Trust Centre

Triage Trust Centre

We believe trust is earned through transparency. Here's exactly how Triage handles your data.

Last reviewed: March 2026

Compliance

GDPR Compliance EU

Triage is designed GDPR-compliant from day one. Compliance is not a retroactive patch — it shaped the architecture of the product.

Data stored in the EU. All primary data is stored in Supabase on AWS eu-west-1 (Ireland region), within EU jurisdiction.
We store contact IDs and scores — not raw contact objects. Triage references your CRM data by ID; it does not duplicate or permanently store contact records in our system.
CSV data is processed transiently. CSV uploads are used to generate briefs and are not stored permanently beyond the processing session.
You control your data. Delete requests are honoured within 30 days. You can export or delete your account at any time from settings.
Lawful basis: Legitimate Interests. Triage is a B2B outreach preparation tool, not a consumer product. Our lawful basis for processing is Legitimate Interests under Article 6(1)(f) GDPR. We do not process personal or consumer data.
We never sell your data. Triage does not sell data, share data with third parties for marketing purposes, or build advertising profiles from your usage.
Data inventory

Data We Collect

Account data

Email address and display name, collected for authentication only via Supabase Auth. We do not collect phone numbers, billing addresses, or personal identifiers beyond what is needed to identify your account.

Usage data

Brief generation counts and credit usage are logged against your account to enforce plan limits and track billing. Product analytics (feature usage, session behaviour) are collected anonymously via PostHog EU Cloud. Individual events are not tied to identifiable personal data in analytics.

CSV uploads

When you upload a CSV, the data is processed server-side to generate contact briefs. CSV contents are not permanently stored beyond your active session. Once briefs are generated, the raw CSV data is discarded.

Domain scrape results

When Triage fetches signals from a company's public web presence (homepage, job postings, blog), results are cached per domain — not per contact. No personally identifiable information is cached as part of the domain scrape.

CRM data (when connected)

CRM integrations operate on a read-only API basis by default. Triage reads contact and account data to generate briefs. We write data back to your CRM only when you explicitly trigger a push action (e.g. saving a brief to a CRM note). We do not store raw CRM contact objects in our own database.

Third parties

Sub-processors

The following sub-processors are used in the delivery of the Triage service. All sub-processors are bound by Data Processing Agreements.

Sub-processor Purpose Location DPA in place
Supabase Database & authentication Ireland (EU) EU Yes
Vercel Hosting & edge delivery EU / US Yes
Anthropic (Claude) AI brief generation US Yes — data not used for model training
ZeroBounce Email verification US Yes
People Data Labs Contact enrichment US Yes
Stripe Payment processing US / EU Yes
PostHog Product analytics EU Cloud EU Yes
Resend Transactional email US Yes
Inngest Background job processing US Yes

For transfers to US-based sub-processors, appropriate safeguards (Standard Contractual Clauses) are in place in accordance with GDPR Chapter V.

Security

Security Practices

A summary of the technical and organisational measures in place. See the full Security page for more detail.

Encryption in transit: All data is transmitted over TLS 1.2 or higher. HTTPS is enforced on all endpoints.
Encryption at rest: AES-256 encryption applied to all stored data via Supabase defaults.
Row Level Security (RLS): Every Supabase database query is scoped to the authenticated user. Users cannot access each other's data.
API key security: All API keys (ZeroBounce, PDL, CRM tokens) are stored as encrypted environment variables. They are never included in client-side code or logs.
Rate limiting: API rate limiting is enforced per user on all endpoints to prevent abuse.
Prompt injection prevention: All CSV and CRM data is sanitised before being passed to Claude API calls to prevent prompt injection attacks.
No shared credentials: Each user's session and data access is isolated. No shared credentials exist across user accounts.
GDPR Articles 12–22

Your Rights

As a data subject under GDPR, you have the following rights. To exercise any of them, contact privacy@triage.club or use your account settings.

Right to access

Export all your personal data directly from account settings at any time.

Right to deletion

Deleting your account removes all your data from our systems within 30 days.

Right to portability

Export your contacts and generated briefs as CSV from your account.

Right to object

Object to our processing at any time by contacting privacy@triage.club.

Right to restrict processing

You can pause your account at any time, which halts all active processing of your data.

Right to rectification

Update your account details at any time via account settings. Contact us for corrections we can't surface in-product.

Enterprise

Data Processing Agreement

A formal Data Processing Agreement (DPA) is available to Enterprise tier customers as standard.

If you require a DPA on a lower tier — for example, as a condition of your organisation's procurement process — contact legal@triage.club and we will review on a case-by-case basis.

Standard Contractual Clauses (SCCs) are available for non-EU customers where data transfers outside the European Economic Area require additional safeguards under GDPR Chapter V.

DPA requests legal@triage.club
SCC enquiries legal@triage.club
Availability Enterprise tier (standard) · Lower tiers on request
Contact

Get in Touch

Data Controller Triage.club
Privacy queries privacy@triage.club
Legal / DPA legal@triage.club
Security issues security@triage.club
Last reviewed March 2026
FAQ

Common Questions

Is Triage GDPR compliant?
Yes. Triage is designed GDPR-compliant from day one. Data is stored in EU-based infrastructure (Supabase, Ireland), we operate under a Legitimate Interests lawful basis for B2B outreach preparation, and we never sell or share data with third parties for marketing purposes.
Where is my data stored?
Account and usage data are stored in Supabase on AWS eu-west-1 (Ireland). CSV uploads are processed transiently and not stored permanently. Domain scrape results are cached per domain — they contain no personally identifiable information.
Does Triage sell my data?
No. Triage never sells your data, shares it with third parties for marketing purposes, or builds advertising profiles. Your data is used solely to operate the Triage service for you.
How do I delete my data?
You can delete your account directly from account settings. Deletion requests are honoured within 30 days. You can also email privacy@triage.club to request deletion, restrict processing, or exercise any other GDPR right.
Does Anthropic use my data to train its models?
No. Triage's use of the Anthropic Claude API is governed by a Data Processing Agreement that confirms your data is used for inference only and is not used to train Anthropic's AI models.
Is a Data Processing Agreement (DPA) available?
Yes. A formal DPA is available as standard on the Enterprise tier. If you require a DPA on a lower tier, contact legal@triage.club and we will review your request. Standard Contractual Clauses (SCCs) are available for non-EU data transfers.