Back to home

Data Processing Addendum

Last updated: June 8, 2026

This Data Processing Addendum ("DPA") forms part of the agreement between you ("Customer") and Clarity Books AI, LLC ("Clarity Books") for the provision of the Clarity Books AI service. It applies to the extent Clarity Books processes Personal Data on Customer's behalf that is subject to the EU General Data Protection Regulation ("GDPR"), the UK GDPR, the California Consumer Privacy Act as amended ("CCPA/CPRA"), or other applicable data-protection laws. Where Customer is a consumer using the Service for personal or household purposes, the Privacy Policy governs.

1. Definitions

Terms not defined here have the meanings given in the applicable data-protection law.

  • Personal Data: any information relating to an identified or identifiable individual that Customer submits to or that is processed through the Service.
  • Processing: any operation performed on Personal Data.
  • Sub-processor: a third party engaged by Clarity Books that processes Personal Data on Clarity Books's behalf.
  • Controller / Processor / Business / Service Provider: as defined under GDPR and CCPA/CPRA, respectively.

2. Roles of the Parties

For Personal Data relating to Customer's end-users, contractors, and business contacts that Customer inputs into the Service, Customer is the Controller (or "Business") and Clarity Books is the Processor (or "Service Provider"). Clarity Books acts on Customer's documented instructions as set out in the Terms of Service and this DPA.

For Personal Data about Customer's own account (name, email, billing, usage), Clarity Books acts as the Controller, as described in the Privacy Policy.

3. Scope of Processing

The table below describes the processing performed by Clarity Books on Customer's behalf.

Subject matterProvision of the Clarity Books AI bookkeeping service.
DurationFor the term of the subscription, plus retention periods in the Privacy Policy.
Nature and purposeImporting, storing, categorizing, and reporting on financial transactions; sending push notifications and email; account management; support.
Types of Personal DataName, email, phone number, business name and structure, billing metadata, bank-account metadata (no credentials), transaction descriptions/amounts/dates and AI-assigned categories, uploaded receipt and statement images, PDFs, and CSV files, invoice and contractor contact details (names, emails, phones, addresses, and masked last-four tax IDs: no full SSN/TIN), mileage start/end locations, sales-tax entries, and push-notification device identifiers.
Categories of data subjectsCustomer; Customer's contractors and 1099 recipients (if entered); Customer's invoice customers and business contacts referenced in transactions or uploaded documents.

4. Processor Obligations

Clarity Books will:

  • Process Personal Data only on Customer's documented instructions, including with regard to cross-border transfers, unless required by law;
  • Ensure that persons authorized to process Personal Data are bound by confidentiality;
  • Implement appropriate technical and organizational measures (see Section 7);
  • Assist Customer in responding to data-subject rights requests (access, deletion, portability, correction);
  • Notify Customer without undue delay (and no later than 72 hours) upon becoming aware of a Personal Data breach;
  • Make available information necessary to demonstrate compliance with this DPA;
  • At the end of the subscription, at Customer's choice, delete or return Personal Data, subject to retention required by law.

5. Sub-processors

Customer provides general authorization for Clarity Books to use the Sub-processors listed below. We maintain a current list; we will provide at least 14 days' advance notice of a new Sub-processor by email to the account owner, during which time Customer may object on reasonable data-protection grounds. If the parties cannot resolve the objection, Customer may terminate the affected portion of the Service for convenience.

Supabase
Database, authentication, and private file storage
US
Vercel
Application hosting, serverless functions, and CDN
US
Plaid
Bank-account connectivity
US
Anthropic
AI categorization, document/receipt/statement OCR, and natural-language assistance (no training on API data)
US
Stripe
Web subscription billing
US
RevenueCat / Apple
iOS in-app purchase and subscription management
US
OneSignal
Push-notification delivery (iOS & Android)
US
Resend
Transactional email
US
Sentry
Error and performance monitoring
US
Upstash
Rate limiting and abuse prevention
US

6. International Data Transfers

Clarity Books is established in the United States and Personal Data is processed in the United States. For transfers of Personal Data from the European Economic Area, the United Kingdom, or Switzerland to the US, the parties incorporate by reference the EU Standard Contractual Clauses (Module Two: Controller to Processor), the UK International Data Transfer Addendum, and the Swiss SCC adjustments, each as applicable. The parties will cooperate in completing any required schedules upon written request.

7. Security Measures

Clarity Books implements the following technical and organizational measures:

  • Encryption in transit: TLS (1.2 or higher) for all traffic to and from the Service.
  • Encryption at rest: AES-256 for database and object storage at the infrastructure layer; in addition, the Plaid bank-connection token is encrypted with AES-256-GCM by the application before storage.
  • Access control: role-based access, least-privilege defaults, and provider-enforced account security for administrative access.
  • Database isolation: Postgres row-level security policies enforce per-customer data isolation at the database layer.
  • No storage of banking credentials: we never receive your online-banking username or password; Plaid handles authentication.
  • Logging and monitoring: audit logs for administrative and security-relevant events.
  • Secure SDLC: dependency scanning, code review, and protected branches.
  • Vendor due diligence: Sub-processors are selected from providers with SOC 2 or equivalent attestations where available.
  • Backups: encrypted, retention-limited, and tested for restoration.
  • Incident response: documented procedure and 72-hour breach-notification commitment.

8. Data Subject Rights Assistance

If Clarity Books receives a request directly from a data subject regarding Personal Data processed on Customer's behalf, we will, without undue delay, forward the request to Customer and will not respond except at Customer's direction or as required by law. For requests Customer receives, Clarity Books will provide reasonable assistance, taking into account the nature of the processing.

9. Deletion and Return of Personal Data

Upon termination, and at Customer's written direction made within 30 days of termination, Clarity Books will either return a copy of Customer's Personal Data in a common electronic format or delete it. Live records (including uploaded receipt and document files) are deleted immediately and irreversibly on request; encrypted backups held by our infrastructure providers are purged on their rolling rotation (typically within about 30 days). Payment and invoice records held by our payment processor (Stripe) may be retained by that processor for up to 7 years to meet its own legal and tax obligations; Clarity Books does not maintain a separate financial archive after deletion.

10. Audits

Customer may verify Clarity Books's compliance with this DPA once per calendar year by reviewing: (a) the Privacy Policy, this DPA, and the Security page; (b) any SOC 2 or equivalent attestations made available; and (c) written responses to a reasonable questionnaire. On-site audits are not included; where required by law, the parties will negotiate in good faith on scope, timing, and cost.

11. CCPA / CPRA-Specific Terms

Clarity Books is a Service Provider under the CCPA/CPRA. Clarity Books will not: (a) sell or share Personal Information (as those terms are defined under CCPA/CPRA); (b) retain, use, or disclose Personal Information outside the direct business relationship between Clarity Books and Customer; (c) combine Personal Information received from Customer with Personal Information from other sources except as permitted by the CCPA/CPRA. Clarity Books certifies that it understands and will comply with these restrictions.

12. Conflict; Survival

In the event of a conflict between the Terms of Service, the Privacy Policy, and this DPA regarding the processing of Personal Data, this DPA controls. This DPA will remain in effect for so long as Clarity Books processes Personal Data on Customer's behalf.

13. Contact

Questions about this DPA? Email brayden@claritybooksai.com.