Introduction
Effective date: May 24, 2026
Last updated: May 24, 2026
This Data Processing Addendum (the DPA) supplements the Terms of Service or other written agreement between Plain Dot, Inc. (Plain Dot, we, us, or our) and the customer identified in that agreement (Customer or you) (together, the Agreement) governing your use of the Plain Dot platform, APIs, MCP server, and related services (the Services).
This DPA sets the terms on which Plain Dot Processes Personal Information on your behalf in the United States. It applies to any Processing of Personal Information by Plain Dot that is subject to a US Data Protection Law (defined below), including Processing of information you submit about your payees, employees, contractors, customers, or other third parties.
1. Definitions
Capitalized terms used and not defined in this DPA have the meanings given in the Agreement. The following terms have the meanings below:
- Affiliate means an entity that controls, is controlled by, or is under common control with a party.
- Business, Service Provider, Contractor, Sell, Share, and Sensitive Personal Information have the meanings given in the CCPA.
- CCPA means the California Consumer Privacy Act, as amended by the California Privacy Rights Act, and its implementing regulations.
- Customer Personal Information means Personal Information that Plain Dot Processes on Customer's behalf in providing the Services, including information about Customer's payees, employees, contractors, customers, and other third parties.
- Federal Tax Information or FTI has the meaning given in IRS Publication 1075.
- GLBA means the Gramm-Leach-Bliley Act and its implementing regulations, including the FTC Safeguards Rule at 16 CFR Part 314.
- Individual means an identified or identifiable natural person to whom Personal Information relates, and includes a "consumer" under the CCPA and equivalent terms under other US Data Protection Laws.
- Personal Information means any information that identifies, relates to, describes, or could reasonably be linked, directly or indirectly, with a particular Individual or household, and includes "personal data," "personally identifiable information," and similar terms under any US Data Protection Law.
- Personal Information Breach means a breach of security leading to the unauthorized acquisition of, access to, loss of, or disclosure of, Personal Information.
- Process (and Processing) means any operation performed on Personal Information, whether or not by automated means, including collection, recording, organization, structuring, storage, use, disclosure, transmission, deletion, and destruction.
- Subprocessor means a third party (other than Plain Dot or its Affiliates) engaged by Plain Dot to Process Customer Personal Information.
- US Data Protection Law means any US federal or state law applicable to the Processing of Personal Information under this DPA, including the CCPA and other US state comprehensive privacy laws (such as the Virginia VCDPA, Colorado CPA, Connecticut CTDPA, Utah UCPA, Texas TDPSA, Oregon OCPA, Montana MCDPA, Iowa ICDPA, Delaware DPDPA, New Hampshire NHPA, New Jersey NJDPA, Tennessee TIPA, Indiana ICDPA, Kentucky KCDPA, Maryland MODPA, Minnesota MCDPA, Rhode Island RIDTPPA, and Nebraska NDPA), state breach-notification statutes, GLBA, IRC § 7216 and its implementing regulations, IRS Publication 1075, and IRS Publication 1345.
2. Roles and Scope
2.1. Roles. With respect to Customer Personal Information:
- You decide what Personal Information to submit, why, and what we should do with it. You are the Business under the CCPA and the equivalent decision-making party (sometimes called "controller") under other US Data Protection Laws.
- We Process Customer Personal Information on your behalf and on your documented instructions. We are a Service Provider (or, where applicable, Contractor) under the CCPA and the equivalent service-side party (sometimes called "processor") under other US Data Protection Laws.
2.2. Subject matter, duration, nature, and purpose. The subject matter and duration of the Processing, the nature and purpose of the Processing, the categories of Individuals, and the categories of Personal Information are described in Annex 1.
2.3. Documented instructions. Your instructions for Processing Customer Personal Information are: (a) this DPA and the Agreement (including any Order Form, SOW, or product documentation); (b) any in-product configuration choices you make; and (c) any other written instructions you give us that are consistent with the Agreement and this DPA. If we believe an instruction violates a US Data Protection Law, we will tell you and we may decline to perform that instruction until you withdraw or modify it.
