Data Processing Agreement
Effective August 12, 2026
This Data Processing Agreement (“DPA”) applies when you use ShadowLedger to process personal data on behalf of someone else, which for most of our customers means an accounting or bookkeeping firm running audits on its clients' books. It forms part of the Terms of Service and applies automatically to Firm accounts. If your organization needs a signed copy before connecting a client ledger, email support@getshadowledger.com and we will send one back countersigned, same day where possible.
1. Roles
You are the controller of the personal data you connect or upload. We are the processor, and we process that data only on your documented instructions. Using the Service is itself an instruction to process the data as described in the Terms and the Privacy Policy. Where your own customer is the controller and you are their processor, we act as a sub-processor and this DPA passes through accordingly.
We will tell you if, in our opinion, an instruction infringes applicable data protection law.
2. Scope of the processing
- Subject matter. Detecting recurring software subscriptions and spend in accounting records, and producing reports about them.
- Duration. For as long as your account is open, plus the erasure period in section 8.
- Nature and purpose. Reading transaction records, analyzing them, storing the results, and presenting them to you.
- Categories of data subject. Your personnel; personnel of your client companies whose names appear in accounting records or in uploaded documents; individuals named as vendor contacts.
- Categories of personal data. Names, business email addresses, transaction descriptions and amounts, vendor names, vendor owner names you enter yourself, and the contents of contract documents you choose to upload.
- Special category data. None is required and none should be uploaded. The Service has no facility for it and we ask you not to send it.
3. Confidentiality
Access to your data is limited to people who need it to run or support the Service and who are bound by confidentiality. In practice today that is one person, the operator named on the Security page.
4. Security measures
The measures below are what the Service does today, not aspirations. The Security page describes them at more length and is kept in step with the code.
- Accounting system credentials are encrypted at rest with AES-256-GCM using a per-record nonce, with the key held in the runtime environment rather than the database. The application refuses to start in production without it.
- Every query is scoped to the owning account at the data layer, so one account cannot read another's data. This is enforced by an automated test that fails the build if a new surface skips its guard.
- Accounting access is read-only in practice: the Service issues only read and query calls and never writes to your books.
- All traffic is encrypted in transit. Reports render in sandboxed frames.
- Every billing and account webhook is signature-verified before it is acted on.
- Access to client reports through a share link is logged, and share links expire and can be revoked.
We do not hold SOC 2 or an equivalent third-party certification, and we say so plainly rather than implying one. If your engagement requires one, tell us early.
5. Sub-processors
You authorize the sub-processors listed in Annex A. We remain responsible for their performance. If we add or replace one, we will update that list, which is published on the Security page, at least 30 days before the change takes effect, and will email the account contact for any change that affects where or how your data is processed. If you reasonably object, you may terminate the affected part of the Service and receive a pro-rata refund of anything paid in advance for it.
5.1 Disclosures you direct
The Service lets you create an API token and connect an AI assistant of your own choosing, which can then read your audit data. Anyone you give a token to is not our sub-processor. You are engaging them, on their terms, and Annex A says nothing about them.
What follows from that, stated plainly because it is the part that matters: once data reaches an assistant you connected, we cannot see what happens to it, we have no contractual relationship with whoever provides it, and none of the commitments in this agreement extend to them. Deciding whether a given assistant is an appropriate recipient for your clients' financial records is yours to make, and if you act as a processor for those clients it is likely a decision your own engagement terms and instructions have to cover before you turn it on.
A token reads only unless you mark it writable when you create it. A writable one additionally lets a connected assistant change finding triage and vendor notes, and every such change is recorded as having come from an assistant rather than from a person. No token can record a savings amount, add or remove a client, run an audit, or share a report.
We log which tool a token called and when, and will provide that record on request; it holds no vendor names or amounts. Revoking a token in Settings ends its access immediately.
6. Assistance
We will help you meet your own obligations, taking into account how the Service works and what we can see:
- Data subject requests. If a request reaches us directly about data you control, we will not answer it ourselves; we will pass it to you promptly. The Service gives you self-serve export and deletion, which covers most requests without our involvement.
