This Data Processing Addendum (“DPA”) is entered into between MatchLedger, Inc., a Delaware corporation with its registered address at 1908 Thomes Ave, STE 68447, Cheyenne, Wyoming 82001, United States (“MatchLedger,” “we,” “us”) and the business customer identified in Annex I (“Customer,” “you”). It forms part of, and is subject to, our Terms of Service(the “Terms”).
It applies where you use the MatchLedger service at app.matchledger.ai (the “Service”) to process personal data about people other than yourself — the account holders, counterparties, and individuals named in the documents you upload. For that data you are the controller and we are your processor, as described in Section 2.2 of our Privacy Policy.
You do not need this DPA to use MatchLedger. It exists because business customers subject to the GDPR, the UK GDPR, or the Swiss FADP are required by Article 28(3) to have a written processing agreement with their processors. If that is you, see Section 15 (How to enter into this DPA).
1. Definitions
“Data Protection Law”means, as applicable to the processing: Regulation (EU) 2016/679 (the “GDPR”); the GDPR as incorporated into United Kingdom law by the European Union (Withdrawal) Act 2018 together with the Data Protection Act 2018 (the “UK GDPR”); and the Swiss Federal Act on Data Protection of 25 September 2020 (the “FADP”).
“Customer Personal Data”means the personal data contained in Customer Data that we process on your behalf as your processor, as described in Annex I.B. It does not include the personal data for which we are ourselves the controller — your own account and billing information, product-usage analytics, and data from the free conversion tool — which we process under our Privacy Policy and not under this DPA.
“SCCs” means the Standard Contractual Clauses annexed to Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
“UK Addendum” means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018, version B1.0, in force 21 March 2022.
“Customer Data,” “Service,” and “Plan” have the meanings given in the Terms. “controller,” “processor,” “sub-processor,” “data subject,” “personal data,” “processing,” and “personal data breach” have the meanings given in the GDPR.
2. Roles, Scope, and Precedence
2.1 Roles of the parties
For Customer Personal Data, you are the controller and we are your processor. Where you are yourself acting as a processor for a third party — for example, a bookkeeping or accountancy firm processing its client's records — we act as that party's sub-processor, you warrant that you have the authority to instruct us on their behalf, and references in this DPA to your instructions include theirs.
2.2 Precedence
This DPA forms part of the Terms. In the event of a conflict, the following order applies to the processing of Customer Personal Data, from highest to lowest: (a) the SCCs and the addenda in Annexes IV and V; (b) this DPA; (c) the Privacy Policy; (d) the Terms. Terms Section 4.8 already provides that an executed DPA prevails over the Terms in relation to the processing of personal data. In all other respects the Terms are unchanged.
2.3 Duration
This DPA takes effect on the date it is countersigned under Section 15 and continues for as long as we process Customer Personal Data on your behalf. Sections 4, 9, 10, 11, and 13 survive its termination.
3. Processing on Documented Instructions
3.1 Your instructions
We process Customer Personal Data only on your documented instructions, including with regard to transfers to a third country. Your documented instructions consist of: the Terms, the Privacy Policy, this DPA, and the instructions you give through your use of the Service — uploading a document, running a reconciliation, generating an export, inviting a user, deleting a record.
The nature and purpose of the processing, the types of personal data, and the categories of data subjects are described in Annex I.B.
3.2 No processing for our own purposes
We do not process Customer Personal Data for our own purposes, and we do not sell it, rent it, trade it, or use it for advertising. We do not use it to train or fine-tune machine-learning models, and our AI sub-processor is contractually bound not to train on it — see Terms Section 4.3 and Privacy Policy Section 8.
The single processing activity that goes beyond running a reconciliation for you is the testing and calibration of format templatesusing the documents you upload, disclosed in Privacy Policy Section 3 and Terms Section 7.1. Format templates are configuration artifacts that describe a financial institution's or accounting package's document layout. They are designed and validated to contain no personal data, and any personal data ever found in one is promptly removed and handled under the Privacy Policy. That activity is carried out on your instruction as part of providing and improving the Service to you.
3.3 Unlawful instructions
We will inform you if, in our opinion, an instruction infringes Data Protection Law, and may suspend performance of that instruction until it is confirmed, amended, or withdrawn.
