1. Parties and precedence
This Data Processing Addendum (“DPA”) is intended to supplement an agreement between the customer organisation (“Customer”) and the configured Bodhi operator (“Processor”) where Bodhi processes personal data on Customer’s documented instructions. If executed, it prevails over conflicting general terms only for that processing.
2. Processing details
| Subject | Cloud accounting, practice, banking/OCR, compliance, audit, communications, reporting and approved AI assistance |
|---|---|
| Duration | Agreement term plus configured deletion/backup/legal retention |
| People | Customer personnel, clients, contacts, employees, vendors, counterparties and authorised users |
| Data | Identity/contact, financial, tax, employment, communications, documents, device/security and professional work records |
| Purpose | Provide, secure, support and maintain the customer-configured Service |
3. Customer instructions and duties
Customer determines lawful purpose, provides notices, obtains authority, configures access/retention, reviews output and ensures instructions comply with law and professional obligations. The Service configuration, authorised user actions and support requests are documented instructions unless Processor reasonably identifies a conflict.
4. Processor duties
Processor will process only on documented instructions; keep personnel under confidentiality; implement appropriate technical/organisational safeguards; limit access; assist with rights, security incidents and assessments as required; maintain relevant records; and delete/return data according to the agreement, subject to law.
5. Security
Controls may include verified authentication, tenant/resource scope, encryption in transit, encrypted evidence storage when configured, key separation, logging/redaction, malware quarantine, signed webhooks, backups, vulnerability/dependency checks and incident procedures. The production security schedule must identify which controls are active.
6. Subprocessors
Customer provides general authorisation for approved subprocessors listed in the versioned disclosure, subject to notice/objection terms in an executed order. Processor remains responsible for imposing suitable data-protection obligations. Candidate providers marked NOT_CONFIGURED do not process data merely by being listed.
7. AI providers
AI processing is capability- and policy-scoped. Customer data is not used for shared-model training by default. Provider retention/training, location, DPA and zero-data-retention status must be approved before sensitive use. Customer may restrict model processing by data class.
8. Rights and requests
Processor will reasonably assist Customer to respond to verified data-principal/subject requests. Processor will not independently disclose Customer-controlled records unless instructed or legally required.
9. Incidents
Processor will notify Customer without undue delay after confirming a personal-data breach affecting Customer data, with available nature, scope, likely consequence and mitigation information. Exact contractual timing remains subject to final legal review and applicable law.
10. Transfers, audits and deletion
Processing locations and safeguards must be documented before activation. Customer may receive appropriate compliance information and, under a negotiated paid/enterprise plan, proportionate audit rights. On termination, data is returned/deleted according to policy, legal hold and backup expiry.
11. Execution pending
This page is an architectural draft, not a signed DPA. Operator: . Privacy contact: .