This Data Processing Agreement (“DPA”) forms part of the agreement governing use of the services provided by Trailblaze Solutions LLC, a New Jersey limited liability company doing business as Trailblaze Data (“Trailblaze Data,” “Processor,” “Service Provider,” “we,” or “us”) to the customer (“Customer,” “Controller,” or “Business”).
This DPA governs Trailblaze Data's processing of Customer Personal Data on behalf of Customer.
1. The Parties
The processor under this DPA is:
| Legal entity | Trailblaze Solutions LLC |
|---|---|
| Trading name | Trailblaze Data (d/b/a) |
| Entity type | Limited liability company formed in the State of New Jersey, United States |
| Registered address | 2500 Morris Ave, 1st Floor, Union, NJ 07083, United States |
| Data protection contact | privacy@trailblazedata.com |
| Legal contact | legal@trailblazedata.com |
The controller is the Customer identified in the applicable account registration or order form. Customer's contact details for the purposes of this DPA are those held on the Customer's account, and Customer is responsible for keeping them current.
2. Acceptance and Execution
This DPA is incorporated into the Terms of Use by reference and takes effect without signature when Customer accepts the Terms of Use or uses Services involving processing of Customer Personal Data.
If Customer requires a countersigned copy, email legal@trailblazedata.com with the Customer's full legal entity name, registered address, the name and title of its authorized signatory, and its account identifier. We will return a signed counterpart, ordinarily within 10 business days. A countersigned copy records the same terms as this page and does not change them unless the parties agree otherwise in writing.
Customers requiring negotiated data-protection terms, additional annexes, or a bespoke security schedule should contact us about an Enterprise agreement.
3. Definitions
“Applicable Data Protection Law” means applicable privacy and data-protection laws governing processing under this DPA, which may include the GDPR, the UK GDPR, the Swiss Federal Act on Data Protection, the California Consumer Privacy Act as amended by the California Privacy Rights Act, the Virginia Consumer Data Protection Act, the Colorado Privacy Act, the Connecticut Data Privacy Act, the Texas Data Privacy and Security Act, the Utah Consumer Privacy Act, the Oregon Consumer Privacy Act, and other applicable privacy laws.
“Customer Data” means information submitted, uploaded, transmitted, imported, or otherwise provided to Trailblaze Data by or on behalf of Customer.
“Customer Personal Data” means Customer Data that constitutes Personal Data or Personal Information under Applicable Data Protection Law.
“Data Subject” means an identified or identifiable individual whose Personal Data is processed.
“Personal Data” means information relating to an identified or identifiable individual or any substantially similar definition under Applicable Data Protection Law.
“Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data.
“Processing” means any operation performed on Personal Data, including collection, storage, analysis, transmission, retrieval, use, alteration, or deletion.
“SCCs” means the Standard Contractual Clauses approved by European Commission Implementing Decision (EU) 2021/914.
“Subprocessor” means a third party engaged by Trailblaze Data to process Customer Personal Data in connection with providing the Services.
“UK Addendum” means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018.
4. Roles of the Parties
Customer acts as the Controller or Business with respect to Customer Personal Data.
Trailblaze Data acts as the Processor or Service Provider processing Customer Personal Data on Customer's behalf.
Each party is responsible for complying with its respective obligations under Applicable Data Protection Law.
5. Customer Instructions
Customer instructs Trailblaze Data to process Customer Personal Data as necessary to:
- Provide the Services
- Verify email addresses
- Validate email addresses
- Perform list cleaning
- Perform data hygiene
- Operate APIs
- Provide integrations
- Return verification results
- Secure the Services
- Prevent fraud and abuse
- Provide technical support
- Comply with applicable law
Trailblaze Data will process Customer Personal Data only on documented Customer instructions unless applicable law requires otherwise, in which case we will inform Customer of that requirement before processing unless the law prohibits us from doing so.
Customer's authorized use of the Services constitutes documented processing instructions. Trailblaze Data will inform Customer if, in our opinion, an instruction infringes Applicable Data Protection Law.
