Skip to content
Stratum AI
AgentsHow it worksSecurityPricingFoundersAbout
Book a call
AgentsHow it worksSecurityPricingFoundersAboutSolutionsInsightsContactBook a call
All legal documents

Data processing addendum

Last updated September 29, 2026 · Version 0.2, under review by counsel

  1. Scope and parties
  2. Roles
  3. Your instructions
  4. What we commit to
  5. CCPA service provider terms
  6. Other US state laws, GLBA and India
  7. Subprocessors
  8. International transfers
  9. Helping you with requests and assessments
  10. Personal data breaches
  11. Return and deletion
  12. Information and audits
  13. Liability
  14. Order of precedence and term
  15. Annex 1. Details of processing
  16. Annex 2. Security measures
  17. Annex 3. Subprocessors
Contents
  1. 1. Scope and parties
  2. 2. Roles
  3. 3. Your instructions
  4. 4. What we commit to
  5. 5. CCPA service provider terms
  6. 6. Other US state laws, GLBA and India
  7. 7. Subprocessors
  8. 8. International transfers
  9. 9. Helping you with requests and assessments
  10. 10. Personal data breaches
  11. 11. Return and deletion
  12. 12. Information and audits
  13. 13. Liability
  14. 14. Order of precedence and term
  15. Annex 1. Details of processing
  16. Annex 2. Security measures
  17. Annex 3. Subprocessors

The short version

  • You decide how your data is used. We process it only to run the service for you, on your instructions.
  • We never sell it, never use it to train models, and never use it for anyone else. The agents never move money without a person's approval.
  • You get 30 days' notice before we add a subprocessor, and you can object.
  • We tell you about a personal data breach within 72 hours of becoming aware of it.
  • We delete or return your data within 30 days of your written request after you leave.
  • EU and UK transfers are covered by the Standard Contractual Clauses, which this addendum includes.

1. Scope and parties

This Data processing addendum ("DPA") forms part of the Terms of service between Aniketh Marian, sole proprietor, trading as DA SUAN ENTERPRISES and Stratum AI ("Stratum", "we", "us") and the client named in the Order ("you"). It applies whenever Stratum processes Customer Personal Data in providing the Service. It takes effect when you accept the Terms, with no separate signature needed. If you need a signed copy, email Stratumai.co@gmail.com.

Terms defined in the Terms of service have the same meaning here. "Customer Personal Data" means personal data within Customer Data. "Data Protection Laws" means all laws that apply to processing of Customer Personal Data under the Agreement, including India's Digital Personal Data Protection Act 2023 and the rules made under it ("DPDP Act"), the EU GDPR, the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, the California Consumer Privacy Act as amended ("CCPA"), and other US state privacy laws. Terms such as "controller", "processor", "data subject", "personal data breach", "business", "service provider", "data fiduciary" and "data processor" have the meanings given in the relevant Data Protection Law.

2. Roles

  • You are the controller (a "business" under the CCPA, a "data fiduciary" under the DPDP Act) of Customer Personal Data. If you act as a processor for someone else, you are a processor and we are your subprocessor.
  • We are your processor (a "service provider" under the CCPA, a "data processor" under the DPDP Act).
  • For our own account, billing and business contact data about your Users, we are a controller (a "data fiduciary" under the DPDP Act), and our Privacy policy applies. Payment details you give Razorpay when you pay us are handled by Razorpay, and we never store card details.

3. Your instructions

We process Customer Personal Data only on your documented instructions. The Agreement, your Order, your configuration of the Service, your Rulebook and your approvals in the Service are your complete instructions. Further instructions must be in writing and consistent with the Agreement.

Instructions found inside emails, documents or other content are not your instructions, and we do not act on them.

We will tell you promptly if we believe an instruction breaks Data Protection Laws, and we may pause the affected processing until you confirm or change it. If the law requires us to process Customer Personal Data other than on your instructions, we will tell you before we do, unless the law forbids it.

