Data Processing Addendum

Effective and last updated: July 21, 2026.

This Data Processing Addendum is part of the GlacialBooks Terms of Service when FinArctic LLC processes personal data for a customer. It is effective when the customer accepts the Terms, signs an order form that incorporates it, or both.

1. Parties and scope

This Data Processing Addendum, or DPA, is between FinArctic LLC, called FinArctic, and the organization identified as the customer in the GlacialBooks account or applicable order form, called Customer. It applies only to personal data that FinArctic processes on Customer's behalf as part of Customer Data. It does not govern data for which FinArctic independently acts as controller or business, which is covered by the Privacy Policy.

2. Definitions and priority

Controller, processor, personal data, processing, data subject, supervisory authority, sell, share, business, service provider, and contractor have the meanings in applicable Data Protection Law. Data Protection Law includes the GDPR, UK GDPR, California Consumer Privacy Act as amended by the CPRA, and other privacy or security law applicable to the processing. If this DPA conflicts with the Terms on personal-data protection, this DPA controls. The Standard Contractual Clauses control over a conflicting provision for a restricted transfer.

3. Roles and documented instructions

Customer is the controller or business and FinArctic is the processor or service provider for Customer Data, except where law assigns another role. FinArctic will process personal data only on Customer's documented instructions, including the Terms, account configuration, enabled integrations, authorized-user actions, and support requests, unless law requires other processing. We will notify Customer before legally required processing unless the law prohibits notice. We will promptly inform Customer if an instruction appears to violate Data Protection Law and may pause that instruction while the parties resolve it.

4. Processing details

Item

Description

Subject matter

Processing personal data submitted to or generated through GlacialBooks to provide the contracted bookkeeping service.

Duration

For the term of the Service and the deletion or return period, including limited backup, accounting-record, legal-hold, and compliance retention.

Frequency

Continuous or intermittent according to Customer use, enabled automation schedules, connected-provider events, authorized-user instructions, and support requests.

Nature

Collection, transmission, organization, storage, retrieval, consultation, comparison, extraction, categorization, reconciliation, reporting, support, protection, export, restriction, and deletion.

Purposes

Account operation, bookkeeping, document extraction, reconciliation, reporting, close, support, security, legal compliance, and other documented Customer instructions consistent with the Service.

Data subjects

Customer personnel, customers, prospective customers, vendors, contractors, employees, payees, account holders, professional advisers, and other people represented in Customer Data.

Personal-data categories

Identifiers, contact and professional data, financial-account and transaction data, invoices, bills, receipts, payroll and tax-related summaries, documents, support data, audit events, and organization-specific automation output.

Sensitive data

Financial-account information, authentication information, payroll and tax-related information, and any sensitive data a Customer lawfully submits for the bookkeeping purpose.

5. Customer obligations

Customer will provide lawful instructions; maintain required notices, legal bases, and consents; limit personal data to what is necessary for bookkeeping; configure roles and retention appropriately; respond to data subjects when Customer is responsible; and avoid submitting data prohibited by the Terms. Customer is responsible for determining whether the Service and its configuration are suitable for Customer's legal obligations.

6. Personnel and confidentiality

FinArctic will limit personal-data access to personnel and contractors who need it for the Service, are subject to confidentiality obligations, and receive security and privacy direction appropriate to their access. Production support access must be authorized, time-limited where supported, and logged.

7. Security measures

FinArctic will maintain technical and organizational measures appropriate to the risk and the sensitive financial nature of Customer Data. Current measures include:

Area

Measures

Access

Organization-scoped authorization, role-based permissions, least privilege, support grants, periodic access review, and separate production controls.

Isolation

Forced PostgreSQL row-level security on tenant tables and signed tenant context for organization requests.

Encryption

TLS for application traffic, managed encryption at rest, protected backups, and authenticated encryption for provider credentials.

Secrets

Restricted secret management outside source code, managed identity where supported, rotation and recovery controls.

Integrity

Immutable posted journals, reversing or adjusting corrections, signed provider webhooks, idempotency, and audit history.

Availability

Managed backups, health monitoring, restore procedures, incident response, and production autoscaling.

Application security

Rate limits, request limits, trusted hosts, explicit origins, security headers, dependency and static scans, test and deployment gates.

Monitoring

Structured logs, correlation identifiers, security events, Azure Monitor telemetry, alerting, and defined retention.

Privacy

Data minimization, consent-gated analytics, no targeted advertising, retention automation, deletion workflows, and legal-hold controls.

Customer acknowledges that security measures evolve. We may replace a measure with one that does not materially reduce overall protection. Public detail is also available in the Information Security Policy and Access Controls Policy.

