Data Processing Addendum
Last Updated: August 21, 2026 Version: 1.6
This Data Processing Addendum ("DPA") forms part of the Terms of Service between Incremenza LLC ("Incremenza," "Processor," "we," or "us") and the customer agreeing to those terms ("Customer," "Controller," or "you"). It governs our processing of personal data on your behalf.
This DPA applies where you are subject to the EU General Data Protection Regulation, the UK GDPR, the Swiss Federal Act on Data Protection, or another data protection law that requires a written processing agreement.
This DPA is incorporated into the Terms of Service by reference and takes effect automatically. No signature is required. If your organization requires a countersigned copy, write to [email protected] and we will provide one.
Where this DPA conflicts with the Terms of Service on a matter of personal data processing, this DPA controls.
1. Definitions
"Data Protection Law" means all laws applicable to the processing of Personal Data under this DPA, including the GDPR, the UK GDPR, the Swiss FADP, and applicable United States state privacy laws.
"Personal Data" means any information relating to an identified or identifiable natural person that is contained within Customer Data and processed by Incremenza on your behalf.
"Processing," "Controller," "Processor," "Data Subject," and "Personal Data Breach" have the meanings given in the GDPR.
"Standard Contractual Clauses" or "SCCs" means the clauses annexed to European Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
"Sub-processor" means a third party engaged by Incremenza to process Personal Data on your behalf.
"UK Addendum" means the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018.
Terms not defined here have the meaning given in the Terms of Service.
2. Roles of the parties
You are the Controller. You determine the purposes and means of processing Personal Data contained in Customer Data.
Incremenza is the Processor. We process that Personal Data on your behalf.
Where you are yourself a processor acting for another controller, you warrant that you have the authority of that controller to appoint us as a sub-processor on these terms, and references to "Controller" apply accordingly.
This DPA does not apply to personal data for which Incremenza is the controller, such as your account details, your team's contact information, your billing records, and information about how your organization uses the Service. That processing is governed by our Privacy Policy.
3. Processing of Personal Data
3.1 Scope and instructions
We process Personal Data only:
- On your documented instructions, including as set out in this DPA, the Terms of Service, and your configuration and use of the Service
- As necessary to provide, secure, and support the Service
- As required by law applicable to us, in which case we will inform you of that requirement before processing unless the law prohibits it on important grounds of public interest
Your use of the Service, including the settings you choose, the integrations you connect, and the automations you configure, constitutes your documented instructions.
3.2 If an instruction appears unlawful
If we believe an instruction from you infringes Data Protection Law, we will inform you without undue delay. We may suspend performance of that instruction until it is amended, confirmed, or withdrawn.
3.3 No independent use
We will not sell Personal Data, retain it for any purpose other than performing the Service, use it for our own commercial purposes, or use it to train machine learning models. We will not combine it with data from other sources except as necessary to provide the Service to you.
3.4 Aggregated and anonymized data
We may create aggregated and anonymized data from Personal Data and use it to operate, analyze, and improve the Service and to produce benchmarks and statistics. Such data is irreversibly anonymized so that no Data Subject, customer, or organization can be identified or re-identified, and once anonymized it is no longer Personal Data.
3.5 Details of processing
The subject matter, duration, nature and purpose of processing, categories of Personal Data, and categories of Data Subjects are set out in Annex I.
4. Confidentiality
We ensure that every person authorized to process Personal Data is bound by an appropriate obligation of confidentiality, whether contractual or statutory, and receives training on their data protection responsibilities.
Access to Personal Data is limited to personnel who require it to perform their role. Access is logged.
5. Security
We implement and maintain the technical and organizational measures set out in Annex II, designed to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing.
We regularly review and, where appropriate, improve those measures. We will not make a change that materially reduces the overall level of security.
6. Sub-processors
6.1 General authorization
You give general authorization for Incremenza to engage Sub-processors, subject to this Section.
6.2 Current list
The current list of Sub-processors, including the processing each carries out and its location, is published at incremenza.com/legal/sub-processors.
6.3 Notice of changes
We will give at least 30 days' notice before a new Sub-processor begins processing Personal Data. Notice is given by email to account administrators and by updating the published list.
In an emergency, such as the sudden failure of an existing provider, we may engage a replacement without advance notice and will inform you as soon as reasonably possible afterward.