You are responsible for having a lawful basis for the processing, for giving any notices and getting any consents required, and for the lawfulness of your instructions.

4. What we commit to

In line with Article 28(3) of the GDPR and equivalent laws, we will:

  1. Process Customer Personal Data only on your documented instructions, including for international transfers, as set out in section 3.
  2. Make sure everyone authorized to process it is bound by confidentiality, by contract or by law.
  3. Take the security measures in Annex 2, as Article 32 requires.
  4. Engage subprocessors only as set out in section 7.
  5. Help you, by appropriate technical and organizational measures and as far as possible, to respond to requests from data subjects to exercise their rights, as set out in section 9.
  6. Help you meet your obligations on security, breach notification, data protection impact assessments and prior consultation, taking into account the nature of the processing and the information available to us, as set out in sections 9 and 10.
  7. Delete or return Customer Personal Data at the end of the Service, at your choice, as set out in section 11.
  8. Make available the information needed to show we meet this DPA, and allow for and contribute to audits, as set out in section 12.

We will also never sell Customer Personal Data, never use Customer Data to train AI models (and our model providers are contractually barred from training on it), and never use Customer Personal Data to build or improve profiles of individuals for anyone else.

5. CCPA service provider terms

Where the CCPA applies, we act as your service provider and, as required by Cal. Civ. Code 1798.100(d) and 1798.140(ag) and 11 CCR 7051:

  1. We process personal information only for the limited and specified business purposes of providing the Service described in the Agreement and Annex 1, including security, debugging and the other purposes the CCPA regulations permit.
  2. We will not sell or share personal information, as the CCPA defines those terms.
  3. We will not retain, use or disclose personal information for any purpose other than those business purposes, including any commercial purpose, or outside the direct business relationship between you and us.
  4. We will not combine personal information we receive from you with personal information we receive from others or collect ourselves, except as the CCPA regulations allow.
  5. We will comply with the CCPA and provide the same level of privacy protection the CCPA requires of you.
  6. You may take reasonable and appropriate steps to make sure we use personal information consistently with your CCPA obligations, including through section 12, and, on notice, to stop and remediate any unauthorized use.
  7. We will tell you within 5 business days if we decide we can no longer meet our CCPA obligations.
  8. We will pass on these obligations to any subprocessor by written contract.
  9. We certify that we understand these restrictions and will comply with them.

6. Other US state laws, GLBA and India

Other US state privacy laws

Where a state law such as those of Virginia, Colorado or Connecticut applies, this DPA is the processor contract that law requires. Annex 1 sets out the nature, purpose and duration of processing and the types of personal data. Our duty of confidentiality, subprocessor terms, deletion terms, information and audit terms in this DPA apply as that law requires.

Financial institution customers

If you are a financial institution under the Gramm Leach Bliley Act and share nonpublic personal information about your consumers with us, we act as your service provider and maintain safeguards for that information consistent with the FTC Safeguards Rule (16 CFR 314), including the measures in Annex 2.

India

Where the DPDP Act applies to you as a data fiduciary, this DPA is the contract under which you engage us as your data processor. We process personal data only on your instructions, keep reasonable security safeguards, tell you of any personal data breach as set out in section 10 so that you can inform the Data Protection Board of India and affected people, and erase personal data when you instruct us to or when the Service ends.

7. Subprocessors

You give us general authorization to engage the subprocessors listed on our Subprocessors page. Before we engage any subprocessor, we will sign a written contract with it that gives Customer Personal Data at least the same protection as this DPA. We remain liable to you for our subprocessors' performance under this DPA.

We will tell you at least 30 days before we add or replace a subprocessor, by email to your account owner and by updating the Subprocessors page. If there is an emergency, such as a subprocessor failing in a way that puts the Service or your data at risk, we may replace it on shorter notice and will tell you as soon as possible, with the same right to object.