6. Customer Obligations
Customer represents that:
- Customer has lawfully collected Customer Personal Data
- Customer has an appropriate lawful basis for processing
- Customer has provided required privacy notices
- Customer is authorized to provide the information to Trailblaze Data
- Customer's instructions comply with applicable law
- Customer will not submit information whose processing would violate applicable law
Customer remains responsible for the legality of Customer Personal Data and Customer's communications with individuals represented in that data.
7. Nature and Purpose of Processing
Trailblaze Data processes Customer Personal Data to provide business-to-business (“B2B”) email verification, B2B validation, list cleaning, data hygiene, API, integration, and related Services.
Processing may include:
- Receiving
- Transmitting
- Storing
- Structuring
- Analyzing
- Validating
- Comparing
- Classifying
- Retrieving
- Returning results
- Deleting
8. Categories of Data Subjects
Customer Personal Data may relate to:
- Customers
- Prospects
- Leads
- Subscribers
- Business contacts
- Employees
- Contractors
- Users
- CRM contacts
- Email recipients
- Other individuals whose information Customer lawfully submits
9. Types of Personal Data
Customer Personal Data may include:
- Email addresses
- Names
- Business names
- Job titles
- Business contact information
- Customer-provided fields
- Technical metadata
- Verification results
Customer must not submit sensitive or special-category Personal Data, data concerning children, government identifiers, financial account numbers, or health information. The Services are not designed for that data, and Trailblaze Data has not agreed to process it.
10. Duration of Processing and Retention
Trailblaze Data processes Customer Personal Data for the duration of Customer's use of the Services and for the applicable retention period.
The retention periods that apply to Customer Personal Data are published in the retention schedule in our Privacy Policy, which forms part of this DPA. In summary, uploaded files and verification results remain available in the account until Customer deletes them, are deleted within 30 days of account closure, and encrypted backups are purged within 90 days.
Customers can delete uploaded files and verification results from the account at any time.
Certain limited information may be retained when necessary for security, fraud prevention, backups, dispute resolution, accounting, legal obligations, or enforcement of agreements, for no longer than the periods stated in that schedule.
11. Data Location
Customer Personal Data is stored and processed in the United States. Content-delivery and edge networks used to serve the Services may cache non-personal static assets outside the United States; Customer Personal Data submitted for verification is not stored outside the United States.
Trailblaze Data does not currently offer a data-residency option outside the United States. Customers with a residency requirement should contact us about an Enterprise agreement before submitting Customer Personal Data.
12. Confidentiality
Trailblaze Data requires personnel authorized to process Customer Personal Data to be bound by written confidentiality obligations that survive the end of their engagement, and limits access to those personnel who need it to perform their role.
Customer Personal Data will be treated as Customer confidential information.
13. Security
Trailblaze Data maintains the technical and organizational measures set out in Annex II, which are designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, unauthorized access, or misuse, taking into account the state of the art, the cost of implementation, and the nature, scope, context, and purposes of processing.
Trailblaze Data may modify its security measures as technology and security practices evolve, provided the overall level of protection is not materially reduced.
Certification Status
Trailblaze Data does not currently hold a SOC 2, ISO/IEC 27001, or comparable third-party certification, and does not claim one. Requests under section 20 are satisfied by written descriptions of our measures, responses to security questionnaires, and the information in Annex II. We will update this section if that changes.
14. Personal Data Breaches
Trailblaze Data will notify Customer without undue delay, and in any event within 72 hours, after confirming a Personal Data Breach affecting Customer Personal Data.
Notification is sent to the account owner and to any security or privacy contact Customer has recorded on its account. Customer is responsible for keeping that contact current.
To the extent reasonably available, our notification will describe the nature of the breach, the categories and approximate number of Data Subjects and records affected, the likely consequences, the measures taken or proposed to address it and mitigate its effects, and a contact point for further information. Where we cannot provide all of that at once, we will provide it in phases without further undue delay.