3.4 Legally required processing
If we are required by United States or other applicable law to process Customer Personal Data other than on your instructions, we will inform you of that legal requirement before processing, unless the law prohibits that information on important grounds of public interest.
3.5 Special categories
The Service is not designed for special categories of personal data within the meaning of GDPR Article 9, or for personal data relating to criminal convictions and offences. Terms Section 4.8 records your warranty not to upload them except where you are lawfully permitted to do so. We apply no additional safeguards specific to such data, and you should not infer any.
4. Confidentiality
We ensure that persons authorised to process Customer Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and that access is limited to those who need it to provide, secure, maintain, or support the Service. Administrative access to production systems requires separate credentials and is audit-logged.
5. Security of Processing
We implement the technical and organisational measures set out in Annex II, having regard to the state of the art, the costs of implementation, and the nature, scope, context, and purposes of the processing, as required by GDPR Article 32.
We may update those measures over time provided the level of security is not materially reduced. Annex II reproduces Section 4.3 of our Privacy Policy; the two are maintained together and the Privacy Policy is the source of record.
6. Sub-processors
6.1 General authorisation
You give us a general written authorisation to engage sub-processors. The sub-processors engaged as at the effective date of this DPA are listed in Annex III. This corresponds to Option 2 of Clause 9(a) of the SCCs.
6.2 Notice of changes and your right to object
We will give you at least 30 days'notice before adding or replacing a sub-processor, by email to your account's administrative contact. You may object on reasonable data-protection grounds within that period. If we cannot accommodate your objection, you may terminate the affected Plan without penalty and receive a pro-rata refund of any fees paid for the unused remainder of the term, and we will delete Customer Personal Data under Section 10.
6.3 Terms and liability
We impose on each sub-processor data-protection obligations no less protective than those in this DPA by written contract, and we remain fully liable to you for a sub-processor's performance of its obligations.
7. Data Subject Requests
Taking into account the nature of the processing, we assist you by appropriate technical and organisational measures, insofar as this is possible, in fulfilling your obligation to respond to requests to exercise data-subject rights under Chapter III of the GDPR.
In practice, the Service's own export and deletion functions let you satisfy most requests without our involvement. Where they do not, contact dpo@matchledger.ai.
If a data subject contacts us directly about Customer Personal Data, we will not respond to the substance of the request ourselves. We will refer it to you without undue delay and assist you in responding. Section 6.4 of our Privacy Policy tells data subjects this and commits us to a one-month response clock for the requests we do answer as controller.
8. Assistance with Assessments and Consultation
Taking into account the nature of the processing and the information available to us, we assist you in ensuring compliance with GDPR Articles 32 to 36 — security of processing, breach notification, data protection impact assessments, and prior consultation with a supervisory authority. Requests under this Section go to dpo@matchledger.ai. Annexes I to III of this DPA, together with the Privacy Policy, are intended to supply most of what a DPIA about the Service needs.
9. Personal Data Breach
We notify you without undue delayafter becoming aware of a personal data breach affecting Customer Personal Data, by email to your account's administrative contact. The notification describes, to the extent known at the time: the nature of the breach and the categories and approximate number of data subjects and records concerned; the likely consequences; the measures taken or proposed; and a contact point for further information. Where that information is not all available at once, we provide it in phases as it becomes available.
You notify the supervisory authority, not us. As controller, the Article 33 72-hour clock and the Article 34 duty to inform data subjects are yours. We assist you in meeting them.
Separately, and as our own controller obligation, we notify the competent supervisory authority within 72 hours where a breach of the personal data we hold as controller is likely to result in a risk to the individuals concerned — see Section 4.4 of our Privacy Policy. We have no establishment in the European Union, so the one-stop-shop mechanism does not apply to us and notification is made to each affected authority directly.