- Breach notification. If we become aware of a personal data breach affecting your data, we will notify you without undue delay and give you the information you need for your own notifications: what happened, which data and roughly how many people, the likely consequences, and what we are doing about it.
- Impact assessments. We will provide the information we reasonably hold to support a data protection impact assessment or prior consultation.
7. Audits
We will make available the information needed to demonstrate compliance with this DPA and will respond to a reasonable security questionnaire once in any twelve-month period. On-site audits are not practical for an operation this size; if your policy requires one, raise it before signing rather than after.
8. Deletion and return
You can delete individual scans at any time, and export everything the account holds from Settings. Closing your account triggers an automatic erasure: every accounting grant is first revoked at the provider, then scans, transactions, connections, client workspaces, rules, share links, calendar links, uploaded branding, and preferences are deleted. Two things are kept in de-identified form, stripped of any link to you or your clients: product analytics events and any feedback you sent us.
Backups age out on their own cycle. We do not restore a backup to serve a closed account.
9. International transfers
We process data in the United States. Where you transfer UK or EEA personal data to us, the parties will rely on the transfer mechanism recorded in Annex C, together with the security measures in section 4.
For Australian personal information, we take reasonable steps to ensure the handling described here is consistent with the Australian Privacy Principles, including APP 8 on cross-border disclosure. For New Zealand, the equivalent applies under Information Privacy Principle 12.
Annex A: sub-processors
| Sub-processor | Purpose | Data it can access | Location |
|---|---|---|---|
| Vercel | Application hosting, and storage for firm logos on client reports. | All request traffic, server logs, and uploaded firm logo images. | United States |
| Prisma Postgres | The primary database that stores your scans and account data. | Everything the Service stores: transactions, findings, vendor records, connection tokens (encrypted), preferences, and billing identifiers. | United States |
| Clerk | Authentication and account management. | Your email address, name, and authentication credentials. | United States |
| Stripe | Payments and subscription billing. | Your email address, billing address, card details you enter on Stripe's own form, and subscription state. Card numbers never reach our servers. | United States |
| Anthropic | The AI analysis behind vendor matching, the Ask your ledger chat, and contract term extraction. | Transaction descriptions and vendor names sent for matching; the text of questions you ask in chat, together with the vendor names and amounts needed to answer them; and the full text of any contract document you upload for extraction. Under Anthropic's commercial terms, API inputs are not used to train their models. | United States |
| Resend | Transactional and notification email. | Your email address and the full contents of every message we send you, which for alerts and digests includes vendor names and amounts. | United States |
| Inngest | Background jobs, including scheduled re-scans and renewal alerts. | Job payloads, which carry account and connection identifiers. The financial data itself stays in our database. | United States |
| Expo | Push notifications to the mobile app, if you use it. Renewal alerts name the vendors that are renewing, so those names appear in the notification text. | Your device push token and the text of each notification. Renewal alerts name the vendors renewing, so those names pass through Expo and the Apple or Google push network in readable form. | United States |
Annex B: known limitations
Stated here rather than left to be discovered, because a DPA that only lists strengths is not worth reading:
- A firm account is a single login. There are no per-person seats yet, so access to client workspaces cannot be attributed to an individual member of your staff.
- The mobile app caches recent report data on the device using the platform's standard storage, which is not separately encrypted by us. Sign-out clears it. Treat a shared or unmanaged device accordingly.
- Push notifications name the vendors that are renewing, so those names are visible to the push network and on a locked screen. Notifications can be turned off in Settings.
- An API token is a bearer credential and is not bound to a device or an IP address. Anyone holding one can read everything your account can, until it is revoked, and we cannot tell one holder from another. See section 5.1.
- We do not hold SOC 2 or an equivalent certification.
Annex C: transfer mechanism
To be completed on execution. The mechanism for UK and EEA transfers is being confirmed with counsel. Until it is settled, ask for the current position before relying on this section, and we will tell you where it stands rather than pointing at a clause that has not been reviewed.
Contact
Anything about this agreement, including a request for a signed copy, goes to support@getshadowledger.com and reaches the person who runs the Service.
This agreement is provided as a starting point and is not legal advice. Both parties should review it with qualified counsel before relying on it.