2.4. Our own data. Plain Dot is the Business (and equivalent decision-making party) with respect to Personal Information we collect about your account contacts, billing contacts, and Authorized Users in the course of providing, marketing, and supporting the Services. Our handling of that information is described in our Privacy Policy and is outside the scope of this DPA.
3. Processing Restrictions
3.1. Limitation on use. We will Process Customer Personal Information only:
- to provide and support the Services in accordance with the Agreement;
- to comply with your documented instructions;
- to comply with applicable law (in which case we will tell you of the legal requirement before Processing, unless prohibited by law); and
- for the limited internal uses permitted to a Service Provider/Contractor under the CCPA and the equivalent service-side party under other US Data Protection Laws — for example, building or improving the quality of the Services, performing security and fraud detection, and complying with legal obligations — in each case in a manner that does not identify or target individual Individuals.
3.2. CCPA service-provider terms. Plain Dot is acting as a Service Provider (or, where applicable, Contractor) with respect to Customer Personal Information that is "personal information" of a California consumer under the CCPA. We:
- will not Sell or Share Customer Personal Information;
- will not retain, use, or disclose Customer Personal Information outside the direct business relationship between you and us, or for any purpose other than the Business Purposes specified in the Agreement and this DPA, except as permitted under the CCPA;
- will not combine Customer Personal Information with personal information we receive from or on behalf of other persons, except as expressly permitted under the CCPA (for example, to perform a Business Purpose);
- will provide the same level of privacy protection to Customer Personal Information as required of a Business under the CCPA; and
- will notify you promptly if we determine we can no longer meet our obligations under the CCPA, and will allow you to take reasonable and appropriate steps to stop and remediate any unauthorized use of Customer Personal Information.
You may take reasonable and appropriate steps to ensure we use Customer Personal Information consistently with your obligations under the CCPA, including the audit and compliance-assistance steps in this DPA.
3.3. Other US state privacy laws. To the extent any other US state Data Protection Law applies to our Processing, Plain Dot is acting as the service-side party ("processor" or equivalent term) for you, and the terms of this DPA are intended to satisfy the requirements of those laws for a controller-processor contract, including the duty-to-assist, breach-notification, subprocessor, audit, and return-or-deletion requirements.
3.4. Sensitive Personal Information. Customer Personal Information may include Sensitive Personal Information (including Social Security numbers and other government identifiers, financial account information, and account credentials). We will Process Sensitive Personal Information only as needed to provide the Services, to comply with law, and for the limited purposes permitted by applicable US Data Protection Law. We will not use Sensitive Personal Information to infer characteristics about Individuals and we will not use, sell, or share Sensitive Personal Information for cross-context behavioral advertising.
3.5. Federal Tax Information and tax-return information. To the extent Customer Personal Information includes FTI within the meaning of IRS Publication 1075 or "tax return information" within the meaning of IRC § 7216 and 26 C.F.R. § 301.7216, we will (a) treat it as confidential, (b) maintain controls aligned with the applicable IRS safeguards, and (c) use and disclose it only as needed to provide the Services or as required by law. Where IRC § 7216 requires Customer to obtain written consent from an Individual before we may use or disclose such information for any purpose other than providing the Services, Customer is responsible for obtaining and maintaining that consent.
3.6. IRS Authorized e-file Provider rules. To the extent we transmit filings on Customer's behalf through IRS systems (such as IRIS or FIRE), we will maintain controls aligned with IRS Publication 1345 applicable to Authorized IRS e-file Providers, including logging the IP address and timestamp of submissions and retaining e-file authorization records (such as Form 8879 or 8453-series authorizations) as required by IRS rules and Customer's instructions.
3.7. GLBA Safeguards Rule flow-down. To the extent Customer is a "financial institution" under the FTC Safeguards Rule (16 CFR Part 314) and Customer Personal Information includes "customer information" under that Rule, this DPA constitutes the written contract required by 16 CFR § 314.4(f). Plain Dot will (a) implement and maintain an information security program reasonably designed to protect Customer Personal Information, (b) provide Customer with reasonable assistance in connection with Customer's own Safeguards Rule obligations, and (c) notify Customer of Personal Information Breaches as set out in Section 7.
