1.Parties, incorporation, and precedence
This Data Processing Addendum (the “DPA”) forms part of the Chiaro Terms of Service (the “Agreement”) between the Customer and Y Assurance PLLC (the “Firm”) and applies to the Firm’s processing of Personal Data within Customer Data. For personal-data processing, this DPA controls over the Agreement. For protected health information, an executed Business Associate Agreement controls over this DPA. For attest services, the applicable Engagement Letter controls.
This DPA binds every customer automatically through the Agreement. A signable copy is available in the portal’s Agreements page for customers whose procurement process requires an executed copy; signing it does not change either party’s rights or obligations.
2.Definitions
“Personal Data” means information relating to an identified or identifiable natural person contained in Customer Data. “Processing,” “Controller,” and “Processor” have the meanings customary under applicable data-protection law; under the California Consumer Privacy Act, “Controller” is read as “Business” and “Processor” as “Service Provider.” Other capitalized terms have the meanings in the Agreement.
3.Roles
For Personal Data in Customer Data processed on the Platform, the Customer is the Controller and the Firm is the Processor, acting on the Customer’s documented instructions.
Workpapers carve-out. Where the Firm performs services under an Engagement Letter, the Firm’s engagement records and workpapers (which may include copies of Customer Data) are created and retained by the Firm to meet its own obligations under AICPA professional standards and Texas law. For those records, the Firm acts as an independent controller: it determines their retention and handling as required by professional standards, retains them for a minimum of five years, and makes them available to peer reviewers and regulators as required. The protections of Sections 6, 7, and 8 continue to apply to Personal Data in retained records.
4.Scope and instructions
The Firm processes Personal Data only: (a) to provide, secure, and support the Platform and the services; (b) as documented in the Agreement, this DPA, and the Customer’s configuration and use of the Platform; (c) as otherwise instructed in writing by the Customer; and (d) as required by law or professional standards, in which case the Firm informs the Customer unless prohibited. Details of the processing appear in Annex I (Section 15).
The Firm will inform the Customer if, in its opinion, an instruction violates applicable data-protection law.
5.Confidentiality of personnel
The Firm ensures that persons authorized to process Personal Data are bound by confidentiality obligations, contractual or professional.
6.Security
The Firm implements and maintains appropriate technical and organizational measures to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, as described in Annex II (Section 16). The Firm may update Annex II from time to time, provided the overall level of protection is not materially reduced.
7.Subprocessors
The Customer generally authorizes the Firm to engage the subprocessors listed in Schedule A (Section 17). The Firm binds each subprocessor to data-protection obligations no less protective than this DPA and remains responsible for their performance. The Firm will notify active customers of material changes to Schedule A within 30 days. If the Customer reasonably objects to a new subprocessor on data-protection grounds and the parties cannot resolve the objection, the Customer may close its account and stop using the Platform, and the Firm will refund any fees paid for services not yet provided.
8.Assistance, data-subject requests, and breach notification
Taking into account the nature of the processing, the Firm will reasonably assist the Customer in responding to data-subject requests (access, correction, deletion, portability, objection) and in meeting the Customer’s security, breach-notification, and assessment obligations. If the Firm receives a request directly from a data subject relating to Customer Data, it will forward the request to the Customer without undue delay and not respond substantively except as required by law.
The Firm will notify the Customer without undue delay after confirming a Personal Data breach affecting Customer Data, with a target of 72 hours from confirmation, and will provide information reasonably available about the nature of the breach, the data affected, and the measures taken, supplementing as the investigation progresses.
9.Return and deletion
While the Customer’s account is open and for 30 days after it closes, the Customer may export Customer Data from the Platform. On written request or after that window, the Firm will delete Personal Data in Customer Data held on the Platform, except Personal Data the Firm must retain under law or professional standards (Section 3 workpapers carve-out; AICPA standards; Texas Administrative Code §501.76). Retained data remains protected under this DPA and is deleted when the retention obligation ends.
