Disclosure
11.1 Sub-Processors
We share personal data with a limited set of vendors that help us operate the Service. Each is bound by a written agreement imposing confidentiality, security, purpose limitation, breach notification and deletion obligations — and, where the SPDI Rules apply to the transfer, a requirement to maintain the same level of protection required of us.
| Category | Purpose | Primary location |
|---|
| Cloud infrastructure — Amazon Web Services | Compute, storage, database, backup, content delivery | India (primary) |
| Email, SMS and push notification providers | Service notifications, alerts, password resets | India, US, EU |
| Payment gateways | Subscription billing and collection | India; varies by method |
| Product analytics, crash and error monitoring | Stability and performance diagnostics | India, US, EU |
| Support desk and ticketing | Handling support requests | India, US |
| Mapping and geocoding | Maps, address lookup, route calculation | Varies |
| Optical character recognition | Reading receipts and forms where enabled | India, US |
| Professional advisers and auditors | Legal, accounting, tax, certification and audit, under professional confidentiality | India |
An itemized register naming each vendor is available to Customers from support@teamtrace.app and forms an annex to our Data Processing Agreement. Customers on that agreement get advance notice of new or replacement sub-processors and may object on reasonable grounds.
11.2 Within the Customer's Organization
Workforce Data is visible to the users the Customer authorizes — typically the reporting manager, field-operations administrators, HR and workspace administrators — under role-based permissions the Customer configures, not us.
11.3 Legal and Regulatory Disclosure
We may disclose personal data where legally required: a court order, warrant, summons, statutory demand or binding request from a competent law-enforcement, tax or regulatory authority, compliance with a legal obligation, or establishing, exercising or defending legal claims. Our practice is to require that requests be in writing under valid legal authority and served on our designated contact, to challenge or narrow requests that are overbroad, defective or unlawful, to disclose only the minimum within scope, and to notify the affected Customer so it can protect its own interests, unless legally prohibited or there is an imminent risk to life or safety.
11.4 Corporate Transactions
In a merger, acquisition, financing, reorganization or sale of assets, personal data may be disclosed to the counterparty and its advisers under confidentiality obligations, and where required, through a de-identified or restricted-access diligence process. If such a transaction completes and the handling of your data would materially change, we will notify affected Customers, and affected individuals where required, before any change takes effect.