Draft — not yet in effect
Data Processing Addendum — draft
Drafting note
Not legal advice. Not reviewed by counsel. Draft v0.1 · 2026-09-24 · not yet published. Drafting notes are in blockquotes like this one; strip them before publishing.
{{…}}= fill before publishing.US customers and US processing only. No GDPR, UK GDPR or Standard Contractual Clauses (see
legal-docs-plan.md§7). Structure adapted from the Common Paper DPA v1.1 (attribution at the end). Section references ("Terms §…") are toterms-of-service.mdv0.1; keep them in sync.
Sidesheet Data Processing Addendum
Effective: {{EFFECTIVE_DATE}}
This Data Processing Addendum ("DPA") is between UNTAP LLC, an Oregon limited liability company, and the Customer named in the Sidesheet Terms of Service at https://sidesheet.co/legal/terms (the "Terms"). It forms part of the Terms and applies automatically to every Customer. A countersigned copy is available on request to legal@sidesheet.co. Capitalized terms not defined here have the meaning in the Terms.
Key terms
| Agreement | The Terms, which this DPA supplements |
| Service | Sidesheet: extracting financial data from business tax returns and related documents that Customer uploads, organizing it into spreads, and letting Customer review, export and delete it |
| Customer Personal Data | Personal information contained in Customer Data (Terms §1) |
| Data subjects | Individuals named in uploaded documents — e.g. business owners, shareholders, partners, officers, return preparers, and other individuals listed on returns and schedules |
| Categories of data | Names, addresses, Social Security and other taxpayer identification numbers, income, compensation, ownership and other financial information, and any other personal information in the documents Customer uploads |
| Duration | For as long as Customer uses the Service, then until deletion under §8 |
| Processing location | United States only |
| Subprocessors | The list at https://sidesheet.co/legal/subprocessors (Annex 2) |
| Security measures | Annex 1 — Security overview (https://sidesheet.co/legal/security) |
| UNTAP LLC security contact | security@sidesheet.co · {{MAILING_ADDRESS}} |
Scope. This DPA covers Customer Personal Data. Account Data (Terms §1) is information UNTAP LLC uses to run Customer's account and is governed by our Privacy Policy at https://sidesheet.co/legal/privacy.
1. Roles
1.1 Customer decides what Customer Data to upload and why. UNTAP LLC processes Customer Personal Data only on Customer's behalf, as Customer's service provider or processor. If Customer is itself processing the data for someone else (for example, a client), UNTAP LLC acts as Customer's subprocessor.
1.2 Customer is responsible for having every right, notice and consent needed to upload Customer Data and have UNTAP LLC process it, including under 26 U.S.C. §7216 and any professional confidentiality rules that apply to Customer (Terms §§3.1–3.2).
2. Processing only on Customer's instructions
2.1 Instructions. Customer instructs UNTAP LLC to process Customer Personal Data only: (a) to provide, secure and support the Service for Customer, as described in the Key terms; (b) as Customer directs through the Service, including its retention setting (Terms §5.1), support-access grants (Terms §4.2), and — only if Customer turns it on — the Help improve extraction setting (Terms §2.4); and (c) as otherwise agreed in writing by both parties. UNTAP LLC may also process Customer Personal Data where required by law, subject to §6.2.
2.2 Prohibited uses. UNTAP LLC will not:
- (a) sell or share Customer Personal Data, or rent, license or otherwise make it available to anyone for their own purposes (Terms §2.5);
- (b) retain, use or disclose it for any purpose, including any commercial purpose, other than the purposes in §2.1, or outside the direct business relationship between UNTAP LLC and Customer;
- (c) combine it with personal information received from another customer or any other source, or collected from UNTAP LLC's own interactions with the individual (Terms §2.5);
- (d) use it to train or fine-tune any AI or machine learning model, or allow any Subprocessor to (Terms §2.3); or
- (e) use it for advertising, profiling or any decision about the individuals concerned.
Aggregate service metrics under Terms §2.6 contain no Customer Data values and are not Customer Personal Data.
2.3 Personnel. UNTAP LLC limits access to Customer Personal Data to personnel who need it for the purposes in §2.1, under the access limits in Terms §4.2. Every such person is bound by a written confidentiality obligation that continues after their engagement ends. Access is logged.
3. Subprocessors
3.1 Customer authorizes UNTAP LLC to use the Subprocessors listed at https://sidesheet.co/legal/subprocessors. The list names each Subprocessor, what it does, whether it receives tax-return content, and its location.
3.2 UNTAP LLC binds each Subprocessor by written contract to restrictions on Customer Personal Data at least as protective as §§2, 4 and 9, including the restrictions required by Cal. Civ. Code §1798.140(ag)(1), and remains responsible for each Subprocessor's performance (Terms §8.1).
3.3 UNTAP LLC will give at least 30 days' notice, by email to Customer's admins and by updating the list, before adding or replacing a Subprocessor. Customer may object in writing on reasonable grounds during that period. If UNTAP LLC cannot reasonably accommodate the objection, Customer may terminate and receive a pro-rata refund of prepaid fees (Terms §8.2).
