Data Processing Addendum
Effective date: October 3, 2026
1. About this DPA
This Data Processing Addendum ("DPA") explains how Liquid Trinity Productions LLC, doing business as Liquid Trinity Technologies ("Liquid Trinity Technologies", "we", "us"), processes personal data on behalf of its customers. It forms part of our Terms of Service and applies automatically when the Customer's use of a Product involves personal data that is protected by the GDPR, the UK GDPR, or similar data protection laws. Capitalized terms that are not defined here have the meaning given in the Terms.
Customers who need a countersigned copy can email support@liquidtrinitytechnologies.com. How we handle our own account, billing, support, and website data is described in our Privacy Policy, not in this DPA.
2. Parties and roles
- The Customer is the organization that subscribes to a Product. For personal data in Customer Data, the Customer is the controller. If the Customer processes that data on behalf of someone else, the Customer is a processor and we are its subprocessor.
- Liquid Trinity Productions LLC, a California limited liability company doing business as Liquid Trinity Technologies, Santa Monica, California, USA, is the processor.
3. Subject matter, duration, nature, and purpose
- Subject matter. Providing the Products the Customer subscribes to, currently DDL Expander, an add-in for Microsoft Outlook.
- Duration. The term of the Customer's Subscription, plus the retention periods in section 5 and in our Privacy Policy.
- Nature. Reading information from the Customer's Microsoft 365 tenant, holding it in memory briefly, returning it to the user who asked for it, and storing the limited account and seat records described below.
- Purpose. To show the members of Exchange Online dynamic distribution groups inside Outlook, to sign users in, to count seats, to manage the Subscription, and to give support.
- Frequency. Continuous, for as long as the Customer uses the Product.
4. Data subjects and categories of data
| Data subjects | Personal data | How we handle it |
|---|---|---|
| The Customer's Authorized Users | Microsoft Entra object ID, tenant ID, and the date of last use. The sign-in token also carries the user's name and sign-in email address. | Object IDs and last-use dates are stored for seat counting and kept for 35 days after the last use. Name and email address are read to recognize the person during a request and are not stored. |
| The Customer's Billing Admin | Contact email address and Microsoft Entra object ID. | Stored while the Subscription is active and deleted or anonymized within 90 days after it ends. |
| People who are members of the Customer's distribution lists | Display name, email address, and recipient type. | Processed in memory to answer a request. Held for up to 5 minutes and never stored in our database or written to disk. |
| People who contact us for support | Name, email address, and the content of their message. | Held in our business mailbox while we answer and for as long as we need the record. |
We do not intend to process special categories of personal data. The Customer should not use a Product to process them. The Customer's tenant ID and its initial onmicrosoft.com domain identify an organization, not an individual.
5. Our obligations as processor
- Instructions. We process personal data only on the Customer's documented instructions. The Terms, this DPA, and the Customer's use of the Product are those instructions. If we think an instruction breaks the law, we will tell the Customer.
- Confidentiality. Everyone who can access personal data on our side is bound by confidentiality obligations.
- Security. We use the measures in the Annex and keep them appropriate to the risk.
- Helping with requests. If a person asks us about personal data we process for the Customer, we will send them to the Customer. Taking into account what the Product does, we will reasonably help the Customer respond to requests from individuals, carry out data protection impact assessments, and consult regulators.
- Deletion and return. When a Subscription ends, we delete or anonymize the Customer's account data within 90 days. On a verified request from the Customer's tenant administrator or Billing Admin, we delete it within 30 days. Deleted data can remain in our encrypted backups for up to 7 days before it is overwritten. We keep only the Customer's tenant ID and the date its Free Trial was used, to prevent repeat free trials, and a deletion record (tenant ID, date, and counts only) as proof that the deletion was carried out. Billing and tax records are held by Stripe for 7 years as the law requires. We do not hold the Customer's distribution list data after the request it was read for, so there is nothing to return.
- Audits. On reasonable written request, no more than once a year, we will give the Customer documentation that shows we meet this DPA, including a description of our security measures. Where the law requires more, we will cooperate with an audit by the Customer or a regulator.
6. The Customer's responsibilities
The Customer decides which Authorized Users may use a Product, has a lawful basis for the processing it instructs, and gives any notices that the law requires to the people whose data it asks us to process. The Customer is also responsible for the messages it sends, as the Terms explain.
