Last updated: August 28, 2026
This Data Processing Addendum ("DPA") is part of the Terms of Service between SaaSy Solutions LLC ("Processor") and the customer that accepts those Terms ("Controller"). It applies when Processor handles personal data on Controller's behalf to provide the Service.
Controller determines the purposes of processing. Processor processes personal data only on documented instructions from Controller, which include the Terms, this DPA, and configuration the Controller sets in the Service. Processor does not process protected health information and the Service is not HIPAA-ready.
Account identifiers, workspace membership, CRM and operational records the Controller stores, billing metadata, support communications, and (only if the Controller connects a bank) account-holder identity, balances, and transaction history obtained through Plaid. Processor does not receive raw bank credentials. Those stay in Plaid Link.
Controller authorizes the processors listed at hellosaasy.ai/subprocessors. Processor remains responsible for their performance. Processor will give 30 days' notice before adding a subprocessor that receives Customer Data, except for emergency security replacements.
Processor uses TLS in transit, access control with MFA for production consoles, tenant isolation on queries, and encryption at rest for designated secret and bank-transaction fields. A personal-data breach that is likely to affect Controller will be notified without undue delay and, where feasible, within 72 hours of confirmation.
Processor will assist Controller with data-subject requests that cannot be completed in-product. After a workspace is cancelled, Customer Data remains restorable for 30 days, then is deleted or anonymized, with backups rolling off within 90 days. Controller may request a written security summary once per 12 months.
Processing occurs in the United States. Where a restricted transfer requires one, the parties rely on the EU Standard Contractual Clauses (module 2) and the UK Addendum, populated with the details in this DPA and the subprocessor list. This DPA lasts for the term of the Terms and survives until Processor has deleted the Customer Data it holds.
Need a countersigned copy? Email legal@hellosaasy.ai from the workspace owner address. Print this page to produce the PDF.