BillCadence
How it worksWhy BillCadencePricingCadence 1.01About
Discuss Your Workflow

Legal

Data Processing Addendum

Effective August 29, 2026

This Data Processing Addendum (the “Addendum”) forms part of the BillCadence Service Agreement (the “Agreement”) between SaaSync, LLC, doing business as BillCadence (“SaaSync”), and the business entity or person identified as the Customer in the Agreement, an Order, or BillCadence Account records (“Customer”).

This Addendum becomes effective when Customer first accepts or uses Services subject to the Agreement or an Order incorporating this Addendum (the “Addendum Effective Date”). It applies only to the extent SaaSync Processes Customer Personal Data on Customer's behalf and Data Protection Laws require these terms.

Capitalized terms not defined here have the meanings in the Agreement. Except as modified by this Addendum, the Agreement remains in effect.

Contents

  1. Definitions
  2. Processing of Customer Personal Data
  3. Confidentiality
  4. Security
  5. Subprocessing
  6. Data Subject rights
  7. Assessments and consultations
  8. Records and audit rights
  9. International transfers
  10. Deletion or return
  11. General terms
  12. Appendix 1: Processing details
  13. Appendix 2: Security measures
  14. Appendix 3: Transfer clauses

1. Definitions

“Controller” means an entity that determines the purposes and means of Processing Personal Data.

“Customer Personal Data” means Personal Data contained in Customer Data that SaaSync Processes on Customer's behalf to perform the Services.

“Data Protection Laws” means privacy and data-security laws applicable to the Processing of Customer Personal Data, including, where applicable, European Data Protection Laws and United States Data Protection Laws.

“Data Subject” means an identified or identifiable natural person to whom Personal Data relates.

“European Data Protection Laws” means, to the extent applicable, the EU General Data Protection Regulation 2016/679 (“GDPR”); the GDPR as incorporated into United Kingdom law (“UK GDPR”), the UK Data Protection Act 2018, and other applicable UK privacy laws; the Swiss Federal Act on Data Protection (“Swiss FADP”); and other applicable privacy laws of the European Economic Area, United Kingdom, or Switzerland.

“Personal Data” means information constituting personal data, personal information, personally identifiable information, or a similar regulated category under Data Protection Laws.

“Process” means any operation performed on Personal Data, including collection, recording, organization, structuring, storage, alteration, retrieval, use, alignment, combination, restriction, disclosure, erasure, or destruction.

“Processor” means an entity that Processes Personal Data on behalf of a Controller.

“Security Incident” means a breach of SaaSync's security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data in SaaSync's possession, custody, or control. It excludes unsuccessful attempts that do not compromise Customer Personal Data, such as unsuccessful login attempts, pings, port scans, denial-of-service attacks, and other unsuccessful network attacks.

“Standard Contractual Clauses” means Module Two or Module Three, as applicable, of the clauses adopted by European Commission Implementing Decision (EU) 2021/914, as modified by Appendix 3.

“Subprocessor” means a Processor appointed by SaaSync to Process Customer Personal Data on Customer's behalf.

“Supervisory Authority” means an independent public authority established or recognized under Data Protection Laws.

“United States Data Protection Laws” means applicable US state comprehensive privacy laws and their implementing regulations, including the California Consumer Privacy Act, as amended (“CCPA”).

2. Processing of Customer Personal Data

2.1 Roles and compliance

As between the parties, Customer is a Controller and SaaSync is a Processor of Customer Personal Data. If Customer is a Processor for a third-party Controller, SaaSync is Customer's subprocessor. Each party will comply with obligations applicable to its role under Data Protection Laws.

2.2 Customer instructions

SaaSync will Process Customer Personal Data only on Customer's documented instructions unless applicable law requires otherwise. If law requires other Processing, SaaSync will inform Customer before Processing unless the law prohibits notice. Customer instructs SaaSync to Process Customer Personal Data to provide, operate, secure, support, and improve the Services; perform the Agreement, this Addendum, and applicable Orders; carry out configurations and actions submitted through the Account; and prevent or resolve technical or security problems.

