Version 1.0Effective September 7, 2026Canonical text (.md)
On this page
  1. 1. Definitions
  2. 2. Scope and roles
  3. 3. Customer's responsibilities
  4. 4. Bucketize's obligations
  5. 5. Security
  6. 6. Subprocessors
  7. 7. Data-subject requests
  8. 8. Security Incidents
  9. 9. Assistance
  10. 10. Audits and reports
  11. 11. Return and deletion
  12. 12. International transfers
  13. 13. Liability
  14. 14. General
  15. Annex 1 — Details of processing
  16. Annex 2 — Technical and organizational measures
  17. Annex 3 — Subprocessors

Bucketize Data Processing Addendum

Version 1.0 · Effective September 7, 2026

This Data Processing Addendum ("DPA") forms part of the Bucketize Terms of Service, or of any other written agreement between the customer ("Customer") and Lilac Impact Ventures LLC d/b/a Bucketize ("Bucketize") that references it (together, the "Agreement"). It applies automatically whenever Bucketize processes personal data on Customer's behalf; no signature is needed. If Customer's procurement process requires a countersigned copy, email legal@bucketize.org and we will sign this standard DPA. On matters of personal-data protection this DPA controls over the rest of the Agreement.

1. Definitions#

  • "Customer Personal Data" — personal data contained in Customer Data (as defined in the Agreement) that Bucketize processes on Customer's behalf.
  • "Data Protection Laws" — all laws that apply to the processing of Customer Personal Data under the Agreement, including, where applicable, the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA"), and other U.S. state privacy laws.
  • "Personal data", "controller", "processor", "data subject", "processing" and "supervisory authority" have the meanings given in Data Protection Laws; under the CCPA, "controller" includes "business" and "processor" includes "service provider".
  • "Security Incident" — a confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data in Bucketize's possession. Unsuccessful attempts (such as blocked login attempts or port scans) are not Security Incidents.
  • "Standard Contractual Clauses" or "SCCs" — the standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission in Implementing Decision (EU) 2021/914.
  • "Subprocessor" — a third party engaged by Bucketize to process Customer Personal Data on Bucketize's behalf.
  • "UK Addendum" — the International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner (version B1.0).

2. Scope and roles#

2.1 Roles. Customer is the controller (or business) of Customer Personal Data and Bucketize is its processor (or service provider). If Customer itself acts as a processor for a third-party controller, Bucketize is Customer's subprocessor, and Customer warrants that its controller has authorized the processing described here.

2.2 Details of processing. The subject matter, duration, nature and purpose of processing, the types of personal data and the categories of data subjects are described in Annex 1.

2.3 Instructions. Bucketize will process Customer Personal Data only on Customer's documented instructions, which consist of: the Agreement; Customer's and its users' configuration and use of the Service (including which integrations, modules and AI features are enabled); and other written instructions Customer gives that are consistent with the Agreement. Bucketize will tell Customer if, in its opinion, an instruction infringes Data Protection Laws, and may suspend that instruction until it is resolved. Bucketize may also process Customer Personal Data where required by law, in which case it will inform Customer of the requirement before processing unless the law prohibits it.

2.4 Compliance. Each party will comply with the Data Protection Laws that apply to it.

3. Customer's responsibilities#

Customer is responsible for: (a) having a lawful basis for the collection and processing of Customer Personal Data and for its transfer to Bucketize; (b) giving any notices and obtaining any consents that Data Protection Laws require, including to its employees and candidates whose compensation or workforce-planning data it places in the Service; (c) the accuracy and quality of Customer Personal Data; (d) configuring the Service's roles, module access and delegation so that only appropriate users can access sensitive data; (e) not submitting Prohibited Data (Agreement §4.7); and (f) responding to data-subject requests concerning Customer Personal Data, with Bucketize's assistance under §7.

4. Bucketize's obligations#

4.1 Purpose limitation. Bucketize will process Customer Personal Data only to provide, secure, support and maintain the Service under the Agreement, and for no other purpose.

4.2 Service-provider certifications (U.S. state law). Bucketize will not: sell Customer Personal Data; share it for cross-context behavioral advertising; retain, use or disclose it for any purpose other than the business purposes specified in the Agreement, or outside the direct business relationship between the parties; or combine it with personal data it receives from other sources, except as permitted for service providers under the CCPA. Bucketize certifies that it understands and will comply with these restrictions, will notify Customer if it can no longer meet them, and grants Customer the right to take reasonable and appropriate steps to stop and remediate unauthorized use.