You may object on reasonable data protection grounds by emailing Stratumai.co@gmail.com within the notice period. We will then work with you in good faith to address the objection, for example by not using the new subprocessor for your data or by offering a configuration that avoids it. If we cannot resolve the objection within 30 days, you may terminate the affected Service by written notice and receive a refund of prepaid fees for the unused period.

The services you connect yourself, such as QuickBooks Online, your bank or bank feed provider, your mailbox provider and Slack, are not our subprocessors. You contract with them directly and choose to connect them.

8. International transfers

DA SUAN ENTERPRISES is registered in India. We host and process Customer Personal Data in the United States, and our personnel access it from New York, USA. Our subprocessors process it in the locations shown on the Subprocessors page. We will not transfer it to another country unless we meet the requirements of Data Protection Laws, including any restriction the Government of India places on transfers under the DPDP Act.

European Economic Area

For transfers of Customer Personal Data from the European Economic Area to Stratum (an Indian business that processes the data in the United States), the Standard Contractual Clauses adopted by the European Commission in Implementing Decision (EU) 2021/914 ("SCCs") are incorporated into this DPA by reference, as follows:

  • Module 2 (controller to processor) applies where you are a controller. Module 3 (processor to processor) applies where you are a processor.
  • You are the data exporter and Stratum is the data importer.
  • Clause 7 (docking clause) is included.
  • Clause 9(a): Option 2 (general written authorization) applies, with the notice period in section 7 of this DPA.
  • Clause 11(a): the optional language does not apply.
  • Clause 13: the competent supervisory authority is the one determined under Clause 13 by your establishment or representative.
  • Clause 17: Option 1 applies. The SCCs are governed by the law of Ireland.
  • Clause 18: disputes are resolved by the courts of Ireland.
  • Annex I of the SCCs is completed by Annex 1 of this DPA and the Subprocessors page. Annex II is completed by Annex 2 of this DPA. Annex III is completed by the Subprocessors page.

United Kingdom

For transfers from the United Kingdom, the International Data Transfer Addendum to the EU SCCs issued by the Information Commissioner (version B1.0, or any version that replaces it) applies. Table 1 is completed with the parties' details in the Order, Tables 2 and 3 with the choices and annexes above, and in Table 4 either party may end the Addendum as its Section 19 allows.

Switzerland

For transfers from Switzerland, the SCCs apply with these changes: references to the GDPR include the Swiss Federal Act on Data Protection, the competent authority is the Swiss Federal Data Protection and Information Commissioner, and "member state" includes Switzerland so that data subjects there can enforce their rights.

Onward transfers

Transfers to our subprocessors are made under the SCCs (Module 3) or, where the subprocessor is certified, the EU US Data Privacy Framework and its UK Extension.

Government requests

If a public authority asks us for Customer Personal Data, we will direct it to you where we can, tell you promptly unless the law forbids it, challenge the request if it is unlawful, and disclose only the minimum required. We have not built any back door for government access.

If the SCCs conflict with this DPA or the Terms, the SCCs win.

9. Helping you with requests and assessments

  • If a data subject asks us directly to exercise a right over Customer Personal Data, we will forward the request to you within 5 business days and will not respond to it ourselves except to confirm we have passed it on, unless you ask us to.
  • The Service lets you find, export, correct and delete personal data. If you cannot do something yourself, we will help you promptly.
  • We will give you reasonable information and help for your data protection impact assessments and any prior consultation with a supervisory authority, including a description of the processing and our security measures.
  • This help is included in the fees, unless a request is manifestly excessive, in which case we will agree any charge with you first.

10. Personal data breaches

If we become aware of a personal data breach affecting Customer Personal Data, we will notify you without undue delay and within 72 hours of becoming aware of it. The notice will describe, as far as we know them at the time:

  • the nature of the breach, including the categories and approximate number of people and records concerned;
  • the likely consequences;
  • the measures we have taken or propose to take to address it and limit its effects;
  • a contact point for more information.

