This Data Processing Addendum ("DPA") forms part of the Terms of Service between DisputeDocs Pro ("Processor", "we") and any professional user — a credit repair organization, law firm, or other business that uploads or manages data about consumers it represents ("Controller", "you"). It applies automatically when you use the Service in a professional capacity. Consumers using the Service for their own file are covered by the Privacy Policy instead, where we act as controller of the account relationship.
1. Roles of the parties
You are the controller of consumer personal information you upload or create in the Service: credit reports, identifiers, authorizations, dispute correspondence, and case notes. You determine the purposes and means of that processing, you obtain the consumer's authorization, and you are responsible for the lawfulness of the instructions you give us.
We are the processor of that data and process it only on your documented instructions, which consist of your use of the Service's features, this DPA, and the Terms.
We are the controller of a narrow set of data we need to run the business: your account and login records, billing records, support communications, and security/diagnostic logs.
2. Scope and duration
Processing continues for as long as your account is active, plus the retention windows in the Privacy Policy. Subject matter: operation of dispute preparation and case management software. Categories of data subjects: consumers you represent and their authorized contacts. Categories of data: identity data, contact data, credit file contents, dispute history, signatures, and any documents you upload.
3. Our obligations
- Process consumer data only on your instructions, unless law requires otherwise.
- Keep personnel with access bound by confidentiality obligations.
- Maintain administrative, technical, and physical safeguards appropriate to the sensitivity of credit file data, including encryption in transit and at rest, least-privilege access, row-level tenant isolation, audit logging of file access, and multi-factor authentication for privileged accounts.
- Assist you, at your cost where the assistance is substantial, with data subject requests, security reviews, and regulator inquiries.
- Notify you without undue delay, and in any event within 72 hours, of a confirmed personal data breach affecting your data.
- Delete or return consumer data on termination, per Section 6.
4. Your obligations
- Obtain and retain a valid, scoped written authorization from every consumer before uploading their data.
- Provide the statutory disclosures your jurisdiction requires and honor consumer rights requests you receive.
- Upload only data you are permitted to process, and only what is necessary.
- Maintain the confidentiality of your credentials and remove access promptly when staff leave.
5. Subprocessors
You authorize us to engage subprocessors to deliver the Service. Current categories and providers:
- Cloud hosting and application delivery — serving the web and mobile applications.
- Managed database, authentication, and file storage — storing account records, case data, and uploaded documents.
- AI model providers — extracting structured data from uploaded reports and drafting correspondence. Processing is transient; providers are contractually barred from training on your data.
- Payment processing (Stripe) — subscription and one-time billing. Card data never reaches our systems.
- Transactional email delivery — account, security, and notification email.
We remain responsible for our subprocessors' performance. We will give notice of a new subprocessor before it begins processing your data; if you reasonably object on data protection grounds you may terminate the affected Service without penalty for the unused prepaid period.
6. Deletion and return
You can export your case data at any time from the application. On account closure or written request, consumer data is removed from live systems within 24 hours and purged from encrypted backups no later than 30 days afterward. Deletion is tracked per artifact so a destruction trail exists for audit. We retain only records we are legally required to keep, such as billing and tax records, in restricted-access archives.
7. Audits
On reasonable written notice, no more than once per twelve months, we will provide available security documentation and respond to a reasonable security questionnaire. On-site audits are available where required by law, at your cost, subject to confidentiality and scheduling that avoids disruption to other customers.
8. International transfers
The Service is operated from the United States and data is processed there. If you are subject to a data protection regime that restricts cross-border transfers, do not upload data covered by that regime without first contacting us to put appropriate transfer mechanisms in place.
9. Liability and conflicts
Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service. Where this DPA conflicts with the Terms on the processing of consumer personal information, this DPA controls.
10. Contact
Requests for a countersigned copy, subprocessor notices, and breach contacts: support@disputedocs.app.
DisputeDocs Pro 440 Coit Rd Plano, TX 75075 United States