Data Processing Addendum
Last updated August 10, 2026
This addendum forms part of the Terms of Service where we process personal data on your behalf. Customers may request a countersigned copy.
1. Roles
You are the controller of personal data contained in the financial records you connect. We act as processor and process that data only on your documented instructions, which include using the product as intended.
2. Nature and purpose of processing
- Subject matter: analytics, reconciliation and AI explanation over connected financial data.
- Duration: for the term of the subscription plus the deletion window.
- Data subjects: your customers, payers and employees represented in connected records.
- Categories: names, emails, transaction amounts, timestamps, identifiers and payment metadata.
3. Security measures
- Encryption in transit (TLS 1.2+) and at rest.
- Provider credentials encrypted with dedicated keys and never exposed to browsers.
- Row-level security enforcing per-organization isolation.
- Role-based access control, append-only audit trails for sensitive actions.
- Least-privilege internal access, reviewed periodically.
4. Subprocessors
You provide general authorization for the subprocessors listed on our subprocessors page. We give notice before adding a new subprocessor and you may object on reasonable data-protection grounds.
5. International transfers
Where personal data is transferred outside the EEA or UK, transfers rely on Standard Contractual Clauses and supplementary measures as appropriate.
6. Assistance and breach notification
We assist you with data subject requests, DPIAs and audits within a reasonable scope, and notify you without undue delay after becoming aware of a personal data breach affecting your data.
7. Deletion and return
On termination we delete workspace personal data within 30 days, or return it in a machine-readable export on request before deletion.
8. Contact
DPA requests: legal@stripepilot.com.