Ledgewave Data Processing Addendum
Effective date:
Important status of this public addendum
This is a baseline addendum for business customers. It becomes part of an agreement only when an order or other signed document identifies the parties, incorporates it, and supplies the deployment-specific hosting, subprocessor, location, transfer, security, return, and deletion details required for the engagement. This page alone is not a completed international-transfer addendum, regulated-industry addendum, or customer-specific security schedule.
1. Scope and incorporation
This Data Processing Addendum (“DPA”) applies when a business customer uses the Ledgewave service to submit personal data and Ledgewave processes that data on the customer's behalf. It supplements the Terms of Service or other agreement governing the service (the “Agreement”). It does not govern personal information Ledgewave handles for its own website, account, billing, security, or business-administration purposes, which is addressed in the Privacy Policy.
2. Parties and roles
“Customer” is the business identified in the applicable account, checkout, or order. “Ledgewave” is the legal entity identified in the applicable checkout record, invoice, order, or direct written notice. If an order does not identify both parties and incorporate this DPA, this public page does not operate as a standalone signed agreement.
For customer personal data, Customer acts as controller, business, or equivalent decision-maker, and Ledgewave acts as processor, service provider, or equivalent recipient, to the extent those concepts apply. Each party remains independently responsible for personal data it handles for its own purposes.
3. Documented instructions
Customer instructs Ledgewave to process customer personal data only as reasonably necessary to provide, secure, support, maintain, and improve the purchased service; follow Customer's use and configuration of the service; comply with the Agreement; and follow additional lawful written instructions agreed by the parties. If an instruction would require materially different services or create legal or security concerns, the parties must agree on scope, feasibility, and fees before that processing begins.
4. Processing details
- Subject matter: provision and support of the Ledgewave receivables workflow and cash-forecasting service purchased by Customer.
- Duration: the subscription term and any limited post-termination period required for return, deletion, backup cycling, dispute preservation, or law, as documented for the applicable deployment.
- Nature and purpose: collecting, receiving, organizing, storing, retrieving, displaying, transmitting, analyzing, deleting, and otherwise processing data as needed to provide the purchased features and support Customer's documented instructions.
- Data subjects: Customer personnel and authorized users; Customer's customers, payers, prospects, and business contacts; and other individuals whose information Customer lawfully submits.
- Data categories: business contact and account information, invoice and receivables information, billing schedules, collection notes and communications, promise dates, forecast inputs, workflow status, user activity, and other data selected by Customer.
- Sensitive data: not intended to include payment card numbers, Social Security numbers, protected health information, biometric data, or other specially regulated or highly sensitive data unless a written order expressly authorizes and configures the service for that data.
5. Customer obligations
Customer is responsible for the lawfulness, accuracy, and quality of customer personal data; providing required notices; obtaining required rights, permissions, and consents; configuring access; limiting data to what is necessary; and ensuring its instructions comply with law. Customer must not instruct Ledgewave to process data the service has not been agreed and configured to handle.
6. Confidentiality and security
Ledgewave will limit processing of customer personal data to authorized purposes and will require people authorized to process it to protect its confidentiality. Ledgewave will maintain safeguards appropriate to the risk, service, and applicable law. The public Security Overview is intentionally not a detailed security schedule and does not claim a certification or particular production control. If Customer requires specified controls, audit evidence, data location, recovery objectives, or security standards, those requirements must be documented in an order or signed security addendum before Customer relies on them.
7. Data-subject and compliance assistance
Taking into account the nature of the processing and information reasonably available, Ledgewave will provide assistance required by the Agreement or applicable processor law for Customer to respond to verified data-subject requests, security obligations, impact assessments, or regulator consultations. Customer remains responsible for evaluating and responding to requests as controller. Additional work outside standard service functionality may require a separate scope.
8. Personal data incidents
If Ledgewave confirms unauthorized access to customer personal data for which applicable law or the Agreement requires notice, Ledgewave will notify Customer without undue delay and provide reasonably available information relevant to Customer's response. This page does not promise a fixed notification period or incident-response service level. The customer contact, notice method, allocation of investigation costs, and any shorter contractual deadline must be stated in the applicable order or security addendum.
9. Subprocessors
Customer generally authorizes Ledgewave to use service providers to support the service, subject to applicable law and the Agreement. The public Subprocessor Disclosure lists website providers and explains how to obtain deployment-specific product vendors. Before regulated customer personal data is processed, the parties must document the relevant vendors, locations, functions, and any notice or objection process required by law or contract. This DPA does not create an unstated advance-notice period.
10. International transfers
Customer must confirm the hosting and processing locations for its deployment. If a restricted transfer mechanism is required, the parties must incorporate the applicable mechanism and any necessary supplementary terms before the transfer. This public DPA does not state that Standard Contractual Clauses, the UK Addendum, a data-privacy framework, or another mechanism has been executed.
11. Return and deletion
At the end of the service, Ledgewave will return or delete customer personal data as required by the Agreement and applicable law, subject to documented export functionality, backup cycles, legal preservation, and technical feasibility. The applicable order or deployment schedule must identify the export method, customer action required, deletion timing, backup treatment, and any retrieval fees. Customer should maintain its own source records and not rely on the service as its only copy unless the order expressly says otherwise.
12. Information and review
Ledgewave will provide information reasonably necessary to demonstrate compliance with binding processor obligations, subject to confidentiality, security, scope, and frequency protections agreed by the parties. This public DPA does not grant unrestricted system access, penetration-testing rights, or an on-site audit. Any audit procedure, third-party report, cost allocation, and remediation process must be documented in the applicable order or signed addendum.
13. Required disclosure
Ledgewave may process or disclose customer personal data where required by law. Where legally permitted and applicable, Ledgewave will inform Customer before acting on a compulsory instruction and will limit disclosure to what is required.
14. Order of precedence and liability
This DPA controls over conflicting general data-processing language in the Agreement for customer personal data. A signed, customer-specific DPA or transfer addendum controls over this public version. Liability under this DPA is subject to the limitations and exclusions in the Agreement unless a signed document states otherwise or applicable law prohibits the limitation.
15. Contact and completion
Submit DPA questions through the Contact page with DPA Request at the start of the message. Before regulated personal data is accepted, the parties must complete the legal identity, notice contact, product vendor list, security schedule, deletion schedule, processing locations, and transfer terms required for the actual deployment.