4. Security
4.1 UNTAP LLC will implement and maintain administrative, technical and physical safeguards appropriate to the nature of Customer Personal Data, as described in Annex 1 and Terms §4.1, including encryption in transit and at rest and processing and storage only in the United States.
4.2 UNTAP LLC may update Annex 1, but will not materially reduce the overall protection of Customer Personal Data during the term.
4.3 UNTAP LLC has not completed a SOC 2 audit, ISO 27001 certification, or independent penetration test (Terms §4.3). Nothing in this DPA claims otherwise.
5. Security incidents
5.1 If UNTAP LLC confirms a security incident that resulted in unauthorized access to or disclosure of Customer Personal Data, UNTAP LLC will:
- (a) notify Customer's admins within 48 hours of confirming it (Terms §4.4);
- (b) provide the information UNTAP LLC has that Customer reasonably needs to meet its own notification obligations (for example, to affected individuals, state regulators, or the FTC under 16 CFR 314.4(j)), and update it as more becomes known; and
- (c) promptly take reasonable steps to contain, investigate and remediate the incident.
5.2 Notice is not an admission of fault. UNTAP LLC will not notify individuals or regulators about Customer Personal Data on Customer's behalf unless Customer asks or the law requires it.
6. Assistance and requests
6.1 Consumer requests. If UNTAP LLC receives a request from an individual about Customer Personal Data, UNTAP LLC will direct the individual to Customer and will not respond itself except to do so. The Service lets Customer find, export and delete Customer Data; where that is not enough, UNTAP LLC will reasonably assist Customer to respond to requests to access, delete or correct personal information under applicable privacy laws, and will comply with any such request Customer tells UNTAP LLC to carry out.
6.2 Legal requests. If a government or other third party demands Customer Personal Data, UNTAP LLC will redirect the demand to Customer where possible, notify Customer before disclosing unless the law prohibits it, and disclose only what is legally required (Terms §5.3).
6.3 Assessments. UNTAP LLC will provide reasonable information Customer needs for any risk assessment, cybersecurity audit or similar assessment that applicable privacy law requires of Customer for this processing.
7. Compliance information (in place of audits)
7.1 UNTAP LLC will make available to Customer, on request and under Terms §9 (Confidentiality): (a) Annex 1 and UNTAP LLC's written security documentation; and (b) written answers to Customer's reasonable security, due-diligence and vendor-assessment questionnaires, up to once every 12 months and additionally after any incident under §5. Customer may use this information to assess UNTAP LLC and to confirm UNTAP LLC processes Customer Personal Data consistently with this DPA.
7.2 UNTAP LLC does not offer on-site audits or inspections, or access to its systems, and holds no third-party certification or audit report (§4.3).
7.3 Unauthorized use. If Customer reasonably believes UNTAP LLC is using Customer Personal Data in breach of this DPA, Customer may, on notice, require UNTAP LLC to stop that use and take reasonable steps to remediate it, including providing written confirmation that data Customer asked to be deleted has been deleted.
7.4 Notice of inability to comply. UNTAP LLC will notify Customer promptly if it determines that it can no longer meet its obligations under this DPA or applicable privacy law. Customer may then stop the affected processing or terminate under Terms §7.
Drafting note
Drafting note: §7.2 (no on-site audits) is narrower than the Common Paper default, which allows inspections. 11 CCR §7051(a)(7) lets the business take "reasonable and appropriate steps," which "may include" reviews, scans and assessments — it does not mandate on-site access. Confirm with counsel whether questionnaire-only is acceptable to larger firms (
questions-for-counsel.md).
8. Retention, return and deletion
8.1 During the term Customer controls retention: Customer chooses how long uploaded source files and their spreads are kept, UNTAP LLC deletes them automatically at the end of that period, and Customer can delete any file or client sooner (Terms §5.1).
8.2 On termination Customer may export Customer Data for 30 days. UNTAP LLC then deletes Customer Data from production systems; backups containing it expire within a further 30 days. On request, UNTAP LLC will confirm deletion in writing (Terms §5.2).
8.3 UNTAP LLC retains Customer Personal Data beyond these periods only where the law or valid legal process requires, only as long as required, and continues to protect it under this DPA (Terms §5.3).