Trailblaze Data will take reasonable steps to contain and remediate the breach and will cooperate with Customer's own notification obligations. Notification does not constitute an admission of fault or liability.
15. Subprocessors
Customer provides Trailblaze Data with general written authorization to engage Subprocessors reasonably necessary to provide the Services.
The current list of Subprocessors is published in our subprocessor register, which identifies each Subprocessor, the service it provides, the purpose of processing, and its processing location. That register is the list referred to in Annex III.
Trailblaze Data imposes on each Subprocessor, by written contract, data-protection obligations no less protective than those in this DPA, and remains responsible for its Subprocessors' performance.
Notice and Objection
We will give Customer at least 30 days' notice before a new Subprocessor begins processing Customer Personal Data, by updating the subprocessor register and notifying Customers who have subscribed to change notifications at the address given on that page.
Customer may object to a new Subprocessor on reasonable data-protection grounds within 30 days of that notice. If Customer objects, we will work with Customer in good faith to make a change or provide an alternative that avoids the objected-to processing. If we cannot do so within a reasonable period, Customer may terminate the affected Services on written notice and receive a pro-rata refund of fees prepaid for the terminated Services covering the period after termination.
16. Data Subject Requests
Taking into account the nature of the processing, Trailblaze Data will provide reasonable assistance to Customer in responding to valid Data Subject requests.
These may include requests concerning:
- Access
- Correction
- Deletion
- Restriction
- Objection
- Portability
The Services provide functionality allowing Customer to access, export, correct, and delete Customer Personal Data directly. Where Customer can act on a request using that functionality, that is the intended route. Where it cannot, we will assist on request.
If Trailblaze Data receives a request concerning Customer Personal Data processed solely on behalf of Customer, we will not respond to it substantively. We will forward the request to Customer without undue delay and direct the individual to Customer unless legally prohibited from doing so.
Customer remains responsible for responding to the request.
17. Compliance Assistance
Taking into account the nature of processing and information available to Trailblaze Data, we will provide reasonable assistance with applicable Customer obligations concerning:
- Security of processing
- Personal Data Breach notifications
- Data protection impact assessments
- Regulatory consultations
Where assistance requires effort materially beyond providing existing documentation, we may charge our reasonable costs, agreed with Customer in advance.
18. Government and Law Enforcement Requests
If Trailblaze Data receives a legally binding request from a public authority for Customer Personal Data, we will notify Customer before responding so that Customer can seek protective relief, unless we are legally prohibited from giving notice. Where we are prohibited, we will use reasonable efforts to obtain a waiver of the prohibition and will document our efforts so that we can make them available to Customer.
We will review each request for lawfulness, challenge it where we conclude there are reasonable grounds to do so, and disclose only the minimum amount of information necessary to respond.
19. International Data Transfers
Where Customer Personal Data protected by the GDPR, the UK GDPR, or Swiss data protection law is transferred to Trailblaze Data in the United States, the following apply and are incorporated into this DPA by reference.
European Economic Area
The SCCs apply, with Module Two (controller to processor) where Customer is a controller, and Module Three (processor to processor) where Customer is itself a processor acting for a third-party controller. The parties agree the following options and completions:
| Clause 7 (docking clause) | Applies |
|---|---|
| Clause 9(a) (subprocessors) | Option 2, general written authorization, with the 30-day notice period in section 15 |
| Clause 11(a) (independent dispute resolution) | The optional language does not apply |
| Clause 13 and Annex I.C (supervisory authority) | The supervisory authority of the EEA member state in which Customer is established, or where Customer is not established in the EEA, the authority of the member state in which its Article 27 representative is established |
| Clause 17 (governing law) | Option 1, the law of Ireland |
| Clause 18(b) (forum) | The courts of Ireland |
| Annex I.A (parties) | Section 1 of this DPA and the Customer account details. Customer is the data exporter; Trailblaze Data is the data importer. |
| Annex I.B (description of transfer) | Annex I of this DPA |
| Annex II (technical and organizational measures) | Annex II of this DPA |
| Annex III (subprocessors) | The subprocessor register, as described in Annex III of this DPA |
United Kingdom
The UK Addendum applies to transfers subject to the UK GDPR. Table 1 is completed with the party details in section 1 and the Customer account details; Table 2 selects the SCCs as completed above; Table 3 refers to Annexes I and II of this DPA and the subprocessor register; and in Table 4, the Importer may end the UK Addendum as set out in section 19 of the Addendum.
