Legal

Data Processing Agreement

The processing terms, responsibilities, and safeguards that apply when Paythos processes Customer Personal Data.
Version 1.1 · Last updated 19 July 2026

This Data Processing Agreement, including its schedules (the DPA), forms part of the agreement governing a customer’s use of Paythos (the Agreement). It applies when Paythos processes Customer Personal Data on the Customer’s behalf. By using the Services, the Customer enters into this DPA on behalf of itself and any authorised affiliates that use the Services.

1

Definitions

Customer means the organisation that has entered into the Agreement. Customer Data means data submitted to or generated through the Services for the Customer. Customer Personal Data means Personal Data contained in Customer Data. Data Protection Laws means the UK GDPR, Data Protection Act 2018, Privacy and Electronic Communications Regulations 2003, and other data protection law applicable to the processing. Personal Data, Controller, Processor, Data Subject, Processing, and Personal Data Breach have the meanings given by applicable Data Protection Laws. Subprocessor means another processor engaged by Paythos to process Customer Personal Data.

2

Roles and scope

The Customer is the Controller and Paythos is the Processor of Customer Personal Data, except where the Customer acts as a Processor, in which case Paythos is its Subprocessor. Each party will comply with the obligations applicable to it under Data Protection Laws.

The Customer determines the purposes and means of processing Customer Personal Data, is responsible for the lawfulness and transparency of its collection and instructions, and will not instruct Paythos to process data in breach of law. Paythos remains an independent Controller for account administration, billing, support, security, sales, and website data as described in the Privacy Policy.

3

Paythos obligations

Documented instructions

Paythos will process Customer Personal Data only to provide, secure, support, and improve the Services in accordance with the Agreement, this DPA, the Customer’s configuration and use of the Services, and other documented instructions agreed by the parties. Paythos will inform the Customer if it believes an instruction infringes Data Protection Laws, unless prohibited from doing so.

Confidentiality

Paythos will ensure that personnel authorised to process Customer Personal Data are subject to an appropriate duty of confidentiality and receive access only where needed for their responsibilities.

Security

Paythos will maintain appropriate technical and organisational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. The current measures are described in Schedule 2 and on the Security page.

Data-subject requests

Taking into account the nature of the processing, Paythos will provide reasonable assistance through appropriate technical and organisational measures so the Customer can respond to requests to exercise data-subject rights. If Paythos receives a request relating to Customer Personal Data, it will direct the requester to the Customer unless legally required to respond.

Compliance assistance

Taking into account the nature of processing and information available to Paythos, Paythos will provide reasonable assistance with the Customer’s obligations concerning security, breach notification, data protection impact assessments, and prior consultation under Data Protection Laws.

Deletion and return

On termination or expiry of the Services, and at the Customer’s choice where technically available, Paythos will delete or return Customer Personal Data, except to the extent retention is required by law. Deletion from backups may occur through the ordinary backup lifecycle, during which retained data remains protected and unavailable for ordinary use.

4

Personal Data Breaches

Paythos will notify the Customer without undue delay after becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data. The notification will describe the nature of the breach, affected data and people where known, likely consequences, and measures taken or proposed, to the extent that information is available. Paythos may provide information in phases and will take reasonable steps to contain, investigate, and mitigate the breach. Notification is not an acknowledgement of fault or liability.

5

Subprocessors

The Customer gives Paythos general authorisation to engage Subprocessors needed to provide the Services. Paythos will impose data-protection obligations on each Subprocessor that are materially protective of Customer Personal Data in the context of the services provided and remains responsible for its Subprocessors to the extent required by Data Protection Laws.

Current core Subprocessors are listed in Schedule 3. Paythos may update that list as the Services change. Where required by law, Paythos will provide reasonable advance notice of a new Subprocessor. A Customer with a reasonable data-protection objection must notify Paythos promptly; the parties will work in good faith on a commercially reasonable resolution. If no resolution is available, the Customer may stop using the affected feature or terminate the affected Services.

6

International transfers

Paythos will not transfer Customer Personal Data from the United Kingdom to a country that is not covered by UK adequacy regulations unless an appropriate safeguard or permitted derogation applies. Where required, the parties incorporate the then-current UK International Data Transfer Agreement or UK Addendum to the EU Standard Contractual Clauses, with the Customer acting as exporter and Paythos acting as importer. Paythos may rely on an equivalent lawful transfer mechanism and will implement supplementary measures where appropriate.