4.3 No model training. Bucketize will not use Customer Personal Data — or any other Customer Data — to train, fine-tune or improve any generalized machine-learning or AI model, and will contractually require each Subprocessor that provides AI models to Bucketize to refrain from doing so. This does not restrict the operation, monitoring, debugging and improvement of the Service using data that contains no Customer Data.

4.4 Confidentiality of personnel. Bucketize will ensure that every person it authorizes to process Customer Personal Data is bound by a duty of confidentiality and has access only to the extent needed for their role.

4.5 Records and cooperation. Bucketize will maintain the records of processing that Data Protection Laws require of a processor and will cooperate with a supervisory authority as required by law, informing Customer where permitted.

5. Security#

5.1 Measures. Bucketize will implement and maintain the technical and organizational measures described in Annex 2, and any others appropriate to the risk, to protect Customer Personal Data against Security Incidents. Bucketize may update those measures over time but will not materially reduce the overall level of protection during the term of the Agreement.

5.2 Customer's part. Customer is responsible for the security of its own systems and networks, its users' credentials and devices, its Connected Services, and its use of the Service's access controls.

6. Subprocessors#

6.1 Authorization. Customer gives general authorization for Bucketize to engage the Subprocessors listed at bucketize.org/subprocessors (Annex 3), which shows each Subprocessor's purpose, the data it processes and its location, and distinguishes always-on infrastructure from Subprocessors engaged only when a feature is enabled.

6.2 Changes. Bucketize will give Customer at least 30 days' notice before authorizing a new or replacement Subprocessor to process Customer Personal Data, by email to Customer's organization administrators and by updating the subprocessor page. Customer may object in writing within 30 days of the notice on reasonable, documented data-protection grounds. The parties will then work in good faith to resolve the objection — for example by Customer disabling the feature that uses the Subprocessor. If they cannot within 30 days of the objection, Customer may terminate the affected Order Form or feature without penalty, and Bucketize will refund prepaid fees for the unused portion of the Subscription Term of any terminated Order Form. Changing or adding an AI model provider is a Subprocessor change under this section.

6.3 Flow-down and liability. Bucketize will impose on each Subprocessor, by written contract, data-protection obligations that protect Customer Personal Data to a standard no less protective than this DPA, and remains liable to Customer for each Subprocessor's performance of those obligations.

7. Data-subject requests#

If Bucketize receives a request from a data subject relating to Customer Personal Data (for example, a request from Customer's employee to access or delete their compensation record), Bucketize will not respond on the merits, but will forward the request to Customer within five business days and tell the requester it has done so. Bucketize will assist Customer in responding, through the Service's export, correction and deletion features where they suffice and otherwise through reasonable additional assistance, taking into account the nature of the processing.

8. Security Incidents#

Bucketize will notify Customer's organization administrators of a Security Incident without undue delay, and in any event within 72 hours after confirming it. The notice will describe, to the extent known, the nature of the incident, the categories and approximate number of data subjects and records affected, the likely consequences, the measures taken or proposed to address it, and a point of contact. Bucketize will update Customer as material information becomes available and will cooperate reasonably with Customer's investigation and any notifications Customer must make. Notification is not an admission of fault.

9. Assistance#

Taking into account the nature of the processing and the information available to it, Bucketize will provide reasonable assistance to Customer with data-protection impact assessments and prior consultations with supervisory authorities that concern the Service. Bucketize may charge reasonable fees for assistance that goes beyond what the Service and this DPA already provide, and will say so in advance.

10. Audits and reports#

10.1 What we provide. On request, no more than once per year unless a Security Incident or a supervisory authority requires otherwise, Bucketize will provide: written responses to Customer's reasonable security questionnaire; a summary of Bucketize's most recent internal control assessment; and a summary of the most recent third-party penetration test, if one has been performed. When Bucketize obtains a third-party attestation (such as a SOC 2 report), it will provide the report under confidentiality obligations in place of the internal summary. Bucketize does not currently hold a third-party attestation and will not represent otherwise.