6.4 Objection
You may object to a new Sub-processor on reasonable data protection grounds by writing to [email protected] within the notice period. We will work with you in good faith to address the objection, which may include offering an alternative arrangement.
If we cannot resolve the objection within 30 days, you may terminate the affected subscription on written notice and receive a refund of prepaid fees for the unused portion of your term. This is your sole remedy.
6.5 Our responsibility
We enter into a written agreement with each Sub-processor imposing data protection obligations no less protective than those in this DPA. We remain fully liable to you for the performance of each Sub-processor's obligations.
7. Assistance with Data Subject requests
The Service provides functionality allowing you to access, correct, export, and delete Personal Data yourself. In most cases this is sufficient to respond to a Data Subject request without our involvement.
Where it is not, we will provide reasonable assistance, taking into account the nature of the processing, to help you fulfil your obligations under Chapter III of the GDPR.
If a Data Subject contacts us directly about Personal Data we process on your behalf, we will not respond substantively. We will promptly inform the Data Subject to contact you, and notify you of the request.
Assistance under this Section is provided at no additional cost unless a request is manifestly excessive or requires substantial engineering effort, in which case we will agree a reasonable fee with you in advance.
8. Personal Data Breach
We will notify you without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data Breach affecting Personal Data we process on your behalf. This gives you time to meet your own 72-hour obligation under Article 33.
Our notification will describe, to the extent known:
- The nature of the breach, including the categories and approximate number of Data Subjects and records concerned
- The likely consequences
- The measures taken or proposed to address it and mitigate its effects
- A contact point for further information
We will provide further information as it becomes available, and will reasonably assist you in meeting your notification obligations to supervisory authorities and Data Subjects.
Our notification is not an acknowledgement of fault or liability.
9. Data Protection Impact Assessments
We will provide reasonable assistance with any data protection impact assessment or prior consultation with a supervisory authority that you are required to carry out under Articles 35 and 36, to the extent the assistance relates to our processing and the information is not otherwise available to you, including through our Security page and the annexes to this DPA.
10. Audit and information rights
We will make available all information reasonably necessary to demonstrate compliance with this DPA and with Article 28.
In the first instance, you may satisfy audit rights by reviewing our published documentation, the annexes to this DPA, and any third-party certification or audit report we hold, and by submitting reasonable written questions to [email protected]. We will respond within 30 days.
Where that is insufficient, you may conduct an audit no more than once in any 12-month period, on at least 30 days' written notice, during business hours, without unreasonable disruption to our operations, and subject to confidentiality obligations. You bear your own costs and ours where the audit requires substantial effort.
More frequent audits are permitted where required by a supervisory authority, or following a confirmed Personal Data Breach affecting your Personal Data.
Auditors must not be a competitor of Incremenza, and must sign a confidentiality agreement before receiving access.
11. International transfers
11.1 Transfers from the EEA
Where processing under this DPA involves a transfer of Personal Data from the European Economic Area to a country not covered by an adequacy decision, the Standard Contractual Clauses apply and are incorporated into this DPA by reference, with:
- Module Two (Controller to Processor) applying where you are a controller
- Module Three (Processor to Processor) applying where you are a processor acting for another controller
- Clause 7 (docking clause): included
- Clause 9 (sub-processors): Option 2, general written authorization, with the notice period set at 30 days as provided in Section 6.3
- Clause 11 (redress): the optional independent dispute resolution language is not included
- Clause 17 (governing law): the law of Ireland
- Clause 18 (forum and jurisdiction): the courts of Ireland
- Annex I and Annex II of the SCCs: as set out in the Annexes to this DPA
- Annex III of the SCCs: the sub-processor list published at incremenza.com/legal/sub-processors
11.2 Transfers from the United Kingdom
Where Personal Data is transferred from the United Kingdom, the UK Addendum applies to the SCCs, with Tables 1 to 3 completed by reference to the Annexes to this DPA, and Table 4 selecting "neither party" as able to end the addendum under Section 19.
11.3 Transfers from Switzerland
Where Personal Data is transferred from Switzerland, the SCCs apply with references to the GDPR read as references to the Swiss FADP, references to EU member state law read as references to Swiss law, the competent supervisory authority being the Swiss Federal Data Protection and Information Commissioner, and the term "member state" not preventing Data Subjects in Switzerland from bringing proceedings in their place of habitual residence.