10. Deletion and Return of Personal Data
10.1 During the term
The Service deletes Customer Personal Data automatically on the retention windows published in Section 5 of our Privacy Policy and Section 4.5 of the Terms, whether or not your account is open. In summary:
| Data | Deleted |
|---|---|
| Uploaded source files and the transaction data extracted from them | 30 daysafter the last reconciliation job that used the document finishes, or 30 days after that job's most recent export, whichever is later. Each new reconciliation or export restarts the window. If never used in a reconciliation, 30 days after upload |
| Reconciliation results and export files | 30 days after the job completes or the last export is generated, whichever is later |
| Account information and organisation settings | On account closure, plus 30 days for you to export |
| Terms-acceptance records and audit logs | 3 years after account closure. These are our own records of a legal act, kept to evidence who agreed to what and when |
10.2 At the end of the service
On termination or expiry, we delete Customer Personal Data on the windows above. At your written choice, made before those windows elapse, we will instead return it to you first — the Service's CSV and Excel export functions are the return mechanism, and we will assist if you cannot use them.
The windows are the constraint on that choice, and they are short. Because deletion is automatic and runs whether or not your account is open, we will in most cases be unable to return Customer Personal Data more than 30 days after your last reconciliation or export, and cannot recover it once deleted. Export before you stop using the Service. We do not offer an extended-retention or escrow option.
10.3 Backups and legal retention
Copies in backup archives are removed as those archives rotate, no more than 30 days after deletion from our active systems. We retain Customer Personal Data beyond the windows above only where United States or other applicable law requires it, and in that case only for as long as required and only for that purpose, and we continue to protect it under this DPA.
11. Information and Audit Rights
We make available to you the information necessary to demonstrate compliance with GDPR Article 28 and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate.
In the first instance we satisfy this by providing the information in this DPA, the Privacy Policy, and written answers to your questions, and by passing on the security documentation of the sub-processors in Annex III. If that is not sufficient for your regulatory obligations, we will cooperate with an audit on reasonable written notice of at least 30 days, no more than once in any 12-month period unless a supervisory authority or a personal data breach requires otherwise, during business hours, subject to confidentiality, and in a manner that does not disrupt the Service or compromise the data of our other customers. You bear the costs of an audit you initiate, except where it establishes a material breach by us.
We hold no third-party security certification. We are not SOC 2 or ISO 27001 certified and do not represent otherwise. Annex II states what we actually do.
12. International Transfers
12.1 Where the data goes
Customer Personal Data is stored and processed in the United States, by us and by the sub-processors in Annex III. The United States has not been found by the European Commission, or by the UK or Swiss authorities, to provide an adequate level of data protection.
12.2 The Standard Contractual Clauses
Where you transfer Customer Personal Data subject to the GDPR to us, the SCCs, Module Two (controller to processor), are incorporated into this DPA by reference and form part of it, with you as data exporter and MatchLedger as data importer. We do not rely on your consent, or on any data subject's consent, as the basis for these transfers.
The optional provisions are completed as follows:
| Clause | As completed |
|---|---|
| Clause 7 — Docking clause | Included. An additional entity may accede as exporter or importer |
| Clause 9 — Sub-processors | Option 2, general written authorisation, with 30 days' notice of changes (Section 6.2) |
| Clause 11(a) — Independent dispute resolution | Not included. The optional independent dispute-resolution body is not selected. Data subjects retain every other redress route in Clause 11 and Clause 18 |
| Clause 13 — Competent supervisory authority | The supervisory authority of the Member State in which the data exporter is established. Where the exporter is not established in a Member State, the Data Protection Commission of Ireland |
| Clause 17 — Governing law | Option 1: the law of Ireland |
| Clause 18(b) — Forum and jurisdiction | The courts of Ireland |
| Annexes I, II, III of the SCCs | Annex I, Annex II, and Annex III of this DPA respectively |
12.3 Onward transfers to sub-processors
Our onward transfers to the sub-processors in Annex III are covered by each sub-processor's own transfer mechanism — in each case the SCCs, or an adequacy decision, under that provider's data processing terms, which we have accepted and keep on file. We make the accepted terms available to you on request under Section 11.
12.4 Government access
We have assessed the laws and practices of the United States as they apply to the data we transfer, and apply the safeguards in Annex II. We have never received a government or law-enforcement request for Customer Personal Data. Should we receive one, we will, to the extent legally permitted, notify you promptly, challenge a request we consider unlawful or excessive, and disclose only the minimum required. Clauses 14 and 15 of the SCCs apply in full. Our transfer impact assessment is available to you on request.
12.5 UK and Switzerland
Transfers subject to the UK GDPR are governed by the SCCs as amended by Annex IV (UK Addendum). Transfers subject to the FADP are governed by the SCCs as amended by Annex V (Swiss amendments).
