Overview
Trustroot (“we”, “us”) is a privacy-operations platform operated by Humano. This policy explains what personal data we process when you use the application, why we process it, and the choices you have. It applies to the Trustroot web application and related services.
Data we collect
- Account & sign-in data. When you sign in with Google, we receive your name, email address, and basic profile information to authenticate you and provision your workspace membership.
- Workspace content. Information you enter to run the service — assessments, questionnaire answers, generated artifacts, vendor and processing details, data-subject requests, breach records, and consent configurations.
- Operational data. Audit logs of actions taken in your workspace, and standard server logs (such as IP address and request metadata) used for security and reliability.
How we use data
We use personal data to provide and secure the service: to authenticate users, operate your workspace, generate compliance artifacts, maintain audit trails, prevent abuse, and communicate service-related messages (for example, member invitations and data-subject-request acknowledgements). We do not sell personal data, and we do not use your workspace content to train AI models.
AI processing
When AI drafting is enabled, the relevant assessment content is sent to Anthropic’s API solely to phrase findings the rules engine has already produced. Anthropic does not train its models on data submitted through its API. AI output is always subject to human review and approval before it is finalized, and every legal citation is constrained to the rules our engine matched.
Sub-processors
We rely on a small set of vendors to run the service, each bound by data-protection terms:
- Vercel — application hosting
- Neon — managed database
- Google — authentication (Sign in with Google)
- Resend — transactional email
- Anthropic — AI drafting (when enabled)
Retention
We retain workspace content for as long as your workspace is active or as needed to provide the service. You may request export or deletion of your data by contacting us. We retain audit logs and limited operational records where required for security, legal, or accounting purposes.
Security
Data is encrypted in transit (TLS) and at rest. Access is restricted to authenticated members of a workspace, scoped by role. We maintain administrative and technical safeguards appropriate to the nature of the data we process.
Your rights
Depending on your location, you may have rights to access, correct, delete, or restrict processing of your personal data, and to object to certain processing. To exercise these rights, contact us using the details below and we will respond within the timeframe required by applicable law.
Changes
We may update this policy as the service evolves. Material changes will be reflected by updating the date at the top of this page.