Substrate
OverviewFor ProducersFor SuppliersFor ConsultantsDemo
Sign inWork With Us
OverviewFor ProducersFor SuppliersFor ConsultantsDemoSign in

Data Processing Agreement

How Trash Club Insights handles the personal information in a customer’s Substrate workspace. It is part of our Terms of Service for every customer, and we will countersign a copy on request.

Last updated October 10, 2026·Trash Club Insights

1Parties, scope and order

This agreement is between Trash Club Insights (“we”) and the customer that uses Substrate under our Terms of Service or an order form (“Customer”). It covers personal information that Customer or its users put into Customer’s workspace (“Customer Personal Data”). It does not cover the account and contact data we handle for our own purposes, which the Privacy Policy covers.

If this agreement and the Terms disagree about Customer Personal Data, this agreement wins. A signed order form wins over both only where it says so expressly.

2Roles

Customer decides why and how Customer Personal Data is processed. We process it on Customer’s behalf. Under the California Consumer Privacy Act we are Customer’s service provider; under other laws, its processor. Annex 1 describes the processing.

3Instructions

We process Customer Personal Data only to provide the Service, as the Terms, this agreement and Customer’s use of the Service direct, and on Customer’s other written instructions. We will tell Customer if we believe an instruction breaks the law, or if we are legally required to process the data in another way, unless we are legally barred from telling.

As a service provider, we will not:

  • sell or share Customer Personal Data;
  • keep, use or disclose it for any purpose other than providing the Service, or outside our direct business relationship with Customer;
  • combine it with personal information from other sources, except where that is legally permitted;
  • use it to train AI models.

We will comply with the CCPA and give Customer Personal Data the protection it requires. We will tell Customer if we can no longer meet these obligations. Customer may then take reasonable steps to stop and remedy any unauthorized use.

4Our people and our security

Only people who need to run the Service may access Customer Personal Data, and each is bound to confidentiality. We keep the security measures in Annex 2. We may improve them, but we will not reduce the overall protection they give.

5Subprocessors

Customer authorizes the subprocessors listed in Annex 3 and on our subprocessor page. Each is bound by data-protection terms that protect Customer Personal Data at least as well as this agreement. We remain responsible for what they do with it.

Before a new subprocessor starts receiving Customer Personal Data, we will add it to that page and email Customer’s workspace administrators at least 30 days ahead. Customer may object in writing within that period on reasonable data-protection grounds. We will then try in good faith to resolve the objection. If we cannot, Customer may end the affected part of the Service, and we will refund any fees paid in advance for the time after it ends.

6Helping with requests from individuals

If a person asks us directly about their information in Customer’s workspace, we will pass the request to Customer and not answer it ourselves, unless we are legally required to. We will help Customer answer such requests, given the nature of the processing. Customer’s administrators can see, correct and download the workspace’s data themselves (§9).

7Security incidents

If we learn of a breach of security that leads to unauthorized access to, or loss, change or disclosure of, Customer Personal Data, we will tell Customer without undue delay, and within 72 hours of confirming it. We will say what we know, what we are doing, and who to contact, and we will add details as we learn them. We will help Customer meet any duty it has to notify regulators or the people affected. Telling Customer is not an admission of fault.

8Information and audits

On request, once a year, we will answer Customer’s reasonable written security questionnaire and give the information reasonably needed to show we meet this agreement. If a regulator requires more, or after a security incident, Customer may audit our compliance with 30 days’ notice, during business hours, under confidentiality, and at its own cost. We do not hold third-party security certifications today.

9Return and deletion

A Customer administrator can download the whole workspace at any time, from Account, as one JSON file that documents its own contents. Uploaded documents are listed in that file; we send the files themselves to an administrator within 30 days of a request. Both stay available for at least 30 days after the subscription ends.