7. Subprocessors
The Customer gives us general authorization to use these subprocessors:
| Subprocessor | Purpose | Location |
|---|---|---|
| Microsoft Azure (Microsoft Corporation) | Hosting, database, storage, secrets storage, diagnostic logging, and email delivery | United States regions |
| Stripe, Inc. | Payment processing, invoicing, and sales tax calculation. Receives the tenant ID, the Billing Admin's Microsoft Entra object ID, the billing contact email address, and the plan and seat count. | United States |
| Microsoft 365 (Microsoft Corporation) | Our business email, which holds support messages | Microsoft data centers |
Changes. We will tell the Customer at least 30 days before we add or replace a subprocessor, by email to the Billing Admin or by updating this page. The Customer can object on reasonable data protection grounds within that time. We will try to resolve the objection. If we cannot, the Customer may cancel the affected Subscription under the Terms.
We have a written agreement with each subprocessor that requires data protection terms at least as protective as this DPA, and we remain responsible for their work.
8. Personal data breaches
If we become aware of a breach of security that leads to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data we process for the Customer, we will tell the Customer without undue delay and within 72 hours of becoming aware. We will describe what happened, the kinds and approximate amount of data involved, the likely consequences, and what we are doing about it, and we will update the Customer as we learn more.
9. International transfers
We process personal data in the United States. When the Customer sends us personal data that is protected by the GDPR, the UK GDPR, or Swiss data protection law, these terms apply:
- EU Standard Contractual Clauses. The Standard Contractual Clauses in Commission Implementing Decision (EU) 2021/914 are incorporated by reference. Module Two(controller to processor) applies where the Customer is a controller. Module Three(processor to processor) applies where the Customer is a processor. The Customer is the data exporter and we are the data importer.
- Choices in the clauses. Clause 7 (docking clause) applies. Clause 9(a) uses Option 2, general authorization, with the 30 days' notice in section 7. The optional wording in Clause 11(a) does not apply. For Clause 13, the supervisory authority is the one for the Customer's establishment in the EU, or for the Customer's representative, and otherwise the Irish Data Protection Commission. For Clause 17 (Option 1) and Clause 18(b), the law and courts are those of Ireland.
- Annexes. Annex I is sections 2 to 4 of this DPA. Annex II is the Annex below. Annex III is the subprocessor table in section 7.
- UK. The UK International Data Transfer Addendum to the EU Standard Contractual Clauses, issued by the UK Information Commissioner, is incorporated by reference. Its tables are completed with the information in this DPA, and neither party may end it when the Commissioner issues a revised version.
- Switzerland. The clauses also apply to transfers governed by Swiss law, with references to the GDPR read as references to Swiss law and the Swiss Federal Data Protection and Information Commissioner as the competent authority.
If the clauses and this DPA conflict, the clauses control.
10. California
For personal information covered by the California Consumer Privacy Act, we act as the Customer's service provider. We do not sell or share that information, and we do not retain, use, or disclose it outside our direct business relationship with the Customer or for any purpose other than providing the Products.
11. Liability and order of precedence
Each party's liability under this DPA is subject to the limits in the Terms, except where the law or the Standard Contractual Clauses do not allow that. If this DPA conflicts with the Terms about personal data, this DPA controls.
12. Contact
Liquid Trinity Productions LLC, doing business as Liquid Trinity Technologies
Santa Monica, California, USA
support@liquidtrinitytechnologies.com
Annex: technical and organizational measures
- Encryption. Traffic to our websites and service uses TLS 1.2 or later. Our database and storage are encrypted at rest by Microsoft Azure.
- Authentication. Users sign in with Microsoft Entra ID. Every request to our service must carry a valid Entra token, which we check for issuer, audience, and tenant before doing anything.
- Tenant isolation. We work out the tenant from the validated token, never from the request, and every query is limited to that tenant.
- Least-privilege access. Our service reads your Exchange Online with a certificate and the read-only View-Only Recipients role. Secrets and certificates are kept in Azure Key Vault. Access to our systems is limited to the people who need it.
- Restricted non-production environments. Our development and staging environments accept requests only from allowlisted IP addresses.
- Logging without personal data. Diagnostic logs contain request times and results, tenant IDs, and error types, but no distribution list names or email addresses. On access-denied and billing-admin events a log entry may include a Microsoft Entra object ID, a random identifier that is not a name or an email address. Client IP addresses are masked. Logs are kept for 90 days.
- Data minimization. We store only the account, subscription, and seat records described in this DPA. Distribution list members are processed in memory and are not stored.
- Backups. Database backups are encrypted and kept for 7 days.
- Deletion. Data is deleted or anonymized on the schedule in section 5.
- Vulnerability reports. Security issues can be reported through our Support page.