4. Confidentiality and Personnel
We will ensure that personnel authorized to Process Customer Personal Information (a) are bound by appropriate confidentiality obligations (whether by contract or by statutory duty), (b) receive appropriate training on data protection and security, and (c) Process Customer Personal Information only on a need-to-know basis.
5. Security
5.1. Security measures. We will implement and maintain appropriate technical and organizational measures to protect Customer Personal Information against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, and unauthorized access. A description of those measures is set out in Annex 2.
5.2. Updates. We may update our security measures from time to time, but no update will materially reduce the overall protection of Customer Personal Information.
5.3. Customer responsibilities. You are responsible for (a) using the Services and any Customer-side security controls (such as multi-factor authentication, SSO configuration, IP allow-lists, and role-based permissions) in a manner that provides appropriate protection for Customer Personal Information; (b) maintaining the security of your own systems and credentials; and (c) determining whether the security measures in Annex 2 meet your own legal and contractual requirements.
6. Subprocessors
6.1. General authorization. You authorize us to engage Subprocessors to Process Customer Personal Information, subject to this Section 6. Our current Subprocessors are listed in Annex 3 (or at the URL referenced in Annex 3).
6.2. Flow-down obligations. Before a Subprocessor begins Processing Customer Personal Information, we will enter into a written contract with the Subprocessor that imposes obligations on the Subprocessor that are substantially the same as the obligations we owe you under this DPA, including the CCPA service-provider terms.
6.3. Notice of changes. We will give you notice of any addition or replacement of a Subprocessor at least 30 days before authorizing that Subprocessor to Process Customer Personal Information. Notice may be given by email, in-product notification, or by updating the Subprocessor list at the URL referenced in Annex 3 (with a mechanism for you to subscribe to updates).
6.4. Objection. You may object to a new Subprocessor on reasonable data-protection grounds by giving us written notice within 15 days of our notice. The parties will work in good faith to resolve the objection. If the objection cannot be resolved, you may terminate the affected Services as your sole and exclusive remedy by giving written notice within 30 days of our notice, and we will refund any prepaid, unused Fees for the terminated portion.
6.5. Liability for Subprocessors. We remain responsible for the acts and omissions of our Subprocessors to the same extent as for our own acts and omissions under the Agreement.
6.6. US location. Our Subprocessors will Process Customer Personal Information in the United States, except where Customer expressly authorizes Processing outside the United States in writing.
7. Breach Notification
7.1. Notification. We will notify you without undue delay, and in any event no later than 72 hours after we confirm a Personal Information Breach affecting Customer Personal Information.
7.2. Information provided. Our notification will include, to the extent then known (and we will supplement as additional information becomes available): (a) a description of the nature of the Personal Information Breach, including, where possible, the categories and approximate number of Individuals and records affected; (b) the likely consequences of the Breach; (c) the measures we have taken or propose to take to address the Breach and to mitigate its possible adverse effects; and (d) a point of contact for further information.
7.3. Cooperation. We will reasonably cooperate with you in your investigation, mitigation, and notification of any Personal Information Breach, including assistance you reasonably need to satisfy your obligations under applicable state breach-notification statutes, the CCPA, GLBA, and other applicable US Data Protection Laws.
7.4. Tax-specific notification. Where Customer Personal Information includes FTI, we will follow the incident-notification practices aligned with IRS Publication 1075 § 10 (including notifying the appropriate parties within the time periods specified there) as applicable.
7.5. No admission. Our notification of, or response to, a Personal Information Breach is not an acknowledgment of fault or liability on our part.
8. Individual Rights
8.1. Assistance with Individual requests. Where an Individual submits a request to us regarding Customer Personal Information (for example, a request for access, correction, deletion, portability, opt-out of sale or sharing, opt-out of targeted advertising or profiling, or limitation on use of Sensitive Personal Information under the CCPA or another US Data Protection Law), we will (a) promptly notify you (or, where reasonable and permitted by law, refer the Individual to you directly) and (b) reasonably cooperate with you in responding to the request, taking into account the nature of the Processing and the information available to us.
