Privacy Policy

Last Updated: September 09 2026

Effective Date: October 09 2026

Interstice Labs, Inc., doing business as Trustero (“Trustero,” “we,”“us,” or “our”), provides software and related services that help organizations manage governance, risk, and compliance.

This Privacy Policy explains how we collect, use, disclose, retain, and protect personal data related to our website at www.trustero.com, our business interactions, and the Trustero platform and related services.

“Personal data” means information relating to an identified oridentifiable individual. It includes personal information contained in customer records, documents, prompts, and AI-generated outputs, as well as information individuals provide directly to Trustero.

This policy explains our practices. Using our website or services doesnot, by itself, constitute consent to processing that requires consent. Where consent is required, we obtain it separately.

1. Our Role and the Scope of This Policy

Personal Data Processed for Customers

Organizations use Trustero to collect, organize, analyze, and manage information for their governance, risk, and compliance activities. Information submitted, connected, stored, or generated for a customer through theseservices is referred to in this policy as “Customer Data.” Personal data weprocess on the customer’s behalf is “Customer Personal Data.”

For Customer Personal Data, Trustero acts as a data processor when thecustomer is the controller, or as a subprocessor when the customer processes data on behalf of another controller.

The customer or underlying controller determines the purposes of processing and is responsible for establishing the applicable legal basis, providing required notices, and directing the authorized use of that information. Trustero remains responsible for its own obligations as a processor or subprocessor.

Our processing is governed by the applicable customer agreement, data processing agreement or addendum (“DPA”), and documented customer instructions.This Privacy Policy does not replace those agreements, change their order of precedence, or authorize additional uses of Customer Personal Data.

Website and Business Contact Information

Trustero separately processes personal data to operate its website,respond to inquiries, manage business relationships, administer contracts, and communicate about its services. Where we determine the purposes and means of those activities, we act as a controller.

Our role depends on the particular processing activity, not simply onthe type of information or where it is received. For example, a business email address used for a sales inquiry may be processed differently from the same address appearing in a customer’s access review.

Customer documents and other Customer Personal Data provided through support channels remain subject to the customer-processing protections in this policy. They do not become available for independent marketing or unrelated uses merely because they were sent to Trustero support.

2. Personal Data We Process

Website and Business Interactions

Depending on how you interact with Trustero, we may process:

 Category  

 Examples and sources  

 Contact and business  information  

 Name, business email  address, phone number, organization, job title, and contact or billing  address provided through forms, correspondence, or business interactions.  

 Communications and  relationship information  

 Inquiries, demonstration requests, support communications, feedback, communication  preferences, and information necessary to administer a business relationship.  

 Website and device  information  

 IP address, browser and  operating system information, pages visited, timestamps, referring pages, and  other technical information collected through website operation.  

 Cookie and  interaction information  

 Information collected  through cookies, analytics, and other technologies described in Section 10,  subject to applicable choices and consent requirements.  

We identify, where appropriate, the information required to fulfill a request at the point of collection. Without that information, we may be unable to provide the requested response or service.

Customer Personal Data

The Customer Personal Data we process depends on the services purchased, the customer’s configuration, the information provided, and the customer’s documented instructions.

It may include information about employees, contractors, authorized users, customer or supplier representatives, and other individuals identified in customer records. Examples include names, work contact details, organizational roles, access permissions, asset assignments, training records, and personal data contained in policies, evidence, control assessments, risk records, vendor documentation, or reports.

We receive this information from customers and their authorized users,from customer-authorized integrations and sources, and through processingperformed to deliver the services. Prompts, retrieved context, generatedassessments, and other outputs may also contain personal data.

The applicable agreement and processing schedules establish the authorized categories of data, categories of individuals, purposes, and processing duration. These examples do not mean every customer provides every category.

Sensitive Information

Customer records may contain sensitive personal data, including information subject to additional legal protections. Its processing must remain with in the agreed service scope, documented instructions, and applicable legal requirements.

Customers should limit submissions to information necessary for the intended task and remove or redact unnecessary sensitive information. Permitted processing of sensitive information must be supported by the appropriate contractual arrangements and safeguards.

3. How We Process Customer Personal Data

We process Customer Personal Data to provide the contracted services under documented customer instructions. Depending on the authorized service,this may include collecting and storing records, organizing evidence, evaluating controls, supporting risk assessments, generating reports, providing AI-assisted functionality, and delivering related support.