Switzerland
For transfers subject to Swiss data protection law, the SCCs apply as amended so that references to the GDPR are read as references to the Swiss Federal Act on Data Protection, the competent authority is the Swiss Federal Data Protection and Information Commissioner, and the term “member state” does not prevent Data Subjects in Switzerland from bringing proceedings in Switzerland.
Alternative Mechanisms
If a transfer mechanism relied on above ceases to be valid, or a superseding mechanism or adequacy decision becomes available, the parties will cooperate in good faith to implement it, and Trailblaze Data may substitute it for the mechanism above on notice to Customer.
20. Audits and Compliance Information
On reasonable request, Trailblaze Data will make available the information reasonably necessary to demonstrate compliance with its processor obligations, including written descriptions of the measures in Annex II and completed security questionnaires.
Where Applicable Data Protection Law entitles Customer to audit, Customer may do so subject to the following, which apply to on-site and remote audits alike:
- At least 30 days' advance written notice
- No more than once in any 12-month period, except where an audit is required by a supervisory authority or follows a confirmed Personal Data Breach affecting Customer Personal Data
- Conducted during business hours, in a manner that does not disrupt our operations or the security or confidentiality of other customers' data
- Scope limited to systems and records relevant to the processing of Customer Personal Data
- Subject to written confidentiality obligations, including by any third-party auditor, who must not be a competitor of Trailblaze Data
Customer bears the cost of an audit it initiates, including our reasonable costs of supporting it. If an audit reveals material non-compliance by Trailblaze Data, we bear our own costs and will remediate at our expense.
Trailblaze Data may satisfy an audit request by providing applicable certifications, assessments, or audit reports where available. Our current certification status is stated in section 13.
21. California Privacy Requirements
Where the CCPA applies to Customer Personal Information processed on Customer's behalf, Trailblaze Data acts as a Service Provider or Contractor as applicable. Customer discloses Personal Information to Trailblaze Data only for the limited and specified business purposes described in section 5.
Trailblaze Data will not:
- Sell Customer Personal Information
- Share Customer Personal Information for cross-context behavioral advertising
- Retain, use, or disclose Customer Personal Information outside the direct business relationship, or for any purpose other than the business purposes specified in this DPA, except as permitted by the CCPA
- Combine Customer Personal Information with Personal Information received from or on behalf of another person, or collected from its own interaction with a consumer, except as permitted by the CCPA
Trailblaze Data certifies that it understands and will comply with these restrictions, will provide the same level of privacy protection as the CCPA requires of Customer, will notify Customer if it determines it can no longer meet these obligations, and grants Customer the right to take reasonable and appropriate steps to stop and remediate unauthorized use of Personal Information. Trailblaze Data will impose these same obligations on its Subprocessors.
22. Other United States State Privacy Laws
Where the Virginia Consumer Data Protection Act, the Colorado Privacy Act, the Connecticut Data Privacy Act, the Texas Data Privacy and Security Act, the Utah Consumer Privacy Act, the Oregon Consumer Privacy Act, or a comparable state law applies, Trailblaze Data acts as a processor for Customer as controller and will:
- Adhere to Customer's instructions and process Personal Data only for the purposes in section 5
- Ensure each person processing Personal Data is subject to a duty of confidentiality
- Implement appropriate technical and organizational measures as described in Annex II
- Engage Subprocessors only under a written contract imposing equivalent obligations, and give Customer the notice and objection rights in section 15
- Delete or return Personal Data at Customer's direction as described in section 23
- Make available the information necessary for Customer to conduct and document data protection assessments
- Cooperate with reasonable assessments of our policies and measures, which may be satisfied by an independent assessment or by the information described in section 20
23. Return and Deletion
On termination of the applicable Services, Trailblaze Data will delete Customer Personal Data in accordance with the retention schedule referenced in section 10, or return it, at Customer's election.
