Data Processing Addendum
Effective July 19, 2026
This Data Processing Addendum ("DPA") forms part of the agreement between CashLinx ("CashLinx", "we", "us") and a practice that uses the CashLinx platform (the "Service") as our customer (the "Practice"). It describes how CashLinx processes personal data on the Practice's behalf. Where this DPA conflicts with the Terms of Service, this DPA controls for matters of data processing.
Roles of the parties
For personal data contained in a client's financial and business information processed through the Service, the Practice (or its client, as the case may be) is the controller and CashLinx is the processor. CashLinx processes that data only on documented instructions from the Practice, including as set out in the agreement and this DPA, unless required to do otherwise by law.
Scope and purpose of processing
- Subject matter: provision of the Service to the Practice and its clients.
- Duration: the term of the agreement, plus any period during which data is retained under the Privacy Policy.
- Nature and purpose: connecting to a client's accounting and, where enabled, banking systems, mirroring that data, rendering financials, running the client and CPA review loop, and billing for services.
- Categories of data: account and contact details of practice staff and portal users, and client financial and banking records processed on the Practice's behalf.
- Data subjects: practice staff, client-portal users, and individuals referenced in a client's financial records.
Confidentiality
CashLinx ensures that personnel authorized to process personal data are bound by confidentiality obligations and access data only as needed to provide and support the Service, on a least-privilege basis.
Security
CashLinx maintains technical and organizational measures appropriate to the risk, including default-deny row level security that isolates each tenant and client, encryption in transit, encrypted connection secrets, least-privilege access, and audit logging of sensitive actions. Our current posture is described on the Security page.
Subprocessors
The Practice authorizes CashLinx to engage the subprocessors listed on our Subprocessors page to process personal data in connection with the Service. CashLinx imposes data protection obligations on each subprocessor that are consistent with this DPA and remains responsible for their performance. We will provide a means to be notified of new subprocessors so the Practice can object on reasonable grounds.
Data subject requests
Taking into account the nature of the processing, CashLinx assists the Practice by appropriate technical and organizational measures, insofar as possible, to respond to requests from data subjects to exercise their rights. Where CashLinx receives such a request directly, it will refer the request to the relevant Practice.
Personal data breach
CashLinx notifies the Practice without undue delay after becoming aware of a personal data breach affecting the Practice's data, and provides information reasonably available to assist the Practice in meeting its own notification obligations.
International transfers
Where processing involves the transfer of personal data across borders, the parties will rely on an appropriate transfer mechanism as required by applicable law.
Return and deletion
On termination of the Service, and subject to legal retention requirements and the never-erase audit model described in the Privacy Policy, CashLinx will delete or return the Practice's personal data on request, within a reasonable period.
Audits
CashLinx makes available information reasonably necessary to demonstrate compliance with this DPA and will cooperate with reasonable audit requests, subject to confidentiality and security constraints.
Contact
To request a signed copy of this DPA or with questions about data processing, contact privacy@mycashlinx.com.
This document is a plain-language template and is not legal advice. Final terms are subject to the executed agreement between the parties.