Retrium Next (Beta)
Effective Date: August 10, 2026
This Data Processing Addendum (“DPA”) forms part of, and is subject to, the Terms & Conditions or other agreement (the “Agreement”) between the customer organization (“Customer,” “Controller,” or “you”) and Retrium, Inc. (“Retrium,” “Processor,” or “we”) for the use of Retrium Next (the “Service”). It applies where and to the extent Retrium processes Customer Personal Data on Customer’s behalf as a processor or service provider. If there is a conflict between this DPA and the Agreement regarding such processing, this DPA controls.
Capitalized terms not defined here have the meaning given in the Agreement. “Applicable Data Protection Laws” means all privacy and data protection laws applicable to the processing of Customer Personal Data, including, as applicable, the California Consumer Privacy Act as amended (“CCPA”), the Maryland Online Data Privacy Act (“MODPA”), other U.S. state privacy laws, the EU General Data Protection Regulation (“EU GDPR”), and the UK GDPR and Data Protection Act 2018 (“UK GDPR”). “Customer Personal Data” means personal data contained in Customer Content that Retrium processes on Customer’s behalf. “Controller,” “Processor,” “Business,” “Service Provider,” “Data Subject,” “Consumer,” “Personal Data,” “Processing,” and “Personal Data Breach” have the meanings given in Applicable Data Protection Laws. “Subprocessor” means a third party engaged by Retrium to process Customer Personal Data. “Standard Contractual Clauses” or “SCCs” means the clauses approved by the European Commission in Commission Implementing Decision (EU) 2021/914 of 4 June 2021 for the transfer of personal data to third countries (the “2021 SCCs”), and not the earlier clauses adopted under Directive 95/46/EC.
For Customer Personal Data, Customer is the Controller (or a processor acting on behalf of another controller) and Retrium is the Processor (or service provider). Retrium acts as an independent controller/business only for information described as such in the Privacy Policy (for example, account administration, security, support, direct communications, and business operations). The subject matter, duration, nature and purpose of processing, categories of Data Subjects, and types of Customer Personal Data are described in Annex I.
Retrium will process Customer Personal Data only on Customer’s documented instructions, including as set out in the Agreement, this DPA, and Customer’s configuration and use of the Service, and as necessary to provide, secure, support, and evaluate the Service, unless required to do otherwise by law (in which case Retrium will, where legally permitted, inform Customer). Retrium will inform Customer if, in its opinion, an instruction infringes Applicable Data Protection Laws.
Retrium will: (a) process Customer Personal Data only for the limited and specified purposes of providing the Service and as permitted by this DPA; (b) not sell or share Customer Personal Data, not use it for advertising, and not retain, use, or disclose it for any purpose other than the business purposes specified in the Agreement, or outside the direct business relationship, except as permitted by Applicable Data Protection Laws; (c) not combine Customer Personal Data with personal data from other sources except as permitted by Applicable Data Protection Laws; (d) not de-identify and then re-identify Customer Personal Data, and where it de-identifies data, maintain it as de-identified and obligate recipients not to re-identify it; and (e) comply with the obligations applicable to processors and service providers under Applicable Data Protection Laws. Retrium certifies that it understands and will comply with these restrictions.
Retrium will ensure that personnel authorized to process Customer Personal Data are subject to appropriate obligations of confidentiality and are informed of the confidential nature of the data. Access is limited to personnel who need it to provide, support, secure, and evaluate the Service.
Retrium will implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data against a Personal Data Breach, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing. A description of these measures is set out in Annex II.
Beta note. The Service is in beta. As stated in the Terms, Retrium does not provide a contractual availability, backup, or recovery service during the beta. This does not relieve Retrium of its obligation to apply appropriate security measures to Customer Personal Data while it is processed.
Customer provides general authorization for Retrium to engage Subprocessors to process Customer Personal Data, including the Subprocessors listed in Retrium’s Subprocessor Information and Annex III. Retrium will: (a) impose data protection obligations on each Subprocessor that are substantially similar to those in this DPA; (b) remain responsible for its Subprocessors’ performance; and (c) make available a mechanism to notify Customer of intended changes to Subprocessors and provide a reasonable opportunity to object on data-protection grounds.
AI inference used to summarize, organize, and surface themes from retrospective content is routed through OpenRouter to Google’s Gemini models, which Retrium uses as its sole model provider; requests are processed only on Google’s infrastructure and meet the requirements below. With respect to AI processing, Retrium will: (a) transmit Customer Personal Data to the AI provider only to generate outputs for the Service; (b) send every request under a zero-data-retention configuration with model training explicitly disabled, so the provider does not persist prompts or outputs or train on them, and cause requests to fail rather than route to a non-compliant endpoint; (c) send only pseudonymous identifiers as request metadata and never direct identifiers such as names or email addresses, so the provider cannot link content to a specific individual unless a user includes personal information within the content itself; and (d) not use Customer Personal Data to train AI models.