Processing necessary to operate, secure, maintain, and troubleshoot the customer’s service must also remain within the applicable agreement and authorized purposes.

We do not treat this Privacy Policy, a general reference to service improvement, or a website visitor’s consent as separate permission to use Customer Personal Data for our own purposes.

In particular, we do not sell Customer Personal Data, use it for cross-context behavioral advertising, or repurpose it for independent marketing. Its use for AI processing does not authorize additional recipients, unrelated purposes, or access beyond the customer’s authorized scope.

The customer’s documented instructions may include the applicableagreements and authorized configurations or requests made within thoseagreements. An instruction must not override applicable law. We inform thecustomer if, in our opinion, an instruction infringes the GDPR or other applicable European Union or Member State data protection provisions.

Any legally required processing outside customer instructions must be permitted under applicable data protection law and is subject to its notification and other requirements. A request from a public authority does not, by itself, remove restrictions on disclosure or international transfer.

4. AI Processing, Transparency, andInformed Use

How AI Uses Information

Trustero uses AI to support authorized governance, risk, and compliance workflows, such as retrieving relevant information, analyzing evidence, evaluating controls, identifying gaps, and preparing drafts or reports.

For an authorized AI task, the information processed may include theuser’s request, relevant customer records, selected evidence, and other context permitted for that workflow. Applicable data protection obligations continue toapply to that information and to personal data contained in the resulting output.

Selected inputs and context may be transmitted to approved external model providers for processing and generation of a response. When those providers process Customer Personal Data on our behalf, they are subject to the applicable subprocessor arrangements, processing restrictions, and transfer safeguards.

AI processing, including processing by external model providers, must remain consistent with the customer’s agreed deployment, processing locations, and applicable residency restrictions described in Section 8.

No Training on Customer Data

We do not use Customer Data, including customer documents, prompts, and outputs, to train or fine-tune AI models or otherwise improve under lying foundation models. We require approved model providers receiving Customer Datato apply the same restriction.

Using authorized information as context to perform a customer’s task is service delivery, not permission to use that information for model training.

Provider retention and deletion requirements are addressed separately through the applicable service configuration and contractual arrangements. Restrictions on model training do not replace those requirements.

Clear Identification of AI Interactions

When a person interacts directly with Trustero AI functionality, we provide a clear and accessible disclosure that the person is interacting withan AI system rather than a human. We provide that disclosure no later than thefirst interaction.

This commitment applies to direct AI interactions offered through the Trustero platform and to any direct AI interaction offered through our website. It is not fulfilled solely by including a statement in this Privacy Policy.

AI Literacy and Appropriate Reliance

Trustero takes measures to support a sufficient level of AI literacyamong its staff and other people operating or using AI systems on its behalf. These measures take account of their technical knowledge, experience, education, training, the context of use, and the people who may be affected.

Relevant guidance addresses appropriate data handling, intended use,limitations, evaluation of outputs, and reporting concerns. We also provide user guidance to support customers’ informed use of Trustero AI.

AI-generated information may be in accurate or incomplete, including when it concerns an individual. Users should evaluate the relevant evidence and context before relying on it. Personal data does not lose its protection because it appears in an AI-generated assessment.

Trustero’s GRC functionality is not intended to serve as the sole basis for decisions about individuals that produce legal or similarly significant effects. The responsible controller determines the permitted use and required decision-making safeguards. Trustero provides assistance with applicable data protection obligations as described in this policy and the DPA.

5. How We Use Website and Business Contact Information

The purposes below apply to information we process for our own website and business activities. They do not authorize independent use of Customer Personal Data.

Purpose  

Basis where GDPR applies to the activity  

Respond to inquiries  and manage business relationships  

mess Our legitimate interests in responding to requests and communicating with prospective and  existing business contacts. Contractual necessity applies where the  individual is a party to the relevant contract or requests steps toward  entering one.

Administer agreements and related business records  

Our legitimate  interests in managing organizational relationships, contractual necessity where applicable, and legal obligations such as applicable accounting requirements.  

Operate and protect the website  

Our legitimate  interests in maintaining a reliable website, preventing misuse, and protecting information, subject to individuals’ rights and applicable consent requirements.  

Provide optional analytics, personalization, or marketing  

Consent where required  by law, or legitimate interests where the activity is legally permitted on that basis and subject to applicable objection and opt-out rights.  

Meet legal requirements and address disputes  

Compliance with  applicable legal obligations and legitimate interests in establishing,  exercising, or defending legal claims.  

