ZeroParse
HomeHelp

Data Processing Addendum

Effective September 25, 2026

1. Purpose & interpretation

This Data Processing Addendum (“DPA”) supplements the ZeroParse Statements Terms of Service (“the Agreement”) between Wedgr Technologies (UEN 53532707B), which operates ZeroParse Statements (“Processor,” “we”) and the accounting firm, bookkeeping practice, or other organization using the Service (“Controller,” “you,” “your firm”) whenever the Controller processes personal data belonging to its own clients or other third parties through the Service. Where this DPA conflicts with the Terms on a data-processing matter, this DPA controls; on everything else — billing, liability, dispute resolution — the Terms control.

This page is incorporated by reference into our Terms of Service for any account used to process a third party's financial data on their behalf — using the Service for that purpose is treated as acceptance of the terms below, the same way using the Service at all is acceptance of the main Terms.

2. Roles of the parties

For personal data the Controller submits to the Service (whether by uploading a client's PDF statement or entering their data via CSV/Excel), the Controller is the Data Controller (or, under the CCPA, the Business) and ZeroParse Statements is the Data Processor (or Service Provider under the CCPA), processing that data solely to provide the Service and only on the Controller's instructions — the instruction, in practice, being the act of uploading a file and requesting extraction.

This role split does not apply to data the Controller submits about itself to run its own ZeroParse Statements account (its own email, billing details, and credit balance) — for that data, ZeroParse Statements is an independent controller in its own right, as described in our Privacy Policy.

3. Processor obligations

ZeroParse Statements agrees to:

  • process personal data only on the Controller's documented instructions (including the extraction request itself), unless required to do otherwise by law;
  • treat all such data as confidential, and limit access to personnel and automated systems that need it to run the Service;
  • implement the technical and organizational measures set out in Annex II;
  • engage only the subprocessors listed in Annex III, under the notification process described there;
  • assist the Controller with data subject rights requests and security incident obligations, as described in Section 6; and
  • at the Controller's request, delete or return personal data on termination — though as Section 4 makes clear, there is ordinarily nothing left to return, because nothing was retained in the first place.

4. Scope & subject matter of processing (Annex I)

Duration of processing: for the life of the Controller's ZeroParse Statements account, or until the Controller stops submitting third-party data through it — whichever is shorter, given that most of what's described below is measured in seconds, not months.

Categories of data subjects: the individuals or entities named in the statements the Controller processes — typically the Controller's own clients and their transaction counterparties.

Categories of personal data: whatever a bank or credit card statement contains — transaction dates, descriptions, and amounts, and potentially account holder names. We do not request, and ask the Controller not to submit, government ID numbers, full payment card numbers, or other special-category data beyond what a standard statement export already contains.

Nature of processing, by file type:

  • CSV & Excel — parsed entirely within the Controller's own browser, client-side. These files are never transmitted to, or stored on, ZeroParse Statements infrastructure at any point. As far as ZeroParse Statements is concerned, this data does not leave the Controller's device.
  • PDF — uploaded over an encrypted connection to a transient extraction server, held strictly in volatile memory (RAM) for the duration of OCR/text extraction, rendered into structured JSON, and returned to the Controller's browser. The file and everything derived from it are dropped from memory immediately afterward — on success or failure — and are never written to non-volatile disk or persistent storage at any point in that path.
  • Retained account & telemetry data — separately from the above, we retain the Controller's own account authentication details (email, credit balance) and non-content operational telemetry for each processing run: a non-reversible account identifier, file type, page count, and response time. This never includes statement contents and is not treated as data processed on the Controller's behalf under this DPA — it's ZeroParse Statements' own operational data about running the Service, in the same category as web-server access logs.

5. Security standards & technical safeguards (Annex II)

  • Encryption in transit: all traffic to and from the Service, including PDF uploads, is encrypted using TLS 1.2 or higher. No statement data is ever transmitted unencrypted.
  • Encryption at rest: the account and billing data described in Section 4 is stored in Supabase's managed Postgres, encrypted at rest by the provider. Statement contents are never written to disk in the first place, so there is nothing for at-rest encryption to apply to on that path.
  • Data isolation: database access is enforced by Supabase Row-Level Security (RLS), so one account's data is not readable by another authenticated user under any normal query path. Administrative access uses a separate, narrowly-scoped service credential that is never exposed to the browser.
  • No AI/LLM training: ZeroParse Statements does not use uploaded documents, extracted transaction data, or any other Controller data to train artificial intelligence or machine learning models, ours or a third party's.
  • Access control: administrative access to the Service's operations console is restricted to a named allow-list of personnel and requires a verified account, not just a matching email address.
  • Incident logging: administrative actions taken on a Controller's account (support access, credit adjustments, refunds) are recorded in an append-only audit log.

