Processor terms, EU Standard Contractual Clauses (Module 2), and UK Addendum for Parsedit.
Last updated: August 19, 2026
Status: Counsel-reviewable draft. Not legal advice. Does not take effect as a signed contract until accepted as described below.
This Data Processing Addendum (“DPA”) forms part of the Terms of Service (the “Agreement”) between Cauldrn LLC, a California limited liability company (“Processor,” “we”) operating Parsedit, and the customer that accepts the Agreement (“Controller,” “you”). If you use Parsedit on behalf of an organization, you accept this DPA for that organization.
This DPA applies only to Personal Data for which you are controller and Cauldrn is processor (uploaded documents and extracted fields about third parties, and related delivery payloads). Cauldrn is controller of account, billing, security logs, support tickets, and marketing data; those processing activities are described in the Privacy Policy and are not governed by this processor DPA.
Terms not defined here have the meaning in the Agreement, GDPR, UK GDPR, or the EU Standard Contractual Clauses. “GDPR” includes the EU GDPR and, where applicable, the UK GDPR. “Personal Data,” “processing,” “data subject,” and “sub-processor” have GDPR meanings. “SCCs” means the Standard Contractual Clauses annexed to European Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
2.1 You are controller; Cauldrn is processor of Customer Content (documents you upload, extracted fields, and payloads we send to destinations you configure).
2.2 We process Customer Content only on documented instructions: the Agreement, this DPA, your configuration in the Service, and written instructions that are consistent with the Service. We will inform you if, in our opinion, an instruction infringes GDPR (Art. 28(3)(h)).
2.3 We do not use Customer Content to train artificial intelligence or machine learning models, and we do not sell it.
2.4 Duration equals the Agreement plus the retention window in Annex I. You may delete documents in-app at any time.
3.1 Confidentiality. Persons authorized to process Customer Content are under confidentiality duties.
3.2 Security. We implement the technical and organizational measures in Annex II. You are responsible for configuring destinations, access roles, and whether documents contain special-category or health data.
3.3 Sub-processors. You authorize the sub-processors in Annex III and our use of replacements on 14–30 days’ notice as described in the Privacy Policy, except emergency security replacements. Sub-processors are bound by data-protection terms no less protective than this DPA. We remain liable for their processing as required by Art. 28(4).
3.4 Assistance. We assist you, taking into account the nature of processing, with data-subject requests (including in-app export and deletion), security, DPIAs, and prior consultation, at our then-current support channels. In-app export is the primary Art. 15/20 mechanism.
3.5 Breach. We notify you without undue delay after becoming aware of a Personal Data Breach affecting Customer Content, with information reasonably available to us to help you meet Art. 33/34. See also our incident clocks in internal policy (GDPR 72 hours; HIPAA 60 days when a BAA applies — a BAA does not replace this DPA).
3.6 Return/deletion. When the Agreement ends, or earlier per the retention schedule, we delete Customer Content from production systems within the windows in Annex I, except copies in backups until they rotate, and except data we must retain as controller (billing, fraud tombstones, audit metadata without document contents). You may export before deletion.
3.7 Audits. Upon reasonable written request, not more than once per 12 months unless a competent authority or documented incident requires more, we will provide security summaries and, where required by GDPR, permit an audit under confidentiality, during business hours, without disrupting operations. You may not access other customers’ data.
3.8 International transfers. Transfers of Customer Content from the EEA to the United States are governed by the SCCs Module 2 (controller → processor) in Annex IV. Transfers from the UK are governed by the UK Addendum / IDTA in Annex V. Cauldrn’s Art. 27 representatives (DataRep) are not a transfer tool.
You warrant that you have a lawful basis and all notices/consents required to upload documents (including documents about third parties). You must not upload PHI unless you have executed the Business Associate Agreement and HIPAA mode is enabled. Healthcare processing without a BAA is prohibited.
SCCs prevail over this DPA for EEA restricted transfers. This DPA prevails over the Agreement on data-protection conflicts for processor activities. The Privacy Policy describes notices to data subjects; it does not reduce SCC protections.
Processor: Cauldrn LLC — [email protected]
EU Art. 27 representative (DataRep; not a DPO; not an EU establishment): TODO_DATAREP_EU_NAME; TODO_DATAREP_EU_ADDRESS; TODO_DATAREP_EU_EMAIL
UK Art. 27 representative (DataRep; not a DPO; not a UK establishment): TODO_DATAREP_UK_NAME; TODO_DATAREP_UK_ADDRESS; TODO_DATAREP_UK_EMAIL
Controller: the customer entity accepting the Agreement (name, address, and contact as in the Parsedit account).
Processor: Cauldrn LLC, California, United States. Privacy: [email protected]. Support: [email protected].
Processor’s EU GDPR Art. 27 representative: DataRep — TODO_DATAREP_EU_NAME; TODO_DATAREP_EU_ADDRESS; TODO_DATAREP_EU_EMAIL (placeholders until the mandate pack is issued; do not treat TODO_* as a street address).
Processor’s UK GDPR Art. 27 representative: DataRep — TODO_DATAREP_UK_NAME; TODO_DATAREP_UK_ADDRESS; TODO_DATAREP_UK_EMAIL.
created_at; Pro, Business = 365 days. CSV/JSON download files and DSAR ZIPs = 7 days. Account deletion: remaining Customer Content erased within about 30 days except legal archives that are not document bytes.EEA: the authority of the controller’s EU establishment or, if none, of the EEA data subjects as determined under the SCCs. UK: the ICO.
parsers.view / parsers.edit / integrations.manage / settings.manage); MFA (required in HIPAA mode; available otherwise).Same list as Privacy Policy §5 and the dated public list:
Supabase (database, auth, storage, US); Vercel (hosting, US); Cloudflare (Turnstile); Stripe (payments — generally not Customer Content documents); Extend (OCR/extraction); Postmark (inbound email if enabled); Resend or SMTP (transactional email); Sentry (errors, if enabled); Google Analytics (optional, consent, not document content).
Controller-configured destinations (Google, Xero, Intuit, Slack, Zapier, webhooks) are not Cauldrn sub-processors.
The parties enter into the Standard Contractual Clauses (Decision (EU) 2021/914) Module 2 (controller-to-processor). The official text is incorporated by reference from https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj.
Docking clause: Clause 7 applies.
Module: Module 2 only, for Customer Content.
Clause 9 (sub-processors): Option 2, general written authorization, 14 days’ notice (or as in §3.3).
Clause 11 (redress): optional clause does not apply unless required.
Clause 13: as Annex I.C.
Clause 17 (governing law): Ireland (or the EEA member state of the controller if the SCCs require a Member State law).
Clause 18 (forum): courts of the Member State of Clause 17.
Annexes I–III of the SCCs are Annex I–III of this DPA.
Cauldrn LLC signs the SCCs by making this DPA part of the Agreement. The controller signs by accepting the Terms.
For transfers of UK GDPR personal data to the United States, the parties enter into the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the ICO (the “UK Addendum”), or the ICO IDTA if the Addendum cannot apply, incorporated by reference from https://ico.org.uk.
UK Addendum tables (working completion):
UK Art. 27 representative: DataRep (TODO_DATAREP_UK_* placeholders).