11.4 Government access requests
If we receive a legally binding request from a public authority for Personal Data we process on your behalf, we will:
- Notify you promptly, unless legally prohibited from doing so
- Where prohibited, use reasonable efforts to obtain a waiver of that prohibition
- Challenge the request where we consider there are reasonable grounds to believe it is unlawful
- Disclose only the minimum amount of data reasonably required
We maintain records of such requests and will make them available to you on request, to the extent permitted by law.
11.5 Alternative mechanisms
If the SCCs are invalidated, superseded, or replaced, we will work with you in good faith to adopt an alternative lawful transfer mechanism within a reasonable period.
12. Deletion and return
If you close your own Account, we automatically return a copy of Personal Data in a structured, commonly used, machine-readable format, by email to the Admin who closed the Account, with a 30-day download window and no written request required.
For any other termination, and on your written request within 30 days of termination, we will return a copy of Personal Data in the same format, or provide access sufficient for you to export it yourself.
After that period, we delete Personal Data in accordance with the retention schedule published in our Privacy Policy. Deletion of business data occurs automatically 90 days after account closure or subscription end.
We retain limited data after deletion where required by law, specifically billing, subscription, and tax records for the period required by applicable financial record-keeping law.
We also retain a record of email suppressions, limited to the email address, the reason, and the date. This is retained because deleting it would allow a person who previously objected to receiving email to be contacted again if their record is later re-imported. This is processing necessary to honor a prior objection under Article 21 and is limited to the minimum data required for that purpose.
Personal Data held in backups is deleted or overwritten within 90 days of the primary deletion. Until then it remains subject to the security measures in Annex II and is not processed for any purpose.
You may request earlier deletion by writing to [email protected]. We complete such requests within 30 days.
13. Liability
Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service. Nothing in this DPA limits either party's liability to a Data Subject under Article 82 of the GDPR.
14. Term
This DPA takes effect when you accept the Terms of Service and continues until we no longer process Personal Data on your behalf. Provisions that by their nature should survive termination will do so.
15. Changes to this DPA
We may update this DPA where necessary to reflect changes in Data Protection Law, in the SCCs or equivalent transfer mechanisms, in our processing activities, or in guidance from supervisory authorities.
We will give at least 30 days' notice of a material change by email to account administrators. No change will materially reduce the protections afforded to Personal Data.
16. Contact
Incremenza LLC
2108 N ST STE N Sacramento, CA 95816 United States
Annex I: Description of Processing
A. List of parties
Data exporter (Controller): The Incremenza customer that has accepted the Terms of Service. Contact details are those associated with the customer's account. Activities relevant to the transfer: use of the Incremenza platform to manage business finances, customers, and operations. Role: Controller (or Processor, where acting for another controller).
Data importer (Processor): Incremenza LLC, 2108 N ST STE N, Sacramento, CA 95816, United States. Contact: [email protected]. Activities relevant to the transfer: provision of the Incremenza software as a service platform. Role: Processor.
B. Description of transfer
Categories of Data Subjects:
- The Customer's own customers and clients
- The Customer's employees, contractors, and team members who use the Service
- The Customer's vendors, suppliers, and business contacts
- Individuals identified within transaction records imported from connected financial systems
Categories of Personal Data:
- Identity data: name, job title, role
- Contact data: email address, telephone number, business address
- Financial and transaction data: transaction descriptions, amounts, dates, merchant names, invoice and payment records, subscription records, masked account identifiers, payment method last four digits
- Account and relationship data: customer notes, health scores, activity history, communication history, support records
- Employment and team data: team assignment, reporting line, role, objectives and progress records
- Technical data: IP address, browser and device information, authentication and session records, product usage events
Sensitive data: None. The Service is not designed to process special categories of personal data under Article 9, or personal data relating to criminal convictions and offences under Article 10. You must not submit such data to the Service.
Frequency of transfer: Continuous, for the duration of the subscription.
Nature of the processing: Collection, recording, organization, structuring, storage, retrieval, consultation, use, analysis, categorization, aggregation, transmission, and erasure, all for the purpose of providing the Service.
Purpose of the processing: To provide the Incremenza platform, including financial reporting and analysis, transaction categorization and reconciliation, customer relationship and health tracking, objective and initiative tracking, invoicing and payment processing, automated workflows, and email sent on the Customer's behalf.
Duration of processing: For the duration of the subscription, plus the retention periods set out in Section 12 and in the Privacy Policy.
Sub-processor transfers: As published at incremenza.com/legal/sub-processors, for the purposes and durations stated there.
