Skip to content

Data Processing Addendum

This Data Processing Addendum (DPA) supplements our Terms of Service and sets out our contractual commitments under GDPR Article 28, UK GDPR, and international data protection laws.

Last revised: September 2026•Version: 1.0

1. Scope and Pre-Signed Status

This Data Processing Addendum ("DPA") enters into force automatically upon your creation of a BillingMart workspace or execution of a Master Services Agreement. It applies to the extent that BillingMart processes Customer Personal Data subject to Applicable Data Protection Laws on your behalf.

Pre-Signed and In Force

To simplify vendor onboarding for our business customers, this DPA is pre-signed by BillingMart and binds both parties upon account creation. A countersigned PDF copy for your compliance files can be requested at any time by emailing legal@billingmart.com.

2. Definitions

  • "Applicable Data Protection Laws" means all global privacy laws applicable to the processing of personal data, including the EU GDPR, UK GDPR, Swiss FADP, and US state privacy laws (such as the California CCPA/CPRA).
  • "Customer Personal Data" means any personal data processed by BillingMart on behalf of Customer in the provision of the platform services.
  • "Controller" and "Processor" have the meanings given under the GDPR. Customer acts as Controller; BillingMart acts as Processor.
  • "Standard Contractual Clauses" (SCCs) means the standard contractual clauses approved by the European Commission for the transfer of personal data to third countries.

3. Scope and Nature of Processing

The subject matter, nature, duration, and purpose of data processing are defined as follows:

  • Subject Matter: The provision of cloud-based invoicing, estimates, payment link delivery, and account ledger management.
  • Duration: The duration of your active subscription, plus the 30-day workspace deactivation and purge window.
  • Categories of Data Subjects: Customer’s employees, contractors, clients, debtors, and billing contacts.
  • Types of Personal Data: Names, business addresses, verified contact email addresses, telephone numbers, invoice line item descriptions, and transaction timestamps.

4. Customer and Processor Obligations

Customer warrants that it has established a lawful basis under Applicable Data Protection Laws for providing Customer Personal Data to BillingMart.

BillingMart shall process Customer Personal Data exclusively in accordance with Customer’s documented lawful instructions, as set forth in the Terms of Service and this DPA, and shall not sell, retain, or disclose Customer Personal Data for any other purpose.

5. Technical and Organizational Measures

BillingMart implements and maintains rigorous technical, physical, and administrative safeguards designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, or unauthorized disclosure:

  • Encryption: Data in transit is encrypted using modern TLS 1.3 protocols. Database records and sensitive merchant gateway credentials are encrypted at rest using AES-256-GCM.
  • Zero Cardholder Invariant: Raw credit card PAN and CVV values are never stored on disk or in persistent databases, conforming to PCI DSS SAQ-D architecture.
  • Cross-Tenant Leak Protection: Multi-tenant isolation is enforced at the database rules layer, verified continuously by automated cross-tenant security test suites.
  • Access Governance: Least-privilege role-based access controls (RBAC), mandatory two-factor authentication for administrative functions, and immutable audit logging.

6. Subprocessors and Prior Notice

Customer grants general authorization for BillingMart to engage subprocessors to support the delivery of the service.

Our current authorized subprocessors are published on our Subprocessors Page. We obligate each subprocessor by written agreement to data protection standards no less stringent than those set out in this DPA.

BillingMart will provide at least 30 days’ advance notice before adding or replacing any subprocessor, allowing Customer a reasonable opportunity to object on documented data protection grounds.

7. Assistance with Data Subject Requests

Taking into account the nature of the processing, BillingMart provides Customer with self-service tools in the console and client portal to fulfill data subject requests (such as data export, profile rectification, and account closure).

If a data subject submits a request directly to BillingMart, we will promptly notify Customer without responding directly, unless legally required to do so.

8. Personal Data Breach Notification

BillingMart will notify Customer without undue delay (and in any event within 48 hours) upon confirming any actual Personal Data Breach affecting Customer Personal Data.

The notification shall describe the nature of the incident, the categories and approximate number of data subjects affected, the likely consequences, and the mitigation measures taken or proposed.

9. International Data Transfers and SCCs

Where the transfer of Customer Personal Data from the European Economic Area (EEA), United Kingdom, or Switzerland to a third country requires an adequacy mechanism, the parties hereby incorporate the European Commission’s Standard Contractual Clauses (Module Two: Controller-to-Processor) by reference.

10. Termination, Return, and 30-Day Purge

Upon termination of the service, Customer may export all Customer Personal Data using our standard REST v1 API or console export tools.

Following workspace termination, all Customer Personal Data enters a 30-day deactivation cycle, after which it is permanently purged from production databases, save for historical invoices and ledger records required to be retained under statutory financial laws.

11. Audits and Compliance Records

BillingMart makes available all information reasonably necessary to demonstrate compliance with Article 28 of the GDPR and allows for and contributes to audits conducted by Customer or an independent auditor agreed upon by the parties.

Legal and compliance questions

If you have questions regarding this agreement, or need a countersigned copy of our Data Processing Addendum, contact us at legal@billingmart.com or write to our privacy officer at privacy@billingmart.com.

We use Google Analytics to see which pages are worth keeping. Nothing is measured until you say yes, and nothing here identifies you personally. Cookie policy