This Data Processing Addendum ("DPA") forms part of the Terms whenever SalesTax50 processes personal information on behalf of a customer to provide the Service. For Customer Personal Data, the customer may act as the business/controller and SalesTax50 may act as the service provider/contractor/processor, depending on applicable law. For SalesTax50 account, billing, security, fraud-prevention, legal, and business-administration information, SalesTax50 may act as an independent business/controller.
Customer Personal Data may include buyer names, addresses, order information, product or line-item information, purchase amounts, tax amounts, refunds, exemptions, marketplace information, and similar sales records. Processing may include importing transactions, organizing and calculating tax data, generating reports, preparing returns, submitting customer-approved filings, maintaining records, providing support, securing the Service, and complying with applicable law. Processing continues for the account term and applicable retention period.
The customer instructs SalesTax50 to process Customer Personal Data as reasonably necessary to provide, secure, maintain, troubleshoot, and support the Service as configured by the customer; prepare tax information and customer-approved filings; comply with documented customer instructions; and satisfy applicable legal obligations. SalesTax50 will not use Customer Personal Data for unrelated advertising purposes.
SalesTax50 will restrict Customer Personal Data to authorized personnel, systems, and service providers with a legitimate need; use reasonable confidentiality obligations; and maintain safeguards appropriate to the nature of the information and Service. No particular security measure is guaranteed to prevent every incident.
If SalesTax50 receives a privacy request relating to Customer Personal Data for which the customer is responsible, SalesTax50 may refer the requester to the customer and provide reasonable assistance where required by applicable law. SalesTax50 is not required to independently adjudicate the customer's legal obligations unless legally required.
SalesTax50 will provide notice without undue delay after becoming aware of a confirmed security incident affecting Customer Personal Data where notification is required by applicable law or this DPA, together with information reasonably available and necessary for the customer to evaluate its obligations. Notice does not constitute an admission of liability.
The customer generally authorizes SalesTax50 to engage service providers and subprocessors needed to operate the Service, including providers for hosting, infrastructure, databases, communications, cybersecurity, monitoring, backup, customer support, payment processing, and related operational functions. SalesTax50 may change providers as reasonably necessary. SalesTax50 will impose appropriate contractual data-protection obligations where required by applicable law. Certain payment, banking, fraud-prevention, regulatory, or legally required processing may be performed by providers in an independent capacity under applicable law and their own obligations.
The customer is responsible for having lawful authority and a lawful basis to provide Customer Personal Data, giving required privacy notices to its own customers, responding to privacy requests for which it is responsible, configuring the Service appropriately, avoiding unnecessary submission of sensitive data, and complying with applicable privacy laws relating to its business and customer relationships.
During the account term, supported data may be available for access or export. Following termination, SalesTax50 may delete, de-identify, return, or retain Customer Personal Data in accordance with the Privacy Policy and applicable law. SalesTax50 may retain filed tax records, approval records, confirmations, billing records, security records, backups, information subject to legal hold, and information reasonably necessary for audits, disputes, fraud prevention, compliance, or enforcement. Retained information remains subject to applicable confidentiality and security obligations.
Where applicable law requires SalesTax50 to provide compliance information or permit an audit concerning Customer Personal Data, any audit will be subject to reasonable advance notice, confidentiality, reasonable frequency, non-disruption of the Service, protection of other customers' information, and use of available third-party reports or certifications where reasonably sufficient. Nothing in this DPA grants unrestricted access to SalesTax50 systems, source code, security architecture, or information belonging to other customers.
The Service is designed primarily for U.S. businesses. If a legally required international data-transfer mechanism becomes applicable, the parties may enter into or incorporate the transfer terms required by applicable law. No international transfer mechanism is promised unless actually required and implemented.
Liability arising under this DPA is subject to the disclaimers, exclusions, claim limitations, and limitations of liability in the main Terms to the maximum extent permitted by law. If this DPA conflicts with the main Terms solely on the processing of Customer Personal Data, this DPA controls only to the extent of that specific conflict. Nothing in this DPA creates a tax guarantee, security guarantee, service-level commitment, or professional-services obligation not expressly stated in a separate written agreement.
Privacy and data protection questions may be directed to support@salestax50.com.