 12 months we have shared the following categories of personal information with advertising networks, analytics providers, and marketing partners for these purposes:

  • Device identifiers and other unique identifiers
  • IP address and browser information
  • Internet or network activity, including browsing behavior
  • Geolocation data


This sharing allows us to deliver more relevant marketing about our solutions to visitors likely to be interested in them. We do not knowingly sell or share the personal information of individuals under 18 years of age, nor use it for advertising purposes.


You can opt out of this sharing at any time by managing your Cookie Preferences, submitting a Do Not Sell or Share My Personal Information request, or, if you've enabled it, through your browser's Global Privacy Control signal.


If personal information covered by this Notice is to be disclosed to a third party not acting as a service provider or vendor in a manner not specified in this Notice, TrustArc will provide you with an opportunity to choose whether to have your personal information disclosed. Requests to opt out of such disclosures should be sent to us as specified in the Contact Us section below or through our Individual Rights form.


With Service Providers (e.g., Cloud Hosting, Support, Analytics)

We disclose personal information to service providers and vendors that support our business activities. These providers are authorized to process information only as necessary to provide the applicable service and as directed by us, in support of the purposes described in the "Your Personal Information" and "How We Use Personal Information" sections above. Some of these providers qualify as "sub-processors" under the GDPR, as they are engaged in the provision of services our customers have contracted with us to deliver. View a list of our sub-processors.


With Integration Partners (If Authorized by the Customer)

TrustArc works with a variety of partners, to whom we may disclose your information on a legitimate basis as described in this Notice, or from whom we may receive information. Partners are only permitted to process your information as necessary and as directed by us. In some cases, partners are contracted through TrustArc; in others, they may disclose your information to us, in which case their privacy notices also apply.


Within Our Corporate Group

TrustArc may share personal information within its corporate group to carry out functions consistent with the purposes described in the "How We Use Personal Information" section.


In the Event of a Business Transaction

In the event of a merger, acquisition, divestiture, or asset sale, personal information may be disclosed to the acquiring organization, provided they agree to the protections set out in this Notice, where within our control. In cases where we are subject to court oversight (e.g., bankruptcy proceedings), we may not have full authority to ensure this protection.


As Required by Law or Legal Process

If required to disclose personal information as part of a legal process, we will take commercially reasonable steps to inform you. We may also disclose personal information in response to lawful requests from government or law enforcement authorities, including national security agencies. We may disclose personal information where we believe in good faith it is necessary for safety, fraud prevention, or protection of our rights.

Data Retention

We retain personal information only as long as necessary to fulfill the purpose for which it was collected including performing our contract with you, meeting legal or contractual obligations, resolving disputes, and serving our legitimate interests.


Information related to authorized users or individuals named in our solutions (such as respondents to customer assessments) is subject to customer control. TrustArc cannot grant access to or delete such information without the customer's permission. We retain it for the duration of the customer contract, and delete it as required by the customer or within an agreed timeframe (generally three years from the date of contract termination).


We will retain personal information about you for as long as we provide solutions to you or your company; as long as you work with us; as long as we are addressing a concern, question, complaint, or request; as required by law; or for as long as needed to respond to investigations or lawsuits. Where we have a contract or agreement with you or your company, we follow its retention obligations.


You may decline to be recorded at any time before or during a meeting, and may request deletion of a recording at any time. All recorded meetings are automatically deleted within 180 days.


Criteria for Determining Retention Periods

We retain personal information for as long as necessary to fulfill the purposes for which it was collected, taking into account the following criteria:


  • Purpose of collection — We retain personal information for as long as is necessary to fulfill the specific purpose for which it was collected, as described in this Notice. Once that purpose has been achieved, we will delete, anonymize, or de-identify the information unless another criterion below requires otherwise.
  • Contractual obligations — Where we have an active contract or agreement with you or your organization, we retain relevant personal information for the duration of that relationship and for a reasonable period thereafter, as necessary to fulfill our post-contractual obligations or to address any potential disputes arising from the contract.
  • Legal and regulatory obligations — We retain personal information for as long as required to comply with applicable laws, regulations, or regulatory guidance including tax, financial reporting, employment, and consumer protection laws. Retention periods mandated by law take precedence over shorter internal retention schedules.
  • Legal claims and dispute resolution — We may retain personal information beyond the standard retention period where it is reasonably necessary to establish, exercise, or defend legal claims, or to resolve complaints, disputes, or regulatory inquiries, including those related to our TRUSTe certification and dispute resolution programs.
  • Legitimate business interests — We may retain personal information where there is a legitimate and proportionate business reason to do so, such as for fraud prevention, security monitoring, auditing, and maintaining the integrity of our systems and services. Such retention is limited to what is necessary and is balanced against your privacy rights and interests.
  • Consent withdrawal and purpose cessation — Where processing is based on your consent, we will cease retention of your personal information upon withdrawal of that consent, unless another legal basis or obligation requires continued retention. We will also initiate deletion where it becomes reasonably apparent that the original purpose of collection no longer applies.
  • Customer instructions (processor context) — Where TrustArc acts as a data processor on behalf of a customer, we retain personal information in accordance with that customer's documented instructions and applicable contractual terms, including agreed deletion timelines upon contract termination (generally three years from the date of contract termination, unless otherwise specified).


At the end of any applicable retention period, personal information will be securely deleted, anonymized, or de-identified in a manner appropriate to the sensitivity of the data and the storage medium used. Where full deletion is not immediately practicable, we will isolate the data from further active processing until deletion can be completed.

International Data Transfers

Locations of Data Processing

TrustArc is headquartered in the United States, where most of the personal information we process is transferred to or accessed from. We also operate through subsidiaries and engage service providers in other countries. Specific information about data hosting locations and infrastructure is available in our Technical and Organizational Measures. Customers should ensure their own privacy notices reflect our transfer arrangements for their data subjects.


We may transfer, access, or store personal information outside the European Economic Area ("EEA"), Switzerland, the United Kingdom, China, or other countries requiring legal protections for international data transfers. When we do, we ensure adequate protection through one or more of the following:

  • Transfers to countries recognized as providing equivalent protections ("adequacy decisions")
  • Written agreements such as Standard Contractual Clauses or other approved data transfer mechanisms
  • Your consent for specific transfers
  • Other transfer mechanisms approved by the relevant authorities


Data Privacy Framework


TrustArc Inc and its subsidiary TRUSTe LLC comply with the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF), as set forth by the U.S. Department of Commerce. TrustArc has certified its adherence to the EU-U.S. DPF Principles for personal data received from the EU and UK, and to the Swiss-U.S. DPF Principles for personal data received from Switzerland. In the event of any conflict between this Notice and the applicable DPF Principles, the Principles shall govern. To learn more or view our certification, visit dataprivacyframework.gov.


TrustArc is subject to the investigatory and enforcement powers of the U.S. Federal Trade Commission (FTC) and is liable under the DPF Principles if our service providers process personal information in a manner inconsistent with those Principles.


Data Privacy Framework Inquiries & Complaints

EU, UK, and Swiss individuals with inquiries or complaints regarding our handling of personal data under the EU-U.S. DPF, UK Extension, or Swiss-U.S. DPF should first contact TrustArc at privacy@trustarc.com. In compliance with the applicable DPF frameworks, TrustArc commits to cooperate with the advice of the relevant supervisory authorities — including the EU DPAs, the UK ICO, and the Swiss FDPIC — for unresolved complaints. Under certain conditions, you may invoke binding arbitration as set forth in Annex I of the DPF Principles by delivering notice to TrustArc at privacy@trustarc.com and following the procedures in Annex I.

Security Measures

We employ appropriate technical, organizational, and administrative security measures designed to protect personal information against loss, misuse, unauthorized access, alteration, disclosure, or destruction. We have implemented measures designed to maintain the ongoing confidentiality, integrity, and availability of the systems and services that process personal information, and to restore access in a timely manner following a physical or technical incident. For further detail on our technical and organizational security measures, please see our Technical and Organizational Measures.


