What you upload
Certificates of Analysis, chemical identity files, sequence files, intake answers, and related business context needed to prepare a diagnostic or dossier sprint. Do not upload materials you lack rights to share. Mark trade-secret or FOIA-sensitive material clearly in intake.
Where it lives
Files are stored in a private Cloudflare R2 bucket bound to the Trellis Pages project. Sprint metadata and review state live in Cloudflare D1. Session tokens use HttpOnly cookies.
Who can open it
- The client user on the engagement
- The assigned expert reviewer
- Trellis admin for quality release and support
While you use it
Your engagement work stays with your engagement. You receive the delivered package (dossier, slides, audio, transcript as applicable) through the client portal.
When the engagement ends
Access for revisions follows the product terms (including any included RFI revision rounds). After close, we keep working vault files for about 90 days by default so you can request an export, then delete them from the working store — unless a signed MSA sets a different schedule.
If you want it gone sooner
Email info@trelliscompliance.co. We will export what we reasonably can and delete working copies within 30 days, except invoices, acknowledgments, and other records the law requires us to keep.
What we keep for our records
Order, invoice, payment, and tax records required for accounting and law — not a second copy of your laboratory science beyond those retention windows.
Outline for a signed institutional DPA (lawyer to finalize)
- Parties and roles (buyer decides purpose; Hortiki processes to run Trellis)
- Scope and term (engagement length plus export period)
- Categories of data and data subjects
- Hortiki duties: instructions, confidentiality, security, assistance with individual requests, breach notice within 72 hours, audit information on request
- Sub-processors (Cloudflare, Stripe, email, Wise) and notice before material changes
- International transfers
- Return/export then deletion at end of term
- Liability aligned to the order form
- E-signature with the order