LEGAL · DATA PROCESSING ADDENDUM

Data Processing Addendum

This Data Processing Addendum ("DPA") forms part of the agreement between BillRecon LLC("BillRecon", the processor) and the customer (the controller) for the BillRecon service. It governs the processing of personal data BillRecon performs on the customer's behalf. Last updated: June 26, 2026.

June 26, 2026last updated
BillRecon LLCoperator
This page reproduces our standard DPA for transparency. A countersigned copy is available on request. Email legal@billrecon.com.

Definitions

"Personal Data", "Controller", "Processor", "Processing", "Data Subject", and "Sub-processor" have the meanings given in applicable data-protection law (including the GDPR and, where relevant, the CCPA/CPRA). Capitalised terms not defined here have the meaning in the main agreement.

Scope & roles

The customer is the Controller and BillRecon is the Processor. BillRecon processes Personal Data only to provide the service (connecting to the customer's PSA and vendor systems, computing billing-reconciliation results, and producing corrections for the customer to act on), and only on the customer's documented instructions (this DPA and the agreement being such instructions).

Nature of processing & data categories

BillRecon processes business-account data: client records, subscription and seat counts, billed agreement lines, product SKUs, and the account-administrator identities used to sign in. BillRecon does not require or seek special-category data and asks that none be submitted.

Security measures

BillRecon maintains technical and organisational measures including:

  • Tenant isolation via PostgreSQL Row-Level Security, enabled and forced on every table.
  • Encryption in transit (TLS 1.2+) and envelope encryption (AES-256-GCM) of stored credentials, with a key-encryption key in a managed vault and rotation support.
  • Immediate destruction of connection credentials on disconnect.
  • Least-privilege, read-only vendor scopes where available, and an append-only audit log of privileged actions.
  • Point-in-time database recovery with tested restores.

Sub-processors

The customer authorises BillRecon to engage the sub-processors listed on our Trust & Security page. BillRecon imposes data-protection obligations on each sub-processor no less protective than this DPA, and will give notice before adding or replacing a sub-processor so the customer may object on reasonable data-protection grounds.

Data-subject rights & assistance

Taking into account the nature of the processing, BillRecon will assist the customer with data-subject requests (access, rectification, erasure, restriction, portability, objection) and with the customer's obligations on security, breach notification, and data-protection impact assessments.

Personal-data breach notification

BillRecon will notify the customer without undue delay after becoming aware of a Personal Data breach affecting the customer's data, and will provide information reasonably necessary for the customer to meet its own notification obligations.

Return & deletion

On termination, and on the customer's request, BillRecon will delete or return the customer's Personal Data. On account cancellation, connection credentials are purged immediately and remaining account data is deleted after a defined grace period, subject to any retention required by law. Deletion takes effect in BillRecon's live systems on that schedule; copies that persist in encrypted backups kept for disaster recovery are retained only until they age out of BillRecon's backup retention cycle, after which they become unrecoverable, and BillRecon restores from those backups solely to recover from an incident, not to revive deleted data.

International transfers

BillRecon processes Personal Data in the United States. Where this DPA covers a transfer of Personal Data subject to the GDPR, UK GDPR, or Swiss FADP from the EEA, the United Kingdom, or Switzerland to a country without an adequacy decision, the parties incorporate by reference the European Commission's Standard Contractual Clauses (Module Two, controller-to-processor), with BillRecon acting as data importer. Onward transfers to sub-processors are covered by the Standard Contractual Clauses (Module Three) between BillRecon and each sub-processor. For United Kingdom transfers, the UK International Data Transfer Addendum to those Clauses applies; for Swiss transfers, the Clauses apply with the adjustments the Swiss FDPIC requires.

Audits

BillRecon will make available information reasonably necessary to demonstrate compliance with this DPA, including its then-current security questionnaire and, when available, third-party attestations (e.g. SOC 2).

Governing law

This DPA is governed by the law of the State of Florida and is subject to the limitations of liability in the main agreement.

To request a countersigned copy, email legal@billrecon.com. This page reproduces our standard DPA for transparency.