We use the Google reCAPTCHA v3 service on our website to prevent spam and abuse. This service collects information about our website's visitors to determine whether a user is a human or a bot. The data collected is used for this purpose alone. The reCAPTCHA service operates without interrupting the user experience but involves the transmission of data to Google's servers. The use of the Google reCAPTCHA service is subject to the Google Privacy Policy and Google Terms of Use.


Our information security program is independently assessed annually in accordance with SOC 2 Type II standards established by the AICPA. We also engage qualified third-party providers to conduct annual comprehensive penetration testing of applicable systems.


Web application security reviews follow methodologies aligned with the OWASP Risk Rating framework, with identified risks prioritized and remediated by severity. We maintain ongoing risk analysis, compliance reviews, and formalized security governance processes to support continuous improvement and alignment with applicable data protection laws and industry standards. We perform due diligence on sub-processors and cloud infrastructure providers and require contractual commitments to maintain appropriate security safeguards.


We maintain a comprehensive data protection program designed to ensure personal information is handled in accordance with applicable privacy laws, including the GDPR, CCPA, and LGPD.

Children's Privacy

TrustArc's solutions and services are not directed to children, and we do not knowingly collect personal information directly from children without parental consent. If we become aware that a child has provided us with personal information, we will delete it from our records. To report such cases, please contact us at privacy@trustarc.com.  We do not knowingly sell or share the personal information of individuals under 18 years of age, nor use it for advertising purposes. Where personal information of a child is required, we will obtain prior, informed, and specific parental consent.

Additional Information for Residents of India

This section supplements the rest of this Notice and applies specifically to individuals located in India ("Data Principals") whose personal data is processed by TrustArc in accordance with India's Digital Personal Data Protection Act, 2023 ("DPDPA") and the Digital Personal Data Protection Rules, 2025 ("DPDP Rules").


Notice Language Options

In accordance with Section 5 of the DPDPA, you have the right to access the contents of this Notice in English or in any of the 22 languages listed in the Eighth Schedule to the Constitution of India. These languages are:


Assamese, Bengali, Gujarati, Hindi, Kannada, Kashmiri, Konkani, Malayalam, Manipuri, Marathi, Nepali, Odia, Punjabi, Sanskrit, Sindhi, Tamil, Telugu, Urdu, Bodo, Santhali, Maithili, and Dogri. To request this Notice in one of the above languages, please contact us at privacy@trustarc.com. We will provide a translated version as soon as reasonably practicable.


Personal Data We Process About You (India)

In accordance with the DPDPA requirement for an itemized description of personal data, the following categories of personal data may be collected and processed by TrustArc depending on how you interact with us:

Category Examples
Identity & Contact Information
Full name, email address, phone number, job title, company name
Account Credentials
Username, password, user profile information
Location & Network Data
IP address, city-level location inferred at time of consent
Device & Browser Data
Browser type, operating system, device identifiers, referring/exit pages
Platform Usage Data
Actions taken in platform applications, record creation, approvals, support tickets
Consent Records
Opt-in/opt-out preferences, consent timestamps, consent method
Communication
Support request content, complaint details, email correspondence
Request Details
Individual rights request type, identity verification information, response records
Assessment & Survey Data
Survey responses, assessment inputs, webinar/event registration details
Transaction & Billing Data
Purchase order numbers, billing details, contract information

The purposes for which each category of personal data is processed are described in the "How We Use Personal Information" section of this Notice. Personal data is processed only for the specific purposes for which it was collected or for which you have provided consent.


Your personal information will be erased if you withdraw your consent to its processing, or as soon as it is reasonable to assume that the specified purpose no longer applies — whichever is earlier. All processing logs and associated traffic data will be retained for at least one year for investigative purposes.


