Processor terms, EU Standard Contractual Clauses (Module 2), and UK Addendum for Parsedit.
Last updated: September 28, 2026
Status: Counsel-reviewable draft. Not legal advice. Does not take effect as a signed contract until accepted as described below. This DPA does not claim GDPR certification, HIPAA compliance, or that a Business Associate Agreement is available.
This Data Processing Addendum (“DPA”) forms part of the Terms of Service (the “Agreement”) between Cauldrn LLC, a California limited liability company (“Processor,” “we”) operating Parsedit, and the customer that accepts the Agreement (“Controller,” “you”). If you use Parsedit on behalf of an organization, you accept this DPA for that organization.
This DPA applies only to Personal Data for which you are controller and Cauldrn is processor (uploaded documents and extracted fields about third parties, and related delivery payloads). Cauldrn is controller of account, billing, security logs, support tickets, and marketing data; those processing activities are described in the Privacy Policy and are not governed by this processor DPA.
Terms not defined here have the meaning in the Agreement, GDPR, UK GDPR, or the EU Standard Contractual Clauses. “GDPR” includes the EU GDPR and, where applicable, the UK GDPR. “Personal Data,” “processing,” “data subject,” and “sub-processor” have GDPR meanings. “SCCs” means the Standard Contractual Clauses annexed to European Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
2.1 You are controller; Cauldrn is processor of Customer Content (documents you upload, extracted fields, and payloads we send to destinations you configure).
2.2 We process Customer Content only on documented instructions: the Agreement, this DPA, your configuration in the Service, and written instructions that are consistent with the Service. We will inform you if, in our opinion, an instruction infringes GDPR (Art. 28(3)(h)).
2.3 We do not use Customer Content to train artificial intelligence or machine learning models, and we do not sell it.
2.4 Duration equals the Agreement plus the retention window in Annex I. You may delete documents, parsers, field templates, and destinations in-app at any time as described in the Privacy Policy — Deleting parsers and templates.
3.1 Confidentiality. Persons authorized to process Customer Content are under confidentiality duties.
3.2 Security. We implement the technical and organizational measures in Annex II. You are responsible for configuring destinations, access roles, and for not uploading special-category or healthcare-regulated data the Service does not support.
3.3 Sub-processors. You authorize the sub-processors in Annex III and our use of replacements on 14–30 days’ notice as described in the Privacy Policy, except emergency security replacements. Sub-processors are bound by data-protection terms no less protective than this DPA. We remain liable for their processing as required by Art. 28(4).
3.4 Assistance. We assist you, taking into account the nature of processing, with data-subject requests (including in-app export and deletion), security, DPIAs, and prior consultation, at our then-current support channels. In-app export is the primary Art. 15/20 mechanism.
3.5 Breach. We notify you without undue delay after becoming aware of a Personal Data Breach affecting Customer Content, with information reasonably available to us to help you meet Art. 33/34. See also our incident clocks in internal policy (GDPR 72 hours).
3.6 Return/deletion. When the Agreement ends, or earlier per the retention schedule, we delete Customer Content from production systems within the windows in Annex I, except copies in backups until they rotate, and except data we must retain as controller (billing, fraud tombstones, audit metadata without document contents). You may export before deletion. User-initiated parser or document deletion is described in Annex I and the Privacy Policy.
3.7 Audits. Upon reasonable written request, not more than once per 12 months unless a competent authority or documented incident requires more, we will provide security summaries and, where required by GDPR, permit an audit under confidentiality, during business hours, without disrupting operations. You may not access other customers’ data.
3.8 International transfers. Transfers of Customer Content from the EEA to the United States are governed by the SCCs Module 2 (controller → processor) in Annex IV. Transfers from the UK are governed by the UK Addendum / IDTA in Annex V. An Art. 27 representative (when appointed) is not a transfer tool.
You warrant that you have a lawful basis and all notices/consents required to upload documents (including documents about third parties). You must not upload protected health information (PHI), medical records, or other healthcare-regulated documents. The Service does not support healthcare processing and does not offer a Business Associate Agreement.
SCCs prevail over this DPA for EEA restricted transfers. This DPA prevails over the Agreement on data-protection conflicts for processor activities. The Privacy Policy describes notices to data subjects; it does not reduce SCC protections.
Processor: Cauldrn LLC — privacy@parsedit.com
EU / UK Art. 27 representatives — to be appointed (planned vendor: DataRep); not a DPO; not an establishment. Until the mandate pack is issued, use privacy@parsedit.com. Placeholders below are not a street address:
Controller: the customer entity accepting the Agreement (name, address, and contact as in the Parsedit account).
Processor: Cauldrn LLC, California, United States. Privacy: privacy@parsedit.com. Support: support@parsedit.com.
Processor’s EU GDPR Art. 27 representative: to be appointed (planned vendor: DataRep) — TODO_DATAREP_EU_NAME; TODO_DATAREP_EU_ADDRESS; TODO_DATAREP_EU_EMAIL (placeholders until the mandate pack is issued; do not treat TODO_* as a street address).
Processor’s UK GDPR Art. 27 representative: to be appointed (planned vendor: DataRep) — TODO_DATAREP_UK_NAME; TODO_DATAREP_UK_ADDRESS; TODO_DATAREP_UK_EMAIL.
created_at; Pro, Business = 365 days. Legal hold skips automatic purge.RETENTION_PURGE_ENABLED).EEA: the authority of the controller’s EU establishment or, if none, of the EEA data subjects as determined under the SCCs. UK: the ICO.
parsers.view / parsers.edit / integrations.manage / settings.manage); optional MFA.RETENTION_PURGE_ENABLED) and 7-day export download purge.Same list as Privacy Policy §5 and the dated public list in internal compliance docs:
Supabase (database, auth, storage, US); Vercel (hosting, US); Cloudflare (Turnstile); Stripe (payments — generally not Customer Content documents); Extend (OCR/extraction — retention per signed vendor DPA; optional zero-data-retention only if org-eligible under that contract); Postmark (inbound email if enabled); Resend or SMTP (transactional email); Sentry (errors, if enabled); Google Analytics (optional, consent, not document content).
Controller-configured destinations (Google, Xero, Intuit, Zapier, webhooks) are not Cauldrn sub-processors.
Vendor DPA signature status is tracked internally and must not be invented in public copy.
The parties enter into the Standard Contractual Clauses (Decision (EU) 2021/914) Module 2 (controller-to-processor). The official text is incorporated by reference from https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj.
Docking clause: Clause 7 applies.
Module: Module 2 only, for Customer Content.
Clause 9 (sub-processors): Option 2, general written authorization, 14 days’ notice (or as in §3.3).
Clause 11 (redress): optional clause does not apply unless required.
Clause 13: as Annex I.C.
Clause 17 (governing law): Ireland (or the EEA member state of the controller if the SCCs require a Member State law).
Clause 18 (forum): courts of the Member State of Clause 17.
Annexes I–III of the SCCs are Annex I–III of this DPA.
Cauldrn LLC signs the SCCs by making this DPA part of the Agreement. The controller signs by accepting the Terms.
For transfers of UK GDPR personal data to the United States, the parties enter into the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the ICO (the “UK Addendum”), or the ICO IDTA if the Addendum cannot apply, incorporated by reference from https://ico.org.uk.
UK Addendum tables (working completion):
UK Art. 27 representative: to be appointed (planned vendor: DataRep; TODO_DATAREP_UK_* placeholders until the mandate pack is issued).