SaaSync will inform Customer if, in its opinion, an instruction infringes Data Protection Laws. Customer is responsible for the lawfulness of its instructions, providing required notices, obtaining necessary rights and consents, and notifying SaaSync when an instruction or permission changes.

2.3 Processing details

The subject matter, nature, purpose, duration, Personal Data categories, and Data Subject categories are described in Appendix 1.

2.4 CCPA and similar US laws

To the extent the CCPA applies, SaaSync is a service provider or contractor. SaaSync will not Sell or Share Customer Personal Data; retain, use, or disclose it outside the direct business relationship with Customer or for a purpose other than the limited and specified business purposes in the Agreement and this Addendum; or combine it with Personal Data received from another person or collected from SaaSync's own interaction with a Data Subject, except as permitted by the CCPA to perform those business purposes. SaaSync certifies that it understands and will comply with these restrictions.

SaaSync will provide the level of privacy protection required by the CCPA, notify Customer if it determines it can no longer meet its applicable obligations, and allow Customer to take reasonable and appropriate steps under Section 8 to help ensure compliant use and to stop and remediate unauthorized use.

2.5 Advertising and model-training restrictions

SaaSync will not use Customer Personal Data—including any information about Customer's customers—for advertising, audience matching, enrichment, lookalike modeling, or campaign attribution, and will not disclose it to Google, Meta, or another advertising partner for those purposes. SaaSync will not use identifiable Customer Personal Data to train or improve a generalized, shared, or cross-customer BillCadence or third-party AI model unless Customer separately and affirmatively authorizes that Processing in a written Order or other written agreement identifying the applicable data, purpose, and additional terms.

SaaSync may use aggregated or deidentified information for analytics, security, product improvement, and model improvement only if the information cannot reasonably identify Customer or a Data Subject and SaaSync maintains safeguards against reidentification.

3. Confidentiality

SaaSync will ensure that personnel authorized to Process Customer Personal Data are bound by confidentiality obligations or an appropriate statutory duty of confidentiality and access the data only as necessary for their assigned responsibilities.

4. Security

4.1 Security measures

Taking into account the state of the art, implementation costs, the nature, scope, context, and purposes of Processing, and risks to Data Subjects, SaaSync will implement appropriate technical and organizational measures designed to ensure security appropriate to the risk, including the measures in Appendix 2. SaaSync may update those measures to reflect improvements, changing risks, or evolving practices, provided the overall security of the Services is not materially reduced during a subscription term.

4.2 Security Incidents

Upon becoming aware of a Security Incident, SaaSync will notify Customer without undue delay and take reasonable steps to investigate the cause, minimize harm, remediate the incident, and prevent recurrence. To the extent available, notice will describe the nature of the incident, categories and approximate numbers of affected Data Subjects and records, likely consequences, and measures taken or proposed. SaaSync may provide information in phases and will not delay initial notice solely because complete information is unavailable. Notice is not an admission of fault or liability.

4.3 Customer responsibilities

Customer is responsible for using the Services securely, configuring access and automation appropriately, protecting credentials, systems, and devices under its control, and independently determining whether the Services and available security information satisfy Customer's legal and risk requirements.

5. Subprocessing

Customer generally authorizes SaaSync to appoint Subprocessors. The current Subprocessor List, including functions and processing locations, is published at www.billcadence.com/subprocessors. SaaSync will provide at least ten days' notice before a new or replacement Subprocessor begins Processing Customer Personal Data.

Customer may object on reasonable data-protection grounds by emailingprivacy@billcadence.com within that ten-day period. SaaSync will use commercially reasonable efforts to address a timely objection, make available a reasonable change avoiding the Subprocessor where practicable, or explain why it cannot do so. If no reasonable alternative is available, Customer may terminate the affected Service as its sole remedy under this Section.

