Data Processing Addendum

Effective 2026-09-20 · version 1

This addendum is part of the Terms of Service between ResidualsOS (“we”, “us”) and the organization using ResidualsOS (“you”). It says how we handle the personal data you load into your workspace. It is written for customers in the United States.

1. Scope

This addendum applies whenever the Customer Data you load into ResidualsOS includes Personal Data about your partners, your merchants and their contacts, or your own staff, and it governs our Processing of that data for as long as the Terms apply. It is incorporated into the Terms by reference: you accept it when you accept the Terms, and no signature is needed.

It does not cover the data that describes your relationship with us — your logins, workspace memberships, our invoices to you, the usage we meter, and the audit trail of the service. For that data we are the controller, and the Privacy Policy applies on its own.

2. Definitions

  • Customer Data is the data you and your users load into your workspace, and what the service derives from it: merchants, partners, uploaded processor statements, calculations, statements, payout records, tickets, notes and email.
  • Personal Data is any Customer Data that identifies or relates to an identifiable person, such as a partner’s name, email and mailing address, or a merchant contact’s phone number.
  • Processing is anything done with Personal Data: storing, calculating, displaying, transmitting, backing up, deleting.
  • Subprocessor is a vendor we use that Processes Customer Data on our behalf.
  • Security Incident is a confirmed breach of our security that leads to the accidental or unlawful destruction, loss, alteration or unauthorized disclosure of, or access to, Personal Data in our custody. An unsuccessful attempt — a blocked probe, a failed sign-in — is not one.

3. Roles

For Customer Data, you are the controller (under the CCPA, the “business”) and we are the processor (the “service provider”). You decide what to load and why. You are responsible for having a lawful basis to collect the Personal Data you load, for giving your partners and merchants any notice they are owed, and for the accuracy of what you upload — as section 4 of the Terms and section 2 of the Privacy Policy already say. For the account, billing and audit data described in section 1 we are the controller.

4. Our instructions

We Process Personal Data only on your documented instructions. The Terms, this addendum, and the way you and your users operate the service — uploading a file, running a calculation, sending statements, connecting a mailbox — are those instructions. We do not Process Customer Data for any other purpose, and never to train machine-learning or AI models, unless the law requires it; if it does, we tell you first unless the law forbids that. If we believe an instruction breaks the law we will tell you and may pause the work until it is resolved.

5. Personnel

Access to Customer Data is limited to personnel who need it to operate or support the service, and each of them is bound by a confidentiality obligation. Staff access to a workspace goes through our Owner Console: it is time-boxed, requires a stated reason, is read-only, can be revoked while it runs, and is written to your own audit log. Who can reach what is reviewed on a quarterly schedule.

6. Security

We maintain the technical and organizational measures section 8 of the Privacy Policy describes, and we will not materially reduce them during the term. Today they include:

  • each customer’s workspace in its own physical database, with no shared table across customers;
  • TLS for traffic in transit and encryption at rest for every database and file;
  • two-factor authentication available to everyone, required for workspace owners and for anyone recording a payment, and enforceable for all staff by your policy;
  • role-based access enforced on the server, so a partner sees only their own book;
  • an append-only audit log of every significant action, readable by your staff in the app;
  • nightly backups of every database, kept 35 days and integrity-checked, with the restore path drilled monthly;
  • the staff console on a separate host behind Cloudflare Access;
  • field-level encryption of partners’ payout bank account numbers and of the taxpayer identification numbers the tax-form feature holds, with only the last four digits readable;
  • a published vulnerability-disclosure route at security.txt and security@residualsos.com.

7. Assistance with requests from individuals

The product lets you answer most requests from a partner or a merchant yourself: export merchants, payout runs and statements; correct a record; delete a partner without payment history, a prospect or a document; and delete the workspace. If a person writes to us directly about data you loaded, we pass the request to you and act on your instruction, and we help you respond within the time the law allows. Some records cannot be erased and we will say so: the audit log, and locked payout runs, statements and payment records that are your financial records.

8. Security Incidents

When we confirm a Security Incident affecting your Personal Data we notify your workspace owners by email without undue delay, with what happened, when, what data was involved, and what we recommend you do, and we keep you updated as we learn more. We take reasonable steps to contain the incident and to help you meet your own notification duties. A notice is not an admission of fault.

9. Deletion and return

You can take your data out at any time through the exports in the app — a workspace owner takes every table as CSV files in one zip from Settings → Workspace → Export everything, kept until the next export replaces it — and a workspace owner can delete the workspace at any time; deletion is immediate and permanent. If we end the agreement other than for cause, you have at least 30 days’ notice to export before we delete the workspace. After a workspace is deleted, what remains is what section 9 of the Privacy Policy lists: backups age out within 35 days and the hosting provider’s point-in-time history within 30, while the account record marked closed, our invoices and the audit log are kept as our own records.

10. Audits

We document how the service handles data in the Privacy Policy, the Subprocessors page, this addendum and the disclosure route above, and we answer reasonable written questions about our security and Processing — at most once a year, unless a Security Incident or a regulator’s demand justifies more. We do not offer on-site audits or third-party audits of our systems unless a written agreement between us provides for one, at your expense.

11. Subprocessors

You authorize the Subprocessors named on the Subprocessors page, which says what each one receives and where it runs. Each is bound by written terms that protect Customer Data at least as well as this addendum, and we remain responsible for their work. Before we add or replace one, we post the change there at least 30 days ahead where that is practical and email your workspace owners. If you object on reasonable data-protection grounds and we cannot resolve it, you may end the agreement under the Terms; we cannot carve a single vendor out of the service for one customer.

12. International transfers

We are a United States business. Customer Data is stored and Processed in the United States on Cloudflare’s network and by the other vendors listed. This addendum is written for customers established in the United States. We have not put in place Standard Contractual Clauses, a UK addendum or an EU or UK representative, and a customer established in the EU, the UK or another jurisdiction that restricts transfers needs a separate written agreement with us before loading that data.

13. Your obligations

Load only data the service is built for. ResidualsOS is not built for, and you agree not to load: payment card numbers or security codes; bank account or routing numbers, Social Security or other government identification numbers, except a partner’s payout bank account entered for ACH payment files and a partner’s taxpayer identification number entered in the tax-form feature, both stored encrypted; health information; or data about anyone under 18. Keep your users’ access current — remove people when they leave — and use the security features we offer. You are responsible for the lawfulness of what you upload and of the emails you direct us to send.

14. CCPA service-provider terms

Where the California Consumer Privacy Act applies, we act as your service provider. We will not sell or share Personal Data; will not retain, use or disclose it for any purpose other than providing the service under the Terms, or outside our direct business relationship with you; will not combine it with Personal Data from another customer or source except as the CCPA permits a service provider to; will give it the same level of privacy protection the CCPA requires of you; will tell you if we can no longer meet these obligations; and will let you take reasonable steps to stop and remedy any unauthorized use. We certify that we understand these restrictions and will comply with them.

15. Liability

Each party’s liability under this addendum is subject to the limitations and exclusions in section 10 of the Terms, and the Terms and this addendum together share one aggregate limit.

16. Precedence and term

This addendum is part of the Terms of Service. For the Processing of Customer Data it controls over a conflicting term in the Terms; a signed agreement between us controls over both. It takes effect on the effective date at the top of this page, lasts as long as the Terms apply, and its obligations continue for as long as we hold any Customer Data. It is governed by the laws of the State of [set in src/shared/legal.ts], as the Terms are. Questions about it go to privacy@residualsos.com.