10.California (CCPA) service-provider terms
To the extent the CCPA applies, the Firm acts as the Customer’s Service Provider and will not: sell or share Personal Data; retain, use, or disclose it for any purpose other than performing the services (or as permitted by the CCPA); retain, use, or disclose it outside the direct business relationship with the Customer; or combine it with personal information from other sources except as permitted for the services. The Firm certifies that it understands and will comply with these restrictions, and will notify the Customer if it can no longer meet them, in which case the Customer may take reasonable steps to stop unauthorized use.
11.International transfers
The Firm processes Personal Data in the United States. Where the Customer submits Personal Data originating outside the United States, the Customer instructs that transfer and is responsible for ensuring an adequate transfer basis under the law applicable to it. The parties will cooperate in good faith to execute additional transfer mechanisms (such as standard contractual clauses) where required.
12.Audits and information
On written request no more than once annually (and after a confirmed breach affecting the Customer), the Firm will make available information reasonably necessary to demonstrate compliance with this DPA: security documentation, Annex II details, completed security questionnaires, and written responses to reasonable inquiries. The parties agree this satisfies audit rights under applicable law to the extent permitted.
13.Liability and term
Liability under this DPA is subject to the limitations of liability in the Agreement. This DPA applies for as long as the Firm processes Personal Data in Customer Data, and Sections 3, 6, 8, and 9 survive for data retained under professional standards.
14.HIPAA add-on engagements
This section applies only to engagements that include the HIPAA compliance add-on. The add-on maps the Customer’s controls to the HIPAA Security Rule (45 CFR Part 164, Subpart C), delivered as additional information with no opinion expressed on HIPAA compliance. The services do not require access to protected health information (“PHI”), and the Customer agrees not to submit PHI to the Platform in any form, including screenshots, exports, documents, and summaries: evidence shows configuration and process, never patient data, and the Customer redacts or masks patient-level detail before submission. Because no PHI is created, received, maintained, or transmitted by the Firm on the Customer’s behalf, the engagement does not establish a business associate relationship under 45 CFR 160.103 and no business associate agreement is entered into. If PHI nonetheless reaches the Firm, whichever party notices notifies the other promptly; the Firm deletes the affected material and confirms the deletion, and the Customer resubmits a redacted version.
15.Annex I: Details of processing
| Subject matter | Provision of the Chiaro platform: readiness tooling, evidence vault, progress tracking, agreements, and account management; engagement support where an Engagement Letter is signed. |
| Duration | For as long as the Customer’s account is open, plus the export window, and any professional retention periods for engagement records. |
| Nature and purpose | Hosting, storage, organization, display, transmission, and retention of Customer Data to provide the services; billing; support; security. |
| Data subjects | The Customer’s personnel and Authorized Users; individuals appearing incidentally in evidence artifacts (for example employees named in HR records or system logs). |
| Categories of Personal Data | Business contact data (names, work emails, titles); account and usage records; signature records; personal data appearing incidentally in evidence artifacts the Customer chooses to submit. System credentials are excluded by architecture. |
| Special categories | None intended or accepted. Protected health information is excluded: on HIPAA add-on engagements evidence must be PHI-free (Section 14), and the Firm does not enter into business associate agreements. |
16.Annex II: Technical and organizational measures
- Encryption of data in transit (TLS) and at rest
- Multi-factor authentication and password-manager standards for Firm access
- Least-privilege, role-based access; tenant isolation with row-level security
- Access tokens stored hashed; revocable per-workspace connections
- Logging, monitoring, and alerting on production systems
- Nightly encrypted backups held in separate storage, with documented recovery objectives and periodic restore testing
- Vendor due diligence and contractual data-protection terms for subprocessors
- Documented incident-response process with the 72-hour customer-notification target
- Personnel confidentiality obligations and security awareness
- Secure development practices, code review, and dependency management
17.Schedule A: Subprocessors
| Subprocessor | Role |
|---|---|
| Anthropic | AI model API (configured not to train on customer content) |
| Supabase | Database, authentication, and file storage |
| Railway | Backend and MCP server hosting |
| Vercel | Web frontend hosting |
| GitHub | Source code management |
| Microsoft | Firm workpaper storage and backup |
| Stripe | Payment processing |
| Resend | Transactional email |
| Cloudflare | DNS hosting (name resolution only; no customer traffic or content passes through it) |
| DocuSign | Electronic signature (fallback channel) |