Data Processing Agreement
Our standard DPA, published so procurement can start from the real text. One core agreement; the module matching your deployment — Cloud SaaS or Self-Hosted — activates automatically. For an executed copy, email sales@taxdocscanner.com.
Template, version of 26 July 2026. The executed agreement between Tax Doc Scanner (“Provider”) and the subscribing organization (“Customer”) controls; this page is for review.
1. Definitions
“NPI” — Nonpublic Personal Information as defined by the Gramm-Leach-Bliley Act, including tax return information within the meaning of 26 U.S.C. §7216. “Customer Data” — documents Customer submits to the software and the data extracted from them. “Security Incident” — confirmed unauthorized access to, or acquisition of, Customer Data held by Provider. “Deployment Type” — Cloud SaaS (Provider-hosted) or Self-Hosted (running entirely in Customer’s environment), as stated on the order.
2. Purpose limitation (all deployments)
Provider processes Customer Data solely to provide the contracted service. Provider will not use Customer Data to train or improve any model, for marketing, analytics, or profiling, and will not sell, rent, or disclose it except as instructed by Customer or required by law. Provider acknowledges that Customer Data may include tax return information subject to §7216 and accepts the corresponding use restrictions.
3. Security controls
3.1 Applicable to Cloud SaaS only
Ephemeral processing. Uploads processed without storage are held in memory only for the life of the request and are not written to disk or logs. Customer Data stored at Customer’s election is encrypted at rest (AES-256-GCM, per-customer keys) and deleted automatically after Customer’s configured retention window (default 72 hours; configurable 1 hour–1 year).
Controls. TLS in transit; multi-factor authentication on interactive logins; tamper-evident security audit logging; per-customer encryption keys with customer-initiated rotation and crypto-shred on termination. Provider’s infrastructure runs on Tier-1 cloud providers; physical data-center security commitments are those of the infrastructure provider’s published terms.
Subprocessors. Google (Gemini API — extraction, paid tier: no model training, processed under Google’s DPA), Stripe (payments), and Provider’s hosting provider. Provider gives 30 days’ notice before adding a subprocessor that will touch Customer Data.
Incident notification. Provider notifies Customer of a Security Incident affecting Customer Data without undue delay and no later than 72 hours after confirmation, with the information Customer reasonably needs for its own obligations (including IRS Stakeholder Liaison and state notifications), and cooperates with Customer’s investigation.
Customer credentials. Customer is responsible for safeguarding its users’ credentials and API tokens. Provider is not liable for access resulting from credentials Customer or its users exposed.
3.2 Applicable to Self-Hosted only
No access to NPI. For Self-Hosted deployments, the software operates entirely within Customer’s environment. Provider does not ingest, collect, view, or store any NPI processed by the software; all data custody, encryption, access control, and logging obligations rest with Customer.
Telemetry isolation. If licensing telemetry is enabled, it contains only quantitative metadata (counts and version identifiers) — never document content, names, or financial values. Its exact schema is documented and inspectable.
Support carve-out. Customer must not transmit NPI through support channels (email, tickets, chat). Documents submitted to demonstrate an issue must be redacted or synthetic. Provider may refuse and delete material received in breach of this section.
4. Audits and evidence
For Cloud SaaS: Provider supplies, on request, its current security documentation, completed questionnaires, and third-party audit reports as they become available. For Self-Hosted: Provider holds no Customer Data, so no data audit applies; build provenance and update integrity documentation are available.
5. Deletion and return
Cloud SaaS: on termination, stored Customer Data is deleted by retention expiry or, on request, immediately by crypto-shred of the customer’s keys. Account records needed for legal and billing obligations are retained as required by law.
6. Term
This DPA is effective for as long as Provider processes Customer Data and survives for data retained under section 5.