7

Information and audits

Paythos will make available information reasonably necessary to demonstrate compliance with this DPA. The Customer may request an audit no more than once in any 12-month period, unless required by a regulator or following a relevant Personal Data Breach. Audits must use an agreed scope, protect other customers and Paythos confidential information, avoid disruption, and, where possible, begin with documentation and remote evidence. The Customer bears its audit costs and reimburses Paythos for unreasonable or excessive assistance.

8

Liability, priority, and changes

The limitations and exclusions of liability in the Agreement apply to this DPA to the extent permitted by law. If this DPA conflicts with the Agreement on the processing of Customer Personal Data, this DPA prevails. This DPA terminates when Paythos no longer processes Customer Personal Data, subject to provisions that by their nature survive. Paythos may update this DPA where necessary to reflect changes in law or the Services, provided the update does not materially reduce data-protection commitments during an active subscription without reasonable notice.

Schedule 1

Details of processing

Subject matter

Provision of the Paythos accounts-payable automation and payment-governance platform.

Duration

For the term of the Agreement and a limited period afterwards for return, deletion, backups, security, dispute resolution, or legal retention.

Nature and purpose

Collection, receipt, hosting, storage, organisation, extraction, invoice and GL-code classification, reviewed account-code proposal, comparison, risk analysis, approval routing, transmission to customer-selected integrations, payment orchestration, reporting, support, security, audit recording, retrieval, export, and deletion.

Data subjects

Customer users and personnel; approvers; supplier and vendor contacts; sole traders; payees; customer contacts shown on invoices; and other people whose data the Customer submits.

Personal data

Names, business contact details, roles, identifiers, authentication and audit data; invoice and purchase details; postal addresses; VAT and tax identifiers; supplier bank and remittance information; payment references and status; approval records and comments; integration identifiers; device, IP, and usage data; and document content submitted by the Customer.

Special-category data

Not intentionally required by Paythos. The Customer must not submit it unless necessary, lawful, and expressly permitted under the Agreement.

Frequency

Continuous or as initiated by users, scheduled synchronisations, configured workflows, and provider events.

Schedule 2

Technical and organisational measures

  • HTTPS for production application traffic and provider API connections.
  • Managed authentication and server-side validation of protected requests.
  • Role-based access for Super Admin, Admin, Approver, and Viewer roles.
  • Tenant host validation, organisation-scoped queries, and PostgreSQL row-level security policies.
  • Private invoice object storage with organisation-folder access policies and upload restrictions.
  • AES-256-GCM envelope encryption for stored accounting-integration credentials.
  • Deployment secrets stored outside source code and separated public and privileged keys.
  • Signature or secret verification for supported provider webhooks and idempotency for supported payment operations.
  • Supplier bank-detail change holds requiring verification before affected payment workflows continue.
  • Organisation-scoped audit records for material platform actions and Sentry-based error and performance monitoring where configured.
  • Logical separation of local development and hosted production configuration, dependency testing, and controlled database migrations.
  • Processes for access removal, incident investigation, customer support, data export, and deletion requests.

These measures may evolve as long as the overall protection of Customer Personal Data is not materially reduced. See the current Security page.

Schedule 3

Core Subprocessors

ProviderPurposeData involved
SupabaseAuthentication, database, private file storageAccount, organisation, invoice, workflow, payment, integration, and audit data
VercelApplication hosting and deliveryApplication requests, technical data, and data processed by hosted functions
OpenAIInvoice extraction, GL-code suggestion, and other AI-assisted featuresInvoice documents or text, extracted invoice and vendor context, relevant organisation GL codes, and prompts required for the requested feature
NorthflankHosting Paythos machine-learning servicesOrganisation identifier, structured risk features, spend-request context, and eligible approver identifiers
ResendTransactional and support email deliveryNames, email addresses, workspace details, and email content
SentryError and performance monitoringTechnical diagnostics and limited request or user context where configured

Stripe acts as a payment provider for Paythos subscription billing and may act as an independent controller for payment data. Google Analytics is used on public pages only after analytics consent. Customer-selected accounting and payment integrations are enabled under the Customer’s direction and may be processors engaged directly by the Customer rather than Paythos Subprocessors.

Contact

Data protection enquiries

Questions, rights requests, or notices under this DPA should be sent to hello@paythos.tech. Customers should retain a copy of the version applicable to their Agreement and obtain legal advice where required.