SaaSync will enter into a written agreement requiring each Subprocessor to protect Customer Personal Data to a standard no less protective than the applicable requirements of this Addendum. SaaSync remains responsible for a Subprocessor's acts and omissions to the same extent SaaSync would be responsible under the Agreement and this Addendum.

6. Data Subject rights

Taking into account the nature of Processing and Service functionality, SaaSync will provide reasonable assistance through appropriate technical and organizational measures, insofar as possible, for Customer to respond to Data Subject requests. If SaaSync receives a request concerning Customer Personal Data, SaaSync will direct the requester to Customer and may notify Customer. Customer is responsible for responding. SaaSync may charge reasonable time-and-materials fees for assistance that is onerous, complex, frequent, or time-consuming, to the extent permitted by law.

7. Assessments and consultations

Upon Customer's written request, SaaSync will use commercially reasonable efforts to provide relevant information and assistance for a required data protection impact assessment, transfer impact assessment, consultation with a Supervisory Authority, breach notification, or other Customer compliance obligation, considering the nature of Processing and information available to SaaSync. SaaSync may charge reasonable time-and-materials fees for onerous, complex, frequent, or time-consuming assistance, to the extent permitted by law.

8. Records and audit rights

8.1 Information

Upon reasonable written request, SaaSync will make available information in its possession reasonably necessary to demonstrate compliance with this Addendum. Unless a Supervisory Authority or Data Protection Laws require otherwise, this information will be provided no more than once per calendar year and will be subject to the Agreement's confidentiality terms or a mutually agreed nondisclosure agreement.

8.2 Audits

If the information under Section 8.1 is insufficient for Customer's legal obligations, SaaSync will allow and contribute to a reasonable audit by Customer or an independent auditor that is not SaaSync's competitor. The audit must be at Customer's expense, on reasonable advance written notice, during normal business hours, scoped to relevant Processing, subject to SaaSync's reasonable safety, security, and confidentiality requirements, and conducted without unreasonable disruption. Audits are limited to once per calendar year unless law or a Supervisory Authority requires more.

8.3 Results

Customer will promptly notify SaaSync of identified noncompliance and, unless prohibited, provide resulting reports. Audit information and results are SaaSync Confidential Information and may be used only to evaluate compliance with this Addendum and Data Protection Laws.

9. International transfers

9.1 Processing locations

SaaSync and its Subprocessors may Process Customer Personal Data in the United States and other locations identified in the Subprocessor List. Each party is responsible for transfer obligations applicable to it.

9.2 European transfers

If Customer transfers Customer Personal Data subject to European Data Protection Laws to SaaSync in a country not recognized as adequate, and no exemption or other adequate mechanism applies, the applicable Standard Contractual Clauses are incorporated by reference and completed as stated in Appendix 3. Execution of this Addendum constitutes execution of those clauses. They terminate automatically for a transfer when another lawful basis makes them unnecessary.

9.3 Other jurisdictions

If another applicable jurisdiction requires approved standard clauses and no other adequate mechanism or exemption applies, those clauses apply automatically and will be completed, to the extent applicable, consistently with Appendix 3.

10. Deletion or return of Customer Personal Data

Upon Customer's express Account deletion, deletion of a data source, or verified written deletion request, SaaSync will promptly queue associated active Customer Personal Data for production deletion, which ordinarily completes within minutes. If an Account becomes inactive through trial expiration, cancellation, nonpayment, termination, or otherwise without an express deletion request, SaaSync may retain active operational Customer Personal Data for up to 45 days for reactivation, export, and recovery and will then schedule it for production deletion.

Before scheduled inactive-Account deletion, SaaSync will provide a reasonable opportunity to export or return available Customer Personal Data where reasonably practicable. Residual copies may remain in encrypted backups for up to seven days and remain protected under this Addendum until deleted through the ordinary backup lifecycle. SaaSync may retain Customer Personal Data longer only as required by applicable law, and will protect and not Process it for another purpose. Upon reasonable written request, SaaSync will confirm completion of deletion.