Your Rights Under the DPDPA

As a Data Principal under the DPDPA, you have the following rights with respect to your personal data:

  • Right to Information and Access — You may request confirmation of whether your personal data is being processed and obtain a summary of the personal data we hold about you and how it is being used.
  • Right to Correction and Completion — You may request that inaccurate, incomplete, or outdated personal data be corrected or updated.
  • Right to Erasure — You may request deletion of your personal data when it is no longer needed for the purpose for which it was collected, or upon withdrawal of consent, subject to applicable legal retention obligations.
  • Right to Withdraw Consent — Where processing is based on your consent, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing that occurred before withdrawal. Upon withdrawal, we will cease processing and erase or de-identify your personal data unless another legal ground applies.
  • Right to Grievance Redressal — You have the right to raise a complaint or grievance with us, and to escalate to the Data Protection Board of India if your concern is not resolved to your satisfaction. See How to Contact Us for more information.
  • Right to Nominate — You may nominate another individual to exercise your rights under the DPDPA on your behalf in the event of your death or incapacity.

To exercise any of these rights, please use the methods described in the "Your Rights" section of this Notice, or contact our India contact listed below.

Updates to This Notice

We review this Notice annually and update it to reflect new operations or requirements. The date it was last updated will be posted at the top of this page. We will notify you of any changes that materially affect your privacy rights.

How to Contact Us

If you have any questions about this Notice or our privacy practices, please contact us:


TrustArc Inc: 2121 N. California Blvd., Suite 290, Walnut Creek, CA 94596 | USA Phone: 1-866-467-8688 (1-866-I-OPT-OUT), service code 751 | Main: +1-415-520-3490 | privacy@trustarc.com


European Economic Area (GDPR)

For questions or concerns about how we process your personal information in the EEA, please contact:


If you have a concern about how we handle your personal information, you are welcome to raise it directly with us at privacy@trustarc.com. You also have the right to directly lodge a complaint with the supervisory authority in your member state of habitual residence, place of work, or place of the alleged infringement. A list of EU supervisory authorities and their contact details is available at https://www.edpb.europa.eu/about-edpb/about-edpb/members_en.


United Kingdom (UK GDPR)


If you have a concern about how we handle your personal information, you are welcome to raise it directly with us at privacy@trustarc.com). You also have the right to directly lodge a complaint with the ICO at www.ico.org.uk or by calling 0303 123 1113.


Philippines (Philippines Data Privacy Act)


If you have a concern about how we handle your personal information, you are welcome to raise it directly with us at privacy@trustarc.com. You also have the right to lodge a complaint with the National Privacy Commission (NPC) at www.privacy.gov.ph.


India (DPDPA)

India Contact and Grievance Officer

TrustArc has designated the following contact to address questions and grievances related to the processing of personal data under the DPDPA. This contact is published in accordance with Section 8 of the DPDPA and Rule 9 of the DPDP Rules.


You may raise any question, concern, or grievance related to the processing of your personal data by contacting us at the above. We will endeavor to acknowledge your grievance within a reasonable timeframe and resolve it as required under applicable law.


Filing a Complaint with the Data Protection Board of India

If you are not satisfied with our response to your grievance, you have the right to escalate your complaint to the Data Protection Board of India ("DPBI"), the statutory authority established under the DPDPA to adjudicate complaints and enforce compliance.


The Data Protection Board of India has been established under the DPDPA; however, its operational complaint-filing mechanism, portal, and procedures are not yet fully published or live. We will update this section with direct links and step-by-step filing instructions as soon as the DPBI officially activates its complaint intake process. Please check back here for the most current information.


In the meantime, before filing a complaint with the DPBI, we encourage you to first raise your concern directly with us using the contact information above, so that we may address it promptly. This first-step grievance process is required under the DPDPA before escalation to the Board.


Once the DPBI complaint portal is operational, you will be able to file a complaint at: [Link to be updated upon DPBI activation — visit https://meity.gov.in for the latest information]


For current updates on the DPBI's establishment and complaint procedures, you may also refer to the Ministry of Electronics and Information Technology (MeitY) at: https://www.meity.gov.in.


Rest of the World

For questions about how we process your personal information in any country or region not addressed above, please contact our Global Data Protection Officer at privacy@trustarc.com. You also have the right to contact the privacy regulatory authority in your country or region.