Customer may export Customer Personal Data using the Services at any time before termination. On written request made within 30 days of termination, we will provide an export in a structured, commonly used, machine-readable format such as CSV.
Information may temporarily remain within secure encrypted backup systems until deleted through normal backup-retention processes, which complete within 90 days.
On written request, Trailblaze Data will provide Customer with written confirmation that deletion has been completed, ordinarily within 30 days of the deletion taking effect.
Trailblaze Data may retain limited information when legally permitted or required for security, fraud prevention, accounting, legal compliance, dispute resolution, or enforcement of contractual rights, and will continue to protect it under this DPA for as long as it is retained.
24. No Sale of Customer Data
Trailblaze Data does not acquire ownership of Customer's email lists by processing them.
Trailblaze Data will not sell Customer Personal Data submitted for verification as an independent data-broker product, and will not use it to build or improve products for any party other than Customer except in aggregated or de-identified form that cannot reasonably be re-identified.
25. Liability
Liability under this DPA is subject to the limitations and exclusions in the Terms of Use or other agreement governing Customer's use of the Services, and those limitations apply to claims under this DPA and the SCCs in the aggregate, except where Applicable Data Protection Law prohibits such limitations.
Nothing in this DPA limits a Data Subject's rights under the SCCs or Applicable Data Protection Law, or either party's liability to a Data Subject or supervisory authority.
Where one party pays a Data Subject or authority for damage caused wholly or partly by the other, it may recover from the other the proportion corresponding to that other party's responsibility.
26. Order of Precedence
If this DPA conflicts with the Terms of Use regarding processing of Customer Personal Data, this DPA controls.
If the SCCs or the UK Addendum conflict with this DPA, the SCCs or the UK Addendum control to the extent of the conflict.
A negotiated data processing agreement signed by both parties controls over this DPA.
27. Term and Changes
This DPA becomes effective when Customer accepts the Trailblaze Data Terms of Use, enters into an agreement incorporating this DPA, or uses Services involving processing of Customer Personal Data.
The DPA remains effective while Trailblaze Data processes Customer Personal Data on Customer's behalf, and provisions that must survive to protect Customer Personal Data survive its termination.
We may update this DPA to reflect changes in law, the Services, or our Subprocessors, provided no update materially reduces the protections for Customer Personal Data. Material changes are notified at least 30 days in advance to the address on Customer's account, and the version number and dates at the top of this page are revised.
| Version | Date | Summary |
|---|---|---|
| 2.1 | August 27, 2026 | Clarified in the processing description and in Annex I that the processing carried out is B2B email verification and validation. |
| 2.0 | August 27, 2026 | Added the processor entity details, an execution route, the published subprocessor register with notice and objection rights, the 72-hour breach notification commitment, SCC and UK Addendum completions, data-location and government-request terms, audit limits and costs, deletion confirmation, and terms for other United States state privacy laws. |
| 1.0 | August 18, 2026 | First published version. |
Annex I — Details of Processing
Parties
Data exporter: the Customer identified on the account or order form, acting as controller or, where Module Three applies, as processor. Data importer: Trailblaze Solutions LLC d/b/a Trailblaze Data, 2500 Morris Ave, 1st Floor, Union, NJ 07083, United States, acting as processor. Contact point for both parties: the Customer account contact and privacy@trailblazedata.com respectively.
Subject Matter
Provision of Trailblaze Data B2B email verification, validation, data hygiene, list cleaning, API, integration, and related Services.
Duration
For the duration of Customer's use of the Services and the applicable retention period stated in section 10.
Nature of Processing
Receipt, transmission, storage, validation, analysis, classification, retrieval, return, and deletion.
