1.Parties, incorporation, and precedence

In plain terms: This addendum is part of the Terms and applies automatically to every customer. If it conflicts with the Terms on data handling, this wins.

This Data Processing Addendum (the “DPA”) forms part of the Chiaro Terms of Service (the “Agreement”) between the Customer and Y Assurance PLLC (the “Firm”) and applies to the Firm’s processing of Personal Data within Customer Data. For personal-data processing, this DPA controls over the Agreement. For protected health information, an executed Business Associate Agreement controls over this DPA. For attest services, the applicable Engagement Letter controls.

This DPA binds every customer automatically through the Agreement. A signable copy is available in the portal’s Agreements page for customers whose procurement process requires an executed copy; signing it does not change either party’s rights or obligations.

2.Definitions

“Personal Data” means information relating to an identified or identifiable natural person contained in Customer Data. “Processing,” “Controller,” and “Processor” have the meanings customary under applicable data-protection law; under the California Consumer Privacy Act, “Controller” is read as “Business” and “Processor” as “Service Provider.” Other capitalized terms have the meanings in the Agreement.

3.Roles

In plain terms: You are the controller of your workspace data; we process it on your instructions. Engagement workpapers are the exception: professional standards make the Firm keep those in its own right.

For Personal Data in Customer Data processed on the Platform, the Customer is the Controller and the Firm is the Processor, acting on the Customer’s documented instructions.

Workpapers carve-out. Where the Firm performs services under an Engagement Letter, the Firm’s engagement records and workpapers (which may include copies of Customer Data) are created and retained by the Firm to meet its own obligations under AICPA professional standards and Texas law. For those records, the Firm acts as an independent controller: it determines their retention and handling as required by professional standards, retains them for a minimum of five years, and makes them available to peer reviewers and regulators as required. The protections of Sections 6, 7, and 8 continue to apply to Personal Data in retained records.

4.Scope and instructions

The Firm processes Personal Data only: (a) to provide, secure, and support the Platform and the services; (b) as documented in the Agreement, this DPA, and the Customer’s configuration and use of the Platform; (c) as otherwise instructed in writing by the Customer; and (d) as required by law or professional standards, in which case the Firm informs the Customer unless prohibited. Details of the processing appear in Annex I (Section 14).

The Firm will inform the Customer if, in its opinion, an instruction violates applicable data-protection law.

5.Confidentiality of personnel

The Firm ensures that persons authorized to process Personal Data are bound by confidentiality obligations, contractual or professional.

6.Security

In plain terms: Encryption in transit and at rest, MFA, least privilege, tenant isolation, monitoring. The full list is Annex II.

The Firm implements and maintains appropriate technical and organizational measures to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, as described in Annex II (Section 15). The Firm may update Annex II from time to time, provided the overall level of protection is not materially reduced.

7.Subprocessors

In plain terms: We use the eleven vendors in Schedule A. If the list materially changes, you hear about it within 30 days and can object.

The Customer generally authorizes the Firm to engage the subprocessors listed in Schedule A (Section 16). The Firm binds each subprocessor to data-protection obligations no less protective than this DPA and remains responsible for their performance. The Firm will notify active customers of material changes to Schedule A within 30 days. If the Customer reasonably objects to a new subprocessor on data-protection grounds and the parties cannot resolve the objection, the Customer may terminate the affected Subscription and receive a refund of prepaid fees for the unused period.

8.Assistance, data-subject requests, and breach notification

In plain terms: Requests from your people go to you, and we help. If a breach hits your data, we aim to tell you within 72 hours of confirming it.

Taking into account the nature of the processing, the Firm will reasonably assist the Customer in responding to data-subject requests (access, correction, deletion, portability, objection) and in meeting the Customer’s security, breach-notification, and assessment obligations. If the Firm receives a request directly from a data subject relating to Customer Data, it will forward the request to the Customer without undue delay and not respond substantively except as required by law.

The Firm will notify the Customer without undue delay after confirming a Personal Data breach affecting Customer Data, with a target of 72 hours from confirmation, and will provide information reasonably available about the nature of the breach, the data affected, and the measures taken, supplementing as the investigation progresses.

9.Return and deletion

During the Subscription and for 30 days after it ends, the Customer may export Customer Data from the Platform. On written request or after that window, the Firm will delete Personal Data in Customer Data held on the Platform, except Personal Data the Firm must retain under law or professional standards (Section 3 workpapers carve-out; AICPA standards; Texas Administrative Code §501.76). Retained data remains protected under this DPA and is deleted when the retention obligation ends.

10.California (CCPA) service-provider terms

To the extent the CCPA applies, the Firm acts as the Customer’s Service Provider and will not: sell or share Personal Data; retain, use, or disclose it for any purpose other than performing the services (or as permitted by the CCPA); retain, use, or disclose it outside the direct business relationship with the Customer; or combine it with personal information from other sources except as permitted for the services. The Firm certifies that it understands and will comply with these restrictions, and will notify the Customer if it can no longer meet them, in which case the Customer may take reasonable steps to stop unauthorized use.

11.International transfers

The Firm processes Personal Data in the United States. Where the Customer submits Personal Data originating outside the United States, the Customer instructs that transfer and is responsible for ensuring an adequate transfer basis under the law applicable to it. The parties will cooperate in good faith to execute additional transfer mechanisms (such as standard contractual clauses) where required.

12.Audits and information

On written request no more than once annually (and after a confirmed breach affecting the Customer), the Firm will make available information reasonably necessary to demonstrate compliance with this DPA: security documentation, Annex II details, completed security questionnaires, and written responses to reasonable inquiries. The parties agree this satisfies audit rights under applicable law to the extent permitted.

13.Liability and term

Liability under this DPA is subject to the limitations of liability in the Agreement. This DPA applies for as long as the Firm processes Personal Data in Customer Data, and Sections 3, 6, 8, and 9 survive for data retained under professional standards.

14.Annex I: Details of processing

Subject matterProvision of the Chiaro platform: readiness tooling, evidence vault, progress tracking, agreements, and account management; engagement support where an Engagement Letter is signed.
DurationThe Subscription term plus the export window, and any professional retention periods for engagement records.
Nature and purposeHosting, storage, organization, display, transmission, and retention of Customer Data to provide the services; billing; support; security.
Data subjectsThe Customer’s personnel and Authorized Users; individuals appearing incidentally in evidence artifacts (for example employees named in HR records or system logs).
Categories of Personal DataBusiness contact data (names, work emails, titles); account and usage records; signature records; personal data appearing incidentally in evidence artifacts the Customer chooses to submit. System credentials are excluded by architecture.
Special categoriesNone intended. Protected health information only where the parties execute a Business Associate Agreement.

15.Annex II: Technical and organizational measures

16.Schedule A: Subprocessors

SubprocessorRole
AnthropicAI model API (configured not to train on customer content)
SupabaseDatabase, authentication, and file storage
RailwayBackend and MCP server hosting
VercelWeb frontend hosting
GitHubSource code management
AppleFirm workpaper backup (redundant copy)
MicrosoftFirm workpaper backup (redundant copy)
StripePayment processing
ResendTransactional email
GoDaddyDNS and domain services
DocuSignElectronic signature (fallback channel)