6. Subprocessors (Annex III)

The Controller authorizes ZeroParse Statements to engage the following subprocessors, each limited to the function listed:

  • Supabase — authentication and database hosting (account data described in Section 4; never statement contents).
  • Stripe — payment processing for the Controller's own ZeroParse Statements subscription. Stripe never receives statement data.
  • Vercel — frontend hosting for the web application the Controller's browser loads. CSV/Excel processing happens entirely within that browser session and is never transmitted to Vercel's infrastructure.
  • Render — hosts the backend execution engine that performs PDF OCR, as described in Section 4. This is the only subprocessor that ever sees PDF contents, and only transiently, in memory.
  • Resend — delivers account and administrative emails on our behalf. It receives statement content only if an authorized user of the Controller's account explicitly opts in to attaching a file to a support request (Privacy Policy Section 3a) — an action available only to signed-in users, off by default, and unrelated to the Controller's clients' statement processing itself.
  • Sentry — error monitoring for the web application and the backend execution engine. It receives technical error reports: the error, where in the code it occurred, the page or endpoint involved without its query string, and preceding log messages that identify an account only by an internal ID or a one-way hash. It never receives statement contents, Controller Data submitted for processing, passwords, payment details, request bodies, or session cookies. Reports are stored in Sentry's United States region.

We rely on each subprocessor above to maintain industry-standard security certifications appropriate to the function it performs for us.

Changes: if we add or replace a subprocessor with access to Controller data, we'll update this page and notify registered business accounts by email at least 14 days before the change takes effect. Given the standardized nature of the Service, if the Controller objects to a new subprocessor, its sole and exclusive remedy is to terminate its account and cease using the Service before the change takes effect; continued use after that point constitutes acceptance of the change.

6A. International data transfers

The subprocessors listed in Section 6 host infrastructure on global platforms and may process data in the United States, the European Economic Area, or other regions where those providers operate. Where data originating in Singapore is routed through our systems, we structure that processing to meet the standard of protection for overseas transfers required by the PDPA (Section 26). Where data originating in the UK or EEA is involved, we rely on the standard contractual clauses and equivalent transfer safeguards that our infrastructure subprocessors incorporate into their own published data-processing terms, rather than maintaining separate bilateral SCCs of our own with each provider.

7. Data subject rights & breach notification

Data subject requests. Because we hold no statement contents to begin with, most data-subject access or deletion requests concerning a Controller's clients have nothing on our side to locate or remove. Where a request does reach data we hold — for example, telemetry tied to a specific processing run — email admin@getzeroparse.com and we'll assist the Controller in responding within a reasonable time, and in any event within the timeframe the Controller specifies as necessary to meet its own regulatory deadline.

Security incident notification. If we confirm a security breach affecting a Controller's account credentials or billing data, we will notify the Controller without undue delay, in accordance with the Singapore PDPA. Given the zero-retention model described in Section 4, uploaded bank statement contents are never written to non-volatile storage in the first place and cannot be exfiltrated from our systems at rest.

8. Audit rights & compliance verification

Compliance verification. ZeroParse Statements does not undergo independent SOC 2 or ISO audits at this time. Instead, upon written request, no more than once per 12-month period absent a suspected incident, we will provide the Controller with a completed standard security questionnaire or written documentation of the Zero-Data-Retention mechanisms described in Section 4.

Subprocessor certifications. As a baseline of infrastructure security, ZeroParse Statements relies on the industry-standard security certifications maintained by the subprocessors listed in Section 6.

Data return/deletion. On termination of the Agreement, ZeroParse Statements will delete the Controller's account data (email, billing records, credit history) in line with the retention terms in our Privacy Policy, or sooner at the Controller's request. Because statement contents are strictly processed in volatile memory (RAM) and dropped immediately upon extraction, no statement data exists on our systems to return, purge, or audit upon termination.

9. General

This DPA is governed by the same law, and subject to the same dispute-resolution and liability terms (including the limitation of liability in Section 9 of the Terms), as the Agreement it supplements. It terminates automatically when the Agreement terminates.

10. Contact

Questions about this DPA, or to request a countersigned version referencing your firm by name: admin@getzeroparse.com