8.2. Assistance with regulators and data protection assessments. Taking into account the nature of the Processing and the information available to us, we will provide reasonable assistance to you in (a) responding to inquiries or investigations from US federal or state regulators, including state attorneys general; and (b) carrying out data protection assessments required under US state privacy laws (such as those required under Colorado CPA § 6-1-1309, Virginia VCDPA § 59.1-580, Connecticut CTDPA § 8, and similar laws).
9. Data Location
We Process Customer Personal Information in the United States. We do not knowingly Process Customer Personal Information outside the United States, and our Subprocessors are required to do the same. If we ever propose to Process Customer Personal Information outside the United States, we will notify you in advance and obtain any additional contractual mechanisms required by US Data Protection Laws and your instructions.
10. Audits
10.1. Information and certifications. On reasonable request, we will make available to you the information necessary to demonstrate compliance with this DPA, including by providing summaries of our most recent independent audit reports or certifications (for example, SOC 2 Type II, where available) under appropriate confidentiality obligations.
10.2. Audits. If the information made available under Section 10.1 is not sufficient to demonstrate our compliance, you may, on reasonable prior written notice (not less than 30 days except in the case of a Personal Information Breach or as required by a regulator), audit our Processing of Customer Personal Information, subject to the following:
- audits will be conducted no more than once per year, except as required by a regulator or following a confirmed Personal Information Breach;
- audits will be conducted during normal business hours, in a manner that does not unreasonably disrupt our operations, and subject to appropriate confidentiality protections;
- audits will be conducted by you or by a mutually agreed independent third-party auditor that is not a competitor of ours;
- you will bear the cost of the audit unless the audit reveals our material non-compliance, in which case we will reimburse your reasonable costs; and
- you will share the audit findings with us promptly, treat them as our Confidential Information, and use them only to confirm our compliance with this DPA.
10.3. Regulator audits. We will cooperate with audits and inspections by US federal or state regulators having jurisdiction over the Processing.
11. Return and Deletion
11.1. End of Processing. Following expiration or termination of the Agreement (or earlier on your written request and at your cost), we will, at your choice, (a) make Customer Personal Information available for export in a commercially reasonable machine-readable format for 60 days and then delete it; or (b) delete Customer Personal Information from our active systems.
11.2. Retention required by law. Notwithstanding Section 11.1, we may retain Customer Personal Information to the extent (and for the period) required by applicable law, regulation, or government order — including IRS recordkeeping rules applicable to filings transmitted through the Services and state tax-record retention rules. We will continue to protect retained Customer Personal Information in accordance with this DPA until deletion.
11.3. Backups. Customer Personal Information held in our routine encrypted backup or archival systems will be deleted in the ordinary course of our backup-rotation schedule.
12. Liability
The aggregate liability of each party under or in connection with this DPA is subject to the limitations of liability set out in the Agreement. Nothing in this DPA limits or excludes either party's liability to an Individual under applicable US Data Protection Law.
13. Term and Conflict
13.1. Term. This DPA takes effect on the Effective Date and remains in effect for as long as we Process Customer Personal Information. Sections that by their nature should survive (including those on confidentiality, breach notification, return or deletion, audits, and liability) survive termination.
13.2. Conflict. If there is a conflict between this DPA and the Agreement with respect to the Processing of Personal Information, this DPA controls.
13.3. Updates. We may update this DPA from time to time to reflect changes in US Data Protection Law or to reflect changes in our Services or security program. We will give you reasonable advance notice of material changes, and updates will not materially reduce the protection of Customer Personal Information.
13.4. Governing law. This DPA is governed by the law specified in the Agreement.
Annex 1 — Processing
- A. List of parties. The Customer is the Business; Plain Dot is the Service Provider. Contact details and roles are as set out in the Agreement and Section 2 of this DPA.
- B. Subject matter of the Processing. Provision of the Services to Customer.
- C. Duration of the Processing. For the term of the Agreement, plus any period of post-termination return or deletion under Section 11 and any retention required by law.