9. US state privacy laws (including the CCPA)
9.1 UNTAP LLC may not meet the thresholds that make a company a "business" under the California Consumer Privacy Act (Cal. Civ. Code §1798.100 et seq., "CCPA") or similar state laws, but Customer may. To the extent the CCPA or a similar state law applies to Customer Personal Data, UNTAP LLC is Customer's service provider (Cal. Civ. Code §1798.140(ag)) or processor, and:
- (a) Business purpose. Customer discloses Customer Personal Data to UNTAP LLC only for the limited and specified business purpose of extracting financial data from the documents Customer uploads, organizing it into spreads for Customer's review and export, and securing and supporting that service, plus the opt-in quality review in Terms §2.4 if Customer enables it;
- (b) UNTAP LLC will not sell or share it, or retain, use or disclose it for any other purpose (including any other commercial purpose), outside the direct business relationship with Customer, or combine it with other personal information, except as the CCPA and its regulations expressly permit (§2.2);
- (c) UNTAP LLC will comply with the applicable sections of the CCPA and its regulations and provide the same level of privacy protection they require of businesses, including reasonable security under Cal. Civ. Code §1798.81.5 (§4);
- (d) Customer may take reasonable and appropriate steps to ensure UNTAP LLC uses Customer Personal Data consistently with Customer's CCPA obligations (§7.1), and, on notice, to stop and remediate unauthorized use (§7.3);
- (e) UNTAP LLC will notify Customer if it determines it can no longer meet its CCPA obligations (§7.4);
- (f) UNTAP LLC will enable Customer to comply with consumer requests, and will comply with requests Customer passes to it (§6.1);
- (g) UNTAP LLC will notify Customer of each Subprocessor it engages and bind each by written contract to these requirements (§3); and
- (h) UNTAP LLC certifies that it understands and will comply with the restrictions in this §9.
Drafting note
Drafting note: (a)–(g) track Cal. Civ. Code §1798.100(d), §1798.140(ag)(1)–(2) and 11 CCR §7051(a) as amended effective 2026-01-01 (text checked 2026-09-24, sources below). §7051(a)(2) requires the business purpose to be specific, not "the Agreement generally" — keep (a) concrete. Item (h) is not required by the checked text; it is a common, low-cost comfort clause.
10. Gramm-Leach-Bliley Act / FTC Safeguards Rule
Customer may be a "financial institution" subject to the FTC Standards for Safeguarding Customer Information (16 CFR Part 314), which requires it to oversee service providers by, among other things, "[r]equiring your service providers by contract to implement and maintain such safeguards" (16 CFR 314.4(f)(2)). UNTAP LLC agrees that it will implement and maintain safeguards for any customer information (as that Rule defines it) within Customer Personal Data that are appropriate to its nature, as described in §4 and Annex 1, will notify Customer of incidents under §5, and will support Customer's periodic assessment of UNTAP LLC (16 CFR 314.4(f)(3)) under §7.
11. General
11.1 Order of precedence. If this DPA conflicts with the Terms about Customer Personal Data, this DPA controls. Otherwise the Terms control.
11.2 Liability. Each party's liability under this DPA is subject to the limits and exclusions in Terms §11. This DPA does not limit any liability to an individual that cannot be limited by law.
11.3 Term. This DPA applies for as long as UNTAP LLC processes Customer Personal Data, including after the Terms end until deletion under §8.
11.4 Changes. UNTAP LLC may update this DPA on 30 days' notice under Terms §13, but will not reduce the protections in §§2–10 without Customer's express, affirmative agreement.
11.5 Governing law and venue are as stated in Terms §14.1–14.2.
Annex 1 — Security measures
See the Security overview at https://sidesheet.co/legal/security (source: security.md, drafted
separately). {{Confirm the published version is consistent with §4 before publishing this DPA.}}
Annex 2 — Subprocessors
See https://sidesheet.co/legal/subprocessors (source: subprocessors.md).
Attribution. This DPA is adapted from the Common Paper Data Processing Agreement (Version 1.1) by Common Paper, https://commonpaper.com/standards/data-processing-agreement/1.1/, licensed under CC BY 4.0 and provided without warranties (see the license's disclaimer). Modified by UNTAP LLC: restructured into a single document; EEA/UK/Swiss transfer terms removed; US-only processing; company-specific instructions, incident, subprocessor, retention and audit terms added; CCPA and FTC Safeguards Rule sections added.
Drafting note
Sources checked 2026-09-24 (drafting note; strip before publishing):
- Common Paper DPA v1.1 and license statement — https://commonpaper.com/standards/data-processing-agreement/ ("Common Paper agreements are free to use and modify under CC BY 4.0").
- CC BY 4.0 legal code §3(a) (attribution: creator, license notice, disclaimer notice, link, and indicate modifications) — https://creativecommons.org/licenses/by/4.0/legalcode.en
- Cal. Civ. Code §1798.140(ag) — https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV§ionNum=1798.140
- Cal. Civ. Code §1798.100(d) — https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV§ionNum=1798.100
- 11 CCR §7051 (approved text, effective 2026-01-01; OAL approval 2025-09-22) — https://cppa.ca.gov/regulations/pdf/ccpa_updates_cyber_risk_admt_appr_text.pdf and https://cppa.ca.gov/regulations/ccpa_updates.html
- 16 CFR 314.4(f), (j) — https://www.ecfr.gov/current/title-16/part-314/section-314.4
Open items
- [unverified] Whether Google Cloud's and Supabase's current data-processing terms contain CCPA service-provider restrictions meeting §3.2. Check each before publishing.
- Terms §14.4 incorporates this DPA by reference.
- Build dependencies: written deletion confirmation (§8.2), logged personnel access (§2.3), questionnaire answer bank (
legal-docs-plan.md§3).