PayoutChecker← Back to PayoutChecker
Business privacy

Data Processing Addendum

Effective date: September 12, 2026 · Draft V4
Pre-launch legal draft. This text is a product-ready starting point, not legal advice. U.S. counsel should review governing law, liability, privacy-law applicability, tax and cross-border terms before public launch.
B2B draft. This Data Processing Addendum (“DPA”) is intended for accounting firms, white-label partners, restaurant groups and other customers that require processor/service-provider terms. Counsel must finalize it before signature.

1. Parties and scope

This DPA supplements the agreement between the customer (“Customer”) and the PayoutChecker contracting entity (“PayoutChecker”) where PayoutChecker processes personal data on Customer’s behalf in providing the Service.

2. Roles

Customer determines the purposes and means of the underlying restaurant/client data processing and acts as controller/business where applicable. PayoutChecker acts as processor/service provider for Customer Data processed solely to provide, secure, support and improve the contracted Service as permitted by the agreement.

3. Processing details

4. Instructions

PayoutChecker will process Customer Data only on documented instructions in the agreement and Customer’s use/configuration of the Service, unless law requires otherwise.

5. Confidentiality and personnel

PayoutChecker will require authorized personnel with access to Customer Data to be subject to confidentiality obligations and access controls appropriate to their role.

6. Security

PayoutChecker will maintain reasonable technical and organizational safeguards designed to protect Customer Data, including tenant authorization, controlled storage, encrypted transport, logging and access restriction. A detailed security exhibit may be added for enterprise contracts.

7. Subprocessors

Customer authorizes PayoutChecker to use subprocessors necessary to provide the Service. PayoutChecker will maintain a current subprocessor list and impose appropriate data-protection obligations. Enterprise Order Forms may define a notification/objection process.

8. Rights requests

Taking into account the nature of processing, PayoutChecker will reasonably assist Customer with legally required data-subject/consumer requests relating to Customer Data.

9. Security incidents

PayoutChecker will notify Customer without undue delay after confirming a security incident involving Customer Data where notice is required by the agreement/law and will provide reasonably available information for Customer’s response.

10. Deletion/return

At termination or Customer request, PayoutChecker will delete or return Customer Data in accordance with product retention controls, backups and legal requirements. Backup copies may persist for a limited cycle and remain protected.

11. Audits/information

PayoutChecker will make reasonable compliance information available. Audit rights for larger customers should be defined in an Order Form and structured to protect other customers, security and confidentiality.

12. Cross-border processing

If applicable law requires a transfer mechanism for cross-border processing, the parties will implement the legally required mechanism in an Order Form/addendum. Production hosting and subprocessor locations must be documented accurately.

13. Conflicts

If this DPA conflicts with the main agreement on processing of Customer Data, the DPA controls to the extent of that conflict.