1. This Addendum
This Data Processing Addendum (“DPA”) forms part of the agreement between BaselineZero, LLC (“BaselineZero”) and Customer for the Service (the “Agreement”). It applies to the extent BaselineZero processes Personal Data contained in Customer Content on Customer’s behalf. If this DPA conflicts with the Agreement, this DPA controls for data protection matters.
2. Definitions
“Personal Data”, “controller”, “processor”, “data subject”, “processing”, and “supervisory authority” have the meanings in applicable Data Protection Laws. “Data Protection Laws” means all laws applicable to the processing of Personal Data under the Agreement, meaning applicable U.S. federal and state privacy laws, as amended. The Service is operated under U.S. law only. “Customer Content” means data submitted to the Service by or for Customer as described in the Agreement. “Subprocessor” means a third party engaged by BaselineZero to process Personal Data on Customer’s behalf.
3. Roles and scope
For Personal Data in Customer Content, Customer is the controller (or a processor for its own clients) and BaselineZero is a processor (or subprocessor). Details of the processing are set out in Annex I. For account, billing, and usage data described in our Privacy Policy, BaselineZero is an independent controller; that processing is outside this DPA.
4. Instructions
BaselineZero will process Personal Data only on Customer’s documented instructions, including as given through the Service’s settings and features, as described in the Agreement, and as required by law (in which case BaselineZero will inform Customer unless the law prohibits it). BaselineZero will promptly inform Customer if, in its opinion, an instruction infringes Data Protection Laws. Connected Services operate under Customer’s direction and Customer’s own agreements with those providers; instructing the Service to read from or write to a Connected Service is a documented instruction.
5. Confidentiality and personnel
BaselineZero ensures that persons authorized to process Personal Data are bound by confidentiality obligations and receive appropriate training, and that access is limited to what each role requires.
6. Security
BaselineZero implements and maintains the technical and organizational measures described in Annex II, and may update them provided the protection level does not materially decrease. Taking into account the nature of the processing, BaselineZero will assist Customer in meeting its own security, breach notification, impact assessment, and consultation obligations, with information reasonably available to it.
7. Subprocessors
Customer generally authorizes the Subprocessors listed in Annex III. BaselineZero will give at least 30 days’ notice before adding or replacing a Subprocessor (by email or in-product notice). If Customer reasonably objects on data protection grounds and the parties cannot resolve the objection, Customer may terminate the affected portion of the Service with a pro-rata refund of prepaid fees.
BaselineZero imposes data protection obligations on each Subprocessor that are no less protective than this DPA and remains responsible for their performance. Connected Services chosen and connected by Customer are not Subprocessors.
8. Data subject requests
Taking into account the nature of the processing, BaselineZero will assist Customer by appropriate technical and organizational measures (including the Service’s correction, deletion, and audit-log features) in responding to data subject requests. If a data subject contacts BaselineZero directly about Customer Content, BaselineZero will refer them to Customer without responding on the merits, except where required by law.
9. Personal data breach
BaselineZero will notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Customer Content, and will provide information reasonably required for Customer’s own notifications as it becomes available, along with measures taken. Notification is not an admission of fault.
10. Deletion
The Service does not provide bulk export of Customer Content. Following termination or expiration, BaselineZero will delete Customer Content, destroy the per-customer key store and its access identity, and allow backups to age out on a fixed schedule, unless retention is required by law. On request, BaselineZero will confirm deletion in writing.
11. Audits
BaselineZero will make available information reasonably necessary to demonstrate compliance with this DPA, including summaries of security assessments and penetration tests. Where Data Protection Laws grant Customer an audit right that cannot be satisfied by documentation, Customer may conduct an audit no more than once per year, on at least 30 days’ notice, during business hours, under confidentiality, at its own cost, without access to other customers’ data, and in a manner that does not disrupt the Service.
12. United States processing only
All processing under this DPA occurs in the United States. BaselineZero does not offer or agree to international transfer mechanisms (including the EU Standard Contractual Clauses and the UK Addendum), and the Service is not intended for Personal Data subject to non-U.S. data protection laws. If Customer nevertheless submits such data, it does so at its own risk, and BaselineZero’s obligations remain solely those stated in this DPA and U.S. law.
13. U.S. state privacy laws
Where BaselineZero processes Personal Data subject to the CCPA or similar U.S. state laws, BaselineZero acts as a service provider or processor: it will not sell or share the Personal Data, will not retain, use, or disclose it outside the direct business relationship or for purposes other than those in the Agreement, will not combine it with data from other sources except as permitted for service providers, and certifies that it understands these restrictions. BaselineZero will notify Customer if it can no longer meet these obligations, and Customer may take reasonable steps to stop and remediate unauthorized use.
14. Liability and order of precedence
The liability of each party under this DPA is subject to the limitations and exclusions in the Agreement. This DPA replaces any previously agreed data processing terms for the Service.
Annex I — Description of processing
Parties. Customer (contact per account records), and BaselineZero, LLC, P.O. Box 511002, Livonia, Michigan 48151, USA; contact privacy@baselinezero.com.
Subject matter and duration. Provision of the Service for the term of the Agreement, plus the export and deletion period in Section 10.
Nature and purpose. Hosting; onboarding and discovery workflow management; reconciliation of expected against actual events from Connected Services; drafting of plans, letters, and reports for human review; portal page delivery; alerting; audit logging; support.
Data subjects. Customer personnel; personnel and contacts of Customer’s clients; Portal Recipients; senders and recipients of messages processed through the Service.
Categories of data. Identification and business contact data; employment details (role, department, device assignment); onboarding and discovery records; messages and files; credential lifecycle metadata (names, states, dates — never secret values); financial records of Customer’s business read from systems Customer connects, including invoices, bills, payroll schedule amounts, and read-only bank transactions; portal link access logs.
Sensitive data. None intended or required; Customer is instructed not to submit special categories of data.
Frequency. Continuous, for the duration of the subscription.
Annex II — Technical and organizational measures
• Encryption of data in transit (TLS 1.2 or higher) and at rest (AES-256).
• Tenant isolation enforced at the database layer through row-level security applied to every table, enforced against every role, and verified by an automated isolation test suite.
• Per-customer key storage for integration tokens, readable only by that customer’s dedicated workload identity; the request-serving tier holds no key-store role.
• Zero-retention design for secret material: credential values are stored in the customer’s own vault of record and referenced, not copied.
• Least-privilege, role-scoped database access; no standing production access for personnel; administrative actions logged.
• Append-only audit logging of consequential actions, including AI-proposed actions and portal link use.
• Schema changes applied only through reviewed, versioned migrations; separation of production from development and test environments; fictional data in non-production environments.
• Encrypted backups with defined retention; restore procedures tested.
• Personnel confidentiality obligations, background-appropriate access assignment, and periodic access reviews.
• Documented incident response with customer notification per Section 9; read-only design for bank connectivity; alerts withheld outside working hours by default.
Annex III — Subprocessors
• Microsoft Corporation (Azure) — cloud infrastructure, database, and key storage — United States.
• Anthropic, PBC — AI model provider for drafting and question answering; inputs are not used for model training — United States.
• SMTP2Go — delivery of invitations, alerts, and approved letters.
For clarity, services Customer connects and directs (for example HaloPSA, NinjaOne, Microsoft 365 and Entra, IT Glue, Hudu, QuickBooks Online, Plaid, Gusto, DocuSign, PandaDoc) act under Customer’s own agreements with those providers and are not Subprocessors of BaselineZero.