Data Processing Addendum
For customers who require a DPA.
CashFlowIQ acts as a data processor for workspace data entered by customers (data controllers). Personal data is processed for the sole purpose of providing the Service and the contracted features. A signed Data Processing Addendum (DPA) is available on request — contact [email protected].
Sub-processors
- Cloud database provider (US/EU regions, encrypted at rest)
- Stripe (billing and customer portal)
- Transactional email provider (SMTP)
- AI provider (OpenAI-compatible) — used only on demand, only with the active tenant's data
Security measures
Tenant isolation, role-based access control, JWT authentication, audit logging, rate limiting, and Stripe webhook signature verification.