Skip to main content

Data Processing Addendum

Last updated: 2026-07-05 (v1.0)

This Data Processing Addendum ("DPA") supplements our Terms of Service and applies whenever CodeSpar processes personal data on behalf of a customer, acting as a processor. Need a countersigned copy for enterprise procurement? Email legal@codespar.dev.

1. Scope and roles

This DPA applies where CodeSpar processes personal data on a customer's behalf and instructions in connection with the Service (the processor role), as opposed to personal data CodeSpar processes as controller for its own account and billing purposes, which is covered by our Privacy Policy.

2. Subject matter, duration, nature, and purpose

The subject matter of the processing is the personal data a customer submits to, or generates through, the Service in the course of agentic payments orchestration and governance (mandates, policy checks, transaction routing, receipts, and audit). The duration of the processing is the term of the customer's agreement with CodeSpar, plus any retention period described in section 10. The nature and purpose of the processing is to provide, secure, and support the Service on the customer's instructions.

3. Categories of data subjects and data

The data subjects are the customer's own end users, consumers, and the principals behind the agents the customer operates on the Service. The categories of data are: identification data (name, identifiers), contact data (email, phone), transaction metadata (amounts, timestamps, routing details, receipts), and KYC results (outcome of identity or sanctions checks run through the Service).

4. Customer instructions

CodeSpar will process personal data only on the customer's documented instructions, including those given through the Service's configuration (policies, mandates, connector setup) and this DPA, unless required to do otherwise by law, in which case CodeSpar will tell the customer about that legal requirement first, unless the law prohibits this.

5. Confidentiality

CodeSpar ensures that personnel authorized to process personal data have committed to confidentiality or are under an appropriate statutory obligation of confidentiality.

6. Security measures

CodeSpar maintains technical and organizational measures including:

  • encryption of data at rest using AES-256-GCM;
  • encryption of data in transit using TLS;
  • per-tenant vault keys, so one customer's secrets and data are cryptographically isolated from another's;
  • hash-chained audit logs, so the audit trail cannot be silently altered after the fact; and
  • access controls limiting who can reach production data, and why.

7. Subprocessors

CodeSpar uses subprocessors to help provide the Service. The current list is published at codespar.dev/legal/subprocessors. CodeSpar will give notice of new subprocessors as described on that page, and imposes data protection obligations on its subprocessors that are consistent with this DPA.

8. Assistance with data-subject requests

Taking into account the nature of the processing, CodeSpar will reasonably assist the customer in responding to requests from data subjects exercising their rights, and in the customer's compliance obligations relating to the security of processing, breach notification, and data protection impact assessments, to the extent the customer does not have access to the relevant information itself.

9. Breach notification

CodeSpar will notify the customer without undue delay after becoming aware of a personal data breach affecting the customer's data, and will provide the information reasonably available to it to help the customer meet its own notification obligations.

10. Deletion and return at termination

On termination of the customer's agreement with CodeSpar, and subject to any retention required by law (for example, financial-audit recordkeeping requirements), CodeSpar will delete or return the customer's personal data at the customer's choice.

11. Audits

CodeSpar will make available the information reasonably necessary to demonstrate compliance with this DPA, in the first instance through security summaries and available certifications. Where those are not sufficient, the parties will agree on the scope, timing, and confidentiality terms of any further audit.

12. International transfers

Where CodeSpar transfers personal data internationally in connection with the Service, it uses appropriate safeguards, including the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) where GDPR applies, and LGPD-compliant safeguards for transfers involving Brazil.

13. Liability

Each party's liability arising out of this DPA is subject to the limitations of liability set out in the Terms of Service.

Need a countersigned copy for enterprise procurement? Email legal@codespar.dev.

Data Processing Addendum | CodeSpar