Legal · Updated July 28, 2026
Data Processing Addendum
A pre-launch processor addendum for account and support data, built around ImportReady’s local-file boundary.
1. Parties and roles
This addendum is intended to apply when a customer is a controller or processor of personal data and the ImportReady operating entity processes that personal data on the customer's behalf to provide account, entitlement, support, or related hosted services.
Spreadsheet contents handled only inside the customer's browser are outside the hosted processing boundary unless the customer independently sends those contents through support or another cloud feature.
2. Documented instructions
The processor will process covered personal data only to provide and secure the service, comply with the agreement and documented lawful instructions, or meet applicable legal obligations. If an instruction appears unlawful, the processor will notify the customer where permitted.
3. Processing details
Subject matter: operation of ImportReady accounts, licences, billing records, support, email delivery, security, and opted-in operational telemetry. Duration: the agreement term plus the documented deletion and legal-retention period.
- Data subjects: customer personnel, authorized users, purchasers, and support contacts.
- Data types: identity and contact data, authentication identifiers, entitlement data, coarse usage data, transaction metadata, support content, and security logs.
- Purpose: authentication, service delivery, billing, support, security, abuse prevention, and customer-authorized communications.
- Excluded by design: spreadsheet bytes, cell values, repaired rows, and exports unless a customer deliberately supplies them to support.
4. Confidentiality and security
Personnel with access to covered data will be subject to appropriate confidentiality duties. Technical and organizational measures will include access control, least privilege, encryption in transit, credential separation, row-level authorization, validated mutations, audit records, vulnerability management, backups, and incident procedures appropriate to risk.
5. Subprocessors
The planned subprocessors include Vercel for hosting, Supabase for authentication and database services, Resend for email delivery, and Stripe for hosted payment checkout. Stripe is selected, but the integration is not live in the current pre-launch build. The final annex must list legal names, locations, functions, and links to governing terms.
The processor will impose materially appropriate data-protection duties on subprocessors and provide the notice and objection process required by the final agreement.
6. Assistance
Taking account of the nature of processing, the processor will reasonably assist with data-subject requests, security obligations, breach response, impact assessments, and regulatory consultations where required. The customer remains responsible for its instructions, notices, lawful basis, and responses as controller.
7. Security incidents
The processor will notify the customer without undue delay after confirming a personal-data breach affecting covered data, provide available information needed for the customer's duties, take reasonable containment and remediation steps, and cooperate with the investigation.
Notification is not an admission of fault. Unsuccessful attacks and events that do not affect covered personal data are not personal-data breaches under this section.
8. Return and deletion
At the end of services, the processor will delete or return covered data according to the customer's choice and the production retention schedule, unless law requires continued storage. Local spreadsheet contents remain under the customer's browser and device controls.
9. International transfers
The final DPA must identify the applicable transfer mechanism, including any standard contractual clauses, UK addendum, adequacy decision, supplementary measure, or regional hosting commitment required by the parties.
10. Information and audits
The processor will make reasonable information available to demonstrate compliance and support proportionate audits under agreed confidentiality, scope, frequency, security, and cost controls. Independent reports should be used before intrusive onsite review where sufficient.