Legal center

Data Processing Agreement

The data-protection terms that apply when TightLedger processes personal data for a customer.

Effective July 23, 2026Version 2026-07-23
On this page
  1. How this DPA applies
  2. 1. Definitions and precedence
  3. 2. Roles and documented instructions
  4. 3. Customer responsibilities
  5. 4. Confidentiality and personnel
  6. 5. Security measures
  7. 6. Subprocessors
  8. 7. Data-subject requests
  9. 8. Government and third-party requests
  10. 9. Personal data incidents
  11. 10. Compliance assistance
  12. 11. Information and audits
  13. 12. Return and deletion
  14. 13. International data transfers
  15. 14. Canada and United States terms
  16. 15. Liability and duration
  17. Annex I — Processing details
  18. Annex II — Technical and organizational measures
  19. Annex III — Subprocessors

How this DPA applies

This Data Processing Agreement (“DPA”) forms part of the agreement between Ivorycom LLC (“Processor,” “Ivorycom,” or “TightLedger”) and the customer identified in an order or online acceptance (“Controller” or “Customer”) when TightLedger processes Customer Personal Data on the Customer’s behalf.

If the Customer is itself a processor, “Controller” includes the relevant controller and the parties will apply processor-to-processor obligations where required. This DPA does not become an executed Standard Contractual Clause package merely by being displayed online. Customers may request an executable copy with completed annexes at legal@tightledger.com.

1. Definitions and precedence

“Applicable Data Protection Law” means privacy and data-protection law that applies to the processing, including where applicable the EU GDPR, UK GDPR, UK Data Protection Act 2018, PIPEDA and substantially similar Canadian provincial laws, and applicable US state privacy laws. “Customer Personal Data” means personal data in Customer Content processed by TightLedger on the Customer’s behalf. “Subprocessor” means a processor engaged by Ivorycom to process Customer Personal Data.

Terms such as controller, processor, personal data, processing, data subject, and supervisory authority have the meanings in Applicable Data Protection Law. If this DPA conflicts with the service agreement on privacy or security, this DPA controls. Mandatory transfer clauses control over conflicting commercial terms.

2. Roles and documented instructions

The Customer determines the purposes and means of processing Customer Personal Data and acts as controller, except where it acts as a processor for another controller. Ivorycom processes Customer Personal Data only on documented instructions in the agreement, this DPA, product configuration, connected-source permissions, support requests, and lawful written directions.

Ivorycom will notify the Customer if, in our reasonable opinion, an instruction violates Applicable Data Protection Law, unless law prohibits notice. Ivorycom may suspend the affected processing while the parties resolve the issue. Ivorycom acts as an independent controller for its own account, billing, security, fraud-prevention, legal, and service-administration data as explained in the Privacy Notice.

3. Customer responsibilities

The Customer will provide lawful instructions, process personal data fairly, give required notices, obtain required permissions or consent, and ensure its use of TightLedger complies with law. The Customer is responsible for the accuracy, quality, and legality of Customer Personal Data and for the systems and people from which it was obtained.

The Customer will not intentionally submit special-category, health, biometric, government-identifier, consumer-credit, or children’s data unless the parties have documented the need and appropriate safeguards in an order or written instruction.

4. Confidentiality and personnel

Ivorycom will ensure that personnel authorized to process Customer Personal Data are bound by confidentiality obligations, receive appropriate privacy and security instruction, and access data only as necessary for their duties. Access is removed when no longer required.

5. Security measures

Ivorycom will maintain technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. Measures are described in Annex II and may evolve to reflect technology and risk, provided overall protection is not materially reduced.

6. Subprocessors

The Customer grants general written authorization for Ivorycom to use the subprocessors in Annex III. Ivorycom will contractually require each Subprocessor to protect Customer Personal Data to a standard consistent with this DPA and remains responsible for its Subprocessor obligations to the extent required by law.

After production launch, Ivorycom will maintain a current list and provide advance notice of a new Subprocessor when required. The Customer may object on reasonable data-protection grounds within 15 days. The parties will work in good faith on a commercially reasonable alternative; if none is available, either party may terminate the affected service without penalty for the unused prepaid period.

7. Data-subject requests

Taking into account the nature of processing, Ivorycom will provide reasonable assistance through appropriate technical and organizational measures so the Customer can respond to requests to access, correct, delete, restrict, object, or port Customer Personal Data. If Ivorycom receives a request relating to Customer-controlled data, we will direct the requester to the Customer and notify the Customer unless prohibited.

8. Government and third-party requests

Ivorycom will notify the Customer of a legally binding demand for Customer Personal Data unless prohibited, review demands for validity, challenge overbroad demands where reasonable, and disclose only what is legally required. Nothing requires Ivorycom to violate law or disclose confidential legal advice.

9. Personal data incidents

Ivorycom will notify the Customer without undue delay after confirming a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data (“Personal Data Incident”). Notice will include available information reasonably needed for the Customer’s legal obligations, and Ivorycom will provide updates as the investigation progresses.

Notice is not an admission of fault or liability. The Customer is responsible for deciding whether to notify regulators or individuals, with Ivorycom’s reasonable assistance. Ivorycom will take reasonable steps to contain, investigate, mitigate, and remediate the incident.