C. Competent supervisory authority
The supervisory authority of the EEA member state in which the data exporter is established. Where the exporter is not established in the EEA but falls within the scope of the GDPR under Article 3(2), the supervisory authority of the member state in which the exporter's Article 27 representative is established.
Annex II: Technical and Organizational Measures
Incremenza maintains the following measures. Our Security page describes them in further detail.
1. Encryption
- All data in transit is encrypted using TLS 1.2 or higher. Unencrypted connections are refused.
- The production database is encrypted at rest, hosted on a managed database cluster with disk-level encryption enabled by default.
- Integration access and refresh tokens are encrypted at rest using AES-256.
- Passwords are hashed using bcrypt with a work factor of 12. Passwords are never stored in a recoverable form.
- Automated daily backups are encrypted at rest, with point-in-time recovery available for the preceding 7 days.
- Payment card data is never stored by Incremenza. It is tokenized and held by Stripe, a PCI DSS Level 1 certified processor.
2. Access control and identity
- Multi-factor authentication is required for administrators and managers, using phishing-resistant methods (a passkey), enforced before any access to the application, with no remembered-device exception. Multi-factor authentication is required for all other users, using either a passkey or an authenticator app. Administrators can reset a team member's MFA credentials, requiring the administrator to re-verify their own identity. Credentials, trusted devices, and sessions are removed when an account is closed.
- Role-based access control with three tiers, granting the minimum permissions necessary for each role.
- Session tracking with the ability to revoke individual sessions, and forced logout when a user is removed.
- Account lockout after repeated failed authentication attempts.
- Alerts to the account owner on sign-in from a new country, and on passkey registration or removal.
- Secure session cookies with httpOnly and same-site policies.
3. Tenant isolation
- Each customer organization's data is isolated by a mandatory database-level scope applied automatically to every query.
- Every request is authorized against the requesting user's organization before any data is returned.
- Isolation is verified by automated tests that run continuously.
4. Infrastructure security
- Application servers and databases are hosted in private networks with no public database access.
- The production database runs on a dedicated managed cluster, reachable only over a private network from application servers.
- Infrastructure credentials can be rotated on demand; a routine rotation schedule is being formalized.
- An additional, independently stored backup is maintained through a separate provider for redundancy, alongside the primary encrypted backups described in Section 1.
5. Application security
- Server-side validation of all input.
- Parameterized queries and an object relational mapper, preventing SQL injection.
- Automatic output escaping, preventing cross-site scripting.
- Cross-site request forgery tokens required on all state-changing requests.
- Cryptographic signature verification on all incoming webhooks.
- Automated dependency scanning for known vulnerabilities, governed by a documented vulnerability management policy with defined patch timelines by severity.
6. Monitoring and logging
- Continuous application error and performance monitoring.
- Automatic redaction of tokens, credentials, and payment data before any log or error report is transmitted.
- Audit logging of authentication events and integration disconnections, retained for two years.
- Failed authentication attempts are logged and monitored on an ongoing basis.
- All staff access to a customer account is logged with the staff member's identity, the account, and the time and duration.
7. Personnel
- Confidentiality obligations for all personnel with access to Personal Data.
- Background checks conducted for employees and contractors granted access to customer data, before access is granted.
- Access limited to what each person's role requires, and all access to production systems is logged.
8. Data minimization
- Personal details are removed from merchant names before any transmission to third-party machine learning providers.
- Only aggregated financial summaries, not individual records, are sent for insight generation.
- Account numbers, card numbers, and credentials are never transmitted to third-party providers.
- Internal matching resolves most transaction categorization, reducing external transmission.
9. Business continuity
- Automated, encrypted daily backups with point-in-time recovery for the preceding 7 days, as described in Section 1.
- A documented incident response procedure covering detection, containment, eradication, recovery, and post-incident review, with defined notification timelines.
10. Sub-processor governance
- Written data processing agreements with every Sub-processor.
- Evaluation of each Sub-processor's security posture before engagement.
- A published, maintained Sub-processor list with 30 days' advance notice of changes.
Annex III: Sub-processors
The current list of authorized Sub-processors is published and maintained at:
incremenza.com/legal/sub-processors
That page states, for each Sub-processor, its name, the processing it carries out, the categories of data it handles, its location, and the applicable transfer mechanism. It is updated before any change takes effect, with the notice period set out in Section 6.3.