Data Processing Agreement
1. The parties and their roles
This agreement is between you (“the Controller”) and PolitelyPaid (“the Processor”). It applies to the personal data of your clients that you enter into, or generate through, the service. You determine why and how that data is processed; we process it only on your documented instructions, which are the actions you take in the product.
2. Subject matter and duration
We process your clients’ contact and billing details in order to produce invoices, deliver them, and send the reminder sequences you have approved. Processing lasts for as long as your account exists, and ends with the deletion process described in clause 6.
3. Categories of data and data subjects
Data subjects are your clients and their staff. Categories are: name, company name, email addresses, postal address, tax registration number, timezone, and the record of messages sent to them.
4. Our obligations
- Process personal data only on your instructions.
- Keep it confidential, and bind our staff to the same.
- Apply appropriate technical and organisational measures: encryption in transit and at rest, per-account isolation enforced at the query layer, and least-privilege access.
- Assist you in responding to data-subject requests.
- Notify you without undue delay if we become aware of a breach.
- Delete or return the data at the end of the agreement.
5. Sub-processors
You authorise the sub-processors listed in our privacy notice — Neon (database hosting), Vercel (application hosting) and Postmark (transactional email). We will give notice before adding one, and you may object.
6. Deletion
On termination, or when you delete your account, we first stop all automated sending on your behalf, then permanently delete your data within 30 days, except where law requires us to retain it.
7. Audit
We will make available the information reasonably necessary to demonstrate compliance with this agreement, on request.