Where we rely on legitimate interests, we consider the impact on individuals and applicable protections. Where we rely on consent, individuals may withdraw it without affecting processing lawfully performed before withdrawal.

An agreement with an organization does not automatically make contractual necessity the legal basis for processing every employee’s personal data.

6. Recipients and Subprocessors

Sub processors Supporting Customer Services

We engage subprocessors to support service delivery, which may include hosting, storage, authorized AI processing, and other contracted functions.

Subprocessors processing Customer Personal Data must be authorized under the applicable DPA and law. Where general written authorization applies,we provide notice of intended additions or replacements and the opportunity to object as required by the DPA and applicable law.

We impose the required data protection obligations through binding agreements. Engaging a subprocessor does not remove our responsibility for its processing under the applicable agreement and law.

Customers may request information about the applicable subprocessors,their processing functions, locations, and change-notification arrangements bycontacting privacy@trustero.com.

Customer-Authorized Recipients

Customer Personal Data may be made available to users, auditors, advisers, integrations, or other recipients as authorized by the customer andthe applicable service configuration. Those disclosures remain subject to the customer’s instructions and agreed processing scope.

Website and Business Service Providers

We may disclose website and business contact information to providers supporting activities such as website operation, communications, relationship management, analytics, and administrative services.

Any disclosure to advertising, analytics, or business partners must be described accurately in the applicable notice and remain subject to legally required consent or opt-out choices. Sections 10 and 12 address the relevant disclosures and controls.

Legal Requirements and Business Transactions

We may disclose personal data where required or otherwise permitted by applicable law, including in response to a legally valid request. We assess therequest, limit disclosure as required, and provide notice where required and legally permitted.

Personal data may also be involved in a merger, acquisition, financing,reorganization, or transfer of business assets, subject to applicable confidentiality and data protection requirements.

For Customer Personal Data, a legal request or business transaction does not independently expand the permitted processing purposes or displace the DPA, customer instructions, or applicable transfer restrictions.

7. Security, Accountability, and Customer Assistance

We maintain technical and organizational measures appropriate to the nature of the processing and the risks to individuals. These measures address the confidentiality, integrity, availability, and resilience of processing,recovery from relevant incidents, and assessment of the effectiveness of safeguards.

Personnel authorized to process Customer Personal Data are subject to confidentiality obligations and access restrictions appropriate to their responsibilities. The applicable agreements and security documentation address detailed security requirements.

No system eliminates every risk. This does not reduce Trustero’s obligations under applicable law or its agreements.

Personal Data Breaches

When we become aware of a personal data breach affecting Customer Personal Data, we notify the customer without undue delay and within anyshorter period required by the applicable agreement.

We provide available information and relevant assistance to support investigation, containment, remediation, and the customer’s assessment of notification obligations. Where information is not available at the time of the initial notice, we provide further information as it becomes available without undue further delay.

The relevant controller determines its notifications to supervisory authorities and affected individuals. This does not limit any notification or cooperation obligation that applies directly to Trustero.

Records, Assistance, and Review

We maintain records of processing activities and other documentation required for our processor activities.

Based on the nature of processing and the information available to us,we assist customers with applicable obligations concerning individual rights,security, breach response, data protection impact assessments, and prior consultation with supervisory authorities.

We make available information necessary to demonstrate compliance withour processor obligations and allow for and contribute to audits and inspections in accordance with the DPA and applicable law. We also cooperatewith competent supervisory authorities as required.

8. Data Residency, Processing Locations, and International Transfers

Trustero is based in the United States and offers different deployment arrangements for its services. The locations in which Customer Personal Data is hosted and processed depend on the customer’s selected deployment and the applicable contractual commitments.

European Union Deployments

Trustero offers service deployments in which the infrastructure used tohost the contracted services is located entirely within the European Union(“EU”).

For customers using this option, the applicable Customer Agreement,order form, or DPA identifies the EU deployment and the scope of the agreed residency commitment. This option applies to the customer’s designated deployment; it does not mean every Trustero customer or service operates exclusively within the EU.

We process Customer Personal Data in accordance with the locations andrestrictions agreed with the customer. Hosting, storage, backup and recovery,AI processing, analytics, and support arrangements must be consistent with those commitments.

Any proposed processing outside an agreed geographic restriction is subject to the applicable contractual change process, required customer authorization, and legal requirements. This Privacy Policy does not authorizean exception to an agreed residency restriction.