11. General terms

This Addendum survives expiration or termination of the Agreement until SaaSync deletes or returns all Customer Personal Data and then expires automatically. If a provision is invalid or unenforceable, it will be modified to preserve its intent as closely as legally possible and the remainder remains effective.

This Addendum controls over the Agreement concerning Processing of Customer Personal Data. The Standard Contractual Clauses control over both to the extent of a conflict concerning a governed transfer. Notices may be sent by email under the Agreement. Liability under this Addendum is subject to the Agreement's limitations, except where prohibited by Data Protection Laws or the Standard Contractual Clauses. The Agreement's governing-law and forum terms apply unless Data Protection Laws require otherwise.

Appendix 1: Details of Processing

A. Subject matter and duration

SaaSync Processes Customer Personal Data to provide, operate, secure, support, and improve the Services described in the Agreement and applicable Order. Processing continues during the Agreement and the limited retention and deletion periods in Section 10.

B. Nature and purpose

SaaSync receives data from Customer and Customer-selected Connected Services; stores, organizes, caches, logs, retrieves, compares, calculates, classifies, transforms, and transmits it; maintains billing schedules and effective-dated subscription changes; generates invoice information and related output; and, as configured, creates or updates draft or final invoices and initiates invoice-delivery workflows in Customer-selected accounting, billing, payment, commerce, customer- relationship, subscription-analytics, revenue-reporting, or communications systems. SaaSync also Processes data to authenticate users, operate integrations, provide AI-assisted features, diagnose errors, maintain audit records, support Customers, secure the Services, and comply with documented instructions and applicable law.

SaaSync may perform this Processing using internal software, infrastructure, APIs, and data-processing functionality also used to provide SaaSync's core integration platform. If Customer enables a ChartMogul integration, Customer instructs SaaSync to use those internal components to retrieve, transform, map, classify, and synchronize applicable Customer Personal Data with Customer's ChartMogul account and to combine it with BillCadence configuration and metadata solely to improve the integration's accuracy and operation. These internal components remain subject to this Addendum, and SaaSync remains responsible for their operation.

C. Data Subject categories

Customer's current, former, and prospective clients, purchasers, subscribers, billing contacts, and other downstream contacts; Customer's personnel and Authorized Users; and individuals identified in Customer Data, Connected Services, support communications, free-text fields, webhooks, or error responses.

D. Customer Personal Data categories

Names; business and billing contact details; email addresses; company and domain information; country, state, city, postal code, and billing address; customer, Account, product, subscription, invoice, credit, payment, transaction, and Connected-Service identifiers; products, descriptions, prices, quantities, discounts, taxes, amounts, currencies, service periods, subscription terms and changes, billing schedules, invoice lines, credits, refunds, payment history, and status information; custom fields; authentication and authorization metadata; BillCadence Output; webhook payloads; error responses; audit and security records; support content; and AI prompts, selected inputs, outputs, classifications, evaluations, embeddings, and other customer-specific AI artifacts.

E. Sensitive data

The Services are not designed for payment-card numbers or security codes, protected health information subject to HIPAA, Social Security or other government identifiers, biometric data, children's data, special-category data, or similarly sensitive data, and Customer must not submit such data unless SaaSync expressly agrees in writing. User-controlled descriptions, webhooks, error messages, or support content could include such data incidentally. Customer is responsible for data minimization, lawful disclosure, and notifying SaaSync when special handling is required.

F. Transfer frequency

Continuous, periodic, event-driven, or one-time, as Customer configures or requests, for the term of the relevant connection or Service.

G. Retention

Active operational Customer Personal Data is generally retained while the relevant Account or Service remains active. More specific operational periods may be stated in the Security page or Subprocessor List. Express deletion, the 45-day inactive-Account period, and residual encrypted backup retention of up to seven days are governed by Section 10. AI provider retention may apply for abuse monitoring, security, or required application functionality as disclosed in the Subprocessor List; SaaSync will configure provider training to be disabled and will minimize persistent provider-side storage where reasonably practicable.

