This Data Processing Agreement ("DPA") forms part of the Terms & Conditions between [COMPANY_LEGAL_NAME] ("Processor", "we") and the customer ("Controller", "you") and applies where we process personal data on your behalf in providing ReceiptTidy (the "Service"). It is entered into to satisfy Article 28 of the UK GDPR.

1. Roles

You are the controller of the personal data contained in the documents and records you upload or process through the Service (e.g. personal data of your suppliers, customers, or staff). We act as your processor for that data. For your own account/billing data we act as a controller (see our Privacy Policy).

2. Subject matter, duration, nature & purpose

  • Subject matter / nature: hosting, OCR, AI extraction, storage, and publishing of receipt/invoice data to accounting systems you connect.
  • Duration: for the term of your use of the Service.
  • Purpose: to provide the Service as described in the Terms and on your instructions.

3. Types of data & data subjects

  • Types: names, contact details, financial/transaction data, tax identifiers, and any other personal data contained in documents you upload.
  • Data subjects: your suppliers, customers, employees, and other individuals appearing in your records.

4. Our obligations

We will: (a) process personal data only on your documented instructions (including the Terms and your use of the Service), unless required by law; (b) ensure persons authorised to process it are under confidentiality obligations; (c) implement appropriate technical and organisational security measures (clause 6); (d) assist you, taking into account the nature of processing, with data-subject requests and with your obligations under Articles 32–36; (e) make available information necessary to demonstrate compliance.

5. Sub-processors

You provide general authorisation for us to engage sub-processors to provide the Service, including:

Sub-processorPurpose
Google Cloud (Vision)OCR
LLM provider(s)Data extraction
Cloudflare R2Encrypted document storage
StripePayments
Hosting providerInfrastructure
Email providerTransactional email

We impose data-protection obligations on each sub-processor no less protective than this DPA, and remain liable for their performance. We will give notice of intended changes to sub-processors and give you a reasonable opportunity to object.

6. Security measures

We implement measures appropriate to the risk, including: encryption of data in transit and at rest; per-tenant isolation via database row-level security; access controls and least-privilege; secrets management; audit logging; and backup with restricted access.

7. Personal data breaches

We will notify you without undue delay after becoming aware of a personal data breach affecting your data, with information to help you meet your own notification obligations.

8. Data-subject requests

If we receive a request from a data subject relating to your data, we will, where legally permitted, refer them to you and assist you in responding.

9. International transfers

Any transfer outside the UK/EEA is made under appropriate safeguards (UK adequacy, IDTA / Standard Contractual Clauses).

10. Return & deletion

On termination, or on your request, we will delete or return your personal data and delete existing copies, except to the extent retention is required by law (see Data Deletion & Retention).

11. Audit

We will make available information reasonably necessary to demonstrate compliance with Article 28 and allow for and contribute to audits, including inspections, conducted by you or your mandated auditor on reasonable notice and subject to confidentiality.

12. General

This DPA is governed by the laws of England and Wales. In case of conflict between this DPA and the Terms regarding processing of personal data, this DPA prevails.

Last updated: [LAST_UPDATED].