Data Processing Agreement
This Data Processing Agreement ("DPA") describes how BillPortal Technologies Inc. processes personal data on behalf of Customers when providing the BillPortal service. It supplements the Terms of Service.
Questions about this policy, a refund, or want to raise a dispute? Our team is happy to help.
Contact support1. Roles
For customer data uploaded to or generated within the platform, the Customer is the controller and BillPortal is the processor. BillPortal processes personal data only on documented instructions from the Customer, including as set out in the Terms and this DPA.
2. Scope, nature and details of processing
Subject matter: provision of the utility bill and expense management service. Nature and purpose: acquisition, AI-supported extraction, validation, payment processing, allocation and reporting of utility/expense data. Duration: for the term of the subscription plus the export/deletion windows in Section 11.
- Categories of data subjects: Customer personnel and authorised users; and, where applicable, tenants, residents or account holders whose utility accounts are managed.
- Categories of personal data: names, business contact details, user credentials/identifiers; utility account numbers and service addresses; billing amounts and usage data; and payment/banking details (e.g., account and routing information) used for disbursements.
- Special categories: none are required or intended; Customers must not upload special-category data except as expressly agreed.
- Retention: personal data is retained for the processing duration above and deleted or returned per Section 11, except where retention is required by law.
3. Confidentiality
We ensure that personnel authorised to process personal data are bound by appropriate confidentiality obligations.
4. Security
We implement appropriate technical and organisational measures, including encryption in transit and at rest, access controls, least-privilege access, and end-to-end audit trails, designed to protect personal data against unauthorised access, loss or disclosure.
Audit-trail traceability: our audit trails record actions taken at each stage of the bill lifecycle (capture, extraction, validation, approval, payment and allocation) and associate them with the acting user and time, so activity can be traced step-by-step for accountability and investigation.
5. Sub-processors
We engage the following categories of sub-processors, consistent with the categories described in our Privacy Policy. The current list of named sub-processors is maintained and published, and is available on request and at a URL provided in the customer application/help centre.
- Cloud infrastructure and storage (hosting).
- Email delivery (Amazon SES).
- Payment/banking partner for ACH, card and cheque rails.
- Analytics and operational tooling.
6. Sub-processor changes
We maintain the current sub-processor list referenced in Section 5 and will notify Customers of intended additions or replacements at least thirty (30) days in advance (via the application, email, or the published list). The Customer may object on reasonable data-protection grounds within that thirty (30) day window; if we cannot reasonably accommodate the objection, the Customer may terminate the affected service as its exclusive remedy.
7. International transfers
Where personal data is transferred across borders, we rely on appropriate safeguards (such as the Standard Contractual Clauses, plus the UK Addendum/Swiss addendum where relevant) where required. Data-residency options may be available as described in your order form.
8. Data subject requests & assistance
Taking into account the nature of processing, we provide reasonable assistance to help the Customer respond to data-subject requests and to meet its security, breach-notification and impact-assessment obligations.
9. Breach notification
We will notify the Customer without undue delay, and in any event within forty-eight (48) hours, after becoming aware of a personal data breach affecting Customer data, and provide the information reasonably required for the Customer to meet its obligations — including its regulator-notification deadline (generally within 72 hours of the controller becoming aware under GDPR).
10. Audit rights
We will make available to the Customer information reasonably necessary to demonstrate compliance with this DPA and applicable data-protection law, including relevant third-party audit reports and certifications where available. On reasonable prior written notice (at least thirty (30) days), no more than once per year (unless required by a regulator or following a breach), and subject to confidentiality, the Customer or its mandated auditor may conduct an audit or inspection of the controls relevant to the processing, during business hours and without unreasonable disruption.
11. Return and deletion
Upon termination, we will, at the Customer's choice, return or delete Customer personal data within ninety (90) days, except where retention is required by law. Data is available for export during that ninety (90) day window (subject to any shorter window applied for fraud-related terminations under the AUP). On request, we will provide written confirmation (a certificate of deletion) once deletion is complete.
12. Liability
The limitation of liability in the Terms of Service applies to this DPA. The parties acknowledge that data-breach-related losses (including regulatory fines and third-party claims) may be significant; any specific or elevated cap or carve-out for such losses will be as set out in an executed order form or negotiated DPA. This section does not limit liability that cannot be limited by law.
13. Contact
For DPA execution, sub-processor lists or data-protection queries, contact info@billportal.io.