Processing Locations and ServiceProviders

The location of hosting infrastructure is one part of the processing arrangement. The applicable customer documentation must also identify relevant processing by subprocessors and any support or administrative access from other locations.

An EU deployment commitment for the contracted services does not automatically extend to separate website and business contact activities. Those activities remain subject to the disclosures, purposes, and safeguards described elsewhere in this policy.

Customers may request information about the processing locations and subprocessor arrangements applicable to their deployment by contactingprivacy@trustero.com.

International Transfer Safeguards

Where personal data is transferred outside the European Economic Area,and a transfer mechanism is required, we use a legally applicable mechanism,such as an applicable adequacy decision or effective contractual safeguards,including the appropriate Standard Contractual Clauses. Where required, we support these arrangements with transfer assessments and supplementary measures.

A transfer mechanism does not, by itself, authorize processing outsidea customer’s agreed geographic restrictions. Both the contractual location commitments and applicable legal requirements must be satisfied.

This Privacy Policy is not itself a transfer agreement. Providing information to Trustero or using the services does not, by itself, constitute consent to an international transfer.

For information about the safeguards applicable to your information, or to request an available copy, contact privacy@trustero.com. Disclosures may be appropriately limited to protect confidential information and other individuals’ rights without restricting access required by law.

9. Retention, Return, and Deletion

Customer Personal Data

We retain and process Customer Personal Data for the duration and purposes authorized under the applicable agreement and documented customer instructions.

At the end of the relevant services, we return or delete Customer Personal Data at the customer’s choice and delete existing copies as required by the DPA and applicable law, unless applicable law requires storage.

Return and deletion procedures address the relevant production data, stored prompts and outputs, logs, backups, and copies held by subprocessors. Applicable processing and deletion schedules must be consistent with the customer’s contractual and legal requirements.

Any copies awaiting deletion remain protected, access-restricted, and limited to the authorized retention purpose. Backup retention does not permit independent reuse. Applicable deletion instructions continue to apply when data is restored from backups.

Where legally required retention applies, the retained information remains protected and restricted to that requirement until deletion is permitted and required.

Website and Business Contact Information

We retain website and business contact information for as long as necessary for the disclosed purpose, considering the nature of the interaction, the information involved, applicable legal requirements, and the need to establish, exercise, or defend legal claims.

When you opt out of marketing, we may retain limited information necessary to respect that choice. We delete or appropriately anonymize information when retention is no longer justified.

The retention considerations in this subsection do not independently authorize extended retention of Customer Personal Data.

10. Cookies, Analytics, and SimilarTechnologies

We use cookies and similar technologies to operate our website,maintain security, remember preferences, and understand how people interact with our website and services. We use Google Analytics and Hotjar for the purposes described below.

Google Analytics

We use Google Analytics to understand website traffic and how visitors interact with our website. This helps us evaluate the usefulness of our content, identify usage patterns, and improve the website experience.

Information processed may include pages visited, interactions, session information, and browser or device information, depending on our configuration and the choices available to you.

For information about Google’s privacy practices, see Google’sPrivacy Policy.

Hotjar

We use Hotjar to understand how users interact with the Trustero application, including through session recordings. These recordings help us review navigation and feature usage, identify usability difficulties, and improve the user experience.

The information recorded depends on the features enabled and the configuration applied to the relevant environment. Session recording must be limited to information permitted for the applicable purpose and processing arrangement.

For information about Hotjar’s privacy practices, see Hotjar’s Privacy Policy.

Customer Data Protections

Where Google Analytics, Hotjar, or another analytics provider processes Customer Personal Data, that processing remains subject to the applicable Customer Agreement, DPA, documented customer instructions, and required subprocessor authorizations.

Use of an analytics or session-recording tool does not independently authorize disclosure of customer documents, prompts, outputs, credentials, or other customer content. It also does not authorize independent marketing, model training, or processing outside an agreed geographic restriction.

Section 8 addresses applicable processing locations and residency restrictions. A provider’s privacy notice does not replace Trustero’s obligations under its agreements or applicable law.

Your Choices

Where consent is required for optional cookies, analytics, or session recording, we obtain it before enabling the relevant processing. Continuing to browse the website or use the services is not treated as consent where anaffirmative choice is required.

You may review and change your choices through [insert the working cookie-preference control and verified Cookie Notice link]. The Cookie Notice identifies the applicable technologies, purposes, providers, and retention periods.

