RRessura

Legal

Data Processing Agreement

Effective September 5, 2026

This Data Processing Agreement (DPA) forms part of the Terms of Service governing Customer's use of Ressura. Customer is the person or organization for which an account is created. Customer accepts this DPA through an account-creation process that presents it for acceptance. The person creating the account must have authority to bind Customer. No separate signature or countersignature is required.

Scope and roles

Customer Personal Data means personal data Ressura processes on Customer's behalf to provide the service, including personal data in submitted documents, connected-system records, and resulting outputs. Customer acts as controller and Ressura as processor. If Customer acts for another controller, Customer is the processor and Ressura is its subprocessor; Customer must have authority to issue instructions and authorize subprocessors on that controller's behalf.

Data Protection Laws means the privacy and data protection laws applicable to this processing, including, where applicable, the EU GDPR, UK GDPR and Data Protection Act 2018, Swiss Federal Act on Data Protection, and applicable United States state privacy laws, including the California Consumer Privacy Act as amended (CCPA). These references do not make a law applicable where it would not otherwise apply.

Limited business contact and billing information processed by Ressura as an independent controller to administer its own customer relationship or meet its own legal obligations is covered by the Privacy Policy. This does not authorize repurposing Customer's documents, connected-system records, or outputs.

Processing details

The subject matter is the processing of financial documents and connected-system records for invoice validation, financial controls testing, document processing, reconciliation, exception detection, and evidence-backed reporting. Processing includes collection, import, organization, storage, extraction, classification, matching, calculation, analysis, generation and display of findings and source references, authorized export, and deletion. Authorized human access may occur for support and security.

Processing takes place as initiated by Customer and as needed for enabled ongoing integrations, for the duration of the service and the limited return, deletion, and legally required retention periods below. Its purposes are to deliver Customer-requested analysis, administer workspace access, provide support, and maintain the security, availability, and reliability of the service supplied to Customer.

Data subjects may include Customer's users, employees, contractors, customers, suppliers, payees, business contacts, and other individuals lawfully included in the records. Data may include names, contact details, user identifiers, roles, signatures, invoice and contract details, transaction amounts and dates, payment references, bank-account and tax details in permitted financial records, correspondence, metadata, derived findings, and technical usage and diagnostic information processed on Customer's behalf.

Special-category data under GDPR Article 9, criminal-offence data, protected health information requiring a HIPAA business associate agreement, biometric identifiers, children's data, and full payment-card credentials require a separate written agreement and appropriate safeguards before submission. Ordinary financial information may still be sensitive personal information under applicable law and receives the protections that law requires.

Customer responsibilities

Customer determines the purposes of processing and is responsible for lawful collection, required notices and lawful bases, the accuracy of the data, authority to connect third-party systems, and the lawfulness of its instructions. Customer must submit only reasonably necessary data, protect credentials, configure access appropriately, and keep registered users' email addresses current. Customer is responsible for routing notices received by those users to the appropriate people in its organization.

Customer reviews findings and decides any resulting financial, employment, contractual, or other action. Ressura provides findings and supporting evidence, not a statutory financial-statement audit or an independent authorization to make legally significant decisions about individuals.

Instructions and permitted use

Ressura processes Customer Personal Data only on documented instructions, including for international transfers, unless law requires otherwise as permitted by Data Protection Laws. The Terms of Service, this DPA, Customer's configuration and use of the service, and further accepted written instructions constitute those instructions. Ressura may choose technical and organizational means, including providers, but may not independently expand processing purposes or materially expand data categories.

Ressura will immediately inform Customer if it believes an instruction infringes Data Protection Laws and may suspend the affected processing while the issue is resolved. Ressura will notify Customer before legally required processing that departs from its instructions unless legally prohibited. Such processing must also satisfy international-transfer requirements.

Authorized document-processing and artificial-intelligence providers may be used to deliver the service. Ressura will not use Customer Personal Data, or permit a subprocessor to use it, to train or improve general-purpose or cross-customer artificial-intelligence models. Any additional use requires a separate written agreement and compliance with Data Protection Laws; general subprocessor authorization alone does not authorize it.

Confidentiality and security

Authorized personnel must be bound by contractual or statutory confidentiality obligations and have access only as needed for permitted purposes. Ressura will maintain appropriate technical and organizational measures, taking account of the nature of the processing, risks to individuals, state of the art, and implementation costs, including measures required by GDPR Article 32 where applicable.

These measures include least-privilege access, individually attributable workforce accounts, multi-factor authentication for privileged production access, access review and revocation, logical customer separation, encryption in transit over public networks and at rest in production storage and backups, and restricted access to keys and credentials.

Measures also include security logging and monitoring, risk-based vulnerability remediation, controlled production changes, protected backups and recovery testing, incident-response procedures, personnel instruction, subprocessor assessment, data minimization, lifecycle controls, and regular assessment of security effectiveness. Ressura may update measures without materially reducing overall protection or breaching an expressly agreed requirement.