8. Subprocessors

Customer gives general written authorization for the subprocessors on the Subprocessor List. FinArctic will require each subprocessor to protect personal data under written terms that are no less protective for the delegated processing. We will remain responsible for our DPA duties when a subprocessor acts on our behalf. We will provide at least 30 days' advance notice of a new subprocessor that will process Customer Data. Customer may object during that period on reasonable data-protection grounds. The parties will seek a reasonable alternative, and if none is available, either party may terminate the affected Service without penalty for the unused prepaid period.

9. Data-subject requests

Taking into account the nature of processing, FinArctic will provide reasonable assistance for requests to access, correct, delete, restrict, object, or port personal data. Customer should first use available product controls. If a data subject sends us a request about Customer Data, we will refer it to Customer and will not respond substantively unless Customer instructs us or law requires it. Customer remains responsible for the response and legal deadline.

10. Security incidents

FinArctic will notify Customer without undue delay after confirming a Personal Data Breach affecting Customer Data and, where practicable, within 48 hours. Notice will include available information about the nature of the incident, affected data and people, likely consequences, containment, remediation, and a contact for follow-up. Information may be provided in phases. We will take reasonable steps to contain and remediate the incident and assist Customer with legally required notices. Notice is not an admission of fault. Customer is responsible for notifying regulators and data subjects unless law directly requires FinArctic to notify them.

11. Assessments and regulatory cooperation

Taking into account the processing and information available to us, we will reasonably assist Customer with data protection impact assessments, prior consultations, and regulator inquiries that concern the Service. Assistance beyond ordinary documentation may be charged at agreed professional-service rates unless the request results from our breach of this DPA.

12. Return, deletion, and legal retention

During the Service, Customer may export supported data. After termination or a valid deletion instruction, FinArctic will delete or return personal data within the periods in the Data Retention and Deletion Policy unless law requires retention. Accounting evidence, fraud and dispute records, suppression records, backups, and legal holds may remain for the stated period, protected and isolated from ordinary use. Backup copies are deleted through the normal backup cycle.

13. Audit information

On reasonable written request, FinArctic will provide information needed to demonstrate compliance with this DPA, including public policies and relevant control summaries. No more than once per year, unless a confirmed incident or regulator requires more, Customer may request a remote audit by an independent auditor bound by confidentiality. The audit must avoid other customers' data, security-sensitive testing, and unreasonable operational disruption. Customer pays its audit costs unless the audit identifies material noncompliance by FinArctic.

14. International transfers

Customer authorizes processing in the United States and the locations on the Subprocessor List. For personal data transferred from the European Economic Area to a country without an adequacy decision, the 2021 European Commission Standard Contractual Clauses under Decision 2021/914 are incorporated by reference. Module Two applies to controller-to-processor transfers and Module Three applies to processor-to-processor transfers. Clause 7 applies, Clause 9 uses general written authorization with the notice period in this DPA, the optional language in Clause 11 does not apply, Clause 17 uses the law of Ireland, and Clause 18 selects the courts of Ireland. For UK restricted transfers, the UK International Data Transfer Addendum to the EU Clauses applies as legally required. Swiss law adaptations apply to Swiss restricted transfers.

15. Standard Contractual Clauses annexes

For Annex I, Customer is the data exporter and FinArctic LLC is the data importer, with contact details from the account or order form and [email protected] for FinArctic. The parties' roles, processing activities, data subjects, categories, sensitive data, frequency, purpose, duration, and retention are described in Sections 1 through 4 and the Data and Processing Inventory. The competent supervisory authority is determined under Clause 13. For Annex II, the measures are in Section 7. For Annex III, authorized subprocessors are in the Subprocessor List. The parties agree that electronic acceptance of the Terms signs the incorporated Clauses to the extent permitted by law. A countersigned copy is available by contacting [email protected].

16. California service-provider terms

For personal information subject to the CCPA, FinArctic acts as Customer's service provider or contractor. FinArctic will not sell or share that personal information; retain, use, or disclose it outside the direct business relationship or for a purpose other than the business purposes in this DPA; combine it with personal information from another person or source except as permitted by the CCPA; or use it for targeted advertising. FinArctic certifies that it understands and will comply with these restrictions. Customer may take reasonable steps to monitor compliance. FinArctic will notify Customer if it determines it can no longer comply, and Customer may take reasonable steps to stop and remediate unauthorized use.

17. Liability, term, and law

This DPA remains effective while FinArctic processes Customer Data. Liability under this DPA is subject to the Terms unless Data Protection Law or the Standard Contractual Clauses prohibit that limitation. Except where the Standard Contractual Clauses require another law, Georgia law governs this DPA. Changes required by law or to improve protection may be made with notice. A material reduction in Customer's rights requires the notice and acceptance process in the Terms.

18. Contact

Data-protection questions, objections, audit requests, and requests for a countersigned DPA may be sent to [email protected] or [email protected]. Related documents include the Privacy Policy, Data and Processing Inventory, Subprocessor List, and Data Retention and Deletion Policy.