Legal
Data Processing Addendum
Last updated: 7 July 2026
This addendum (the “DPA”) governs how we process the personal data of your clients on your behalf when you use UntilPaid. It forms part of the Terms of Service and reflects Article 28 of the GDPR (and the UK GDPR) and the Czech Act No. 110/2019 Coll. If there’s a conflict on data-protection matters, this DPA wins.
1. Roles & scope
You are the controller of the Client Personal Data and we are your processor. You’re responsible for making sure you have a lawful basis to collect that data and to have us process it, and for giving your clients any privacy notice the law requires. We process it only to provide the service, as set out in Annex A.
2. Our instructions
We process Client Personal Data only on your documented instructions — which include your use of the service’s settings (your rules, templates, schedule, and the webhook endpoints you configure), this DPA, and the Terms. We won’t process it for our own purposes. If we believe an instruction breaks data-protection law, we’ll tell you. If the law requires us to process data beyond your instructions, we’ll let you know first, unless the law forbids it.
3. Confidentiality
We make sure the people who process Client Personal Data are bound by confidentiality and only access what they need to do their job.
4. Security
We put in place appropriate technical and organisational measures to protect Client Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access, taking into account the state of the art, the costs, and the risk. Those measures are described in Annex B, and we may update them provided protection isn’t reduced.
5. Sub-processors
You give us general authorisation to use sub-processors to help provide the service. The current list is in Annex C. When we engage a sub-processor we impose data-protection obligations on it that are no less protective than those in this DPA, and we remain responsible for its performance.
If we plan to add or replace a sub-processor, we’ll give you reasonable notice (by updating Annex C and/or emailing you). If you have a reasonable, data-protection-based objection, tell us within 30 days and we’ll work with you in good faith — which may mean adjusting the service or, if we can’t resolve it, letting you terminate the affected part.
6. Helping you comply
Taking into account the nature of the processing, we’ll help you:
- respond to requests from data subjects exercising their rights (access, correction, erasure, and so on) — the service also lets you edit or delete this data directly, and you can permanently delete everything by disconnecting Stripe;
- meet your own security, breach-notification, and data-protection-impact-assessment duties; and
- demonstrate compliance with your obligations as controller.
7. Breach notification
If we become aware of a personal-data breach affecting Client Personal Data, we’ll notify you without undue delay and give you the information you reasonably need to meet your own notification duties. We’ll also take reasonable steps to contain and remedy it.
8. International transfers
Where providing the service involves transferring Client Personal Data outside the EEA or UK, we rely on a valid transfer mechanism — normally the European Commission’s Standard Contractual Clauses together with the UK International Data Transfer Addendum, which are incorporated into this DPA by reference where they apply.
9. Audits
We’ll make available the information reasonably needed to show we’re meeting this DPA, and allow for audits — including inspections — by you or an auditor you appoint. To keep things practical and protect other customers, audits happen on reasonable notice, no more than once a year (unless a regulator or a breach requires otherwise), during business hours, and subject to confidentiality. Where available, we may satisfy an audit request by providing a recent third-party report.
10. Return & deletion
When you stop using the service, or on your request, we delete Client Personal Data. Disconnecting Stripe from your settings triggers deletion of your data, including the data we processed on your behalf, except where we’re required by law to keep a copy or where it remains briefly in routine backups before they rotate out.
11. Liability
Each party’s liability under this DPA is subject to the limitations and exclusions in the Terms of Service.
Annex A — Details of processing
| Subject matter | Automated follow-up on the Customer’s overdue Stripe invoices. |
|---|---|
| Duration | For as long as the Customer uses the service, then deletion per section 10. |
| Nature & purpose | Reading invoice and customer data from Stripe; sending reminder emails and SMS; maintaining a suppression list of opt-outs, bounces, and complaints; and, where configured, sending a signed webhook to the Customer’s endpoint to restrict client access. |
| Categories of data subjects | The Customer’s clients — the individuals and business contacts named on the invoices being chased. |
| Types of personal data | Names; email addresses; phone numbers; invoice details (numbers, amounts, due dates, status); and delivery/opt-out records. No special-category data is intended to be processed. |
| Frequency | Continuous, on an automated schedule set by the Customer, plus a periodic reconciliation with Stripe. |
Annex B — Security measures
- Encryption in transit — all traffic served over HTTPS/TLS.
- Encryption at rest — sensitive secrets (such as connection tokens and provider credentials) are encrypted with authenticated encryption before storage.
- Authentication & session security — signed, http-only session cookies; origin checks and anti-forgery tokens on state-changing requests.
- Signed outbound webhooks — access-revocation webhooks are HMAC-signed so the receiving endpoint can verify authenticity.
- Access control — least-privilege access to production systems, limited to personnel who need it.
- Tenant isolation — each customer’s data is scoped to their account and not accessible to others.
- Rate limiting & abuse protection on the public interfaces.
- Logging & monitoring to detect and investigate issues, with an internal process for handling incidents.
Annex C — Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Stripe | Source of invoice/customer data (via Stripe Connect) | Ireland (Stripe Technology Europe) / United States — EU–U.S. Data Privacy Framework & SCCs |
| Postmark (ActiveCampaign, LLC) | Transactional email delivery & bounce handling | United States — EU–U.S. Data Privacy Framework & SCCs |
| Twilio Inc. | SMS delivery & opt-out handling | United States — EU–U.S. Data Privacy Framework & SCCs |
| Railway Corp. | Application hosting, database, job queue | United States [or EU — confirm the deploy region in the Railway dashboard] — SCCs |
| PostHog, Inc. | Product analytics & error reporting (identifiers such as email addresses and phone numbers are redacted before transmission) | EU Cloud — hosted in Frankfurt, Germany (provider is US-incorporated; SCCs as fallback safeguard) |