Data Processing Addendum

Last updated August 10, 2026

This addendum forms part of the Terms of Service where we process personal data on your behalf. Customers may request a countersigned copy.

1. Roles

You are the controller of personal data contained in the financial records you connect. We act as processor and process that data only on your documented instructions, which include using the product as intended.

2. Nature and purpose of processing

  • Subject matter: analytics, reconciliation and AI explanation over connected financial data.
  • Duration: for the term of the subscription plus the deletion window.
  • Data subjects: your customers, payers and employees represented in connected records.
  • Categories: names, emails, transaction amounts, timestamps, identifiers and payment metadata.

3. Security measures

  • Encryption in transit (TLS 1.2+) and at rest.
  • Provider credentials encrypted with dedicated keys and never exposed to browsers.
  • Row-level security enforcing per-organization isolation.
  • Role-based access control, append-only audit trails for sensitive actions.
  • Least-privilege internal access, reviewed periodically.

4. Subprocessors

You provide general authorization for the subprocessors listed on our subprocessors page. We give notice before adding a new subprocessor and you may object on reasonable data-protection grounds.

5. International transfers

Where personal data is transferred outside the EEA or UK, transfers rely on Standard Contractual Clauses and supplementary measures as appropriate.

6. Assistance and breach notification

We assist you with data subject requests, DPIAs and audits within a reasonable scope, and notify you without undue delay after becoming aware of a personal data breach affecting your data.

7. Deletion and return

On termination we delete workspace personal data within 30 days, or return it in a machine-readable export on request before deletion.

8. Contact

DPA requests: legal@stripepilot.com.