Troi
These policies are drafts pending legal review and may change before launch.

Troi — Data Processing Addendum (DPA)

Draft pending attorney review. This is a usable template implementing Troi's data-processing commitments. It is not a substitute for licensed-counsel sign-off before publication or execution.

Effective date: 9 July 2026 · Version: Draft 1.0 · Last updated: 9 July 2026


In short

  • This DPA applies where you (the Customer) are a data controller and you use Troi to process personal data of your team or others — Kanah LLC acts as your processor.
  • It implements GDPR Article 28 and equivalent laws: we process on your instructions, keep data confidential and secure, use vetted sub-processors, help you with data-subject requests and breaches, and delete or return data when you leave.
  • International transfers rely on the EU Standard Contractual Clauses and the EU-US Data Privacy Framework, with a transfer impact assessment.
  • It is incorporated into and forms part of the Terms of Service. Where they conflict on data protection, this DPA governs.
  • Program note: Troi is consumer-first (18+ B2C). A formal, signable B2B DPA is available on request (email info@kanah.app) and may be offered in-product as the B2B program matures.

This Data Processing Addendum ("DPA") is entered into between Kanah LLC, a Wyoming limited liability company operating Troi ("Processor", "we", "us"), and the customer that accepts it ("Customer", "Controller", "you"). It applies to the extent we process Personal Data on your behalf in providing the Service. Capitalized terms not defined here have the meaning given in the Terms of Service or in Applicable Data Protection Law.


1. Definitions

  • Applicable Data Protection Law — all laws applicable to the processing of Personal Data under this DPA, including the EU General Data Protection Regulation (2016/679) ("GDPR"), the UK GDPR and Data Protection Act 2018, the Swiss FADP, and US state privacy laws (including the CCPA/CPRA and the Washington My Health My Data Act) as applicable.
  • Controller, Processor, Data Subject, Personal Data, Personal Data Breach, Processing, Special Category Data, Supervisory Authority — as defined in the GDPR (and their equivalents under other Applicable Data Protection Law).
  • Sub-processor — any third party engaged by us to process Personal Data on your behalf.
  • Standard Contractual Clauses / SCCs — the clauses annexed to EU Commission Implementing Decision 2021/914, including Module Two (controller-to-processor) and Module Three (processor-to-processor), plus the UK International Data Transfer Addendum and Swiss adaptations where relevant.
  • DPF — the EU-US Data Privacy Framework (and its UK Extension and Swiss-US framework) operated by the US Department of Commerce.

2. Roles and scope

For Personal Data governed by this DPA, you are the Controller (or a processor acting on behalf of your own controller) and we are the Processor (or sub-processor). Each party complies with its own obligations under Applicable Data Protection Law. This DPA does not apply to data for which we are an independent controller (for example, our own account-administration and billing data), which is governed by the Privacy Policy.

3. Subject-matter, duration, nature, and purpose of processing

  • Subject-matter: our provision of the Troi Service to you under the Terms.
  • Duration: the term of your Troi agreement, plus any period during which we are permitted or required to retain data as set out in §10 and the Privacy Policy retention schedule.
  • Nature and purpose: hosting, storage, transmission, generation, analysis, and other processing operations necessary to provide the Service and its features (including AI-assisted features on a zero-retention / no-training basis — see the AI Transparency Disclosure), and to provide support, security, and billing.

4. Categories of Data Subjects and Personal Data

Categories of Data Subjects may include: you and your authorized users; your invited team members (Troi Studio); and third parties whose information you or your users choose to enter (for example contacts, people, and emergency contacts).

Categories of Personal Data may include:

  1. Account data — email, display name, country of residence, age confirmation (18+), authentication tokens.
  2. User content — everything created or stored in the Service (projects, designs, code, chats, videos, social posts, notes, tasks, journals, and similar).
  3. Special Category Data (Troi Life) — health/wellness, mental-health/journal, reproductive/cycle, and sensitive financial data. Processed only where the relevant individual has given explicit opt-in consent as provided in the Service. (Troi does not derive biometric identifiers/voiceprints or clone voices.)
  4. Third-party personal data you enter — contacts, people, emergency contacts.
  5. Connected-account data — data from services you choose to connect.
  6. Payment/billing metadata — plan, status, country (card data is handled by Stripe).
  7. Device / technical data — push tokens, IP address, device/browser info, diagnostics/logs.

5. Controller instructions

We process Personal Data only on your documented instructions, including with regard to international transfers, unless required to act otherwise by law (in which case we inform you first, unless the law prohibits it). Your instructions are set out in this DPA, the Terms, the configuration choices you make in the Service, and any further written instructions you give. If we consider an instruction to infringe Applicable Data Protection Law, we will inform you. You are responsible for ensuring you have a lawful basis and any required consents for the Personal Data you process through the Service.

6. Confidentiality

We ensure that persons authorized to process Personal Data are bound by confidentiality (contractual or statutory) and are trained on their obligations. Access is limited to personnel who need it to provide, support, or secure the Service.

7. Security (GDPR Article 32)

We implement and maintain appropriate technical and organizational measures to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, appropriate to the risk. These include:

  • Encryption in transit (TLS) and at rest, including AES-256-GCM encryption of sensitive identity columns (for example government-ID and policy numbers);
  • Access controls — least-privilege access, authentication, and a default-deny access-control layer governing AI-agent access to sensitive data tables;
  • Logging and audit — administrative-action logging and read-audit logging on sensitive data tables (who/what/when/which record);
  • Segregation of data by workspace and tenant;
  • Backups with defined rotation (purged on rotation, maximum 35 days) and resilience measures;
  • Regular review and testing of these measures.

We may update our security measures over time provided the level of protection is not materially decreased.