Where we cannot provide everything at once, we will provide it in phases without further undue delay. We will take reasonable steps to contain and investigate the breach and will cooperate with you so that you can meet your own notice duties, including under the DPDP Act, GDPR Articles 33 and 34, and US state breach laws such as New York General Business Law 899 aa. Where Indian law requires us to report an incident to the Indian Computer Emergency Response Team, we will. We will not notify regulators or data subjects about a breach of Customer Personal Data on your behalf without your approval, unless the law requires us to. Our notice is not an admission of fault.

11. Return and deletion

  • You can export Customer Data, your Rulebook and your Audit Log at any time during the Agreement and for 30 days after it ends.
  • Within 30 days of your written request after termination, we will delete Customer Personal Data from our active systems, or return it to you first if you ask. If you make no request, we delete it no later than 90 days after termination.
  • Deleted data rolls off our backups within 90 days of deletion. Until then, it stays encrypted and isolated and is not used.
  • We will also instruct our subprocessors to delete Customer Personal Data they hold for us.
  • We may keep Customer Personal Data only where the law requires, only for as long as required, and still protected by this DPA.
  • On request, we will confirm deletion in writing.

12. Information and audits

We will make available the information reasonably needed to show we meet this DPA. Audits work in this order:

  1. Documents first. On request, we will answer your reasonable security and privacy questionnaire and share our written policies, and any independent audit reports we hold at the time, under confidentiality.
  2. Audit if still needed. If the documents do not reasonably answer your question, or a regulator requires it, or after a personal data breach affecting your data, you (or an independent auditor bound by confidentiality who is not our competitor) may audit our compliance with this DPA.
  3. Limits. Audits happen at most once in any 12 months (except after a breach or when a regulator requires it), on at least 30 days' written notice, during business hours, for no more than two business days, under an agreed scope, and without access to other customers' data or to information that would compromise security. Each party bears its own costs, unless the audit shows a material breach of this DPA by us, in which case we pay your reasonable audit costs.
  4. Results. You will give us a copy of any audit report, and we will fix any confirmed failures promptly.

This section also satisfies the audit rights under the SCCs and US state laws, as far as those laws allow.

13. Liability

Each party's liability arising out of or relating to this DPA, including under the SCCs, is subject to the limitation of liability section of the Terms of service. This DPA is governed by the laws of India, and the courts of Bangalore (Bengaluru), Karnataka have exclusive jurisdiction, as set out in the Terms of service, except where the SCCs require otherwise. Nothing in this DPA limits either party's liability to data subjects under the SCCs, or any liability that cannot be limited under Data Protection Laws.

14. Order of precedence and term

If there is a conflict, this order applies: first the SCCs (and UK Addendum), then this DPA, then the Terms of service, then the Order. This DPA lasts as long as we process Customer Personal Data, including after the Agreement ends until deletion is complete.

We may update this DPA to reflect changes in law or our subprocessors, with at least 30 days' notice for material changes. We will not reduce the overall level of protection it gives your data during your subscription.

15. Annex 1. Details of processing

ItemDetails
Subject matterProviding AI agents for finance back office work, as described in the Terms of service and the Order.
DurationThe term of the Agreement, plus the period until deletion under section 11.
Nature of processingCollection through connectors (accounting data through QuickBooks OAuth, and email or bank data only where you connect it), storage, reading, classification, matching, extraction, drafting, sending messages from your mailbox on your rules and approvals, writing approved entries to your ledger, logging, export and deletion. Automated processing by AI models, under your rules and approval thresholds. The agents never move money.
PurposeReceivables reminders, bill capture and coding, payment run preparation, bank reconciliation, month end close drafts, cash forecasts, spend audit and extracting terms from documents, plus keeping your Rulebook and Audit Log, supporting you and keeping the Service secure.
Categories of data subjectsYour Users; your customers and their contacts; your vendors and their contacts; your employees and contractors appearing in ledger, expense or payment records; other people named in emails, documents or Slack messages you connect.
Categories of personal dataNames, job titles, business email addresses, phone numbers and postal addresses; invoice, bill, payment and transaction details; bank account details on vendor and payment records; tax identifiers appearing on invoices or vendor records; email and Slack message content and metadata; document content; User sign in records, approvals and actions.
Sensitive dataNot intended. Bank account details are treated with heightened protection. You should not connect sources that are likely to contain special category data unless needed for the Service.
Frequency of transferContinuous, for as long as the Service runs.
RetentionAs set out in section 11.
Subprocessor transfersAs listed on the Subprocessors page, for the purposes and locations shown there.
Data exporterYou, the client named in the Order. Contact: your account owner.
Data importerAniketh Marian, sole proprietor, trading as DA SUAN ENTERPRISES and Stratum AI, Ack Corp, OMBR Layout, Bangalore [area, state and PIN code to be added], India. Team operating from New York, USA. Data protection contact: Stratumai.co@gmail.com, +1 (516) 613-0509. Grievance Officer: Aniketh Marian.