10.2 Audits. If the materials in §10.1 are not reasonably sufficient to demonstrate compliance with this DPA, or an audit is required by a supervisory authority or Data Protection Laws, Customer (or an independent auditor it appoints who is not a competitor of Bucketize and is bound by confidentiality) may audit Bucketize's compliance with this DPA once per year, on at least 30 days' written notice, during business hours, in a manner that does not disrupt Bucketize's operations or expose other customers' data, and at Customer's expense. Bucketize will address any material non-conformance the audit identifies.

11. Return and deletion#

When the Agreement (or the relevant Order Form) ends, Bucketize will make Customer Data available for export for 30 days and then delete Customer Personal Data from its production systems within 60 days, with copies in backups overwritten in the ordinary course within 90 days after that, as described in Agreement §11.5. Bucketize may retain Customer Personal Data to the extent required by law, and may retain the tamper-evident audit-log records described in Annex 1 in a form isolated from active processing to preserve the log's integrity; retained data remains subject to this DPA and the Agreement's confidentiality obligations. On written request Bucketize will confirm deletion in writing.

12. International transfers#

12.1 Location. Bucketize processes Customer Personal Data in the United States (production database and authentication in the AWS us-east-1 region; application logic on a global edge network; Subprocessors as listed in Annex 3).

12.2 EEA, UK and Swiss transfers. To the extent Customer transfers Customer Personal Data that is subject to the GDPR, UK GDPR or Swiss data-protection law to Bucketize in the United States, the parties enter into the SCCs, which are incorporated into this DPA by reference, as follows:

  • Module Two (controller to processor) applies where Customer is a controller, and Module Three (processor to processor) applies where Customer is a processor; Customer is the "data exporter" and Bucketize the "data importer".
  • Clause 7 (docking) is not included. In Clause 9, Option 2 (general written authorization) applies with the notice period in §6.2. The optional language in Clause 11 is not included. In Clause 13, the supervisory authority is that of the EU member state in which Customer is established or, if Customer is not established in the EU, that of Ireland. In Clauses 17 and 18, the governing law and courts are those of Ireland.
  • Annex I and Annex II of the SCCs are completed by Annexes 1, 2 and 3 of this DPA.
  • For transfers subject to UK law, the UK Addendum applies, with the tables completed by the information in this DPA and the "Importer" and "Exporter" being the parties above; the option in Table 4 permitting either party to end the Addendum applies to neither party.
  • For transfers subject to Swiss law, the SCCs are adapted so that references to the GDPR are read as references to the Swiss Federal Act on Data Protection, the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner, and the term "member state" is read to include Switzerland so that Swiss data subjects may bring claims in their place of habitual residence.

12.3 Other mechanisms. If a transfer mechanism in §12.2 is invalidated or Bucketize adopts an additional approved mechanism (such as a certification under the EU-U.S. Data Privacy Framework), the parties will cooperate in good faith to rely on a valid alternative, and the SCCs will continue to apply to the extent they remain valid.

13. Liability#

Each party's liability arising out of or related to this DPA, including the SCCs, is subject to the exclusions and limitations of liability in the Agreement, and the Agreement's cap applies in aggregate to claims under the Agreement and this DPA together. Nothing in this section limits a data subject's rights under the SCCs.

14. General#

14.1 Term. This DPA lasts for as long as Bucketize processes Customer Personal Data.

14.2 Changes. Bucketize may update this DPA to reflect changes in Data Protection Laws or in the Service, and will give Customer notice under the Agreement's change procedure; changes that materially reduce Customer's protections require Customer's agreement.

14.3 Governing law. This DPA is governed by the law that governs the Agreement, except that the SCCs are governed as stated in §12.2.

14.4 Precedence. If this DPA conflicts with the Agreement, this DPA controls on matters of personal-data protection; if the SCCs conflict with this DPA, the SCCs control.


Annex 1 — Details of processing#

Subject matter. Provision of the Bucketize budget-planning service, including budget trees, forecasting, actuals and invoice matching, headcount and compensation planning, contract and commitment tracking, integrations with Customer's Connected Services, and AI-assisted analysis.

Duration. The term of the Agreement plus the return and deletion periods in §11.

Nature and purpose. Hosting, storage, display, computation, export and backup of Customer Data; retrieval of data from Connected Services at Customer's direction; sending notifications and digests to Customer's users; AI-assisted analysis and import at Customer's direction; security monitoring and support.

Categories of data subjects.