10. Compliance assistance

Considering the nature of processing and information available, Ivorycom will reasonably assist with security obligations, breach notifications, data-protection impact assessments, and prior consultations required by Applicable Data Protection Law. Additional work beyond standard service capabilities may be subject to reasonable fees agreed in advance unless the need resulted from Ivorycom’s breach.

11. Information and audits

Ivorycom will make available information reasonably necessary to demonstrate compliance with processor obligations, such as current security summaries, relevant independent reports, and questionnaire responses. No more than once annually, unless required by a regulator or following a material incident, the Customer may request a reasonable audit on advance notice.

Audits must minimize disruption, protect other customers and Ivorycom confidential information, and use an independent auditor bound by confidentiality. The Customer bears its audit cost unless the audit identifies a material Ivorycom breach.

12. Return and deletion

During the service term, available product features may allow the Customer to export Customer Personal Data. At termination or on lawful instruction, Ivorycom will delete or return Customer Personal Data and delete remaining copies within 30 days, unless law requires retention. Encrypted backups expire within 90 days under normal rotation and remain protected and unavailable for ordinary use.

13. International data transfers

Ivorycom will use a lawful transfer mechanism for restricted transfers. Where required and legally available, the parties incorporate the European Commission’s 2021 Standard Contractual Clauses (“EU SCCs”), using Module Two for controller-to-processor transfers or Module Three for processor-to-processor transfers as applicable. The docking clause applies; optional clauses and competent authority details must be completed in the executed DPA.

For restricted transfers governed by UK law, the parties incorporate the then-current UK International Data Transfer Addendum to the EU SCCs (“UK Addendum”) or another mechanism approved under UK law. Counsel must confirm whether SCCs are the correct mechanism where Ivorycom’s processing is directly subject to EU GDPR or UK GDPR.

14. Canada and United States terms

Where PIPEDA or substantially similar Canadian provincial law applies, Ivorycom will process personal information only for the contracted purposes, use appropriate safeguards, assist with access and correction, and provide information about processing outside Canada as required.

Where applicable US state law treats Ivorycom as a processor, service provider, or contractor, Ivorycom will not sell Customer Personal Data, share it for cross-context behavioral advertising, retain/use/disclose it outside the contracted business purposes, or combine it with unrelated personal information except as law permits.

15. Liability and duration

The service agreement’s liability provisions apply to this DPA except where mandatory law or incorporated transfer clauses require otherwise. This DPA remains effective while Ivorycom processes Customer Personal Data and survives termination for as long as retained data remains.

Annex I — Processing details

  • Subject matter: operating TightLedger’s business financial-recovery, evidence, approval, reporting, support, and security functions.
  • Duration: the service term plus the 30-day deletion period and up to 90-day encrypted backup rotation, subject to lawful retention.
  • Nature: collection, access, organization, analysis, classification, comparison, storage, retrieval, transmission on instruction, restriction, export, and deletion.
  • Purposes: provide the configured service, detect and verify possible financial leakage, support human approvals, confirm outcomes, secure accounts, and provide support.
  • Data subjects: Customer users; sole proprietors; employees and contractors; and people represented in connected business records, such as vendor, customer, payer, payee, and contact personnel.
  • Data categories: account and contact details, business roles, transaction and payment records, invoices, contracts, communications, files, evidence, approvals, audit events, device/security data, and derived findings.
  • Sensitive data: financial information and confidential business records. Special-category data is not intentionally required and must not be submitted without documented safeguards.
  • Frequency: continuous or event-driven according to Customer configuration.
  • Controller contact: the Customer contact identified in its account or order.
  • Processor contact: Ivorycom LLC, 5208 White Chicory Dr, Apollo Beach, FL 33572, United States; legal@tightledger.com; and privacy@tightledger.com.

Annex II — Technical and organizational measures

  • Identity and access management with role-based access, least privilege, strong authentication, and step-up controls for sensitive actions.
  • Encryption in transit; protected secret storage; encryption at rest where supported by the production platform.
  • Tenant-aware authorization and separate least-privilege service/database identities.
  • Structured audit trails for material actions, approvals, consent, and administrative access.
  • Secure software-development practices, automated testing, dependency scanning, code review, and controlled production releases.
  • Logging and monitoring designed to redact credentials, tokens, passwords, and sensitive request fields.
  • Backup, recovery, availability, incident-response, and business-continuity procedures proportionate to the service.
  • Vendor diligence and written data-protection obligations for subprocessors.
  • Data minimization, purpose limitation, documented retention, deletion workflows, and restricted support access.
  • Periodic review of risks and safeguards as the product and threat environment change.

Annex III — Subprocessors

The following service providers may process Customer Personal Data to support the production architecture. Ivorycom will maintain this schedule and provide notice of changes as described in Section 6.

  • Cloudflare — edge delivery, security, DNS, and frontend hosting.
  • Railway — backend application hosting, managed databases, cache infrastructure, and operational logs.
  • WorkOS — identity, authentication, organization, and single-sign-on services.
  • Upstash/QStash — asynchronous message delivery and signing infrastructure.
  • Postmark/Wildbit — transactional email delivery.
  • Sentry — application error monitoring only if enabled in the production environment.
  • Payment provider named in the applicable order or checkout — subscription and invoice payment processing.