16. Annex 2. Security measures

We maintain the measures on our Security page, which forms part of this Annex. In summary:

  • Guardrails enforced by the system: no money movement, approval thresholds, no filing, locking or writing off, content never treated as instructions, changed bank details flagged for verification, sensitive parties never contacted.
  • Least privilege OAuth scopes, read only bank feeds, and no ledger or bank passwords held.
  • Encryption in transit with TLS 1.2 or higher, and at rest with AES 256 or equivalent, including access tokens and backups.
  • Logical separation of each customer's data, checked on every request.
  • Append only audit log of every agent action, plus logs of all access to customer data by our team.
  • Multifactor sign in, company managed encrypted devices, no customer data on local devices, quarterly access reviews, confidentiality agreements and annual training for all personnel.
  • Vendor review and written data protection terms for every subprocessor.
  • Code review, dependency monitoring and guardrail testing before release.
  • Written incident response plan, 72 hour breach notification, encrypted backups with annual restore tests.

17. Annex 3. Subprocessors

The current list of subprocessors is on the Subprocessors page, which forms part of this Annex. At the date of this DPA it is:

SubprocessorPurposeData involvedLocation
Vercel Inc.Hosting of the website and application, and request logsAll client data processed by the application; IP addresses and browser details in logsUSA
Anthropic PBCAI processing for the agents. Contractually barred from training models on client dataThe ledger records, transactions, documents and message content an agent needs for a taskUSA
Razorpay Software Private LimitedPayment processing for our fees. Stratum never stores card detailsName, email and payment details, handled by Razorpay on its own checkout. We receive only the payment reference, amount, status, name, email and companyIndia
ResendSending transactional email, such as notifications, approval requests and website form messages to Stratumai.co@gmail.comRecipient names and email addresses, and message contentUSA
Google LLC (Gmail)The Stratumai.co@gmail.com mailbox, where your emails and website form messages arriveNames, email addresses and the content of messages you send usUSA
Plausible AnalyticsCookieless website analyticsNo personal data. Aggregated page views, referrers, browser, device and countryEU (Germany)

The ledger, bank and mailbox providers you choose to connect are Connected Services, not our subprocessors.

Questions about this document: Stratumai.co@gmail.com.

Stratum AI

Software that automates invoicing, accounts payable, bank reconciliation and month end close, set up and run for you.

New York, NY

Stratumai.co@gmail.com
+1 (516) 613-0509

AgentsAll agentsReceivablesPayablesReconciliationMonth end closeSpend auditCash and runwayDocuments into dataBy kind of business
CompanyHow it worksSecurityPricingAboutThe foundersInsightsCareersBook a callContact
LegalAll legal documentsPrivacy policyTerms of serviceRefund and cancellationShipping and deliverySecurity commitmentsData processing addendumSubprocessorsAcceptable useCookies

Stratum AI is software. We never hold, receive or transfer client funds. Payments between our clients and their customers or vendors always happen through the client's own bank and accounting system.

© 2026 Stratum AI · DA SUAN ENTERPRISESEvery company named on this site is illustrative and fictional. The workflow is real.