This Data Processing Addendum ("DPA") forms part of the Worthic Terms of Service or other written agreement between Worthic Systems (Pty) Ltd, trading as Worthic ("Worthic", "Processor", "Operator", "we", "us", or "our"), and the customer using the Service ("Customer", "Controller", "Responsible Party", or "you").
This DPA applies where Worthic processes personal information or personal data on behalf of a Customer in connection with the Service.
1. Definitions
Terms such as "personal information", "personal data", "processing", "controller", "processor", "responsible party", "operator", "data subject", "subprocessor", and "supervisory authority" have the meanings given under applicable data protection laws, including POPIA, GDPR, UK GDPR, and similar laws where applicable.
"Customer content" means documents, records, transactions, workspace data, files, metadata, notes, extracted data, and other content submitted to or generated inside a Customer workspace.
"Customer personal data" means personal information included in Customer content that Worthic processes on behalf of Customer.
2. Roles
For Customer personal data, Customer is generally the controller/responsible party and Worthic is generally the processor/operator.
Customer determines the purposes and means of processing Customer personal data, including what information is uploaded, who is invited to a workspace, which records are retained, and how outputs are used.
Worthic processes Customer personal data to provide, secure, support, and improve the Service according to Customer instructions and the agreement.
Worthic remains a controller/responsible party for account, billing, security, product analytics, support, compliance, and business operations data that Worthic determines how to process.
3. Processing instructions
Customer instructs Worthic to process Customer personal data as necessary to:
- provide, operate, maintain, and secure the Service;
- upload, store, retrieve, organize, extract, review, categorize, and analyze documents and workspace records;
- provide AI-assisted extraction, routing, categorization, review, and workflow assistance;
- manage users, roles, permissions, sessions, mobile access, supported OAuth sign-in, trusted devices, step-up approvals, settings, subscriptions, billing, support, and notifications;
- prevent, detect, investigate, and respond to security incidents, fraud, abuse, and technical issues;
- comply with applicable laws and lawful requests;
- perform processing described in the Privacy Policy, Terms of Service, and product documentation.
Worthic will not process Customer personal data for other purposes unless required by law or authorized by Customer.
4. Customer obligations
Customer is responsible for:
- having a lawful basis for collecting and processing Customer personal data;
- giving required privacy notices to data subjects;
- obtaining required consents where needed;
- ensuring Customer personal data is accurate, relevant, and lawful;
- configuring workspace permissions appropriately;
- responding to data-subject requests where Customer is the controller/responsible party;
- ensuring use of the Service complies with laws applicable to Customer.
5. Nature and purpose of processing
Worthic processes Customer personal data to provide a document-first accounting and finance workspace for individuals and businesses.
Processing may include hosting, storage, access control, mobile access, supported OAuth sign-in, trusted-device management, step-up approval checks, extraction, analysis, classification, AI-assisted suggestions, reporting, search, indexing, email notifications, support, security monitoring, logging, backup, deletion, and export.
6. Categories of data subjects
Customer personal data may relate to:
- Customer users and workspace members;
- Customer employees, contractors, directors, owners, partners, trustees, beneficiaries, and representatives;
- customers, clients, vendors, suppliers, tenants, landlords, agents, advisers, and counterparties;
- individuals named in financial or administrative documents;
- other people whose information appears in Customer content.
7. Categories of personal data
Customer personal data may include:
- identity and contact details;
- financial, transaction, account, invoice, receipt, payroll, tax, real estate, investment, and administrative information;
- document contents and metadata;
- authentication, mobile session, OAuth sign-in, trusted-device, step-up approval, and workspace access data;
- notes, tags, categories, reports, and user-entered records;
- extracted or derived data;
- AI outputs and user corrections;
- technical, audit, and security logs.
Customer must not upload special-category, sensitive, or regulated data unless it is necessary for Customer's use of the Service and Customer has a lawful basis to do so.
8. Confidentiality
Worthic will ensure that personnel authorized to process Customer personal data are subject to appropriate confidentiality obligations.
9. Security measures
Worthic will implement and maintain appropriate technical and organizational measures designed to protect Customer personal data against unauthorized or unlawful processing, accidental loss, destruction, damage, alteration, and disclosure.
Current controls are summarized in the Worthic Security Overview and may include encryption in transit, access controls, authentication controls, mobile session controls, supported OAuth sign-in controls, trusted-device records, step-up approvals for sensitive actions, environment separation, audit logs, secure object storage, database access controls, backups, monitoring, and incident response practices.
10. Subprocessors
Customer authorizes Worthic to use subprocessors to provide the Service. Current material subprocessors are listed on the Worthic Subprocessors List.
Worthic will impose data protection obligations on subprocessors that are appropriate to the nature of the services they provide. Worthic remains responsible for subprocessor processing to the extent required by applicable law and the agreement.
Worthic may update subprocessors from time to time. Where required by law or contract, Worthic will provide notice of material subprocessor changes and allow Customer to object on reasonable data protection grounds.
11. International transfers
Customer authorizes Worthic and its subprocessors to process Customer personal data in countries where Worthic or its subprocessors operate, subject to applicable safeguards.
Where GDPR, UK GDPR, POPIA transfer restrictions, or similar requirements apply, Worthic will use appropriate transfer mechanisms and contractual protections where required.
12. Data-subject requests
Where Worthic receives a request from a data subject relating to Customer personal data, Worthic may direct the requester to Customer unless Worthic is legally required to respond.
Worthic will provide reasonable assistance to Customer for data-subject requests, taking into account the nature of the processing and information available to Worthic.
13. Assistance with compliance
Taking into account the nature of the processing and information available to Worthic, Worthic will provide reasonable assistance with:
- security obligations;
- breach notifications;
- data protection impact assessments;
- prior consultation with regulators where required;
- audits or information requests reasonably necessary to verify compliance.
14. Security incidents
Worthic will notify Customer without undue delay after becoming aware of a confirmed personal data breach affecting Customer personal data.
The notification will include information reasonably available to Worthic, such as the nature of the incident, affected data categories, likely consequences, mitigation steps, and contact point.
Customer is responsible for any legally required notifications to data subjects or regulators where Customer is the controller/responsible party, unless applicable law requires Worthic to notify directly.
15. Return, deletion, and export
During the term, Customer may export Customer content using available Service functionality.
If a workspace is deleted, Worthic retains workspace data and documents for 14 days to allow export and recovery. After that period, production data is scheduled for deletion or de-identification, subject to limited retention in backups, logs, audit records, billing records, security records, legal holds, and compliance records.
Upon termination or written request, Worthic will delete or return Customer personal data in accordance with the agreement, technical feasibility, and legal retention requirements.
16. Audits
Worthic will make available information reasonably necessary to demonstrate compliance with this DPA.
Customer may request additional information about Worthic's security and processing controls. Any audit must be reasonable, proportionate, protect Worthic and other customers' confidential information, and avoid disruption to the Service.
Where Worthic provides independent security summaries, certifications, or written responses, those should generally satisfy routine audit requests.
17. AI processing
Where Customer uses AI-assisted features, Customer instructs Worthic to process Customer personal data through AI workflows as described in the AI and Data Processing Statement.
Worthic does not use Customer documents, Customer financial data, or workspace content to train third-party foundation models or general AI models without explicit opt-in consent.
AI outputs are assistance only and must be reviewed by Customer before reliance.
18. Order of precedence
If this DPA conflicts with the Terms of Service, this DPA controls for the processing of Customer personal data on behalf of Customer. The Terms of Service continue to apply to all other matters.
19. Contact
Questions about this DPA can be sent to [email protected].