Founding 10 · First 10 customers lock in $99/mo for 12 months.
Legal

Data Processing Addendum

Last updated: August 15, 2026 · GST-DPA-001 v1.0

This DPA is part of the Cinch Terms of Service. It applies when GullStack Trust processes Customer Data as a processor / service provider. If a signed agency data addendum or a BAA/QSOA applies to the same data, that signed paper controls to the extent of conflict.

1. Definitions

Terms in the Cinch Terms have the same meaning here. Customer Data means personal information of the Customer’s End Users, staff, and other individuals that we host in the Customer’s tenant. Security Incident is defined in the Terms (confirmed unauthorized access, acquisition, disclosure, or loss of Customer Data in our possession; unsuccessful probes are excluded).

2. Roles

Customer is the controller / business. GullStack Trust is the processor / service provider. We will process Customer Data only to provide the Service, on the Customer’s documented instructions (the Terms, this DPA, product configuration, and written directions), and as required by law (with notice where lawful).

We will not sell Customer Data, will not share it for cross-context behavioral advertising, and will not retain, use, or disclose it outside the business purpose of providing the Service, except as the Terms allow for security, law, and de-identified / aggregated statistics. Consumer financial data obtained through Plaid is never sold, rented, or monetized.

Customer is responsible for the lawfulness of its instructions, End User notices, consents, COPPA, TCPA, employment records, and its own breach-notification duties.

3. Customer instructions

Product configuration, API calls, and admin actions by Customer’s users are instructions. We may refuse an instruction that we reasonably believe is unlawful or would compromise tenant isolation or security, and we will promptly say why.

4. Confidentiality and personnel

We will ensure persons authorized to process Customer Data are bound by confidentiality and are limited to need-to-know access.

5. Security

We maintain the program described in Terms §16 and our Information Security Policy. Commitments are limited to that program. We do not warrant SOC 2, pen tests, 24/7 SOC, or universal End User 2FA.

6. Subprocessors

Customer authorizes our current subprocessors:

  • Vercel (hosting, edge, Blob, analytics)
  • Neon (database)
  • Stripe (payments)
  • Plaid (optional bank recon)
  • SendGrid (email)
  • SignalWire or a successor (optional SMS/voice)
  • AI inference vendors used to provide in-product AI features (Anthropic, xAI, or similar, typically via a gateway)
  • Object storage (Vercel Blob / Cloudflare R2 as configured)

We will impose confidentiality and security obligations consistent with this DPA on subprocessors that process Customer Data, and we remain responsible for their processing within our control. A platform account Customer owns is Customer’s vendor, not a subprocessor. Material additions will be reflected on this page or the Privacy Policy. Customer may object on reasonable privacy grounds within 15 days; the exclusive remedy is to terminate the affected connector or the Service under the Terms.

7. Assistance

Taking into account the nature of processing, we will provide reasonable assistance for End User rights requests (we will point End Users to Customer unless law requires a direct response), security questionnaires that can be answered from existing documents, and Security Incident cooperation. On-site audit or a paid penetration test is available only under a separate paid Enterprise SOW and NDA.

8. Incidents

We will notify Customer as stated in the Terms: without undue delay and within five (5) business days after confirmation. Notification is not an admission. Customer decides End User and regulator notice unless law says otherwise.

9. Return and deletion

On termination or written request, we will delete or return Customer Data within 30 days as stated in the Terms, with backup, legal-hold, and billing/security exceptions.

10. International

Processing is in the United States unless a later writing says otherwise.

11. Special categories

No PHI or 42 C.F.R. Part 2 records unless a BAA and, if applicable, a QSOA is fully executed. No PAN/CVV stored by us. SMS, ads, and pixels: Customer owns consent and campaign legality (Terms §8).

12. Liability

Liability under this DPA is subject to the disclaimer, indemnity, and single aggregate cap in the Terms. There is no separate or stacked cap for data-protection claims.

13. CPRA service-provider terms

For California (and similar state laws): we are a service provider / processor; we will comply with applicable obligations and provide the level of privacy protection the statute requires of a service provider; we will notify Customer if we determine we can no longer meet those obligations; Customer may take reasonable and appropriate steps to stop unauthorized use, including termination as the Terms allow. We will not combine Customer Data from this Customer with personal information from another customer except as permitted for security or as the statute allows for a service provider.