- D. Nature and purpose of the Processing. Hosting, storing, transmitting, validating, classifying, matching, generating, transmitting to government systems, archiving, and otherwise Processing Customer Personal Information as needed to provide the Services described in the Agreement (including 1099 filing, TIN matching, W-9 collection, ACA reporting, Form 720 excise filing, and other regulated workstreams Customer enables).
- E. Categories of Individuals. Customer's Authorized Users; Customer's payees, employees, contractors, customers, and other individuals about whom Customer submits information to the Services; and other individuals whose information Customer submits to the Services.
- F. Categories of Personal Information. Identifiers (name, business name, email, phone, mailing address, account credentials, IP address); government identifiers (TINs including SSNs and EINs); financial information (payee/employer information, payment amounts, withholding information, bank or payment-card reference tokens); employment and benefits information (where relevant to ACA reporting or other workstreams); communications and correspondence; technical, device, and usage data; and any other categories Customer chooses to submit to the Services.
- G. Sensitive Personal Information. Social Security numbers and other government identifiers; financial account information; account credentials. Processed only as set out in Section 3.4 and Annex 2.
- H. Frequency of the Processing. Continuous, for the term of the Agreement.
- I. Retention. As described in the Plain Dot Privacy Policy and Section 11 of this DPA.
- J. Subprocessors. As described in Annex 3.
- K. Processing location. United States.
Annex 2 — Security
This Annex describes the technical and organizational measures we maintain to protect Customer Personal Information. We may update these measures from time to time provided no update materially reduces the overall level of protection.
- Governance. Information security program with documented policies, an executive owner, regular risk assessments, and an annual policy review.
- Personnel security. Background checks (as permitted by law) for personnel with access to Customer Personal Information; mandatory confidentiality obligations; security and privacy training at onboarding and annually thereafter.
- Access control. Role-based access control with least-privilege provisioning; mandatory multi-factor authentication for administrative access; centralized identity management; access reviews on a regular cadence; immediate revocation on personnel changes.
- Encryption. Encryption of Customer Personal Information in transit (TLS 1.2 or higher) and at rest (AES-256 or equivalent); secure key-management practices.
- Network and system security. Segmented network architecture; firewalls and intrusion-detection controls; hardened images; vulnerability management; patch management on a documented cadence; endpoint protection.
- Application security. Secure software-development lifecycle with peer code review; static and dynamic analysis; dependency scanning; annual third-party penetration testing of the Services.
- Logging and monitoring. Centralized logging of security-relevant events, including authentication, access to Customer Personal Information, administrative actions, and filings transmitted on Customer's behalf (including IP address and timestamp for IRS e-file authentication); alerting and incident triage.
- Data segregation. Logical separation of Customer environments and data within a multi-tenant architecture.
- Backups and resilience. Encrypted backups on a documented schedule; tested restoration procedures; documented business continuity and disaster recovery plans.
- Vendor risk management. Security and privacy review of Subprocessors before engagement; contractual flow-down of security and confidentiality obligations.
- Physical security. Reliance on US-based commercial cloud-provider data centers with industry-recognized physical security certifications (for example, SOC 2 Type II, ISO 27001).
- Incident response. Documented incident-response plan with defined roles, response timelines, and post-incident review; integrated with the breach-notification commitments in Section 7.
- Tax-specific safeguards. For workstreams involving FTI, controls aligned with IRS Publication 1075. For IRS-authorized e-file activities, controls aligned with IRS Publication 1345.
Annex 3 — Subprocessors
The following Subprocessor Processes Customer Personal Information on our behalf as of the Last updated date above. The current list is also maintained at https://www.plaindot.com/subprocessors and is updated in line with Section 6.
| Subprocessor | Purpose | Data categories | Location |
|---|---|---|---|
Amazon Web Services, Inc. | Cloud hosting, storage, compute, and managed database infrastructure underlying the Services. | All categories of Customer Personal Information described in Annex 1. | United States |
AWS is currently our sole infrastructure Subprocessor. Plain Dot has no Affiliates that Process Customer Personal Information.
Customer may subscribe to changes to the Subprocessor list by emailing hello@plaindot.com with the subject line "Subprocessor updates".
Questions about this DPA? Email hello@plaindot.com.