Data Processing Agreement
Spend acts as a processor for customer-imported data and documents purposes, security controls, retention, and onward subprocessors.
Pre-launch validation
This document is product structure, not legal advice. Its contractual version must be approved by Yodev's legal adviser and accountant before production payments are enabled.
Scope and instructions
For personal data entrusted to a workspace, the client determines purposes and instructions; the publisher processes it to provide provider inventory and spending tracking. Operations include authorized collection, organization, access, export and erasure. Data subjects may include users, employees, client contacts and provider representatives.
Security and confidentiality
Access is restricted by workspace and role. Connection secrets are encrypted, amounts retain their currency, and audit events exclude repository contents and secrets. Authorized personnel must maintain confidentiality. Incident procedures must support notifying the client without undue delay after discovering a breach and documenting remedial action.
Assistance and subprocessors
The publisher assists with individual requests, security evidence, incidents and necessary impact assessments. Providers, roles and locations appear in the subprocessors document. Change notification, objection rights, transfer safeguards and audit procedures must be agreed in the final contract.
Return and erasure
Owners can export data. A deletion request stops connections and opens a thirty-day export period before business data erasure. Identities shared across workspaces and the publisher's own legal obligations are handled separately. Backup retention must be finalized, and restored backups must reapply erasures.
Publisher identity
The publisher’s complete legal identity must be supplied before commercial launch.
Contact
The professional support address must be confirmed before commercial launch.