H. Subprocessor Processing

Subprocessors Process Customer Personal Data only to provide the infrastructure, database, authentication, security, monitoring, communication, support, payment, AI, or other functions identified in the current Subprocessor List, for the period necessary to provide the relevant function subject to this Addendum and applicable retention obligations.

Appendix 2: Security Measures

SaaSync maintains administrative, technical, and organizational safeguards designed to protect Customer Personal Data, including:

  1. encryption of data in transit using TLS 1.2 or later;
  2. encryption of production databases, logs, and backups at rest using AES-256-GCM or an equivalently strong industry-standard mechanism;
  3. multifactor authentication for production and administrative access;
  4. least-privilege access limited to authorized personnel who require it to operate, secure, or support the Services;
  5. confidentiality obligations for personnel with access to Customer Personal Data;
  6. daily encrypted backups with an ordinary retention period of seven days;
  7. vulnerability scanning and penetration testing at least annually;
  8. a documented incident-response process addressing investigation, containment, remediation, escalation, notification, and review;
  9. logical separation of Customer Accounts and data;
  10. logging and monitoring designed to identify unauthorized activity and support investigation;
  11. data-minimization, retention, access-control, and deletion practices designed to limit Customer Personal Data to what is reasonably necessary; and
  12. vendor review and written data-protection obligations for Subprocessors.

Additional information is available on the BillCadence Security page. SaaSync may update these measures as permitted by Section 4.1.

Appendix 3: Standard Contractual Clauses

A. Modules

Module Two applies when Customer is a Controller. Module Three applies when Customer is a Processor for a third-party Controller and SaaSync is its subprocessor.

B. Clause selections

For Clause 9(a), Option 2 applies and the notice period is the period in Section 5. The optional language in Clause 11(a) is omitted. For Clause 17, Option 1 applies and the laws of the Republic of Ireland govern. Under Clause 18(b), disputes will be resolved by the courts of the Republic of Ireland.

C. Annex I: parties, transfers, and authority

The data exporter is the Customer identified in the Agreement, Order, or Account records. Its Account-owner or billing-contact email is its notice contact unless it designates another. Customer will provide its legal name, address, and privacy contact upon request. The data importer is SaaSync, LLC, doing business as BillCadence, a United States limited liability company acting as processor or subprocessor. To avoid publishing a residential address, SaaSync's legally valid notice address will be supplied to Customer privately in the applicable Order, signature page, or completed transfer annex and is available fromlegal@billcadence.com.

Appendix 1 completes Annex I.B. The competent Supervisory Authority in Annex I.C is determined under Clause 13 and the GDPR; if unclear, it is the Irish Data Protection Commission. Appendix 2 completes Annex II.

D. Supplemental business terms

Customer's instructions are in Section 2.2. Section 10 governs return and deletion, and SaaSync will provide a deletion certification upon written request. Clause 8.8, Section 5, and applicable safeguards govern onward transfers. Section 8 governs information and audits. Agreement terms concerning confidentiality, liability, indemnification, suspension, and termination apply only to the extent permitted by the Standard Contractual Clauses and do not limit mandatory Data Subject or Supervisory Authority rights.

E. United Kingdom transfers

The UK International Data Transfer Addendum issued by the Information Commissioner is incorporated by reference and modifies the Standard Contractual Clauses where UK Data Protection Laws apply. Its Part 1 tables are completed with this Addendum's information. Either party may end it as permitted by section 19 of the UK Addendum.

F. Switzerland transfers

Where the Swiss FADP applies, references in the Standard Contractual Clauses to member states and the GDPR include Switzerland and the Swiss FADP as required; Data Subjects may sue in their Swiss place of habitual residence; and the competent authority is the Swiss Federal Data Protection and Information Commissioner.

Effective: August 29, 2026

Questions: privacy@billcadence.com

BillCadence

Subscription change management for QuickBooks Online and Xero.

A product by SaaSync.

Legal & Trust

Service AgreementPrivacy PolicyData Processing AddendumSecuritySubprocessors