Data Processing Agreement

Last updated: July 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service between VendorRecon and any customer ("Customer") that uses the service to process personal data on behalf of its own clients or other individuals. It describes how we process that data on your instructions. If you need a countersigned copy for your records, email info@vendorrecon.org.

1. Roles

For personal data contained in the files you upload, you (the Customer) act as the data controller and VendorRecon acts as the data processor. VendorRecon processes that data only on your documented instructions, which include your use of the service and these Terms.

2. Scope and purpose

We process the data you upload (vendor statements, ledgers, and the results derived from them) for the sole purpose of providing the reconciliation service. We do not use it for any other purpose, do not sell it, and do not use it to train AI or machine-learning models.

3. Confidentiality

We keep your data confidential and ensure that anyone who processes it is bound by appropriate confidentiality obligations.

4. Security

We maintain technical and organisational measures appropriate to the risk, including encryption of uploaded files at rest (AES-256), encryption in transit (HTTPS/TLS), and access controls that isolate each customer's data through row-level security.

5. Sub-processors

You authorise us to engage the sub-processors listed on our Sub-processors page. Each is bound by data-protection obligations consistent with this DPA. We will update that page before adding a new sub-processor, and you may object to a change on reasonable data-protection grounds.

6. Data subject requests

Taking into account the nature of the processing, we will assist you, as far as reasonably possible, in responding to requests from individuals to exercise their rights (such as access, correction, or deletion). You can also delete your data directly at any time from your account settings.

7. Personal data breach

If we become aware of a breach affecting your personal data, we will notify you without undue delay and provide the information you reasonably need to meet your own notification obligations.

8. Return and deletion

You can permanently delete your files and results at any time from your account settings, which also removes the encrypted files from storage. On termination, or on your request, we will delete your data within a reasonable period unless we are required by law to retain it.

9. International transfers

Where personal data is transferred across borders, we rely on appropriate safeguards, such as the European Commission's Standard Contractual Clauses, where they apply.

10. Audit

On reasonable written request, we will provide the information reasonably necessary to demonstrate our compliance with this DPA.

11. Contact

For any data-protection question, or to request a signed DPA, email info@vendorrecon.org.

This page summarises our data-processing commitments in plain language. It is not legal advice. For a binding, signed agreement tailored to your requirements, contact us.