Browser settings may provide additional controls, but they do not replace the consent or opt-out mechanisms we must provide.

We honor legally recognized opt-out preference signals where required by applicable law. These signals are distinct from legacy “Do Not Track”browser settings.

11. Your Privacy Rights and Choices

Depending on applicable law and the processing involved, you may haverights to access your personal data, obtain a copy, correct in accurate information, request deletion, restrict processing, request portability, or object to certain processing.

Where processing relies on consent, you may withdraw it. Where applicable, you also have protections concerning decisions based solely on automated processing that produce legal or similarly significant effects.

These rights are subject to the conditions and exceptions established by applicable law.

Requests Concerning Customer Personal Data

The customer or underlying controller is generally responsible for deciding and responding to requests concerning Customer Personal Data.

You may contact the organization responsible for the information directly. You may also contact Trustero at privacy@trustero.com so we can help identify and notify the appropriate customer and provide assistance under the applicable DPA and law.

We do not independently determine how a customer should respond unless the law requires us to. This routing process does not limit your rights, our own obligations, or your ability to raise a concern with a supervisory authority.

Requests Concerning Trustero’s Own Processing

For information we control, contact privacy@trustero.com. We mayrequest information reasonably necessary to verify identity or authority where appropriate, taking account of the nature of the request. We do not request unnecessary identity information.

Where GDPR response periods apply, we respond without undue delay and ordinarily within one month. Where a permitted extension is necessary because of the complexity or number of requests, we explain the extension and reasons within the initial month. The extension may be up to two additional months.

If we cannot act on a request, we explain the reason and available complaint or other remedies as required by law.

Marketing Choices

You may opt out of marketing emails through the unsubscribe mechanismin the message or by contacting privacy@trustero.com.

Opting out of marketing does not prevent communications necessary toadminister a service, respond to a request, or meet a legal requirement.

Complaints

You may contact us about a privacy concern at privacy@trustero.com.Where applicable, you also have the right to complain to a competent dataprotection supervisory authority, including in the European Economic Area whereyou habitually reside, work, or believe an infringement occurred.

12. California Privacy Information

Where California privacy law applies, Trustero's role depends on the activity. For Customer Personal Data processed on behalf of customers, the customer agreement and DPA address the applicable service-provider or contractor restrictions. Trustero handles requests concerning that informationas described in Section 11.

For activities in which Trustero acts as a business subject to California privacy law, applicable rights may include knowing and accessing personal information, requesting correction or deletion, obtaining a portable copy, opting out of sale or sharing for cross-context behavioral advertising, and limiting certain uses or disclosures of sensitive personal information.

Individuals may exercise applicable rights without unlawful discrimination and may use an authorized agent in accordance with applicable requirements. We apply verification procedures where permitted and appropriateto the request; we do not impose identity-verification requirements on opt-out requests where prohibited by law.

Submit requests to privacy@trustero.com or through the applicable website privacy controls.

California residents may also request information about applicable disclosures for third parties’ direct marketing under California’s Shine the Light law. Eligible registered minor users may request removal of information they publicly posted where California law provides that right, subject to its conditions and exceptions.

13. Children and Independent Third-PartyServices

Children

Our website and services are intended for business use, not for children under 13. We do not knowingly collect personal data directly from children under 13 through our website.

If you believe a child has provided information directly to us, contactprivacy@trustero.com so we can assess and address it.

This statement does not mean Customer Personal Data can never include information about a minor. Any such processing remains subject to the customer’s authorized purposes, applicable agreement, and additional legal protections.

Independent Third-Party Services

Our website may link to independent websites and services. Their processing is governed by their own notices and applicable terms.

This does not remove Trustero’s responsibilities for providers acting as our processors or subprocessors, or for personal data we disclose to them.

14. Changes to This Policy

We may update this Privacy Policy to reflect changes in our practices, services, or applicable requirements. We identify the updated policy throughits “Last Updated” and “Effective Date” entries.

Where appropriate or required, we provide additional notice of material changes before they take effect, such as through a prominent website notice or direct communication.

Updating this policy does not amend a customer agreement or DPA,replace a required subprocessor authorization, or authorize new processing that requires consent or another legal basis.

15. Contact Us

For privacy questions, requests, or concerns:

Interstice Labs, Inc., doing business as Trustero

Email: privacy@trustero.com

Mailing address: Interstice Labs, Inc., DBA Trustero, 409 Sherman Ave,Palo Alto, CA 94306