General subprocessor authorization

Customer grants Ressura general written authorization, through electronic acceptance of this DPA, to use subprocessors, including affiliates and downstream processors, for hosting, storage, authentication, document processing, artificial-intelligence inference, communications, monitoring, support, and service analytics performed on Customer's behalf. Ressura may add, replace, or discontinue subprocessors without a separate amendment, signature, or individual prior consent, subject to the notice requirements and safeguards below.

Authorization applies only to disclosed providers and processing relevant to Customer's service, not unidentified recipients or unrelated purposes. Ressura will make available a current subprocessor register identifying legal names, processing purposes, data categories, processing and relevant remote-access countries, and applicable transfer safeguards. Contact Ressura using the details below to obtain the register and relevant processing-location information before providing Customer Personal Data.

Subprocessor changes and email notices

Ressura will update its subprocessor register when adding or replacing a provider or materially expanding its processing purpose, data access, or processing countries. Ressura will notify Customer by email to any one or more users registered to Customer's account no later than 90 calendar days after the change takes effect, except where advance or earlier notice is required. The notice will identify the change, effective date, and relevant register information, directly or through a link. No separate notice subscription is required. Updating a webpage alone does not replace the email notice.

Where Data Protection Laws, including GDPR Article 28(2), or an applicable transfer instrument require notice of an intended change and an opportunity to object, Ressura will instead notify Customer sufficiently in advance to provide a meaningful opportunity to object and discontinue the affected service before processing begins. Any required minimum advance-notice period applies. The 90-day period does not permit retrospective notice in those circumstances. Removal without replacement or expanded processing requires only a register update.

Stopping use and objections

If Customer does not agree to a lawful subprocessor change that complies with this DPA, its sole contractual recourse for that change is to stop using the service and terminate the affected service or close its account, through available account controls or by contacting Ressura. Ressura is not required to negotiate an alternative provider or maintain a customer-specific configuration. Fees and refunds remain governed by the Terms of Service, any applicable order, and applicable law; this DPA creates no additional refund entitlement or termination penalty.

Stopping interactive use alone does not terminate storage or enabled integrations. Customer must also request termination or account closure. Return and deletion are governed by the provisions below.

Where advance-notice requirements apply, Customer may object on data-protection grounds before proposed processing begins. If Customer maintains its objection, Ressura will allow discontinuation before the proposed provider receives Customer Personal Data and suspend affected processing if necessary. Retained data will not be sent to that provider during return and deletion. An objection does not restrict provider choices for other customers. These provisions do not limit remedies for a breach, non-waivable legal rights, or rights under transfer instruments. Continued use does not waive those rights or constitute data-subject consent.

Urgent changes and provider safeguards

For an urgent change needed to address a material security risk, comply with law, or replace a provider that unexpectedly ceases service, Ressura will give as much advance notice as reasonably possible and explain the urgency. Shorter notice is permitted only where consistent with Data Protection Laws and transfer instruments, preserving a meaningful opportunity to object where required. Otherwise Ressura must obtain specific written authorization or suspend affected processing until the requirements can be met.

Before allowing processing, Ressura will assess each subprocessor's guarantees and impose the same applicable data protection obligations through a binding written agreement, including purpose limitation, confidentiality, security, breach reporting, assistance, return or deletion, and lawful transfers. Ressura remains fully responsible to Customer for performance of those obligations and will require equivalent protections and applicable authorization and notice requirements throughout downstream processing chains.

A service independently engaged by Customer, such as its Google Drive or accounting provider, is not a Ressura subprocessor merely because Customer connects it. Ressura remains responsible for its own processing through that connection. If Ressura separately engages the provider to process data on its behalf, the subprocessor requirements apply.

Individual rights and compliance assistance

Taking account of the nature of processing and available information, Ressura will assist Customer through appropriate technical and organizational measures, insofar as possible, with applicable individual rights, security obligations, breach assessments and notifications, data protection impact assessments, and prior consultations with authorities, including GDPR Articles 32 through 36 where applicable. Requests received directly will be promptly forwarded and answered substantively only on Customer's instructions or as required by law.

The parties will cooperate to meet legal deadlines. Reasonable, previously disclosed and agreed fees may apply to assistance beyond ordinary service capabilities where legally permitted, but not to remedy Ressura's own breach. Fee disputes will not delay legally required assistance.

Personal data breaches

A Personal Data Breach is a security breach leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data. Ressura will notify Customer without undue delay after awareness, including for a breach at a subprocessor, and within any shorter legally required period. Ressura will not wait for a completed investigation. The 90-day change-notice period does not apply.

Notice will include available information about the nature of the breach, affected data and approximate numbers of individuals and records, likely consequences, containment and remediation measures, and a contact for further information. Updates may follow in stages without undue further delay. Ressura will take reasonable containment and remediation measures, preserve relevant evidence, and assist Customer. Customer determines notices to individuals and authorities unless Ressura has a separate legal obligation. Breach notice is not an admission of liability.

