Effective September 25, 2026
This Data Processing Addendum (“DPA”) supplements the ZeroParse Statements Terms of Service (“the Agreement”) between Wedgr Technologies (UEN 53532707B), which operates ZeroParse Statements (“Processor,” “we”) and the accounting firm, bookkeeping practice, or other organization using the Service (“Controller,” “you,” “your firm”) whenever the Controller processes personal data belonging to its own clients or other third parties through the Service. Where this DPA conflicts with the Terms on a data-processing matter, this DPA controls; on everything else — billing, liability, dispute resolution — the Terms control.
This page is incorporated by reference into our Terms of Service for any account used to process a third party's financial data on their behalf — using the Service for that purpose is treated as acceptance of the terms below, the same way using the Service at all is acceptance of the main Terms.
For personal data the Controller submits to the Service (whether by uploading a client's PDF statement or entering their data via CSV/Excel), the Controller is the Data Controller (or, under the CCPA, the Business) and ZeroParse Statements is the Data Processor (or Service Provider under the CCPA), processing that data solely to provide the Service and only on the Controller's instructions — the instruction, in practice, being the act of uploading a file and requesting extraction.
This role split does not apply to data the Controller submits about itself to run its own ZeroParse Statements account (its own email, billing details, and credit balance) — for that data, ZeroParse Statements is an independent controller in its own right, as described in our Privacy Policy.
ZeroParse Statements agrees to:
Duration of processing: for the life of the Controller's ZeroParse Statements account, or until the Controller stops submitting third-party data through it — whichever is shorter, given that most of what's described below is measured in seconds, not months.
Categories of data subjects: the individuals or entities named in the statements the Controller processes — typically the Controller's own clients and their transaction counterparties.
Categories of personal data: whatever a bank or credit card statement contains — transaction dates, descriptions, and amounts, and potentially account holder names. We do not request, and ask the Controller not to submit, government ID numbers, full payment card numbers, or other special-category data beyond what a standard statement export already contains.
Nature of processing, by file type:
The Controller authorizes ZeroParse Statements to engage the following subprocessors, each limited to the function listed:
We rely on each subprocessor above to maintain industry-standard security certifications appropriate to the function it performs for us.
Changes: if we add or replace a subprocessor with access to Controller data, we'll update this page and notify registered business accounts by email at least 14 days before the change takes effect. Given the standardized nature of the Service, if the Controller objects to a new subprocessor, its sole and exclusive remedy is to terminate its account and cease using the Service before the change takes effect; continued use after that point constitutes acceptance of the change.
The subprocessors listed in Section 6 host infrastructure on global platforms and may process data in the United States, the European Economic Area, or other regions where those providers operate. Where data originating in Singapore is routed through our systems, we structure that processing to meet the standard of protection for overseas transfers required by the PDPA (Section 26). Where data originating in the UK or EEA is involved, we rely on the standard contractual clauses and equivalent transfer safeguards that our infrastructure subprocessors incorporate into their own published data-processing terms, rather than maintaining separate bilateral SCCs of our own with each provider.
Data subject requests. Because we hold no statement contents to begin with, most data-subject access or deletion requests concerning a Controller's clients have nothing on our side to locate or remove. Where a request does reach data we hold — for example, telemetry tied to a specific processing run — email admin@getzeroparse.com and we'll assist the Controller in responding within a reasonable time, and in any event within the timeframe the Controller specifies as necessary to meet its own regulatory deadline.
Security incident notification. If we confirm a security breach affecting a Controller's account credentials or billing data, we will notify the Controller without undue delay, in accordance with the Singapore PDPA. Given the zero-retention model described in Section 4, uploaded bank statement contents are never written to non-volatile storage in the first place and cannot be exfiltrated from our systems at rest.
Compliance verification. ZeroParse Statements does not undergo independent SOC 2 or ISO audits at this time. Instead, upon written request, no more than once per 12-month period absent a suspected incident, we will provide the Controller with a completed standard security questionnaire or written documentation of the Zero-Data-Retention mechanisms described in Section 4.
Subprocessor certifications. As a baseline of infrastructure security, ZeroParse Statements relies on the industry-standard security certifications maintained by the subprocessors listed in Section 6.
Data return/deletion. On termination of the Agreement, ZeroParse Statements will delete the Controller's account data (email, billing records, credit history) in line with the retention terms in our Privacy Policy, or sooner at the Controller's request. Because statement contents are strictly processed in volatile memory (RAM) and dropped immediately upon extraction, no statement data exists on our systems to return, purge, or audit upon termination.
This DPA is governed by the same law, and subject to the same dispute-resolution and liability terms (including the limitation of liability in Section 9 of the Terms), as the Agreement it supplements. It terminates automatically when the Agreement terminates.
Questions about this DPA, or to request a countersigned version referencing your firm by name: admin@getzeroparse.com