Purpose
B2B email verification, validation, list cleaning, data hygiene, deliverability-related analysis, account support, security, and related Services.
Categories of Data Subjects
Prospects, leads, subscribers, customers, employees, business contacts, CRM contacts, and other individuals whose information Customer submits.
Types of Personal Data
Email addresses, names, business information, job titles, Customer-provided fields, technical metadata, and verification results.
Sensitive Data
None. The Services are not designed for sensitive or special-category Personal Data and Customer must not submit it, as stated in section 9.
Frequency of Transfer
Continuous, for as long as Customer uses the Services.
Transfers to Subprocessors
Subject matter, nature, and duration as described above, to the Subprocessors listed in the subprocessor register.
Annex II — Technical and Organizational Measures
Trailblaze Data maintains the following measures, appropriate to the nature, scope, context, and risks associated with processing. Where a measure is described as applying to a specific system, it applies to every system that processes Customer Personal Data.
- Encryption in transit. Customer Personal Data in transit over public networks is encrypted using TLS 1.2 or later, and plaintext HTTP requests are redirected to HTTPS.
- Encryption at rest. Stored Customer Data, including uploaded files, verification results, and backups, is encrypted at rest.
- Access control. Access to systems processing Customer Personal Data requires individually attributable accounts. Shared or generic accounts are not used for administrative access.
- Authentication. Multi-factor authentication is required for administrative and infrastructure access. Credentials and API keys are stored using a secrets manager rather than in source code or configuration files.
- Least privilege. Access is granted on a need-to-know basis by role, reviewed at least annually and on any change of role, and revoked promptly on termination of employment or engagement.
- Network and infrastructure security. Production systems are segregated from development and test systems, administrative interfaces are not publicly exposed, and Customer Personal Data is not used in development or test environments.
- Logging and monitoring. Access to and administrative activity on systems processing Customer Personal Data is logged, logs are retained for at least 12 months, and alerts are raised on anomalous access and authentication failures.
- Vulnerability and patch management. Dependencies and infrastructure are monitored for known vulnerabilities, and security patches are applied on a risk-prioritized basis, with critical issues addressed promptly.
- Backup and recovery. Encrypted backups are taken on a regular schedule, stored separately from production, and restoration is tested periodically.
- Incident detection and response. A documented incident-response procedure defines roles, escalation, containment, remediation, and the notification process in section 14, and is reviewed periodically.
- Personnel. Personnel with access to Customer Personal Data are subject to written confidentiality obligations and receive data-protection and security awareness guidance appropriate to their role.
- Vendor and Subprocessor management. Providers are assessed before engagement, bound by written data-protection terms, and recorded in the subprocessor register.
- Secure development. Changes are reviewed before release, and dependencies are tracked so that vulnerable components can be identified and replaced.
- Retention and deletion. Data is retained and deleted according to the published retention schedule, and deletion routines are applied to expired data without requiring a customer request.
- Periodic review. These measures are reviewed at least annually and after any material change to the Services or any confirmed security incident.
Measures for transfers: the measures above apply to Customer Personal Data transferred under the SCCs. In addition, transfers between Trailblaze Data and its Subprocessors are encrypted in transit, and the government-request handling described in section 18 applies to any request affecting transferred data.
Annex III — Subprocessors
The authorized Subprocessors for the purposes of this DPA and Annex III of the SCCs are those published in the Trailblaze Data subprocessor register, which is maintained as a page of this website and updated when a Subprocessor is added, removed, or changed.
For each Subprocessor the register identifies:
- Subprocessor name and corporate entity
- Service provided to Trailblaze Data
- Purpose and categories of processing
- Processing location
The register also records the date of the last change and how to subscribe to change notifications. Notice and objection rights are set out in section 15.
Contact
Trailblaze Solutions LLC d/b/a Trailblaze Data
2500 Morris Ave, 1st Floor
Union, NJ 07083
United States
Website: trailblazedata.com
Privacy: privacy@trailblazedata.com
Legal: legal@trailblazedata.com
Phone: 888-628-9316