Information and audits

Ressura will provide information necessary to demonstrate compliance and allow and contribute to audits, including inspections, by Customer or its mandated independent auditor. Available documentation, relevant assessment reports, and written responses will ordinarily be used first. Where insufficient, reasonably scoped inspections may take place on reasonable notice during business hours, subject to confidentiality and safeguards that protect other customers and system security without preventing meaningful verification.

Routine audits ordinarily occur no more than once in 12 months. That limit and ordinary notice requirements do not apply where a breach, reasonable evidence of noncompliance, a regulator, law, or transfer instrument requires additional or urgent review. Ressura will cooperate with competent authorities. Each party bears routine audit costs unless otherwise agreed or legally required; Ressura bears reasonable additional audit costs resulting from its material breach.

International transfers

Processing may occur in disclosed countries, subject to expressly agreed residency restrictions and Data Protection Laws. Subprocessor authorization is not itself an international-transfer mechanism. Before a transfer requiring safeguards begins, the parties must establish a valid mechanism, such as an applicable adequacy decision or duly completed and binding standard contractual clauses, together with required assessments and supplementary measures. The same requirements apply to onward transfers and relevant remote access.

Where required and eligible, transfers from Customer to Ressura will use the European Commission standard contractual clauses under Decision (EU) 2021/914, Module Two for controller-to-processor or Module Three for processor-to-processor transfers, with completed particulars and a legally sufficient advance-notice period. Required UK transfers will use a completed UK Addendum or International Data Transfer Agreement; Swiss transfers will include required adaptations. Electronic acceptance may be used where permitted, without a separate handwritten signature.

This DPA alone does not complete those instruments. Affected transfers must not begin, or must be suspended, if a required mechanism is absent, invalid, or no longer provides required protection. Mandatory transfer terms prevail over conflicting service terms or this DPA.

Return and deletion

Ressura will carry out lawful return and deletion instructions during the service through available functionality or reasonable assistance. At termination or expiry, Customer may choose return in a reasonably usable format followed by deletion of remaining copies, or deletion without return. Customer may elect return within 30 calendar days; otherwise Customer instructs deletion.

Return and deletion from active systems will be completed within 60 calendar days after termination or expiry, or sooner where required by law or a transfer instrument. Backup copies will be isolated from ordinary use and deleted within 90 calendar days after termination or expiry. Deletion instructions will be reapplied to restored backups before ordinary processing resumes. Ressura will require subprocessors to comply and confirm completion in writing on request.

Data may be retained only to the extent and for the period legally required and permitted under Data Protection Laws and transfer instruments. Ressura will identify the requirement unless legally prohibited, restrict processing to that purpose, and delete when retention is no longer required. This DPA continues to protect retained data. Earlier legally required deletion takes precedence.

United States state privacy terms

Where applicable, Ressura acts as a service provider or contractor under the CCPA or a processor under other state privacy laws. Customer discloses personal information only for the limited processing purposes described above. Ressura will not sell or share Customer Personal Data as those terms are defined by the CCPA, use it for cross-context behavioral or targeted advertising, or retain, use, or disclose it outside the direct business relationship or specified purposes except as expressly permitted by applicable law. Combining it with personal information from another person or Ressura's own interactions is prohibited except as permitted by the CCPA.

Ressura will comply with applicable CCPA obligations, provide the same level of privacy protection required by that law, and notify Customer if it can no longer comply. Customer may take reasonable and appropriate steps to verify compliant processing and, on notice, stop and remediate unauthorized use. Ressura certifies that it understands and will comply with these restrictions. Subcontracting must satisfy this DPA and applicable statutory requirements.

Updates and general terms

This DPA takes precedence over conflicting service terms concerning Customer Personal Data, subject to mandatory transfer instruments. Liability limitations in the Terms of Service apply to the extent permitted by law, without limiting non-waivable liability, individual rights, supervisory powers, or rights under transfer instruments.

Ressura may update this online DPA by publishing a revised version with its updated date and notifying one or more registered account users by email within 90 calendar days after publication. Updates take effect only as permitted by the applicable agreement and law. Where advance notice or affirmative acceptance is required, Ressura will provide it before applying the amendment. Customer may stop using the service and terminate or close its account if it disagrees. Updates cannot retroactively authorize processing, waive accrued claims, remove mandatory protections, expand purposes without documented instructions, or override transfer instruments.

Contact

For DPA questions, subprocessor information, objections, or account-closure and data requests, contact contact@ressura.com. Customer authorizes change notices to any one or more users registered to its account at the time of sending. Breach notices will instead go directly to Customer's designated security contact, if provided, or otherwise a registered account administrator, within the breach-notification period above.

PrivacyTermsSecurityDPA