8. Sub-processors

  • You grant general authorization for us to engage Sub-processors to process Personal Data, subject to this section.
  • Our current Sub-processors are listed on the Sub-processor List, including Microsoft Azure (hosting/storage/email) and Stripe (payments, once paid plans launch); any Troi-managed AI providers (Anthropic, OpenAI, ElevenLabs, and others) operate on a zero-retention / no-training tier. Services you connect with your own credentials (e.g. Twilio, social platforms) are user-initiated connections, not Troi sub-processors.
  • We impose data-protection obligations on each Sub-processor by written contract that are no less protective than those in this DPA, and we remain responsible for their performance.
  • Change notice: before adding or replacing a Troi-operated Sub-processor, we give at least 30 days' advance notice via the Sub-processor List. You may object on reasonable, data-protection grounds within that period; if we cannot reasonably accommodate the objection, you may terminate the affected part of the Service as your exclusive remedy.

9. Assistance to the Controller

Taking into account the nature of the processing and the information available to us, we assist you as follows:

  • Data-subject requests (GDPR Arts 12–22). We provide self-service tools (in-app and via a public web URL) for access, export (JSON/CSV), correction, and deletion, and we assist you with responding to Data Subject requests we cannot resolve through those tools. We respond to your reasonable request for assistance within 30 days. If a Data Subject contacts us directly about data we process for you, we refer them to you unless otherwise legally required.
  • Security, breach notification, DPIAs, and prior consultation (GDPR Arts 32–36). We assist you in ensuring compliance with your security, breach-notification, data-protection-impact-assessment, and prior-consultation obligations, taking into account the information available to us.
  • Personal Data Breach. We notify you without undue delay after becoming aware of a Personal Data Breach affecting your Personal Data, and provide the information reasonably available to us to help you meet your own notification duties. We take reasonable steps to mitigate and remediate.

10. Deletion or return on termination

On termination or expiry of the Service, and at your choice, we delete or return all Personal Data processed on your behalf and delete existing copies, unless Applicable Data Protection Law requires storage. Deletion follows the retention schedule in the Privacy Policy (including the 30-day grace period after a deletion request, and immediate deletion of Special Category Life data on consent revocation), after which residual copies are removed from active systems and expire from backups on the normal rotation (maximum 35 days). Self-service deletion and export are available in-app at any time.

11. Audits

We make available to you the information reasonably necessary to demonstrate compliance with GDPR Article 28 and this DPA, and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate. To respect the confidentiality and security of our systems and other customers' data, audits are conducted on reasonable prior notice, no more than once per year (except where required by a Supervisory Authority or following a Breach), during business hours, subject to confidentiality, and — where sufficient — may be satisfied by our security documentation and any third-party certifications or reports we hold.

12. International transfers

Where our processing involves transferring Personal Data from the EEA, UK, or Switzerland to a country without an adequacy decision:

  • We rely on the Standard Contractual ClausesModule Two (controller-to-processor) between you and us, and Module Three (processor-to-processor) for onward transfers to Sub-processors — which are incorporated into this DPA by reference and completed by the details in this DPA, the Sub-processor List, and the Annexes below; plus the UK IDTA/Addendum and Swiss adaptations as applicable.
  • Where a recipient participates in the EU-US Data Privacy Framework (and its UK/Swiss extensions), we also rely on the DPF.
  • We maintain a Transfer Impact Assessment and apply supplementary measures (such as encryption) as appropriate.
  • Where there is any conflict between the SCCs and this DPA, the SCCs prevail.

13. Order of precedence and incorporation

This DPA is incorporated into and forms part of the Terms of Service. In the event of a conflict on the subject of data protection, the order of precedence is: (1) the SCCs; (2) this DPA; (3) the Terms of Service; (4) the Privacy Policy. This DPA is governed by the same law and dispute-resolution terms as the Terms, except where Applicable Data Protection Law or the SCCs require otherwise.

14. How to accept this DPA

A signable DPA is available on request (email info@kanah.app). You may accept this DPA by (a) executing our standard order or acceptance mechanism, or (b) where offered, clicking to accept in-product on behalf of your organization. The person accepting warrants they are authorized to bind the Controller. Until a signed DPA is in place, processing is governed by the Terms and Privacy Policy.


Annex I — Description of processing

  • A. List of parties. Data exporter: the Customer/Controller accepting this DPA (contact: as provided in your account). Data importer: Kanah LLC, 1603 Capitol Avenue, Suite 413A, #2280, Cheyenne, WY 82001, USA · info@kanah.app · +1 (424) 291-5470. Our EU Representative (GDPR Art 27) appointment is in progress; a DPO is not currently appointed. In the interim, contact info@kanah.app.
  • B. Description of transfer. Data subjects: §4. Categories of data: §4. Special categories: §4(3), processed with explicit consent, with restricted access and read-audit as in §7. Frequency: continuous, for the term. Nature and purpose: §3. Retention: §10 and the Privacy Policy schedule. Sub-processor transfers: per the Sub-processor List.
  • C. Competent Supervisory Authority. Determined per the SCCs based on the exporter's establishment or EU Representative — to be confirmed once our EU Representative is appointed.

Annex II — Technical and organizational security measures

As described in §7 (encryption in transit and at rest including AES-256-GCM for sensitive identity columns; least-privilege access controls and default-deny AI-agent ACL; administrative and read-audit logging; tenant/workspace segregation; backup rotation and resilience; ongoing review and testing).

Annex III — List of Sub-processors

As set out on the Sub-processor List, which forms part of this DPA and is updated on 30 days' advance notice for Troi-operated Sub-processors.


Questions about this DPA: info@kanah.app · Kanah LLC, 1603 Capitol Avenue, Suite 413A, #2280, Cheyenne, WY 82001, USA.