After that, on Customer’s written request, we will delete or de-identify Customer Personal Data in the workspace within 90 days, with two exceptions that are part of what Customer buys. Signed filings and their attestations, and the change log, cannot be changed or deleted by design. We keep them, limit access to them, and use them for nothing else. We switch off the workspace’s accounts, and our daily job de-identifies each one 90 days later. Database backups are kept for 7 days, so deleted data leaves them within a week.

10Where data is held

We store Customer Personal Data in the United States and do not move it elsewhere. If Customer needs to send us personal data from the European Economic Area, the United Kingdom or Switzerland, tell us before doing so, and we will agree the transfer terms the law requires first.

11Liability and term

Each party’s liability under this agreement is subject to the limits in the Terms. This agreement lasts as long as we process Customer Personal Data.

12Annex 1 · The processing

Subject matter and purpose

Providing Substrate: collecting packaging specifications, matching them to volumes, computing fees, and preparing and recording regulatory filings.

Nature

Storing, organizing, computing on, displaying and transmitting data.

Duration

The subscription, then as §9 describes.

People concerned

Customer’s staff and contractors who use the Service; contacts at Customer’s suppliers whom Customer invites.

Kinds of data

Names, business email addresses, job titles, workspace roles, the name and title on a filing attestation, and records of who changed what and when. No sensitive personal information is expected; the Service does not ask for any.

13Annex 2 · Security measures

  • All traffic encrypted with TLS; browsers told to use only encrypted connections.
  • Passwords stored only as bcrypt hashes, which the web application cannot read.
  • Session tokens stored only as SHA-256 hashes. Sessions end 12 hours after sign-in, or at sign-out.
  • Failed sign-ins slowed by network address and by account; no account is ever locked.
  • Each workspace’s data separated by row-level rules in the database itself.
  • The website’s database account holds only the permissions it needs; credentials are not readable by it.
  • The demonstration and the client service run on separate databases; no data is copied between them.
  • Signed filings are hash-chained and cannot be changed; every change to workspace data is logged.
  • The database is backed up daily, and each backup is kept for 7 days. Uploaded files are stored separately and are not in those backups.
  • Access to the production database is limited to the people who run the Service.
  • Two-step sign-in and sign-out after inactivity are not offered today.

14Annex 3 · Subprocessors

The list as of the “last updated” date above. The current list is always at substratereport.com/subprocessors.

Vercel Inc. · Hosting and delivery

ReceivesEvery request to the Service, including the network address and browser details that come with it, and the pages and data sent back. Vercel keeps short-lived request logs.

WhyIt runs the application and serves it over an encrypted connection.

WhereUnited States

Used onDemonstration and client service

Supabase, Inc. · Database and file storage

ReceivesEverything stored in the Service: accounts, workspace data, filings, the change log, and uploaded specification documents.

WhyIt hosts the database and the file store. The demonstration and the client service each have their own project.

WhereUnited States (Amazon Web Services, Oregon)

Used onDemonstration and client service

Resend · Sending email

ReceivesEach email we send: the recipient's address and name, the workspace or company it concerns, the sender's address as the reply-to, and the message, which holds a one-time link.

WhyIt delivers account invitations, demonstration access invitations and password-reset emails.

WhereUnited States

Used onDemonstration and client service

Google LLC (Google Workspace) · Our mailbox

ReceivesEmail you send to our addresses, including privacy requests and security reports, and our replies.

WhyIt hosts the mailbox our legal, privacy and security addresses deliver to.

WhereUnited States

Used onDemonstration and client service

15Notices and signature

Notices under this agreement go to legal@trashclubventures.com and to Customer’s workspace administrators by email. To receive a countersigned copy, email that address with Customer’s legal name and a signatory.

Trash Club Insights
PO Box 1067

Indian Hills, CO 80454

Substrate

The data layer underneath packaging EPR, built for the obligated producer.

For ProducersFor SuppliersFor ConsultantsFee estimatorDemo accessWork With Us

Rate, deadline and obligated-party information is curated from published regulatory sources and cited to source inside the product; it is not legal advice.

© 2026 Trash Club Insights
PrivacyTermsContact