Contents
1Definitions
- Applicable Data Protection Laws
- All data protection and privacy laws that apply to the processing of Personal Data under the Services Agreement, including GDPR, UK GDPR, and relevant US state privacy laws where applicable.
- Customer
- The entity that enters the Services Agreement.
- Customer Personal Data
- Personal Data contained in Customer Data that Elements processes on behalf of Customer.
- Controller and Processor
- Have the meanings given under Applicable Data Protection Laws.
- Subprocessor
- A third party engaged by Elements to process Customer Personal Data.
- Security Incident
- A confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data.
2Roles and Scope
2.1 Customer Role
Customer acts as Controller for Customer Personal Data.
2.2 Elements Role
Elements acts as Processor for Customer Personal Data.
2.3 Instructions
Customer instructs Elements to process Customer Personal Data to provide the Services and related support as described in the Services Agreement, and as configured by Customer and its authorised users inside the Services.
3Details of Processing
3.1 Subject Matter
Provision of a finance and accounting operations platform and related support.
3.2 Duration
For the term of the Services Agreement, plus the deletion and retention periods in Section 10.
3.3 Nature of Processing
Collection, recording, structuring, storage, retrieval, consultation, use, disclosure by transmission, alignment, combination, restriction, and deletion, as required to provide the Services.
3.4 Categories of Data Subjects
Customer users, employees, contractors, vendors, suppliers, clients, and other individuals whose data Customer submits to the Services.
3.5 Categories of Customer Personal Data
Depending on Customer configuration and connected systems:
- Identification data, contact data, role and employment data
- Vendor and client records
- Invoice, receipt, and expense details
- Payment and transaction metadata
- Approvals, audit logs, notes, and supporting documentation
- System access logs and usage data tied to user accounts
3.6 Special Category Data
Customer agrees not to submit special category data unless the Services Agreement or a signed order form states otherwise and Customer applies required safeguards.
4Customer Obligations
Customer represents and warrants:
- Customer holds a valid lawful basis for collecting and sharing Customer Personal Data with Elements
- Customer provides required notices to data subjects
- Customer obtains required consents where needed
- Customer instructions comply with Applicable Data Protection Laws
- Customer configures access controls to limit access to authorised users
5Elements Obligations
Elements will:
- Process Customer Personal Data only on documented instructions from Customer, unless law requires other processing
- Inform Customer if an instruction violates Applicable Data Protection Laws, to the extent permitted by law
- Ensure personnel authorised to process Customer Personal Data are bound by confidentiality
- Implement and maintain appropriate technical and organisational measures as described in Section 8
- Support Customer with requests from data subjects as described in Section 7
- Notify Customer of confirmed Security Incidents as described in Section 9
- Delete or return Customer Personal Data at end of Services as described in Section 10
6Subprocessors
6.1 Authorisation
Customer grants general authorisation for Elements to engage Subprocessors to provide the Services.
6.2 Subprocessor Obligations
Elements enters a written agreement with each Subprocessor that includes data protection terms no less protective than this DPA, including confidentiality, security, and processing only on instructions.
6.3 Subprocessor List and Updates
Elements maintains a list of Subprocessors and provides notice of material Subprocessor changes through the Services, email, or an online notice.
6.4 Objection
Customer may object to a new Subprocessor on reasonable data protection grounds by sending notice within fourteen days of the update notice. If the parties do not resolve the objection within a reasonable time, Customer may terminate the affected Services under the termination terms in the Services Agreement.
7Data Subject Requests
If Elements receives a request from a data subject relating to Customer Personal Data, Elements will:
- Direct the data subject to Customer where appropriate
- Notify Customer where legally permitted
- Provide reasonable assistance to Customer to fulfil requests, taking into account the nature of processing and information available to Elements
Customer remains responsible for responding to data subject requests as Controller.
8Security
8.1 Security Measures
Elements maintains a security program designed to protect Customer Personal Data, including:
- Access controls, least privilege, and authentication controls
- Encryption in transit, and encryption at rest where appropriate
- Network security controls and monitoring
- Vulnerability management and patching
- Logging and audit trails within the Services
- Backups and disaster recovery processes
- Secure development practices and change management
- Employee security training
8.2 Customer Responsibilities
Customer remains responsible for:
- User account management
- Password hygiene and multi-factor authentication where offered
- Authorised user access permissions
- Secure use of integrations and API keys under Customer control
9Security Incident Notification
9.1 Notice
Elements will notify Customer without undue delay after confirming a Security Incident affecting Customer Personal Data.
9.2 Content of Notice
To the extent information is available, the notice includes:
- A description of the incident
- Categories of data involved
- Estimated number of affected records or individuals where available
- Measures taken or planned to address the incident
- Contact point for follow-up
9.3 No Admission
Incident notice does not represent a fault finding or liability admission.
10Deletion and Return
10.1 During the Term
Customer controls Customer Data in the Services through features such as delete, export, and access controls, subject to system limits and audit needs.
10.2 End of Services
After termination or expiry, Elements will delete or return Customer Personal Data in line with the Services Agreement.
10.3 Retention
Elements retains limited data where required by law, for security, dispute resolution, enforcement, or backups. Backups follow a rolling retention cycle and are overwritten on schedule.
11International Transfers
11.1 Transfer Mechanisms
Where GDPR or UK GDPR applies and Customer Personal Data transfers outside the UK or EEA, the parties rely on an approved transfer mechanism.
11.2 Standard Contractual Clauses
For transfers from the EEA, the parties incorporate the EU Standard Contractual Clauses, Module Two (Controller to Processor), and Module Three (Processor to Processor) where relevant.
11.3 UK Addendum
For transfers from the UK, the parties incorporate the UK Addendum to the EU Standard Contractual Clauses.
11.4 Conflict
If a transfer mechanism conflicts with this DPA, the transfer mechanism governs for that conflict only.
12Audits and Compliance
12.1 Information
Elements will provide reasonable information to demonstrate compliance with this DPA.
12.2 Audit
Customer audit rights follow the Services Agreement. If the Services Agreement does not cover audits:
- Customer may request one audit per year
- Audit occurs on reasonable notice, during business hours, and under confidentiality
- Audit scope is limited to information relevant to Customer Personal Data
- Customer pays audit costs unless the audit identifies a material breach of this DPA by Elements
13Assistance with DPIAs and Consultations
Elements will provide reasonable assistance with:
- Data protection impact assessments required under Applicable Data Protection Laws
- Consultations with regulators that relate to processing under this DPA
Assistance is limited to information available to Elements and provided at Customer expense where work exceeds standard support.
14Payment Processing Providers
The Services use third-party payment processing providers for subscription billing and payments. Payment card numbers and bank details are collected and processed by payment processing providers under their own terms and privacy practices. Elements stores only limited billing metadata needed for account administration and reconciliation.
15–16Liability and Order of Precedence
15. Liability
Liability under this DPA follows the liability and limitation of liability clauses in the Services Agreement.
16. Order of Precedence
If conflict exists:
- Transfer mechanisms in Section 11 govern for international transfer issues
- This DPA governs data protection processing terms
- The Services Agreement governs all other terms
17Contact
Security and privacy contact: [email protected]
For questions about this Data Processing Addendum, our security practices, or to exercise data subject rights, please contact us using the details above.
Have questions?
Our team is here to help. Reach out at [email protected]