  • Customer's Authorized Users (employees, contractors, advisors and invited external collaborators).
  • Customer's current employees, contractors and planned or open positions, where Customer uses the headcount module or connects an HRIS, payroll or applicant-tracking system.
  • Contacts at Customer's vendors, counterparties and approvers, where they appear in invoices, contracts or approval workflows.
  • People Customer invites to the Service.

Categories of personal data.

  • Authorized Users: name, email address, avatar, role and access grants, activity within the Service (edits, approvals, comments), AI-assistant questions and answers, diagnostic events.
  • Employees and positions: name, title, level, department or function, start and end dates, employment status, FTE percentage, annual salary, bonus, benefits and sign-on amounts, monthly gross pay and employer cost (from payroll), planned compensation bands, tags, notes and custom fields Customer defines, hiring manager, requisition status and decisions.
  • Vendor and counterparty contacts: name, email, company, role in an approval, and invoice or contract details associated with them.
  • Free-text fields (descriptions, notes, request reasons) may contain any personal data Customer's users enter.

Sensitive data. The Service is not designed for, and Customer agrees not to submit, special categories of personal data under the GDPR or "sensitive personal information" under U.S. state law beyond account credentials. Compensation and payroll figures are treated as highly sensitive within the Service and gated by dedicated access controls.

Frequency. Continuous, for the term of the Agreement.

Audit log. The Service keeps a tamper-evident, append-only hash-chained log of changes to budget structures and amounts. Each entry records the user who made the change (by user identifier), the time, and the before-and-after values of the changed fields, which may include free-text names and notes. The log is retained as described in §11 to preserve the integrity of the chain.

Annex 2 — Technical and organizational measures#

AreaMeasures
EncryptionTLS for all connections in transit, with HTTP Strict Transport Security enforced. AES-256 encryption at rest on the database infrastructure. Credentials Customer supplies for Connected Services and any customer-supplied AI provider key are encrypted with AES-256-GCM using per-integration keys held outside the database. Passwords are stored as salted hashes.
Tenant isolationEvery table holding Customer Data carries the owning organization's identifier and is protected by PostgreSQL row-level security; the database itself refuses cross-organization reads and writes, independently of application code. Integration-credential tables allow no direct client access at all.
Access controlRole-based access (owner, admin, FP&A, member, viewer, plus HR and IT seats with restricted scope), per-branch delegation, per-module access grants (headcount and compensation data is available only to explicitly granted users), and approval gates for sign-offs. SAML single sign-on with domain-based provisioning and deprovisioning hooks.
Authorization testingAn automated adversarial test suite signs in as users of different organizations and roles and attempts cross-tenant and cross-role access; it runs on changes to the access model.
Audit loggingA tamper-evident hash-chained log of budget changes with periodic sealed checkpoints; an administrative-action log; history of accrual and position changes.
Application securitySecurity headers (HSTS, content-type protections, frame denial, referrer and permissions policies) enforced on every response and verified on each deploy. Invitation, delegation and authentication tokens are stripped from URLs before any diagnostic tooling runs.
DiagnosticsError monitoring with authentication tokens scrubbed; session replay sampled and configured to mask all text, inputs and media client-side.
Data minimizationUploaded spreadsheets and documents are parsed in the user's browser; only the extracted rows are stored, not the files. Integrations pull only the fields the feature needs.
Backups and resilienceAutomated backups of the production database; versioned budget snapshots with customer-initiated restore; backups stored encrypted and access-restricted.
Environment separationA staging environment with disposable data, backed by a separate database project, is used to verify every change before production. Production data is never used in tests or automated scripts.
Change managementAll changes flow through source control with continuous-integration type-checking, tests and build verification, and a migration guard that blocks deploys when the database schema and application code would diverge.
SecretsApplication secrets and API keys are held in a secrets manager and injected at deploy time; they are not stored in source control.
PersonnelProduction access is limited to named personnel bound by confidentiality obligations.
Vulnerability handlingA published security contact (security@bucketize.org) and a commitment to investigate and respond to reports.
Incident responseA documented process for triage, containment, customer notification under §8, and post-incident review.

Annex 3 — Subprocessors#

The current list of Subprocessors, their purposes, the data they process and their locations is published at bucketize.org/subprocessors and is incorporated into this DPA. Changes are made under §6.


Change log — v1.0 (2026-09-07): first published version.