13. Liability
Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Terms, except that nothing in this DPA or the Terms limits: (a) either party's liability to a data subject under Clause 12 of the SCCs; (b) liability that cannot be limited under Data Protection Law; or (c) either party's liability for death or personal injury caused by negligence, or for fraud.
14. General
If a provision of this DPA is held invalid or unenforceable, the rest remains in force. We may update this DPA to reflect a change in Data Protection Law, a change in the Service, or a change of sub-processor; a change that materially reduces your rights takes effect no earlier than 30 days after we notify you, and Section 6.2 governs sub-processor changes. Where an executed copy exists, the executed copy governs until the parties agree a replacement.
The current version of this DPA is always published at matchledger.ai/dpa.
15. How to Enter Into This DPA
We do not yet have an electronic signature flow, so execution is by email:
- Print or export this page, complete Annex I.Awith your entity's details, and sign it.
- Email the signed copy to dpo@matchledger.ai from an address on your account, quoting your organisation name.
- We countersign and return it within 5 business days. The DPA takes effect on the date of our countersignature, and the SCCs are treated as signed by both parties on that date.
If your organisation requires its own DPA template instead, send it to the same address. We will review it, but we may ask you to use this one.
Annex I — Parties and Description of the Processing
This Annex is Annex I to the SCCs.
A. List of parties
Data exporter (controller).The Customer. Name, address, contact person's name, position and contact details, and signature to be completed by the Customer on execution. Activities relevant to the transfer: use of the MatchLedger service to reconcile financial records. Role: controller.
Data importer (processor). MatchLedger, Inc., 1908 Thomes Ave, STE 68447, Cheyenne, Wyoming 82001, United States. Contact: dpo@matchledger.ai. Activities relevant to the transfer: provision of the MatchLedger service as described in the Terms. Role: processor.
B. Description of the transfer
| Categories of data subjects | The Customer's own account holders and personnel; and the individuals and businesses named in the documents the Customer uploads — account holders, payees, payers, and other counterparties named in transaction descriptions. Where the Customer is a bookkeeping or accountancy firm, these include its clients and its clients' counterparties |
| Categories of personal data | Identity and contact data appearing on statements and ledger reports (names, account names, partial account numbers, addresses where printed on a statement); financial transaction data (dates, amounts, currencies, transaction descriptions, running balances, references); and the reconciliation results derived from them |
| Sensitive data | None. The Service is not intended for special categories of personal data and the Customer warrants under Terms Section 4.8 not to upload them. No additional restrictions or safeguards specific to sensitive data are applied |
| Frequency of the transfer | Continuous, for the duration of the Customer's use of the Service |
| Nature and purpose of the processing | Storage of uploaded documents; AI-assisted extraction of transaction data from them; matching of transactions between a statement and a ledger; generation of reconciliation results and export files; transactional email about those operations; and the testing and calibration of format templates described in Section 3.2 — all for the purpose of providing the Service to the Customer |
| Retention period | As set out in Section 10. In summary: documents and extracted data, 30 days after last use; reconciliation results and exports, 30 days; account data, closure plus 30 days; acceptance records and audit logs, 3 years after closure |
| Sub-processors | As set out in Annex III, for the subject matter, nature, and duration stated there |
C. Competent supervisory authority
The supervisory authority of the Member State in which the data exporter is established. Where the data exporter is not established in a Member State but falls within the territorial scope of the GDPR under Article 3(2), the Data Protection Commission of Ireland (dataprotection.ie).
Annex II — Technical and Organisational Measures
This Annex is Annex II to the SCCs. It reproduces Section 4.3 of our Privacy Policy.
We implement the following security measures to protect your data:
- All data transmitted between your browser and our servers is encrypted using TLS (HTTPS)
- Passwords are stored using bcrypt hashing with salt
- Authentication uses stateless JWT tokens with configurable expiration
- Database access is restricted by Row-Level Security policies per organization
- File storage uses per-organization path isolation with time-limited access URLs
- Administrative access requires separate credentials and is audit-logged
In addition, for the purposes of Clause 8.6 of the SCCs: each organisation's data is isolated at the database level using PostgreSQL Row-Level Security, so users in one organisation cannot access another's (Privacy Policy Section 4.2); data at rest is held on Linode Object Storage and a PostgreSQL database in the United States (Section 4.1); data is deleted on the automatic retention windows in Section 10 of this DPA; and the measures a sub-processor is required to take are those in its own data processing terms, which we have accepted and keep on file.