Retrium will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data. The notification will describe, to the extent known, the nature of the breach, the categories and approximate number of Data Subjects and records affected, the likely consequences, and the measures taken or proposed. Retrium will provide reasonable assistance to Customer in meeting Customer’s breach-notification obligations.
Taking into account the nature of the processing, Retrium will provide reasonable assistance, including appropriate technical and organizational measures and functionality within the Service, to help Customer respond to requests from Data Subjects or Consumers to exercise their rights (such as access, correction, deletion, portability, and opt-out) under Applicable Data Protection Laws. If Retrium receives such a request directly, it will, where permitted, direct the individual to Customer or promptly inform Customer.
Retrium will provide reasonable assistance to Customer with data protection impact assessments and prior consultations with supervisory authorities, to the extent required by Applicable Data Protection Laws and taking into account the information available to Retrium.
Upon termination or expiry of the Agreement, or upon Customer’s request, Retrium will, at Customer’s choice, delete or return Customer Personal Data within 30 days, and will delete existing copies (including residual copies in routine backups, which are overwritten in the ordinary course of Retrium’s backup rotation and are not restored to active use), except to the extent retention is required by law. Any Customer Personal Data that Retrium is required by law to retain remains subject to this DPA, is isolated from active processing, and will not be used for any other purpose until deletion is possible. Retrium will not use termination, the beta limitations, or its backup practices as a basis to retain or use Customer Personal Data beyond these limits.
Retrium will make available to Customer information reasonably necessary to demonstrate compliance with this DPA, and will allow for and contribute to audits, including inspections, conducted by Customer or an auditor mandated by Customer, subject to reasonable confidentiality, scope, frequency, and notice requirements. Retrium may satisfy audit obligations by providing summaries of relevant certifications, third-party audit reports, or security documentation where available.
Where Retrium processes Customer Personal Data originating from the European Economic Area, the United Kingdom, or Switzerland and transfers it to a country that has not received an adequacy decision, the parties agree that the appropriate transfer mechanism applies:
The SCCs prevail over any conflicting terms in this DPA with respect to transfers to which they apply. Retrium Next serves customers in the EEA and the UK, so these transfer terms apply. This DPA uses the 2021 EU SCCs and the UK IDTA, and does not rely on the legacy pre-2021 clauses used in Retrium’s prior DPA.
Each party’s liability under this DPA is subject to the limitations and exclusions of liability set out in the Agreement. This DPA takes effect on the Effective Date above and continues for as long as Retrium processes Customer Personal Data. This DPA is governed by the governing law and dispute-resolution provisions of the Agreement, except where Applicable Data Protection Laws or the SCCs require otherwise.
Parties: Data exporter — Customer (Controller). Data importer — Retrium, Inc. (Processor), 8705B Colesville Road, #219, Silver Spring, MD 20910, USA; +1-888-768-4259; next@retrium.com.
Categories of Data Subjects: Customer’s personnel and authorized users who participate in retrospectives (for example, employees, contractors, and team members).
Categories of Customer Personal Data: Identifiers and contact details (name, email, organization/team); account and authentication data; and retrospective content such as comments, notes, votes, interview/survey responses, and action items, including opinions about work and workplace situations.
Sensitive data: The Service is not designed to process Highly Sensitive Data (as defined in the Terms), and Customer agrees not to submit it intentionally.
Nature and purpose of processing: Hosting, storage, and processing of Customer Content to provide, secure, support, and evaluate the Service, including AI-assisted summarization and theme identification.
Duration: For the term of the Agreement and the beta, subject to the retention and deletion practices described in the Privacy Policy.
SCC module selection: Module Two (Controller-to-Processor). For UK transfers, the UK International Data Transfer Addendum (IDTA) to the EU SCCs applies.
Retrium maintains measures that include: encryption of Customer Personal Data in transit (TLS/SSL); hosting on Amazon Web Services in the United States; access controls and least-privilege permissions, with access revoked on termination; authentication controls, including multi-factor authentication; network protections and hardening; logging, monitoring, and intrusion detection; independent penetration testing; secure software development practices; subprocessor risk management; personnel confidentiality obligations; and incident response procedures.
The current list of Subprocessors, including their functions and locations, is set out in Retrium’s Subprocessor Information. AI providers used for the Service should be identified there as well. Retrium will update the list and provide a mechanism to receive notifications of changes.