DATA PROCESSING AGREEMENT

Last Updated: August 2026

PREAMBLE

This Data Processing Agreement ("DPA") is entered into between Scott's Add-Ins, LLC ("Processor", "we", "us", or "our") and the customer or user ("Controller", "Customer", "you", or "your") who is using Scott's Add-Ins services.

This DPA applies to the processing of personal data in connection with the use of Scott's Add-Ins products and services (the "Services"). It incorporates data protection obligations required by the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and other applicable data protection laws.

1. DEFINITIONS

"Personal Data" means any information relating to an identified or identifiable natural person, as defined under applicable data protection laws.

"Processing" means any operation performed on Personal Data, including collection, recording, organization, structuring, storage, adaptation, retrieval, use, disclosure, erasure, or destruction.

"Data Subject" means any individual to whom Personal Data relates.

"GDPR" means the General Data Protection Regulation (EU) 2016/679.

"CCPA" means the California Consumer Privacy Act (Cal. Civ. Code § 1798.100 et seq.).

2. ROLES AND RESPONSIBILITIES

2.1 DATA CONTROLLER

You (the Customer) act as the Data Controller with respect to Personal Data processed through the Services. You are responsible for:

●      Determining the purposes and means of Processing

●      Ensuring lawful basis for Processing exists

●      Providing required privacy notices to Data Subjects

●      Obtaining necessary consents where required

●      Responding to Data Subject access requests

●      Ensuring compliance with data protection laws

2.2 DATA PROCESSOR

Scott's Add-Ins acts as the Data Processor. We Process Personal Data only on your behalf and in accordance with your documented instructions. We do not determine the purposes or means of Processing.

3. SCOPE OF PROCESSING

3.1 CATEGORIES OF DATA

The Services may process the following categories of Personal Data:

●      Contact information (name, email, phone)

●      Account credentials and authentication data

●      Company/organizational information

●      Financial information from integrated platforms (Xero, etc.)

●      Usage and log data

●      IP addresses and device information

3.2 CATEGORIES OF DATA SUBJECTS

Data Subjects include your employees, contractors, customers, and other individuals whose data is processed through the Services.

3.3 DURATION OF PROCESSING

Processing will continue for the duration of your use of the Services and for such period as necessary to comply with legal obligations.

4. PROCESSOR OBLIGATIONS

4.1 PROCESSING INSTRUCTIONS

We will Process Personal Data only in accordance with your documented written instructions. If we receive a Processing instruction that we believe violates data protection laws, we will inform you promptly.

4.2 CONFIDENTIALITY

All personnel who have access to Personal Data are bound by confidentiality obligations either by contract or by law.

4.3 SUB-PROCESSORS

We use authorized sub-processors to assist in providing the Services. Currently, Amazon Web Services is the only sub-processor we use.

4.4 DATA SUBJECT RIGHTS

We will, to the extent reasonably possible, assist you in fulfilling Data Subject rights requests, including rights of access, rectification, erasure, restriction, portability, and objection.

4.5 SECURITY MEASURES

We implement and maintain appropriate technical and organizational security measures to protect Personal Data. These are described in detail in our Security and Data Protection Policy document.

5. SECURITY AND CONFIDENTIALITY

5.1 We implement industry-standard security measures including:

●      Encryption of data in transit (TLS/SSL)

●      Encryption of data at rest

●      Access controls and authentication mechanisms

●      Regular security audits and testing

●      Incident response procedures

●      Employee security training and awareness

5.2 While we maintain appropriate safeguards, no transmission over the internet or electronic storage is completely secure. We cannot guarantee absolute security of Personal Data.

6. INTERNATIONAL DATA TRANSFERS

If we transfer Personal Data outside your country or region, we will implement appropriate safeguards in accordance with applicable law. This may include Standard Contractual Clauses (SCCs) or other approved transfer mechanisms.

7. DATA RETENTION AND DELETION

We retain Personal Data only for so long as necessary to provide the Services or as required by law. Upon termination of your account or your request, we will delete Personal Data within 30 days, except where legal obligations require retention.

8. AUDIT RIGHTS

You have the right to audit our Processing activities to verify compliance with this DPA. We will cooperate with reasonable audit requests and provide evidence of compliance. We may charge reasonable fees for extensive audits.

9. BREACH NOTIFICATION

If we become aware of a Personal Data breach, we will notify you without undue delay and provide details necessary for you to meet regulatory notification requirements.

10. DATA PROTECTION IMPACT ASSESSMENT

We will assist you in conducting Data Protection Impact Assessments (DPIAs) and provide any necessary information regarding our Processing activities.

11. CONTROLLER OBLIGATIONS

You agree to:

●      Provide lawful instructions for Processing

●      Ensure you have lawful basis to transfer data to us

●      Indemnify us against claims related to your data or instructions

●      Comply with data protection laws regarding data subjects

 

12. GOVERNING LAW

This DPA shall be governed by the laws of the State of Ohio, except that matters arising under the GDPR shall be governed by GDPR. You consent to the jurisdiction of courts in Hamilton County, Ohio.

13. TERM AND TERMINATION

This DPA continues for the duration of your use of the Services. Upon termination, we will delete or return Personal Data as instructed by you, except where required to retain by law.

14. ENTIRE AGREEMENT

This DPA, together with our Terms and Conditions and Privacy Policy, constitutes the entire agreement regarding data processing.

15. CONTACT INFORMATION

For questions regarding this DPA or data processing practices, contact:

Scott's Add-Ins, LLC Email: help@scottsaddins.com Website: www.scottsaddins.com

IMPORTANT DISCLAIMER

This DPA has been prepared as a comprehensive framework for your business. We strongly recommend that you have this DPA reviewed by qualified legal counsel, particularly in jurisdictions where you operate, as data protection laws vary significantly by location. This document should be customized based on your specific business model and applicable regulations. Scott's Add-Ins provides this template for informational purposes and disclaims liability for any consequences arising from its use.