Annex III — Sub-processors
This Annex is Annex III to the SCCs. It is the same list as Section 3 of our Privacy Policy, which is the source of record. Changes are notified under Section 6.2.
| Sub-processor | What is shared | Purpose | Location |
|---|---|---|---|
| Anthropic (Claude API) | Contents of uploaded financial documents | AI-powered data extraction, and testing and calibration of format templates using documents you upload | United States |
| Linode (Akamai Cloud) | Uploaded source files, generated export files | Cloud storage | United States |
| Stripe, Inc. | Name, email, billing country, and payment-card details you enter at checkout | Payment processing and subscription billing | United States |
| Resend | User email addresses, notification content | Transactional email delivery | United States |
| Google (Analytics) | Aggregated browsing data from the marketing website and the application (pages viewed, time on page, referral source) | Website and application traffic analysis | United States |
| Google (Ads) | An advertisement click identifier, and the fact that a signup followed it. No name, email address, or account details | Measuring which advertisements result in new signups | United States |
| PostHog, Inc. | Product-usage events in the application — pages viewed, controls clicked, a defined set of product events, and plan attributes. No document contents | Product analytics | United States |
| Sentry (Functional Software, Inc.) | Error reports from the application and our servers: the error message, page, browser type, and technical trace. No IP address and no account identifiers | Error monitoring | United States |
| Cloudflare, Inc. (Turnstile) | IP address and browser signals, on the free conversion tool only | Automated bot check, to prevent abuse of the free tool | United States |
Only the first four process Customer Personal Data. Anthropic, Linode, Stripe, and Resend are sub-processors for the purposes of this DPA. The remaining entries process personal data for which weare the controller — product analytics, error monitoring, advertising measurement, and the free conversion tool — not Customer Personal Data. They are listed here because Section 3 of the Privacy Policy lists them and the two must agree; changes to any of them are notified under Section 6.2 all the same. None of them receives document contents.
Annex IV — UK International Data Transfer Addendum
For transfers subject to the UK GDPR, the parties enter into the UK Addendum (version B1.0, in force 21 March 2022), which is incorporated by reference and completed as follows.
| Table 1 — Parties | As set out in Annex I.A. Start date: the date of countersignature under Section 15 |
| Table 2 — Selected SCCs | The SCCs as incorporated by Section 12.2: Module Two, with Clause 7 included, Clause 9 Option 2 (30 days), Clause 11(a) optional wording not used, Clause 17 Option 1 (Ireland), Clause 18(b) Ireland |
| Table 3 — Appendix information | Annex 1A and 1B: Annex I. Annex II: Annex II. Annex III: Annex III |
| Table 4 — Ending the Addendum when the Approved Addendum changes | Neither party |
For UK transfers, references in the SCCs to the GDPR are read as references to the UK GDPR, references to Member State law as references to the law of the United Kingdom, the competent supervisory authority is the Information Commissioner's Office, and the governing law and forum are those of England and Wales, in each case as provided by the UK Addendum.
Annex V — Swiss Amendments
For transfers subject to the FADP, the SCCs incorporated by Section 12.2 apply with the amendments set out by the Swiss Federal Data Protection and Information Commissioner:
- The competent supervisory authority is the Federal Data Protection and Information Commissioner (edoeb.admin.ch), and the Data Protection Commission of Ireland where the transfer is also subject to the GDPR.
- References to the GDPR are read as references to the FADP, and references to Member State or EU law as references to Swiss law, in each case to the extent the transfer is governed by the FADP.
- The term “personal data” includes data about legal entities until the entry into force of the revised FADP's treatment of such data.
- Data subjects in Switzerland may enforce their rights under the SCCs in Switzerland.
Questions about this DPA— including a request for a signable copy, our transfer impact assessment, or a sub-processor's data processing terms — go to dpo@matchledger.ai.
MatchLedger, Inc.
1908 Thomes Ave, STE 68447, Cheyenne, Wyoming 82001, United States
Data Protection Officer: dpo@matchledger.ai