Effective September 11, 2026

Data Processing Addendum

For business customers. Sets out how Everykept processes personal information on your behalf, and lists every sub-processor we use.

1. Scope and roles

This Addendum forms part of the Terms of Service between TiqyTech Inc. (“Everykept”) and a customer using the service for business purposes (“Customer”). Where Customer uploads or connects data that includes personal information about third parties (for example, employee names on receipts or counterparties in transactions), Customer is the controller (or, under PIPEDA, the accountable organization) and Everykept is the processor, acting only on Customer’s documented instructions. For Customer’s own account and login details, Everykept is an independent controller as described in the Privacy Policy.

2. Instructions

Customer’s instructions are: to store, display, categorize, summarize and make available the financial and receipt data Customer connects or uploads, for Customer’s use, as configured through the service. Everykept will not process the data for any other purpose and will inform Customer if an instruction appears to violate applicable law.

3. Confidentiality

Access to personal data is limited to personnel who need it to operate the service and who are bound by confidentiality obligations. Everykept does not read individual transactions or receipts except to resolve a support request Customer has raised, or as required by law.

4. Security

Everykept implements the technical and organizational measures described on the Security page, including encryption in transit and at rest, application-level encryption of bank access tokens, argon2id password hashing, per-user data isolation enforced at the data-access layer, audit logging, and automated vulnerability scanning of dependencies. Everykept may update these measures provided the overall level of protection is not reduced.

5. Sub-processors

Customer authorizes the following sub-processors:

  • Plaid Inc.: Financial account connectivity and data retrieval. Location: United States.
  • Neon Inc.: Managed PostgreSQL database. Location: United States (us-east-1).
  • Cloudflare Inc.: Object storage for receipt files (R2). Location: Global network, data at rest in North America.
  • Fly.io: Application hosting. Location: United States.
  • Vercel Inc.: Web application hosting (static assets only). Location: Global CDN.
  • Resend Inc.: Transactional email. Location: United States.
  • Google LLC: Identity provider (only for accounts that sign in with Google). Location: United States.

Everykept will publish changes to this list on this page at least 30 days before a new sub-processor begins processing financial or receipt data, and will email Customer’s account holder. If Customer reasonably objects on data-protection grounds and no alternative is available, Customer may terminate the service and export its data. Everykept remains responsible for its sub-processors’ performance.

6. International transfers

Data is stored and processed primarily in the United States. For customers subject to the GDPR or UK GDPR, transfers are made under the European Commission’s Standard Contractual Clauses (Module 2, controller to processor) or the UK International Data Transfer Addendum, which are incorporated by reference and will be executed on request.

7. Assistance

Everykept will assist Customer, at no charge and taking into account the nature of the processing, in responding to data subject requests (access, correction, deletion, export) that relate to data held in the service, and in carrying out data protection impact assessments where the processing warrants one.

8. Personal data breaches

Everykept will notify Customer without undue delay, and in any event within 72 hours of becoming aware of a breach affecting Customer’s personal data, providing the information reasonably available at the time and updating it as the investigation proceeds.

9. Deletion and return

On termination of the service, or on Customer’s request at any time, Everykept will make Customer’s data (including receipt files) available for export in a machine-readable form and will delete it from live systems within 30 days and from backups within 90 days, unless retention is required by law.

10. Audit

Everykept will make available the information reasonably necessary to demonstrate compliance with this Addendum, including summaries of its security practices and, where available, third-party assurance reports of its sub-processors. Where this is insufficient, Customer may conduct an audit once per year on 30 days’ notice, at Customer’s expense, in a manner that does not disrupt the service or expose other customers’ data.

11. Liability and precedence

Liability under this Addendum is subject to the limitations in the Terms of Service. In case of conflict between this Addendum and the Terms regarding the processing of personal data, this Addendum prevails.

12. Contact

Data protection enquiries: privacy@everykept.com. To request signed Standard Contractual Clauses or a countersigned copy of this Addendum, email the same address from the account holder’s email.